TerraLex Cross-Border Guide to Global Crisis Management Regulatory Guide

Welcome to the TerraLex global crisis management regulatory guide

When a crisis hits your organisation, you need to take action quickly. What practical steps can you and your team take to minimize the impact on your business? What are your reporting requirements in the relevant jurisdiction(s)? What legislation applies there?

Our guide provides you with the answers to these questions in relation to key jurisdictions and it supports your understanding of the relevant local legal framework. It also provides high level practical guidance for those crucial first 72 hours, together with contact details of the local TerraLex firm for when you need specialist advice.

A crisis, by its nature, is both serious and unexpected and your response and actions within the first 72 hours will most likely define its impact on your organisation.

It is therefore important to have in place robust procedures that, if followed, will help minimize the adverse consequences.

The crisis checklist below includes next steps which are common across all jurisdictions. Please refer to the chapter for the relevant jurisdiction for more detailed guidance on your obligations in that country.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Poland Global Crisis Management Regulatory Guide Guide

Date posted:
23/01/2025
Last update:
27/02/2025

Data breach

On discovering a data breach, which regulators or other government agencies should be notified?

As stated in Article 33(1) of the Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance) (the “GDPR” or the “Regulation”), data breaches resulting in a risk of infringement of the rights or freedoms of natural persons, must be notified by controllers to the national supervisory authority, which in Poland is the President of the Personal Data Protection Office (pl, Prezes Urzędu Ochrony Danych Osobowych) (the “Data Protection Office” or “DPO”).

The Data Protection Office is competent to lead any investigations related to actual and suspected data breaches as well as to issue administrative decisions in this regard, including imposing administrative fines.

In Poland, notifications of data breaches are made traditionally (via mail) or electronically (via the Data Protection Office's website).

In some cases, a data breach may result in action being taken by other Polish authorities such as the President of the Office of Competition and Consumer Protection (“UOKiK”) or the President of the Office of Electronic Communications.

What legislation, relating to both criminal offences and civil wrongs, covers such a breach?

Criminal offences In Poland, criminal liability for data breaches is governed by the Act of 10 May 2018 on the Protection of Personal Data (the “Personal Data Protection Act”).

According to Articles 107 and 108 of the Personal Data Protection Act, criminal liability arises in the following cases:

  • the processing of personal data is unlawful;
  • the processing of personal data is carried out by a person who is not authorized to do so;
  • preventing or obstructing a controller from conducting an inspection of compliance with data protection regulations, or failing to provide data necessary to determine the basis for an administrative fine, or providing data that makes it impossible to determine the basis for an administrative fine.

The above offenses are punishable by a fine, restriction of freedom or imprisonment for up to two years.

In addition, data breaches may also be considered crimes under Chapter XXXIII of the Criminal Code of 6 June 1997 (the “Criminal Code”) penalizing crimes against information protection.

Unauthorized disclosure or use of processed personal data in connection with your function will incur liability under Article 266 of the Penal Code. Gaining unauthorized access to personal data as a result of a security breach will incur liability under Article 267 of the Criminal Code. Obstructing an authorized person from learning this information may exhaust the elements of a crime under Article 268 of the Criminal Code.

In addition, for example, an employer who, despite the lack of specific legal grounds, requests and processes criminal record data from an employee candidate may also incur criminal liability under Article 25 of the National Criminal Register Act of 20 August 1997.

Civil wrongs First of all, in case of any wrongs, the data subject can file a complaint with the supervisory authority, i.e. the DPO.

Regardless of filing a complaint with the DPO, the data subject can raise civil claims. Here, the GDPR provides for two types of actions. The first concerns the restoration of the lawful state of affairs, i.e. the cessation of violations (whether as a result of taking or not taking certain actions). The second is an action for damages. Under Article 82 of the GDPR, any person who has suffered pecuniary or non-pecuniary damage as a result of a violation of this regulation has the right to obtain compensation from the controller or processor for the damage suffered.

In addition, the data subject may bring an action for the protection of personal rights under Article 24 of the Civil Code of 23 April 1964.

