{
 "jurisdiction_id": "PL",
 "jurisdiction": "Poland",
 "url": "https://dataprotection.gi/jurisdictions/poland/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 37,
  "sub_modules": 57,
  "source_register": 16
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/poland/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Mature, non-derogating GDPR implementation with an active, well-resourced single supervisory authority and 8 years of enforcement practice.",
   "claims": [
    {
     "statement": "UODO's President is the competent GDPR supervisory authority in Poland, with powers to conduct compliance audits, issue administrative decisions and publish guidance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act of 10 May 2018 on the Protection of Personal Data implements the GDPR in Poland and does not contain major derogations from the Regulation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As a non-derogating GDPR implementation, Poland's material scope of protected processing mirrors GDPR Article 2 (automated processing and structured filing systems).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Poland's territorial scope of application to non-established controllers mirrors GDPR Article 3, extending to entities targeting or monitoring data subjects in Poland.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Controllers and processors must notify the appointment of a DPO to PUODO within 14 days of the appointment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/poland-notification-of-a-dpo-to-the-supervisory-authority",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/poland/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "GDPR-aligned lawful basis and consent framework with active enforcement precedent; anonymisation/pseudonymisation guidance is comparatively thin.",
   "claims": [
    {
     "statement": "Data controllers in Poland must rely on one of the GDPR Article 6 lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interests) to process personal data lawfully.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UODO fined a company over PLN 201,000 for obstructing the exercise of the right to withdraw consent, finding that withdrawal mechanisms must be as easy as giving consent under Article 7(3) GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/polish-dpa-withdrawal-consent-shall-not-be-impeded_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UODO's employer's guide sets out restrictive views on collecting candidate and employee data, including that former employers and social media accounts should generally not be used as data sources without specific justification; this guidance is formally non-binding.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/poland-uodos-guidance-data-protection-employment",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/poland/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Full GDPR rights framework in force with confirmed enforcement precedent on erasure/objection; deadlines follow the standard one-month GDPR response window.",
   "claims": [
    {
     "statement": "UODO found that a company unlawfully continued processing personal data of individuals who were not its customers and who had objected to processing, in violation of the right to erasure/'right to be forgotten'.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/polish-dpa-withdrawal-consent-shall-not-be-impeded_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/poland/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Deep, multi-year enforcement record across DPIA/accountability, DPO, ROPA, security, breach-notification and retention obligations confirms these duties are actively supervised and litigated up to appellate courts.",
   "claims": [
    {
     "statement": "UODO found a mayor's office breached the accountability principle (Article 5(2) GDPR) due to shortcomings in its register of processing activities and absence of risk analysis for publication of council meeting recordings.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/polish-supervisory-authority-imposed-first-administrative-fine-public_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The first administrative fine imposed on a Polish public entity (PLN 40,000) included findings that its register of processing activities failed to indicate all data recipients or planned deletion dates.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/polish-supervisory-authority-imposed-first-administrative-fine-public_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Provincial Administrative Court in Warsaw confirmed that a controller remains responsible for the security of personal data processing and cannot shift that responsibility entirely to its processor.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/poland-warsaw-administrative-court-upholds-uodo-fines",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UODO imposed a €645,000 fine on a company for failing to implement technical means of data protection appropriate to risk, breaching the confidentiality principle of Article 5(1)(f) GDPR, after a breach exposed data of about 2.2 million people.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/polish-dpa-imposes-eu645000-fine-insufficient-organisational-and-technical_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A Provincial Administrative Court upheld a PLN 16,000 UODO fine against a company for failing to report a data breach, emphasising the obligation to notify UODO within 72 hours of discovering a breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/poland-court-upholds-uodos-decision-impose-fine",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UODO imposed a further fine of over PLN 85,000 on a healthcare entrepreneur for failing to comply with an order to communicate a personal data breach to affected patients.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2021/polish-dpa-first-fine-non-compliance-administrative-decision-order_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UODO found a public body violated the storage-limitation principle (Article 5(1)(e) GDPR) by retaining property declarations from 2010 despite a statutory 6-year retention period.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/polish-supervisory-authority-imposed-first-administrative-fine-public_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/poland/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Core transfer mechanisms are harmonised and green at EU level, but Poland-specific friction exists around telecom data-retention law that UODO itself has flagged as inconsistent with EU standards, and this evidence set could not source distinct Polish-issued adequacy decisions (correctly, as this is an EU Commission competence).",
   "claims": [
    {
