Autor: user

  • Impact of the Omnibus Directive on Sellers in Polish E-commerce

    Impact of the Omnibus Directive on Sellers in Polish E-commerce

    The Omnibus Directive, introduced at the European Union level, marks a significant milestone in e-commerce regulation. In the context of the dynamic development of e-commerce and the digitization of the economy, unification and updating of regulations have become essential to create a consistent regulatory framework. The Omnibus Directive responds to these challenges by providing a comprehensive approach to regulating various aspects of e-commerce. Its main objective is to create a coherent and effective framework legislation that takes into account both the rights of consumers and the obligations of businesses in the area of e-commerce. § Impact of the Omnibus Directive on Sellers in Polish E-commerce.

    Impact of the Omnibus Directive on Sellers in Polish E-commerce

    The introduction of the Omnibus Directive has a huge impact on sellers operating in the Polish e-commerce market, changing the context of the legal environment in which they operate. Below we will discuss the key areas in which this directive affects e-commerce sellers in Poland:

    Consumer Rights Protection

    The Omnibus Directive introduces significant changes to the protection of consumer rights in e-commerce. Expanded consumer rights are designed to increase consumer confidence and trust when shopping online. One key element is the right to easy access to detailed information about products or services. Sellers must provide full and accurate descriptions of products, including their features, characteristics and technical parameters.

    Another important aspect is the extended cancellation period of up to 14 days without giving a reason. This right gives customers more flexibility and confidence, allowing them to carefully examine the product after receiving it. In the event of cancellation, the seller must refund all payments received from the customer, including delivery costs.

    In addition, the Omnibus Directive requires vendors to provide clear and transparent information on prices and fees. The final price, which is visible to the customer, must include any additional costs, such as delivery charges or taxes. This ensures that customers are not exposed to misunderstandings about hidden fees.

    Adjustment of Terms of Sale

    The introduction of the Omnibus Directive requires e-commerce sellers to adapt their terms of sale to the new regulations. They must ensure full transparency and availability of information regarding products or services. This includes accurate descriptions, specifications, technical parameters and information on the availability of goods. Sellers must also allow an easy and understandable ordering procedure and provide information on delivery costs and delivery times.

    One important aspect is also the protection of customers’ personal data. The Omnibus Directive introduces stricter requirements for the processing of personal data, which obliges vendors to use appropriate security measures to protect their customers’ data from unauthorized access or disclosure. Compliance with these regulations is key to avoiding data protection violations and potential financial penalties.

    Oversight of Internet Platforms

    The Omnibus Directive makes online platforms more accountable for the content and activities of vendors operating on their platforms. Platforms must actively monitor the content and activities of their users to eliminate illegal content, products or illegal activities. Implementing effective control and regulation mechanisms is becoming a priority for platforms, which must ensure that their vendors’ activities comply with the law.

    One of the main aspects of oversight is preventing the sale of fake or dangerous products. Platforms must effectively identify and remove such products and monitor the activities of their sellers to ensure compliance with the law. In addition, platforms must take action in the event of violations, including suspending or terminating the accounts of sellers who fail to comply with regulations.

    Adjusting Terms of Sale Polish e-commerce companies must adjust their terms and conditions.

    Adapting Terms of Sale Polish e-commerce companies must adapt their terms of sale to the new directive’s regulations. This includes ensuring transparency of information about products or services, the ordering process and delivery. Vendors must also pay special attention to customer data protection issues to meet the new security and privacy requirements. This means investing in the right tools and procedures to comply with these regulations.

    Increased Accountability


    The Omnibus Directive introduces significant changes to the liability of e-commerce sellers, imposing greater responsibilities and risks for malfunction or non-compliance. We will elaborate on the increased liability of e-commerce sellers below:

    1. Necessity of ComplianceThe Omnibus Directive requires e-commerce sellers to operate in full compliance with online sales regulations. This means that they must adapt their practices to the new requirements regarding consumer protection, product information, delivery, returns and complaints. Failure to comply with these obligations can lead to legal violations and penalties.

    2. Effective Customer ServiceE-commerce sellers must provide effective customer service, both in terms of orders and complaint handling. Customers need to feel confident that they can easily contact the vendor, get answers to questions and resolve any problems. Failure to provide adequate customer service can lead to negative reviews, loss of customers and loss of trust.

    3. Timely Delivery and Realistic Lead TimesThe directive requires vendors to ensure timely delivery of ordered products. They must deliver the products within the agreed time or in accordance with the contract with the customer. Untimely delivery can lead to dissatisfied customers and the need for returns.

