Legal-Updates
Legal-Updates

Regulatory Update in Poland: Q4 2025

Poland';s regulatory landscape shifted considerably in the final quarter of the year, with legislative amendments touching corporate governance, tax compliance, employment law, and financial services oversight. Businesses operating in Poland - whether locally incorporated or through a branch or representative structure - face a tightened compliance calendar and several new substantive obligations. This guide summarises the most consequential poland regulatory 2025 developments from Q4, explains what each change means in practice, and identifies the steps businesses should take now.

Corporate law amendments affecting Polish entities

The most structurally significant corporate development in Q4 was the amendment to the Commercial Companies Code (Kodeks spółek handlowych, KSH), which introduced revised rules on board liability and related-party transactions for limited liability companies (spółka z ograniczoną odpowiedzialnością, sp. z o.o.) and joint-stock companies (spółka akcyjna, S.A.). The amendment tightened the business judgment rule, requiring management board members to document the informational basis for material decisions more rigorously than before.

Under the revised provisions, a management board member who approves a transaction with a related party above a defined materiality threshold must now obtain prior approval from the supervisory board or, where no supervisory board exists, from the shareholders'; meeting. The threshold is calibrated to the company';s net assets, meaning the obligation is proportionate rather than fixed. Failure to obtain approval does not automatically void the transaction, but it exposes the board member to personal liability for any resulting loss.

A non-obvious requirement introduced alongside this amendment concerns the register of related-party transactions. Companies above a certain headcount and revenue threshold must now maintain a dedicated internal register and make it available to auditors and, on request, to the National Court Register (Krajowy Rejestr Sądowy, KRS). Many smaller sp. z o.o. entities have not historically maintained such documentation, and the transition period is short.

In practice, founders should consider reviewing their articles of association to ensure they align with the new approval procedures. A common mistake is assuming that informal shareholder consent - communicated by email or in a management meeting - satisfies the statutory requirement. It does not. The approval must be recorded in a formal resolution.

Tax compliance: new obligations under the updated CIT and VAT frameworks

Poland';s corporate income tax (CIT) framework saw several targeted amendments in Q4, most of which build on the broader minimum income tax (minimalny podatek dochodowy) regime that entered force in earlier periods. The current quarter';s changes clarify the calculation base for the minimum tax, particularly for entities that are part of a capital group and share costs across group members.

The amended rules under the Corporate Income Tax Act (ustawa o podatku dochodowym od osób prawnych) now require group entities to allocate shared costs using a documented methodology that must be consistent year-on-year unless a material change in business structure justifies revision. The Polish Tax Authority (Krajowa Administracja Skarbowa, KAS) has indicated it will scrutinise cost-allocation arrangements as part of its transfer pricing audit programme. Entities that have relied on informal or undocumented allocation keys face a meaningful risk of reassessment.

On the VAT side, the National e-Invoice System (Krajowy System e-Faktur, KSeF) implementation timeline was revised again in Q4. The mandatory rollout for large taxpayers - those exceeding the statutory revenue threshold - is now confirmed for the first half of the coming year, with smaller taxpayers following several months later. Businesses that have not yet integrated their accounting systems with KSeF should treat this as an urgent priority. The penalties for issuing invoices outside the system once the obligation applies are substantial and are calculated per invoice.

A practical scenario: a mid-sized manufacturing company with a German parent has been issuing intercompany invoices using a legacy ERP module. Under the new KSeF timeline, those invoices will need to be issued through the KSeF platform, which requires a qualified electronic signature or a trusted profile (Profil Zaufany) for the authorised representative. Setting up the technical integration typically takes several weeks, and the queue at certified IT providers has lengthened as the deadline approaches.

Many underestimate the administrative burden of KSeF onboarding. The system requires not only technical integration but also a review of invoice data fields, since KSeF uses a structured XML schema (FA(2) format) that differs from free-form PDF invoices. Errors in the schema result in rejection, not just a warning.

If your business needs assistance mapping current invoicing workflows to KSeF requirements or reviewing transfer pricing documentation, contact info@vlolawfirm.com. We can assist with documents and filings.

Employment law: changes to remote work rules and employee monitoring

The Labour Code (Kodeks pracy) amendments that formalised remote work arrangements in an earlier period continue to generate compliance questions, and Q4 brought further regulatory guidance from the State Labour Inspectorate (Państwowa Inspekcja Pracy, PIP). The guidance clarifies several contested points, particularly around employer rights to monitor remote workers and the obligation to cover work-from-home costs.

