Skip to the content
Global Data RulesData governance rules, country by country

Poland

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Poland — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Active

Poland is a European Union country, so data may leave as long as you use one of the approved European transfer routes. We found no general Polish rule forcing data to stay in the country. The privacy regulator is fully staffed and busy. It fines government bodies as well as companies. Finance is the industry to watch. The financial supervisor wants cloud data kept in Europe.

Data governance in Poland

The eight things that decide how you handle data about people in Poland. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it reaches you even with no office in Poland. European privacy law applies to any organisation anywhere that offers goods or services to people in Poland, or that monitors their behaviour. There is no size or revenue threshold. An organisation based outside Europe normally has to name a representative inside Europe. Poland then adds one local step that foreign groups routinely miss. If you must appoint a data protection officer, you have to tell the Polish regulator that person's name and contact details within 14 days of appointing them.

What you have to do here:
Appoint a representative · Appoint a data protection officer

Where the data is allowed to live

Yes, with paperwork. Poland has not added a general rule of its own keeping data inside the country. European law actually forbids member states from imposing storage-location rules on data that is not about people, except on public-security grounds. We searched for industry restrictions in banking, payments, insurance, securities, health, telecoms, government cloud, mapping and gambling. The only one we could confirm from an official Polish source is in finance. It is a firm supervisory recommendation, not an outright ban.

What to do: Get the paperwork for one of the routes below signed before any data leaves Poland.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

Think of it as a list of approved routes. Personal data may go outside Europe if the destination country has been officially approved. Or if you sign the standard European contract with the recipient. Or if your corporate group has rules approved by a regulator. The approved-country list is real and populated, with roughly sixteen countries plus one international organisation. For the United States it only covers companies that have signed up to a specific certification scheme. So you have to check the recipient, not the country.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims

What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.

The regulator, and whether it actually acts

The Personal Data Protection Office, and it really works. It is led by Mirosław Wróblewski. It publishes news several times a week. Its public decisions database held 581 decisions when we checked on 18 August 2026, with new ones published through June and July 2026. It fines public bodies too. It penalised the Minister of Justice in June 2026, and a local social welfare centre later the same month. Three other regulators matter. The financial supervisor covers banks and insurers. The electronic communications office covers telecoms and post. The Ministry of Digital Affairs covers cyber security.

How long you must keep it — and when to delete it

There is a maximum and a minimum. The maximum is European. You may not keep personal data in a form that identifies someone for longer than you need it, and you must be able to state that period. The minimum is Polish. Tax, accounting, employment and medical rules force you to keep certain records for years. When the two collide, the specific keeping duty wins for those records. Everything else must still be deleted on time. We could not confirm the exact Polish periods against the official texts. Treat any specific number you read elsewhere as unverified until you see the statute.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Let people delete their data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

Count at least two clocks, often three. For a personal data breach you have 72 hours to tell the Polish privacy regulator. You must also warn the people affected without undue delay, if the risk to them is high. Separately, Poland rewrote its cyber security law and the new version started on 3 April 2026. If you are on the new register of key or important organisations, you also report to the national cyber teams, on a much shorter first clock. Financial firms add a third set of reporting duties to the financial supervisor. The overlap is what breaks people. The same incident triggers all three, with different content and different deadlines.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five things. First, appointing a data protection officer is not the end of it. You have 14 days to file that person's name and contact details with the Polish regulator, and foreign groups miss this constantly. Second, the list of Polish organisations that must appoint one is wider than expected. It includes the central bank and state research institutes. Third, a brand-new Polish law on data management started in July 2026. It can fine you about two million złoty, roughly $550,000, for sending protected public-sector data to the wrong country. Fourth, the financial supervisor expects to be told 14 days before a cloud project starts, and wants critical firms' data inside Poland where possible. Fifth, being a public body is no shield. The regulator fined the Minister of Justice in June 2026.

What you have to do here:
Appoint a data protection officer · Put a transfer safeguard in place
What it costs if you get it wrong:
Fixed maximum fine

What's changing next

Three dated things and one live risk. Poland's new cyber security register is being phased in through 2026. Self-registration opened on 7 May 2026. Organisations the ministry enters itself get six months from being served notice to complete their details. On 12 January 2027 European rules ban cloud providers from charging you anything to move your data out. On 2 April 2027 a new European regulation starts, on how privacy regulators run cross-border cases. It will change how Polish complaints against foreign companies are handled. The live risk is the European Union-United States data transfer arrangement. It is valid today but is being challenged.

