Skip to the content
Global Data RulesData governance rules, country by country

Poland

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Active

Poland is a European Union country, so data may leave as long as you use one of the approved European transfer routes. We found no general Polish rule forcing data to stay in the country. The privacy regulator is fully staffed and busy, and it fines government bodies as well as companies. Finance is the sector to watch: the financial supervisor wants cloud data kept in Europe.

Eight questions about Poland

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Poland's rules apply to my company?

Yes, it reaches you with no office in Poland. European privacy law applies to any organisation anywhere that offers goods or services to people in Poland, or that monitors their behaviour. There is no size or revenue threshold. An organisation based outside Europe normally has to name a representative inside Europe. Poland then adds one local step that foreign groups routinely miss: if you must appoint a data protection officer, you have to tell the Polish regulator that person's name and contact details within 14 days of appointing them.

High confidenceBloc rulesNational rulesAppoint a local representativeAppoint a data protection officer

Can I store my users' data outside Poland?

Yes, with paperwork. Poland has not added a general rule of its own that keeps data inside the country, and European law actually forbids member states from imposing storage-location rules on data that is not about people, except on public-security grounds. We searched for industry walls in banking, payments, insurance, securities, health, telecoms, government cloud, mapping and gambling. The only one we could confirm from an official Polish source is in finance, and it is a firm supervisory recommendation rather than an outright ban.

Medium confidenceYes, with paperworkAllowlist

What do I need in place before data leaves Poland?

Think of it as an approved-routes list. Personal data may go outside Europe if the destination country has been officially approved, or if you sign the standard European contract with the recipient, or if your corporate group has rules approved by a regulator. The approved-country list is real and populated — roughly sixteen countries plus one international organisation. For the United States it only covers companies that have signed up to a specific certification scheme, so you have to check the recipient, not the country.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesCertification schemeApproved code of conductExplicit consentNeeded for a contractLegal claims

Who enforces the rules in Poland, and what can they do?

The Personal Data Protection Office, and it is genuinely working. It is led by Mirosław Wróblewski, it publishes news several times a week, and its public decisions database held 581 decisions when we checked on 18 August 2026, with new ones published through June and July 2026. It fines public bodies too: it penalised the Minister of Justice in June 2026 and a local social welfare centre later the same month. Three other regulators matter — the financial supervisor for banks and insurers, the electronic communications office for telecoms and post, and the Ministry of Digital Affairs for cyber security.

High confidenceActiveRegulator

How long do I have to keep the data?

There is a ceiling and a floor. The ceiling is European: you may not keep personal data in a form that identifies someone for longer than you need it, and you have to be able to state that period. The floor is Polish: tax, accounting, employment and medical rules force you to keep certain records for years. When the two collide, the specific keeping duty wins for those records and everything else must still be deleted on time. We could not open the official Polish texts for the exact periods on the day we checked, so treat any specific number you read elsewhere as unverified until you see the statute.

Medium confidenceKeep data for a minimum periodDelete data after a periodLet people delete their data

What happens if there is a breach?

Count at least two clocks, often three. For a personal data breach you have 72 hours to tell the Polish privacy regulator, and you must warn the people affected without undue delay if the risk to them is high. Separately, Poland rewrote its cyber security law and the new version started on 3 April 2026; if you are on the new register of key or important organisations you also report to the national cyber teams, on a much shorter first clock. Financial firms add a third set of reporting duties to the financial supervisor. The overlap is what breaks people, because the same incident triggers all three with different content and different deadlines.

Medium confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Poland?

Five things that are not in the summary. First, appointing a data protection officer is not the end of it — you have 14 days to file that person's name and contact details with the Polish regulator, and foreign groups miss this constantly. Second, the list of Polish organisations that must appoint one is wider than expected and includes the central bank and state research institutes. Third, a brand-new Polish law on data management started in July 2026 and can fine you about two million złoty, roughly $550,000, for sending protected public-sector data to the wrong country. Fourth, the financial supervisor expects to be told 14 days before a cloud project starts and wants critical firms' data inside Poland where possible. Fifth, being a public body is no shield — the regulator fined the Minister of Justice in June 2026.

High confidenceAppoint a data protection officerRegister or notifyPut a transfer safeguard in placeFixed maximum fine

What is changing soon in Poland?

Three dated things and one live risk. Poland's new cyber security register is being phased in through 2026: self-registration opened on 7 May 2026, and organisations the ministry enters itself get six months from being served notice to complete their details. On 12 January 2027 European rules ban cloud providers from charging you anything to move your data out. On 2 April 2027 a new European regulation on how privacy regulators run cross-border cases starts to apply, which will change how Polish complaints against foreign companies are handled. The live risk is the European Union–United States data transfer arrangement, which is valid today but being challenged.

