Krzysztof Podolski

CTO | Information Security Expert

M: +48 606 284 284  |  T: +48 22 380 33 44  |  E: [email protected]

I have over 20 years of professional experience in IT security, gained in both the private and public sectors. Throughout my career, I have been closely associated with the legal industry.

For six years, I served as an ICT Systems Administrator at the Chancellery of the President of the Republic of Poland, where I contributed to developing and implementing high-level information security standards and procedures designed to protect IT systems and personal data.

Since 2018, I have been advising RK RODO clients on ensuring the security of personal data processed within IT systems.

I am a Lead Auditor for ISO/IEC 27001, ISO/IEC 22301 and ISO/IEC 42001 – internationally recognised standards for Information Security Management Systems (ISMS), Business Continuity Management Systems (BCMS) and Artificial Intelligence Management Systems (AIMS).

My practice focuses on IT compliance audits under the GDPR, helping organisations identify security gaps and risks arising from non-compliance with implemented policies and procedures. I support legal teams in IT security assessments carried out as part of risk analyses and Data Protection Impact Assessments (DPIAs). I also advise on appropriate technical safeguards for international data transfers and conduct Transfer Impact Assessments (TIAs).

In addition, I develop information security policies and procedures tailored to clients’ IT environments, ensuring compliance with key regulatory and industry frameworks, including the GDPR, DORA, NIS2, ISO and NIST. I support clients and companies within the RK Legal Group in implementing organisational and technical measures to protect data covered by banking secrecy obligations. My advisory work also includes cloud security, ensuring compliance with the Polish Financial Supervision Authority’s (KNF) Cloud Communication, as well as supporting processor audits and the assessment and management of third-party vendors across the supply chain.

As part of the practical implementation of GDPR compliance programmes, I deliver employee training aimed at increasing awareness of personal data protection risks. I also conduct proprietary cybersecurity training sessions focused on recognising social engineering attacks and addressing the latest cybersecurity threats associated with the use of artificial intelligence.