• PL
  • EN
  • Proud Member of Alliott Global Alliance — Chambers Top Ranked Global 2023
    Data protection legal solutions with Wołoszański & Partners

    Personal Data Protection

    GDPR implementations and audits, ongoing compliance and breach support — we protect your company's data and reduce the risk of fines.
    Home Services Personal Data Protection / GDPR

    Virtually every operating company processes personal data — of clients, employees, contractors and users. The GDPR has applied in Poland since 2018, but the risk landscape in 2026 looks different than it did a few years ago: fines imposed by the President of the Polish DPA (UODO) have risen sharply, cybersecurity has become a duty for the management of entities covered by the National Cybersecurity System Act (the NIS2 implementation), and the use of artificial intelligence has added another layer of obligations to personal data.

    At the foundation of the GDPR are principles that must be met whatever the industry: lawful bases for processing, data minimisation, correct retention periods, security (Art. 32) and accountability — the ability to demonstrate compliance. So GDPR compliance is not a one-off "paper" project but a state you have to maintain: up-to-date registers and documentation, correct data-processing agreements, real procedures for a breach and for data-subject requests. Gaps usually surface at the worst moment — during an inspection, a data leak or a transaction in which a buyer examines compliance.

    We guide companies through this whole area: from an audit and implementation, through ongoing advice and outsourcing of the data protection officer (DPO) function, to representation before the President of the UODO. Rather than leaving you with a bare statement that "this is what the rule says", we implement the specific documents and procedures that genuinely work in your organisation.

    How we help

    Data audit & mapping

    We check what data you process, on what basis and where, and where the compliance gaps and risks are.

    GDPR implementation

    A complete rollout: lawful bases, policies, procedures and documentation tailored to the company.

    Records, retention & documentation

    The record of processing activities (RoPA), a data-retention and deletion policy, a data-protection policy and internal procedures.

    Processing agreements & processors

    Data-processing agreements (Art. 28 GDPR), assessment of IT and cloud providers and controller–processor relations.

    Information duties & consent

    Privacy notices, consents and lawful bases — correct, clear and demonstrable.

    Data-subject requests (DSAR)

    Handling access, rectification, erasure ("right to be forgotten") and objection requests, within GDPR deadlines.

    Breaches & UODO notifications

    Assessing a breach, notifying the President of the UODO within 72 hours and informing the data subjects.

    Impact assessments (DPIA)

    A data protection impact assessment where processing may result in high risk (Art. 35 GDPR).

    Outsourced DPO

    Acting as, or supporting, your data protection officer — independently and without a conflict of interest.

    Transfers outside the EEA

    Lawful transfers to the US and other countries: the DPF, standard contractual clauses (SCC) and transfer impact assessments.

    Employee monitoring & biometrics

    Monitoring, email review and biometrics in line with the Labour Code and the proportionality principle.

    GDPR in AI, marketing & cookies

    Data in AI systems, marketing and profiling, and cookie consent — at the crossroads of GDPR, the AI Act and telecoms law.

    Our data protection specialists

    Your matter is handled by lawyers for whom data protection is daily practice, not a side topic.

    Marta Solarska-Kaleńczuk

    Marta Solarska-Kaleńczuk

    Partner, COO,
    Data Protection Officer

    Implements and audits GDPR programmes, handles breaches and acts as data protection officer; works at the crossroads of data protection, new technologies and competition law.

    Contact MartaClick the card to see the full profile ›
    Oliwia Koper

    Oliwia Koper

    Associate, Advocate

    An advocate advising businesses on data protection: data-processing agreements, information duties, e-commerce and new technologies, and representation in disputes.

    Contact OliwiaClick the card to see the full profile ›

    How we work with you

    We start with what genuinely protects the company — not with a stack of documents "for the drawer".

    01

    Audit

    We establish what data and processes you have, where the gaps are and which risks are most pressing.

    02

    Implementation plan

    We prioritise the work and present a plan with scope, cost and a timeline.

    03

    Implementation & documentation

    We prepare policies, registers, data-processing agreements and procedures — ready to use.

    04

    Maintenance & cover

    We run ongoing compliance, updates and support during breaches and inspections.

    Frequently asked questions about personal data protection

    Does my company have to comply with the GDPR?

    In practice, yes — the GDPR applies to any entity that processes personal data, regardless of size. If you have clients, employees, collaborators, website or newsletter users, then you process personal data and are subject to the GDPR. There is no company-size threshold and no "we are small" exemption — the obligations differ in scale, but not in whether they apply.

