Latest update · 28 September 2026
Lead Signal
The UODO's enforcement posture in Poland continues to escalate. Following what secondary reporting characterises as a record 2025 with over PLN 64 million in fines, 2026 has already produced a further large single decision: UODO fined DPD Polska PLN 11 million on 23 February 2026 following an ex officio inspection of courier-delivery data processing, splitting the penalty between deficient data-processing-agreement governance (PLN 6.251 million) and inadequate technical and organisational access controls (PLN 5.209 million). This is understood to be the largest 2026 fine to date, and it sits alongside an earlier decision against a delivery platform (Glovo), fined almost PLN 5.9 million for requiring users to upload ID-card scans for anti-fraud purposes with no legal basis, in breach of the data-minimisation principle, with UODO ordering erasure of the collected scans.
Other Developments
UODO articulates a cross-sectoral standard for identity-document copying. UODO's 2026 decisions are reported to confirm that copying identity documents is permitted only for entities expressly authorised by law, such as obliged institutions under the Polish AML Act — a standard that non-AML-obliged sectors, including delivery and gig-economy platforms, do not meet. This creates a compliance boundary that reaches beyond the financial sector into any business relying on identity-document copying as a verification or anti-fraud tool without an equivalent statutory authorisation.
Cross-Monitor Connections
The UODO's identity-document-copying standard is understood to draw its authorisation benchmark from the Polish AML Act's obliged-institution framework, a topic tracked in detail by the financial-integrity monitor. Firms operating across both data-protection and financial-crime compliance functions in Poland should read this cycle's sectoral-watch finding alongside financial-integrity's own AML/CTF regime tracking for this jurisdiction, though the AML/CTF regime analysis itself belongs to that monitor, not to this one.
Outlook
Whether the UODO's officially published 2025 annual report confirms the approximately PLN 64 million total-fines figure currently reported by secondary sources remains an open question worth tracking. Also worth watching is whether other non-financial sectors relying on identity-document copying for verification purposes receive similar UODO scrutiny following the Glovo precedent, which would extend the reach of this cycle's sectoral standard beyond the delivery-platform context in which it first emerged.
Standing brief · as of 23 August 2026
Written before the update above. Where they differ, the update is the more recent position.
Lead Signal
Poland's most material data-protection development this cycle is an unresolved institutional competence dispute over who supervises artificial-intelligence systems that process personal data. The Draft Act on Artificial Intelligence Systems, adopted by the Council of Ministers on 31 March 2026 and submitted to Parliament, would establish a new body, KRiBSI, as Poland's primary national AI supervisory authority, with UODO — the existing data-protection authority — retaining only a coordination role on data-protection matters. UODO has publicly criticised this allocation, arguing that relegating it to an advisory role without voting rights is inadequate given that AI Act enforcement involving personal data requires meaningful participation in decision-making. At the same time, the draft law does recognise UODO's exclusive supervisory competence over high-risk AI systems, but the draft is described as lacking detailed cooperation rules and explicit protection of fundamental rights. This is assessed with High confidence, corroborated by a Tier-3 source describing the objection and a Tier-2 DataGuidance source describing the competence allocation independently. The competence dispute is significant beyond its immediate institutional stakes: it will determine whether AI-related personal-data supervision in Poland proceeds through a body with established GDPR enforcement experience and precedent, or through a newly-created authority without that institutional history, at a moment when UODO itself is demonstrating an increasingly high-volume enforcement posture in its existing remit.
Other Developments
UODO's enforcement profile remains high-volume and material, but now shows a judicial-constraint signal. UODO imposed over PLN 64 million in fines in 2025, including the three largest penalties in Polish data-protection enforcement history, and issued a March 2026 enforcement decision against a large courier company totalling more than PLN 11 million in administrative fines for GDPR-related failures. The scale of this activity establishes UODO as an increasingly assertive regulator by regional standards, a posture that makes the question of its role in AI-related personal-data supervision more consequential than it might be for a less active authority. Separately, the Provincial Administrative Court in Warsaw overturned UODO's PLN 27 million fine against Poczta Polska, an early signal that UODO's fining methodology may face increased judicial scrutiny going forward. Each of these findings is High confidence, sourced respectively to Tier-2 and Tier-3 material.
Cross-Monitor Connections
The KRiBSI/UODO competence dispute over AI-related personal-data supervision is directly relevant to any monitor tracking Poland's emerging AI-regulation framework, given that the same draft legislation determines both AI supervisory architecture and the scope of UODO's residual data-protection role within it. More broadly, the pattern of a national data-protection authority contesting its own role in an adjacent AI-governance framework is a structural development relevant to any cross-jurisdictional comparison of how EU Member States are allocating AI-supervision competence relative to existing GDPR supervisory authorities, though this cycle's evidence supports only the Poland-specific instance described above. No financial-integrity, world-payments, advennt, or crypto-specific overlap is asserted this cycle.
Outlook
How the KRiBSI/UODO competence split is finally allocated for AI systems processing personal data, and on what timeline the AI Systems Act completes its parliamentary passage, remains unresolved and is the single most consequential open question for Poland's data-protection trajectory. Separately, whether the Poczta Polska fine reversal materially affects UODO's future fining methodology or appeal-resistance drafting is also unresolved. A primary legislative text for the Draft Act on Artificial Intelligence Systems, and any parliamentary amendment addressing UODO's cooperation-rights concerns, would materially sharpen next cycle's assessment of how this competence dispute is likely to resolve.