Law / Poland

Poland

European Union law applies in Poland Poland is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Poland, described on this page below, applies here too.

17 of 18 named instruments researched to a stage, across all six areas of law we track: 15 in force and 2 enacted but not yet in force. As of 14 September 2026.

When they take effect13 of 17 carry a date, 4 do not. Earlier is before 2015.
Before 2015: 2 instruments (2 in force) earlier 2015: 0 instruments 2016: 0 instruments 2017: 0 instruments 2018: 6 instruments (6 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 2 instruments (2 in force) 2025: 0 instruments ’25 2026: 1 instrument (1 in force) 2027: 2 instruments (2 enacted but not yet in force) ’27 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 2
  5. Age gating law 2
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (215 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Poland and is not restated here as Polish law.

Poland's own implementing act, the Act of 3 July 2026 on Artificial Intelligence Systems, creates the Committee for the Development and Security of Artificial Intelligence as the national market-surveillance authority, single point of contact, and notifying authority for the Regulation, and empowers the Committee to impose the administrative fines the Regulation's own Chapter XII sets, rather than adding a separate national fine schedule.

The general provisions of that Act took effect 10 August 2026, 14 days after promulgation; a narrow provision on standing up the Committee's staff took effect the day after promulgation, and Articles 8 to 18 and Chapters 3 to 5, 8, and 9 take effect 28 October 2026.

Separately, Kodeks karny Art. 202 section 4b criminalizes producing, distributing, presenting, storing, or possessing pornographic content depicting a generated or digitally altered image of a minor engaged in a sexual act, reaching AI-generated and deepfake child sexual abuse material regardless of whether any real child was involved in its creation, and section 4c extends the same penalty to participating in the presentation of such content for sexual gratification; the date these paragraphs were themselves inserted into the Code is not stated in the consolidated text.

AI governance

Ustawa o systemach sztucznej inteligencji, Act on Artificial Intelligence Systems

Ustawa z dnia 3 lipca 2026 r. o systemach sztucznej inteligencji (Dz.U. 2026 poz. 1003)Dziennik Ustaw, official text of the Act of 3 July 2026 on Artificial Intelligence Systems

In force 44 days, effective 10 August 2026. Binds public and private bodies.

What this law does

The Act creates the Komisja Rozwoju i Bezpieczenstwa Sztucznej Inteligencji, the Committee for the Development and Security of Artificial Intelligence, as Poland's market-surveillance authority and notifying authority for the EU AI Act and the single point of contact the Regulation requires. The Committee imposes administrative fines in the cases, amounts, and on the conditions Chapter XII of Regulation (EU) 2024/1689 itself sets, rather than under a separate national fine schedule.

Fines are paid within 30 days of a final decision and go to the state budget. The Committee may reduce a fine by 10 to 50 percent for timely remedial action, or by 20 to 70 percent, or 30 to 90 percent for a small or medium enterprise, under a settlement. A decision imposing a fine may be appealed to the Regional Court in Warsaw acting as the competition and consumer protection court.

The Act does not itself apply to matters of national defense, national security including the special services, or academic research and development work that does not involve real-world testing under the Regulation's own definition. The Act's general provisions took effect 10 August 2026, 14 days after promulgation, and Articles 8 to 18 and Chapters 3 to 5, 8, and 9 do not take effect until 28 October 2026.

The Committee's Chairperson is to be appointed within 2 months of the Act's entry into force, the Committee is to hold its first meeting within 3 months, and the Committee's supporting organizational unit is to begin operating within 2 months.

What it requires

AI prohibited practices

Kodeks karny art. 202 § 4b-4c, Fabricated Child Sexual Abuse Material

Ustawa z dnia 6 czerwca 1997 r. Kodeks karny (Dz.U. 1997 nr 88 poz. 553, tekst jednolity), art. 202 § 4b-4cDziennik Ustaw, consolidated text of the Kodeks karny, Kancelaria Sejmu edition

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 5, 2026. Publisher's page: https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19970880553/U/D19970553Lj.pdf

In force. Binds public and private bodies.

