Blog

  • International Law and Cybersecurity – Regulations on Hacker Attacks and Data Protection

    International Law and Cybersecurity – Regulations on Hacker Attacks and Data Protection

    Cybersecurity has become one of the key challenges of the modern world. With the dynamic development of digital technologies, the number of cyberattacks threatening the security of states, companies, and private users is growing. In recent years, malware, attacks on critical infrastructure, and data breaches have caused massive economic losses and destabilization in various regions. But is international law prepared to face such challenges? Are there universal regulations that allow states to effectively counter cyber threats? In this article, we will analyze how international law regulates cybersecurity issues and what challenges the international legal community faces. § International Law and Cybersecurity – Regulations on Hacker Attacks and Data Protection

    International Law and Cybersecurity – Regulations on Hacker Attacks and Data Protection

    The Evolution of Cyber Threats and the Need for International Regulations

    Cyber threats have evolved in parallel with technological progress. The first computer viruses, such as the „Elk Cloner” in the 1980s, were more experimental in nature. Today, cybercrime has become a highly sophisticated activity, often supported by states or criminal organizations. Attacks such as Stuxnet, which damaged Iran’s nuclear program, demonstrate that cyberspace has become a new battlefield for global conflicts.

    With these changes came the need to establish legal frameworks to regulate activities in cyberspace. However, international law, originally designed to address physical conflicts, did not anticipate digital challenges. International organizations, such as the UN and NATO, have taken steps to fill this gap, but the adaptation process has been slow.

    One of the groundbreaking developments was the publication of the Tallinn Manual, developed by a group of NATO experts in 2013. This document serves as an interpretative guide to the application of the law of armed conflict in cyberspace. The manual recognizes that cyberattacks can be equivalent to the use of force if they cause damage similar to traditional armed actions, such as loss of life or destruction of infrastructure. However, the document is not legally binding, which limits its effectiveness.

    Another issue is the lack of consensus among states on the definitions of cyberspace and cyberattacks. For some, any unauthorized breach of an information system constitutes an attack, while others recognize only actions with serious consequences as such. Without shared standards, international cooperation in this area remains challenging.

    National and regional governments, however, are taking action. A notable example is the European Union, which introduced the NIS Directive (Network and Information Security) to improve cybersecurity in member states. It is worth noting, however, that regional regulations do not always translate into global cooperation, especially given the political differences among major players such as the US, China, and Russia.

    In conclusion, the evolution of cyber threats demands that international law dynamically adapts to the changing reality. While some steps have been taken, a more decisive and harmonized approach is needed that considers both the protection of individual rights and the security of states.

    Does International Law Cover Cyberattacks?

    One of the most debated topics in the context of cybersecurity is whether cyberattacks can be considered acts of aggression under the United Nations Charter. Article 2(4) of the Charter prohibits the use of force in international relations, but the interpretation of „force” in the context of cyberattacks remains controversial.

    The adoption of the Tallinn Manual by a group of NATO experts was a significant step toward regulating activities in cyberspace. While not legally binding, the document suggests that serious cyberattacks could violate international law if they cause effects similar to traditional armed actions, such as the destruction of critical infrastructure or loss of life. The manual also explores the thresholds at which cyber operations qualify as uses of force, threats to sovereignty, or violations of neutrality.

    However, the lack of a universally accepted definition of a „cyberattack” complicates matters. For some states, any unauthorized intrusion into their systems constitutes an attack, while others require substantial physical or economic damage to categorize an incident as such. These differing interpretations make it difficult to establish clear global norms.

    The applicability of Article 51 of the UN Charter, which grants states the right to self-defense, also raises questions. If a cyberattack causes widespread damage equivalent to a kinetic attack, can the affected state respond militarily? Some nations argue in favor of this interpretation, citing the increasing sophistication of cyber threats, but others caution against expanding the scope of self-defense in this manner.

    The lack of consensus has led to fragmented approaches. Some countries, like the United States, have taken unilateral measures to deter and respond to cyberattacks, including sanctions or even counterattacks. Others advocate for diplomatic resolutions, calling for treaties akin to arms control agreements for cyberspace.

    In summary, while international law does provide some frameworks for addressing cyberattacks, significant gaps remain. Clarifying how existing principles apply in the digital age is essential for ensuring global stability and fostering international cooperation.

    The Budapest Convention as a Foundation for Combating Cybercrime

    The Budapest Convention on Cybercrime, adopted in 2001, is the most comprehensive international treaty addressing cybercrime. It establishes standards for national legislation and promotes international cooperation in investigating and prosecuting cyber offenses such as hacking, phishing, and the distribution of malware.

    The convention serves as a legal framework for harmonizing criminal laws related to cyberspace. It requires signatory states to criminalize unauthorized access to computer systems, data interference, and computer-related fraud, among other offenses. Additionally, it facilitates cross-border investigations and evidence-sharing between law enforcement agencies.

    Despite its strengths, the convention has limitations. Its adoption is not universal; it has primarily been ratified by European countries and a few states outside Europe. Major players like Russia and China have not signed the treaty, arguing that it reflects Western interests and biases. They have instead pushed for alternative agreements under the framework of the Shanghai Cooperation Organization.

