Poland — Ustawa o ochronie danych osobowych (UODO)
The Act of 10 May 2018 that operationalises the GDPR in Poland: it establishes the Prezes Urzędu Ochrony Danych Osobowych (PUODO) as the supervisory authority, sets national procedure, and caps administrative fines for public-sector bodies. Poland is the second-largest market by our subscriber base (1,883 active subscriptions — see the TODO).
Fact text is Polish (authentic language); this README is curation.
Applicability to EdTech
- Digital-consent age stays at the GDPR default of 16: the act contains no provision lowering the Art. 8(1) GDPR age for information-society services (checked mechanically against the full consolidated text, 2026-09-06 — no derogation exists). Parental consent is therefore required for under-16s in Poland where consent is the basis.
- PUODO is the one-stop supervisor: competent authority for data protection and supervisory authority under the GDPR (art. 34); since 2026 also the competent authority for data-intermediation services and data altruism under the EU Data Governance Act (art. 34 ust. 2a, added by the Act of 27 March 2026 on data management).
- Fines are asymmetric between schools and vendors: public-finance-sector units listed in art. 9 pkt 1–12 and 14 of the public-finance act — which include local-government budget units, the usual legal form of Polish public schools — face administrative fines capped at 100 000 PLN (art. 102 ust. 1); cultural institutions at 10 000 PLN (art. 102 ust. 2). A private vendor gets the full Art. 83 GDPR scale — the cap protects the school, not the supplier.
- Scope: the act applies within the material scope of Arts. 2–3 GDPR (art. 1); press, literary, artistic and academic expression enjoy carve-outs from listed GDPR provisions (art. 2).
Contents
| Document | Covers |
|---|---|
| USTAWA.md | UODO art. 1, 2, 34 (incl. the 2026 ust. 2a), 102 |
Scope note: the act's remaining chapters (DPO notification, certification/accreditation, inspections, civil and criminal liability) are procedure for the authority and controllers generally — add specific articles when a Poland deployment question needs them. School-sector data rules live in the education acts (Prawo oświatowe, SIO act), curated separately.
Key obligations at a glance
- GDPR applies directly; UODO adds the authority, procedure and public-sector fine caps.
- Under-16 consent needs parental authority (GDPR Art. 8(1) default, not derogated).
- PUODO enforcement against public schools is capped at 100 000 PLN; vendors face full GDPR fines.
Enforcement
Prezes Urzędu Ochrony Danych Osobowych (PUODO), appointed by the Sejm with Senate consent for a four-year term (art. 34 ust. 3–7).
Related
Sources
Meta
Statute text in USTAWA.md is reproduced verbatim in Polish from the official tekst jednolity HTML served by the Sejm ELI API and built/re-verified mechanically by tools/sejm-eli/build_pl_uodo.py (verify mode; do not hand-edit statute text). The TJ HTML is frozen at its publication date, so post-TJ amendments are tracked via the API's "Nowelizacje po tekście jednolitym" reference list: the two 2026 amendments are assessed in the builder (one adds art. 34 ust. 2a — integrated verbatim from the amending act's official PDF; one rewrites art. 104, not extracted), and verify fails if a new amendment touches an extracted article. Anchors come from the source's own unit ids ({#a34-2a} = art. 34 ust. 2a).