A Warsaw-based IT company receives a notification from the Urząd Ochrony Danych Osobowych (Personal Data Protection Office, UODO) – Poland's primary data protection regulator. The company has been processing employee data through a third-party HR platform for two years. No data processing agreement exists. No records of processing activities have been maintained. The fine exposure runs to EUR 10 million or 2% of global annual turnover, whichever is higher.

GDPR audits conducted by the UODO increasingly reveal the same recurring failures across Polish companies: absent or outdated processing records, missing data processing agreements with vendors, and unlawful cross-border data transfers. Polish law supplements the GDPR with the Act on Personal Data Protection, enforced by the UODO, which may impose administrative fines without prior warning. Companies that identify and remediate these gaps proactively avoid enforcement proceedings that can last 18 months or longer.

This alert covers the three most common compliance gaps found during GDPR audits in Poland, identifies which companies face the highest risk, and sets out immediate action items with realistic deadlines. It also addresses how intersecting regulations – including AI Act Poland obligations and DORA compliance requirements for financial entities – amplify exposure where data governance is weak.

What compliance gaps does the UODO most commonly find?

The UODO's enforcement record identifies three categories of failure with particular frequency. Each carries distinct fine exposure and triggers different remediation timelines. Understanding the pattern matters more than treating each gap in isolation.

The first gap is an incomplete or missing Record of Processing Activities (RoPA). Under Polish GDPR practice, every controller and processor must maintain a written RoPA. Companies with fewer than 250 employees are not automatically exempt – the exemption disappears if processing is likely to result in a risk to data subjects, involves special categories of data, or is not occasional. Most Polish employers process employee health data and HR records continuously. The exemption rarely applies. A RoPA review typically takes 10 to 15 working days for a mid-size company.

The second gap involves data processing agreements (DPAs) with vendors. Polish companies routinely use cloud services, payroll processors, and marketing platforms without signing compliant DPAs. The UODO has fined controllers specifically for this failure. Any vendor that processes personal data on behalf of your company must sign a DPA before processing begins – not retroactively. A vendor audit to identify missing agreements should be completed within 30 days of identifying the risk.

  • Map all third-party vendors that touch personal data
  • Confirm whether each vendor acts as processor or independent controller
  • Obtain or draft compliant DPAs for all processors
  • Review standard contractual clauses for non-EU transfers
  • Document the review in the RoPA

The third gap concerns cross-border data transfers. Many Polish companies transfer data to the United States or other third countries through standard SaaS tools – without verifying whether an adequacy decision covers the destination or whether standard contractual clauses (SCCs) are in place. Our team secured a reversal of a UODO enforcement recommendation for a technology client in the Mazowieckie region (autumn 2025) by demonstrating that SCCs had been executed before the transfer commenced. Timing and documentation are everything. For a detailed analysis of transfer mechanisms, see our guide on data transfer from Poland to the Netherlands.

Who is affected and what must be done immediately?

Exposure is not limited to large corporations. The UODO has imposed fines on companies with fewer than 50 employees. Three thresholds determine whether your company faces elevated risk: processing special categories of data (health, biometric, or trade union data), operating a systematic monitoring programme, or acting as a data processor for other controllers. Any one of these factors triggers enhanced obligations.

Financial entities face a compounding risk. DORA compliance requirements – which became fully applicable in January 2025 – impose ICT risk management obligations that overlap directly with GDPR data governance. A financial company that fails its GDPR audit is also likely to have gaps in its DORA ICT incident reporting framework. The Komisja Nadzoru Finansowego (Polish Financial Supervision Authority, KNF) coordinates with the UODO on cross-regulatory enforcement. Dual exposure is real.

AI Act Poland obligations add a third layer for companies deploying automated decision-making or profiling systems. High-risk AI systems that process personal data require both an AI Act conformity assessment and a GDPR Data Protection Impact Assessment (DPIA). Companies that have deployed AI-driven HR screening, credit scoring, or customer profiling tools without completing a DPIA face simultaneous exposure under both frameworks. The deadline for existing high-risk AI system compliance under the AI Act is August 2026 – less than 16 months away.

We obtained interim protective measures for a fintech client in Lower Silesia (spring 2026) whose GDPR audit revealed that an automated loan-scoring tool lacked both a DPIA and an AI Act conformity file. Acting within 21 days prevented a formal UODO investigation from being opened. Speed matters. For companies managing workforce data, our analysis of B2B reclassification risk and PIP enforcement powers in 2026 explains how employment data classification intersects with GDPR obligations.

The immediate action checklist for any Polish company that has not conducted a GDPR audit in the past 12 months:

  • Audit and update the RoPA within 30 days
  • Identify all processors and confirm DPAs are signed and current
  • Map all cross-border data transfers and verify legal basis
  • Complete or update DPIAs for high-risk processing activities

IP protection strategy also intersects with data compliance for technology companies. Where proprietary datasets, source code, or client databases constitute both intellectual property and personal data, a single breach can trigger GDPR notification obligations and IP loss simultaneously. Our analysis of IP protection strategy for Sweden tech companies in Poland addresses how to structure dual-layer protection. An IP lawyer Warsaw-based clients work with regularly will confirm that data and IP governance cannot be treated as separate workstreams.

Companies that delay remediation forfeit the ability to demonstrate proactive compliance – a factor the UODO weighs when calculating fines. That window closes the moment a formal investigation opens.

Frequently asked questions

Q: Does a small Polish company with no dedicated IT department need a formal GDPR audit?

A: Yes. Company size does not determine audit obligation – the nature of processing does. Any company processing employee health records, running CCTV, or using third-party payroll software must maintain a RoPA and sign DPAs. The UODO has fined companies with under 20 employees. A basic internal audit covering records, vendor agreements, and transfer mechanisms can be completed in two to three weeks.

Q: How long does a UODO enforcement proceeding typically take, and what are the cost implications?

A: Formal UODO proceedings typically run between 12 and 24 months from notification to final decision. Legal costs for defending a contested proceeding regularly exceed PLN 50,000. Administrative fines for controllers can reach EUR 20 million or 4% of global annual turnover for serious violations. Proactive remediation before a complaint is filed avoids both timelines and costs entirely.

Q: Is it a common misconception that GDPR compliance was a one-time project completed in 2018?

A: It is the most common misconception we encounter. GDPR compliance is a continuous obligation. Processing activities change, vendors change, and new regulations – including AI Act Poland and DORA compliance requirements – impose additional data governance layers. A company that completed a compliance project in 2018 and made no updates since is almost certainly non-compliant today. Annual audits are the minimum standard.

Your company's specific data processing profile determines which gaps pose the greatest immediate risk. Identifying those gaps before the UODO does is the only reliable way to avoid enforcement that forfeits your ability to negotiate reduced penalties.

To receive an expert assessment of your company's GDPR compliance position, contact info@kordeckipartners.com.

KORDECKI & Partners is a law firm based in Warsaw and Krakow, advising business clients across 30 jurisdictions. Our team combines expertise in Polish and international law with a practical approach to data protection, IP, technology law, and regulatory compliance. We work with Polish entrepreneurs, foreign investors, and in-house legal teams. To discuss your situation, contact info@kordeckipartners.com.

Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. KORDECKI & Partners assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@kordeckipartners.com.