    Another challenge is that the convention was drafted in a pre-cloud era, meaning it does not fully address modern cybercrime techniques. While additional protocols have been proposed, adapting the treaty to contemporary realities remains an ongoing process.

    Nevertheless, the Budapest Convention has proven effective in fostering cooperation between member states. It has provided a platform for coordinated responses to global cyber threats, including high-profile incidents like ransomware attacks on critical infrastructure.

    To enhance its impact, efforts must be made to expand its adoption globally and update its provisions to address emerging threats. Only through collective action can the international community effectively combat the ever-evolving landscape of cybercrime.

    State Responsibility for Cyberattacks – International Accountability

    The question of state responsibility for cyberattacks is one of the most complex issues in international law. The difficulty in attributing cyberattacks to specific actors—referred to as the attribution problem—makes holding states accountable particularly challenging.

    Under the Draft Articles on Responsibility of States for Internationally Wrongful Acts, a state can be held liable for cyberattacks if:

    1. The attack was carried out by state agents.
    2. The state knowingly supported or failed to prevent cybercriminals operating from its territory.

    The 2014 cyberattack on Sony Pictures, allegedly orchestrated by North Korea, serves as a notable example. While the United States publicly attributed the attack to North Korea, it stopped short of imposing severe sanctions, highlighting the complexities of navigating state accountability in cyberspace.

    Attribution is further complicated by the use of proxy actors. States can indirectly sponsor or condone cyberattacks while denying involvement. This raises questions about the thresholds for accountability and the evidence required to prove state complicity.

    International law also struggles with the issue of proportional responses to cyberattacks. If a state is targeted by a significant cyber operation, what level of retaliation is permissible under international law? The lack of clear guidelines often leads to unilateral responses, increasing the risk of escalation.

    Developing mechanisms for transparent and reliable attribution, as well as establishing consensus on the responsibilities of states in cyberspace, is critical. Without these measures, international accountability for cyberattacks will remain elusive.

    International Cooperation on Data Protection

    In the era of globalization, protecting personal data across borders has become a pressing issue. High-profile data breaches, such as the exposure of millions of user accounts by major tech companies, underscore the need for robust international standards.

    The General Data Protection Regulation (GDPR), implemented by the European Union, is widely regarded as a gold standard for data protection. It establishes stringent requirements for data processing, mandates breach notifications, and provides individuals with extensive rights over their personal data. However, its extraterritorial application has sparked debates, particularly among non-EU states.

    Efforts to harmonize data protection globally face numerous challenges. Divergent legal systems and cultural attitudes toward privacy create obstacles to achieving a unified approach. For instance, the United States prioritizes business interests and national security, while the EU emphasizes individual rights. This divergence was evident in the collapse of the Privacy Shield agreement between the EU and the US, which aimed to regulate transatlantic data transfers.

    Emerging technologies, such as artificial intelligence and the Internet of Things, further complicate the landscape. These innovations generate vast amounts of data, often processed in jurisdictions with weak privacy protections. Strengthening international cooperation to address these issues is essential for safeguarding individuals’ rights.

    Initiatives such as the Global Privacy Assembly and regional agreements can serve as building blocks for a more coherent global framework. However, achieving this will require balancing competing interests and fostering trust between states.

    Cybersecurity and data protection have become critical issues in international law. While instruments such as the Budapest Convention and Tallinn Manual provide some guidance, significant gaps remain. Addressing these challenges requires enhanced international cooperation, the development of clear legal standards, and the willingness of states to work together to ensure stability in cyberspace. In a world where digital threats know no borders, the legal response must be equally swift and comprehensive.

    www.petlic.co

    § International Law and Cybersecurity – Regulations on Hacker Attacks and Data Protection

  • Impact of the Omnibus Directive on Sellers in Polish E-commerce

    Impact of the Omnibus Directive on Sellers in Polish E-commerce

    The Omnibus Directive, introduced at the European Union level, marks a significant milestone in e-commerce regulation. In the context of the dynamic development of e-commerce and the digitization of the economy, unification and updating of regulations have become essential to create a consistent regulatory framework. The Omnibus Directive responds to these challenges by providing a comprehensive approach to regulating various aspects of e-commerce. Its main objective is to create a coherent and effective framework legislation that takes into account both the rights of consumers and the obligations of businesses in the area of e-commerce. § Impact of the Omnibus Directive on Sellers in Polish E-commerce.

    Impact of the Omnibus Directive on Sellers in Polish E-commerce

    The introduction of the Omnibus Directive has a huge impact on sellers operating in the Polish e-commerce market, changing the context of the legal environment in which they operate. Below we will discuss the key areas in which this directive affects e-commerce sellers in Poland:

    Consumer Rights Protection

    The Omnibus Directive introduces significant changes to the protection of consumer rights in e-commerce. Expanded consumer rights are designed to increase consumer confidence and trust when shopping online. One key element is the right to easy access to detailed information about products or services. Sellers must provide full and accurate descriptions of products, including their features, characteristics and technical parameters.

    Another important aspect is the extended cancellation period of up to 14 days without giving a reason. This right gives customers more flexibility and confidence, allowing them to carefully examine the product after receiving it. In the event of cancellation, the seller must refund all payments received from the customer, including delivery costs.

    In addition, the Omnibus Directive requires vendors to provide clear and transparent information on prices and fees. The final price, which is visible to the customer, must include any additional costs, such as delivery charges or taxes. This ensures that customers are not exposed to misunderstandings about hidden fees.

    Adjustment of Terms of Sale

    The introduction of the Omnibus Directive requires e-commerce sellers to adapt their terms of sale to the new regulations. They must ensure full transparency and availability of information regarding products or services. This includes accurate descriptions, specifications, technical parameters and information on the availability of goods. Sellers must also allow an easy and understandable ordering procedure and provide information on delivery costs and delivery times.

    One important aspect is also the protection of customers’ personal data. The Omnibus Directive introduces stricter requirements for the processing of personal data, which obliges vendors to use appropriate security measures to protect their customers’ data from unauthorized access or disclosure. Compliance with these regulations is key to avoiding data protection violations and potential financial penalties.

    Oversight of Internet Platforms

    The Omnibus Directive makes online platforms more accountable for the content and activities of vendors operating on their platforms. Platforms must actively monitor the content and activities of their users to eliminate illegal content, products or illegal activities. Implementing effective control and regulation mechanisms is becoming a priority for platforms, which must ensure that their vendors’ activities comply with the law.

    One of the main aspects of oversight is preventing the sale of fake or dangerous products. Platforms must effectively identify and remove such products and monitor the activities of their sellers to ensure compliance with the law. In addition, platforms must take action in the event of violations, including suspending or terminating the accounts of sellers who fail to comply with regulations.

    Adjusting Terms of Sale Polish e-commerce companies must adjust their terms and conditions.

    Adapting Terms of Sale Polish e-commerce companies must adapt their terms of sale to the new directive’s regulations. This includes ensuring transparency of information about products or services, the ordering process and delivery. Vendors must also pay special attention to customer data protection issues to meet the new security and privacy requirements. This means investing in the right tools and procedures to comply with these regulations.

    Increased Accountability


    The Omnibus Directive introduces significant changes to the liability of e-commerce sellers, imposing greater responsibilities and risks for malfunction or non-compliance. We will elaborate on the increased liability of e-commerce sellers below:

    1. Necessity of ComplianceThe Omnibus Directive requires e-commerce sellers to operate in full compliance with online sales regulations. This means that they must adapt their practices to the new requirements regarding consumer protection, product information, delivery, returns and complaints. Failure to comply with these obligations can lead to legal violations and penalties.

    2. Effective Customer ServiceE-commerce sellers must provide effective customer service, both in terms of orders and complaint handling. Customers need to feel confident that they can easily contact the vendor, get answers to questions and resolve any problems. Failure to provide adequate customer service can lead to negative reviews, loss of customers and loss of trust.

    3. Timely Delivery and Realistic Lead TimesThe directive requires vendors to ensure timely delivery of ordered products. They must deliver the products within the agreed time or in accordance with the contract with the customer. Untimely delivery can lead to dissatisfied customers and the need for returns.

    4. Data Security and PrivacyE-commerce sellers are now more responsible for the security and privacy of their customers’ personal information. They must use appropriate security measures to protect data from unauthorized access or disclosure. In the event of a data breach, merchants are required to notify customers of the incident and take corrective action.

    5. Effective Returns and Complaints ManagementVendors must effectively manage the returns and complaints process, ensuring that customers can file complaints and return goods in accordance with regulations. They must process complaints in a timely manner and provide customers with appropriate solutions, such as refunds or product replacements.

    Summary

    In summary, the Omnibus Directive introduces significant changes to e-commerce regulations that are designed to increase consumer protection and improve e-commerce standards. E-commerce sellers in Poland must be prepared to comply with the new regulations, which requires investment in adjusting procedures, ensuring legal compliance and providing excellent customer service. Compliance with the Omnibus Directive is not only a legal obligation, but also an opportunity to increase customer confidence and succeed in a dynamic e-commerce environment. At the same time, retailers need to be aware of possible changes in the regulations and adapt their operations to the new guidelines in order to maintain their competitiveness in the market. It is also worth noting that these changes are a step towards a more sustainable and secure e-commerce environment, which can benefit both customers and businesses in the industry.

    § Impact of the Omnibus Directive on Sellers in Polish E-commerce

    www.petlic.co

  • Corporate Mergers And Acquisitions – What Are The Differences Between Them

    Corporate Mergers And Acquisitions – What Are The Differences Between Them

    Dynamic changes in the economy force companies to flexibly adapt to the ever-changing situation. One way to grow and expand into new markets is to acquire other companies in order to gain their customers, acquire the technologies they use or take advantage of the good market position they have achieved in further areas. Merging with competitors to take advantage of synergies, reduce costs, improve profitability and gain greater market share is also a way to expand the reach and size of the business. In addition to their economic dimension, both mergers and acquisitions also produce certain legal effects. While the business objectives of strengthening a company making an acquisition or merging with another company may be similar, the mechanism of action and legal consequences will be quite different. CORPORATE MERGERS AND ACQUISITIONS – WHAT ARE THE DIFFERENCES BETWEEN THEM?

