A Warsaw-based e-commerce company receives a letter from the Personal Data Protection Office (Urząd Ochrony Danych Osobowych, UODO). The letter opens a formal inquiry into whether the company's customer database processing meets General Data Protection Regulation (GDPR) requirements. The compliance team has 14 days to respond. Miss the deadline, and the inquiry escalates to a full investigation – one that can end in a fine reaching EUR 20 million or four percent of global annual turnover, whichever is higher.

UODO enforces the GDPR in Poland through a structured administrative procedure that moves from initial inquiry to formal decision within months, not years. Fines already issued in Poland have ranged from tens of thousands to several million PLN, with the largest individual penalties exceeding PLN 3 million. Any controller or processor established in Poland – or targeting Polish data subjects – falls within UODO's jurisdiction, regardless of corporate structure or country of headquarters.

This guide explains how UODO enforcement works in practice, what procedural steps to expect, which sectors have drawn the most attention, and what concrete actions reduce exposure. The analysis covers the full cycle: from the first investigative letter to post-decision appeal before the Wojewódzki Sąd Administracyjny (Regional Administrative Court, WSA) and, if necessary, the Naczelny Sąd Administracyjny (Supreme Administrative Court, NSA).

How does UODO open and conduct a GDPR investigation?

UODO investigations begin in one of three ways: a data subject complaint, an ex officio inquiry triggered by media reports or a data breach notification, or a sector-wide sweep. The most common trigger is a complaint. UODO receives several thousand complaints annually, and the office has demonstrated a clear preference for cases involving large volumes of data subjects or systemic failures rather than isolated incidents.

Once an inquiry opens, the controller typically has 14 to 30 days to submit written explanations and documentation. UODO may request processing records, data protection impact assessments, consent forms, processor agreements, and evidence of technical and organisational measures. Failure to respond – or a response UODO considers incomplete – extends the procedure and signals non-cooperation, which Polish administrative courts have confirmed is an aggravating factor in fine calculations.

The formal investigation phase can last from three months to over two years, depending on complexity. UODO may conduct on-site inspections, request additional rounds of submissions, and consult with other European data protection authorities through the consistency mechanism of the European Data Protection Board (EDPB). Controllers in cross-border cases – where Poland is not the lead supervisory authority – face a different timeline governed by the one-stop-shop procedure under GDPR.

  • Initial inquiry letter: 14–30 day response window
  • Documentation review: 1–6 months
  • On-site inspection (if ordered): scheduled with 7 days' notice
  • Draft decision and right to be heard: 14 days to comment
  • Final administrative decision: issued within the overall administrative procedure deadline

One concrete figure matters here: under Polish administrative procedure law, UODO must in principle resolve a case within one month of gathering all necessary evidence, with a two-month limit for complex cases. In practice, UODO issues a notification extending proceedings when the factual picture is unclear. Controllers who engage proactively – submitting organised evidence and demonstrating remediation steps – consistently shorten the timeline.

What factors determine the size of a GDPR fine in Poland?

UODO applies the same eight corrective criteria that apply across the EU: the nature, gravity, and duration of the infringement; intent or negligence; mitigation measures taken; technical and organisational safeguards; notification of the breach; cooperation with UODO; categories of personal data affected; and how UODO learned of the infringement. Polish enforcement decisions show that three of these criteria carry the most practical weight in fine calculations.

First, the number of data subjects affected. Decisions involving fewer than 1,000 individuals have produced fines in the PLN 10,000–100,000 range. Cases affecting hundreds of thousands of people have generated penalties exceeding PLN 1 million. This is not a statutory rule – it is a pattern visible across published UODO decisions, and it shapes how practitioners assess exposure from the outset.

Second, the controller's cooperation during the investigation. UODO has explicitly noted in several decisions that prompt breach notification to the supervisory authority (within the 72-hour window required by GDPR) and proactive submission of remediation evidence reduced the fine that would otherwise have applied. We secured a significant reduction in administrative penalties for a retail client in the Mazowieckie region (spring 2025) by preparing a structured remediation report before UODO issued its draft decision.

Third, whether the infringement was systemic or one-off. A single misconfigured server disclosed to UODO within hours carries far less weight than a pattern of ignoring subject access requests over 18 months. UODO has issued fines of PLN 2.8 million or more in cases where the controller had received prior warnings and failed to act. That trajectory – warning, inaction, fine – is the one practitioners work hardest to break early.

The GDPR maximum is EUR 20 million (approximately PLN 85 million at current rates) or four percent of global annual turnover for the most serious infringements. For smaller violations – such as failures to maintain processing records – the cap is EUR 10 million or two percent of turnover. Polish courts reviewing UODO decisions have, in several cases, reduced fines on proportionality grounds, which creates a real appellate strategy worth considering.

Which sectors face the highest GDPR enforcement risk in Poland?

UODO's published enforcement record shows a clear sectoral pattern. Financial services, telecommunications, healthcare, and e-commerce have attracted the largest fines and the highest number of formal decisions. Each sector has a distinct risk profile, and understanding that profile shapes compliance investment decisions.

Financial services firms – banks, insurance companies, and payment processors – process large volumes of sensitive financial data and are subject to dual regulation: GDPR and the requirements of the Polish Financial Supervision Authority (Komisja Nadzoru Finansowego, KNF). A GDPR breach in this sector can trigger parallel KNF enforcement. Since January 2025, DORA compliance obligations have added a third regulatory layer for entities classified as financial entities under that regulation. DORA compliance and GDPR compliance overlap significantly in ICT risk management and incident reporting.

Healthcare providers and medical record processors have drawn UODO attention because health data falls within the special categories attracting the higher EUR 20 million fine cap. A single misconfigured patient portal – exposing records of 50,000 patients – creates immediate maximum-tier exposure. We obtained interim protective measures for a healthcare group in the Małopolska region (autumn 2024) while a UODO investigation was pending, preventing further data exposure during the inquiry period.

E-commerce and retail companies face volume-driven risk. Large customer databases, cookie consent failures, and automated profiling for targeted advertising are the three most common triggers. UODO has issued formal reprimands and fines to e-commerce operators whose consent mechanisms did not meet the freely given, specific, informed, and unambiguous standard. The intersection with AI Act Poland obligations – particularly around automated decision-making affecting consumers – is an emerging area that practitioners should monitor from 2025 onward.

  • Financial services: dual KNF/GDPR risk, DORA overlap from 2025
  • Healthcare: maximum-tier exposure for special category data
  • E-commerce: consent mechanisms, profiling, AI Act intersection
  • Telecommunications: bulk data, location data, marketing consent
  • Public sector: UODO has fined municipalities and state entities

How should businesses respond to a UODO inquiry?

The first 14 days after receiving a UODO inquiry letter are the most consequential. The response submitted in that window sets the factual and legal frame for everything that follows. A response that is accurate, organised, and demonstrates good-faith compliance effort gives UODO less to work with and signals the kind of cooperation that reduces fines. A defensive, incomplete, or legalistic response does the opposite.

Step one: map the processing activity under inquiry immediately. Identify the legal basis, the categories of data, the retention period, the processors involved, and any sub-processors. If a data protection impact assessment (DPIA) was required and was not conducted, acknowledge it and begin remediation. UODO has repeatedly noted that discovering a missing DPIA during an investigation and conducting it promptly is treated as a mitigating factor.

Step two: review the processor agreements. Under GDPR, controllers must have written agreements with every processor. Missing or outdated processor agreements are among the most common findings in UODO investigations. A 2023 UODO decision fined a controller PLN 1.5 million partly because processor agreements with three technology vendors lacked the mandatory clauses. Fixing this before the investigation closes matters.

Step three: prepare a remediation timeline with concrete milestones. UODO responds well to evidence that the controller is not merely explaining the past but changing the future. A written remediation plan with named responsible persons and 30/60/90-day checkpoints is more persuasive than general assurances. For guidance on cross-border data transfers – which frequently arise in investigations involving cloud processors – see our analysis of data transfer from Poland to the Netherlands and applicable legal mechanisms.

Step four: consider whether to engage an external data protection officer (DPO) or specialist counsel. Under GDPR, certain controllers must appoint a DPO – public authorities, large-scale systematic monitoring operations, and processors of special category data at scale. If a DPO is mandatory and was not appointed, that is a separate infringement. If a DPO exists, their role in the investigation response should be documented and visible to UODO.

What are the appeal options after a UODO decision?

A UODO administrative decision imposing a fine is not final. The controller has two procedural options. The first is a request for reconsideration (wniosek o ponowne rozpatrzenie sprawy) filed with UODO itself within 14 days of receiving the decision. This keeps the matter within the administrative authority and is useful when new evidence has emerged or when the factual basis of the decision contains clear errors. It does not suspend enforcement of the fine.

The second option – and the more strategically significant one – is an appeal to the WSA within 30 days of receiving UODO's decision. Polish administrative courts review UODO decisions for both procedural and substantive legality. Courts have overturned or reduced UODO fines on several grounds: disproportionality of the penalty relative to the infringement, procedural errors in the investigation, and incorrect application of the GDPR criteria. The NSA provides a further appellate level, though proceedings there can extend to two to three years.

For complex disputes involving technical evidence – such as whether a given security measure met the "state of the art" standard – the WSA may appoint an expert witness. The rules governing expert witnesses in Polish court proceedings are relevant here; for a detailed analysis, see our guide on expert witnesses in Polish court proceedings. The expert's report can become the pivotal document in a fine appeal.

One practical point: filing an appeal does not automatically suspend the obligation to pay the fine. Controllers must either pay and seek reimbursement if successful, or apply to the WSA for a stay of enforcement pending the appeal. The stay application is separate and requires demonstrating that enforcement would cause irreversible harm. Courts grant stays selectively – typically where the fine is large relative to the company's financial capacity and the legal arguments are substantive.

Frequently asked questions

Q: How long does a UODO enforcement procedure typically take from first inquiry to final decision?

A: The timeline varies significantly by complexity. Straightforward complaints involving a single controller and a defined dataset are typically resolved within six to twelve months. Complex cross-border cases, or those involving multiple processing activities, can extend to two years or more. The 72-hour breach notification window is a separate, much shorter obligation that runs independently of the main investigation timeline. Controllers should track both simultaneously from the moment an incident is identified.

Q: Is it a misconception that only large companies receive significant GDPR fines in Poland?

A: Yes, this is a common and costly misconception. UODO has issued fines against entities of all sizes, including small and medium enterprises, sole traders, and local government units. The scale of the fine reflects the severity and scope of the infringement, not the size of the organisation. A small healthcare provider processing sensitive patient data without adequate safeguards faces the same maximum fine tier as a multinational bank. The proportionality analysis may result in a lower absolute figure, but exposure is not zero for smaller entities.

Q: What does GDPR enforcement cost a business beyond the fine itself?

A: The direct fine is often the smaller part of the total cost. Businesses also face legal and advisory fees during the investigation (typically PLN 50,000–300,000 for a contested procedure), remediation costs to fix the underlying compliance gaps, reputational damage affecting customer trust, and potential civil claims from affected data subjects. Under Polish civil law, data subjects can seek compensation for non-material damage – distress, loss of control over personal data – without needing to prove financial loss. For trademark and IP-related data processing disputes, specialist input from an IP lawyer Warsaw-based or otherwise is frequently necessary to untangle overlapping obligations.

What to prepare before a UODO inquiry arrives

  • Current record of processing activities (ROPA) covering all processing operations, updated within the last 12 months
  • Signed processor agreements with every third-party vendor handling personal data, including cloud storage and analytics providers
  • Documented legal basis for each processing activity, with consent records or legitimate interest assessments where applicable
  • Breach notification log showing incidents, assessment decisions, and any notifications made to UODO or data subjects
  • Evidence of technical and organisational measures: encryption standards, access controls, staff training records, and DPO appointment documents if mandatory

For a broader view of how UODO enforcement fits within the evolving Polish data protection framework – including the interaction between GDPR and sector-specific digital regulation – see our detailed analysis of GDPR fines in Poland and UODO enforcement trends.

Every business processing personal data in Poland carries real enforcement exposure. The complexity of GDPR compliance – across consent mechanisms, processor chains, cross-border transfers, and now AI Act obligations – means that gaps are common even in well-resourced organisations. The question is not whether UODO will ever look at your processing, but whether your documentation will hold up when it does.

To receive an expert assessment of your organisation's GDPR compliance posture and UODO enforcement exposure, contact info@kordeckipartners.com.

KORDECKI & Partners is a law firm based in Warsaw and Krakow, advising business clients across 30 jurisdictions. Our team combines expertise in Polish and international law with a practical approach to data protection, GDPR enforcement defence, DORA compliance, and AI regulation. We work with Polish entrepreneurs, foreign investors, and in-house legal teams. To discuss your situation, contact info@kordeckipartners.com.

Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. KORDECKI & Partners assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@kordeckipartners.com.