What this law does

Article 202 section 4b criminalizes producing, distributing, presenting, storing, or possessing pornographic content that depicts a generated or digitally processed image of a minor participating in a sexual act, reaching fabricated and AI-generated child sexual abuse material regardless of whether any real child appears in it. Section 4c extends the same penalty to a person who, for sexual gratification, participates in the presentation of such content.

What it requires

Privacy law6 instruments, 6 in force

Research summary (98 words)

Poland's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic institutional and procedural effect by the Act of 10 May 2018 on the Protection of Personal Data. The Act establishes UODO as supervisory authority with a two-track administrative-fine structure, a civil-liability venue for GDPR claims, and its own criminal offenses for unlawful processing.

A separate Kodeks pracy provision restricts employer use of employee biometric data to consent given on the employee's own initiative, plus a narrow no-consent carve-out for protecting sensitive information or specially protected premises. No UODO enforcement decision on facial recognition or voiceprints specifically is located.

Biometric privacy

GDPR Article 9, Act Article 107(2), and Kodeks Pracy Article 22(1b), Biometric Data

Regulation (EU) 2016/679, Art. 9(1); Ustawa z 10 maja 2018 r., Art. 107(2); Kodeks pracy, Art. 22(1b)Ustawa z 10 maja 2018 r., Art. 107(2) and Art. 176 (in-force date)

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) lists biometric data processed for unique identification as a special category.

Poland's own Act Article 107(2) independently names biometric data processed for unambiguous identification as one of the aggravating categories that raises the criminal penalty ceiling for unlawful processing from two to three years' deprivation of liberty, alongside racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, health data, and sexual life or orientation data.

Article 107(2)'s own in-force date is the Act's general commencement date, 25 May 2018, confirmed against the same Article 176 text used for the Act's comprehensive-regime instrument.

For employees specifically, Kodeks pracy Article 22(1b), read verbatim, permits biometric-data processing on consent only where the employee supplied it on their own initiative, plus a narrow no-consent carve-out for controlling access to particularly sensitive information or specially protected premises; only staff holding written authorization may process it, bound to confidentiality.

The current Kodeks pracy text is confirmed, but not the amending act or the precise date that provision was inserted, so no date is asserted for the Kodeks pracy limb specifically, only for the Act Article 107(2) limb this instrument's effective date reflects.

What it requires

Breach notification

GDPR Articles 33-34, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34GDPR Arts. 33-34

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify UODO within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. No Poland-specific derogation from this timeline or threshold was identified in the Act's own chapters.

What it requires

Comprehensive regime

Act on the Protection of Personal Data of 10 May 2018

Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych, Dz.U. 2018 poz. 1000isap.sejm.gov.pl, consolidated text, Arts. 78-108 (full text)

In force since 25 May 2018. Binds public and private bodies.

What this law does

Poland gives the General Data Protection Regulation (GDPR) domestic effect through the Act of 10 May 2018 on the Protection of Personal Data, read in full from its 48-page consolidated text.

It establishes the Prezes Urzedu Ochrony Danych Osobowych (President of the Personal Data Protection Office, UODO) as supervisory authority with inspection powers (Rozdzial 9, Arts. 78-91), a civil-liability venue for GDPR Article 79/82 claims at the sad okregowy (Rozdzial 10, Arts. 92-100), a two-track administrative-fine regime distinguishing public-finance-sector bodies from other controllers (Rozdzial 11, Arts. 101-106), and its own criminal offenses for unlawful processing and for obstructing a UODO inspection (Arts. 107-108).

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

Regulation (EU) 2016/679, Arts. 44-49, 83(5)GDPR Arts. 44-49, 83(5)

In force since 25 May 2018. Binds public and private bodies.

What this law does

A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. Reading the Act's operative chapters (Rozdzialy 1-11) end to end found no Poland-specific derogation from this framework.

