Poland';s regulatory landscape has shifted considerably in recent months, with new obligations touching corporate governance, employment, data protection, environmental compliance, and financial services. Businesses operating in Poland - whether locally incorporated or through a branch or representative office - face a more demanding compliance environment than at any point in the past decade. This guide maps the key legislative and regulatory developments, explains what each change means in practice, identifies the authorities responsible for enforcement, and outlines the steps companies should take to stay compliant. It covers corporate and commercial law amendments, labour and social-security updates, data and digital regulation, environmental and ESG obligations, and financial-sector requirements.
Corporate and commercial law: recent amendments affecting Poland regulatory 2026
The National Court Register (Krajowy Rejestr Sądowy, KRS) has continued its digitalisation programme, and the obligations that flow from it have become more demanding for foreign-owned entities. All limited liability companies (spółka z ograniczoną odpowiedzialnością, sp. z o.o.) and joint-stock companies (spółka akcyjna, S.A.) are now required to file annual financial statements exclusively through the electronic portal linked to the KRS. Paper submissions are no longer accepted, and the deadline for filing approved financial statements remains 15 months from the end of the financial year, but the approval meeting itself must be held within six months of year-end. Failure to file on time triggers automatic notifications to the tax authority and can result in the KRS initiating compulsory dissolution proceedings.
The Commercial Companies Code (Kodeks spółek handlowych, KSH) has been amended to strengthen the duties of management board members in relation to related-party transactions. Under the current rules, any transaction between a company and a related party that exceeds a defined materiality threshold must be disclosed to the supervisory board or, where no supervisory board exists, to the shareholders. The amendment introduces a cooling-off mechanism: the transaction cannot be executed until the supervisory body has either approved it or allowed a specified review period to lapse without objection. A common mistake among foreign founders is assuming that informal group-level approvals satisfy this requirement - they do not. Polish law requires a formal resolution recorded in the minutes of the competent body.
Beneficial ownership reporting under the Central Register of Beneficial Owners (Centralny Rejestr Beneficjentów Rzeczywistych, CRBR) has also been tightened. Entities must now update their CRBR entries within seven days of any change in beneficial ownership, down from the previous 14-day window. Trusts and similar arrangements with a Polish nexus are subject to separate registration obligations. Non-compliance carries administrative fines that can reach significant sums, and the register is publicly accessible, meaning that errors or omissions are visible to counterparties and regulators alike.
Labour law and social security: what employers must address now
The Labour Code (Kodeks pracy) has seen a cluster of amendments that affect hiring practices, working-time arrangements, and termination procedures. The most operationally significant change relates to remote and hybrid work. Employers must now maintain a written remote-work policy that specifies the conditions under which remote work is permitted, the equipment provided by the employer, the reimbursement mechanism for home-office costs, and the inspection rights of the employer. Policies that pre-date the current rules and have not been updated are technically non-compliant, even if the underlying arrangements function smoothly in practice.
Parental leave entitlements have been expanded in line with the EU Work-Life Balance Directive. Fathers and second parents now have a non-transferable entitlement to a defined period of parental leave that cannot be waived by agreement. Employers who fail to accommodate these requests face claims before the labour court (sąd pracy) and potential liability for compensation. In practice, founders should consider updating their HR documentation proactively rather than waiting for an employee to raise a formal request.
Social Insurance Institution (Zakład Ubezpieczeń Społecznych, ZUS) reporting requirements have been updated to require more granular data on employment contracts, civil-law contracts (umowy zlecenia and umowy o dzieło), and B2B arrangements. The ZUS has increased audit activity targeting companies that engage individuals on B2B terms where the economic reality resembles an employment relationship. Reclassification of such arrangements results in back-payment of social contributions, interest, and penalties. Many underestimate the retroactive scope of ZUS audits, which can extend back several years.
The minimum wage has been adjusted upward in line with the statutory indexation mechanism. Employers must ensure that all remuneration structures - including those with a base salary supplemented by variable components - meet the minimum wage floor on a monthly basis, not merely on average. A non-obvious requirement is that certain allowances and bonuses are excluded from the minimum wage calculation, meaning that a package that appears compliant on paper may fall short when the excluded components are stripped out.
