GDPR Guide

GDPR for Poland

GDPR compliance for companies in Poland — UODO enforcement, Polish data protection law, and requirements for companies with Polish operations or customers.

Data Protection Authority

Urząd Ochrony Danych Osobowych (UODO)

Key Requirements

  • UODO has issued significant fines including Poland's largest GDPR fine (€2.8M to a credit bureau)
  • Poland requires notification of 4+ processing purposes changes to UODO
  • Strong enforcement on credit and debt data processing
  • Polish data subjects are increasingly aware of GDPR rights

Poland's UODO (Urząd Ochrony Danych Osobowych — Personal Data Protection Office) has established itself as a credible enforcement authority with some of the larger GDPR fines in Central Europe. The 2022 fine of PLN 14.8 million (~€3.2M) against a credit information company demonstrated that Polish enforcement is substantive, not symbolic.

Poland has national-level data protection legislation that supplements GDPR, particularly around sensitive data categories and employee data. The Polish Labour Code intersects with GDPR for employee personal data processing — specific rules govern what employers can ask for in job applications and what data can be retained after employment ends.

Credit and financial data processing is heavily regulated in Poland. Credit bureaus and financial institutions face specific UODO scrutiny around accuracy of reported data, data subject rights in credit reporting, and the legal basis for sharing data with third parties. If your product touches credit or payment data for Polish users, this is a priority area.

Data breach notifications to UODO must be filed within 72 hours under GDPR — Polish law doesn't extend this. Importantly, UODO may initiate its own investigation based on breach notifications, even if you notified proactively. Having detailed documentation of the breach scope, root cause, and remediation ready at notification time is important.

For international companies entering the Polish market, note that UODO conducts inspections and can audit companies with Polish data subjects even without a complaint — particularly for sectors like fintech, healthcare, and e-commerce.

Check your GDPR compliance now

Free 5-minute self-assessment — score your GDPR controls across lawful basis, data subject rights, security, and breach notification.

Run free GDPR compliance check →