What it requires

Data subject rights

GDPR Data-Subject Rights, Act Articles 92-97

Regulation (EU) 2016/679, Arts. 12-23; Ustawa z 10 maja 2018 r., Arts. 92-97isap.sejm.gov.pl, Ustawa z 10 maja 2018 r., Arts. 92-97

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12-23 govern access, rectification, erasure, restriction, portability, objection, and Article 22 automated-decision rights, exercisable against the controller.

Poland's Act adds the enforcement forum: a GDPR Article 79 or Article 82 claim is heard by the sad okregowy, UODO must be notified of any such filing and final judgment (Art. 94), proceedings are stayed if UODO has an open matter on the same violation (Art. 95), and a final UODO decision or court ruling finding a violation binds a later damages court on that finding (Art. 97).

What it requires

Enforcement supervision

UODO Enforcement, GDPR Article 82, and Act Articles 98, 101-108

Regulation (EU) 2016/679, Art. 83; Ustawa z 10 maja 2018 r., Arts. 98, 101-108isap.sejm.gov.pl, Ustawa z 10 maja 2018 r., Arts. 101-108, 98

In force since 25 May 2018. Binds public and private bodies.

What this law does

UODO is Poland's supervisory authority. The Act creates a distinct two-track fine structure: Article 101 lets UODO fine any controller other than a public-finance-sector unit, research institute, or the National Bank of Poland under ordinary General Data Protection Regulation (GDPR) Article 83 terms, while Article 102 caps fines for those three categories at 100,000 or 10,000 PLN.

GDPR Article 82 arms an individual with a direct private right of action, and Article 98 gives UODO its own standing to bring or join a data subject's civil claim, with that person's consent, at any procedural stage.

What it requires

Scraping law3 instruments, 3 in force

Research summary (237 words)

Poland has no scraping-specific statute; three general regimes reach the collection, reuse, and republication of data from Polish sources. Kodeks karny Arts. 267 to 269c criminalize bypassing an electronic, technical, or other special security measure to access data or a system not meant for the accessor, and separately criminalize producing or supplying a device, program, password, or access code adapted to commit that or a related computer offense.

The 2024 amendment to the Act on Copyright and Related Rights added a general text-and-data-mining exception subject to an express, machine-readable rightsholder opt-out, alongside an unconditional exception for cultural-heritage institutions and research organizations acting for non-commercial scientific research.

The Act on the Protection of Databases gives a database's producer an exclusive, transferable right to extract or reuse the whole or a substantial part of its contents, running 15 years from completion, and separately bars repeated and systematic extraction or reuse of even insubstantial parts where that conflicts with the database's normal exploitation or unreasonably prejudices the producer's legitimate interests.

The reach of Poland's General Data Protection Regulation (GDPR)-implementing regime over personal data obtained by scraping, including publicly accessible personal data, is addressed in this jurisdiction's privacy document rather than restated here, because the duty attaches to the data rather than to the collection method.

A dedicated unfair-competition claim against scraping (Ustawa o zwalczaniu nieuczciwej konkurencji) is a lead not described here, and robots.txt's legal weight and any AI-training-specific crawl signal are not addressed.

Computer misuse

Kodeks karny, Unauthorized Access to Information and Computer-Misuse Offenses

Ustawa z dnia 6 czerwca 1997 r. Kodeks karny (Dz.U. 1997 nr 88 poz. 553, tekst jednolity), art. 267-269cDziennik Ustaw, consolidated text of the Kodeks karny, Kancelaria Sejmu edition

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 5, 2026. Publisher's page: https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19970880553/U/D19970553Lj.pdf

In force. Binds public and private bodies.

What this law does

Article 267 criminalizes obtaining unauthorized access to information not intended for the accessor by opening a sealed letter, connecting to a telecommunications network, or bypassing or circumventing an electronic, magnetic, IT, or other special safeguard protecting it, and separately criminalizes unauthorized access to the whole or part of an IT system, planting or using an eavesdropping, visual, or other device or software to obtain information, and disclosing information obtained that way.

