School blog
Kristina Sedeke: Law in IT
What does TikTok know about you that your mum does not? And what happens when artificial intelligence decides you are not a good enough neighbour? Technology is advancing at breakneck speed while legislation struggles to keep up. At ITG, we had a rare opportunity to explore IT law with expert Kristýna Sedeke. Here are the highlights of her talk.
When we hear ‘internet law’, many of us think only of annoying cookie pop-ups. But Kristina Sedeke showed us that seemingly dull abbreviations such as GDPR, NIS2 and DORA stand for rules that protect our everyday lives, our money and our future.
GDPR: ‘My data is my business’
Since May 2018, we have been living in the GDPR era, based on three main pillars. The first is that our data belongs to us: a company does not borrow it forever; we are in control of our information. We also have the right to know what companies know about us and to say ‘STOP’. Companies that break the rules face substantial fines of up to €20 million or 4% of global turnover.
One interesting topic was the ‘right to be forgotten’ under Article 17 of the GDPR. Imagine Adam, a thirty-year-old politician who posted something inappropriate online when he was young and now wants it removed from Google. For an ordinary person, a search engine would probably remove the link because it is outdated. For a public figure such as a politician, the law protects the public interest: voters have a right to know about his past.
The AI Act: An algorithm must not judge me unfairly
Artificial intelligence is fascinating, but it needs boundaries. The European Union therefore introduced the AI Act, which classifies AI systems by their level of risk.
What is completely unacceptable and prohibited?
Social scoring and biometric categorisation: Systems that score and classify people according to their behaviour are prohibited.
Emotion analysis: Your boss or teacher must not use AI to analyse how you feel from your voice in a meeting or at school.
Generative AI such as ChatGPT and systems that create deepfakes are permitted, but their output must be clearly and transparently identified as AI-generated.
NIS2: Hospitals and power plants must withstand hackers
While cybersecurity used to be mainly a concern for banks and power plants, the NIS2 directive extends it to healthcare, where a virus must not bring a hospital down, as well as food production, transport and even waste management.
Organisations covered by the legislation must report incidents to the Czech National Cyber and Information Security Agency (NÚKIB) within 24 hours. During 2026, these institutions face their final deadlines for introducing the appropriate technical and security measures.
DORA: Keeping banks running, whatever happens
When money is involved, everything is at stake. The Digital Operational Resilience Act (DORA) requires banks, insurers and exchanges to withstand cyber threats. A new development is that banks are now also accountable for their IT suppliers, such as Microsoft or Amazon, so they can no longer simply blame their cloud provider. Banks must even hire ethical hackers to test their systems and look for weaknesses.
The takeaway?
Law and technology constantly meet, and sometimes sparks fly. Kristina Sedeke's talk at ITG showed us that laws are more than dry legal provisions: they are tools to protect what matters most, our privacy, safety and a fair society.
Thank you for a wonderful and informative visit!