Under the current framework, employers must reimburse employees for the reasonable costs of remote work, including electricity and internet connectivity. The Q4 guidance confirms that a flat-rate allowance agreed in a collective agreement or individual contract satisfies this obligation, provided the amount is not manifestly disproportionate to actual costs. Employers who have been paying no allowance at all - a common oversight in companies that transitioned to hybrid work informally - are exposed to claims for back-payment.

The monitoring rules are equally important. Employers may monitor remote workers'; activity, but only within the limits set out in the employment contract and the remote work policy (porozumienie lub regulamin pracy zdalnej). Monitoring that goes beyond what is disclosed in those documents constitutes a breach of the employee';s privacy rights and may trigger liability under both the Labour Code and the General Data Protection Regulation (GDPR) as implemented in Poland through the Personal Data Protection Act (ustawa o ochronie danych osobowych).

A practical scenario: a technology company with a distributed workforce across Poland introduced keystroke-logging software to measure productivity. The software had not been disclosed in the remote work policy. Following a complaint, PIP opened an inspection and found the monitoring unlawful. The company was required to cease the practice immediately and faced an administrative fine. The lesson is that any monitoring tool must be documented and disclosed before deployment, not after.

Foreign employers with employees in Poland - whether through a Polish entity or under a direct employment arrangement - should audit their remote work policies against the current PIP guidance. The de facto standard applied during inspections is stricter than many foreign HR teams expect.

Financial services and AML: updated obligations for obligated institutions

Poland';s Anti-Money Laundering and Counter-Terrorist Financing Act (ustawa o przeciwdziałaniu praniu pieniędzy oraz finansowaniu terroryzmu, AML Act) was amended in Q4 to transpose the remaining provisions of the EU';s AML package into national law. The amendments expand the list of obligated institutions and tighten the customer due diligence (CDD) requirements for existing categories.

The most significant expansion concerns virtual asset service providers (VASPs) and certain categories of high-value goods dealers. VASPs operating in Poland must now register with the General Inspector of Financial Information (Generalny Inspektor Informacji Finansowej, GIIF) and implement a full CDD programme, including enhanced due diligence for transactions above the statutory threshold. The registration process involves submitting documentation on ownership structure, AML policies, and the identity of the compliance officer.

For existing obligated institutions - banks, payment institutions, notaries, lawyers, and accountants - the Q4 amendments introduce a revised risk assessment methodology. Institutions must now update their enterprise-wide risk assessments within a defined period following the amendment';s entry into force. The GIIF has published a guidance document outlining the expected structure of the risk assessment, and institutions that fail to update their documentation in time face administrative sanctions.

A common mistake among smaller obligated institutions, particularly accounting firms and tax advisers, is treating the AML risk assessment as a one-time document rather than a living instrument. The current amendments make clear that the assessment must be reviewed whenever there is a material change in the institution';s client base, service offering, or the broader risk environment. Firms that last updated their assessment several years ago are likely non-compliant.

The beneficial ownership register (Centralny Rejestr Beneficjentów Rzeczywistych, CRBR) obligations were also tightened. Entities that have undergone ownership changes must update the CRBR within seven days of the change. The Q4 amendment introduced a mechanism for GIIF to cross-reference CRBR data with other public registers, increasing the likelihood that discrepancies will be detected automatically.

Data protection and digital compliance developments

The Q4 period brought notable enforcement activity from the Polish Data Protection Authority (Urząd Ochrony Danych Osobowych, UODO), reinforcing several compliance themes that businesses should address proactively. UODO issued decisions in a series of cases involving inadequate data breach notification procedures, cookie consent mechanisms, and cross-border data transfers.

On data breach notification, UODO confirmed that the 72-hour notification clock under GDPR begins from the moment any member of the organisation - not just the Data Protection Officer (DPO) - becomes aware of a potential breach. Several companies had argued that the clock started only when the DPO was formally notified internally. UODO rejected this interpretation, aligning with the position of other EU supervisory authorities. The practical implication is that internal escalation procedures must be fast enough to allow a substantive notification to UODO within 72 hours of the first internal awareness.

Cookie consent enforcement intensified in Q4. UODO and the Office of Electronic Communications (Urząd Komunikacji Elektronicznej, UKE) coordinated inspections of websites operated by Polish businesses, focusing on pre-ticked consent boxes and the absence of a genuine "reject all" option. Websites that do not offer a reject option at the same level of prominence as the accept option are non-compliant. Many businesses updated their consent management platforms (CMPs) in response, but the inspections revealed that a significant number of sites still use dark patterns.

Cross-border data transfers to third countries remain a sensitive area. Following the Q4 enforcement decisions, businesses transferring personal data outside the European Economic Area must ensure that their Standard Contractual Clauses (SCCs) are accompanied by a documented transfer impact assessment (TIA). UODO has indicated it will request TIA documentation as a standard part of any investigation involving international transfers.