Article 268 and 268a criminalize destroying, damaging, deleting, or altering a record of significant information or IT data, or hindering a person's or a system's ability to use it. Article 269 raises the penalty where the IT data affects national defense, communications security, or government or local-government functioning.

Article 269a criminalizes materially disrupting an IT system's or network's operation through unauthorized transmission, destruction, deletion, damage, hindrance, or alteration of data.

Article 269b criminalizes producing, obtaining, selling, or making available a device or computer program adapted to commit the offenses in Articles 165(1)(4), 267(1) to (3), 268a, 269, 269a, 270, or 270a, or a password, access code, or other data enabling unauthorized access to an IT system or network, with an exemption at Article 269b(1a) for a person acting solely to secure a system or to develop a securing method.

What it requires

Copyright and text and data mining (TDM)

Ustawa o prawie autorskim i prawach pokrewnych, Text-and-Data-Mining Exceptions

Ustawa z dnia 4 lutego 1994 r. o prawie autorskim i prawach pokrewnych (tekst jednolity Dz.U. 2025 poz. 24) art. 26(2) i art. 26(3), dodane ustawa z dnia 26 lipca 2024 r. (Dz.U. 2024 poz. 1254)Dziennik Ustaw

In force since 20 September 2024. Binds public and private bodies.

What this law does

Article 26(2), added by the Act of 26 July 2024 transposing the EU Digital Single Market Copyright Directive, lets a cultural-heritage institution or a body covered by Article 7(1)(1), (2), or (4) to (8) of the Law on Higher Education and Science reproduce a work to text-and-data-mine it for scientific research, without a rightsholder opt-out, so long as the activity is not carried out for direct or indirect financial gain; the reproductions may be retained only under access controls limited to authorized persons, and the rightsholder may apply only the measures necessary to keep the network or database where they are stored secure.

Article 26(3) lets anyone reproduce a disseminated work for text-and-data-mining, unless the rightsholder has reserved that use. A reservation must be express, and for a work made publicly available so that anyone can access it at a place and time of their choosing, it must be in a machine-readable format together with metadata. Reproductions made under Article 26(3) may be retained only as long as necessary for the mining purpose.

What it requires

Database right

Ustawa o ochronie baz danych, Sui Generis Database Right

Ustawa z dnia 27 lipca 2001 r. o ochronie baz danych (tekst jednolity Dz.U. 2024 poz. 1769), art. 2, 6-8, 10-11Dziennik Ustaw

In force since 10 November 2002. Binds public and private bodies.

What this law does

A database's producer, the person bearing the investment risk of making it, holds an exclusive and transferable right to extract or reuse the whole or a substantial part, by quality or quantity, of its contents, running 15 years from the year the database was made, or from the year it was first made available to the public if that happens within the initial term, restarting on any subsequent substantial new investment.

A lawful user may extract or reuse an insubstantial part for any purpose without the producer's permission, but Article 8(2) separately bars repeated and systematic extraction or reuse, of even an insubstantial part, that conflicts with the database's normal exploitation or unreasonably prejudices the producer's legitimate interests, and a contract term contrary to the lawful user's Article 7 rights is void.

On infringement, the producer may seek an injunction, removal of the infringement's effects, damages on general principles or as a statutory multiple, restitution of profits, and a court order for publication of the judgment.

What it requires

Cybersecurity law2 instruments, 2 enacted but not yet in force

Research summary (596 words)

Poland's NIS2 transposition is enacted and in force after a nearly seven-year legislative process: the Ustawa z dnia 23 stycznia 2026 r. o zmianie ustawy o krajowym systemie cyberbezpieczeństwa oraz niektórych innych ustaw (Dz.U. 2026 poz. 252) was published on 2 March 2026 and, under its own Article 49, entered into force on 3 April 2026, one month after publication. It rewrites large parts of the 2018 Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), the base act it amends.

Article 8 requires a podmiot kluczowy (essential entity) or podmiot ważny (important entity), classified against the Załącznik nr 1 (key sectors) and Załącznik nr 2 (important sectors) sector lists, to implement an information security management system covering fourteen baseline categories of technical and organisational measure, transposing NIS2 Article 21.

Załącznik nr 2 names an online-marketplace provider, an internet search-engine provider and a social-networking-service-platform provider among the digital service providers this duty reaches expressly, alongside critical-facility operators, large telecommunications and digital-infrastructure providers (DNS, top-level domain (TLD) registries, domain registration services, cloud computing, data centres, content delivery networks, managed services and managed security services), and public administration.

Article 11 sets a graduated incident-notification clock to the competent sectoral CSIRT: an early warning within 24 hours of detecting a significant incident, a fuller notification within 72 hours, a periodic report on the CSIRT's request, and a final report within one month of the 72-hour notification, transposing NIS2 Article 23; new Article 11(2a)-(2b) duties also require notifying affected users of a serious cyber threat and of a significant incident with an adverse effect on the service.

Both duties phase in rather than binding immediately: Article 33(1) of the amending Act gives an entity that already meets the essential-entity or important-entity criteria on 3 April 2026 twelve months, until 3 April 2027, to carry out the Chapter 3 duties (Articles 8 and 11 among them), with the essential entity's first Article 15 audit due within 24 months; an entity that was already regulated as an operator usługi kluczowej (essential service operator) under the pre-amendment Act has an accelerated six-month deadline, 3 October 2026, to begin reporting incidents under the new Article 11-12b regime, and continues applying the prior Article 8 regime until it has deployed the new system.

Article 73 arms the organ właściwy do spraw cyberbezpieczeństwa (the sector-specific competent cybersecurity authority) to impose an administrative fine for an Article 8 or Article 11 infringement: up to EUR 10,000,000 or 2 percent of turnover, whichever is higher, for an essential entity, and up to EUR 7,000,000 or 1.4 percent of turnover for an important entity, both enforced through the same procedure as the authority's supervisory powers over essential entities.

No instrument reviewed here imposes a mandatory product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.

Poland has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation, and personal-data breach notification under GDPR Articles 33-34 and the Polish Act of 10 May 2018 to the President of the Personal Data Protection Office (UODO) sits in the privacy topic rather than here.

Only the digital-provider slice of the essential-and-important-entity class (an online marketplace, an internet search engine, and a social-networking-service platform) is flagged on this jurisdiction's rows; the wider sector classes Article 8 and Article 11 also reach (critical-facility operators, energy, transport, health, finance, digital-infrastructure providers and public administration) are recorded here as law the lint does not yet reach rather than flagged on an unrelated activity.

Sector security regimes

Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), System Zarządzania Bezpieczeństwem Informacji

Art. 8 ustawy z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2026 poz. 20) w brzmieniu nadanym ustawą z dnia 23 stycznia 2026 r. (Dz.U. 2026 poz. 252)Dziennik Ustaw text, api.sejm.gov.pl, amending Act of 23 January 2026 (Dz.U. 2026 poz. 252)

In force in 192 days, effective 3 April 2027. Binds public and private bodies.

What this law does

Article 8 requires an essential entity or an important entity to implement an information security management system in the information system used in the processes affecting its provision of the service, covering fourteen baseline categories of technical and organisational measure: risk-assessment and information-security policy, secure system acquisition and development, physical and environmental security, personnel security, ICT supply-chain security, business continuity and disaster-recovery planning, continuous monitoring, effectiveness evaluation, cybersecurity training, basic cyber-hygiene, cryptography, secure communications and multi-factor authentication, asset management, and access control, transposing NIS2 Article 21.

Załącznik nr 2 names an online-marketplace provider, an internet search-engine provider and a social-networking-service-platform provider among the digital service providers this duty reaches expressly. The Act entered into force on 3 April 2026, but Article 33(1) of the amending Act gives an entity that already meets the essential-entity or important-entity criteria on that date twelve months, until 3 April 2027, to carry out this duty.

An entity already regulated as an operator usługi kluczowej (essential service operator) under the pre-amendment Act continues applying the prior Article 8 regime until it has deployed the new system.

What it requires

Vulnerability and incident reporting

Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów Poważnych

Art. 11 ustawy z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2026 poz. 20) w brzmieniu nadanym ustawą z dnia 23 stycznia 2026 r. (Dz.U. 2026 poz. 252)Dziennik Ustaw text, api.sejm.gov.pl, amending Act of 23 January 2026 (Dz.U. 2026 poz. 252)

In force in 192 days, effective 3 April 2027. Binds public and private bodies.

What this law does

Article 11 requires an essential entity or an important entity to notify the competent sectoral CSIRT of a significant incident on a graduated clock, transposing NIS2 Article 23. It requires an early warning without delay and no later than 24 hours after detection. It requires a fuller notification within 72 hours of detection, and a periodic report on the CSIRT's request. It requires a final report no later than one month after the 72-hour notification.

New Article 11(2a) requires the entity to inform affected users of a serious cyber threat and of the preventive measures they can take, and new Article 11(2b) requires informing users of a significant incident that adversely affects the service.

The Act entered into force on 3 April 2026, but Article 33(1) of the amending Act gives an entity that already meets the essential-entity or important-entity criteria on that date twelve months, until 3 April 2027, to carry out this duty; Article 33(4) accelerates that clock to six months, until 3 October 2026, for an entity already regulated as an operator usługi kluczowej (essential service operator) under the pre-amendment Act.

What it requires

Age gating law2 instruments, 2 in force

Research summary (177 words)

Poland's Broadcasting Act restricts and labels content harmful to minors rather than running an age-verification regime as such.

Article 18 bans broadcasting programmes and other transmissions that endanger minors' physical, psychological, or moral development, in particular pornographic content or content that unjustifiedly exposes violence, and confines programmes carrying scenes or content that could negatively affect minors' development, short of that outright ban, to the hours of 23:00 to 06:00, with a graphic-symbol labeling duty for such content throughout its broadcast.

Article 47p, added to transpose the 2018 revision of the EU Audiovisual Media Services Directive, requires a video-sharing platform provider to operate effective technical safeguards, including parental-control systems, protecting minors from user-generated video and other content that could harm their physical, psychological, or moral development, to let users flag and tag the content they upload, and bars using personal data collected for that child-protection purpose for commercial ends such as direct marketing, profiling, or behaviourally targeted advertising.

No statute requiring age verification before access to pornographic content, and no device- or app-store-level age-verification duty, is described here.

Adult content age verification (AV)

Ustawa o radiofonii i telewizji, Watershed Hours and Content Labeling for Content Harmful to Minors

Ustawa o radiofonii i telewizji art. 18 (tekst jednolity Dz.U. 2022 poz. 1722)Dziennik Ustaw

In force. Binds private bodies.

What this law does

Broadcasting a programme or other transmission that endangers a minor's physical, psychological, or moral development is prohibited, in particular one carrying pornographic content or unjustifiably exposing violence. A programme or other transmission carrying scenes or content that could negatively affect a minor's proper physical, psychological, or moral development, other than the content the outright ban already covers, may be broadcast only between 23:00 and 06:00.

A broadcaster must classify and label such a programme or transmission with an appropriate graphic symbol throughout its television broadcast, indicating that its content could negatively affect a minor's development.

Note and primary source

Age-appropriate design code

Ustawa o radiofonii i telewizji, Video-Sharing Platform Minor Protection Duties

Ustawa o radiofonii i telewizji art. 47p (tekst jednolity Dz.U. 2022 poz. 1722)Dziennik Ustaw

In force. Binds private bodies.

What this law does

A video-sharing platform provider must create and operate effective technical safeguards, including parental-control systems or other appropriate measures, protecting minors from programmes, user-generated video, or other content that could harm their proper physical, psychological, or moral development, in particular pornographic content or content unjustifiably exposing violence, and must let a platform user classify the programmes, user-generated video, or other content they upload and apply those same technical safeguards to it.

Personal data of minors collected or otherwise generated by a video-sharing platform provider for this child-protection duty may not be processed for commercial purposes such as direct marketing, profiling, or behaviourally targeted advertising, or otherwise used for those purposes in supplying that platform, another video-sharing platform, or a media service.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (239 words)

Poland transposed the EU Digital Single Market Copyright Directive's press-publisher neighbouring right through the Act of 26 July 2024, which added Articles 99(7) to 99(13) to the Act on Copyright and Related Rights.

A press publisher established in Poland or another EEA state holds an exclusive right over the online reproduction and making-available of its press publications for two years from first dissemination, subject to statutory carve-outs for hyperlinks and for single words or very short extracts, and the publisher must pass 50 percent of the resulting remuneration to the journalists whose work the publication contains.

Where a publisher and a service provider cannot agree on remuneration within three months, either side may ask the President of the Office of Electronic Communications to mediate, a narrower mechanism than Australia's compelled bargaining code or Canada's Online News Act.

Separately, Article 25 of the Copyright Act lets the press, radio, and television redistribute already-disseminated news reports, opinion articles, and short extracts of them for informational purposes, with remuneration owed to the author for reproduced articles and reporter photographs unless the rightsholder has expressly reserved the right, and Article 29 permits quoting an excerpt of a disseminated work, or a whole short work, to the extent justified by explanation, polemic, criticism, teaching, or the nature of the genre.

No hot-news or misappropriation doctrine distinct from ordinary unfair-competition law is described here, and the statute's own carve-outs are its only press-publisher waiver mechanism.

Press publishers' right

Ustawa o prawie autorskim, Press Publisher Neighbouring Right

Prawo autorskie art. 99(7)-99(13), dodane ustawa z dnia 26 lipca 2024 r. (Dz.U. 2024 poz. 1254)Dziennik Ustaw

In force since 20 September 2024. Binds private bodies.

What this law does

A press publication's publisher, established in Poland or in an EU or EFTA/EEA state, holds the exclusive right to reproduce the publication for online use and to make it available online, without prejudice to the underlying authors' and other rightsholders' own rights, per Article 99(7). The right does not reach an individual's private, non-commercial use, a hyperlink to the publication, or single words or very short, insignificant extracts of it, per Article 99(7)(3).

The right lasts two years from the calendar year following the publication's first dissemination, per Article 99(8). Authors of works contained in the publication are entitled to 50 percent of the remuneration due to the publisher for exercising the right, paid within 30 days of the publisher's own receipt, per Article 99(9).

Where the publisher and a service provider fail to agree remuneration within three months of an offer to contract, either side may apply to the President of the Office of Electronic Communications for mediation, per Article 99(12).

Note and primary source

Snippet reproduction

Ustawa o prawie autorskim, Press Review, Quotation, and Reporting Exceptions

Ustawa z dnia 4 lutego 1994 r. o prawie autorskim i prawach pokrewnych (tekst jednolity Dz.U. 2025 poz. 24), art. 25 i art. 29Dziennik Ustaw

In force since 23 May 1994. Binds private bodies.

What this law does

Article 25 lets the press, radio, and television redistribute, for informational purposes, already-disseminated reports on current events, articles on current political, economic, or religious topics unless expressly reserved against further distribution, current statements and reporters' photographs, short extracts of the reports and articles just named, reviews of disseminated publications and works, and short summaries of disseminated works.

The author is entitled to remuneration for the reproduced articles and reporters' photographs, and the same rules apply to making a work available online in a way that lets anyone access it at a place and time of their own choosing.

Article 29 permits quoting excerpts of disseminated works, and reproducing a disseminated visual, photographic, or other short work in its entirety, within works that form an independent whole, to the extent justified by the purposes of explanation, polemic, critical or scientific analysis, teaching, or the rights of the genre of creativity.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.