    4. Data Security and PrivacyE-commerce sellers are now more responsible for the security and privacy of their customers’ personal information. They must use appropriate security measures to protect data from unauthorized access or disclosure. In the event of a data breach, merchants are required to notify customers of the incident and take corrective action.

    5. Effective Returns and Complaints ManagementVendors must effectively manage the returns and complaints process, ensuring that customers can file complaints and return goods in accordance with regulations. They must process complaints in a timely manner and provide customers with appropriate solutions, such as refunds or product replacements.

    Summary

    In summary, the Omnibus Directive introduces significant changes to e-commerce regulations that are designed to increase consumer protection and improve e-commerce standards. E-commerce sellers in Poland must be prepared to comply with the new regulations, which requires investment in adjusting procedures, ensuring legal compliance and providing excellent customer service. Compliance with the Omnibus Directive is not only a legal obligation, but also an opportunity to increase customer confidence and succeed in a dynamic e-commerce environment. At the same time, retailers need to be aware of possible changes in the regulations and adapt their operations to the new guidelines in order to maintain their competitiveness in the market. It is also worth noting that these changes are a step towards a more sustainable and secure e-commerce environment, which can benefit both customers and businesses in the industry.

    § Impact of the Omnibus Directive on Sellers in Polish E-commerce

    www.petlic.co

  • Can the IT license agreement be replaced by a lease agreement?

    Can the IT license agreement be replaced by a lease agreement?

    The onerousness of the copyright regulation of the license agreement is leading to further attempts by IT companies to break out of these shackles by their legal services.

    In particular, there has been a demand to apply the regulation of the lease of a thing (Article 659 § 1 of the Civil Code) directly to an object that is not a thing, i.e. software.

    In fact, this required at least partial identification of software with its copy. Aside from the narrow issue of so-called marketing, however, this still seems unacceptable.

    Moreover, it required drawing an overly far-reaching conclusion about the possibility of software leases from the mere coincidence of the concept of „lease” in defining the field of exploitation in the form of a lease of a copy and in the named contract of the Civil Code. However, these issues are separate and completely different and cannot be equated in this way. A field of exploitation is a field of exploitation, and a contract is a contract.

    It also seems to be going too far to conclude that it would be permissible to conclude software lease agreements due to the sheer significant discrepancies in copyright law doctrine with regard to the possible application of the contract provisions of sections of the Copyright Act to lease and use agreements.

    It turns out, moreover, that having constructed, in extensive and based on rich professional literature and extremely interesting case law, the entire model of a software lease agreement, the authors allow, however, to refer to it only in the contractual provisions „in addition to the provisions providing for the granting of a license to the ordering party” or in a salvatory clause.

    As a result, it seems that such a narrow, and in fact also very unclear as to the exact scope, admission of the use of a software lease agreement has little practical application. As it seems, therefore, the work done by the authors themselves has led to the exclusion of the use of a software lease agreement (which is a pertinent conclusion!), rather than to the confirmation of such a possibility.

    As can be seen from this, IT companies remain basically „condemned” to right-author licenses, since the conclusion of a software lease agreement can also give rise to difficulties.

  • To achieve a successful real estate flip, involving a lawyer is essential.

    To achieve a successful real estate flip, involving a lawyer is essential.

    The professionalization of property purchasing, renting, and investment has accelerated significantly. Real estate flips, which involve quickly buying and selling properties to achieve substantial profits, have become popular. However, this form of investment comes with risks, making cooperation with an experienced lawyer crucial. § To achieve a successful real estate flip, involving a lawyer is essential.

    Real estate flip


    Flippers search for properties that can increase in value in the future, often due to undervalued offers. They identify opportunities that, after renovation or minor changes in decor, can be sold at a profit. However, the growing number of investors makes it harder to access favorable offers and increases the risk associated with legal and property aspects of such transactions.

    Why to achieve a successful real estate flip, involving a lawyer is essential?

    Flippers may encounter properties without land and property registers or discrepancies with the actual legal status, restitution claims, problematic tenants, unresolved land status under buildings, or doubts about preservation regulations. These issues can complicate the flipping process and lead to financial losses.


    Despite these challenges, real estate flips have advantages, such as the potential for significant short-term profits with minimal effort and without the need for specialized education or permits. The increasing interest in this form of investment has led to a higher demand for legal services related to flipping.


    Collaborating with a real estate lawyer undoubtedly enhances the safety of investment activities. The knowledge and support of a specialist can simplify the flipping process and help avoid potential legal problems.


