Law note · Poland
Act on the Protection of Personal Data of 10 May 2018
Poland gives the General Data Protection Regulation (GDPR) domestic effect through the Act of 10 May 2018 on the Protection of Personal Data, read in full from its 48-page consolidated text.
It establishes the Prezes Urzedu Ochrony Danych Osobowych (President of the Personal Data Protection Office, UODO) as supervisory authority with inspection powers (Rozdzial 9, Arts. 78-91), a civil-liability venue for GDPR Article 79/82 claims at the sad okregowy (Rozdzial 10, Arts. 92-100), a two-track administrative-fine regime distinguishing public-finance-sector bodies from other controllers (Rozdzial 11, Arts. 101-106), and its own criminal offenses for unlawful processing and for obstructing a UODO inspection (Arts. 107-108).
What it asks of an app
- Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Poland; the Act adds no Polish derogation to the Article 6 list.
- Expect a criminal offense under Act Article 107 or 108 to attach to unlawful processing or to obstructing a UODO inspection, on top of GDPR's own administrative-fine exposure.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot
Primary source: isap.sejm.gov.pl, consolidated text, Arts. 78-108 (direct read, full text)