Data protection and digital regulation: enforcement and new obligations
Poland';s data protection authority, the Personal Data Protection Office (Urząd Ochrony Danych Osobowych, UODO), has intensified enforcement activity and issued a series of decisions that clarify - and in some cases expand - the practical obligations of data controllers. The GDPR remains the primary framework, but the UODO';s recent decisions have addressed specific Polish-market practices, including the use of employee monitoring tools, the processing of health data by HR platforms, and the conditions under which consent can serve as a lawful basis for marketing communications.
Employee monitoring - covering keystroke logging, screen capture, GPS tracking of company vehicles, and email monitoring - is now subject to explicit requirements under both the Labour Code and the UODO';s guidance. Employers must inform employees in advance of the nature, scope, and purpose of monitoring. The information must be provided before monitoring begins, not merely included in a general privacy notice buried in the employment contract. A common mistake is treating the data protection notice and the monitoring policy as interchangeable documents - they serve different legal functions and must be maintained separately.
The EU';s Digital Services Act (DSA) and Digital Markets Act (DMA) are directly applicable in Poland and have created new obligations for platforms and intermediary service providers operating in the Polish market. While the heaviest obligations fall on very large online platforms, smaller providers are not exempt from the DSA';s transparency and notice-and-action requirements. Polish businesses that operate marketplaces, content platforms, or hosting services should review their terms of service, complaint-handling procedures, and transparency reporting obligations. The competent authority for DSA enforcement in Poland is the Office of Electronic Communications (Urząd Komunikacji Elektronicznej, UKE) in coordination with the European Commission.
The NIS2 Directive has been transposed into Polish law, expanding the scope of cybersecurity obligations to a broader range of sectors and entities. Companies in sectors classified as "essential" or "important" under the transposing legislation must implement risk-management measures, report significant incidents to the national cybersecurity authority (CERT Polska, operating under the National Cybersecurity Centre), and ensure that their supply chains meet defined security standards. The transposition introduces personal liability for management board members who fail to ensure compliance, a provision that has attracted considerable attention from corporate counsel.
If your business is navigating data protection or digital compliance obligations in Poland, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Environmental and ESG obligations: new reporting and due diligence requirements
Poland has transposed the EU';s Corporate Sustainability Reporting Directive (CSRD) into national law, extending mandatory sustainability reporting to a wider population of companies. Large companies that meet defined size thresholds - based on balance sheet total, net turnover, and average number of employees - are now required to include a sustainability statement in their annual report, prepared in accordance with the European Sustainability Reporting Standards (ESRS). The sustainability statement must be audited by a statutory auditor or audit firm. Companies that previously filed only a financial report and a brief management commentary will need to invest significantly in data collection, internal processes, and external assurance.
The EU Corporate Sustainability Due Diligence Directive (CS3D) introduces supply-chain due diligence obligations that will apply to Polish companies above defined thresholds and to non-EU companies with significant Polish-market turnover. The due diligence obligation requires companies to identify, prevent, mitigate, and account for actual and potential adverse impacts on human rights and the environment in their own operations and in those of their business partners. In practice, founders should consider beginning supply-chain mapping now, because the data-gathering exercise is time-consuming and the documentation requirements are detailed.
Environmental permitting under the Environmental Protection Law (Prawo ochrony środowiska) has been updated to reflect revised EU emissions standards. Companies operating industrial installations must review their existing integrated permits (pozwolenia zintegrowane) to confirm that the conditions remain consistent with current best available techniques (BAT) conclusions. Where a permit pre-dates the relevant BAT conclusions, the competent regional environmental authority (marszałek województwa or starosta, depending on the installation type) may initiate a review and impose updated conditions. Failure to comply with permit conditions can result in suspension of operations, which represents a significant operational and financial risk.
Waste management obligations have also been updated. Companies that generate, transport, or process waste must register in the Waste Database (Baza danych o produktach i opakowaniach oraz o gospodarce odpadami, BDO) and submit annual reports. The BDO registration requirement extends to companies that use packaging, which captures a very wide range of businesses. Many underestimate the scope of BDO obligations, particularly companies in the retail, manufacturing, and logistics sectors that have not previously engaged with environmental compliance.
Financial services and AML: compliance obligations for regulated and unregulated entities
The Polish Financial Supervision Authority (Komisja Nadzoru Finansowego, KNF) has updated its supervisory expectations for licensed financial institutions, payment service providers, and investment firms. The most significant development for the broader business community is the expansion of anti-money laundering (AML) obligations under the Act on Counteracting Money Laundering and Financing of Terrorism (Ustawa o przeciwdziałaniu praniu pieniędzy oraz finansowaniu terroryzmu). The act has been amended to bring additional categories of obligated institutions into scope, including certain professional service providers, real estate agents, and high-value goods dealers.