    Engaging an experienced lawyer can significantly facilitate and secure the investment process, providing support in setting up a company, documentation, and tax-related matters. We are pleased to offer assistance in auditing legal aspects of properties, contract verification, and organizing the legal status of properties.

    § To achieve a successful real estate flip, involving a lawyer is essential.

  • Telemedicine in Poland: Utilization, regulation and challenges

    Telemedicine in Poland: Utilization, regulation and challenges

    Telemedicine in Poland is a rapidly growing field of medicine that plays an important role in providing access to health care, especially in the context of modern health challenges. It uses advanced telecommunications technologies to enable medical consultations, diagnosis of medical conditions and provision of medical advice at a distance. Let’s now outline its use, regulations and challenges in Poland. § Telemedicine in Poland: Usage, regulations and challenges


    Use of telemedicine in Poland

    Telemedicine in Poland has found application in various areas of medicine. Patients can receive medical consultations online, get advice from specialists, and even monitor their health through medical devices and apps. This makes it easier for people living in hard-to-reach regions or with limited mobility to access healthcare. Telemedicine can also support diagnostics by sending test results and medical images, allowing specialists to quickly evaluate a case.


    Legal regulations of telemedicine in Poland

    In Poland, telemedicine regulations are evolving to adapt to new challenges. In May 2021, the Law on Public Health came into force, which includes provisions on telemedicine. According to it, telemedicine is legal and can be used for diagnosis, treatment, prevention and rehabilitation. Doctors and other health professionals can provide medical advice online, and patients can access these services through telemedicine platforms. It is also worth noting that electronic prescriptions have become widely available, making it easier for patients to access medicines.

    However, telemedicine regulations still need to be clarified and standardized. There are challenges related to the protection of patient data and ensuring appropriate standards for the provision of online medical services. It is also necessary to regulate the professional liability of physicians working in telemedicine and to guarantee the safety and quality of care.


    Challenges of telemedicine in Poland

    With the development of telemedicine in Poland, there are some challenges. One of them is the need to ensure appropriate quality and safety standards for telemedicine services. It is also important to consider the issue of legal liability in the case of medical errors committed online and the protection of patient data.

    Another challenge is to ensure access to telemedicine for all patients, regardless of their location or ability to use the technology. It is also necessary to educate both patients and medical personnel about telemedicine to ensure effective and safe use of these services.

    In conclusion, telemedicine in Poland has great potential in improving access to healthcare and the efficiency of the healthcare system. However, in order to realize this potential to the fullest, it is necessary to further improve regulations and solve challenges related to the quality, safety and accessibility of telemedicine services.

    §Telemedicine in Poland: Utilization, regulation and challenges

  • VAT taxation of NFT transactions

    VAT taxation of NFT transactions

    The popularity of non-fungible tokens (NFTs) and numerous new proposals for their use raise questions about how transactions involving them are taxed. The problem of VAT treatment of transactions involving NFTs comes to the fore. Indeed, a number of questions arise in this context: Is NFT a good or a service? If a service, what kind of service? Does the sale of tokens constitute a financial service? Is it subject to VAT exemption? We will try to answer these questions in this text. § VAT taxation of NFT transactions.

    What are NFT tokens?

    NFT tokens are non-exchangeable, unique digital elements that represent a unique digital or even physical object through data stored on the blockchain. Thanks to this solution, the data can be considered unique and authentic, allowing NFTs to be used as a kind of certificate referring to a specific right.

    It is worth further clarifying what an NFT token is not. First of all, it should not be equated with virtual currency in the sense of the Law of March 1, 2018 on Anti-Money Laundering and Terrorist Financing [1], i.e. a digital representation of certain values that is exchangeable in business for legal tender and accepted as a means of exchange, and can be electronically stored or transferred, or can be subject to electronic commerce. It is convertibility that is the essence of the functionality of virtual currencies, which are accepted as a means of exchange and can also be the subject of electronic commerce. Examples of virtual currencies understood in this way include cryptocurrencies such as Bitcoin or Ether.

    In contrast, the NFT token, unlike virtual currencies, as a rule is not convertible into a means of payment (especially fiat currency), which means that it does not even indirectly have a payment or near-payment function. However, is this always the case? It is conceivable that the NFT will be traded – after all, it represents a certain value and its owner may be interested in selling it and another person in acquiring it. Nor can it be ruled out that such a token will be traded, for example, on a cryptocurrency exchange. The line between convertibility and non-convertibility is therefore thin and difficult to grasp. In some cases, therefore, NFT will be able to constitute a virtual currency within the meaning of AML regulations, as also indicated by the position of the Financial Action Task Force (FATF).