"Dawn" raids

What agencies have the power to conduct dawn raids on private sector companies? What legislation gives those agencies the power to undertake those inspections?

In Poland, different authorities have the power to conduct dawn raids on private companies’ premises depending on the subject of the investigation. These include:

  • President of the Office of Competition and Consumer Protection (pl., Prezes Urzędu Ochrony Konkurencji i Konsumentów) with regard to the competition infringement in accordance with the Act of 16 February 2007 on Protection of Competition and Consumers;
  • Chief of National Revenue Administration (pl., Szef Krajowej Administracji Skarbowej) with regard to the customs and revenue control in accordance with the Act of 4 April 2019 on National Revenue Administration;
  • National Labour Inspectorate (pl., Państwowa Inspekcja Pracy) with regard to occupational safety and health rules and regulations, as well as regulations on legality of employment and other paid work in accordance with the Act of 13 April 2007 on National Labour Inspectorate;
  • National Sanitary Inspectorate (pl., Główny Inspektorat Sanitarny) with regard to compliance with regulations defining hygiene and health requirements in accordance with the Act of 14 March 1985 on the National Sanitary Inspectorate;
  • President of the Personal Data Protection Office (pl., Prezes Urzędu Ochrony Danych Osobowych) with regard to personal data processing in accordance with the GDPR and the Personal Data Protection Act;
  • Office of the Public Prosecutor (pl., prokuratura) with regard to criminal offences in accordance with the Act of 6 June 1997 on the Criminal Procedure Code;
  • Financial Supervision Authority (pl., Komisja Nadzoru Finansowego) with regard to overseeing compliance with regulations concerning banking, capital market, insurance market, pension system, payment services, and corporate governance in accordance with the Act of 21 July 2006 on Financial Market Supervision;
  • Chief Inspectorate of Environmental Protection (pl., Główny Inspektorat Ochrony Środowiska) with regard to the implementation of environmental protection obligations in accordance with the Act of 27 April 2001 on Environmental Protection Law.

On what bases, including privilege and/or confidentiality, may organisations refuse to permit the seizure of documents?

As a general rule, companies must comply with the actions carried out during the investigation, which may include the seizure of documents. If this obligation is not fulfilled, the authority leading/conducting the investigation may seek assistance from the Police or use coercive measures. A company can also be fined.

Companies are not allowed to refuse the handover of the documents to authorities during a dawn raid or in the execution of a search warrant, even if they are covered by privileges (e.g., attorney-client, reporter’s, doctor-patient privilege) or contain trade secrets. In principle, the only exceptions are documents that contain information related to the criminal defense, which are explicitly protected from seizure under Polish law,

There are, however, measures in place to protect privileged or confidential documents. When there is a possibility that such documents might be seized, they should be submitted in a sealed package or envelope (persons conducting the search cannot review them). Also, a separate report on the seizure of such documents should be drawn up.

To use the privileged or confidential materials during the investigation, their protection must be waived.

The doctor-patient privilege and the confidentiality of the trade secrets may be waived by the prosecutor (a complaint may be filed against the prosecutor's decision in this regard, along with a request to suspend the execution of the decision).

The attorney-client privilege and the reporter’s privilege may be waived only by the court and only if the facts cannot be otherwise established, and the waiver is necessary for the justice system.

Whistleblowing

What are the circumstances under which an employee is entitled to protection when reporting an alleged wrongdoing?

Poland has adopted a new whistleblowing law to transpose the EU Directive on Whistleblowing into its national legal system – the Act of 14 June 2024 on the Protection of Whistleblowers (the “Whistleblowing Act”).

The Whistleblowing Act establishes rules and procedures designed to protect whistleblowers.

The Whistleblowing Act generally applies to all entities, and some of them have specific obligations to establish an internal reporting procedure, including reporting channels. The latter include:

  • public and private sector entities that employ at least 50 people as of 1 January or 1 July of a given year, and
  • entities operating in the financial sector, regardless of whether they belong to the public or private sector and regardless of the number of employees.