Obligated institutions must maintain and regularly update their AML risk assessments, implement customer due diligence (CDD) procedures calibrated to the assessed risk level, and report suspicious transactions to the General Inspector of Financial Information (Generalny Inspektor Informacji Finansowej, GIIF). The current rules require enhanced due diligence for politically exposed persons (PEPs) and for transactions involving jurisdictions identified as high-risk by the European Commission. A common mistake among newly obligated entities is treating AML compliance as a one-time exercise rather than an ongoing programme that must be reviewed and updated as the risk environment changes.
The EU';s Markets in Crypto-Assets Regulation (MiCA) is now applicable across the EU, including Poland. Crypto-asset service providers (CASPs) operating in Poland must either hold a MiCA authorisation or qualify for a transitional arrangement. The KNF is the competent authority for MiCA authorisation in Poland. Providers that previously operated under the Polish virtual asset service provider (VASP) registration regime must assess whether their activities require a full MiCA licence and, if so, initiate the authorisation process. The transition period is finite, and applications take time to process, so early engagement with the KNF is advisable.
Payment institutions and electronic money institutions supervised by the KNF face updated capital adequacy and operational resilience requirements under the Digital Operational Resilience Act (DORA). DORA applies directly in Poland and requires in-scope entities to implement ICT risk-management frameworks, conduct regular resilience testing, and manage third-party ICT risks. The obligations extend to critical ICT service providers, meaning that cloud providers and other technology vendors serving Polish financial institutions are also within scope.
Frequently asked questions
What are the most immediate compliance actions for a foreign-owned sp. z o.o. in Poland?
The most pressing actions are confirming that the CRBR entry is current and reflects any recent ownership changes, verifying that the annual financial statement has been filed electronically with the KRS within the required timeframe, and reviewing the remote-work policy to ensure it meets the current Labour Code requirements. Foreign owners often overlook the CRBR update obligation when restructuring at the group level, because the Polish entity';s register entry does not update automatically when the foreign parent changes hands. The KRS digitalisation requirements also mean that any management board changes must be filed electronically, and the authorised signatory for the e-filing portal must be designated in advance. Engaging a local legal or compliance adviser before a restructuring closes is the most effective way to avoid gaps.
How long does it take to implement NIS2 compliance, and what does it cost at a general level?
The implementation timeline depends heavily on the starting point. A company that already has an ISO 27001-certified information security management system may need only a gap analysis and targeted remediation, which can be completed in a matter of weeks. A company with no formal cybersecurity programme may require several months of work to implement the required risk-management measures, incident-reporting procedures, and supply-chain security controls. Costs vary widely based on company size, sector, and existing infrastructure. At a general level, mid-sized companies should budget for professional advisory fees in the low to mid tens of thousands of euros, plus internal resource costs. The personal liability provision for management board members makes early engagement with qualified cybersecurity and legal advisers a sound investment.
Does MiCA affect Polish companies that use crypto assets for treasury or payment purposes but are not crypto-asset service providers?
MiCA';s authorisation requirements apply to entities that provide crypto-asset services as a business activity - that is, on a professional basis for third parties. A company that holds crypto assets on its own balance sheet for treasury purposes, or that accepts crypto payments from customers without providing custody or exchange services to third parties, is generally not required to obtain a MiCA authorisation. However, such companies remain subject to AML obligations under the Polish AML Act if their activities bring them within the definition of a VASP or an obligated institution. They must also consider the accounting and tax treatment of crypto assets under Polish law, which has been the subject of recent guidance from the Ministry of Finance. If the business model is at all ambiguous, a formal legal opinion is advisable before concluding that no authorisation is required.
Conclusion
Poland';s regulatory environment is evolving rapidly across multiple domains simultaneously. Companies that address each change in isolation risk missing the cumulative compliance burden. A coordinated review - covering corporate, employment, data, environmental, and financial obligations - is the most efficient approach and reduces the risk of gaps that attract regulatory attention.
VLO Law Firms advises international clients on regulatory compliance and legal matters in Poland. We can assist with CRBR and KRS filings, Labour Code policy updates, NIS2 and DORA gap analyses, CSRD reporting preparation, AML programme reviews, and MiCA authorisation assessments. To request a consultation, contact: info@vlolawfirm.com