What to do: Diarise 12 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries1 rule

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Cloud and outsourcing rules

Official name: Komunikat UKNF dotyczący przetwarzania przez podmioty nadzorowane informacji w chmurze obliczeniowej publicznej lub hybrydowej · Communication of the Office of the Polish Financial Supervision Authority, 23 January 2020 · Regulator guideline

In forceYes, with paperwork

The real industry restriction in Poland, and it is a soft one. The financial supervisor tells banks, insurers, brokers and payment firms to keep cloud data in European data centres. It tells critical firms to use Polish data centres first. Going outside Europe is possible, but you must document and own the risk. You must also warn the supervisor 14 days before you start.

In force since 23 January 2020Enforced from 1 August 2020

Enforced by Polish Financial Supervision Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych · Journal of Laws (Dziennik Ustaw) 2018 item 1000, consolidated text · Act of parliament

In forceYes — store it anywhere

Poland's national privacy act sits on top of the European rules rather than replacing them. It adds no storage-location requirement. Its most commonly missed duty is a 14-day filing telling the regulator who your data protection officer is.

In force since 25 May 2018

Enforced by Personal Data Protection Office

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Government

General data protection law (Government)

Official name: Ustawa z dnia 27 marca 2026 r. o zarządzaniu danymi · Journal of Laws (Dziennik Ustaw) 2026 item 548, published 22 April 2026 · Act of parliament

In forceYes, with paperwork

Poland's newest data law, in force since late July 2026. It plugs the European data governance rules into Polish law. It gives the privacy regulator a new job supervising data-sharing intermediaries. And it creates a fine of about $550,000 for sending protected public-sector data to the wrong country.

In force since 22 July 2026

Enforced by Personal Data Protection Office

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses

Cyber security rules

Official name: Ustawa o krajowym systemie cyberbezpieczeństwa, w brzmieniu nadanym nowelizacją wdrażającą dyrektywę NIS2 · Original act in force 28 August 2018 (Journal of Laws 2018 item 1560); amending act in force 3 April 2026 · Act of parliament

Partly in forceYes — store it anywhere

Poland's cyber security law was rewritten to implement the European network and information security rules, and the new version started on 3 April 2026. Registration of key and important organisations began on 7 May 2026 and is being phased in sector by sector. It imposes security and incident-reporting duties but no storage-location requirement.

In force since 3 April 2026Enforced from 7 May 2026

Enforced by Ministry of Digital Affairs

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Applies across the European Union3 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Rozporządzenie Parlamentu Europejskiego i Rady (UE) 2016/679 (RODO) · Regulation (EU) 2016/679, Chapter V · Directly binding regulation

In forceYes, with paperwork

The European privacy rules apply directly in Poland. Data may leave Europe only through an approved route: an officially approved destination country, the standard European contract, approved group-wide rules, or a narrow exception. Fines scale with the whole group's worldwide turnover.

In force since 25 May 2018

Enforced by Personal Data Protection Office

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

Free cloud switching from 2019

Official name: Rozporządzenie (UE) 2018/1807 w sprawie swobodnego przepływu danych nieosobowych · Regulation (EU) 2018/1807 · Directly binding regulation

In forceYes — store it anywhere

This is the reason Poland has almost no storage-location rules. European law forbids member states from requiring data that is not about people to be stored inside their territory, unless they can justify it on public-security grounds. Poland has not used that exception, as far as we could verify.

In force since 28 May 2019

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Cloud and outsourcing rules (2027)

Official name: Rozporządzenie (UE) 2023/2854 (akt w sprawie danych) · Regulation (EU) 2023/2854 · Directly binding regulation

Partly in forceYes — store it anywhere

European rules that have applied since September 2025. They matter more from 12 January 2027, when cloud providers must stop charging anything for moving your data out. They also restrict foreign government access to data held in Europe that is not about people. There is no storage-location requirement.

