EnglishPolski
Poland flag

Poland

Poland Data Privacy Laws: GDPR, UODO & 2026 Guide

By Recording Law Editorial TeamReviewed September 9, 202623 min read
Poland Data Privacy Laws: GDPR, UODO & 2026 Guide

Frequently Asked Questions

What is the main data privacy law in Poland?

Poland operates under two parallel instruments: the EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, which is directly applicable across the EU, and the national Act of 10 May 2018 on the Protection of Personal Data. Both entered force on 25 May 2018. The national act supplements the GDPR by establishing UODO, fixing the age of digital consent at 16, capping public-sector fines at PLN 100,000, and providing procedural rules for enforcement and appeals.

What is UODO and what powers does it have?

UODO (Urzad Ochrony Danych Osobowych) is Poland's Office for Personal Data Protection and the country's independent GDPR supervisory authority. Its President holds ministerial rank and is appointed by the Sejm for a renewable four-year term. UODO can conduct inspections, issue binding administrative decisions including orders to cease processing or erase data, and impose fines up to EUR 20 million or 4% of global annual turnover. In 2024, UODO issued 1,719 decisions, received 8,056 complaints, and imposed PLN 13.9 million in fines.

What are the breach notification deadlines in Poland?

Controllers must notify UODO within 72 hours of becoming aware of a personal data breach that poses a risk to individuals' rights and freedoms. Telecommunications providers face a stricter 24-hour deadline. Where the breach creates a high risk for individuals, the controller must also notify affected data subjects without undue delay using clear, plain language. A February 2025 UODO guideline confirmed that the DPO must not be designated as the responsible party for filing breach notifications; that responsibility remains with the data controller.

What are the maximum penalties for GDPR violations in Poland?

Private organizations face fines of up to EUR 20 million or 4% of global annual turnover for serious violations (basic processing principles, consent, data subject rights, international transfers). Lesser violations carry fines up to EUR 10 million or 2% of turnover. Public bodies are capped at PLN 100,000 under Polish national law. Criminal penalties reach up to two years' imprisonment for unauthorized processing, rising to three years for violations involving special-category data. Electronic marketing violations carry fines up to 3% of prior-year revenue.

What is Poland's age of consent for digital services?

Poland set the age of consent for processing children's personal data in information society services at 16 years, the GDPR maximum under Article 8. Some EU member states have lowered this to 13, 14, or 15, but Poland chose the highest permitted threshold. Processing data of children under 16 requires verifiable consent from a holder of parental responsibility.

Does Poland have specific rules for employee monitoring?

Yes. Poland's Labour Code permits video surveillance for employee safety, property protection, production control, and confidential information purposes. Cameras are prohibited in toilets, changing rooms, canteens, rest rooms, and trade union premises. Audio recording through monitoring systems is prohibited because the Labour Code does not provide a legal basis for it. Employers must give employees at least two weeks' notice before implementing monitoring. Email and internet monitoring is permitted but must be disclosed in the employer's workplace regulations.

How is the PESEL number treated under Polish data protection law?

UODO treats the PESEL number, Poland's permanent 11-digit national identification number, as one of the most sensitive categories of personal data. Because PESEL numbers cannot be changed, unauthorized disclosure creates lasting identity fraud risk. The Poczta Polska case (PLN 27 million fine, March 2025) involved the transfer of PESEL numbers for 30 million citizens without a valid legal basis, underscoring UODO's strict approach to PESEL data processing.

How does the EU AI Act interact with Polish data protection law?

The EU AI Act, Regulation (EU) 2024/1689, began applying in stages from 2 August 2024. AI systems using biometric identification, social scoring, employment filtering, and other high-risk applications must comply with both the AI Act's conformity requirements and the GDPR's data protection obligations. Poland's draft national AI Act (adopted by the Council of Ministers on 31 March 2026) proposes a new Commission for AI Development and Security (KRiBSI) as the primary AI supervisory body, while UODO retains a coordination role on data protection matters. The division of authority remained unresolved as of May 2026.