    Share deal and asset deal acquisitions


    Acquisition of another company in light of the current Polish economic reality is connected with the acquisition of such a number of its shares or stocks that allows the acquisition of a sufficient number of votes at the general meeting of shareholders in the case of a joint stock company or at the meeting of shareholders in a limited liability company. This makes it possible to gain the ability to shape the business conducted by the acquired company by filling positions on the board of directors and appointing members to the supervisory board or the audit committee. An acquisition of this type is known as a share deal.

    Another option is the acquisition of a business, the so-called assets deal. In this case, the acquiring company buys the assets belonging to the acquired company, while its liabilities remain with it. In acquisitions involving the purchase of an enterprise or a specific part of it, such as a branch, only those rights and obligations are transferred to the buyer that connect to the assets that are the subject of the contract being concluded.

    The purchaser of an enterprise taking it over under an assets deal is liable for the obligations incumbent on it in the same way as on the transferor, but the former is burdened with them only up to the amount of the assets taken over.

    In a takeover by purchase of a company, the burdens associated with the employees of the acquired company are transferred to the acquirer, unless the subject of the agreement is a separated part of the company. In that case, the liability of the acquirer and the transferor of the company is joint and several.

    Corporate mergers


    In a merger, a situation occurs in which a capital company incorporates another company into its organizational structure, which entails the termination of its legal existence. In such a situation, the shareholders or stockholders of the absorbed company may receive shares or stock in the merging company. The procedure can also be carried out in another way, in which case a new capital company is formed from both entities, and the merging companies end their existence.

    The condition for carrying out the merger is that the companies that carry out the merger function in the form of a corporation or partnership, but the entity that will remain after the whole procedure is carried out will be a capital company. The entity remaining as a result of the merger enters into all the rights of the absorbed company or both merging companies, becoming their legal successor.

    This also applies to matters relating to employees employed by the companies involved in the merger. As soon as the procedure is carried out, they become employees of the newly formed company or the company that absorbed the other company, employed under the existing conditions.

    Selected restrictions on mergers and acquisitions


    Conducting mergers and acquisitions has its limitations. They involve, among other things, concentration laws, regulations related to foreigners and provisions related to agricultural land. According to these, for entities that have or may obtain a dominant position as a result of a merger or acquisition, they must request permission from the President of the Office of Competition and Consumer Protection. This obligation, however, applies only to entities that in the previous fiscal year exceeded a turnover of €50 million, in the case of operating solely on the domestic market, or €1 billion when operating on the international market.

    Under current regulations, in the case of a takeover of a company that owns agricultural land or shares in a company that owns agricultural land, it is only possible after the right of first refusal is waived by the Agricultural Property Agency. This does not apply only to agricultural properties of less than 0.3 hectares or publicly traded companies.

    Restrictions on foreigners stem from provisions that exclude the possibility of a foreigner acquiring property located in Poland without the approval of the Ministry of Internal Affairs. This provision does not apply to companies and citizens of the European Economic Area, i.e. the countries of the European Union, as well as Iceland, Norway and Liechtenstein and Switzerland. The regulations on foreigners also do not apply to publicly traded companies and real estate not exceeding 0.4 hectares.

  • Construction Law – big changes to come in 2023

    Construction Law – big changes to come in 2023


    Several changes to the Construction Law were enacted this year, which will take effect on January 1 and 27 and April 28, 2023. They were introduced by the laws published in the Official Gazette under items 1557 and 2206. The changes that will come into force in 2023 mainly concern the construction site book and the construction log, which will be kept in electronic form.

    Construction Law 2023 – when the changes will take effect

    There will be quite a few changes to the Construction Law in 2023. In addition to those already enacted, changes introduced by the Law on Amendments to the Law – Construction Law and Certain Other Laws (hereafter I will refer to it as the Amending Law) will take effect. This Amending Law, is expected to amend not only the Construction Law, but also several other laws. For example, another Law Amending the Construction Law (Journal of Laws No. 1557), which was recently passed and is scheduled to come into force on January 1 and 27.


    Legislative work on the amending law has not yet been completed. The draft law is after opinions, consultations and public consultations, which were conducted in October and lasted an exceptionally short period of only 7 days. As I prepare this text, the draft law of November 16, 2022 is available on the pages of the Government Legislation Center, and this text is based on that draft.


    The amending law, although it hasn’t even made it to the Diet yet, is to come into force on January 1, 2023, with the exception of a dozen (yes – as many as a dozen) amendments, which are to come into force on January 27, 2023, June 30, 2023, 6 months and 9 months after promulgation, as well as „as of the date of implementation of appropriate technical solutions enabling the authorities and entities indicated in the communication to conduct proceedings through the System for Handling Administrative Proceedings in Construction, as specified in the communications referred to in Article 28.”


    As you can see, the legislature is not making life easy for participants in the construction process, once again making last-minute changes and setting so many different effective dates for the various regulations.


    What changes to the construction law in 2023 are likely to come into effect


    Below is a selection (subjective choice) of the planned changes to the construction law in 2023. As I mentioned – the legislative process has not been completed, so there is not yet 100% certainty that these changes in this form will be enacted and will come into force.


    If the planned changes to the construction law in 2023 come into force, then:

    – all applications, notifications and notifications with attachments will be submitted only in electronic form. This will not apply only to construction projects in closed areas;
    – there will be definitions of: technical assessment and technical expertise;
    – as an independent technical function in construction, the performance of construction appraisal will return;
    – there will also be a second new independent technical function in construction – the preparation of technical studies on construction objects, in particular: technical assessments, and technical expertise;
    – construction authorization in the relevant specialty will entitle the holder to prepare technical assessments within the scope of that specialty;
    – technical expertise will only be able to be prepared by a construction expert. This is to include expert reports required for expansions, additions, remodeling and changes in use;
    – people who have graduated from a technical school in an industry relevant to a particular specialty will be able to obtain construction authorizations to design to a limited extent, but they will be required to complete a longer apprenticeship than those with a university degree – four years in drafting projects and one year in construction;
    – construction authorizations in architectural specialization in a limited scope will entitle to design or direct construction works:
    – in the case of persons holding the professional title of magister inżynier, magister inżynier architekt, engineer or engineer architect with respect to the architecture of a building with a volume of up to 1000 m3,
    – in the case of persons holding a professional title of a technician or a professional diploma or a diploma confirming professional qualifications in a profession taught at the level of a technician with regard to the architecture of a structure with a cubic capacity of up to 1000 m3 in a homestead development or in a homestead development area;
    – the catalog of objects and construction works that do not require a permit will be significantly expanded. For example, by single-family houses with a building area of more than 70 m2 (there will be a total of 3 different procedures for the construction of single-family houses without a permit – not a bad „convenience”);
    – construction of up to 100 m of mains will be possible without a permit and without notification – after meeting additional conditions, i.e., among other things, drawing up a situation plan on a copy of a current base map or unit map accepted into the state geodetic and cartographic resource;
    – notification of buildings and shelters related to agricultural production with a construction area of up to 300 sqm and backyard shelters (such structures will be allowed to be built upon notification) will have to be accompanied by „technical documentation” (or more precisely, as the draft law indicates: „technical documentation containing solutions to ensure the load-bearing capacity and stability of the structure, safety of people and property, and fire safety, the scope and content of which should be adapted to the specificity and nature of the object and the degree of complexity of the construction work, made by a designer with the appropriate construction authorization”) – the legislator thus introduces a new type of documentation, which is not really known what it is supposed to contain (because the law does not specify it) and probably each office will have different requirements in this regard. I don’t know why the legislator is doing this, but with the facilitation of the construction process, it has nothing to do, because you could use the regulations that are already in place for the notification of these objects;
    – the construction project will have to be drawn up in electronic form;
    – architectural and construction administration authorities in proceedings for a construction permit will not check the development design of a plot or land for compliance with technical and construction regulations;
    – the time limit, the exceeding of which when issuing construction permits results in a financial penalty for the authority, will be shortened. Instead of 65 days, there will be 21 days (if the investor is the only party to the proceedings) or 45 days (if there are other parties than the investor);
    – a Database of Construction Projects will be created – instead of attaching projects to applications, notifications or notices, the investor will be able to indicate the individual number of the project that has been placed (by the investor or designer, for example) in the Database;
    – in the case of illegal significant deviations from the design documentation, the construction supervision authority, before initiating corrective proceedings, will be able to instruct (by making an entry in the inspection protocol and in the construction log) the investor that the construction work should be brought within 60 days to a state consistent with the arrangements and conditions set forth in the decision on the construction permit, the plot or land development project or the architectural and construction design or the regulations;

    – almost all objects will be able to be used after notification of the completion of construction (if the construction supervision authority does not raise objections within 14 days);
    – use of single-family residential buildings and facilities classified as category III and built on the basis of a construction permit decision will be allowed upon submission by the construction manager of a statement on the completion of construction and the possibility of using the facility. It will also be indicated in which cases the construction manager may submit a statement on the completion of construction and the possibility of proceeding to use. Within 14 days from the date of commencement of use, the developer will notify supervision of the commencement of use;
    – a System for the Processing of Administrative Proceedings in Construction (SOPAB) will be established.

  • Changes to the Labor Code: new mandatory elements of the employment contract and expanded information obligations of the employer.

    Changes to the Labor Code: new mandatory elements of the employment contract and expanded information obligations of the employer.


    The government’s bill to amend the Labor Code and certain other laws, aimed at implementing into Polish legislation the solutions provided for in EU directives, may significantly affect employees’ rights and, correlating with them, employers’ obligations. Among other things, the amendment provides for the expansion of rights related to parenthood, including through the extension of parental leaves (in the spirit of work-life balance), as well as revolutionary changes regarding the termination of employment contracts. Aiming to achieve the greatest possible transparency and predictability in employment – it also modifies the mandatory elements of the employment contract and significantly affects (expands) the employer’s information obligations towards the employee.

    Employment contract


    The draft amendment clarifies and expands the catalog of mandatory elements of the employment contract. It assumes that – specifying the parties to the contract – it is mandatory to indicate the address of the employer’s registered office, and in the case of an employer who is a natural person without a registered office – the place of residence. In principle, this change should be considered a reflection of established practice in the law – since the precise definition of both parties to the employment relationship is a market standard.

    With regard to fixed-term contracts – probationary and fixed-term – the draft further provides for the obligation to indicate explicitly their duration or the date of their termination. This change should also be seen in terms of sanctioning the already existing state of affairs – employment contracts of this type in practice contain provisions precisely indicating their duration.

    In the case of a contract of employment for a trial period, in connection with the amendment of the provisions regulating this type of contract, it is also to become mandatory to include provisions on:

    -the extension of the contract for the period of vacation, as well as for the period of other excused absence of the employee from work, if such absences occur;
    -the period for which the parties intend to conclude a fixed-term employment contract – if this period determines the permissible length of the probationary period (which, under the proposed regulations, is to be a maximum of 1 month if the intention is to subsequently conclude a fixed-term contract for a period of less than 6 months, or 2 months if the intention is to conclude such a contract for a period of less than 12 months);
    extension of the contract concluded, in connection with the above-mentioned regulations, for a period of 1 or 2 months in case it is justified by the type of work.

    Additional information related to employment


    What should be considered revolutionary, however, is the change proposed in the amendment regarding the scope of mandatory additional information related to employment, which the employer is obliged to provide to the employee within 7 days (according to the draft amendment – from the date the employee is admitted to work, while currently – from the date the employment contract is concluded). According to the current legislation, it should include information on:

    -the daily and weekly working time norms applicable to the employee;
    -The frequency of payment of remuneration for work;
    -the amount of vacation leave to which the employee is entitled;
    -the applicable length of the notice period of the employment contract; and
    -collective bargaining agreements to which the employee is covered.

    In addition, if the employer is not required to establish work regulations, the supplementary information must also include information on night time; the place, date and time of payment of wages; and the method adopted by employees to confirm their arrival and attendance at work and justify their absence from work. In practice, the document prepared to implement the obligation to provide the employee with the above-mentioned information is usually one-page. In turn, the ratio legis of covering the above-mentioned elements with such – one-sided – information, is due to the organizational nature of its elements. In view of this nature, it is reasonable for the employer to have the discretion to shape them freely (but within the limits of the law).  Employees, in turn, should be (and are) secure in their ability to obtain knowledge of them. However, as far as these elements are not regulated in the employment contract, their consent to modify them is not necessary.

    According to the bill, the additional information – in addition to or in place of some of the elements listed above – is to include information about:

    -The breaks to which an employee is entitled;
    -the daily and weekly rest to which an employee is entitled;
    -rules regarding overtime work and compensation for it;
    -in the case of shift work – the rules on moving from shift to shift;
    -in the case of more than one place of work – rules regarding movement between places of work;
    -components of remuneration and benefits in cash or in kind other than those specified in the employment contract;
    -the amount of paid leave to which the employee is entitled, in particular vacation leave or, if it is not possible to determine it at the date of providing the employee with this information, the procedures for granting and determining it;
    -the applicable procedure for termination of the employment relationship, including the formal requirements, the length of notice periods and the time limit for appeal to the labor court or, if it is not possible to determine the length of notice periods on the date of providing the employee with this information, the method of determining such notice periods;
    -the employee’s right to training, if the employer provides it, in particular the general principles of the employer’s training policy; and
    the collective bargaining agreement or other collective agreement to which the employee is covered, and, if a collective agreement is concluded outside the workplace by joint bodies or institutions, the name of such bodies or institutions.

    Any changes in the elements covered by the supplementary information should be communicated to employees immediately.

    Following the proposed changes, employment-related supplementary information will take the form of an often multi-page and sometimes complicated document. What’s more – since the elements it covers may change regularly, each time it is modified, it will create an obligation on the part of the employer to provide employees with an updated version of it. This, in turn, will generate additional and, it seems, unjustified bureaucracy at workplaces.

    Moreover, according to the draft amendment law, in the case of employment contracts in force on the date of its entry into force, the employer will be obliged – at the request of the employee – to appropriately supplement (update) the additional information used by him within 3 months of the date of the employee’s request.

    There is also to be an obligation on employers to inform employees, no later than within 30 days from the date of admission to work, of the name of the social security institution to which social security contributions related to the employment relationship are paid and of the social security-related protection provided by the employer, as well as of any change in the address of the employer’s headquarters or residence – in this case, no later than within 7 days.

    Information obligations related to the referral of an employee abroad
    The proposed legislative changes also concern obligations related to the referral of an employee abroad. The legislator, on the one hand, aims to extend the information obligations introduced in the Labor Code also to cases where an employee goes to work or to perform a business task to a country that is a member of the European Union (and not only to a country outside the European Union), and, on the other hand, to modify and expand the catalog of information provided to the employee.

    According to the amendment, if an employee is sent abroad for a period exceeding 4 consecutive weeks, the employer will be obliged to provide him with information in advance about:

    -the country or countries in which the work or business task abroad is to be performed;
    -the expected duration of this work or business task;
    -the currency in which the employee will be paid while performing the work or business task abroad;
    -monetary or in-kind benefits related to the performance of the work or business task abroad, where such benefits are provided for in the labor law unless this is provided for in the employment contract;
    -the provision or lack of provision for the return of the employee to the country;
    -the conditions for the employee’s return to the country – where such return is provided for.

