Poland data protection 2025 has entered a more demanding phase. The Polish supervisory authority, the Personal Data Protection Office (Urząd Ochrony Danych Osobowych, or UODO), intensified its enforcement activity in the final quarter, issuing several significant decisions and guidance documents. Organisations operating in Poland - whether Polish-registered or foreign entities processing data of Polish residents - face a more scrutinised compliance environment. This guide covers the key regulatory and enforcement developments from Q4, their practical implications for businesses, and the steps organisations should take to remain compliant.
Key regulatory developments affecting poland data protection 2025
The most consequential regulatory shift in the final quarter relates to the implementation of the EU AI Act';s first binding obligations. Poland, like all EU member states, is subject to the AI Act';s phased application schedule. The provisions prohibiting certain high-risk AI practices became applicable, and UODO issued a position paper clarifying how these obligations intersect with GDPR requirements under Polish law. In practice, this means that organisations using AI-driven profiling, automated decision-making, or biometric categorisation tools must now assess compliance under both frameworks simultaneously.
Separately, the Polish legislature advanced work on amendments to the Act on the Protection of Personal Data of 10 May 2018 (the "Polish Data Protection Act"), which supplements and implements the GDPR at the national level. The proposed amendments address the procedural rights of data subjects in administrative proceedings before UODO and clarify the evidentiary standards applicable in enforcement cases. Although the amendments had not yet entered into force by the close of the quarter, their parliamentary progress signals a tightening of procedural rules that controllers and processors should monitor closely.
UODO also updated its guidance on the use of cookies and tracking technologies, aligning its position more closely with recent decisions by peer supervisory authorities in the EU. The updated guidance reinforces that pre-ticked consent boxes and "consent walls" - where access to a service is conditioned on accepting all cookies - remain non-compliant under Polish and EU law. Organisations running Polish-language websites or targeting Polish users should treat this updated guidance as operationally binding.
UODO enforcement decisions: patterns and priorities
UODO';s enforcement output in the final quarter revealed clear thematic priorities. The authority focused on three areas: inadequate technical and organisational measures, failures in data breach notification, and unlawful data transfers to third countries.
In the area of technical and organisational measures, UODO issued decisions against entities in the financial services and healthcare sectors. The decisions cited failures to implement appropriate access controls, insufficient encryption of personal data at rest, and inadequate staff training. The fines imposed ranged from moderate to substantial, reflecting the scale of the organisations involved and the number of data subjects affected. A recurring finding was that organisations had documented policies in place but failed to implement them operationally - a gap UODO described as a systemic weakness.
On data breach notification, UODO reiterated the 72-hour notification requirement under Article 33 of the GDPR and penalised several controllers for late or incomplete notifications. A non-obvious requirement that surfaced in these decisions is the obligation to document the reasoning behind any decision not to notify the supervisory authority, even when the controller concludes that the breach is unlikely to result in a risk to individuals. UODO inspectors examined internal breach logs and found that many organisations lacked adequate documentation of their risk assessments.
Regarding international data transfers, UODO scrutinised the use of standard contractual clauses (SCCs) and transfer impact assessments (TIAs). Several decisions noted that organisations had executed SCCs but failed to conduct or document TIAs, particularly for transfers to processors in countries without an EU adequacy decision. In practice, founders and compliance officers should treat TIA documentation as a mandatory step, not an optional supplement to SCCs.
Practical implications for businesses operating in Poland
The Q4 developments carry concrete compliance obligations for a wide range of organisations. Foreign companies with Polish subsidiaries, e-commerce operators targeting Polish consumers, and employers processing employee data in Poland are all directly affected.
For organisations using AI tools in HR, marketing, or customer service, the intersection of the AI Act and GDPR creates a dual compliance burden. A common mistake is to treat AI Act compliance as a separate IT project disconnected from the existing GDPR programme. In practice, the data protection impact assessment (DPIA) process under Article 35 of the GDPR is the natural vehicle for integrating AI Act risk assessments. Organisations that have not yet reviewed their DPIA inventory in light of AI tool deployments should do so promptly.
