PRACTICE AREAS

Compliance that keeps pace with your operations. COMPLIANCE & RISK

Operating in Poland and the EU means running under a regulatory layer that keeps expanding.

COMMON ISSUES

Where EU compliance breaks down for international companies

Companies build EU operations quickly and assume compliance is a back-office problem. It isn’t. AI Act, NIS2, CSRD, sector-specific obligations, and supply chain requirements are live obligations with board-level exposure. Most US operators find out about the gaps when an auditor, investor, or regulator asks the question.

You don't have a clear map of what EU law actually requires from your operations AI Act, GDPR, NIS2, CSRD, sector rules — each regulation covers different entities, timelines, and thresholds. US companies often know they're affected but don't have a clean answer to: which obligations apply to us, which are live now, and which ones we're currently not meeting?
We run a regulatory scope assessment — identifying which EU obligations apply to your Polish entity, what the thresholds and timelines are, where you're compliant, and where the gaps are. The output is a prioritized compliance map, not a recitation of law.
Your vendors and supply chain create EU compliance exposure you can't see NIS2 extends obligations into supply chains. AI Act creates accountability for deployers as well as developers. GDPR creates liability for processor relationships. US companies often have clean internal processes and blind spots everywhere vendors, contractors, and technology partners touch their operations.
We assess your third-party compliance exposure — mapping vendor access to data, systems, and critical functions; identifying the gaps in your contractual protections; and building the vendor compliance framework that covers NIS2, AI Act, and GDPR supply chain requirements.
When something goes wrong, you don't have a documented response path Regulatory incidents in the EU are multi-statute events — a data breach can trigger GDPR, NIS2, sector-specific notification requirements, and potential AI Act reporting depending on the system involved. Most US companies have a data breach playbook and nothing else. When an incident touches multiple regulatory frameworks at once, the improvised response is the most expensive one.
We build a cross-regulation incident response framework — intake, classification, notification decisions, documentation, and regulatory reporting requirements mapped across GDPR, NIS2, AI Act, and applicable sector rules — so your first action after an incident is following a tested procedure, not calling a lawyer in a panic.

WHO THIS IS FOR

Built for companies running EU operations without a dedicated EU compliance team

We work best with US founders, GCs, compliance officers, and operators who are managing EU regulatory obligations from the US side — and need Polish law counsel that understands US org structures, explains EU requirements in plain language, and builds programs that work for lean teams, not EU compliance departments.

You're a US GC responsible for EU regulatory compliance across Polish operations

You need a clear map of what applies, what's live, and what your team needs to build - without a six-month engagement that tells you nothing actionable.

  • GC
  • CLO
  • VP
  • Legal

You're a founder whose Polish entity is growing fast and outrunning its compliance program

Your team is hiring, processing more data, using more AI tools, and onboarding more vendors - and your compliance documentation hasn't kept up.

  • CEO
  • Founder
  • COO

You're preparing for an investor, acquisition, or corporate partnership that requires EU compliance diligence

Your EU regulatory posture is going to be reviewed. You need to know where you stand and what to close before the process starts.

  • CFO
  • GC
  • CEO

You're a compliance officer building the EU compliance program from scratch

EU law applies differently than US regulations — the obligation structures, timelines, and supervisory expectations are unfamiliar, and you need EU counsel that can translate them into a buildable program.

  • CCO
  • Compliance Officer
  • VP Compliance

OUTCOMES

what you can expect

What a well-structured EU compliance program gives your operations.

Clarity

Every applicable EU obligation mapped to your operation, with thresholds, timelines, and status included.

Ownership

Ownership assigned and procedures built for how your team actually works.

Vendors

Every vendor assessed for regulatory risk, with gaps closed before they surface.

Response

One incident process, mapped to every regulation's deadlines and requirements.

Readiness

A documented, current program, ready for any buyer, investor, or auditor.

