Poland
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Poland — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Poland is a European Union country, so data may leave as long as you use one of the approved European transfer routes. We found no general Polish rule forcing data to stay in the country. The privacy regulator is fully staffed and busy. It fines government bodies as well as companies. Finance is the industry to watch. The financial supervisor wants cloud data kept in Europe.
Data governance in Poland
The eight things that decide how you handle data about people in Poland. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it reaches you even with no office in Poland. European privacy law applies to any organisation anywhere that offers goods or services to people in Poland, or that monitors their behaviour. There is no size or revenue threshold. An organisation based outside Europe normally has to name a representative inside Europe. Poland then adds one local step that foreign groups routinely miss. If you must appoint a data protection officer, you have to tell the Polish regulator that person's name and contact details within 14 days of appointing them.
- What you have to do here:
- Appoint a representative · Appoint a data protection officer
Where the law applies comes from Article 3 of Regulation (EU) 2016/679. The duty to name a representative comes from Article 27. The Polish layer on top is the Act of 10 May 2018 on the protection of personal data. Article 8 of that Act refers back to Article 37 of the Regulation for when an officer is required. Article 9 lists the Polish public bodies that must always appoint one: public finance sector units, research institutes, and the National Bank of Poland. Article 10(1) creates the filing duty. Article 10(2) allows the filing to be made by an attorney with an electronic power of attorney.
Sources
- Official sourceUrząd Ochrony Danych OsobowychAct of 10 May 2018 on the protection of personal data — consolidated text published by the Personal Data Protection Office, articles 8, 9 and 10
uodo.gov.pl
“Podmiot, który wyznaczył inspektora, zawiadamia Prezesa Urzędu o jego wyznaczeniu w terminie 14 dni od dnia wyznaczenia, wskazując imię, nazwisko oraz adres poczty elektronicznej lub numer telefonu inspektora.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), articles 3 and 27
eur-lex.europa.eu
Where the data is allowed to live
Yes, with paperwork. Poland has not added a general rule of its own keeping data inside the country. European law actually forbids member states from imposing storage-location rules on data that is not about people, except on public-security grounds. We searched for industry restrictions in banking, payments, insurance, securities, health, telecoms, government cloud, mapping and gambling. The only one we could confirm from an official Polish source is in finance. It is a firm supervisory recommendation, not an outright ban.
Here is what we found industry by industry, checked on 18 August 2026. FINANCE (banking, payments, insurance, securities): the financial supervisor's cloud notice of 23 January 2020 recommends keeping data in data centres located in European Economic Area states. It says operators of critical infrastructure and providers of key services should use data centres located in Poland in the first instance. Using data centres outside the Area is possible where the supervised firm assesses and accepts the risk. Rated data can leave only if conditions are met GOVERNMENT AND CLASSIFIED: the state runs its own cloud service at chmura.gov.pl. Classified information sits under a separate accreditation system and is closed. We could not open a binding text for either, so we state no rule. HEALTH, TELECOM, GEOSPATIAL, GAMBLING, EDUCATION, DEFENCE: we found no rule about keeping data in the country on an official Polish website, checked 18 August 2026, confidence medium. We could not confirm the telecoms record-keeping rules, or any territorial condition attached to them. We flag that as unconfirmed rather than reporting it as absent.
Sources
- Official sourceUrząd Komisji Nadzoru FinansowegoCommunication of the Office of the Polish Financial Supervision Authority of 23 January 2020 on the processing of information by supervised entities in public or hybrid cloud
knf.gov.pl
“UKNF rekomenduje przetwarzanie informacji w CPD zlokalizowanych na terenie państw należących do EOG.”
