Cybersecurity · 5 min

When does a company need a DPO?

Not every company must have a DPO — but every one must check.

17 September 2025

Cyberattacks on Polish businesses are no longer a problem for large corporations only. In 2026 the primary targets are small and mid-sized companies, because they have data, money and weaker defences. Below we show exactly what When does a company need a DPO? means and which decisions are worth making this quarter.

Not every company must have a DPO — but every one must check.

DPO obligation

Regulatory compliance is not optional — it is a condition for operating. For Polish companies in 2026 the three sets of requirements that matter most are: GDPR, NIS2 and (in selected industries) sectoral rules (e.g. KNF).

The minimum you need

  • A record of processing activities and a risk analysis.
  • Data Processing Agreements (DPA) with every provider processing personal data.
  • An incident reporting procedure (72 hours to the DPA in case of a breach).
  • A security policy and regular employee training.
  • Backups with restore tests (proof that the backup works).

GDPR fines in Poland reach up to 4% of global turnover. NIS2 adds reporting duties and personal liability of the management. The cost of preparation is incomparably lower than the cost of being unprepared.

Tasks

Procedures are a way to make sure nobody has to remember the order of steps under stress. A good procedure fits on one A4 page and says what, when and by whom is to be done.

  • Access to systems (mail, VPN, line-of-business apps) — granted before the first day.
  • Hardware (laptop, monitor, accessories) — pulled from stock and configured two days ahead.
  • Accounts and MFA activated; a starter password that forces a change on first login.
  • Short training on tools + security policy (30–60 minutes).
  • Helpdesk contact and incident reporting procedure — in writing, on the intranet.

Internal vs external DPO

Regulatory compliance is not optional — it is a condition for operating. For Polish companies in 2026 the three sets of requirements that matter most are: GDPR, NIS2 and (in selected industries) sectoral rules (e.g. KNF).

The minimum you need

  • A record of processing activities and a risk analysis.
  • Data Processing Agreements (DPA) with every provider processing personal data.
  • An incident reporting procedure (72 hours to the DPA in case of a breach).
  • A security policy and regular employee training.
  • Backups with restore tests (proof that the backup works).

GDPR fines in Poland reach up to 4% of global turnover. NIS2 adds reporting duties and personal liability of the management. The cost of preparation is incomparably lower than the cost of being unprepared.

Key takeaways

  • Significantly reduced risk of ransomware and customer data leaks.
  • Relying only on antivirus instead of layered protection (EDR + MFA + backup).
  • Treat the topic of "When does a company need a DPO?" as a project, not a one-off purchase — the best results come from a step-by-step approach.

Frequently asked questions

Check your company's security level

We invite you to a free cybersecurity consultation. We will walk through a checklist of 30 key areas (MFA, backup, EDR, training) and point out priorities for the next quarter.