Cybersecurity and Data Protection

Катерина Дубас Legal IT Group
Kateryna Dubas
Head of Privacy and Cybersecurity Practices
Send a request
Cybersecurity Lawyers. Legal Services in Cybersecurity
Юристи в сфері кібербезпеки
icon

About the Industry

Legal Challenges in Cybersecurity

Cybersecurity has become part of everyday business operations due to digitalisation and the democratisation of AI-powered services. Information security covers every aspect of a company’s operations — from cameras and access control systems at the office entrance to long-term non-disclosure obligations imposed on employees who have moved to other companies.
Companies of all sizes and across all industries must prioritise cybersecurity and respond even to seemingly minor incidents. A data leak, an unauthorised presence within corporate networks, an accidentally connected USB drive, or employees discussing current projects with acquaintances — any of these factors can put information and personal data protection systems to the test.

Postponing security is a luxury no business can afford in an era when AI agent tools are available to people who make a living by identifying and exploiting vulnerabilities. Although demand for protection is growing, the market still lacks accessible expertise of the required standard. Moreover, cybersecurity has evolved from a business best practice into a legal obligation.
It is therefore important that your compliance programme can withstand the challenges created by the convergence of technical and legal cybersecurity measures.

  • Risks and Consequences of Personal Data Loss

    GDPR compliance is not limited to a Privacy Policy: the security system must also be assessed.
    01
  • Theft of Know-How, Expertise, and Work Materials

    Security measures may conflict with employees’ privacy rights.
    02
  • Shadow IT and Negligence Regarding Security Measure

    Disciplinary action and contractual liability for negligence are common concerns.
    03
  • Competitive Intelligence and Unfair Competition

    Businesses should invest in developing a strategy, conducting risk assessments, and preparing for rapid action.
    04
  • Consequences of Attacks on Partners and Contractors — Supply Chain Attacks

    Failure to include vendors and business partners in risk assessments prevents companies from evaluating the actual level of danger.
    05
  • Audits by Regulators and Business Partners — Vendor Assessments

    It is important to prepare in advance so that an audit does not disrupt normal business operations.
    06
  • Ability to Export and Sell Technologies

    Special export and customs clearance procedures, as well as sanctions lists, are common business blockers.
    07
  • Requests for Information from Public Authorities

    It is important to have a strategy for disclosing information in response to different types of requests.
    08
  • Interference with the Privacy of Employees and Third Parties

    Employee monitoring and whistleblowing schemes may create additional risks instead of mitigating them.
    09
  • Lack of Crisis Preparedness

    An inability to restore all or part of the company’s operations quickly in the event of an attack or force majeure.
    10

We Work Systematically with Cybersecurity Service Providers and Organisations Building Their Own Information Security Systems


title_icon

Our Services

  • GDPR Cybersecurity Requirements

    Articles 25 and 32 and other requirements, including privacy by design and by default
  • HIPAA Compliance

    The Security Rule, Privacy Rule, and other requirements
  • Cyber Resilience Act (CRA) і NIS2

    Applicability analysis, documentation, roadmaps, and ongoing support
  • AI Act, Data Act compliance

    Audits, documentation, and implementation support
  • Data Breach Response

    Incident analysis and classification, notifications, and communications
  • Interaction with the State Service of Special Communications and Information Protection of Ukraine

    Legal support in interactions with the regulator regarding access to data in Ukraine
  • Compliance with State Registry Requirements

    Legal support throughout the process of connecting to state registries
  • Support with Comprehensive Information Protection System and Technical Information Protection Certification

    Communications, documentation, and coordination with the parties involved
  • Security Documentation

    We prepare drafts and assist with their completion and review
  • ISO 27001 and ISO 27701 Support

    Legal aspects of certification and support during audits
  • Training and Education

    Training on legal requirements and best practices
Юристи в сфері інформаційної та кібербезпеки

Simply implementing a cybersecurity system is not enough. It is essential to consider applicable legislation and the company’s business strategy and to prepare for critical situations.

blog_iconRelevant and Practical Articles on the Topic

  • Data protection officer
  • AI compliance officer
  • Data privacy compliance
  • Diia.City
  • Digital Millennium copyright Act
  • Trademark in IT
Go to Blog

We Write About What We Practice

IP, GDPR, contracts, and disputes, as well as the legal aspects of implementing technologies such as artificial intelligence and best practices for introducing specific legal solutions.