    In addition, notwithstanding the aforementioned, as well as the elements covered by the employment-related supplementary information, before posting an employee to work in another member state for a period exceeding 4 consecutive weeks, the employer is to be required to inform the employee of:

    -labor remuneration payable under the law of the member state in the territory of which the employee is posted;
    -the posting allowance or regulations on the reimbursement of expenses for travel, food and accommodation, where such benefits are provided for by labor laws, provisions of regulations, statutes, collective bargaining agreements or other collective agreements, or receivables for expenses related to business travel;
    -a link to the official website, maintained by the Member State in whose territory the worker has been posted, containing information on the terms and conditions of employment that must be applied to posted workers.

    As a general rule, the employer will be obliged to inform the employee of any change regarding the aforementioned elements immediately, but no later than the effective date of the change.

    As in the case of additional information related to employment, in the case of employment contracts in progress on the date of entry into force of the amending law, the employer will be required – at the request of the employee – to provide information covering all of the aforementioned elements within 3 months from the date of the employee’s request.

  • Can the IT license agreement be replaced by a lease agreement?

    Can the IT license agreement be replaced by a lease agreement?

    The onerousness of the copyright regulation of the license agreement is leading to further attempts by IT companies to break out of these shackles by their legal services.

    In particular, there has been a demand to apply the regulation of the lease of a thing (Article 659 § 1 of the Civil Code) directly to an object that is not a thing, i.e. software.

    In fact, this required at least partial identification of software with its copy. Aside from the narrow issue of so-called marketing, however, this still seems unacceptable.

    Moreover, it required drawing an overly far-reaching conclusion about the possibility of software leases from the mere coincidence of the concept of „lease” in defining the field of exploitation in the form of a lease of a copy and in the named contract of the Civil Code. However, these issues are separate and completely different and cannot be equated in this way. A field of exploitation is a field of exploitation, and a contract is a contract.

    It also seems to be going too far to conclude that it would be permissible to conclude software lease agreements due to the sheer significant discrepancies in copyright law doctrine with regard to the possible application of the contract provisions of sections of the Copyright Act to lease and use agreements.

    It turns out, moreover, that having constructed, in extensive and based on rich professional literature and extremely interesting case law, the entire model of a software lease agreement, the authors allow, however, to refer to it only in the contractual provisions „in addition to the provisions providing for the granting of a license to the ordering party” or in a salvatory clause.

    As a result, it seems that such a narrow, and in fact also very unclear as to the exact scope, admission of the use of a software lease agreement has little practical application. As it seems, therefore, the work done by the authors themselves has led to the exclusion of the use of a software lease agreement (which is a pertinent conclusion!), rather than to the confirmation of such a possibility.

    As can be seen from this, IT companies remain basically „condemned” to right-author licenses, since the conclusion of a software lease agreement can also give rise to difficulties.

  • Can a doctor advertise?

    Can a doctor advertise?

    What is allowed to a doctor? Can you have your own brand of supplements and thus promote it on your practice’s website? What kind of content on Instagram can you post? §Can a doctor advertise?

    It should be noted that the legislator refers to the prohibition of advertising in a very general way. Article 63 of the Code of Medical Ethics indicates only that a doctor can form his professional opinion only on the basis of the results of his work, so any advertising is prohibited.  

    Importantly, Article 14(1) of the Law on Medical Activity states that: A healthcare provider shall make public information on the scope and types of healthcare services provided. The content and form of this information must not have the characteristics of advertising”.

    If you have more similar issues, remember that our law firm deals with Medical Law.

    It should be noted here that we distinguish between indirect and direct advertising, which is prohibited by the KEL and by the Law on Medical Activities.

    Indirect advertising it is used in messages to potential customers the procedure of using a distinctive sign, which is a symbol of a specific product, to distinguish another good, service, enterprise or specific activity;

    Direct advertising its purpose is to draw attention to specific services or goods and, consequently, to induce the potential recipient of the advertisement to use such service or purchase the goods,

    The Supreme Medical Council vs. advertising

    The Supreme Medical Council has tried to dispel doubts about permitted advertising in Resolution No. 29/11/VI of December 16, 2011 on detailed rules for making public information about the provision of health services by physicians and dentists.

    NRL indicated that the following data may be made public:professional title, first and last name,place, days and hours of admissions,type of professional practice performed,degree, scientific title,specialization,skills in narrower fields of medicine or the provision of specific health services, special authorizations,telephone number,determination of prices and method of payment in the case of providing this information by posting it on the website of the professional practice or through special information telephones.

    Please note that this information may be provided only through:no more than 2 permanent billboards outside the building in which the practice is carried out and, in addition, no more than 2 billboards along the access roads to the practice premises;newspaper advertisements in the sections on medical services;information contained in telephone directories and guides on medical services in the section on medical services;posting of information on websites;special information telephones;

    According to the Resolution, such information may not bear the characteristics of advertising, and in particular may not include:  any form of inducement or attempt to induce the use of health services;information about methods, their effectiveness and treatment time, as well as promises and colloquial terms;specifying prices and payment methods, except for specifying prices and payment methods when providing this information by posting it on the professional practice’s website or through special information telephones;information about the quality of medical equipment. Advertising by doctors is a topic that is often widely discussed, and it is very important to know what you can afford.