High confidencePartly in forceProposed

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    3 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    1 rule here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules3 rules

Rozporządzenie Parlamentu Europejskiego i Rady (UE) 2016/679 (RODO)

Directly binding regulation · Regulation (EU) 2016/679, Chapter V

In forceYes, with paperwork

The European privacy rules apply directly in Poland. Data may leave Europe only through an approved route: an officially approved destination country, the standard European contract, approved group-wide rules, or a narrow exception. Fines scale with the whole group's worldwide turnover.

In force since 25 May 2018

Enforced by Personal Data Protection Office

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

High confidence

Rozporządzenie (UE) 2018/1807 w sprawie swobodnego przepływu danych nieosobowych

Directly binding regulation · Regulation (EU) 2018/1807

In forceYes — store it anywhere

This is the reason Poland has almost no storage-location rules. European law forbids member states from requiring data that is not about people to be stored inside their territory, unless they can justify it on public-security grounds. Poland has not used that exception, as far as we could verify.

In force since 28 May 2019

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Rozporządzenie (UE) 2023/2854 (akt w sprawie danych)

Directly binding regulation · Regulation (EU) 2023/2854

Partly in forceYes — store it anywhere

European rules that have applied since September 2025 and bite harder on 12 January 2027, when cloud providers must stop charging anything for moving your data out. They also restrict foreign government access to non-personal data held in Europe. No storage-location requirement.

In force since 12 September 2025But only enforceable from 12 January 2027

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

National rules3 rules

Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych

Act of parliament · Journal of Laws (Dziennik Ustaw) 2018 item 1000, consolidated text

In forceYes — store it anywhere

Poland's national privacy act sits on top of the European rules rather than replacing them. It adds no storage-location requirement. Its most commonly missed duty is a 14-day filing telling the regulator who your data protection officer is.

In force since 25 May 2018

Enforced by Personal Data Protection Office

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Ustawa z dnia 27 marca 2026 r. o zarządzaniu danymi

Act of parliament · Journal of Laws (Dziennik Ustaw) 2026 item 548, published 22 April 2026 · Government

In forceYes, with paperwork

Poland's newest data law, in force since late July 2026. It plugs the European data governance rules into Polish law, gives the privacy regulator a new job supervising data-sharing intermediaries, and creates a fine of about $550,000 for sending protected public-sector data to the wrong country.

In force since 22 July 2026

Enforced by Personal Data Protection Office

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses

High confidence

Ustawa o krajowym systemie cyberbezpieczeństwa, w brzmieniu nadanym nowelizacją wdrażającą dyrektywę NIS2

Act of parliament · Original act in force 28 August 2018 (Journal of Laws 2018 item 1560); amending act in force 3 April 2026

Partly in forceYes — store it anywhere

Poland's cyber security law was rewritten to implement the European network and information security rules, and the new version started on 3 April 2026. Registration of key and important organisations began on 7 May 2026 and is being phased in sector by sector. It imposes security and incident-reporting duties but no storage-location requirement.

In force since 3 April 2026But only enforceable from 7 May 2026

Enforced by Ministry of Digital Affairs

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Industry rules1 rule

Komunikat UKNF dotyczący przetwarzania przez podmioty nadzorowane informacji w chmurze obliczeniowej publicznej lub hybrydowej

Regulator guideline · Communication of the Office of the Polish Financial Supervision Authority, 23 January 2020 · Finance

In forceYes, with paperwork

The real sectoral wall in Poland, and it is a soft one. The financial supervisor tells banks, insurers, brokers and payment firms to keep cloud data in European data centres, and tells critical firms to use Polish data centres first. Going outside Europe is possible but you must document and own the risk, and you must warn the supervisor 14 days before you start.

In force since 23 January 2020But only enforceable from 1 August 2020

Enforced by Polish Financial Supervision Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses

High confidence

Who you would hear from

  • Urząd Ochrony Danych Osobowych

    General privacy law; from July 2026 also data intermediation services and data altruism organisations

    Fully staffed and issuing decisions. Headed by Mirosław Wróblewski. The public decisions portal held 581 decisions on 18 August 2026 with new items published through June and July 2026, including cases DKE.561.1.2026 and DKE.561.4.2026. Fined the Minister of Justice on 2 June 2026 and a local social welfare centre on 24 June 2026, and announced an inspection of the company MyDr on 13 August 2026.

