EXPERT AND AUTHOR
Michał Rutkowski — DPO, GDPR, NIS2 and cybersecurity
Since 2004 I have worked at the intersection of technology, data protection and risk management. I act as an external DPO, run GDPR audits, prepare organizations for NIS2 and the Polish KSC Act, support them during incidents and breaches, and train management boards and teams.
Over 20 years of experience • data protection, technology, and risk management • cooperation in Polish and English

Direct contact with an expert
A brief answer and a clear recommendation for the next step.

Experience and how I work
I am a data protection and cybersecurity practitioner and the owner of LabLogic. I work with medium and large organizations, including the financial sector and other regulated industries. I combine the legal, organizational and technological perspective: support for and fulfilment of the DPO role, preparation for NIS2 and the Polish KSC Act, incident response, audits and training.
Over 20 years of technological experience
Practical experience working with systems, processes, vendors, and real organizational problems.
Audits and practice in breach handling
Recommendations result from the analysis of events, projects, and the organization’s mode of operation.
Support for complex organizations
Communication tailored to the management board and cooperation with legal, compliance, HR, and IT.
Polish and English
Ability to work with documentation, teams, and stakeholders in both languages.
Areas where I can help
Choose the area that matches your organization’s situation.
DPO and GDPR
External DPO, support for your current officer, GDPR audit and ongoing advice for the board and teams.
NIS2 and KSC
Entity qualification, gap and risk analysis, a plan and support for implementation and audit readiness.
Incidents and breaches
Situation and risk assessment, notification decisions, communication and remedial actions.
Training and workshops
Practical GDPR and NIS2 training for boards, senior staff and IT and compliance teams.
Knowledge and insights
I publish current analyses and explanations in the LabLogic Knowledge Base. Choose the category that matches the question your organization is facing.
DPO and GDPR
When a data protection officer has to be appointed, how the role works with the management board and what day-to-day GDPR practice requires.
NIS2 and KSC
Whether your organization falls under the new rules, how to read the result of a gap analysis and where to start the preparations.
Incidents and breaches
How an incident differs from a personal data breach, when the duty to notify arises and what the breach register has to contain.
Training and workshops
Who to train and how often, what the management board should expect from a session and how to measure its effectiveness.
Latest publications
The newest explanations and analyses from the LabLogic Knowledge Base.

Who else needs NIS2 training besides the management board?
The KSC Act names only the head of the entity and the person entrusted with their…

What should a personal data breach register contain?
Article 33(5) GDPR requires documentation, not a register in a prescribed form. The documentation has to…

When and how to apply for entry in the KSC register?
The deadline depends on the day the conditions were met. Entities that met them on 3…

External or internal DPO? What to consider before deciding?
The regulation allows both models and holds them to the same requirements. The choice is not…

How do you know that training produced a real effect?
Attendance and a final test describe how the training went, not its effect. The effect shows…

Cybersecurity incident vs personal data breach: what is the difference?
An incident under the Polish KSC act and a breach under the GDPR are two independent…

What should a NIS2 gap analysis contain?
A gap analysis has to let the board take three decisions: what the organisation must meet,…

Where should the board begin preparing for NIS2?
With two board decisions: who is the entity manager within the meaning of the KSC Act,…

How often should employees be trained on data protection?
The GDPR does not specify training frequency. The rhythm is set by changes in processes, staff…
DIAGNOSTIC CONVERSATION
Let’s start with a conversation about your organization’s needs
We will determine whether the appropriate first step will be an audit, formal fulfillment of the DPO function, ongoing expert support, or assistance with a breach.
Briefly describe your situation
The administrator of the data provided in the form is Michał Rutkowski, operating LabLogic Consulting. I use the data to handle inquiries and prepare a response or offer. Details can be found in the Privacy Policy. Do not send passwords, special categories of data, or full incident documentation.