Legal-Updates
Legal-Updates

Data Protection Update in Poland: Q1 2026

Poland data protection 2026 has entered a notably active phase. The Polish supervisory authority, the Personal Data Protection Office (Urząd Ochrony Danych Osobowych, or UODO), has intensified enforcement, issued new guidance and pursued several high-profile investigations. Businesses operating in Poland - whether Polish-incorporated or foreign entities processing Polish residents'; data - face a more demanding compliance environment than in previous periods. This guide covers the most significant legislative and regulatory developments, key enforcement actions, practical compliance implications, and the questions businesses are asking most frequently.

Why the current period matters for businesses processing data in Poland

Poland';s data protection landscape is shaped by three overlapping frameworks: the EU General Data Protection Regulation (GDPR), the Polish Act on the Protection of Personal Data of May 2018 (the "Polish PDPA"), and sector-specific legislation covering areas such as telecommunications, healthcare and financial services. In the current period, all three layers are generating compliance obligations simultaneously.

UODO has signalled a clear shift toward proactive supervision rather than reactive complaint handling. The Office has published an updated supervisory strategy that prioritises artificial intelligence systems, data brokers, and cross-border data transfers. This shift means that businesses which previously relied on a low-profile approach - processing data without attracting complaints - now face a realistic prospect of ex officio investigations.

The practical consequence for international businesses is significant. A non-EU company that targets Polish consumers, operates a Polish-language website, or processes data of Polish employees through a non-EU parent is subject to GDPR and, where applicable, the Polish PDPA. Failure to appoint an EU representative when required, or to maintain records of processing activities in Polish-accessible form, has become a specific enforcement focus.

In practice, founders and compliance officers should treat the current period as a reset point: review processing records, update privacy notices, and confirm that data processing agreements with Polish processors and sub-processors are current.

Key legislative and regulatory developments

The most consequential recent development is the transposition of the NIS2 Directive into Polish law. The Polish Act on the National Cybersecurity System (Ustawa o Krajowym Systemie Cyberbezpieczeństwa, or KSC Act) has been substantially amended to align with NIS2 requirements. While NIS2 is primarily a cybersecurity instrument, its intersection with GDPR is direct: organisations classified as "essential" or "important" entities under the KSC Act must implement technical and organisational security measures that also satisfy GDPR Article 32 obligations. A breach of the KSC Act';s security requirements will, in most cases, simultaneously constitute a GDPR compliance failure.

UODO has also issued updated guidance on the use of AI tools in employment contexts. The guidance addresses the use of automated screening, monitoring and performance-evaluation systems. The core position is that decisions with significant effects on employees - including hiring, promotion and termination - cannot be made solely by automated means without a valid legal basis under GDPR Article 22. Employers using AI-driven HR platforms must conduct a Data Protection Impact Assessment (DPIA) before deployment, document the human oversight mechanism, and inform employees through a clear privacy notice.

A further development concerns cookie consent. Following coordinated enforcement across EU member states, UODO has adopted the position that consent obtained through so-called "dark patterns" - pre-ticked boxes, misleading button labelling, or consent walls that deny access to content unless the user agrees - does not constitute valid consent under GDPR Article 7. Websites targeting Polish users must audit their consent management platforms against this standard.

Finally, UODO has clarified its approach to data retention in the context of the Polish Labour Code. Employers are required by the Labour Code to retain certain employment records for defined periods. Where GDPR';s data minimisation principle appears to conflict with statutory retention obligations, UODO';s position is that the statutory obligation constitutes a legal basis under GDPR Article 6(1)(c), but only for the specific categories of data covered by the Labour Code. Retaining additional data beyond the statutory scope on the basis of a general "legal obligation" argument is not accepted.

Enforcement actions and UODO decisions

UODO';s enforcement activity in the current period has produced several decisions with direct practical relevance.

In one significant case, a large retail company received a substantial administrative fine for failing to implement adequate technical measures following a data breach. The breach involved the exposure of customer payment data. UODO found that the company had not conducted a DPIA before launching the affected processing system, had not encrypted data at rest, and had delayed notifying UODO beyond the 72-hour window required by GDPR Article 33. The decision reinforces three compliance obligations simultaneously: pre-launch DPIA, encryption as a baseline security measure, and prompt breach notification.