Link checked 18 August 2026
- Official sourceKomisja Nadzoru FinansowegoPolish Financial Supervision Authority — cloud computing section, listing the 23 January 2020 communication as the current instrument
knf.gov.pl
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data
eur-lex.europa.eu
What to do: Get the paperwork for one of the routes below signed before any data leaves Poland.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
Think of it as a list of approved routes. Personal data may go outside Europe if the destination country has been officially approved. Or if you sign the standard European contract with the recipient. Or if your corporate group has rules approved by a regulator. The approved-country list is real and populated, with roughly sixteen countries plus one international organisation. For the United States it only covers companies that have signed up to a specific certification scheme. So you have to check the recipient, not the country.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims
Chapter V of Regulation (EU) 2016/679 governs this. The 2021 Standard Contractual Clauses, Decision (EU) 2021/914, remain the set in force and are unchanged. The promised extra clauses, for recipients already directly caught by the Regulation, are still not adopted as at 18 August 2026. Binding corporate rules remain available. The narrow exceptions in Article 49 cannot be used for routine or bulk flows. You are still expected to write a transfer impact assessment after Schrems II. The European Data Protection Board's Guidelines 02/2024 confirm that an order from a non-European authority is not by itself a lawful reason to hand data over. The European Union-United States Data Privacy Framework is in force and legally valid today, but it is under pressure. The Latombe case was dismissed by the General Court on 3 September 2025 and is on appeal to the Court of Justice. On 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether recent United States developments affect the decision's validity. It has not been suspended. Do not build on it as your only route.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, Chapter V (articles 44 to 50)
eur-lex.europa.eu
- Official sourceEuropean CommissionEuropean Commission — adequacy decisions (the populated approved-destination list)
commission.europa.eu
- Official sourceUrząd Ochrony Danych OsobowychPersonal Data Protection Office — legal acts page listing Regulation (EU) 2016/679 and accompanying instruments as the applicable framework in Poland
uodo.gov.pl
Link checked 18 August 2026
What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.
The regulator, and whether it actually acts
The Personal Data Protection Office, and it really works. It is led by Mirosław Wróblewski. It publishes news several times a week. Its public decisions database held 581 decisions when we checked on 18 August 2026, with new ones published through June and July 2026. It fines public bodies too. It penalised the Minister of Justice in June 2026, and a local social welfare centre later the same month. Three other regulators matter. The financial supervisor covers banks and insurers. The electronic communications office covers telecoms and post. The Ministry of Digital Affairs covers cyber security.
Here is the evidence that it works, not just that it exists. The decisions portal at orzeczenia.uodo.gov.pl carried decisions with 2026 publication dates. They include DKE.561.1.2026 and DKE.561.4.2026, on failure to cooperate with the supervisory authority and on unlawful video surveillance. They also include DKN.5131.5.2025, published 27 July 2026. The office is also opening inspections on its own initiative. On 13 August 2026 it announced an inspection of the company MyDr. We rate it active rather than aggressive. The published Polish fines are still modest by European standards, and the office still leads with guidance.
Sources
- Official sourceUrząd Ochrony Danych OsobowychPortal Orzeczeń UODO — searchable database of decisions of the President of the Personal Data Protection Office; 581 decisions, 2026 decisions present
orzeczenia.uodo.gov.pl
Link checked 18 August 2026
- Official sourceUrząd Ochrony Danych OsobowychPersonal Data Protection Office — news feed, items dated 2 June 2026 (fine on the Minister of Justice), 24 June 2026 (fine on a social welfare centre) and 13–17 August 2026
uodo.gov.pl
Link checked 18 August 2026
- Official sourceUrząd Komunikacji ElektronicznejOffice of Electronic Communications — active regulator for telecoms and post, running cyber security registration for its sectors
uke.gov.pl
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a maximum and a minimum. The maximum is European. You may not keep personal data in a form that identifies someone for longer than you need it, and you must be able to state that period. The minimum is Polish. Tax, accounting, employment and medical rules force you to keep certain records for years. When the two collide, the specific keeping duty wins for those records. Everything else must still be deleted on time. We could not confirm the exact Polish periods against the official texts. Treat any specific number you read elsewhere as unverified until you see the statute.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Let people delete their data
The maximum is the storage limit in Article 5(1)(e) of Regulation (EU) 2016/679, backed by the erasure right in Article 17. The minimums sit in the Accounting Act, the Tax Ordinance, the Labour Code and the Act on patients' rights. The Ministry of Finance publishes the accounting rules and the Ministry of Health publishes the medical documentation rules. We could not open either binding text from a government website on 18 August 2026. The official statute database at isap.sejm.gov.pl and the official gazette at dziennikustaw.gov.pl both refuse automated access. Two Polish points are worth confirming before you build to them. One is whether accounting books may be held outside Poland at all, and what notification that requires. The other is the long keeping period attached to medical documentation. Both are listed as unconfirmed.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, article 5(1)(e) storage limitation and article 17 erasure
eur-lex.europa.eu
- Official sourceMinisterstwo FinansówMinistry of Finance — accounting section, the official home of the Polish accounting record-keeping rules
gov.pl
Link checked 18 August 2026
- Official sourceMinisterstwo ZdrowiaMinistry of Health — the official home of the medical documentation rules
gov.pl
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
Count at least two clocks, often three. For a personal data breach you have 72 hours to tell the Polish privacy regulator. You must also warn the people affected without undue delay, if the risk to them is high. Separately, Poland rewrote its cyber security law and the new version started on 3 April 2026. If you are on the new register of key or important organisations, you also report to the national cyber teams, on a much shorter first clock. Financial firms add a third set of reporting duties to the financial supervisor. The overlap is what breaks people. The same incident triggers all three, with different content and different deadlines.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
The 72-hour clock is Article 33 of Regulation (EU) 2016/679. It runs from when you become aware, not from when you confirm. The Polish cyber clock comes from the amended Act on the national cyber security system. That entered into force on 3 April 2026 and implements the European network and information security directive. The underlying European rules set a first alert within 24 hours and a fuller notification within 72 hours. We could not open the Polish article text to confirm the Polish wording, so treat the Polish hours as unconfirmed. Financial firms also sit under the European digital operational resilience regulation, which has applied since 17 January 2025.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, articles 33 and 34 — 72-hour breach notification
eur-lex.europa.eu
- Official sourceUrząd Komunikacji ElektronicznejOffice of Electronic Communications, 15 May 2026 — the amendment to the Act on the national cyber security system entered into force on 3 April 2026
uke.gov.pl
Link checked 18 August 2026
- Official sourceUrząd Ochrony Danych OsobowychPersonal Data Protection Office — breach guidance items 'Wyciek danych – co dalej?' and 'Administrator musi zgłosić wyciek', 12 August 2026
uodo.gov.pl
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Five things. First, appointing a data protection officer is not the end of it. You have 14 days to file that person's name and contact details with the Polish regulator, and foreign groups miss this constantly. Second, the list of Polish organisations that must appoint one is wider than expected. It includes the central bank and state research institutes. Third, a brand-new Polish law on data management started in July 2026. It can fine you about two million złoty, roughly $550,000, for sending protected public-sector data to the wrong country. Fourth, the financial supervisor expects to be told 14 days before a cloud project starts, and wants critical firms' data inside Poland where possible. Fifth, being a public body is no shield. The regulator fined the Minister of Justice in June 2026.
- What you have to do here:
- Appoint a data protection officer · Put a transfer safeguard in place
- What it costs if you get it wrong:
- Fixed maximum fine
The officer filing duty is Article 10 of the Act of 10 May 2018. It can be made through an attorney holding an electronic power of attorney. The list of bodies that must appoint one is Article 9: public finance sector units, research institutes, and the National Bank of Poland. The data management fines are in Articles 29 to 31 of the Act of 27 March 2026. That Act also gives the privacy regulator a new job supervising data intermediation services and data altruism organisations. The financial supervisor's 14-day warning applies where you put legally protected information in public or hybrid cloud, and to critical cloud outsourcing. A sixth trap is worth watching, and we could not confirm it from a government source. Poland's 2018 Act is widely reported to create criminal offences as well as fines. That is flagged as unconfirmed.