    Equally complicated is the issue of the possible qualification of an NFT token as a security or, more broadly, a financial instrument within the meaning of the Act of July 29, 2005 on Trading in Financial Instruments [2]. Tax authorities, such as the Director of National Tax Information in an individual interpretation dated October 7, 2022 (No. 0112-KDIL1-3.4012.279.2022.2.KK), assume that an NFT token does not constitute a financial instrument. However, it seems that this issue is not clear-cut, and it is possible to imagine such a construction of the NFT that would prejudge its character as a financial instrument. One should also bear in mind here the issues related to the implementation into the Polish legal order of the amendments to the MIFID II Directive [3], which relate to changing the definition of a financial instrument to include instruments issued using DLT technology, as we pointed out in the article on the DLT pilot regulation [4].

    An NFT token – „minted” on a blockchain – does not in itself constitute an object of copyright, and its transfer does not transfer to the buyer intellectual property rights over the digital content constituting the work referenced by the NFT token, and does not imply the conclusion of a license to use the work. Depending on the situation, a non-exclusive license agreement, for example, may be needed to use the digital content.

    Goods or services?

    The specific construction and legal nature of the NFT token is the reason for doubts about its classification under VAT. The main question in this regard is whether the sale of an NFT constitutes a supply of goods or a provision of services within the meaning of the Law of March 11, 2004 on Value Added Tax[5] (hereinafter: the „VAT Law”). In this context, it is important to note that the token is not in-kind, but constitutes a right. Consequently, it cannot be classified as a good within the meaning of Article 2(6) of the VAT Law. On the other hand, any service that does not constitute a supply of goods is treated as a supply of services under VAT (Article 8(1) of the VAT Act). This includes the transfer of rights. Therefore, the sale of NFT should be treated as a supply of services for VAT purposes.

    This was the position taken by the Director of National Tax Information in an individual interpretation dated August 29, 2022 (No. 0111-KDIB3-1.4012.346.2022.7.ICZ). The facts presented by the applicant involved the transfer of NFT tokens in exchange for virtual currency. The authority concluded that such an activity is subject to value added tax. In addition to the nature of the activity performed (on a service-for-service basis), attention was also paid to the equivalence of the parties’ benefits under such a legal relationship and the presence of remuneration. It was considered that there is an equivalence of benefits between the parties to the relationship in question, and that the actions taken by both parties are in the nature of mutual benefits. There is a direct legal relationship between the actions of the parties, as well as equivalence and reciprocity of benefits (payment of a fixed amount in cryptocurrency as part of the act of making a purchase of an NFT token of a specific value, and therefore for remuneration). In the opinion of the authority, such a transaction meets the criteria for the provision of services by the seller and thus qualifies for the taxation of such an activity (the object of which is the transfer of NFT to the buyer) with VAT.

    Thus, in this case, the pecuniary nature of the transaction was crucial. In contrast, the gratuitous transfer of NFT tokens could be treated differently. In an individual interpretation dated January 31, 2023 (No. 0113-KDIPT1-2.4012.751.2022.2.PRP), the Director of National Tax Information indicated that the activity of manufacturing and transferring NFT tokens free of charge to contractors who are participants in the loyalty program does not constitute an activity subject to VAT at all. This position, however favorable to the taxpayer, should be treated with caution. This is because it should be noted that, according to Article 8(2)(2) of the VAT Act, a gratuitous provision of services is also considered to be a gratuitous provision of services for the personal purposes of the taxpayer or his employees, including former employees, partners, shareholders, members of cooperatives and their household members, members of bodies of legal persons, members of associations, and any other gratuitous provision of services for purposes other than the taxpayer’s business activity. Therefore, in order for a gratuitous service to fall under the VAT exemption, it should serve the purposes of the taxpayer’s business activity, which may be difficult to demonstrate in some cases.

    If a service – what kind of service?

    Thus, in this case, the pecuniary nature was crucial

    From the standpoint of classifying NFT transactions for VAT purposes, it is important to determine what specific service such an activity constitutes. After all, if it is considered a financial service, it may be subject to VAT exemption.

    From this point of view, the important question is whether NFT can be considered a virtual currency or a financial instrument. In the first case, the classification of the service as exempt from VAT would come into play under Article 43(1)(7) of the VAT Law, in light of which transactions, including intermediation, involving currencies, banknotes and coins used as legal tender are exempt from VAT.

