Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018)
Poland's Act on Personal Data Protection of 2018 supplements the EU GDPR with national provisions. The President of the Personal Data Protection Office (UODO — Urząd Ochrony Danych Osobowych) oversees enforcement. The Act includes provisions on the age of digital consent (16 years — the maximum GDPR permits), certification bodies, accreditation, administrative fines for public bodies, and procedural rules for UODO. Poland also has sector-specific data protection provisions in telecommunications, banking, and healthcare legislation.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Chapter 1 — General Provisions
| Code | Title |
|---|---|
| 152FZ-1 | Scope of the Federal Law (Article 1) |
| 152FZ-2 | Purpose of the Federal Law (Article 2) |
| 152FZ-3 | Basic Terms (Article 3) |
| 152FZ-4 | Legislation on Personal Data (Article 4) |
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Legal Recognition of Data Messages |
| EPDPA-1 | Scope of Regulation (§1) |
| EPDPA-2 | Specifications for Application (§2) |
| EPDPA-3 | Application of Administrative Procedure Act (§3) |
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
Chapter 11 — Criminal Penalties and Final Provisions
| Code | Title |
|---|---|
| Art. 101 | Processing for Historical Research |
| Art. 107 | Unlawful Processing |
| Art. 175 | Entry into Force |
Chapter 2 — Data Protection Officer
| Code | Title |
|---|---|
| Art. 11 | Consent Revocation |
| Art. 8 | Data Categories |
| Art. 9 | Free Data Sharing |
Chapter 3 — Accreditation of Certifying Entities
| Code | Title |
|---|---|
| Art. 12 | Data Ownership |
| Art. 13 | Data Security and Privacy |
| Art. 14 | Direct Data Flows |
Chapter 6 — President of the Personal Data Protection Office (UODO)
| Code | Title |
|---|---|
| Art. 34 | Notification of Personal Information Breach |
| Art. 35 | Right of Access |
| Art. 44 | Right to Effective Judicial Remedy |
| Art. 46 | Administrative Fines |
Chapter 7 — Proceedings Concerning Violations
| Code | Title |
|---|---|
| Art. 60 | Initiation of Proceedings |
| Art. 63 | Interim Measures |
| Art. 70 | Criminal Penalties for False Consent |
| Art. 73 | Administrative Fines |
Chapter 9 — Monitoring Compliance
| Code | Title |
|---|---|
| Art. 78 | Inspection Powers |
| Art. 82 | Inspection Procedure |
| Art. 85 | Inspection Reports |
Maps to 533 other frameworks
Frequently Asked Questions
What is Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018)?
Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) is a compliance framework from Poland with 7 domains and 35 controls. Poland's Act on Personal Data Protection of 2018 supplements the EU GDPR with national provisions. The President of the Personal Data Protection Office (UODO — Urząd Ochrony Danych Osobowych) oversees enforcement. The Act includes provisions on the age of digital consent (16 years — the maximum GDPR permits), certification bodies, accreditation, administrative fines for public bodies, and procedural rules for UODO. Poland also has sector-specific data protection provisions in telecommunications, banking, and healthcare legislation. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) have?
Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) has 35 controls organised across 7 domains. The largest domains are Chapter 1 — General Provisions (15 controls), Chapter 6 — President of the Personal Data Protection Office (UODO) (4 controls), Chapter 7 — Proceedings Concerning Violations (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) map to?
Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) maps to 533 other compliance frameworks. The top mapping partners are Ethiopia Personal Data Protection Proclamation (No. 1321/2024) (37% coverage), Senegal Law on Personal Data Protection (Law No. 2008-12) (37% coverage), Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) (37% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) compliance?
Start your Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required