What must organizations do if they appoint a Data Protection Officer in Poland?

In addition to the GDPR's Articles 37-39 requirements, Polish law requires the controller or processor to notify UODO of the DPO appointment, change, or dismissal within 14 days, using the UODO electronic notification form with a qualified electronic signature or ePUAP trusted profile. The DPO's name and contact details must be published on the organization's website immediately. The DPO must report directly to the highest management level; UODO fined Toyota Bank EUR 132,000 in 2024 for placing the DPO in a subordinate reporting structure.

How can data subjects exercise their rights and file complaints in Poland?

Data subjects should first submit a written request to the controller, which must respond within one month. If the controller fails to respond adequately or refuses the request, the data subject can lodge a complaint with the President of UODO. UODO investigates and issues a binding administrative decision. That decision can be challenged before the Voivodeship Administrative Court (WSA), with a further cassation appeal to the Supreme Administrative Court (NSA). Data subjects may also pursue civil compensation for material or non-material damage in civil courts, independently of UODO proceedings.

Updates

AI Act dates updated for the July 2026 Digital Omnibus: high-risk conformity is now required by 2 December 2027 (Annex III) and 2 August 2028 (Annex I); the 2 August 2026 transparency date is unchanged.

Expanded to full audit-and-evolve refresh: added constitutional basis (Articles 47 and 51), 2024 UODO Annual Report statistics (8,056 complaints; PLN 13.9 million in fines), detailed 2025 enforcement record (Poczta Polska PLN 27 million, ING Bank EUR 4.37 million, McDonald''s EUR 4.02 million, mBank PLN 4.05 million), EU AI Act overlay and Poland''s draft national AI Act, updated 2026 inspection priorities, complaint and appeal procedure, and expanded FAQ to 10 questions.

Original publication.

Sources and References

  1. Act of 10 May 2018 on the Protection of Personal Data (English summary)(uodo.gov.pl).gov
  2. UODO Official Website — President of the Personal Data Protection Office(uodo.gov.pl).gov
  3. Data Subject Rights in Poland — UODO(uodo.gov.pl).gov
  4. Designation and position of the DPO — UODO(uodo.gov.pl).gov
  5. UODO Sectoral Inspection Plan for 2025(uodo.gov.pl).gov
  6. President of the Personal Data Protection Office presented the 2024 Annual Report(uodo.gov.pl).gov
  7. UODO Breach Notification Guide(uodo.gov.pl).gov
  8. UODO — PESEL Number Importance(uodo.gov.pl).gov
  9. Administrative Fines for GDPR Infringement During Correspondence Elections (Poczta Polska)(uodo.gov.pl).gov
  10. ING Bank Fine — UODO Decision(uodo.gov.pl).gov
  11. Fine for Toyota Bank for Improperly Located DPO(uodo.gov.pl).gov
  12. Fine for mBank for Failure to Inform Data Breach Victims(uodo.gov.pl).gov
  13. EDPB — McDonald's Polska Fine EUR 4,022,773(edpb.europa.eu).gov
  14. EDPB — ING Bank Slaski Fine EUR 4,375,273(edpb.europa.eu).gov
  15. EDPB — Poczta Polska Election Fine(edpb.europa.eu).gov
  16. EDPB — EUR 132,000 Fine for Improper DPO Positioning(edpb.europa.eu).gov
  17. European Commission — GDPR Adequacy Decisions(commission.europa.eu).gov
  18. European Commission — Standard Contractual Clauses(commission.europa.eu).gov
  19. Regulation (EU) 2016/679 — General Data Protection Regulation(eur-lex.europa.eu).gov
  20. Regulation (EU) 2024/1689 — EU AI Act(eur-lex.europa.eu).gov
  21. DataGuidance — UODO Statement on EU AI Act Implementation(dataguidance.com)
  22. Right to Lodge a Complaint with the President of the Personal Data Protection Office(uodo.gov.pl).gov
  23. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
Share: