Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Accountability Instruments
Per Poland law + GDPR Articles 25 + 30 + 35: accountability instruments. Requirements include (a) conduct Data Protection Impact Assessment (DPIA) for high-risk processing per GDPR Article 35 + UODO (Urzad Ochrony Danych Osobowych) lists + (b) implement Privacy by Design and by Default per GDPR Article 25 + (c) maintain Records of Processing Activities (RoPA) per GDPR Article 30 + (d) implement Accountability Demonstration including governance + roles + documentation + (e) integrate with broader privacy + risk + IT governance + (f) maintain documented accountability framework.
- Poland PDPA + GDPR evidence for POLAND-4
- UODO notification + employee monitoring + DPIA partial
Breach and Enforcement
Per Poland law + GDPR Articles 33-34 + 77-84: breach notification + enforcement. Requirements include (a) implement Personal Data Breach Notification to UODO (Urzad Ochrony Danych Osobowych) within 72 hours of becoming aware unless unlikely to result in risk + notify affected data subjects where high risk per GDPR Article 34 + (b) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (c) maintain UODO (Urzad Ochrony Danych Osobowych) Inspections and Cooperation cooperation including responding to inspection + audit + complaint + (d) maintain Enforcement and Penalties awareness including administrative fines (up to higher of EUR 20m or 4% global annual turnover) + national criminal penalties + civil liability + (e) maintain breach log + incident response + tabletop exercises.
- Poland PDPA + GDPR evidence for POLAND-8
- UODO notification + employee monitoring + DPIA partial
Cross-Border Transfer
Per Poland law + GDPR Chapter V: international transfers. Requirements include (a) implement International Transfers restrictions per GDPR including adequacy + appropriate safeguards (SCCs + BCRs + certification) + derogations + (b) maintain Cross-Border Transfer Safeguards documentation + Transfer Impact Assessment (TIA) per Schrems II + (c) maintain inventory of cross-border flows + recipients + safeguards + (d) implement contractual protections with processors involving international transfer + (e) cooperate with UODO (Urzad Ochrony Danych Osobowych) on transfer matters.
- Poland PDPA + GDPR evidence for POLAND-6
- UODO notification + employee monitoring + DPIA partial
Governance and Lifecycle
Per Poland law + GDPR: governance + lifecycle. Requirements include (a) Designation and Notification of Data Protection Officer (DPO) per GDPR Article 37 + national requirements with notification to UODO (Urzad Ochrony Danych Osobowych) + (b) cooperate with UODO (Urzad Ochrony Danych Osobowych) (UODO) including responding to inquiries + facilitating audits + (c) implement Retention and Erasure including retention schedules + secure deletion + (d) implement Direct Marketing and ePrivacy safeguards per national + EU ePrivacy + (e) deliver Training and Awareness programmes including role-based content + national specifics + (f) maintain documented governance + accountability framework.
- Poland PDPA + GDPR evidence for POLAND-7
- UODO notification + employee monitoring + DPIA partial
High-Risk Processing
Per Poland law + GDPR Article 9 + national supplements: heightened safeguards. Requirements include (a) implement Special Categories and Sensitive Data protections per GDPR Article 9 + Poland-specific safeguards + (b) implement Children's Data including consent age per national law (13 years per Polish law) + (c) implement Employee Monitoring and Workplace Privacy controls per Poland labour law + GDPR + (d) implement sensitive data per national + GDPR requirements + (e) conduct DPIA where required + (f) maintain documented safeguards + risk assessments.
- Poland PDPA + GDPR evidence for POLAND-3
- UODO notification + employee monitoring + DPIA partial
Individual Rights
Per Poland law + GDPR Articles 12-23: data subject rights. Requirements include (a) implement Data Subject Rights Handling including Access + Rectification + Erasure + Restriction + Object + Data Portability per GDPR + (b) implement Information Obligation in Polish including privacy notices in national language per UODO (Urzad Ochrony Danych Osobowych) guidance + (c) maintain mechanism for receiving + verifying + responding within statutory timelines (typically 30 days extendable) + (d) maintain records of requests + responses + decisions + (e) integrate with broader privacy programme.
- Poland PDPA + GDPR evidence for POLAND-2
- UODO notification + employee monitoring + DPIA partial
Scope and Lawful Basis
Per Poland Ustawa o ochronie danych osobowych 2018 implementing GDPR: scope + lawful basis + Poland-specific supplements. Requirements include (a) determine GDPR + national law scope including extraterritorial application + sectoral specifics + (b) establish Lawful Basis per GDPR Article 6 + Article 9 for special categories + national derogations + (c) maintain Lawful Basis Register and Documentation + (d) provide Privacy Notices in Polish per national requirement + (e) document applicability + lawful basis + (f) align with UODO (Urzad Ochrony Danych Osobowych) guidance + national derogations + supplements.
- Poland PDPA + GDPR evidence for POLAND-1
- UODO notification + employee monitoring + DPIA partial
Security and Processor
Per Poland law + GDPR Articles 32 + 28: security + processor management. Requirements include (a) implement Security of Processing including organisational + technical + appropriate to risk per GDPR Article 32 + UODO (Urzad Ochrony Danych Osobowych) security guidance + (b) maintain Processor Agreements per GDPR Article 28 ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (c) implement supplier + processor + sub-processor due diligence + (d) conduct regular security testing + (e) integrate with broader information security programme.
- Poland PDPA + GDPR evidence for POLAND-5
- UODO notification + employee monitoring + DPIA partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.