I am Katarzyna Szczudlik – a fintech, AI Act and NIS2 lawyer based in Poland, advising international companies, technology businesses and financial institutions on some of the most consequential regulatory questions in Europe right now. As a Partner at Schoenherr in Warsaw, ranked by Chambers & Partners among Poland’s leading FinTech lawyers and by Legal 500 EMEA as a leading Data Protection and TMT practitioner, I work at the intersection of technology, financial regulation and compliance – where product decisions and legal obligations meet.
This post explains who I work with, what I advise on, and how engagements typically work. If you are looking for a fintech, AI Act or NIS2 lawyer in Poland – or for legal advice on EU regulatory compliance more broadly — I hope it gives you a clear picture of whether I can help.
Who I Work With as a Fintech, AI Act and NIS2 Lawyer in Poland
My clients are typically international businesses that need clear, practical and commercially grounded legal advice in regulated environments. Specifically, I work with:
- International fintechs and crypto-asset businesses entering or scaling in Poland and the EU – navigating MiCA, CASP licensing, VASP transition, PSD2 and KNF authorisation
- Technology companies building or deploying AI systems – preparing for EU AI Act obligations, including risk classification, governance frameworks and AI vendor contracts
- Financial institutions and regulated entities managing DORA operational resilience requirements, NIS2 cybersecurity obligations and overlapping compliance frameworks
- In-house legal, compliance and product teams that need a strategic external partner who understands both the regulation and the business behind it
Most of my clients are non-Polish companies. Consequently, a significant part of my work involves helping international organisations understand what Polish and EU regulation actually requires in practice – not just in theory.
What I Advise On
FinTech, MiCA and Financial Regulation
As one of Poland’s leading fintech lawyers, I advise payment institutions, crypto-asset businesses, neobanks and digital finance companies on EU financial regulation and Polish market entry. My work in this area covers MiCA and CASP licensing, VASP transition strategy, PSD2 and payment services compliance, AML/CFT frameworks, KNF authorisation and representation, and cross-border regulatory strategy for companies entering Poland and the EU.
Furthermore, I have a strong track record in blockchain and crypto-asset regulation – including MiCA transition arrangements such as CASP as a Service, which emerged as a practical solution for Polish VASPs ahead of the July 2026 deadline. For more on this, see my post on CASP as a Service Under MiCA in Poland.
EU AI Act and AI Governance
I have followed the AI Act since its earliest legislative stages – before most organisations realised it would apply to them. As a result, I bring a depth of understanding that goes beyond reading the final text. My AI Act work covers high-risk AI system classification, AI governance frameworks and internal policies, contracts with AI solution providers, algorithmic accountability and liability assessment, and IP and data protection considerations in AI projects.
For a practical breakdown of high-risk classification – including what it means for financial services – see my post on High-Risk AI Classification Under the EU AI Act.
NIS2 and Cybersecurity Law in Poland
I am one of Poland’s leading lawyers advising on NIS2 implementation under the amended KSC Act, which entered into force on 3 April 2026. My NIS2 work covers applicability assessments , SZBI implementation and governance, incident response and reporting frameworks, supply chain and vendor risk, and board-level liability under the amended Act.
I have written an in-depth series on NIS2 in Poland covering the full compliance journey:
- Does NIS2 Apply to Your Business in Poland? – how to determine whether you qualify and how to register before 3 October 2026
- NIS2 Poland Cybersecurity Measures: 10 Things Your Organisation Must Build by April 2027 – a practical breakdown of all ten Article 8 obligations and board liability
- NIS2 Compliance for SMEs in Poland – what the framework means for smaller businesses and how to implement it proportionately
DORA and Operational Resilience
I advise financial entities – banks, payment institutions, investment firms, CASPs and insurers – on DORA compliance, including ICT risk management frameworks, ICT third-party contracts under Article 30, the Register of Information, incident classification and reporting, and KNF supervisory expectations. Additionally, I advise technology vendors and cloud providers on their obligations as ICT third-party service providers under DORA.
Data Protection and GDPR
As a Fellow of Information Privacy (FIP, IAPP) — one of the most rigorous privacy certifications globally — and Legal 500 EMEA leading individual in Data Protection and TMT, I advise on GDPR governance, data breaches, DPIAs, cross-border data transfers, and the intersection of GDPR with the AI Act and NIS2. For technology companies and fintechs, data protection is rarely a standalone question — it connects directly to product design, AI governance and cybersecurity obligations.
IT Contracts and Intellectual Property
I draft, negotiate and audit technology agreements — SaaS contracts, cloud agreements, IT outsourcing, AI vendor contracts and enterprise technology frameworks — with particular attention to DORA Article 30 requirements, AI Act deployer obligations and cybersecurity flow-down clauses. Furthermore, I advise on software ownership, trade secrets, open source risk and IP structuring for technology businesses.
How I Work
Most engagements start with a short introductory call — usually 20 to 30 minutes. In that conversation, I ask about the business, the regulatory question and what you are trying to achieve. The goal is simple: to understand whether I can genuinely help, and how.
If it makes sense to work together, I outline the scope, format, timeline and expected output. I do not propose more than the situation actually requires.
My advice is delivered in plain language, with clear recommendations and reasoning — not just a list of risks. I work in Polish, English and French, which is particularly useful for international companies navigating Polish regulatory requirements.
For a fuller description of how I structure engagements, see the How I Work page.
Get in Touch
If you are looking for a fintech, AI Act or NIS2 lawyer in Poland — or for practical legal advice on EU regulatory compliance — I am happy to have an initial conversation.
You can reach me via the contact page or find more detail on my practice areas and about page.
Most first conversations happen within 48 hours of reaching out.
Katarzyna Szczudlik is a Partner at Schoenherr in Warsaw and one of Poland’s leading fintech, AI Act and NIS2 lawyers. She advises international technology companies, crypto-asset businesses and financial institutions on EU regulatory compliance, Poland market entry and technology law. Ranked by Chambers & Partners (FinTech) and Legal 500 EMEA (Data Protection & TMT). Fellow of Information Privacy (IAPP). Forbes Poland Top 25 Women Lawyers in Business.