Sources
- Official sourceUrząd Ochrony Danych OsobowychAct of 10 May 2018 on the protection of personal data, articles 9 and 10
uodo.gov.pl
“Przez organy i podmioty publiczne obowiązane do wyznaczenia inspektora, o których mowa w art. 37 ust. 1 lit. a rozporządzenia 2016/679, rozumie się: 1) jednostki sektora finansów publicznych; 2) instytuty badawcze; 3) Narodowy Bank Polski.”
Link checked 18 August 2026
- Official sourceUrząd Ochrony Danych OsobowychAct of 27 March 2026 on data management, Journal of Laws 2026 item 548, articles 19, 23 and 29 to 31
uodo.gov.pl
Link checked 18 August 2026
- Official sourceUrząd Komisji Nadzoru FinansowegoFinancial supervisor's cloud communication of 23 January 2020 — 14-day advance notification
knf.gov.pl
“podmiot nadzorowany w terminie 14 dni przed rozpoczęciem przetwarzania informacji w chmurze obliczeniowej”
Link checked 18 August 2026
What's changing next
Three dated things and one live risk. Poland's new cyber security register is being phased in through 2026. Self-registration opened on 7 May 2026. Organisations the ministry enters itself get six months from being served notice to complete their details. On 12 January 2027 European rules ban cloud providers from charging you anything to move your data out. On 2 April 2027 a new European regulation starts, on how privacy regulators run cross-border cases. It will change how Polish complaints against foreign companies are handled. The live risk is the European Union-United States data transfer arrangement. It is valid today but is being challenged.
These are powers already held that could change things without new legislation. First, the Commission can suspend or change an official decision that a country is safe enough. The European Data Protection Board formally asked it on 31 July 2026 to examine the United States decision, and the Latombe appeal is pending before the Court of Justice. Second, the Polish financial supervisor's cloud position is a communication, not a statute. It can be tightened or replaced with no parliamentary process. The current text has stood since 23 January 2020. Third, the Minister of Digital Affairs sets the cyber registration timetable by communication, as it did on 8 April 2026. It can widen the register's reach the same way. Fourth, the free flow rules for data that is not about people let a member state require data to stay in the country on public-security grounds. Poland has not used that power, but it keeps it. Two proposed European measures have no legal effect. Do not plan around them as binding. They are the Cloud and Artificial Intelligence Development Act of 3 June 2026 and the Digital Omnibus of 19 November 2025.
Sources
- Official sourceUrząd Komunikacji ElektronicznejOffice of Electronic Communications, 15 May 2026 — registration opened 7 May 2026; ministerial communication of 8 April 2026 sets the timetable; six months to complete data after service
uke.gov.pl
“uzupełnić brakujące dane w terminie 6 miesięcy od dnia doręczenia wezwania”
Link checked 18 August 2026
- Official sourceUrząd Ochrony Danych OsobowychRegulation (EU) 2025/2518 of 26 November 2025 laying down additional procedural rules for enforcing Regulation (EU) 2016/679 — applies from 2 April 2027
uodo.gov.pl
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) — cloud switching charges must be zero from 12 January 2027
eur-lex.europa.eu
What to do: Diarise 12 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries1 rule
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: Komunikat UKNF dotyczący przetwarzania przez podmioty nadzorowane informacji w chmurze obliczeniowej publicznej lub hybrydowej · Communication of the Office of the Polish Financial Supervision Authority, 23 January 2020 · Regulator guideline
The real industry restriction in Poland, and it is a soft one. The financial supervisor tells banks, insurers, brokers and payment firms to keep cloud data in European data centres. It tells critical firms to use Polish data centres first. Going outside Europe is possible, but you must document and own the risk. You must also warn the supervisor 14 days before you start.