Other entities may establish internal reporting procedures voluntarily.

According to the Whistleblowing Act, a whistleblower is an individual who reports or publicly discloses information about a violation of the law obtained in a work-related context, including:

-employees,

-temporary workers,

-persons performing work on another basis than an employment relationship, including under a civil law contract,

-entrepreneurs,

-commercial proxies,

-shareholders,

-members of corporate bodies,

-a person who performs work under the supervision and direction of a contractor, subcontractor, or supplier,

-trainees or interns, and

-volunteers.

Under the Whistleblowing Act, a whistleblower status also applies to the persons referred to above in the event of a report or public disclosure of an infringement of the law obtained in a work-related context prior to the establishment of the employment relationship, or other legal relationship underlying the provision of work or services, or the performance of functions in or for a legal entity, or the performance of services in or after they have ceased.

According to the Whistleblowing Act, the following infringements of law can be reported:

  1. corruption,

  2. public procurement,

  3. financial services, products, and markets,

  4. anti-money laundering and countering the financing of terrorism,

  5. product safety and compliance,

  6. transport safety,

  7. environmental protection,

  8. radiological protection and nuclear safety,

  9. food and feed safety,

  10. animal health and welfare,

  11. public health,

  12. consumer protection,

  13. protection of privacy and personal data,

  14. security of information and communication networks and systems,

  15. financial interests of the State Treasury of the Republic of Poland, local government units, and the European Union,

  16. the internal market of the European Union, including the public law principles of competition and state aid as well as corporate taxation, and constitutional freedoms and rights of a human being and a citizen - occurring in the relations of an individual with public authorities and not related to the areas indicated in items 1-16 above.

Whistleblowers are protected from the moment of reporting or from the moment of public disclosure, provided that they had reasonable grounds to believe that the information provided was true and it constituted information about a breach of law.

A person who reports or discloses information to the public, knowing that there has been no violation of the law, is subject to a fine, restriction of liberty, or imprisonment for up to 2 years.

What legislative protection does that employee enjoy?

Whistleblowers are protected from any form of retaliation. This means that whistleblowers are protected against unfair treatment such as refusal to hire, termination of employment, demotion, suspension, negative performance evaluations, and any other form of discrimination or harassment. If a whistleblower does suffer from retaliatory actions, they are entitled to compensation.

The Whistleblowing Act also ensures that public disclosure cannot be used as a basis for the whistleblower's liability, including disciplinary or damage liability, provided that the whistleblower had reasonable grounds to believe that the disclosure was necessary to expose the violation according to the law (for more details, see the answer above).

The rights set forth to protect whistleblowers cannot be waived, and any law or agreement that directly or indirectly restricts the right to report or disclose information or that provides for retaliatory measures is considered null and void.

In the case of external reporting, a whistleblower may request certification from the competent authority to confirm their status.

Anti-bribery and corruption

What are the main anti-corruption laws and regulations in your jurisdiction?

In Poland, there are many legal acts aimed at preventing or reducing the risk of corruption and bribery, as well as identifying, detecting, and investigating such crimes. Key legislation regarding corruption and bribery includes:

  1. the Criminal Code, which provides main regulations for penalizing offences in this regard, including accepting and offering benefits in connection with performing public functions (also in a foreign State or an international organisation), influence peddling, exceeding of authority by a public official, and commercial bribery;

  2. the Criminal Procedure Code of 6 June 1997, which regulates the conduct of criminal proceedings;

  3. the Act of 25 June 2010 on Sports, which penalises bribery related to sports competitions;

  4. the Act of 12 May 2011 on the Reimbursement of Medications Foodstuffs for Special Nutritional Purposes and Medical Devices, which prohibits accepting and offering benefits in exchange for activities influencing the level of sales of medications or medical devices subject to reimbursement from public funds;

  5. the Act of 28 October 2002 on the Liability of Collective Entities, which provides sanctions for collective entities for bribery and corruption offenses;