In force since 12 September 2025In force now, but not enforced until 12 January 2027

That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Urząd Ochrony Danych Osobowych

    General privacy law; from July 2026 also data intermediation services and data altruism organisations

    Fully staffed and issuing decisions. Headed by Mirosław Wróblewski. The public decisions portal held 581 decisions on 18 August 2026 with new items published through June and July 2026, including cases DKE.561.1.2026 and DKE.561.4.2026. Fined the Minister of Justice on 2 June 2026 and a local social welfare centre on 24 June 2026, and announced an inspection of the company MyDr on 13 August 2026.

  • Komisja Nadzoru Finansowego

    Banking, payments, insurance, securities, pensions — including cloud outsourcing supervision

    Runs a dedicated supervision track for cloud computing. The January 2020 cloud communication and its question-and-answer guidance were still published as current on 18 August 2026.

  • Urząd Komunikacji Elektronicznej

    Telecoms and postal services, including cyber security registration for those sectors

    Publishing market reports and running the 2026 cyber security registration process for telecoms and postal operators.

  • Ministerstwo Cyfryzacji

    Cyber security policy, the register of key and important entities, public-sector data re-use

    Issued the communication of 8 April 2026 setting the registration timetable and operates the register at wykaz-ksc.gov.pl.

  • Ministerstwo Finansów

    Accounting and tax record-keeping rules; licensing of legal gambling

  • Ministerstwo Zdrowia

    Medical documentation rules and health information systems

  • Centrum e-Zdrowia

    Runs Poland's national e-health platform, including the patient account and electronic prescriptions

    Reports 21 million active patient account users and 3.15 billion electronic prescriptions issued.

  • Główny Urząd Geodezji i Kartografii

    State surveying and mapping resource

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact day the Act of 27 March 2026 on data management started to apply

    The act says it enters into force three months after publication, and it was published on 22 April 2026. Depending on how Polish law counts that period, the date is 22 or 23 July 2026. We recorded 22 July 2026, the earlier and safer date.

  • Whether Poland's telecoms law imposes any territorial condition on retained call and connection records

    The old telecommunications law was reported to require records to be kept on Polish territory. We could not confirm the current Electronic Communications Law against a government source. This is the single largest gap in this record. It could change the telecom rating from open to closed. If you run a telecoms business in Poland, check this first.

  • The exact incident reporting deadlines in the amended Polish cyber security act

    We confirmed the amendment entered into force on 3 April 2026, from the electronic communications regulator's own announcement. We could not confirm the article text. The 24-hour and 72-hour figures come from the European directive the act implements, not from the Polish wording.

  • Whether the Act of 10 May 2018 creates criminal offences for unlawful processing, and the prison terms

    We could not confirm the later articles of this Act. Criminal liability is widely reported, but we have no government quotation for it. So we describe it as reported, not as confirmed.

  • Whether Poland caps administrative fines on public sector bodies, and at what amount

    A cap is widely reported. We could not confirm it from a government source. Note that the regulator did fine the Minister of Justice in June 2026, so any cap is clearly not immunity.

  • The age at which a child can consent to online services in Poland

    We checked the articles of the 2018 Act we could read, and none of them sets an age. Article 8 of that Act deals with data protection officers, not children. Poland is understood not to have lowered the European default of 16, but we have no government confirmation.

  • Retention periods for medical documentation, accounting books and employment records

    The ministries that own these rules do not publish the binding text on a page we could read. The minimum periods certainly exist. Check the numbers against the statutes before you use them.

  • Whether accounting books for a Polish entity may lawfully be kept on servers outside Poland, and what notification that requires

    This is a hidden rule that behaves like a requirement to keep data in the country. We could not confirm it against the Ministry of Finance's question-and-answer content. Treat it as an open question for any outsourced finance function.

  • Whether Poland imposes residency conditions on public administration cloud services

    The state runs its own cloud at chmura.gov.pl. We found no procurement or legal requirement about where data must sit, so we state none.

  • Whether any localisation or export restriction applies to state mapping and surveying data, or to online gambling archiving systems

    We reached both regulators' sites and neither publishes such a rule on the pages we could read. Checked 18 August 2026. We record this as no rule found, not as no rule existing.

  • The current status of the banking law's outsourcing rules for suppliers based outside the European Economic Area

    We verified the financial supervisor's cloud communication in full. We could not confirm the Banking Act itself, so we do not know whether a separate permission requirement still applies to outsourcing partners outside Europe.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.