    The scope of the obligations depends on what data you process and for what purpose. It looks different for a sole trader running a newsletter, different for a company that employs staff and uses monitoring, and different again where special categories of data (for example health data) are processed or large-scale profiling is carried out. Some obligations — such as the record of processing or appointing a DPO — depend precisely on those circumstances.

    We help establish which obligations genuinely apply to you and implement them in a sensible scope — without over-regulating a small company and without gaps in a larger one. The starting point is usually a short audit, after which you know what is urgent and what can wait.

    How large are the fines for a GDPR breach?

    The GDPR provides for administrative fines of up to EUR 20 million or — for an undertaking — up to 4% of total worldwide annual turnover, whichever is higher. These are the upper ceilings for the most serious infringements; in practice the amount depends on factors such as the nature of the breach, the number of people affected, the degree of fault and cooperation with the authority.

    In Poland, 2025 was a record year: the President of the UODO imposed fines totalling over PLN 64 million, including some of the highest in the country's history — among them Bank ING (about PLN 18.4 million, in connection with the unlawful processing of identity-document data) and McDonald's Poland (about PLN 16.9 million, after employee data were exposed through, among other things, failures in risk analysis, security and oversight of a processor). These are amounts imposed — not necessarily final or collected: the largest (PLN 27.1 million, national-ID data, Poczta Polska) was annulled by the court, but that judgment is non-final and contested by the UODO. The clear trend, though, is towards higher, deterrence-oriented fines for systemic infringements, and the financial and reputational risk is real.

    Beyond the fine itself come further costs: handling the incident, notifications, claims by those affected and loss of client trust. That is why it pays to invest in compliance before a problem arises. We help reduce the risk on the organisational and documentation side and, if proceedings begin, represent the company before the President of the UODO.

    What is NIS2 and the new KSC Act — does it apply to my company?

    NIS2 is an EU cybersecurity directive that Poland implemented by amending the National Cybersecurity System Act (KSC). The amendment entered into force on 3 April 2026, but the obligations phase in: covered entities should implement the requirements (among others an information-security management system, risk assessment and incident reporting and handling) by 3 April 2027, and mandatory audits and real penalties begin from 3 April 2028. The catalogue of covered entities expanded from about 400 to roughly 38,000 (most of them public-sector bodies).

    NIS2 covers "essential" and "important" entities in listed sectors (among others energy, transport, healthcare, digital infrastructure, manufacturing and ICT service providers) — often including medium-sized companies that previously had no obligations here. For covered entities, cybersecurity has ceased to be solely an IT matter: it has become a duty of the entity's manager, with requirements on risk management, supply-chain security and incident reporting. Penalties vary by entity category and, in the most serious cases, can reach as high as PLN 100 million.

    Data protection and cybersecurity overlap heavily here — the same incident is often at once a personal-data breach (GDPR) and an incident reportable under the KSC/NIS2, though the two regimes have different thresholds, deadlines and recipients. We help establish whether and to what extent NIS2 applies to your company, and implement the requirements coherently with the GDPR and — where relevant — with DORA. You can read more about the compliance area on our compliance and ESG page.

    When must I appoint a data protection officer (DPO)?

    Appointing a data protection officer is mandatory in three cases: where the processing is carried out by a public authority or body (except courts acting in their judicial capacity); where the core activity consists of regular and systematic monitoring of individuals on a large scale; and where the core activity consists of large-scale processing of special categories of data (for example health data) or data on convictions. The tests are assessed separately for a controller and for a processor. Outside those cases, appointing a DPO is voluntary — but often worth considering nonetheless.

    A DPO must have expert knowledge, act independently and free of a conflict of interest, and report directly to the highest level of management. In practice it is hard to combine this role with a function that decides on the purposes and means of processing (for example a board member or the head of IT), as that would amount to "checking oneself".

    That is why many companies outsource the role. We offer outsourcing of the data protection officer or support for your in-house DPO — combining independence, experience and availability without the cost of another full-time hire. We also handle the formalities: a DPO is a specific natural person, and their contact details are published and notified to the President of the UODO electronically within 14 days of appointment (and on any change or dismissal). And we help assess whether, in your case, appointing a DPO is mandatory or merely advisable.

    What is a data protection impact assessment (DPIA) and when is it mandatory?

    A data protection impact assessment (DPIA) is a risk analysis that must be carried out before starting processing that is likely to result in a high risk to people's rights and freedoms (Art. 35 GDPR). It answers the questions: what data do we process and why, what are the threats and how do we reduce them to an acceptable level.