    The VAT exemption would also be based on the classification of NFT as a financial instrument. This is because according to Article 43 (1) (41) of the VAT Law, services the object of which are financial instruments, excluding their storage and management, and intermediary services in this regard are exempt.

    In this context, it is worth quoting the position expressed by the Director of National Fiscal Information in an individual interpretation dated October 7, 2022 (No. 0112-KDIL1-3.4012.279.2022.2.KK), in which the authority stated that if NFT does not constitute a virtual currency or a financial instrument, the transaction in its subject matter is not subject to VAT exemption.

    In conclusion, in most cases NFT does not constitute a virtual currency or a financial instrument, and therefore the transaction of such tokens is not subject to VAT exemption. However, in some cases, such a qualification of NFTs may be justified, in which case the subject exemption may apply.

    Summary

    As it turns out, the issue of VAT taxation of transactions on the subject of NFT tokens is not unambiguous and raises many doubts. Depending on the nature of the transaction, the specifics of the NFT in question and the regulatory approach, such a transaction may or may not constitute a VAT-taxable activity, and if it is taxable, it may or may not enjoy a VAT exemption. The final assessment in this regard is therefore determined by a number of variables, some of which are evaluative in nature.

    It can be assumed that with the development of the tokenization phenomenon, the emergence of various forms of NFT itself, and regulatory changes, these doubts will become more numerous. It is therefore advisable to consult a tax law specialist before engaging in NFT trading. In some cases, it may also make sense to obtain an individual interpretation to reduce tax risks.

    § VAT taxation of NFT transactions.

  • Can a doctor advertise?

    Can a doctor advertise?

    What is allowed to a doctor? Can you have your own brand of supplements and thus promote it on your practice’s website? What kind of content on Instagram can you post? §Can a doctor advertise?

    It should be noted that the legislator refers to the prohibition of advertising in a very general way. Article 63 of the Code of Medical Ethics indicates only that a doctor can form his professional opinion only on the basis of the results of his work, so any advertising is prohibited.  

    Importantly, Article 14(1) of the Law on Medical Activity states that: A healthcare provider shall make public information on the scope and types of healthcare services provided. The content and form of this information must not have the characteristics of advertising”.

    If you have more similar issues, remember that our law firm deals with Medical Law.

    It should be noted here that we distinguish between indirect and direct advertising, which is prohibited by the KEL and by the Law on Medical Activities.

    Indirect advertising it is used in messages to potential customers the procedure of using a distinctive sign, which is a symbol of a specific product, to distinguish another good, service, enterprise or specific activity;

    Direct advertising its purpose is to draw attention to specific services or goods and, consequently, to induce the potential recipient of the advertisement to use such service or purchase the goods,

    The Supreme Medical Council vs. advertising

    The Supreme Medical Council has tried to dispel doubts about permitted advertising in Resolution No. 29/11/VI of December 16, 2011 on detailed rules for making public information about the provision of health services by physicians and dentists.

    NRL indicated that the following data may be made public:professional title, first and last name,place, days and hours of admissions,type of professional practice performed,degree, scientific title,specialization,skills in narrower fields of medicine or the provision of specific health services, special authorizations,telephone number,determination of prices and method of payment in the case of providing this information by posting it on the website of the professional practice or through special information telephones.

    Please note that this information may be provided only through:no more than 2 permanent billboards outside the building in which the practice is carried out and, in addition, no more than 2 billboards along the access roads to the practice premises;newspaper advertisements in the sections on medical services;information contained in telephone directories and guides on medical services in the section on medical services;posting of information on websites;special information telephones;

    According to the Resolution, such information may not bear the characteristics of advertising, and in particular may not include:  any form of inducement or attempt to induce the use of health services;information about methods, their effectiveness and treatment time, as well as promises and colloquial terms;specifying prices and payment methods, except for specifying prices and payment methods when providing this information by posting it on the professional practice’s website or through special information telephones;information about the quality of medical equipment. Advertising by doctors is a topic that is often widely discussed, and it is very important to know what you can afford.

    If you have more contentious issues and Medical Law intervenes – come to us.

    §Can a doctor advertise? What to pay attention to when advertising doctors? We hope we have answered some important questions.

  • What criteria should be looked for in a product so that I can be a product for a cosmetic?

    What criteria should be looked for in a product so that I can be a product for a cosmetic?

    In practice, a fairly common problem is misclassification when marketing another consumer product as a cosmetic product. What criteria, according to the law, must a product meet in order to be considered a cosmetic?