HOW WE WORK TOGETHER

from compliance gap to working program

International companies managing EU compliance typically move through four stages: understanding what applies, closing the identified gaps, building the ongoing programs that keep them current, and having counsel to handle what comes up. Below is the typical shape, with the services that appear at each stage.

Map

We establish what EU regulations apply to your operation, what you're currently meeting, and where the gaps are.

  • EU Regulatory Compliance Program
  • Sector Regulatory Compliance EU

Build

We design and implement the compliance programs your assessment identified - ESG, vendor risk, incident response, or sector-specific programs.

  • ESG and CSRD Compliance
  • Vendor Compliance Program EU
  • Regulatory Incident Response EU

Operate

We provide ongoing compliance counsel - monitoring regulatory changes, answering questions, and keeping your programs current.

  • Compliance Retainer

Respond

When something goes wrong - an incident, a regulatory inquiry, a vendor issue. We manage the response across every applicable framework.

  • Regulatory Incident Response EU
  • Compliance Retainer

BLOG

knowledge base

Practical reads on Polish and EU law, written for the people actually running the business – not studying it.

YOU OFTEN ASK

FAQ

On compliance, most questions come down to two things – what applies, and who’s personally liable. Here are the answers we give most often.

The core regulatory stack for most companies with Polish entities includes: GDPR (data protection, applies from day one of EU data processing); the EU AI Act (phased obligations from 2025 through 2027 depending on system type); NIS2 (cybersecurity incident reporting and supply chain requirements for companies in or supplying to covered sectors); CSRD (sustainability reporting obligations for larger entities and, indirectly, for smaller companies in their supply chains); and sector-specific requirements if the operation is in financial services, healthcare, energy, or other regulated industries. The applicable set depends on the entity’s size, sector, and operational footprint.

Yes. The EU AI Act applies to providers and deployers of AI systems when those systems are placed on the EU market or used in the EU — regardless of where the company is incorporated. A US company that deploys an AI system in its Polish entity, or that provides an AI product to EU customers, can be subject to AI Act obligations. The specific requirements depend on the risk classification of the system. Prohibited practices and AI literacy requirements became applicable in February 2025; most other obligations phase in through 2026 and 2027.

CSRD obligations are triggered at the entity level based on size thresholds (number of employees, balance sheet, net turnover) and, for EU subsidiaries of non-EU groups, can apply even when the Polish entity doesn’t independently meet the thresholds if the parent group does. The practical effect is that US companies with larger EU operations may face EU sustainability reporting obligations — including double materiality assessment and ESRS-aligned disclosure — even though the legal entity is a Polish subsidiary of a US parent. We assess applicability based on the specific group structure and operational numbers.

NIS2 applies to entities in 18 critical sectors and important sectors — including digital infrastructure, cloud services, managed service providers, energy, financial market infrastructure, health, and others. The obligation extends to the supply chains of covered entities, which means a US company that provides ICT services or software to a NIS2-covered Polish entity may face contractual compliance requirements even if it isn’t directly covered. Polish NIS2 transposition requires covered entities to implement risk management measures, report incidents within defined timelines (24 hours for early warning, 72 hours for initial notification), and manage their supply chain security.

Policies and procedures are documents. A compliance program is a functioning system: someone owns it, it maps to actual obligations, it’s updated when regulations change, it connects to how operations actually run, and it produces the documentation you need to demonstrate compliance to a regulator, auditor, or investor. Most US companies with EU operations have policies. Fewer have programs. The distinction matters in enforcement and diligence: a regulator or acquirer can assess whether a program was functioning; they can only read whether a policy existed.

We start with a regulatory scope assessment — a structured review of what the Polish entity does, what data and systems it operates, what sectors it participates in, how it manages vendors, and what its size thresholds are. From that, we produce an obligation map: which regulations apply, which are currently live, which are approaching, and where the entity stands against each. The assessment typically takes two to three weeks and produces the prioritized action plan we then use to scope any program-building work.