TerraLex Guide to Data Protection

Welcome to the Terralex cross-border guide to data protection

Data protection continues to be a top issue for companies around the globe. With the ever-changing technology and responding legislation, it is important that businesses be prepared to handle a patchwork of data protection regulations. This guide, prepared by TerraLex members from around the globe, provides initial guidance on some of the key aspects to consider.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Poland TerraLex Guide to Data Protection Guide

Date posted:
23/08/2022
Last update:
14/04/2025

Legislation and regulations

What national laws regulate the processing of personal data in your jurisdiction?

The main data protection legislation in Poland is the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (the “GDPR”). The GDPR has been implemented in Poland under the Personal Data Protection Act of 10 May 2018 (the “Data Protection Act 2018”) which entered into force on 25 May 2018, thereby repealing the old Personal Data Protection Act of 29 August 1997.

In the following year, Poland has adopted an act of 21 February 2019 amending certain sector-specific acts to ensure further harmonization of national laws with the GDPR (“GDPR Implementation Act 2019”). In total, the 2019 GDPR Implementation Act amended over 160 different acts, including the Telecommunications Act of 16 July 2004, the Electronic Services Act of 18 July 2002, the Payment Services Act of 19 August 2011; the Labour Code of 23 December 1997, the Administrative Procedure Code of 14 June 1960; the Banking Act of 29 August 1997, the Tax Code of 29 August 1997; and the Insurance and Reinsurance Activity Act of 11 September 2015, to name a few.

To whom do the laws apply?

GDPR applies to all businesses and organisations which are responsible for handling personal data in the European Union (and the UK) as well as any organisation using data that was collected within participating states. It does not matter the nationality of the people whose data is processed, where the processing takes place, or where the servers are located.

The GDPR would therefore apply to, e.g.:

  • companies headquartered outside the European Union but carrying out activities within the European Union,
  • entities that offer their services to customers outside the European Union, but have their main headquarters within the European Union,
  • companies that process data via cloud computing (it does not matter where the servers are located),
  • entrepreneurs who perform accounting activities for other companies,
  • entrepreneurs who do not have business units in the European Union but offer goods and services to citizens in the European Union (e.g., an online store).

Scope of protection

What type of data is covered by the law?

The GDPR only applies to personal data, which is any piece of information that relates to an identifiable person. To determine whether a natural person is identifiable all possible means should be used, either by the controller or by another person. Examples of personal data governed by the GDPR include:

  • basic identity information such as name, address, and ID number;
  • web data such as location, IP address, cookie data and RFID tags;
  • health and genetic data;
  • biometric data;
  • racial or ethnic data;
  • political opinions;
  • sexual orientation

What are the main exemptions (if any)?

Some areas have been excluded from the GDPR application. First of all, The GDPR does not apply to law enforcement activities which are instead subject to the Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (Law Enforcement Directive) (the “LED”).

The GDPR also does not apply to areas of law that are outside the scope of Union law, such as national security. Consequently, the GDPR does not cover the activities of special forces as well as the processing of personal data by entities of the public finance sector if such processing is necessary for the execution of tasks that are aimed to ensure national security. The GDPR also does not apply to purely personal or household activity.

Furthermore, the Data Protection Act 2018 excludes (or partially excludes) the application of the GDPR in several other fields. This includes processing of personal data by competent authorities for money laundering prevention, editing, preparing, or publishing press materials, conducting literary or artistic activities, as well as performing public services.

What rights do the laws grant to the data owners?

These are the key rights of the data owners (data subjects): - right to be informed/right to obtain privacy notices;

  • right of access to data/copies of data;
  • right to rectification of errors;
  • right to deletion/right to be forgotten;
  • right to object to or restrict processing;
  • right to data portability;
  • right to withdraw consent;
  • right to object to marketing;
  • right protecting against solely automated decision-making and profiling;
  • right to complain to the relevant data protection authority(ies); and
  • right to erasure.