A non-obvious requirement concerns processors established outside Poland but processing data on behalf of Polish controllers. Those processors must designate a representative in the EU if they do not have an establishment in a Member State. Several enforcement cases in Q4 involved Polish controllers who had engaged non-EU processors without verifying whether the processor had an EU representative in place.

We can help structure the setup correctly the first time, including reviewing data processing agreements and transfer documentation. Reach out to info@vlolawfirm.com for a consultation.

Practical implications for foreign businesses operating in Poland

Foreign businesses - whether operating through a Polish subsidiary, a branch, or under a service agreement with Polish clients - face a layered compliance picture following the Q4 amendments. The changes span multiple regulatory domains simultaneously, which creates a risk that businesses address each area in isolation and miss cross-cutting obligations.

The interaction between the KSeF invoicing obligation and the AML CDD requirements is one example. A business that issues invoices through KSeF to a new client must also ensure that the client has been through the appropriate CDD process if the business is an obligated institution. The KSeF system does not substitute for AML checks; it is a separate obligation running in parallel.

Similarly, the revised KSH related-party transaction rules interact with transfer pricing documentation requirements under the CIT Act. A transaction that triggers the KSH approval requirement may also require a transfer pricing benchmark study if it involves a related party in a different tax jurisdiction. Businesses that treat corporate governance and tax compliance as separate workstreams may find that a transaction is approved at board level but challenged by KAS on transfer pricing grounds.

Foreign founders unfamiliar with Poland sometimes underestimate the role of the KRS as a public register. Changes to the management board, registered address, or share capital must be filed with the KRS within defined statutory deadlines - typically seven days for most changes. Late filings attract fines, and the KRS has become more active in issuing notices to non-compliant entities. Ensuring that a local representative or adviser monitors KRS obligations is a practical necessity, not a luxury.

The employment law changes also have direct implications for foreign employers. A company based outside Poland that employs Polish residents under direct employment contracts - without a Polish entity - must still comply with Polish Labour Code requirements, including the remote work policy obligations and the cost reimbursement rules. The fact that the employer has no Polish establishment does not exempt it from these obligations.

---

Frequently asked questions

What is the most urgent compliance action for a Polish sp. z o.o. following the Q4 KSH amendments?

The most urgent step is to review the company';s articles of association and internal approval procedures for related-party transactions. If the articles do not already require supervisory board or shareholder approval for material related-party dealings, they should be amended by a notarial deed and the change filed with the KRS. In parallel, the company should establish a formal register of related-party transactions. This is not a theoretical exercise - KAS and auditors are beginning to request this documentation as a standard part of reviews. Companies that delay risk personal liability for board members who approve transactions without the required authorisation.

How much time does KSeF integration typically take, and what are the main cost drivers?

The technical integration timeline depends heavily on the complexity of the existing accounting system. For a company using a major ERP platform with a Polish localisation module, integration can take four to eight weeks if the provider has a ready-made KSeF connector. For bespoke or legacy systems, the process can extend to several months. The main cost drivers are IT development or configuration fees, testing and validation against the FA(2) schema, and staff training. Businesses should also budget for ongoing maintenance, since the KSeF schema is subject to revision. Starting the process well before the mandatory deadline is strongly advisable, as certified IT providers are operating at capacity.

Does a foreign company with no Polish entity need to comply with Polish remote work rules for its Polish employees?

Yes. Polish Labour Code provisions apply to employment relationships performed in Poland, regardless of where the employer is incorporated. A foreign company employing Polish residents under Polish law contracts must comply with the remote work framework, including the obligation to have a written remote work policy, to reimburse reasonable costs, and to disclose any monitoring tools. The State Labour Inspectorate has jurisdiction to inspect such arrangements and has done so in practice. Foreign employers who have not yet formalised their remote work arrangements should treat this as a priority, particularly given the increased PIP enforcement activity observed in Q4.

---

Conclusion

The Q4 regulatory developments in Poland represent a broad tightening of compliance obligations across corporate, tax, employment, data protection, and AML domains. Businesses that address each area in isolation risk missing the cross-cutting interactions that create the greatest practical exposure. A coordinated review of governance documents, tax documentation, employment policies, and data processing arrangements is the most efficient response.

VLO Law Firms advises international clients on regulatory compliance and corporate matters in Poland. We can assist with KSH governance reviews, KSeF readiness assessments, AML programme updates, employment policy audits, and GDPR documentation. To request a consultation, contact: info@vlolawfirm.com