EXPERT AND AUTHOR
Michał Rutkowski — DPO, GDPR, NIS2 and cybersecurity
Since 2004 I have worked at the intersection of technology, data protection and risk management. I act as an external DPO, run GDPR audits, prepare organizations for NIS2 and the Polish KSC Act, support them during incidents and breaches, and train management boards and teams.

Experience and how I work
I am a data protection and cybersecurity practitioner and the owner of LabLogic. I work with medium and large organizations, including the financial sector and other regulated industries. I combine the legal, organizational and technological perspective: support for and fulfilment of the DPO role, preparation for NIS2 and the Polish KSC Act, incident response, audits and training. I also publish current commentary on GDPR, NIS2/KSC and the AI Act on LinkedIn.
Practical experience working with systems, processes, vendors, and real organizational problems.
Recommendations result from the analysis of events, projects, and the organization’s mode of operation.
Communication tailored to the management board and cooperation with legal, compliance, HR, and IT.
Ability to work with documentation, teams, and stakeholders in both languages.
Areas where I can help
Choose the area that matches your organization’s situation.
DPO and GDPR
External DPO, support for your current data protection officer, a GDPR audit and ongoing advice for the board and the teams.
NIS2 and local law KSC
Qualification under NIS2 and the KSC act, gap and risk analysis, a plan and support for implementation and audit readiness.
Incidents and breaches
Assessment of the situation and the risk, decisions on notifications, communication and corrective actions.
Training and workshops
Practical GDPR, NIS2 and AI Act training for boards, senior management, employees and IT and compliance teams.
NEW AREA
AI Act — a new area of my practice
The AI Act is settled on the same ground as GDPR and NIS2: roles, obligations, evidence. I start from what actually runs in the organisation — chatbots, assistants, anything that generates content — and establish which obligations already apply to you and which are still ahead.
Knowledge and insights
I publish current analyses and explanations in the LabLogic Knowledge Base. Choose the category that matches the question your organization is facing.

Incidents and Breaches
Assessing the event, the notification decision and the first day.
NEW AREA
AI Act
Roles towards an AI system, the obligations that already apply and how to evidence them.
Latest publications
The newest explanations and analyses from the LabLogic Knowledge Base.
DIAGNOSTIC CONVERSATION
Let’s start with a conversation about your organization’s needs
We will determine whether the appropriate first step will be an audit, formal fulfillment of the DPO function, ongoing expert support, or assistance with a breach.
Briefly describe your situation
The administrator of the data provided in the form is Michał Rutkowski, operating LabLogic Consulting. I use the data to handle inquiries and prepare a response or offer. Details can be found in the Privacy Policy. Do not send passwords, special categories of data, or full incident documentation.