    The basic action of a cosmetic must be in accordance with its definition, for example, skin lotion, whose primary action is bactericidal, cannot be classified as a cosmetic.

    In recent years, there has been a dynamic development of the cosmetics industry, and consequently, the number and availability of cosmetic products on the Polish market is constantly increasing. Cosmetics manufacturers, based on current trends, are outdoing themselves in creating more and more new formulas or product packaging to attract the consumer’s attention and encourage him to buy the product. It should be remembered, however, that both the composition and the declarations contained on the packaging of a cosmetic product must comply with the law and, above all, must not mislead the consumer.

    Not always, however, cosmetic products that reach the market are safe for consumers and the statements made on the cosmetic label are true. Importantly, the responsibility for the compliance of the product with the law is borne not only by the manufacturer, but in some cases also by the distributor.

    Irregularities in cosmetics labeling

    The report published in early June this year by the Office of Competition and Consumer Protection (OCCP) on the inspection conducted by the Trade Inspection shows that irregularities related to cosmetics labeling were detected in one in three stores and in the case of one in three tested cosmetics. The inspection was carried out at 295 entrepreneurs (at 276 retail stores and 19 wholesalers), and 119 of them were found to have irregularities.

    The most common irregularities were:

    – lack of information on the use of the product,

    – lack of a list of ingredients,

    – lack of a minimum shelf life date,

    – lack of marking in Polish.

    Some of the inspected products due to their composition and labeling (which suggested that they may be biocidal products) did not meet the definition of a cosmetic product.

    What is a cosmetic

    ProductIn practice, a fairly common problem is misclassification when marketing another consumer product as a cosmetic product. How a cosmetic product should be defined is determined by Regulation (EC) No. 1223/2009 of the European Parliament and of the Council of November 30, 2009.

    According to the aforementioned regulation, the term „cosmetic product” means any substance or mixture intended to come into contact with the external parts of the human body (epidermis, hair, nails, lips and external genitalia) or with the teeth and mucous membranes of the oral cavity, the sole or main purpose of which is to keep them clean, perfume them, change their appearance, protect them, keep them in good condition or correct body odor.

    Provided that, in classifying each such product, it must be individually evaluated, taking into account all of its characteristics¹. Products that do not meet the definition of a cosmetic product, or whose characteristics go beyond this definition, are not cosmetics, but products of another category (e.g., medical devices or biocidal products, or medicinal products depending on their scope of action).For a product to be considered a cosmetic, it must simultaneously meet the criteria in the above definition, i.e. its form, place and method of application must comply with the definition of a cosmetic product, while its form must not exceed this definition.

    The primary action of a cosmetic should comply with its definitionConsider whether the primary action of a cosmetic complies with its definition, e.g., a skin lotion whose primary action is bactericidal cannot be classified as a cosmetic. On the other hand, however, if the inhibitory effect of the liquid on the development of microorganisms had an additional function, in addition to the primary one, i.e. nurturing, then such a product could be classified as a cosmetic. A similar case was taken by the Regional Administrative Court in Lodz in a judgment dated 12/08/2021, ref. no. III SA/Łd 203/21. The case concerned „antibacterial soothing hand gel”, which, due to its composition and declaration on the label, was questioned as a cosmetic by representatives of the State District Sanitary Inspectorate. The WSA agreed with the authority’s position that the product, which, according to the label, is an „antibacterial soothing hand gel to ensure adequate levels of hand hygiene without the use of water,” containing 65% ethyl alcohol in its composition, should be classified as a biocidal product, since the suggested soothing effect is its secondary, additional function.

    In the era of the COVID-19 pandemic, when the demand for disinfectant products was enormous, guidelines² have been published on the European Commission’s website relating to claims that should not be used in the labeling of hydroalcoholic, no-rinse gels for hands, classified as cosmetic products. According to the aforementioned guidelines, such claims as antibacterial, antimicrobial, virucidal, disinfectant, kills X% of bacteria/viruses/microbes etc. should not be placed on such products. Additional information on cosmetics packaging – permissible, as long as it is not misleadingWith regard to the information placed on the label or packaging of a cosmetic product, manufacturers, in addition to the information imposed on them by law, are free to include any marketing information, provided that it does not mislead the consumer³. Otherwise, their action may be considered an unfair market practice.Distributors of cosmetics must check the correctness of the labeling on packagingAdditionally, certain obligations related to ensuring the compliance of a cosmetic product with the law are also incumbent on distributors. They are obliged to check that the product has all the legally required labeling and that its minimum shelf life⁴ has not expired. Ultimately, responsibility for any irregularities lies with the person who places the cosmetic product on the market or makes it available on the market; this can be either the distributor, importer or manufacturer of the cosmetic.

  • International Law and Cybersecurity – Regulations on Hacker Attacks and Data Protection

    International Law and Cybersecurity – Regulations on Hacker Attacks and Data Protection

    Cybersecurity has become one of the key challenges of the modern world. With the dynamic development of digital technologies, the number of cyberattacks threatening the security of states, companies, and private users is growing. In recent years, malware, attacks on critical infrastructure, and data breaches have caused massive economic losses and destabilization in various regions. But is international law prepared to face such challenges? Are there universal regulations that allow states to effectively counter cyber threats? In this article, we will analyze how international law regulates cybersecurity issues and what challenges the international legal community faces. § International Law and Cybersecurity – Regulations on Hacker Attacks and Data Protection

    International Law and Cybersecurity – Regulations on Hacker Attacks and Data Protection

    The Evolution of Cyber Threats and the Need for International Regulations

    Cyber threats have evolved in parallel with technological progress. The first computer viruses, such as the „Elk Cloner” in the 1980s, were more experimental in nature. Today, cybercrime has become a highly sophisticated activity, often supported by states or criminal organizations. Attacks such as Stuxnet, which damaged Iran’s nuclear program, demonstrate that cyberspace has become a new battlefield for global conflicts.

    With these changes came the need to establish legal frameworks to regulate activities in cyberspace. However, international law, originally designed to address physical conflicts, did not anticipate digital challenges. International organizations, such as the UN and NATO, have taken steps to fill this gap, but the adaptation process has been slow.

    One of the groundbreaking developments was the publication of the Tallinn Manual, developed by a group of NATO experts in 2013. This document serves as an interpretative guide to the application of the law of armed conflict in cyberspace. The manual recognizes that cyberattacks can be equivalent to the use of force if they cause damage similar to traditional armed actions, such as loss of life or destruction of infrastructure. However, the document is not legally binding, which limits its effectiveness.

    Another issue is the lack of consensus among states on the definitions of cyberspace and cyberattacks. For some, any unauthorized breach of an information system constitutes an attack, while others recognize only actions with serious consequences as such. Without shared standards, international cooperation in this area remains challenging.

    National and regional governments, however, are taking action. A notable example is the European Union, which introduced the NIS Directive (Network and Information Security) to improve cybersecurity in member states. It is worth noting, however, that regional regulations do not always translate into global cooperation, especially given the political differences among major players such as the US, China, and Russia.

    In conclusion, the evolution of cyber threats demands that international law dynamically adapts to the changing reality. While some steps have been taken, a more decisive and harmonized approach is needed that considers both the protection of individual rights and the security of states.

    Does International Law Cover Cyberattacks?

    One of the most debated topics in the context of cybersecurity is whether cyberattacks can be considered acts of aggression under the United Nations Charter. Article 2(4) of the Charter prohibits the use of force in international relations, but the interpretation of „force” in the context of cyberattacks remains controversial.

    The adoption of the Tallinn Manual by a group of NATO experts was a significant step toward regulating activities in cyberspace. While not legally binding, the document suggests that serious cyberattacks could violate international law if they cause effects similar to traditional armed actions, such as the destruction of critical infrastructure or loss of life. The manual also explores the thresholds at which cyber operations qualify as uses of force, threats to sovereignty, or violations of neutrality.

    However, the lack of a universally accepted definition of a „cyberattack” complicates matters. For some states, any unauthorized intrusion into their systems constitutes an attack, while others require substantial physical or economic damage to categorize an incident as such. These differing interpretations make it difficult to establish clear global norms.

    The applicability of Article 51 of the UN Charter, which grants states the right to self-defense, also raises questions. If a cyberattack causes widespread damage equivalent to a kinetic attack, can the affected state respond militarily? Some nations argue in favor of this interpretation, citing the increasing sophistication of cyber threats, but others caution against expanding the scope of self-defense in this manner.

    The lack of consensus has led to fragmented approaches. Some countries, like the United States, have taken unilateral measures to deter and respond to cyberattacks, including sanctions or even counterattacks. Others advocate for diplomatic resolutions, calling for treaties akin to arms control agreements for cyberspace.

    In summary, while international law does provide some frameworks for addressing cyberattacks, significant gaps remain. Clarifying how existing principles apply in the digital age is essential for ensuring global stability and fostering international cooperation.

