World Watch/Poland/Data & Privacy

Data & Privacy · Poland

Data protection & privacy laws in Poland (2026)

Comprehensive lawEU GDPR (Regulation 2016/679) as directly applicable law, implemented nationally by the Personal Data Protection Act of 10 May 2018 (Ustawa o ochronie danych osobowych); supervised by the President of the Personal Data Protection Office (Prezes UODO).Country index 93 · A+

Poland shaded by its data & privacy status

As an EU member state, Poland applies the General Data Protection Regulation (GDPR) directly, supplemented by the national Personal Data Protection Act of 10 May 2018, which entered into force on 25 May 2018 and exercises the GDPR's national-discretion options. The independent supervisory authority is the President of the Personal Data Protection Office (UODO), which replaced the former Inspector General (GIODO) and actively enforces the regime, issuing roughly 2,000 administrative decisions per year, including several record fines in 2025.

Key points

Comprehensive GDPR-based regime

Poland is bound by the directly applicable EU GDPR, with national specifics set out in the Personal Data Protection Act of 10 May 2018. The Act fully incorporated the GDPR and addressed areas left to member-state discretion (e.g., the supervisory authority's structure and powers).

Supervisory authority (UODO)

The independent supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, PUODO), based in Warsaw. The President is appointed by the Sejm with the Senate's consent for a four-year term; the office replaced the former GIODO when the 2018 Act took effect.

Data subject rights

Individuals in Poland enjoy the full set of GDPR rights: access, rectification, erasure, restriction of processing, data portability, objection, and protection against solely automated decision-making. Rights are exercised directly against the data controller.

Controller obligations / breach notification

Controllers must notify a personal data breach to UODO within 72 hours of becoming aware of it (unless unlikely to risk individuals' rights), and must communicate high-risk breaches to affected individuals. Standard GDPR duties on lawful basis, transparency, security and DPO appointment apply.

National-discretion specifics

The 2018 Act sets the child's consent age for information-society services at 16, caps administrative fines on public bodies at PLN 100,000, and requires notification of a Data Protection Officer (DPO) to UODO within 14 days of designation.

Active enforcement

UODO issues about 2,000 administrative decisions annually and has imposed major fines, including a record PLN 27 million on Poczta Polska (March 2025, presidential-election data) and PLN 18.4 million on ING Bank Śląski (2025), demonstrating a maturing, robust enforcement posture.

Timeline - major decisions & events

Mar 31, 2026law
Council of Ministers Adopts Draft AI Systems Act — New AI Supervisory Authority Proposed

Poland's government approved a bill to create a dedicated national AI supervisory authority and transpose the EU AI Act into domestic law, forwarding it to Parliament for enactment. Poland is one of the first EU states to propose a single, purpose-built institution for AI oversight rather than assigning the role to an existing body.

Digital Policy Alert
Oct 1, 2025decision
Supreme Administrative Court Rules IP Addresses and Cookie IDs Are Not Automatically Personal Data

Poland's Naczelny Sąd Administracyjny held that UODO must affirmatively demonstrate that an individual is identifiable — within the meaning of Article 4(1) GDPR — before classifying IP addresses or cookie identifiers as personal data. The ruling imposes a higher evidentiary burden on the regulator and constrains blanket cookie-consent enforcement.

International Network of Privacy Law Professionals (INPLP)
Aug 27, 2025enforcementofficial
ING Bank Śląski Fined €4.375 Million for Systematically Scanning Customer Identity Documents

UODO penalised ING Bank Śląski PLN 18.4 million (~€4.375 million) for scanning the identity cards of approximately 4.7 million customers and prospective customers without verifying whether each scan was legally required under the AML Act, violating Articles 5(1)(a,b,c) and 6(1) GDPR. The case exposed widespread over-collection of biographic data in Polish retail banking.

European Data Protection Board
Mar 18, 2025enforcementofficial
Record Fine: Poczta Polska Penalised PLN 27 Million for 2020 Postal-Election PESEL Data Transfer

UODO imposed its largest-ever fine — PLN 27,124,816 (~€6.44 million) on state postal operator Poczta Polska and PLN 100,000 on the Minister of Digitization — for unlawfully receiving and processing PESEL register data covering ~30 million adult citizens to organise a COVID-era postal presidential election without a valid legal basis under Articles 5(1)(a) and 6(1) GDPR. The case set a precedent that executive-directed emergency data transfers are not exempt from GDPR.

European Data Protection Board
Sep 1, 2024enforcement
mBank Fined for Failure to Notify Data Subjects of Personal Data Breach

UODO issued a significant fine against mBank S.A. for breaching Article 34 GDPR by failing to communicate a personal data breach directly to affected individuals, continuing the authority's intensified focus on breach-notification obligations as a standalone compliance requirement distinct from the 72-hour regulator notification rule.

CMS Expert Guide — Data Protection and Cybersecurity: Poland
Apr 1, 2024enforcement
Santander Bank Polska Fined PLN 1.44 Million for Data Breach Notification Failure

UODO penalised Santander Bank Polska S.A. (~€344,498) for not reporting a breach in which a parcel containing bank documents — including PESEL numbers, credentials, and ID data — was lost, in violation of the 72-hour notification requirement under Article 33 GDPR. The case reinforced that physical document losses trigger the same notification obligations as digital breaches.

ICLG — Data Protection Laws & Regulations: Poland 2025-26
Jan 1, 2023enforcementofficial
UODO Fines P4 (Play) Telecom Operator for Failure to Notify Personal Data Breach

UODO imposed an administrative fine on P4 Sp. z o.o. (mobile network Play) for failing to notify the supervisory authority of a personal data breach within 72 hours as required by Article 33 GDPR, signalling that the authority would treat notification-deadline breaches as a standalone, fining-worthy violation.

European Data Protection Board
Mar 26, 2019enforcementofficial
Poland's First GDPR Fine: Bisnode Penalised ~€220,000 for Failure to Inform Data Subjects

UODO issued Poland's inaugural GDPR enforcement decision against Bisnode, a data-analytics firm that scraped 7.6 million business records from public registries but notified only ~700,000 individuals, citing the cost of postal outreach as disproportionate; the authority rejected that argument and ordered contact with the remaining ~6 million people. The ruling established that financial inconvenience does not excuse Article 14 transparency obligations.

European Data Protection Board
Feb 21, 2019lawofficial
Sectorial Amendments Act Completes Poland's GDPR Incorporation

Parliament enacted the Act of 21 February 2019 amending over 160 sector-specific statutes — covering health, employment, scientific research, and financial services — to align them with GDPR and exercise Member State discretions. Together with the 2018 PDPA, it closed the formal transposition of the GDPR into Polish law.

Internetowy System Aktów Prawnych (ISAP) — Polish Official Legislative Journal
Aug 29, 1997lawofficial
Poland's Foundational Personal Data Protection Act Enacted — GIODO Created

Poland enacted its first comprehensive data-protection statute to transpose EU Directive 95/46/EC, establishing the Inspector General for Personal Data Protection (GIODO) as supervisory authority and setting foundational rules on lawful processing, data subjects' rights, and cross-border transfers. The Act governed Polish data protection for over two decades until superseded by the PDPA 2018.

EU Agency for Fundamental Rights (FRA)

Poland - other topics

Last verified 5/23/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →