A Kraków-based software company receives a routine inquiry from the Polish supervisory authority – the Personal Data Protection Office (Urząd Ochrony Danych Osobowych, UODO) – asking for documentation of its data processing activities. The company's legal team scrambles. Records of processing activities are incomplete. Consent clauses in customer contracts have not been updated since 2018. The data protection officer was appointed but never given a formal mandate. What follows is a corrective proceeding that could have been avoided entirely.

GDPR compliance in Poland is supervised by the UODO, which has intensified its audit activity since 2024. Polish companies face fines of up to EUR 20 million or 4% of global annual turnover for serious violations – whichever is higher. The most common gaps found during audits are not exotic edge cases; they are procedural failures that accumulate quietly over months and become costly when discovered.

This alert covers the three compliance gaps that UODO inspections most frequently expose, explains who is affected, and sets out immediate action items with concrete deadlines. Foreign investors operating through Polish subsidiaries and domestic companies processing personal data at scale should treat this as a checklist, not background reading.

What are the most common GDPR compliance gaps found in Polish companies?

Polish data protection law operates under the same framework as the rest of the EU, but the UODO's enforcement priorities have a distinctly local character. Three gaps appear in virtually every audit. First: outdated or absent records of processing activities (RoPA). Second: defective legal bases for data transfers – particularly relevant given the volume of cross-border data flows between Polish entities and their EU and non-EU counterparts. Third: inadequate data processor agreements with vendors and subcontractors.

The RoPA requirement applies to any organisation employing more than 250 people, and also to smaller entities if they process data that poses a risk to individuals' rights or freedoms. In practice, this threshold captures most B2B software companies, HR platforms, and e-commerce operators. We have seen RoPA documents that were accurate at the time of drafting but never updated to reflect new SaaS tools, cloud migrations, or changes in marketing consent flows – a gap that UODO treats as a continuing violation.

Data transfer compliance is a separate pressure point. Polish subsidiaries of international groups routinely send employee and customer data to parent companies in non-EEA jurisdictions. Without valid Standard Contractual Clauses (SCCs) or another recognised transfer mechanism, each such transfer is unlawful. Our team obtained a reversal of a corrective decision for a technology client in Małopolska (spring 2026) by demonstrating that SCCs had in fact been executed – but the documentation had simply not been filed in the right place. For a practical overview of transfer mechanisms, see our analysis of data transfer from Poland to Sweden: legal mechanisms.

Processor agreements are the third gap. Polish companies frequently sign vendor contracts that contain a data processing clause but omit mandatory elements: the subject matter and duration of processing, the nature and purpose, the type of personal data, and the categories of data subjects. A clause that says "the vendor will keep data confidential" is not a compliant processor agreement. UODO has issued fines specifically for this deficiency.

Who is affected and what must be done within 30 days?

The short answer: any Polish company that processes personal data as part of its core business activity. That includes manufacturers with employee databases, IT firms handling client data, retailers with loyalty programmes, and professional services firms storing client files. The UODO's 2024–2025 inspection programme targeted healthcare, fintech, and e-commerce sectors specifically – but enforcement is not sector-limited. Companies operating in corporate groups should also review subsidiary liability in Polish corporate groups, since GDPR violations at subsidiary level can create reputational and contractual exposure for the parent.

Immediate action items fall into three categories. Documentation must be audited and updated. Legal bases must be verified for each processing activity. Vendor relationships must be reviewed for compliant processor agreements. A 30-day internal review cycle is the minimum defensible standard – UODO expects companies to be able to produce documentation within days of a formal request, not weeks.

What to prepare before an audit:

  • Current RoPA covering all processing activities, including new tools added in the past 12 months
  • Executed SCCs or equivalent transfer mechanisms for all non-EEA data flows
  • Data processor agreements with every vendor that accesses personal data
  • Written mandate and reporting line for the Data Protection Officer (DPO), if appointed
  • Evidence of staff training on data handling completed within the past 12 months

Technology companies should also monitor the intersection of GDPR with the AI Act Poland obligations now entering force, and with DORA compliance requirements for financial sector entities. Both frameworks impose data governance obligations that overlap with – and in some cases exceed – standard GDPR requirements. IP lawyer Warsaw practices are increasingly asked to advise on how trademark and IP protection strategies interact with data processing in product development contexts, a question that also arises for Swiss tech companies expanding into Poland. For that cross-border dimension, see our note on IP protection strategy for Switzerland tech companies in Poland.

We secured a full compliance clearance for a manufacturing client in the Mazowieckie region (autumn 2025) after a targeted UODO inquiry. The key was producing a complete, dated RoPA alongside executed processor agreements covering the company's ERP and payroll vendors. Neither document had existed six months earlier. The inquiry closed without a fine. The cost of preparation was a fraction of the EUR 20 million maximum exposure.

Specific situations require specific analysis. If your company has not reviewed its GDPR documentation in the past 12 months, or if you are operating under a corporate group structure with cross-border data flows, the window to act before an inspection is narrowing. To receive an expert assessment of your company's GDPR compliance position, contact info@kordeckipartners.com.

Frequently asked questions

Q: Does the RoPA requirement apply to small Polish companies?

A: The general threshold is 250 employees, but Polish data protection law and GDPR both extend the obligation to smaller entities that process sensitive data categories, data related to criminal convictions, or data that poses a risk to individuals' rights on a non-occasional basis. Most active B2B or B2C businesses fall within scope regardless of headcount. A company should assess its actual processing activities rather than rely on the employee count alone.

Q: How long does a UODO audit typically take, and what are the costs of non-compliance?

A: A standard UODO inspection can last between two weeks and several months depending on the scope. Administrative fines for serious violations reach EUR 20 million or 4% of global annual turnover. Beyond fines, corrective decisions may require suspension of processing activities – which is operationally disruptive and commercially damaging for data-dependent businesses.

Q: Is a data processing clause in a vendor contract sufficient, or is a separate agreement required?

A: A clause embedded in a commercial contract can satisfy the processor agreement requirement, but only if it contains all mandatory elements under GDPR: subject matter, duration, nature and purpose of processing, type of data, categories of data subjects, and the controller's specific instructions. A general confidentiality clause does not meet this standard. Many Polish companies discover this gap only when UODO requests documentation – by which point the violation has already occurred.

KORDECKI & Partners is a law firm based in Warsaw and Krakow, advising business clients across 30 jurisdictions. Our team combines expertise in Polish and international law with a practical approach to GDPR compliance, data protection audits, and technology regulation. We work with Polish entrepreneurs, foreign investors, and in-house legal teams. To discuss your situation, contact info@kordeckipartners.com.

Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. KORDECKI & Partners assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@kordeckipartners.com.