Law / Poland

Poland

privacy

Poland's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic institutional and procedural effect by the Act of 10 May 2018 on the Protection of Personal Data. The Act establishes UODO as supervisory authority with a two-track administrative-fine structure, a civil-liability venue for GDPR claims, and its own criminal offenses for unlawful processing.

A separate Kodeks pracy provision restricts employer use of employee biometric data to consent given on the employee's own initiative, plus a narrow no-consent carve-out for protecting sensitive information or specially protected premises. No UODO enforcement decision on facial recognition or voiceprints specifically was located in this pass.

12 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

GDPR Article 9, Act Article 107(2), and Kodeks Pracy Article 22(1b), Biometric Data

cite Regulation (EU) 2016/679, Art. 9(1); Ustawa z 10 maja 2018 r., Art. 107(2); Kodeks pracy, Art. 22(1b) stage In effect since 2018-05-25 source Ustawa z 10 maja 2018 r., Art. 107(2) and Art. 176 (direct read, in-force date)

General Data Protection Regulation (GDPR) Article 9(1) lists biometric data processed for unique identification as a special category.

Poland's own Act Article 107(2), read directly, independently names biometric data processed for unambiguous identification as one of the aggravating categories that raises the criminal penalty ceiling for unlawful processing from two to three years' deprivation of liberty, alongside racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, health data, and sexual life or orientation data.

Article 107(2)'s own in-force date is the Act's general commencement date, 25 May 2018, confirmed by the same direct read of Article 176 already used for this document's comprehensive_regime instrument.

For employees specifically, Kodeks pracy Article 22(1b), read verbatim, permits biometric-data processing on consent only where the employee supplied it on their own initiative, plus a narrow no-consent carve-out for controlling access to particularly sensitive information or specially protected premises; only staff holding written authorization may process it, bound to confidentiality.

This session confirmed the current Kodeks pracy text but not the amending act or the precise date that provision was inserted, so no date is asserted for the Kodeks pracy limb specifically, only for the Act Article 107(2) limb this instrument's effective_date reflects.

What it asks of an app

Breach notification

GDPR Articles 33-34, Breach Notification

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source GDPR Arts. 33-34

A controller must notify UODO within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. No Poland-specific derogation from this timeline or threshold was identified in the Act's own chapters.

What it asks of an app

Comprehensive regime

Act on the Protection of Personal Data of 10 May 2018

cite Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych, Dz.U. 2018 poz. 1000 stage In effect since 2018-05-25 source isap.sejm.gov.pl, consolidated text, Arts. 78-108 (direct read, full text)

Poland gives the General Data Protection Regulation (GDPR) domestic effect through the Act of 10 May 2018 on the Protection of Personal Data, read in full from its 48-page consolidated text.

It establishes the Prezes Urzedu Ochrony Danych Osobowych (President of the Personal Data Protection Office, UODO) as supervisory authority with inspection powers (Rozdzial 9, Arts. 78-91), a civil-liability venue for GDPR Article 79/82 claims at the sad okregowy (Rozdzial 10, Arts. 92-100), a two-track administrative-fine regime distinguishing public-finance-sector bodies from other controllers (Rozdzial 11, Arts. 101-106), and its own criminal offenses for unlawful processing and for obstructing a UODO inspection (Arts. 107-108).

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

cite Regulation (EU) 2016/679, Arts. 44-49, 83(5) stage In effect since 2018-05-25 source GDPR Arts. 44-49, 83(5)

A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. Reading the Act's operative chapters (Rozdzialy 1-11) end to end found no Poland-specific derogation from this framework.

What it asks of an app

Data subject rights

GDPR Data-Subject Rights, Act Articles 92-97

cite Regulation (EU) 2016/679, Arts. 12-23; Ustawa z 10 maja 2018 r., Arts. 92-97 stage In effect since 2018-05-25 source isap.sejm.gov.pl, Ustawa z 10 maja 2018 r., Arts. 92-97 (direct read)

General Data Protection Regulation (GDPR) Articles 12-23 govern access, rectification, erasure, restriction, portability, objection, and Article 22 automated-decision rights, exercisable against the controller.

Poland's Act adds the enforcement forum, confirmed by direct read: a GDPR Article 79 or Article 82 claim is heard by the sad okregowy, UODO must be notified of any such filing and final judgment (Art. 94), proceedings are stayed if UODO has an open matter on the same violation (Art. 95), and a final UODO decision or court ruling finding a violation binds a later damages court on that finding (Art. 97).

What it asks of an app

Enforcement supervision

UODO Enforcement, GDPR Article 82, and Act Articles 98, 101-108

cite Regulation (EU) 2016/679, Art. 83; Ustawa z 10 maja 2018 r., Arts. 98, 101-108 stage In effect since 2018-05-25 source isap.sejm.gov.pl, Ustawa z 10 maja 2018 r., Arts. 101-108, 98 (direct read)

UODO is Poland's supervisory authority. The Act creates a distinct two-track fine structure, confirmed by direct read: Article 101 lets UODO fine any controller other than a public-finance-sector unit, research institute, or the National Bank of Poland under ordinary General Data Protection Regulation (GDPR) Article 83 terms, while Article 102 caps fines for those three categories at 100,000 or 10,000 PLN.

GDPR Article 82 arms an individual with a direct private right of action, and Article 98 gives UODO its own standing to bring or join a data subject's civil claim, with that person's consent, at any procedural stage.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.