     "statement": "UODO acted as lead supervisory authority under the GDPR one-stop-shop mechanism in a cross-border complaint originally lodged with the German DPA for Rhineland-Palatinate, because the controller company was established in Poland.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/president-personal-data-protection-office-imposes-fine-cross-border_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UODO issued an opinion highlighting the inconsistency of Polish telecommunications data-retention laws with EU standards and associated privacy risks.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/poland/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Health, employment, education and credit-scoring/data-broker sub-sectors show active supervisory engagement; financial-sector-specific and insurance-specific DP overlays were not surfaced in this research pass.",
   "claims": [
    {
     "statement": "UODO fined a healthcare-sector entrepreneur more than PLN 85,000 for failing to comply with an administrative order requiring it to notify affected patients of a personal data breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2021/polish-dpa-first-fine-non-compliance-administrative-decision-order_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A Polish data-broker/business-verification company holding over 7.5 million records was fined approximately €220,000 for failing to provide Article 14 GDPR privacy notices to most affected business owners.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Commission",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?rid=6&uri=CELEX:52020SC0115",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UODO commented on a draft amendment to Poland's Education Law, highlighting privacy concerns and recommending refinements to better protect personal data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/poland/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie/consent and direct-marketing enforcement are well evidenced; dark-pattern enforcement is emerging via UOKiK; opt-out signal, clean-room and cross-context advertising sub-modules lack Poland-specific evidence.",
   "claims": [
    {
     "statement": "UODO has published guidance addressing cookies, alongside guidance on employment data protection and DPIAs.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UOKiK (Poland's Office of Competition and Consumer Protection) is developing AI-based tools to detect and combat dark patterns in online commerce.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/poland/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "AI governance framework is actively in development (draft law, not yet finalised) with UODO's competence recognised but cooperation rules incomplete; biometric/genetic/surveillance-carveout sub-modules lack dedicated Poland-specific evidence.",
   "claims": [
    {
     "statement": "Poland applies GDPR Article 22's restriction on decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects, without national derogation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Poland's Council of Ministers adopted a draft law implementing the EU AI Act, establishing KRiBSI as the national market surveillance authority to supervise AI compliance and support innovation.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Poland's draft AI implementing law recognises UODO's exclusive supervisory competence over high-risk AI systems, but commentary indicates the draft lacks detailed inter-authority cooperation rules and explicit protection of fundamental rights.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/poland/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Age-verification-for-adult-content legislation is a live, not-yet-fully-effective development; the precise Article 8 age-of-consent figure for Poland could not be confirmed with a dedicated primary-source citation in this pass, and minor-profiling-ban / dependent-adult sub-modules lack direct evidence.",
   "claims": [
    {
     "statement": "Poland's Council of Ministers adopted a draft act requiring age verification for online adult content specifically to protect minors.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Because the Act of 10 May 2018 does not contain major derogations from the GDPR, Poland is presumed to apply the GDPR default age of 16 for a child's own consent to information-society services under Article 8, absent an identified national derogation lowering that age.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/poland/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "UODO exhibits sustained, escalating enforcement activity with judicial oversight (both upholding and overturning decisions), indicating a mature and active enforcement ecosystem; collective-redress mechanisms specific to Poland were not confirmed in this pass.",
   "claims": [
    {
     "statement": "UODO's corrective powers include the power to order breach communication to data subjects and to impose administrative fines in addition to or instead of other Article 58(2) GDPR measures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2021/polish-dpa-first-fine-non-compliance-administrative-decision-order_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UODO imposed a PLN 15,000 fine on a company for failing to provide the supervisory authority with access to personal data and information necessary for performance of its tasks in a cross-border complaint.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/president-personal-data-protection-office-imposes-fine-cross-border_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UODO fined the Minister of Justice PLN 100,000 for unlawful access and misuse of judges' personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Provincial Administrative Court in Warsaw overturned UODO's PLN 27 million fine against Poczta Polska concerning personal data processing during the 2020 postal presidential elections.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UODO fined the Nawrocki Presidential Electoral Committee PLN 35,582 for unlawfully disclosing personal data during a press conference.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Between 25 May 2018 and 30 November 2019, Poland's data protection authority was among the highest-volume EU/EEA authorities, registering around 12,000 complaints in that period.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "European Commission",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?rid=6&uri=CELEX:52020SC0115",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Polish administrative courts, including the Provincial Administrative Court in Warsaw and the Supreme Administrative Court, actively review and can uphold or overturn UODO's administrative fine decisions on appeal.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/poland-warsaw-administrative-court-upholds-uodo-fines",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Poland's amended Cybersecurity Act, aligning with the NIS2 Directive and imposing new compliance deadlines and reporting obligations for key and important entities, was signed on 19 February 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Poland's Parliament passed the Data Management Act to ensure full application of the EU Data Governance Act, designating UODO's President as the competent authority.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/poland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}