Expert advice
GDPR Violations with Criminal Consequences in Poland
09.09.2026
A GDPR violation is an infringement of rules governing the lawful processing, security, retention, disclosure or use of personal data. In Poland, most infringements result in administrative proceedings before the President of the Personal Data Protection Office (UODO). However, certain intentional or unauthorised acts may also constitute a criminal offence. This distinction is important for companies because a single data protection incident may create regulatory, civil, criminal and reputational exposure at the same time.
The GDPR criminal penalty Poland framework is therefore not contained solely in the GDPR. The GDPR establishes administrative sanctions and requires Member States to provide for effective penalties. Polish criminal consequences are primarily regulated by the Act of 10 May 2018 on the Protection of Personal Data and, depending on the conduct, by the Polish Criminal Code.[1][2]
Administrative GDPR fines versus criminal liability in Poland
Not every data protection violation is a data breach crime. A company may breach the GDPR by failing to provide proper information clauses, keeping data longer than necessary, using an incorrect legal basis, or failing to conclude a processor agreement. Such cases may lead to corrective measures, an order to change processing practices, a reprimand or an administrative fine.
Under Article 83 GDPR, fines can reach EUR 20 million or 4% of the undertaking’s total worldwide annual turnover for the preceding financial year, whichever is higher. The applicable threshold depends on the type of infringement. UODO must assess, among other factors, the nature, gravity, duration and intentional character of the infringement, mitigation measures, previous infringements and the degree of cooperation with the authority.[1]
Criminal liability generally requires more than a procedural or organisational deficiency. The key issue is whether personal data were processed without authorization or whether the conduct involved unlawful access, interference with systems, disclosure, fraud or another prohibited act.
Criminal offence of unlawful processing of personal data
Article 107 of the Polish Act on the Protection of Personal Data provides the principal offence directly connected with unlawful data processing. A person who processes personal data despite lacking authorization to process them, or where processing is not permitted, may face a fine, restriction of liberty or imprisonment for up to two years.[2]
The penalty increases where the unlawful processing concerns special categories of personal data, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, health data, or data concerning sex life or sexual orientation. In such cases, imprisonment may extend to three years.[2]
Article 107 concerns natural persons. In a business context, potential exposure may concern an employee, manager, IT administrator, contractor or other individual who acted without authority. Whether a management board member is personally liable depends on the actual facts, including knowledge, decision-making powers, intent and the scope of duties.
When a data breach can become a cybercrime
A personal data breach means a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. It does not automatically mean that a crime has been committed. For example, an email sent to the wrong recipient may be a reportable GDPR incident but may not satisfy the elements of a criminal offence.
Criminal exposure becomes more likely where the incident results from deliberate conduct. Relevant provisions of the Criminal Code may include:
- Article 267 – unlawful access to information, including breaking or bypassing electronic, magnetic, IT or other special security;
- Article 268 – destruction, damage, deletion or alteration of information, or preventing access to it;
- Article 268a – interference with IT data, including significant hindrance to automated processing, collection or transmission of data;
- Article 269a – interference with an IT system or network causing substantial hindrance to its operation.
These provisions are particularly relevant in ransomware, credential theft, insider data extraction, unauthorized database access and sabotage cases. More information on the practical criminal-law context of digital incidents is available in KKZ’s cybercrime practice overview.
Three GDPR scope exceptions relevant to criminal risk assessment
Before assessing a GDPR breach, the scope of the Regulation must be verified. Article 2 GDPR contains exceptions that may affect whether GDPR obligations apply. Three practical examples are particularly relevant:
- Processing by a natural person in the course of a purely personal or household activity is outside the GDPR’s scope.
- Processing carried out by competent authorities for the prevention, investigation, detection or prosecution of criminal offences is generally governed by the separate law-enforcement data protection regime.
- Processing in activities falling outside the scope of Union law is excluded from the GDPR.
These exceptions do not automatically eliminate criminal risk. Unauthorized access to another person’s data, disclosure of confidential information or interference with a system may still be assessed under the Criminal Code or other legislation. The legal classification depends on the source of data, the purpose of conduct, the manner of access and the resulting harm.
Business consequences of a suspected data breach crime
A company facing a suspected data breach crime must act quickly but carefully. Uncontrolled internal communications, alteration of logs or premature accusations against employees can damage evidence and increase legal risk. The first steps should focus on stopping the incident, preserving evidence and establishing facts.
