February brought significant changes to the Polish Commercial Companies Code (KSH). The amendments to this act primarily include:
- Imposing an obligation on the company’s management board to report current data to the entity maintaining the shareholder register within seven days of the occurrence of the event justifying the entry;
- Imposing an obligation on the entity maintaining the shareholder register to notify the registry court – via the IT system – of the expiration or termination of the agreement to maintain the shareholder register, specifying the date of its expiration or termination within seven days;
- Introducing a solution that a list of the company’s shareholders will have to be attached to the application for deletion of the company from the National Court Register (KRS) in connection with the company’s liquidation;
- Determining the legal form of the declaration of consent to entry in the shareholder register, submitted by the person whose rights are to be deleted, changed, or encumbered by the entry in the shareholder register;
- Expanding the scope of data to be disclosed in the shareholder register, simultaneously specifying the permissible scope of its processing;
- Expanding the list of grounds for invalidation of the registration certificate; – abandoning the division of shares into registered and bearer shares – which also results in the introduction of a number of adjustment changes in other acts
Changes to the Commercial Companies Code necessitated amendments to related acts. One such act is the Act on the National Court Register (KRS), which, in addition to harmonizing regulations with the amendments introduced in the Commercial Companies Code, requires the Register of Entrepreneurs to disclose information about the entity maintaining the register of company shareholders or the securities depository where shares are registered, along with the entity’s designation. Furthermore, it adds a provision requiring the submission to the registry court of a list of the company’s shareholders, prepared as of the approval of the liquidation report or as of the date specified by the registry court.
Another act amended in this regard is the Act on Trading in Financial Instruments, which adds a provision stipulating that, upon termination of the shareholder register agreement, the investment firm’s obligation to retain and archive documents will apply to copies of the shareholder register and copies of documents related to its maintenance. Upon termination of the shareholder register agreement, the investment firm will be obligated to transfer the register and related documents to the entity designated by the company that has taken over the maintenance of the shareholder register.
February also saw the passage of a law terminating the provisions of the Act on Assistance to Ukrainian Citizens in the Event of Armed Conflict in the Territory of Ukraine, which provides for a systemic regulation of temporary protection granted to foreigners in the territory of the Republic of Poland who have left their country of origin due to foreign invasion, civil war, ethnic conflicts, or gross violations of human rights.
This law is intended to constitute a fundamental national act comprehensively implementing Council Directive 2001/55/EC of 20 July 2001 on minimum standards for granting temporary protection in the event of a mass influx of displaced persons and on measures promoting a balance of efforts between Member States in receiving such persons and their consequences, regardless of the refugees’ country of origin.
February also saw the entry into force of the Act amending the Act on the National Cybersecurity System and certain other acts. However, the President of the Republic of Poland referred part of this act for review by the Constitutional Tribunal.
This act amends the provisions of the current Cybersecurity System Act to ensure a comprehensive cybersecurity system and increase the level of resilience to cyber threats and information protection in the public, military, and private sectors. Furthermore, it implements into the Polish legal order Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 concerning measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972 and repealing Directive (EU) 2016/1148 – hereinafter referred to as the “NIS 2 Directive” or “Directive 2022/2555” – so that Polish cybersecurity regulations are consistent with the solutions adopted at the European Union level.
The adopted act adapts the national cybersecurity system to the changed digital environment and the growing scale of cyber threats. The changes include expanding the list of entities subject to obligations, replacing the current division into essential service operators and digital service providers with a new category of essential and important entities, strengthening the incident response system, and clarifying the roles of authorities responsible for cybersecurity.
The act introduces a new structure for the national cybersecurity system, expanding the responsibilities of public and private entities in the area of cybersecurity, redefining the competences of state authorities, and introducing preventive and control mechanisms for essential and important entities. The act also introduces the definition of essential entities, meaning those whose activities are crucial to the functioning of the state and the economy, as well as essential entities, which, despite their smaller scale of operation, must still fulfill cybersecurity obligations, including reporting incidents and implementing basic procedures for protecting information systems.