    If you have more contentious issues and Medical Law intervenes – come to us.

    §Can a doctor advertise? What to pay attention to when advertising doctors? We hope we have answered some important questions.

  • Artificial intelligence and legislation

    Artificial intelligence and legislation

    In today’s world of technology and computing, artificial intelligence (AI) is undeniably one of the most important areas of development. However, with its advancement, a number of challenges arise, especially in the regulatory contextin Poland. § Artificial intelligence and regulation

     

    One of the main challenges associated with AI is the issue of liability. As AI-based systems become increasingly autonomous, the question arises as to whois liable for any errors or damage caused by these systems. Is it the AI provider, the user or perhaps the algorithm itself? Polish legislation faces the task of resolving these questions in a clear and fair manner.

     

    Poland has laws regulating some aspects of artificial intelligence. One of the key pieces of legislation in this context is the Government bill on artificial intelligence, which aims to regulate issues related to the responsibility, ethics and safety of AI. This bill also focuses on the protection of the rights of consumers using AI-based services and safeguards against discrimination resulting from the use of this technology.

     

    Mention should also be made of the General Data Protection Regulation(GDPR), which is relevant to data processing using AI. The provisions of the RODO require organizations to ensure compliance with data protection regulations when using AI.

     

    In addition, Poland must also align its laws with European Union directives, whichintroduce general rules on ethics, transparency and accountability related toAI. Actions at the EU level influence the formation of national regulations.

     

    It is worthnoting that AI regulations in Poland are still being developed and adapted tochanging technological realities. For people and companies operating in the field of AI, monitoring and adapting to regulations is crucial. At the same time, these regulations are designed to ensure that evolving AI technology isused ethically, safely and with respect for the rights and values ofindividuals.

     

    Legislationon artificial intelligence (AI) in Poland and the European Union

    1.     Artificial Intelligence (AI) Draft Law: The AI bill is a government initiative to regulate many aspects of AI in Poland.The bill’s provisions cover issues such as:

    –      Liability:The draft introduces rules on liability for damages caused by AI. It specifies that an AI provider can be held liable for defects in an AI product, whichincludes errors in algorithms.

    –      Ethics:The draft imposes an obligation to create and use AI with respect for ethics,human dignity and human rights.Provides protection against the use of AI for purposes that violate human rights.

    –      Consumer Protection: The provisions of the draft are aimed at protecting consumers whouse AI-based services. Provides them with access to information about AIoperations and the right to seek redress in the event of damage.

    2.     General Data Protection Regulation (RODO): The RODO is a key piece of legislation in the context of AI, as itregulates the processing of personal data. Companies and organizations using AI must comply with the provisions of RODO regarding the collection, storage and processing of personal data.

    3.     European Union AI Directive: The European Union is developing an AI directive to ensure that developing AItechnology is in line with European values and principles. The directive isexpected to focus on the ethics, accountability and transparency of AI.

    4.      Consumer Rights Directive: AI regulations affect consumer rights, especially in the context of services based on this technology. The Consumer Rights Directive regulates consumers’ rights toinformation and protection against unfair practices.

    5.     Copyright and Intellectual Property:Copyright and intellectual property issues in the context of the creation and use of AI algorithms are governed by copyright and patent laws. Protecting the results of work on algorithms is important, both for creators and users of AI.

    6.     Civil Code: The provisions of the Civil Code may be applied in cases of AI-related violations, especially insituations where there is damage resulting from the operation of AI.

    7.     Criminal Code: In cases of AI-related legal violations, the provisions of the Criminal Code may also be applied, especially in cases of cybercrime, privacy violations or fraud using AI.

    Artificial intelligence (AI) regulations in Poland and the European Union are an increasingly important part of law and technology. As AI develops and becomes more widely used, appropriate regulations become crucial to ensure that thiscutting-edge technology is used ethically, safely and with respect for therights of individuals.

     

    The draft law on AI in Poland focuses on key issues such as liability, ethics and consumer protection. It introduces liability rules for damage caused by AI, and imposes an obligation to create and use AI with respect for ethics and humanrights.

     

    The General Data Protection Regulation (GDPR) plays an important role in the context of AI,as it regulates the processing of personal data, which is often an integralpart of AI-based solutions.

     

    The European Union is also working on an AI directive to ensure that AI technologies comply with European values and standards.

     

    Copyright, intellectual property, and civil and criminal codes also affect AI issues and can be applied in cases of infringement or litigation.

     

    All of these laws provide a legal framework to ensure that evolving AI technology serves society and the economy while respecting the rights and values of individuals. For companies and organizations using AI, compliance with these regulations is not only a matter of legality, but also a matter of building user and customer trust and maintaining an ethical approach to the technology. As AI continues to evolve, monitoring and adapting to changing regulations becomes essential to operate in a manner that complies with current regulations and contributes to technological development in a responsible manner.

     

    § Artificial intelligence and legislation

    www.petlic.co