Expert advice
Cybercrime Laws in Poland: Complete Guide for Foreigners
02.09.2026
Cybercrime is conduct involving computer systems, data, networks or digital communications that is prohibited under criminal law. In Poland, cybercrime is not regulated by one separate code. Instead, the Polish Criminal Code and procedural laws criminalise specific acts, such as unauthorised access to systems, data interference, online fraud, identity misuse, digital harassment and distribution of unlawful content.
For foreign individuals and businesses, cybercrime Poland cases can create immediate operational and personal risks. A report to law enforcement may lead to the securing of servers, laptops and phones, cross-border evidence requests, restrictions on travel, reputational damage and disruption of business continuity. The legal assessment depends on the actual conduct, system permissions, location of data, affected persons and evidence available.
Cyber crime law in Poland: the main legal framework
The principal legal basis is the Polish Criminal Code of 6 June 1997. It contains offences often described as computer crimes or digital offences. Relevant procedural rules are found primarily in the Code of Criminal Procedure of 6 June 1997, including provisions on searches, seizure of items and electronic evidence.
Polish law also reflects international standards arising from the Council of Europe Convention on Cybercrime, known as the Budapest Convention. Poland is a party to that Convention, which supports cooperation in obtaining electronic evidence and investigating offences with a cross-border element.[1]
A cyber incident may also trigger non-criminal obligations. For example, a personal data breach can require assessment under the General Data Protection Regulation and, depending on the circumstances, notification to the supervisory authority or affected individuals. A GDPR breach is not automatically a criminal offence. Criminal liability requires fulfilment of the elements of a specific offence.
Key cybercrime offences and computer crime penalties
Unauthorised access and interception of data
Article 267 of the Criminal Code concerns unauthorised access to information. It may apply where a person gains access to information not intended for them by overcoming electronic, IT or other special protection. The provision also covers unauthorised interception of information and installation or use of devices or software enabling such interception. Depending on the form of conduct, the maximum penalty may be up to two years’ imprisonment.[2]
This provision can be relevant in cases involving hacked email accounts, access to cloud storage, corporate systems, messaging platforms or employee accounts after termination of employment.
Data interference and disruption of IT systems
Articles 268, 268a, 269 and 269a of the Criminal Code address damage to data, interference with data processing and disruption of IT systems. These provisions may apply to deleting, altering, suppressing or making data inaccessible, as well as seriously disrupting the operation of a computer system, network or telecommunications network.
Article 269a is particularly important in ransomware, denial-of-service and sabotage cases. It provides for imprisonment from three months to five years where conduct significantly disrupts the operation of a computer system, IT network or telecommunications network.[2]
Malware, hacking tools and credentials
Article 269b of the Criminal Code criminalises producing, obtaining, selling, making available or distributing devices or computer programs adapted to commit certain cyber offences. It can also cover computer passwords, access codes and similar data enabling unauthorised access. The statutory penalty is imprisonment from three months to five years.[2]
Possession alone does not automatically establish liability in every case. The purpose, nature and intended use of the tool must be assessed. This distinction matters to IT security professionals, software developers and internal security teams.
Computer fraud and theft of software
Article 287 of the Criminal Code covers computer fraud. It may apply where a person influences automatic data processing, alters data or unlawfully interferes with an IT system in order to obtain a financial benefit or cause damage. The penalty may be imprisonment from three months to five years.[2]
Article 278 § 2 separately criminalises obtaining another person’s computer program without consent for the purpose of financial gain. Online fraud may also fall under the general fraud provision in Article 286 § 1, particularly where the offender misleads another person to obtain money, goods or services.[2]
Three situations where access may not be unlawful
Access to a system is not automatically a criminal digital offense. The legal position depends on authority, scope and purpose. Three situations require particular attention:
- Valid consent from the system owner or authorised administrator – consent should be clear, provable and limited to specified systems, accounts and activities.
- Access based on a statutory power – public authorities may act only within the limits and procedures established by law, including procedural safeguards.
- Authorised security testing under a defined mandate – penetration tests and incident-response work should be covered by written authorisation defining the target environment, timing, testing methods and reporting rules.
These circumstances do not create a blanket exemption. For example, an employee with access credentials may still exceed the authorised scope, access unrelated data or retain access after the end of employment. Written permissions and audit logs are therefore important evidence.
When can Poland prosecute cybercrime involving foreigners?
Poland generally applies its criminal law to offences committed within Polish territory under Article 5 of the Criminal Code. In cybercrime cases, the territorial link may arise from the location of the offender, victim, affected system, server, business activity or harmful result. The analysis is fact-specific and may involve more than one jurisdiction.