Enforced by Polish Financial Supervision Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses
What you have to do
- Prove the data stays under local controlCloud data centres should be in European Economic Area states. Operators of critical infrastructure and providers of key services should use data centres located in Poland in the first instance, where conditions are comparable. Using data centres outside the Area is possible only where the firm has assessed and accepted the risk.
- Register or notify — within 336 hoursNot a licence. The firm must tell the supervisor at least 14 days before putting legally protected information in cloud, or before critical cloud outsourcing. Arrangements already running had to be notified by 1 August 2020.
- Assess high-risk projectsA documented information classification and risk assessment must be done before any cloud project starts.
- Written vendor contract
- Independent audit
What it costs if you get it wrong
- Order to stopSupervisory measures where a firm's cloud arrangements are found inadequate
- Loss of your licencePersistent failure to meet outsourcing and supervisory requirements
Sources
- Official sourceUrząd Komisji Nadzoru FinansowegoCommunication of the Office of the Polish Financial Supervision Authority of 23 January 2020 on cloud processing by supervised entities
knf.gov.pl
“powinny w pierwszej kolejności wykorzystywać CPD znajdujące się na terenie Rzeczypospolitej Polskiej”
Link checked 18 August 2026
- Official sourceKomisja Nadzoru FinansowegoPolish Financial Supervision Authority — cloud computing page, listing the 23 January 2020 communication as the operative instrument on 18 August 2026
knf.gov.pl
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych · Journal of Laws (Dziennik Ustaw) 2018 item 1000, consolidated text · Act of parliament
Poland's national privacy act sits on top of the European rules rather than replacing them. It adds no storage-location requirement. Its most commonly missed duty is a 14-day filing telling the regulator who your data protection officer is.
Enforced by Personal Data Protection Office
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Appoint a data protection officerRequired in the cases set by the European rules. Poland additionally forces public finance sector units, research institutes and the National Bank of Poland to appoint one.
- Register or notify — within 336 hoursNot a licence. Within 14 days of appointing a data protection officer you must file that person's name and either email address or phone number with the Polish regulator. May be filed by an attorney holding an electronic power of attorney.
Sources
- Official sourceUrząd Ochrony Danych OsobowychAct of 10 May 2018 on the protection of personal data — consolidated text published by the Personal Data Protection Office
uodo.gov.pl
“Administrator i podmiot przetwarzający są obowiązani do wyznaczenia inspektora ochrony danych, zwanego dalej „inspektorem”, w przypadkach i na zasadach określonych w art. 37 rozporządzenia 2016/679.”
Link checked 18 August 2026
- Official sourceUrząd Ochrony Danych OsobowychPersonal Data Protection Office — list of Polish legal acts on data protection
uodo.gov.pl
Link checked 18 August 2026
General data protection law (Government)
Official name: Ustawa z dnia 27 marca 2026 r. o zarządzaniu danymi · Journal of Laws (Dziennik Ustaw) 2026 item 548, published 22 April 2026 · Act of parliament
Poland's newest data law, in force since late July 2026. It plugs the European data governance rules into Polish law. It gives the privacy regulator a new job supervising data-sharing intermediaries. And it creates a fine of about $550,000 for sending protected public-sector data to the wrong country.
Enforced by Personal Data Protection Office
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses
What you have to do
- Register or notifyData intermediation services must notify the privacy regulator; data altruism organisations must be registered by it.
- Put a transfer safeguard in placeProtected public-sector data and data held by intermediaries may only go to a country outside Europe under the conditions set by the European data governance rules.
- Do not hand data to foreign authorities on demand
What it costs if you get it wrong
- Fixed maximum fine: PLN 2,000,000 — about $550 thousandUnlawful transfer of protected data to a country outside Europe, or breach of the conditions for running a data intermediation service
- Fixed maximum fine: PLN 200,000 — about $55 thousandFailure to notify a data intermediation service
- Fixed maximum fine: PLN 20,000 — about $6 thousandBreach of the registration rules for data altruism organisations
Sources
- Official sourceUrząd Ochrony Danych OsobowychAct of 27 March 2026 on data management (ustawa o zarządzaniu danymi), Journal of Laws 2026 item 548
uodo.gov.pl
“Ustawa wchodzi w życie po upływie 3 miesięcy od dnia ogłoszenia.”