For e-commerce and digital marketing operators, UODO';s updated cookie guidance requires an immediate review of consent management platforms. Many underestimate the technical complexity of achieving genuine, granular consent - particularly where third-party analytics and advertising scripts are loaded before consent is registered. Controllers should verify that their consent management platform logs are auditable and that withdrawal of consent is as straightforward as giving it.
For employers, the final quarter brought renewed attention to employee monitoring. UODO';s published decisions and guidance confirm that covert monitoring of employees - including undisclosed tracking of work devices or location data - is unlawful under the Polish Labour Code read together with the GDPR. Employers must provide clear, specific notice of any monitoring before it begins, and the scope of monitoring must be proportionate to the legitimate purpose pursued.
If your organisation needs to review its compliance posture in light of these developments, contact us at info@vlolawfirm.com. We can help structure the review correctly the first time.
Data subject rights: enforcement and procedural developments
Data subject rights complaints remained the largest single category of cases before UODO in the final quarter. The most frequently litigated rights were the right of access under Article 15 of the GDPR, the right to erasure under Article 17, and the right to object under Article 21.
UODO';s decisions on access requests clarified several practical points. Controllers must provide a copy of the personal data undergoing processing, not merely a summary or a confirmation that data is held. Where data is held in multiple systems, the controller';s obligation extends to all systems, not only the primary CRM or database. A common mistake made by foreign-owned entities operating in Poland is to respond to access requests based on the practices of their home jurisdiction, which may set lower standards than the GDPR as interpreted by UODO.
On the right to erasure, UODO confirmed that the existence of a legitimate interest ground for processing does not automatically override an erasure request. Controllers must conduct a fresh balancing exercise at the time the request is received, taking into account the specific circumstances of the data subject. Organisations that have automated their erasure responses without building in a case-by-case review mechanism are at risk of non-compliance.
The right to object in the context of direct marketing received particular attention. UODO reiterated that an objection to direct marketing processing must be honoured immediately and unconditionally, without requiring the data subject to provide reasons. Several decisions found that organisations had imposed procedural barriers - such as requiring the data subject to complete a form or contact a specific department - that effectively delayed or frustrated the exercise of this right.
Cross-border data flows and third-country transfers
Cross-border data transfer compliance remained a significant operational challenge for Polish-based organisations in the final quarter. The EU-US Data Privacy Framework continued to provide a basis for transfers to certified US entities, but UODO signalled that it would scrutinise reliance on the framework in cases where the US recipient';s certification scope did not clearly cover the categories of data being transferred.
For transfers to other third countries, the standard contractual clauses adopted by the European Commission remain the primary mechanism. UODO';s Q4 decisions reinforced that executing SCCs is a necessary but not sufficient step. Controllers must also conduct and document a transfer impact assessment that evaluates the legal framework of the destination country and identifies any supplementary measures needed to bring the level of protection to EU standards. In practice, many organisations complete the SCC paperwork but treat the TIA as a formality, producing a generic document that does not engage with the specific risks of the transfer. UODO inspectors have shown they will look behind the documentation.
Organisations using cloud service providers headquartered outside the EU should pay particular attention to sub-processor chains. Where a cloud provider relies on sub-processors in third countries, the controller';s TIA obligation extends to those sub-processors. This is a non-obvious requirement that frequently surfaces only during a UODO inspection or audit. Controllers should request and review their cloud providers'; sub-processor lists and assess whether the existing TIA documentation covers the full transfer chain.
A practical scenario illustrating the risk: a Polish e-commerce company uses a US-based email marketing platform that in turn routes data through a data centre in a country without an EU adequacy decision. The company has executed SCCs with the US platform but has not assessed the onward transfer. Under UODO';s current approach, this gap would likely be treated as a violation of Chapter V of the GDPR.
A second scenario: a Warsaw-based fintech uses an AI-powered fraud detection tool provided by a non-EU vendor. The tool processes transaction data and generates risk scores. The company has conducted a DPIA for the fraud detection process but has not updated it to reflect the AI Act';s requirements for high-risk AI systems. Under the dual compliance framework now in effect, this gap creates exposure under both the GDPR and the AI Act.
Sector-specific guidance and upcoming obligations
UODO published sector-specific guidance in the final quarter covering healthcare, financial services, and public administration. Each guidance document identified the most common compliance gaps observed during inspections and set out UODO';s expectations for remediation.
In healthcare, the guidance focused on the processing of special category data under Article 9 of the GDPR. UODO noted that many healthcare providers rely on the explicit consent of patients as the legal basis for processing health data, but fail to ensure that consent is freely given in the context of a treatment relationship where there is an inherent power imbalance. The guidance recommends that healthcare providers assess whether an alternative legal basis - such as the necessity of processing for medical diagnosis or the provision of health care - is more appropriate.
In financial services, UODO';s guidance addressed the use of credit scoring and automated decision-making. Controllers using automated scoring models must be able to explain the logic of the model to data subjects upon request, as required by Article 22(3) of the GDPR. Many financial institutions have implemented explainability tools at the model level but have not translated this into meaningful, plain-language explanations for individual data subjects. UODO indicated that it will assess the quality of explanations provided, not merely their existence.
For public administration bodies, the guidance emphasised the role of the Data Protection Officer (DPO). Under Article 37(1)(a) of the GDPR, public authorities are required to designate a DPO. UODO found that several public bodies had designated DPOs who lacked the necessary expertise or were placed in organisational positions that compromised their independence. The guidance sets out minimum qualifications and structural requirements for DPOs in the public sector.
Looking ahead, organisations should prepare for the next phase of AI Act obligations, which will impose conformity assessment requirements on providers and deployers of high-risk AI systems. The interaction between these requirements and existing GDPR obligations - particularly around DPIAs, records of processing activities, and data subject rights - will require coordinated compliance planning across legal, IT, and business functions.
To discuss how these developments affect your organisation';s specific situation, reach out to info@vlolawfirm.com. We can assist with compliance gap analyses, DPIA reviews, and transfer impact assessments.
Frequently asked questions
What is the most significant practical risk for foreign companies processing data of Polish residents?
The most significant risk is the assumption that compliance with GDPR in another EU member state automatically satisfies UODO';s requirements. While the GDPR is directly applicable across the EU, UODO has developed specific interpretive positions - on cookie consent, employee monitoring, and data subject rights responses - that go beyond the minimum requirements of the regulation. Foreign companies should treat UODO';s published decisions and guidance as operationally relevant, not merely as local colour. Failure to do so has resulted in enforcement actions against non-Polish entities that underestimated the supervisory authority';s reach and expectations.
How long does a UODO investigation typically take, and what costs should organisations anticipate?
A UODO investigation can range from a few months for straightforward cases to well over a year for complex matters involving multiple data subjects or cross-border elements. The direct costs include legal representation, the cost of producing documentation and responding to information requests, and any remediation work required. Fines, where imposed, are calculated as a proportion of annual global turnover under Article 83 of the GDPR, so the financial exposure for larger organisations can be substantial. Organisations should also factor in the indirect costs of management time, reputational impact, and the operational disruption of an inspection.
Should a company appoint a Data Protection Officer if it is not strictly required to do so under the GDPR?
The mandatory DPO requirement under Article 37 of the GDPR applies to public authorities, organisations engaged in large-scale systematic monitoring, and organisations processing special category data at scale. However, many organisations that fall outside these categories find it operationally useful to appoint a DPO or a dedicated data protection function. In Poland';s current enforcement environment, having a knowledgeable internal or external DPO provides a practical advantage: it ensures that compliance issues are identified and addressed before they become enforcement matters, and it provides a clear point of contact for UODO in the event of an inquiry or inspection.
Conclusion
The final quarter marked a clear intensification of data protection enforcement and regulatory activity in Poland. UODO';s focus on technical measures, breach notification, and cross-border transfers reflects the supervisory authority';s maturing enforcement capacity. Organisations that treat compliance as a documentation exercise rather than an operational discipline face growing exposure.
VLO Law Firms advises international clients on data protection matters in Poland. We can assist with GDPR compliance reviews, DPIA preparation, transfer impact assessments, DPO support, and representation before UODO. To request a consultation, contact: info@vlolawfirm.com