Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
cite Regulation (EU) 2016/679, Art. 9(1); Ustawa z 10 maja 2018 r., Art. 107(2); Kodeks pracy, Art. 22(1b)
stage In effect
since 2018-05-25
source Ustawa z 10 maja 2018 r., Art. 107(2) and Art. 176 (direct read, in-force date)
General Data Protection Regulation (GDPR) Article 9(1) lists biometric data processed for unique identification as a special category.
Poland's own Act Article 107(2), read directly, independently names biometric data processed for unambiguous identification as one of the aggravating categories that raises the criminal penalty ceiling for unlawful processing from two to three years' deprivation of liberty, alongside racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, health data, and sexual life or orientation data.
Article 107(2)'s own in-force date is the Act's general commencement date, 25 May 2018, confirmed by the same direct read of Article 176 already used for this document's comprehensive_regime instrument.
For employees specifically, Kodeks pracy Article 22(1b), read verbatim, permits biometric-data processing on consent only where the employee supplied it on their own initiative, plus a narrow no-consent carve-out for controlling access to particularly sensitive information or specially protected premises; only staff holding written authorization may process it, bound to confidentiality.
This session confirmed the current Kodeks pracy text but not the amending act or the precise date that provision was inserted, so no date is asserted for the Kodeks pracy limb specifically, only for the Act Article 107(2) limb this instrument's effective_date reflects.
What it asks of an app →
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
source GDPR Arts. 33-34
A controller must notify UODO within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. No Poland-specific derogation from this timeline or threshold was identified in the Act's own chapters.
What it asks of an app →
Comprehensive regime
cite Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych, Dz.U. 2018 poz. 1000
stage In effect
since 2018-05-25
source isap.sejm.gov.pl, consolidated text, Arts. 78-108 (direct read, full text)
Poland gives the General Data Protection Regulation (GDPR) domestic effect through the Act of 10 May 2018 on the Protection of Personal Data, read in full from its 48-page consolidated text.
It establishes the Prezes Urzedu Ochrony Danych Osobowych (President of the Personal Data Protection Office, UODO) as supervisory authority with inspection powers (Rozdzial 9, Arts. 78-91), a civil-liability venue for GDPR Article 79/82 claims at the sad okregowy (Rozdzial 10, Arts. 92-100), a two-track administrative-fine regime distinguishing public-finance-sector bodies from other controllers (Rozdzial 11, Arts. 101-106), and its own criminal offenses for unlawful processing and for obstructing a UODO inspection (Arts. 107-108).
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)
stage In effect
since 2018-05-25
source GDPR Arts. 44-49, 83(5)
A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. Reading the Act's operative chapters (Rozdzialy 1-11) end to end found no Poland-specific derogation from this framework.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Arts. 12-23; Ustawa z 10 maja 2018 r., Arts. 92-97
stage In effect
since 2018-05-25
source isap.sejm.gov.pl, Ustawa z 10 maja 2018 r., Arts. 92-97 (direct read)
General Data Protection Regulation (GDPR) Articles 12-23 govern access, rectification, erasure, restriction, portability, objection, and Article 22 automated-decision rights, exercisable against the controller.
Poland's Act adds the enforcement forum, confirmed by direct read: a GDPR Article 79 or Article 82 claim is heard by the sad okregowy, UODO must be notified of any such filing and final judgment (Art. 94), proceedings are stayed if UODO has an open matter on the same violation (Art. 95), and a final UODO decision or court ruling finding a violation binds a later damages court on that finding (Art. 97).
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Art. 83; Ustawa z 10 maja 2018 r., Arts. 98, 101-108
stage In effect
since 2018-05-25
source isap.sejm.gov.pl, Ustawa z 10 maja 2018 r., Arts. 101-108, 98 (direct read)
UODO is Poland's supervisory authority. The Act creates a distinct two-track fine structure, confirmed by direct read: Article 101 lets UODO fine any controller other than a public-finance-sector unit, research institute, or the National Bank of Poland under ordinary General Data Protection Regulation (GDPR) Article 83 terms, while Article 102 caps fines for those three categories at 100,000 or 10,000 PLN.
GDPR Article 82 arms an individual with a direct private right of action, and Article 98 gives UODO its own standing to bring or join a data subject's civil claim, with that person's consent, at any procedural stage.
What it asks of an app →