Where legal
complexity
meets practical clarity
Cybersecurity regulation has grown into one of the most intricate areas of modern law — layered with jurisdictional differences, technical requirements, and rapidly shifting enforcement priorities.
Ulnisrak brings together practitioners who have worked directly with compliance frameworks, breach response protocols, and regulatory bodies. Each masterclass is built around real legal scenarios, not hypothetical exercises. Participants leave with a working understanding of how specific laws apply to specific situations — which is a different thing entirely from memorizing statutes.
Six areas of cybersecurity law — each taught by someone who has worked it
Structured as independent masterclasses. Each can be taken separately or as part of a progressive sequence depending on your existing background.
GDPR and Data Protection Law in Depth
The General Data Protection Regulation is referenced constantly and understood inconsistently. This masterclass works through the actual text — lawful basis for processing, data subject rights, controller and processor obligations, and the conditions under which supervisory authorities have intervened. Taught by a practitioner who has handled GDPR compliance assessments for organizations operating across EU member states.
Incident Reporting Obligations
When a breach occurs, the legal clock starts immediately. This masterclass maps the reporting timelines, notification thresholds, and documentation requirements under NIS2, GDPR Article 33, and sector-specific rules in financial services and healthcare.
Compliance FocusCross-Border Data Transfer Rules
Standard Contractual Clauses, adequacy decisions, and the post-Schrems II landscape. This session covers how organizations legally move personal data between jurisdictions and what documentation regulators actually examine during audits.
International LawOrganizational Liability and Accountability
How courts and regulators assess whether an organization took reasonable security measures — and what "reasonable" actually means in practice. Covers liability allocation between controllers, processors, and third-party vendors.
Legal LiabilitySector-Specific Compliance Frameworks
Financial institutions, healthcare providers, and critical infrastructure operators face layered obligations beyond general data protection law. This masterclass maps the intersections between DORA, HIPAA equivalents, and national critical infrastructure legislation.
Sector RegulationAI Systems and Emerging Regulatory Risk
The EU AI Act introduces risk-tiered obligations that intersect directly with existing cybersecurity and data protection law. This session examines how organizations deploying automated decision systems should approach compliance before enforcement begins.
Emerging Law
Tomasz Kwiatkowski
Data Protection Specialist
GDPR enforcement & cross-border transfers
Iryna Havryliuk
Compliance Advisor
Incident response law & NIS2 obligations
Benedikt Oravec
Regulatory Risk Analyst
AI Act, DORA & sector-specific frameworks