Skip to content

Evidence request lists

Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Accountability Instruments

POLAND-4
DPIA, Privacy by Design, Records of Processing

Per Poland law + GDPR Articles 25 + 30 + 35: accountability instruments. Requirements include (a) conduct Data Protection Impact Assessment (DPIA) for high-risk processing per GDPR Article 35 + UODO (Urzad Ochrony Danych Osobowych) lists + (b) implement Privacy by Design and by Default per GDPR Article 25 + (c) maintain Records of Processing Activities (RoPA) per GDPR Article 30 + (d) implement Accountability Demonstration including governance + roles + documentation + (e) integrate with broader privacy + risk + IT governance + (f) maintain documented accountability framework.

Artefacts an auditor will ask for
  • Poland PDPA + GDPR evidence for POLAND-4
Where this commonly fails
  • UODO notification + employee monitoring + DPIA partial

Breach and Enforcement

POLAND-8
Breach Notification, UODO (Urzad Ochrony Danych Osobowych) Inspections, Enforcement

Per Poland law + GDPR Articles 33-34 + 77-84: breach notification + enforcement. Requirements include (a) implement Personal Data Breach Notification to UODO (Urzad Ochrony Danych Osobowych) within 72 hours of becoming aware unless unlikely to result in risk + notify affected data subjects where high risk per GDPR Article 34 + (b) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (c) maintain UODO (Urzad Ochrony Danych Osobowych) Inspections and Cooperation cooperation including responding to inspection + audit + complaint + (d) maintain Enforcement and Penalties awareness including administrative fines (up to higher of EUR 20m or 4% global annual turnover) + national criminal penalties + civil liability + (e) maintain breach log + incident response + tabletop exercises.

Artefacts an auditor will ask for
  • Poland PDPA + GDPR evidence for POLAND-8
Where this commonly fails
  • UODO notification + employee monitoring + DPIA partial

Cross-Border Transfer

POLAND-6
International Transfers

Per Poland law + GDPR Chapter V: international transfers. Requirements include (a) implement International Transfers restrictions per GDPR including adequacy + appropriate safeguards (SCCs + BCRs + certification) + derogations + (b) maintain Cross-Border Transfer Safeguards documentation + Transfer Impact Assessment (TIA) per Schrems II + (c) maintain inventory of cross-border flows + recipients + safeguards + (d) implement contractual protections with processors involving international transfer + (e) cooperate with UODO (Urzad Ochrony Danych Osobowych) on transfer matters.

Artefacts an auditor will ask for
  • Poland PDPA + GDPR evidence for POLAND-6
Where this commonly fails
  • UODO notification + employee monitoring + DPIA partial

Governance and Lifecycle

POLAND-7
DPO Designation, UODO (Urzad Ochrony Danych Osobowych) Cooperation, Retention, Marketing, Training

Per Poland law + GDPR: governance + lifecycle. Requirements include (a) Designation and Notification of Data Protection Officer (DPO) per GDPR Article 37 + national requirements with notification to UODO (Urzad Ochrony Danych Osobowych) + (b) cooperate with UODO (Urzad Ochrony Danych Osobowych) (UODO) including responding to inquiries + facilitating audits + (c) implement Retention and Erasure including retention schedules + secure deletion + (d) implement Direct Marketing and ePrivacy safeguards per national + EU ePrivacy + (e) deliver Training and Awareness programmes including role-based content + national specifics + (f) maintain documented governance + accountability framework.

Artefacts an auditor will ask for
  • Poland PDPA + GDPR evidence for POLAND-7
Where this commonly fails
  • UODO notification + employee monitoring + DPIA partial

High-Risk Processing

POLAND-3
Special Categories, Children, Employee Monitoring, Health Data

Per Poland law + GDPR Article 9 + national supplements: heightened safeguards. Requirements include (a) implement Special Categories and Sensitive Data protections per GDPR Article 9 + Poland-specific safeguards + (b) implement Children's Data including consent age per national law (13 years per Polish law) + (c) implement Employee Monitoring and Workplace Privacy controls per Poland labour law + GDPR + (d) implement sensitive data per national + GDPR requirements + (e) conduct DPIA where required + (f) maintain documented safeguards + risk assessments.

Artefacts an auditor will ask for
  • Poland PDPA + GDPR evidence for POLAND-3
Where this commonly fails
  • UODO notification + employee monitoring + DPIA partial

Individual Rights

POLAND-2
Data Subject Rights Handling and Information Obligation

Per Poland law + GDPR Articles 12-23: data subject rights. Requirements include (a) implement Data Subject Rights Handling including Access + Rectification + Erasure + Restriction + Object + Data Portability per GDPR + (b) implement Information Obligation in Polish including privacy notices in national language per UODO (Urzad Ochrony Danych Osobowych) guidance + (c) maintain mechanism for receiving + verifying + responding within statutory timelines (typically 30 days extendable) + (d) maintain records of requests + responses + decisions + (e) integrate with broader privacy programme.

Artefacts an auditor will ask for
  • Poland PDPA + GDPR evidence for POLAND-2
Where this commonly fails
  • UODO notification + employee monitoring + DPIA partial

Scope and Lawful Basis

POLAND-1
GDPR Implementation Scope and Lawful Basis (Poland)

Per Poland Ustawa o ochronie danych osobowych 2018 implementing GDPR: scope + lawful basis + Poland-specific supplements. Requirements include (a) determine GDPR + national law scope including extraterritorial application + sectoral specifics + (b) establish Lawful Basis per GDPR Article 6 + Article 9 for special categories + national derogations + (c) maintain Lawful Basis Register and Documentation + (d) provide Privacy Notices in Polish per national requirement + (e) document applicability + lawful basis + (f) align with UODO (Urzad Ochrony Danych Osobowych) guidance + national derogations + supplements.

Artefacts an auditor will ask for
  • Poland PDPA + GDPR evidence for POLAND-1
Where this commonly fails
  • UODO notification + employee monitoring + DPIA partial

Security and Processor

POLAND-5
Security of Processing and Processor Agreements

Per Poland law + GDPR Articles 32 + 28: security + processor management. Requirements include (a) implement Security of Processing including organisational + technical + appropriate to risk per GDPR Article 32 + UODO (Urzad Ochrony Danych Osobowych) security guidance + (b) maintain Processor Agreements per GDPR Article 28 ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (c) implement supplier + processor + sub-processor due diligence + (d) conduct regular security testing + (e) integrate with broader information security programme.

Artefacts an auditor will ask for
  • Poland PDPA + GDPR evidence for POLAND-5
Where this commonly fails
  • UODO notification + employee monitoring + DPIA partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.