    A DPIA is mandatory in cases such as systematic profiling with legal effects, large-scale processing of special categories of data, and systematic monitoring of publicly accessible areas. The President of the UODO also publishes a list of operations for which an assessment is required. If, despite the measures applied, the risk remains high, a prior consultation with the supervisory authority may be necessary before the processing begins.

    Increasingly, a DPIA is combined with the fundamental-rights impact assessment (FRIA) required under the AI Act — where the high risk relates to the use of an artificial-intelligence system. We help carry out the assessment, choose risk-mitigating measures and document the whole process so that it can be demonstrated during an inspection.

    What should I do if a personal-data breach (leak) occurs?

    The first hours matter most. A breach that may pose a risk to the rights or freedoms of individuals (where such a risk is "not unlikely") must be reported to the President of the UODO without undue delay, and no later than 72 hours after becoming aware of it; for cross-border processing you must also identify the lead authority. If the risk to individuals is high, the affected data subjects must additionally be informed — unless one of the Art. 34 exceptions applies (for example the data were encrypted, or a public communication is used instead of individual notices). Every breach — even one that is not reported — must be recorded in an internal register.

    In practice, prior preparation is what counts: a response procedure, a clear division of roles and knowing how to assess the severity of a breach. Under time pressure it is easy to slip up — a late or unnecessary report, missing documentation, chaotic communication with clients. The same incident may at the same time be an event reportable under NIS2/KSC, so it is worth keeping the procedures aligned.

    We support companies both before an incident (procedures, tests, training) and during one: we help assess whether and what to report, prepare the report and notifications and manage communication. When a matter turns into proceedings, we represent the company before the President of the UODO.

    How can I lawfully transfer data outside the EEA (for example to the US)?

    Transferring data outside the European Economic Area is permitted only on one of the bases provided for in the GDPR. The simplest situation is a country covered by a European Commission adequacy decision. For the US, that basis is the EU–US Data Privacy Framework — but only a recipient certified under the programme can rely on it.

    The status of the transatlantic framework is, however, uncertain. In September 2025 the EU General Court upheld the DPF adequacy decision, but the ruling has been appealed to the Court of Justice of the EU (the Latombe case, C-703/25 P, pending), and privacy organisations have announced further challenges. The DPF, moreover, covers only recipients currently certified under the programme. The DPF currently applies, but it is prudent to have a "plan B" in case it is struck down — as happened with the earlier mechanisms (Safe Harbour, Privacy Shield).

    Where a recipient does not rely on an adequacy decision, the main tool is the standard contractual clauses (SCC) — which, however, are not enough on their own: they require a documented transfer impact assessment (TIA), often additional safeguards and ongoing monitoring. We help choose the right basis, prepare the SCC and the transfer assessment and put in order data flows to cloud providers and tools based outside the EU.

    How does the GDPR relate to the AI Act and the use of artificial intelligence?

    The two regimes apply in parallel and complement each other. If an artificial-intelligence system processes personal data, GDPR obligations (a lawful basis, information duties, data-subject rights — including the Art. 22 rules on decisions taken solely by automated means — and a DPIA) apply regardless of the AI Act. The AI Act deadlines for high-risk systems have, however, been postponed by an amendment (the so-called Omnibus): obligations for stand-alone Annex III systems apply from 2 December 2027, and for AI embedded in Annex I products from 2 August 2028. From 2 August 2026 only the transparency requirements (Art. 50) begin to apply — for example telling users they are dealing with AI or AI-generated content.

    The scope of your obligations depends on your role (provider or deployer of the system) and on the risk level of the particular use. A fundamental-rights impact assessment (FRIA) under the AI Act is not a general obligation — it applies to specific actors (among others public bodies and private providers of public services, and certain uses such as creditworthiness assessment or life and health insurance) and complements, rather than replaces, the DPIA required by the GDPR.

    The European Data Protection Board stresses that a model's anonymity cannot be assumed up front — it requires a case-by-case assessment of the risk of identifying individuals and of extracting data from the model. We help arrange the use of AI in line with both regimes: establishing roles and risk, preparing lawful bases, assessing automated decisions (Art. 22), carrying out the DPIA (and a FRIA where required) and setting out rules for employees' use of AI tools — so as to adopt AI safely rather than give it up out of fear of the rules.

    Can I monitor employees and use biometrics?

