Law / Poland

UODO Enforcement, GDPR Article 82, and Act Articles 98, 101-108

Regulation (EU) 2016/679, Art. 83; Ustawa z 10 maja 2018 r., Arts. 98, 101-108

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • Expect UODO to have General Data Protection Regulation (GDPR) Article 83 fining power over your processing of personal data of a person in Poland.
  • Expect any person in Poland who suffered material or non-material damage from an infringement to have a direct GDPR Article 82 right to compensation, which UODO may itself help bring under Act Article 98.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Act Article 107(1) criminalizes processing personal data that is either impermissible or done by a person unauthorized to process it, punishable by a fine, restriction of liberty, or imprisonment up to two years; Article 107(2) raises the maximum to imprisonment up to three years where the unlawfully processed data reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, is genetic data, is biometric data processed to uniquely identify a person, or concerns health, sex life, or sexual orientation. Article 108 applies the identical fine, restriction of liberty, or up-to-two-years penalty to obstructing or impeding a UODO inspector's compliance audit, and to withholding, or supplying data that prevents establishing, the basis for calculating an administrative fine during a pending fine proceeding. These are prosecuted through the ordinary criminal courts rather than imposed by UODO itself; UODO made 8 such criminal referrals in 2025 per its own annual report.

Penalty structure

Act Article 101 empowers the Prezes Urzedu (President of UODO) to fine any controller or processor other than a public-finance-sector unit, research institute, or the National Bank of Poland, on the basis and under the conditions set out in GDPR Article 83. This row records the higher, Article 83(5) tier as the headline ceiling; a separate lower EUR 10,000,000 or 2% tier (Article 83(4)) applies to the narrower controller and processor obligations in Articles 8, 11, 25 to 39, 42 and 43. Act Article 102 sets a separate, lower ceiling for the three excluded public categories: up to PLN 100,000 for public-finance-sector units under Article 9 points 1 to 12 and 14 of the Public Finance Act of 27 August 2009, research institutes, and the National Bank of Poland, and up to PLN 10,000 for public-finance-sector units under Article 9 point 13 of that Act. Article 103 converts the EUR figures to PLN yearly at the National Bank of Poland's 28 January average rate.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

UODO, Urzad Ochrony Danych Osobowych (the Office for Personal Data Protection), acting through its Prezes (President), as Poland's GDPR Article 51 supervisory authority. The Prezes UODO issues administrative-fine decisions under Act Articles 101-102, may itself bring or join a data subject's GDPR Article 82 civil damages claim under Article 98, and refers suspected Article 107-108 criminal offenses to prosecuting authorities.

Enforcement record

President of UODO's own 2025 annual activity report (Sprawozdanie z dzialalnosci Prezesa UODO w roku 2025), published 2026-09-01. The President exercised the fining power in 20 proceedings during 2025, imposing 32 individual administrative fines on 23 entities totaling PLN 64,436,940.25, an 18.5% rise in the number of fines and a 363% rise in their combined value over 2024 (27 fines totaling PLN 13,907,740.96). actions_per_year records the 20 fine-imposing proceedings; median_fine and p90_fine are omitted because no per-fine dataset is published in this summary. The same report separately records 2,020 individual-complaint decisions, 31 inspection or breach decisions, and 8 criminal-referral notifications in 2025, none of which are folded into actions_per_year.

As of
2 September 2026
Trend
Rising
Currency
PLN
Source link
https://uodo.gov.pl/pl/138/4555
Fines per year
64436940.25
Actions per year
20

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

UODO is Poland's supervisory authority. The Act creates a distinct two-track fine structure: Article 101 lets UODO fine any controller other than a public-finance-sector unit, research institute, or the National Bank of Poland under ordinary General Data Protection Regulation (GDPR) Article 83 terms, while Article 102 caps fines for those three categories at 100,000 or 10,000 PLN.

GDPR Article 82 arms an individual with a direct private right of action, and Article 98 gives UODO its own standing to bring or join a data subject's civil claim, with that person's consent, at any procedural stage.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

Read the law

isap.sejm.gov.pl, Ustawa z 10 maja 2018 r., Arts. 101-108, 98

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app