EXPERT AND AUTHOR

Michał Rutkowski — DPO, GDPR, NIS2 and cybersecurity

Since 2004 I have worked at the intersection of technology, data protection and risk management. I act as an external DPO, run GDPR audits, prepare organizations for NIS2 and the Polish KSC Act, support them during incidents and breaches, and train management boards and teams.

Michał Rutkowski, data protection officer (DPO) and NIS2 expert, owner of LabLogic

Experience and how I work

I am a data protection and cybersecurity practitioner and the owner of LabLogic. I work with medium and large organizations, including the financial sector and other regulated industries. I combine the legal, organizational and technological perspective: support for and fulfilment of the DPO role, preparation for NIS2 and the Polish KSC Act, incident response, audits and training. I also publish current commentary on GDPR, NIS2/KSC and the AI Act on LinkedIn.

Over 20 years of technological experience

Practical experience working with systems, processes, vendors, and real organizational problems.

Audits and practice in breach handling

Recommendations result from the analysis of events, projects, and the organization’s mode of operation.

Support for complex organizations

Communication tailored to the management board and cooperation with legal, compliance, HR, and IT.

Polish and English

Ability to work with documentation, teams, and stakeholders in both languages.

Areas where I can help

Choose the area that matches your organization’s situation.

DPO and GDPR

External DPO, support for your current data protection officer, a GDPR audit and ongoing advice for the board and the teams.

NIS2 and local law KSC

Qualification under NIS2 and the KSC act, gap and risk analysis, a plan and support for implementation and audit readiness.

Incidents and breaches

Assessment of the situation and the risk, decisions on notifications, communication and corrective actions.

Training and workshops

Practical GDPR, NIS2 and AI Act training for boards, senior management, employees and IT and compliance teams.

NEW AREA

AI Act — a new area of my practice

The AI Act is settled on the same ground as GDPR and NIS2: roles, obligations, evidence. I start from what actually runs in the organisation — chatbots, assistants, anything that generates content — and establish which obligations already apply to you and which are still ahead.

See the AI Act service

Knowledge and insights

I publish current analyses and explanations in the LabLogic Knowledge Base. Choose the category that matches the question your organization is facing.

Illustration for the DPO and GDPR area

DPO and GDPR

When a DPO must be appointed and how to evidence accountability.

See the publications

Illustration for the NIS2 and KSC area

NIS2 and KSC

Entity qualification, the scope of measures and responsibility.

See the publications

Illustration for the Incidents and breaches area

Incidents and Breaches

Assessing the event, the notification decision and the first day.

See the publications

Illustration for the Training and workshops area

Training and workshops

Who to train, how often and how to evidence the effect.

See the publications

NEW AREA

AI Act

Roles towards an AI system, the obligations that already apply and how to evidence them.

See the publications

Latest publications

The newest explanations and analyses from the LabLogic Knowledge Base.

What does the AI literacy obligation require?

What does the AI literacy obligation require?

Article 4 of the AI Act, after the July 2026 amendment, describes the obligation through measures…

Read the article

Who cannot act as a data protection officer?

Who cannot act as a data protection officer?

The GDPR contains no list of positions excluded from the role of data protection officer. The…

Read the article

What risk management measures must an essential entity implement?

What risk management measures must an essential entity implement?

NIS2 risk management measures do not take the form of a checklist in the Polish KSC…

Read the article

Is the AI tool we use a high-risk system?

Is the AI tool we use a high-risk system?

Whether a tool is a high-risk AI system is settled by its intended purpose and the…

Read the article

What does a significant incident report to a CSIRT contain?

What does a significant incident report to a CSIRT contain?

A significant incident report is not one document but a sequence of four submissions. An early…

Read the article

What to do after 3 October 2026, once the deadline for entry in the KSC register has passed?

What to do after 3 October 2026, once the deadline for entry in the KSC register has passed?

The third of October closes the schedule for filing applications, but not the registration obligations. After…

Read the article

What should an AI use register contain?

What should an AI use register contain?

The AI Act does not require a register of AI use cases. A central inventory is…

Read the article

When does an organisation using AI become the provider of a system?

When does an organisation using AI become the provider of a system?

Article 25(1) of the AI Act names three circumstances in which a deployer becomes the provider…

Read the article

Who is responsible for AI Act transparency obligations?

Who is responsible for AI Act transparency obligations?

Article 50 of the AI Act splits the obligations by role towards the system, not by…

Read the article

Previous slide
Next slide

DIAGNOSTIC CONVERSATION

Let’s start with a conversation about your organization’s needs

We will determine whether the appropriate first step will be an audit, formal fulfillment of the DPO function, ongoing expert support, or assistance with a breach.

Briefly describe your situation

The administrator of the data provided in the form is Michał Rutkowski, operating LabLogic Consulting. I use the data to handle inquiries and prepare a response or offer. Details can be found in the Privacy Policy. Do not send passwords, special categories of data, or full incident documentation.

Scroll to Top