Link checked 18 August 2026
- Official sourceUrząd Ochrony Danych OsobowychPersonal Data Protection Office — page publishing the Act of 27 March 2026 on data management
uodo.gov.pl
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2022/868 (Data Governance Act), the European rules this Polish act implements
eur-lex.europa.eu
Cyber security rules
Official name: Ustawa o krajowym systemie cyberbezpieczeństwa, w brzmieniu nadanym nowelizacją wdrażającą dyrektywę NIS2 · Original act in force 28 August 2018 (Journal of Laws 2018 item 1560); amending act in force 3 April 2026 · Act of parliament
Poland's cyber security law was rewritten to implement the European network and information security rules, and the new version started on 3 April 2026. Registration of key and important organisations began on 7 May 2026 and is being phased in sector by sector. It imposes security and incident-reporting duties but no storage-location requirement.
Enforced by Ministry of Digital Affairs
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notify — from 7 May 2026Entry in the register of key and important entities, filed through the S46 system at wykaz-ksc.gov.pl. Organisations entered by the ministry on its own initiative have six months from being served notice to complete their details.
- Report cyber incidents — within 24 hoursThe European rules the Polish act implements require a first alert within 24 hours and a fuller notification within 72 hours. The exact Polish wording could not be opened from a government source on 18 August 2026.
- Secure the data
- Independent audit
Sources
- Official sourceUrząd Komunikacji ElektronicznejOffice of Electronic Communications, 15 May 2026 — registration of electronic communications entities in the register of key and important entities
uke.gov.pl
“Rozpoczęła się rejestracja podmiotów komunikacji elektronicznej w wykazie podmiotów kluczowych i ważnych”
Link checked 18 August 2026
- Official sourceUrząd Komunikacji ElektronicznejOffice of Electronic Communications, 15 May 2026 — self-registration of postal operators through the S46 system
uke.gov.pl
Link checked 18 August 2026
- Official sourceMinisterstwo CyfryzacjiMinistry of Digital Affairs — the Act on the national cyber security system, in force since 28 August 2018
gov.pl
Link checked 18 August 2026
Applies across the European Union3 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Rozporządzenie Parlamentu Europejskiego i Rady (UE) 2016/679 (RODO) · Regulation (EU) 2016/679, Chapter V · Directly binding regulation
The European privacy rules apply directly in Poland. Data may leave Europe only through an approved route: an officially approved destination country, the standard European contract, approved group-wide rules, or a narrow exception. Fines scale with the whole group's worldwide turnover.
Enforced by Personal Data Protection Office
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest
What you have to do
- Put a transfer safeguard in placeA transfer impact assessment is still expected where the destination is not officially approved.
- Tell people what you do
- Let people see their data
- Let people delete their data
- Let people take their data elsewhere
- Keep records of how you use data
- Secure the data
- Assess high-risk projects
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Do not hand data to foreign authorities on demandEuropean Data Protection Board Guidelines 02/2024: an order from a non-European authority is not by itself a lawful basis to disclose.