    Yes, but within the limits of the law and the proportionality principle. The Labour Code permits monitoring (video, email and other forms) only for specific purposes — such as ensuring safety, protecting property or checking the organisation of work — and only after informing employees in advance and introducing the rules into internal documentation. Monitoring may not infringe dignity or personal rights, nor cover areas where that would be excessive.

    Biometric data are a special category of data when they are processed for the purpose of uniquely identifying a person (for example a fingerprint or facial geometry used for recognition) — an ordinary employee photo is not automatically "biometric data". The Labour Code allows an employer to collect biometric data from an employee only in a narrow scope — as a rule, where it is necessary to control access to particularly important information or premises. For special-category data the consent must, as a rule, come from the employee and carry no detriment on refusal, and in a relationship of subordination it may be ineffective — so "fingerprint entry for everyone" is most often excessive.

    We help design monitoring and any biometrics so that they achieve the purpose with the least intrusion: choosing the measure, the legal basis, privacy notices, provisions in workplace rules and retention periods. That way you reduce the risk of disputes with employees and objections from the President of the UODO.

    How do I lawfully collect marketing consents and handle cookies?

    Consent must be freely given, specific, informed and unambiguous — and the company must be able to demonstrate that it obtained it. In practice this means separate, non-pre-ticked boxes, a clear description of the purpose and the ability to withdraw consent as easily as it was given. "Forced" consents (for example access to content only after accepting marketing) are usually defective.

    Cookies and similar technologies are an additional layer: alongside the GDPR, the rules of the Polish Electronic Communications Law (PKE) apply here, and authorities expect a genuine choice — "accept" and "reject" on equal terms, with no hidden consents. The rules may change: the Digital Omnibus package (a European Commission proposal of 19 November 2025 — separate from the already-adopted amendment to the AI Act itself, and still not adopted) proposed, among other things, moving the cookie rules into the GDPR and a minimum period during which consent may not be re-requested after refusal. Until it is adopted, the existing rules apply.

    We put consents and cookies in order from both the legal and the implementation side: the wording of consents and notices, configuring the banner and cookie categories, recording consents and consistency with privacy policies. That way marketing works, and the company is able to demonstrate compliance during an inspection.

    What is the difference between a controller and a processor, and why the data-processing agreement?

    A controller is the entity that decides on the purposes and means of processing (for example your company in relation to its own clients' and employees' data). A processor processes data on behalf of, and on the instructions of, the controller — most often service providers: hosting, cloud, HR systems, marketing or accounting. The same company may be a controller in some processes and a processor in others.

    Which agreement is needed depends on the provider's role — so we establish it first. If the provider acts as a processor (on your instructions), the GDPR requires a data-processing agreement (Art. 28) setting out, among other things, the scope, purpose, duration and manner of processing and the processor's obligations on security and sub-processing. If instead the provider decides on the purposes of processing itself, it is a separate or joint controller — and then different arrangements apply (for example a joint-controllership agreement). The "terms of service" alone are usually not enough, and mis-classifying the role is one of the more common gaps caught during audits.

    We help correctly classify the roles in each process, prepare and negotiate data-processing agreements and assess providers for security and data location. This is especially important when using cloud tools and providers outside the EU, where it ties in with the question of transfers.

    Where do we start our cooperation?

    We start with a short audit: we establish what data and processes you handle, on what basis, to whom you entrust data and where the biggest gaps and risks are. The result is a clear map of your compliance status together with priorities — what is urgent (for example missing processing agreements, defective consents, no breach procedure) and what can be spread out over time.

    On that basis we propose a plan with scope, cost and a timeline, and then move to implementation: policies and procedures, registers, privacy notices, data-processing agreements, a breach-response procedure and, where needed, a DPIA. We can also take over the data protection officer function or support your DPO on an ongoing basis.

    We match the cooperation model to the scale of the company: from a one-off implementation, through ongoing advice, to a full outsourcing of the DPO function. You can book a first conversation and an initial assessment through our contact form. If you are looking for broader legal support for your company, see also outsourcing of legal services.

    Legal position: July 2026. Data protection law is changing rapidly — among other things, work is under way on the so-called Digital Omnibus (a proposal to amend the GDPR, cookie rules and the Data Act, announced by the European Commission on 19 November 2025 and not yet adopted). The President of the UODO has also announced a 2026 sectoral inspection plan (among others marketing entities and delivery platforms), and inspections are not limited to that plan. This information is general in nature and does not constitute legal advice on an individual matter.

    Let us take care of the data in your company

    Book a short call — afterwards you will know where the biggest risks are and where to start your GDPR implementation.