Processing requirement and main obligations

What are the lawful grounds for processing personal data or sensitive personal data (if different)?

Generally, the lawful grounds for processing of personal data under the Data Protection Act 2018 are the same as under the GDPR. It means that the processing of personal data must comply with all six general data quality principles found in Article 5(1) od the GDPR. Personal data must be therefore:

  1. processed fairly, lawfully and transparently;
  2. collected for specific, explicit, and legitimate purposes and not processed in a manner incompatible with those purposes;
  3. adequate, relevant, and not excessive;
  4. accurate and, where necessary, up to date;
  5. kept in an identifiable form for no longer than necessary;
  6. kept secure.

On the top of that, the controller shall be responsible for, and be able to demonstrate compliance with, all the principles mentioned above (‘accountability’).

The processing of personal data must also satisfy at least one condition for processing personal data. These conditions are that the processing is:

  1. carried out with the data subject’s consent;
  2. necessary for the performance of a contract with the data subject;
  3. necessary for compliance with a legal obligation;
  4. necessary in order to protect the vital interests of the data subject;
  5. necessary for the public interest or in the exercise of official authority; or
  6. necessary for the controller’s or recipient’s legitimate interests, except where overridden by the interests of the data subject.

Sensitive personal data is a special category data including personal data consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person’s sex life or sexual orientation.

Sensitive personal data may only be processed if a condition for processing special category data is satisfied. A condition arises where the processing:

  1. is carried out with the data subject’s explicit consent;
  2. is necessary for a legal obligation in the fields of employment, social security, and social protection law;
  3. is necessary to protect the vital interests of the data subject or another person where the data subject is unable to give consent;
  4. is carried out by a non-profit-seeking body and relates to members of that body or persons who have regular contact;
  5. relates to data made public by the data subject;
  6. is necessary for legal claims;
  7. is for reasons of substantial public interest under European Union or Member State law;
  8. is necessary for healthcare reasons;
  9. is necessary for public health reasons; or
  10. is necessary for archiving, scientific or historical research purposes or statistical purposes and is based on European Union or Member State law.

What are the main obligations imposed by the law?

The main obligations regarding collecting and processing personal data under the Data Protection Act 2018 are generally the same as under the GDPR. They include the following requirements imposed on the collectors (i.e., the entities who determine the purpose and means of processing):

  • the requirement to provide a certain minimum information to data subjects regarding the collection and further processing of their personal data;
  • the requirement to meet legal bases for processing, including: (i) consent of the data subject; (ii) contractual necessity; (iii) compliance with legal obligations; or (iv) legitimate interests (pursued by the controller or by a third party), except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject;
  • the requirement to collect data only for specified, explicit and legitimate purposes;
  • the requirement to maintain appropriate proportions of the scope of data for the purposes of the processing;
  • the requirement to keep the personal data in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed;
  • the requirement to keep a record of processing activities;
  • the requirement of personal data to be adequate, relevant, and limited to what is necessary for relation to the purposes for which the data are processed;
  • the requirement of personal data to be processed in a manner that ensures appropriate security of those data, including protection against unauthorised or unlawful processing and accidental loss, using appropriate technical or organizational measures;
  • the requirement of personal data to be accurate and, where necessary, kept up to date.

Do the laws establish a data retention period to be observed?

Under the GDPR, there are no definitive statutory retention periods regarding data protection, per se. The legislation states that a business should keep information for “no longer than is necessary” for the purpose. This storage limitation principle, however, does not apply to personal data processing concerning journalistic, artistic, or literary activity,

In Poland, there are several statutory minimum or maximum retention periods set out by law with respect to certain types of documents. The retention periods for particular documents, including personal data, include:

  • employee documentation for 10 to 50 years (depending on the particular circumstances);
  • accidents and injury at work documentation for 10 years from making the files;
  • employee CCTV recordings for three months from the date of recording (if the recorded event is subject to further proceedings, as long as the event is fully explained); and
  • tax documentation for five years from the end of the calendar year in which tax payment was due.