In a second notable decision, UODO fined a data broker operating in Poland for processing personal data without a valid legal basis. The broker had compiled profiles of Polish individuals from publicly available sources and sold access to those profiles to third parties. UODO rejected the argument that publicly available data can be freely processed for any purpose. The decision confirms that the GDPR';s purpose limitation principle applies regardless of whether the original data was publicly accessible. Businesses that aggregate, enrich or resell personal data must identify a specific legal basis for each processing purpose.

A third enforcement action targeted a healthcare provider that had transferred patient data to a US-based cloud service provider without implementing adequate transfer safeguards. Following the invalidation of the EU-US Privacy Shield and the subsequent adoption of the EU-US Data Privacy Framework, UODO has made clear that transfers to US processors must be covered either by the Data Privacy Framework (where the US processor is certified) or by Standard Contractual Clauses supplemented by a Transfer Impact Assessment. The healthcare provider had relied on SCCs but had not conducted a Transfer Impact Assessment. UODO found this insufficient and issued a corrective order alongside a fine.

These three decisions together define UODO';s current enforcement priorities: pre-processing risk assessment, lawful basis for data aggregation, and transfer safeguards for non-EU processors.

If your organisation has received an inquiry from UODO or is reviewing its transfer mechanisms, contact info@vlolawfirm.com. We can assist with documents and filings.

Practical compliance priorities for businesses in Poland

The enforcement picture translates into a concrete compliance agenda for businesses operating in Poland.

Records of processing activities. GDPR Article 30 requires controllers and processors to maintain records of processing activities. UODO has confirmed that it requests these records as a first step in any investigation. Records must be current, accurate and sufficiently detailed to demonstrate compliance. A common mistake is maintaining a single outdated record that does not reflect new processing activities introduced through software updates, new vendors or organisational changes.

Data processing agreements. Any business that uses third-party vendors to process personal data on its behalf must have a written data processing agreement (DPA) in place, covering the mandatory content specified in GDPR Article 28. In practice, many businesses have DPAs in place but have not updated them to reflect changes in the vendor';s sub-processors. UODO has treated outdated or incomplete DPAs as evidence of systemic non-compliance rather than a minor procedural gap.

DPIA obligations. UODO has published a list of processing activities that always require a DPIA in Poland. The list includes large-scale processing of health data, systematic monitoring of publicly accessible areas, and processing that involves profiling with significant effects. Businesses that have not reviewed their processing activities against this list should do so promptly. A DPIA that is conducted but not documented is treated by UODO as equivalent to no DPIA.

Employee data. The intersection of the Polish Labour Code and GDPR creates specific obligations. Employers must inform employees of the legal basis for each category of data processed, the retention period, and the identity of any processors. Many employers use a single, generic privacy notice that does not address these specifics. UODO has indicated that generic notices do not satisfy the transparency requirements of GDPR Articles 13 and 14.

Breach notification. The 72-hour notification window under GDPR Article 33 runs from the moment the controller becomes "aware" of a breach. UODO has clarified that awareness is attributed to the organisation when any employee with relevant responsibilities becomes aware, not only when the matter reaches senior management. Businesses should ensure that their incident response procedures route breach reports to the Data Protection Officer or compliance team immediately, without waiting for internal escalation.

A scenario that illustrates the practical risk: a Polish e-commerce company uses a US-based email marketing platform. The platform suffers a breach affecting Polish customer data. The e-commerce company learns of the breach from a news report rather than from the platform. Under GDPR, the company is the controller and bears the notification obligation. The 72-hour clock starts when the company reads the news report. If the company then spends 48 hours conducting an internal investigation before notifying UODO, it has likely complied. If it spends five days, it has not.

A second scenario: a Warsaw-based fintech startup uses an AI-powered credit-scoring tool supplied by a third-party vendor. The tool makes automated decisions about loan eligibility. The startup has not conducted a DPIA and has not informed applicants of their right to human review under GDPR Article 22. UODO';s current guidance makes clear that this configuration is non-compliant on multiple grounds. The startup must conduct a DPIA, update its privacy notice, implement a human review mechanism, and ensure the DPA with the vendor covers the AI tool';s processing activities.

Cross-border data transfers: current requirements in Poland

Cross-border data transfers remain one of the most technically complex areas of GDPR compliance, and UODO';s recent enforcement confirms that Polish supervisory scrutiny in this area is increasing.