A structured response commonly includes:
- securing affected systems, accounts, devices and access logs;
- identifying the categories and volume of personal data involved;
- assessing whether the incident creates a risk to the rights and freedoms of individuals;
- considering notification to UODO within 72 hours under Article 33 GDPR;
- considering communication with affected individuals under Article 34 GDPR;
- assessing whether notification to law-enforcement authorities is justified;
- documenting decisions, evidence preservation and remediation measures.
The 72-hour GDPR deadline applies where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons. It is not an automatic obligation for every technical incident. A documented assessment is therefore essential. If the breach is unlikely to create such a risk, notification to UODO may not be required, but the controller must still document the breach.[1]
Management responsibility and internal investigations
Data protection incidents often reveal broader governance weaknesses: excessive permissions, lack of offboarding procedures, poor vendor controls, insufficient training or ineffective monitoring. These weaknesses may increase the likelihood of an administrative penalty and complicate a defence that the company implemented appropriate technical and organisational measures under Article 32 GDPR.
Forensic review should separate confirmed facts from assumptions. It should establish who accessed the data, when access occurred, what was copied or disclosed, whether data left the organisation and whether the conduct was intentional. Where an internal investigation indicates possible criminal conduct, legal privilege, employee rights, whistleblowing obligations and evidence-handling rules should be considered from the outset.
Kopeć & Zaborowski (KKZ) supports businesses in criminal-law assessments of cyber incidents, internal investigations, regulatory response and crisis communication where a data protection violation may have criminal consequences.
This is informational material, not legal advice. Each assessment depends on the factual circumstances, including the nature of the data, the scope of access and the conduct of the persons involved.
Where a matter also concerns criminal allegations relating to personal data processing, it may be appropriate to consult the case with a lawyer and obtain an assessment of the situation. Early discussion can help identify possible procedural steps and evidence-related risks.
FAQ – GDPR Violations with Criminal Consequences in Poland
Can a GDPR violation lead to imprisonment in Poland?
Yes. Under Article 107 of the Polish Act on the Protection of Personal Data, unlawful processing of personal data may be punishable by imprisonment of up to two years, or up to three years where special categories of personal data are involved.[2]
Is every personal data breach a criminal offence?
No. A breach may result from error, negligence or technical failure. Criminal liability requires fulfilment of the elements of a specific offence, such as unlawful processing, unauthorized access or interference with IT data.
Does UODO impose criminal penalties?
No. UODO imposes administrative measures and fines. Criminal liability is assessed in criminal proceedings by law-enforcement authorities and courts.
Must every data breach be reported to UODO within 72 hours?
No. Notification is required when the breach is likely to result in a risk to the rights and freedoms of natural persons. The controller must nevertheless document every breach assessment.[1]
Can an employee be criminally liable for copying customer data?
Potentially, yes. Liability depends on whether the employee had authority to access and use the data, the purpose of copying, the nature of subsequent use and other factual circumstances.
Can a company itself be criminally liable for a data protection offence?
Criminal offences are generally attributed to natural persons. A collective entity may face separate consequences under the Act on Liability of Collective Entities for Acts Prohibited under Penalty, provided that statutory conditions are met.[3]
Bibliography
- [1] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).
- [2] Act of 10 May 2018 on the Protection of Personal Data, Journal of Laws 2018, item 1000, as amended.
- [3] Act of 28 October 2002 on Liability of Collective Entities for Acts Prohibited under Penalty, Journal of Laws 2002 No. 197, item 1661, as amended.
- [4] Act of 6 June 1997 – Criminal Code, Journal of Laws 1997 No. 88, item 553, as amended.
- [5] President of the Personal Data Protection Office (UODO), official guidance and decisions.
Need help?
Paweł Gołębiewski
Attorney-at-law, Head of International Criminal Law Practice
Expert advice
Surveillance and Wiretapping in Poland: Defense Strategies
Surveillance and Wiretapping in Poland: Defense StrategiesSIM Swapping and Phone Fraud in Poland: Criminal Threat
SIM Swapping and Phone Fraud in Poland: Criminal ThreatDigital Evidence in Polish Criminal Cases: Admissibility
Digital Evidence in Polish Criminal Cases: AdmissibilityHow can
we help you?
the experts