In other cases, retention periods must be established based on the above-mentioned GDPR retention principle.

Must the data processing activities be recorded under the law?

Generally, the requirements for recording personal data activities under the Data Protection Act 2018 are the same as under Article 30 of the GDPR. It means that since 25 May 2018 all organizations whose activities fall within the scope of the GDPR must maintain internal records containing information on personal data they collect, where it comes from and how that data is being processed. This obligation, however, does not apply to an enterprise or an organisation employing fewer than 250 persons, unless the processing of data: could cause a risk of infringement of the rights and liberties of data subjects, is not occasional, or includes special categories of personal data or personal data relating to criminal convictions and offences, referred to in Article 10 of the GDPR.

National authority and DPO

Is there a Data Protection National Authority? If so, what is the National Authority main role?

The Data Protection Act 2018 appointed a new national supervisory authority in Poland, namely the President of the Office of Personal Data Protection (the “Polish DPA”). This Polish DPA replaced the Inspector General for Personal Data Protection whose office ceased to exist as of 25 May 2018. The Polish DPA deals with the protection of personal data and complies with the application of the data protection regulation. The Polish DPA also represents Poland on the European Data Protection Board.

The Polish DPA is the main regulator for data protection in Poland. In addition, a violation of rules on direct marketing may result in action being taken by other authorities, such as the President of the Office of Competition and Consumer Protection or the President of the Office of Electronic Communications.

Does the law impose the obligation of designating a data protection officer (DPO)? If so, what is the role of the DPO under the law?

Both controllers and processors (i.e., the entities who just process personal data on behalf of the controller) must appoint a DPO if: 1. they are a public authority, except for courts acting in their judicial capacity 2. their core activities consist of regular and systematic monitoring of data subjects on a large scale; or 3. their core activities consist of processing special category personal data on a large scale (including processing information about criminal offences).

Under the GDPR, a DPO must also be appointed where required by national law. However, Poland has not made such appointments mandatory in the private sector in any additional circumstances.

Cross-border transfers

What rules regulate the transfer of data outside your jurisdiction?

The rules for cross-border transfers of personal data are regulated under Article 44 and following of the GDPR which provides different rules for transferring data within the EEA and transferring data to jurisdictions outside the EEA. These rules indicate that the transfer of personal data from Poland to a processor or controller in another EEA member state must comply with the same requirements as if the transfer was made within Poland, whereas the transfer of personal data from Poland to countries or territories outside the EEA cannot be made unless that third country or territory in that third country provides an adequate level of protection for personal data. At the same time, the GDPR sets forth a number of exceptions to this rule, i.e., situations where data can be transferred outside the EEA without seeking confirmation about an adequate level of protection. Whereas in the case of third countries as to which the European authorities have made no ruling that there are adequate safeguards, personal data may still be transferred to those countries under certain specific circumstances.

In practice, it means that transfers from Poland outside EEA may be made where the European Commission has decided that a given third country, a territory in that third country, or an international organization, ensures adequate safeguards for the protection of data. Currently, these countries are Andorra, Argentina, Canada (commercial organisations), the Faeroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Switzerland, United Kingdom, Uruguay, and South Korea. Alternatively, the controller as transferor could ensure an adequate level of protection through either entering into standard contractual clauses approved by the European Commission for both controller-to-processor and controller-to-controller transfers, or, for transfers within the same group, adopting binding corporate rules. On 4 June 2021, the European Commission issued modernised standard contractual clauses under the GDPR for data transfers from controllers or processors in the EU/EEA to controllers or processors established outside the EU/EEA (the Commission Implementing Decision (EU) 2021/914). These modernized standard contractual clauses have replaced the previous standard contractual clauses adopted under the Data Protection Directive 95/46.