The primary transfer mechanisms available to businesses transferring data from Poland (as an EU member state) to third countries are: adequacy decisions issued by the European Commission, Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and the derogations listed in GDPR Article 49. The EU-US Data Privacy Framework provides an adequacy basis for transfers to certified US organisations, but businesses must verify that their specific US counterpart is currently certified under the Framework before relying on it.

For transfers to countries without an adequacy decision - which includes many jurisdictions commonly used for outsourcing and cloud services - SCCs remain the primary tool. However, UODO';s enforcement makes clear that SCCs alone are not sufficient. Controllers must conduct a Transfer Impact Assessment (TIA) to evaluate whether the legal framework of the destination country provides essentially equivalent protection to EU law. Where the TIA identifies gaps, supplementary measures - technical, contractual or organisational - must be implemented.

A non-obvious requirement that many foreign businesses miss: where a non-EU parent company acts as a processor for a Polish subsidiary (for example, processing employee data through a centralised HR system), the transfer from the Polish subsidiary to the non-EU parent requires a valid transfer mechanism. Intra-group transfers are not exempt from GDPR transfer rules simply because the entities share common ownership.

Many underestimate the documentation burden associated with TIAs. A TIA must assess the destination country';s laws on government access to data, the availability of effective legal remedies for data subjects, and the track record of the destination country';s authorities. This assessment must be documented and kept current. UODO has indicated that a TIA conducted at the time of contract signature but not reviewed since is unlikely to satisfy the ongoing compliance obligation.

FAQ

What are the most significant practical risks for a foreign company processing Polish residents'; data without a local entity?

A foreign company that targets Polish residents or monitors their behaviour is subject to GDPR regardless of where the company is incorporated. The most immediate practical risk is the obligation to appoint an EU representative under GDPR Article 27, if the company has no establishment in the EU. Failure to appoint a representative is itself an infringement that UODO can act on directly. Beyond representation, the company must maintain records of processing activities, respond to data subject requests within the statutory timeframes, and notify UODO of breaches within 72 hours. UODO has the power to impose fines on non-EU companies and to request cooperation from supervisory authorities in the company';s home jurisdiction. The absence of a Polish entity does not create a safe harbour.

How long does a UODO investigation typically take, and what does it cost to respond?

UODO investigations vary considerably in duration depending on complexity. A straightforward complaint-based investigation may conclude within several months. A complex ex officio investigation involving multiple processing activities, cross-border transfers and technical evidence can extend to well over a year. The cost of responding depends on the scope of the investigation and the volume of documentation requested. Professional fees for legal representation and technical assistance in a significant UODO investigation typically run from the mid-thousands to the low tens of thousands of EUR, depending on the complexity of the matter. Fines, where imposed, are calculated as a percentage of global annual turnover and can reach substantial amounts for serious infringements. Investing in preventive compliance is generally far less expensive than managing an enforcement action.

Should a business in Poland appoint an internal Data Protection Officer or use an external DPO service?

The obligation to appoint a Data Protection Officer under GDPR Article 37 applies to public authorities, organisations that carry out large-scale systematic monitoring of individuals, and organisations that process special categories of data on a large scale. Many businesses in Poland fall outside these categories and are not legally required to appoint a DPO. However, UODO';s current enforcement posture makes a voluntary DPO appointment a sensible risk-management measure for any business processing significant volumes of personal data. The DPO can be an employee or an external service provider. External DPO services are widely available in Poland and offer flexibility for smaller businesses. The key requirement is that the DPO must have expert knowledge of data protection law, must be independent, and must have access to senior management. A DPO who is also the company';s legal counsel or IT manager may face conflicts of interest that undermine the role';s effectiveness.

Conclusion

Poland';s data protection environment has become more demanding across enforcement, legislative and regulatory dimensions. UODO is pursuing a broader range of organisations, applying stricter standards to transfer mechanisms and AI-related processing, and treating procedural gaps - missing DPIAs, outdated DPAs, delayed breach notifications - as substantive compliance failures. Businesses that have not reviewed their compliance programmes recently face meaningful enforcement risk.

VLO Law Firms advises international clients on data protection matters in Poland. We can assist with DPIA preparation, data processing agreement review, transfer impact assessments, UODO investigation response, and DPO support. To request a consultation, contact: info@vlolawfirm.com