    The Budapest Convention as a Foundation for Combating Cybercrime

    The Budapest Convention on Cybercrime, adopted in 2001, is the most comprehensive international treaty addressing cybercrime. It establishes standards for national legislation and promotes international cooperation in investigating and prosecuting cyber offenses such as hacking, phishing, and the distribution of malware.

    The convention serves as a legal framework for harmonizing criminal laws related to cyberspace. It requires signatory states to criminalize unauthorized access to computer systems, data interference, and computer-related fraud, among other offenses. Additionally, it facilitates cross-border investigations and evidence-sharing between law enforcement agencies.

    Despite its strengths, the convention has limitations. Its adoption is not universal; it has primarily been ratified by European countries and a few states outside Europe. Major players like Russia and China have not signed the treaty, arguing that it reflects Western interests and biases. They have instead pushed for alternative agreements under the framework of the Shanghai Cooperation Organization.

    Another challenge is that the convention was drafted in a pre-cloud era, meaning it does not fully address modern cybercrime techniques. While additional protocols have been proposed, adapting the treaty to contemporary realities remains an ongoing process.

    Nevertheless, the Budapest Convention has proven effective in fostering cooperation between member states. It has provided a platform for coordinated responses to global cyber threats, including high-profile incidents like ransomware attacks on critical infrastructure.

    To enhance its impact, efforts must be made to expand its adoption globally and update its provisions to address emerging threats. Only through collective action can the international community effectively combat the ever-evolving landscape of cybercrime.

    State Responsibility for Cyberattacks – International Accountability

    The question of state responsibility for cyberattacks is one of the most complex issues in international law. The difficulty in attributing cyberattacks to specific actors—referred to as the attribution problem—makes holding states accountable particularly challenging.

    Under the Draft Articles on Responsibility of States for Internationally Wrongful Acts, a state can be held liable for cyberattacks if:

    1. The attack was carried out by state agents.
    2. The state knowingly supported or failed to prevent cybercriminals operating from its territory.

    The 2014 cyberattack on Sony Pictures, allegedly orchestrated by North Korea, serves as a notable example. While the United States publicly attributed the attack to North Korea, it stopped short of imposing severe sanctions, highlighting the complexities of navigating state accountability in cyberspace.

    Attribution is further complicated by the use of proxy actors. States can indirectly sponsor or condone cyberattacks while denying involvement. This raises questions about the thresholds for accountability and the evidence required to prove state complicity.

    International law also struggles with the issue of proportional responses to cyberattacks. If a state is targeted by a significant cyber operation, what level of retaliation is permissible under international law? The lack of clear guidelines often leads to unilateral responses, increasing the risk of escalation.

    Developing mechanisms for transparent and reliable attribution, as well as establishing consensus on the responsibilities of states in cyberspace, is critical. Without these measures, international accountability for cyberattacks will remain elusive.

    International Cooperation on Data Protection

    In the era of globalization, protecting personal data across borders has become a pressing issue. High-profile data breaches, such as the exposure of millions of user accounts by major tech companies, underscore the need for robust international standards.

    The General Data Protection Regulation (GDPR), implemented by the European Union, is widely regarded as a gold standard for data protection. It establishes stringent requirements for data processing, mandates breach notifications, and provides individuals with extensive rights over their personal data. However, its extraterritorial application has sparked debates, particularly among non-EU states.

    Efforts to harmonize data protection globally face numerous challenges. Divergent legal systems and cultural attitudes toward privacy create obstacles to achieving a unified approach. For instance, the United States prioritizes business interests and national security, while the EU emphasizes individual rights. This divergence was evident in the collapse of the Privacy Shield agreement between the EU and the US, which aimed to regulate transatlantic data transfers.

    Emerging technologies, such as artificial intelligence and the Internet of Things, further complicate the landscape. These innovations generate vast amounts of data, often processed in jurisdictions with weak privacy protections. Strengthening international cooperation to address these issues is essential for safeguarding individuals’ rights.

    Initiatives such as the Global Privacy Assembly and regional agreements can serve as building blocks for a more coherent global framework. However, achieving this will require balancing competing interests and fostering trust between states.

    Cybersecurity and data protection have become critical issues in international law. While instruments such as the Budapest Convention and Tallinn Manual provide some guidance, significant gaps remain. Addressing these challenges requires enhanced international cooperation, the development of clear legal standards, and the willingness of states to work together to ensure stability in cyberspace. In a world where digital threats know no borders, the legal response must be equally swift and comprehensive.

    www.petlic.co

    § International Law and Cybersecurity – Regulations on Hacker Attacks and Data Protection