  • Komisja Nadzoru Finansowego

    Banking, payments, insurance, securities, pensions — including cloud outsourcing supervision

    Maintains a dedicated cloud computing supervisory track; the January 2020 cloud communication and its question-and-answer guidance were still published as current on 18 August 2026.

  • Urząd Komunikacji Elektronicznej

    Telecoms and postal services, including cyber security registration for those sectors

    Publishing market reports and running the 2026 cyber security registration process for telecoms and postal operators.

  • Ministerstwo Cyfryzacji

    Cyber security policy, the register of key and important entities, public-sector data re-use

    Issued the communication of 8 April 2026 setting the registration timetable and operates the register at wykaz-ksc.gov.pl.

  • Ministerstwo Finansów

    Accounting and tax record-keeping rules; licensing of legal gambling

  • Ministerstwo Zdrowia

    Medical documentation rules and health information systems

  • Centrum e-Zdrowia

    Runs Poland's national e-health platform, including the patient account and electronic prescriptions

    Reports 21 million active patient account users and 3.15 billion electronic prescriptions issued.

  • Główny Urząd Geodezji i Kartografii

    State surveying and mapping resource

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact day the Act of 27 March 2026 on data management started to apply

    The act says it enters into force after three months from publication and it was published on 22 April 2026. Depending on how Polish law counts that period the date is 22 or 23 July 2026. We recorded 22 July 2026 as the cautious earlier date.

  • Whether Poland's telecoms law imposes any territorial condition on retained call and connection records

    The predecessor telecommunications law was reported to require retention on Polish territory. We could not open the current Electronic Communications Law from any reachable government source on 18 August 2026, because the official statute database at isap.sejm.gov.pl, the official gazette at dziennikustaw.gov.pl and the parliament's own site all refuse automated access. This is the single largest gap in this record and could change the telecom rating from open to closed.

  • The exact incident reporting deadlines in the amended Polish cyber security act

    We confirmed the amendment entered into force on 3 April 2026 from the electronic communications regulator's own announcement, but could not open the article text. The 24-hour and 72-hour figures come from the European directive the act implements, not from the Polish wording.

  • Whether the Act of 10 May 2018 creates criminal offences for unlawful processing, and the prison terms

    The consolidated text published by the regulator was retrieved but the automated reader could only surface the early articles. Criminal liability is widely reported but we have no government quotation for it, so it is described as reported rather than asserted.

  • Whether Poland caps administrative fines on public sector bodies, and at what amount

    A cap is widely reported. We could not verify it from a government source. Note that the regulator did fine the Minister of Justice in June 2026, so any cap plainly does not amount to immunity.

  • The age at which a child can consent to online services in Poland

    We checked the articles of the 2018 Act that the reader could surface and none of them set an age; article 8 of that Act deals with data protection officers, not children. Poland is understood not to have lowered the European default of 16, but we have no government confirmation.

  • Retention periods for medical documentation, accounting books and employment records

    The ministries that own these rules were reached but neither publishes the operative provision on a page an automated reader can open. The floors certainly exist; the numbers should be checked against the statutes before use.

  • Whether accounting books for a Polish entity may lawfully be kept on servers outside Poland, and what notification that requires

    This is a classic hidden localisation-adjacent rule and we could not reach the Ministry of Finance's question-and-answer content. Treat as an open question for any outsourced finance function.

  • Whether Poland imposes residency conditions on public administration cloud services

    The state operates its own cloud at chmura.gov.pl, but the site requires JavaScript and returned no readable policy text. No procurement or statutory residency requirement was located, so none is asserted.

  • Whether any localisation or export restriction applies to state mapping and surveying data, or to online gambling archiving systems

    Both regulators' sites were reached and neither publishes such a rule on the pages we could open. Checked 18 August 2026; recorded as no rule found rather than no rule existing.

  • The current status of the banking law's outsourcing rules for suppliers based outside the European Economic Area

    The financial supervisor's cloud communication was verified in full, but we could not open the Banking Act itself to confirm whether a separate permission requirement still applies to non-European outsourcing partners.

30-day cadence. Two reasons: the cyber security registration regime is commencing in phases through 2026 under ministerial communications that can be reissued at any time, and the European Union–United States transfer arrangement is under live challenge before the Court of Justice with the European Data Protection Board having asked the Commission on 31 July 2026 to re-examine it. A third reason is this record's own gaps — the telecoms and accounting questions need closing from primary sources at the next pass.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.