Data can otherwise be transferred if one of the exceptions mentioned above applies. These include the following situations:

  • the data subject has consented to the transfer (as noted above, this consent should be explicit as well as freely given, specific, informed, and unambiguous);
  • the transfer is necessary for the performance of a contract between the data subject and controller, or the implementation of pre-contractual measures taken at the data subject’s request;
  • the transfer is necessary for the conclusion of a contract between the controller and a person other than the data subject, which is entered into in the data subject’s interests;
  • the transfer is necessary for important reasons of public interest;
  • the transfer is necessary for the establishment, exercise or defence of legal claims; or
  • the transfer is necessary to protect the vital interests of the data subject.

Where none of the above situations is the case, a transfer to a third country or an international organisation may still take place if the transfer is not repetitive, concerns only a limited number of data subjects, and is necessary for the purposes of compelling legitimate interests of the controller (which are not overridden by the interests or rights and freedoms of the data subject), and the controller has assessed all the circumstances surrounding the transfer and has, based on that assessment, provided suitable safeguards concerning the protection of personal data.

Is it necessary to notify the National Authority prior to the international transfer?

Under the GDPR, the transfer of personal data to a third country or an international organisation providing for an adequate level of protection approved by the European Commission or appropriate safeguards shall not require any specific authorization from national authorities. However, approval of the Polish DPA is required for corporate rules and administrative arrangements between public authorities or entities governing data transfers.

Security standards, data breaches, and sanctions

Do the laws impose any information security standards and/or requirements?

Yes. The controller and the processor must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The GDPR does not specify measures to be implemented, which means that the burden of choosing an adequate security measure lies with the controller and the processor.

In addition, controllers and processors must ensure, where appropriate:

  1. the pseudonymisation and encryption of personal data;
  2. the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of its information technology systems;
  3. the ability to restore the availability and access to personal data promptly in the event of a physical or technical incident; and
  4. a process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

Also, in some cases, Polish regulations require specific security measures to protect special categories of personal data or criminal conviction data. The main security measures for the processing of special categories of personal data or criminal conviction data are that only persons appropriately authorised in writing who are obliged to maintain confidentiality may process these special categories of data.

Do the laws establish any kind of mandatory notification duty?

Yes. A personal data breach must be notified to the Polish DPA unless the breach is unlikely to result in a risk to the rights and freedoms of the data subject(s). The notification must, where feasible, be made without undue delay (and in any case within 72 hours of becoming aware of the breach – after this term, it needs to be accompanied by reasons for the delay). Under the Data Protection Act 2018, the Polish DPA has created an online system enabling controllers to report personal data breaches in electronic form. If the personal data breach is a high risk for data subjects, those data subjects must also be notified.

The notification must include, i.e.: the nature of the data breach, including the categories and number of data subjects concerned, the likely consequences of the breach and the measures taken to address the breach, including attempts to mitigate possible adverse effects. The Article 29 Working Party has issued Guidelines on Personal Data Breach Notification (WP250) and the European Data Protection Board has issued Examples regarding Personal Data Breach Notification (1/2021).

Specific laws regarding notice of breach apply to the electronic communications sector under national laws implementing the Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) and to operators of essential services and digital service providers under national laws implementing the Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union.

What are the sanctions for noncompliance with data protection laws?

The GDPR introduces a sanction regime with different fines depending on which provisions were violated: up to 4% of annual worldwide turnover or €20m, whichever is the greater, in case of, for example, failing to comply with the six general data quality principles or carrying out processing without satisfying a condition for processing personal data;

up to 2% of annual worldwide turnover or €10m, whichever is the greater, in case of, for example, failing to notify a personal data breach, failing to appoint a DPO where required, or failing to put an adequate contract in place.

Article 29 Working Party has issued Guidelines on administrative fines (WP253).

As for national regulations, the Data Protection Act 2018 lowers the level of the said fines for public authorities to 100,000 PLN (approximately EUR 25,000). The Data Protection Act 2018 also introduces criminal fines that can be imposed on an individual as a result of a criminal conviction for criminal offences related to data protection. Their value of these fines is determined by the Polish Criminal Code.

Other comments

Other comments

N/A.

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.