What it costs if you get it wrong
- Percentage of global turnover: €20m or 4% of worldwide group turnover, whichever is higher — about $22 millionBreach of basic principles, individual rights, or the transfer rules
- Percentage of global turnover: €10m or 2% of worldwide group turnover, whichever is higher — about $11 millionBreach of controller or processor duties such as security or records
- Order to stopOrder to stop processing or to suspend flows to a country outside Europe
- Claims by individualsCompensation claims by individuals
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
- Official sourceUrząd Ochrony Danych OsobowychPersonal Data Protection Office — legal acts page confirming Regulation (EU) 2016/679 as the applicable framework in Poland
uodo.gov.pl
Link checked 18 August 2026
Free cloud switching from 2019
Official name: Rozporządzenie (UE) 2018/1807 w sprawie swobodnego przepływu danych nieosobowych · Regulation (EU) 2018/1807 · Directly binding regulation
This is the reason Poland has almost no storage-location rules. European law forbids member states from requiring data that is not about people to be stored inside their territory, unless they can justify it on public-security grounds. Poland has not used that exception, as far as we could verify.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Make switching cloud provider possibleNow largely superseded by the Data Act, which makes cloud switching charges zero from 12 January 2027.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union
eur-lex.europa.eu
Cloud and outsourcing rules (2027)
Official name: Rozporządzenie (UE) 2023/2854 (akt w sprawie danych) · Regulation (EU) 2023/2854 · Directly binding regulation
European rules that have applied since September 2025. They matter more from 12 January 2027, when cloud providers must stop charging anything for moving your data out. They also restrict foreign government access to data held in Europe that is not about people. There is no storage-location requirement.
That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Make switching cloud provider possible — from 12 January 2027From 12 January 2027 all cloud switching charges and data egress fees must be zero.
- Do not hand data to foreign authorities on demandRestricts access by non-European governments to data held in Europe that is not about people.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act)
eur-lex.europa.eu
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact day the Act of 27 March 2026 on data management started to apply
The act says it enters into force three months after publication, and it was published on 22 April 2026. Depending on how Polish law counts that period, the date is 22 or 23 July 2026. We recorded 22 July 2026, the earlier and safer date.
Whether Poland's telecoms law imposes any territorial condition on retained call and connection records
The old telecommunications law was reported to require records to be kept on Polish territory. We could not confirm the current Electronic Communications Law against a government source. This is the single largest gap in this record. It could change the telecom rating from open to closed. If you run a telecoms business in Poland, check this first.
The exact incident reporting deadlines in the amended Polish cyber security act
We confirmed the amendment entered into force on 3 April 2026, from the electronic communications regulator's own announcement. We could not confirm the article text. The 24-hour and 72-hour figures come from the European directive the act implements, not from the Polish wording.
Whether the Act of 10 May 2018 creates criminal offences for unlawful processing, and the prison terms
We could not confirm the later articles of this Act. Criminal liability is widely reported, but we have no government quotation for it. So we describe it as reported, not as confirmed.
Whether Poland caps administrative fines on public sector bodies, and at what amount
A cap is widely reported. We could not confirm it from a government source. Note that the regulator did fine the Minister of Justice in June 2026, so any cap is clearly not immunity.
The age at which a child can consent to online services in Poland
We checked the articles of the 2018 Act we could read, and none of them sets an age. Article 8 of that Act deals with data protection officers, not children. Poland is understood not to have lowered the European default of 16, but we have no government confirmation.
Retention periods for medical documentation, accounting books and employment records
The ministries that own these rules do not publish the binding text on a page we could read. The minimum periods certainly exist. Check the numbers against the statutes before you use them.
Whether accounting books for a Polish entity may lawfully be kept on servers outside Poland, and what notification that requires
This is a hidden rule that behaves like a requirement to keep data in the country. We could not confirm it against the Ministry of Finance's question-and-answer content. Treat it as an open question for any outsourced finance function.
Whether Poland imposes residency conditions on public administration cloud services
The state runs its own cloud at chmura.gov.pl. We found no procurement or legal requirement about where data must sit, so we state none.
Whether any localisation or export restriction applies to state mapping and surveying data, or to online gambling archiving systems
We reached both regulators' sites and neither publishes such a rule on the pages we could read. Checked 18 August 2026. We record this as no rule found, not as no rule existing.
The current status of the banking law's outsourcing rules for suppliers based outside the European Economic Area
We verified the financial supervisor's cloud communication in full. We could not confirm the Banking Act itself, so we do not know whether a separate permission requirement still applies to outsourcing partners outside Europe.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.