photo
17.09.2026

Data protection rules are not a burden, but an opportunity

On September 16, a conference titled “Breakthrough Technologies: 12 Months Later. Time for the Next Step” was held at the Presidential Palace. During the first panel, Mirosław Wróblewski, President of the Personal Data Protection Office, was among those who spoke at the invitation of the Chancellery of the President of the Republic of Poland. The discussion focused on where Poland might gain a competitive edge in the field of breakthrough technologies. The President of the Personal Data Protection Office pointed out that, on the one hand, EU regulations should be more understandable and consistent, but on the other hand, they should not be viewed merely as restrictions, but rather as a factor that enhances the quality of services and competitiveness.

The opening remarks were delivered by Paweł Szefernaker, Secretary of State and Chief of Staff to the President of the Republic of Poland; Adam Andruszkiewicz, Secretary of State and Deputy Head of the Chancellery of the President of the Republic of Poland; and Magdalena Hajduk, Advisor to the President of the Republic of Poland and Chair of the Council for New Technologies and Digitalization under the President of the Republic of Poland. Dr. Ireneusz Wochlik, who moderated the debate, noted that many Polish innovators are establishing companies in the United States. He asked whether this stems from concerns about regulations governing new technologies that are in force in Poland and the European Union. From the perspective of a regulatory body, are these regulations actually such a serious obstacle to development?

Mirosław Wróblewski pointed out that the best place to do business is determined not only by regulations but also by many other factors, such as access to capital, market size, scalability, access to talent, and the overall economic environment. Therefore, it cannot be said that the GDPR is the reason innovators are moving to the U.S. He added that Europe’s innovation potential is also limited by, among other things, the fragmentation of regulatory initiatives, the lack of consistent coordination in their implementation, and difficulties in scaling solutions across the entire EU.

The GDPR does not block technological development, but it does highlight the risks

The President of the Personal Data Protection Office  acknowledged that excessive regulation can be a barrier to business and technological development. However, this is not because the regulations protect human rights, but rather when entrepreneurs are uncertain about how they will be interpreted and enforced. As he emphasised, the GDPR itself does not prohibit the development of technology; rather, it is a technology-neutral regulation based on the principle of risk. It requires organizations to answer several fundamental questions before implementing new solutions: what data they intend to process, whether they actually need it, what risks it poses to individuals, how they will mitigate those risks, and whether the security measures in place reflect the current state of technical knowledge.

“That is precisely why, for example, the development of artificial intelligence does not conflict with data protection if we take data protection principles into account right from the design phase of a solution that uses new technologies—in accordance with the ‘privacy by design’ principle. The GDPR provides a solid foundation for data protection, even in the face of groundbreaking technologies, including quantum technologies,” said Mirosław Wróblewski.

And it is precisely quantum technologies that were used as an example to illustrate the above statement. This is because they significantly increase the risk of current data security measures—particularly data encryption—being cracked. The GDPR does not require an immediate change in infrastructure or the use of a specific algorithm. It merely obligates the data controller to respond appropriately to changes in cryptography and not to act as if technological progress had not occurred.

Regulations can improve competitiveness and the quality of services

Mirosław Wróblewski pointed out that data protection and security are not merely a cost. They can be an integral part of a product or service and can even contribute to its quality and competitive advantage. In a data-driven economy, it is important not only to convince customers that a service works, but also that they can safely enter their information into it.

“When we ensure data security, we also build trust in innovation. In sectors such as healthcare, finance, government, and advanced technologies in particular, it will not be possible to scale a solution if users do not trust it. That is why security and privacy by design should be viewed not only as a regulatory requirement, but as part of a product’s maturity.” – emphasised the President of the Personal Data Protection Office.

In addition to the President of the Personal Data Protection Office, the first panel discussion also featured: Eliza Kruczkowska from the European Innovation Council and the think tank The Company – TBC; Prof. Marcin Pawłowski; President Joanna Szczegielniak; Dr. Jerzy Ramert-Greblicki, Ph.D.; Paweł Wiszniewski, Deputy Director at the National Security Bureau; and Marlena Plebańska.