  6. the Act of 9 June 2006 on the Central Anti-Corruption Bureau, which establishes and regulates the functioning of the agency (Centralne Biuro Śledcze - CBA) responsible for identifying, preventing, and detecting crimes and offences, prosecuting the perpetrators as well as controlling, analytical and preventive activities dedicated to combating corruption in public and economic life, particularly in public and local government institutions;

  7. the Act of 21 August 1997 on Limiting the Conduct of Business Activity by Persons Holding Public Functions, which imposes restrictions related to the business activity on persons holding public functions;

  8. the Act of 27 June 1997 on Political Parties, which bans political parties from obtaining financing from commercial law companies, as well as from other business entities;

  9. the Act of 11 September 2019 on Public Procurement Law, which prohibits a natural person who has been finally convicted of bribery from applying for a public contract for a certain period; the same prohibition applies to a legal person if a member of its governing bodies has been convicted of such crime;

  10. the Act of 24 May 2002 on the Internal Security Agency and the Intelligence Agency, which establishes and regulates the functioning of the agency (Agencja Bezpieczeństwa Wewnętrznego - ABW) responsible for monitoring and conducting investigations related to public procurement contracts, privatisation processes, and other cases of high importance for the economic security of the State;

  11. the Act of 7 May 2009 on Certified Auditors and their Government, Entities Authorised to Examine Financial Statements and on Public Supervision, which imposes on a certified auditor an obligation to report any instances in which a public official accepted a financial or personal benefit;

  12. the Act of 17 April 2023 on Combating Money Laundering and the Financing of Terrorism, which penalises failure to notify the competent authority of the facts that may imply a suspicion of committing money laundering or terrorist financing or a substantiated suspicion that a specific transaction or property values being the subject of such transaction could be linked to money laundering or terrorist financing as well as providing the competent authority with inaccurate data concerning transactions, accounts or persons or concealing accurate ones.

Does the legislation have extra-territorial effect?

Yes, but only in cases where the committed criminal act harms the interests of Poland or a Polish citizen/entity.

What are the main enforcement bodies?

Crimes of corruption and bribery are investigated and prosecuted by public prosecutors, who are supervised by the General Public Prosecutor.

The Police also has the authority to conduct criminal investigations.

The investigation of certain types of offences may also be conducted by public agencies, such as the Central Anti-corruption Bureau (CBA) and the Internal Security Agency (ABW).

Internal investigations

Is there any duty to report the issue, for example to a regulator?

In general, there is no legal obligation to self-report.

However, there are certain circumstances in which reporting misconduct to enforcement authorities is mandatory.

This obligation arises in cases involving specific criminal offences (i.e., crimes prosecuted ex officio), including in particular crimes against life and health as well as drug crimes. This obligation is imposed on both legal entities (as a legal obligation) and individuals (as a social obligation, which means that there is no penalty for its violation, except for the most serious crimes, in which case anyone who has credible knowledge of their preparation, attempt or execution, has a legal obligation to report them).

Additionally, entities operating in the financial sector, including banks and other financial institutions, are obliged to report any suspicions of money laundering or terrorist financing to the appropriate authorities as part of anti-money laundering and counterterrorism financing regulations. A reporting obligation may also follow from other sector-specific legislation, such as the GDPR.

What is the protection from disclosure for documents generated as part of the investigation (for example, privilege)?

As there is no specific regulation regarding an internal investigation and the documents generated as part of such an investigation, general rules shall apply.

These include, in particular, rules on privileges and trade secrets protection (as described above) as well as rules for handling personal data.

Is the advice given by an in-house lawyer in relation to the investigation privileged and/or confidential?

In Poland, the information provided to and advice given by an in-house lawyer (being an advocate or an attorney-at-law) enjoys the same attorney-client privilege as the advice given by an external counsel. As for the information provided, an in-house lawyer must also comply with the obligation to keep trade secrets confidential.

Sometimes, however, the status of an in-house lawyer can be more complex. For example, if an in-house lawyer is also a member of the management board or a proxy, in which case it may be difficult to distinguish which information should be protected by the attorney-client privilege and which should not.

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.