Polish law may also apply to certain conduct committed abroad. Articles 109-111 of the Criminal Code regulate extraterritorial jurisdiction, including offences committed abroad by Polish citizens and certain offences affecting Polish interests. In some situations, dual criminality is required, meaning that the conduct must also be criminal in the place where it occurred.[2]
Investigations involving foreign nationals often rely on international cooperation mechanisms, including European Investigation Orders within the European Union, mutual legal assistance and cooperation under the Budapest Convention. Data held by foreign service providers may be requested, preserved or obtained through cross-border procedures, subject to applicable law.
Business risks: management responsibility and incident response
A cyber incident can create exposure for the company, its employees and management. The immediate issue is often evidence preservation. Deleting logs, resetting devices, changing access records or contacting suspected individuals without a plan may compromise an internal investigation and increase legal risk.
Practical first steps commonly include:
- isolating affected systems without destroying logs or volatile data;
- securing access records, emails, backups, source materials and devices;
- identifying persons with administrative permissions and recent access;
- assessing contractual, data protection and regulatory notification duties;
- conducting a legally structured internal investigation before attributing blame publicly.
Forensic audits may help establish what happened, when the intrusion occurred, which accounts were used and whether data was copied, altered or exfiltrated. Technical findings should be assessed alongside employment law, data protection obligations, criminal law and potential civil claims.
Criminal procedure and rights of foreign nationals
In a Polish cybercrime investigation, law enforcement may secure electronic devices, documents and data carriers under the rules on seizure and search in the Code of Criminal Procedure, including Articles 217 and 219.[3] The legality and proportionality of these measures can be reviewed in appropriate circumstances.
A foreign suspect has the right to defence counsel and, where necessary, assistance from an interpreter. Article 72 of the Code of Criminal Procedure requires use of an interpreter where an accused person does not have sufficient command of Polish.[3] A detained foreign national may also request that the relevant consular office be informed, in line with Article 36 of the Vienna Convention on Consular Relations.[4]
Early legal assessment is important where devices have been seized, company accounts are inaccessible or an individual has been summoned for questioning. The classification of conduct may change during the investigation as forensic evidence is reviewed.
This is informational material, not legal advice. Each cybercrime case requires assessment of the technical facts, evidence and applicable Polish and international rules.
For criminal cases concerning cybercrime and other offences committed online, it may be useful to consult the matter with a lawyer and discuss possible procedural steps. Kopeć & Zaborowski (KKZ) handles criminal matters requiring an assessment of evidence, procedural risks and cross-border issues.
FAQ – Cybercrime Laws in Poland
Is hacking illegal in Poland?
Unauthorised access to protected information or IT systems may be criminal under Article 267 of the Polish Criminal Code. Liability depends on whether the person had valid authority and whether they exceeded the permitted scope of access.
What is the computer crime penalty in Poland?
Penalties depend on the offence. Unauthorised access under Article 267 may carry up to two years’ imprisonment. Serious disruption of an IT system under Article 269a and distribution of hacking tools under Article 269b may carry imprisonment of up to five years.
Can a foreigner be prosecuted for a cybercrime committed outside Poland?
Potentially, yes. Polish jurisdiction may apply where the offence has a sufficient connection with Poland, such as a Polish victim, affected system or harmful result. Articles 109-111 of the Criminal Code govern selected forms of extraterritorial jurisdiction.
Is ransomware a criminal offence in Poland?
Ransomware may involve several offences, including data interference, disruption of IT systems, computer fraud, extortion or unlawful access. The final classification depends on the conduct, damage, demands made and available evidence.
Can an employer access an employee’s business email account?
Access may be lawful only within an authorised and proportionate framework. The assessment may involve employment law, data protection law, internal policies and the employee’s reasonable expectation of privacy. Unauthorised access can create criminal and civil risks.
What should a company do after discovering a digital offense?
The company should preserve evidence, limit further harm, secure systems and obtain legal and forensic assessment before taking accusatory or public action. Notification obligations and possible criminal reports should be evaluated based on the facts.
Bibliography
- [1] Council of Europe Convention on Cybercrime, Budapest, 23 November 2001, ETS No. 185.
- [2] Act of 6 June 1997 – Criminal Code, consolidated text: Journal of Laws of 2025, item 383, in particular Articles 5, 109-111, 267, 268, 268a, 269, 269a, 269b, 278, 286 and 287.
- [3] Act of 6 June 1997 – Code of Criminal Procedure, consolidated text: Journal of Laws of 2025, item 46, in particular Articles 72, 217 and 219.
- [4] Vienna Convention on Consular Relations, Vienna, 24 April 1963, Article 36.
Need help?
Paweł Gołębiewski
Attorney-at-law, Head of International Criminal Law Practice
Expert advice
Surveillance and Wiretapping in Poland: Defense Strategies
Surveillance and Wiretapping in Poland: Defense StrategiesSIM Swapping and Phone Fraud in Poland: Criminal Threat
SIM Swapping and Phone Fraud in Poland: Criminal ThreatDigital Evidence in Polish Criminal Cases: Admissibility
Digital Evidence in Polish Criminal Cases: AdmissibilityHow can
we help you?
the experts