• en
  • zh
  • ru
  • es
  • What we do
  • Who we work for
  • Experience
  • Awards
  • Team
  • Expert advice
  • Guidelines
  • Contact
  • en
  • zh
  • ru
  • es

Expert advice

Identity Theft in Poland: Digital Identity Protection

08.09.2026

Identity theft is the unlawful use of another person’s identifying information – such as a PESEL number, ID card details, online banking credentials, email account or electronic signature – to impersonate that person or obtain an unlawful benefit. In Poland, digital identity crime may result in financial loss, criminal liability for the offender, disruption to business operations and serious reputational consequences for the victim.

Personal data theft and ID fraud increasingly combine traditional methods with cybercrime. Criminals may use phishing emails, fake online shops, data leaks, fraudulent phone calls, malware or compromised employee accounts. A stolen identity can be used to take out loans, open accounts, sign contracts, submit false invoices, obtain mobile subscriptions or commit fraud while appearing to act on behalf of another person.


Identity theft under Polish criminal law

Polish law does not treat every misuse of personal data as one standalone offence. The legal classification depends on the conduct, intent, harm and means used. The central provision is Article 190a § 2 of the Polish Criminal Code. It criminalises impersonating another person by using that person’s image, other personal data or other identifying information where this causes material or personal harm to that person.[1]

The offence may be punishable by imprisonment from 6 months to 8 years. Where the victim takes their own life as a result of persistent harassment or impersonation, the legal consequences are significantly more severe under Article 190a § 3 of the Criminal Code.[1]

Digital identity crime may also meet the criteria of other offences, including:

  • fraud under Article 286 of the Criminal Code, where deception is used to obtain a financial benefit;
  • computer fraud under Article 287 of the Criminal Code, including unlawful interference with automated data processing to obtain a financial benefit or cause damage;
  • unlawful access to information under Article 267 of the Criminal Code, for example accessing an email account, cloud storage or IT system without authorisation;
  • damage to or interference with computer data under Articles 268a and 269a of the Criminal Code;
  • use of a forged or altered document under Article 270 of the Criminal Code, where counterfeit identity documents or contracts are involved.[1]

For a company, the distinction matters. A fraudulent invoice sent from a compromised employee mailbox may involve unauthorised access, computer fraud, fraud and, depending on the facts, document-related offences. A proper legal assessment should therefore begin with evidence, technical findings and the actual flow of information and funds.


PESEL number protection and ID fraud prevention in Poland

The PESEL number is a key element of personal identity verification in Poland. Its disclosure does not automatically mean that a crime has occurred, but it increases the risk of ID fraud, particularly where criminals possess additional information such as an address, ID card number, telephone number or a scan of an identity document.

Since 1 June 2024, individuals may reserve their PESEL number in the official register. Certain institutions, including banks, credit institutions, payment institutions, telecommunications operators and notaries, must verify whether a PESEL number has been reserved before carrying out specified transactions.[2] If an institution fails to carry out the required verification despite a PESEL reservation, the consumer may be protected from the adverse financial consequences of a transaction made in their name.

PESEL reservation is an important preventive tool, but it does not replace basic security measures. It will not prevent account takeover, phishing, social engineering or unauthorised use of a business email account. It also does not remove the need to react quickly when identity theft is suspected.


How businesses should respond to digital identity crime

A digital identity incident should be treated as both a legal and operational event. Delayed action may allow criminals to redirect payments, access customer data, impersonate management or create false contractual obligations. The first hours are often decisive for preserving logs, tracing transfers and limiting further misuse.

Immediate steps after suspected personal data theft

  1. Secure affected accounts, reset passwords and revoke active sessions or access tokens.
  2. Preserve evidence, including emails, headers, server logs, screenshots, bank confirmations and communication with counterparties.
  3. Notify the bank or payment service provider without delay where payments or account access may be affected.
  4. Check whether a personal data breach has occurred and assess notification duties under the GDPR.
  5. Consider filing a criminal notification with the Police or Public Prosecutor’s Office, supported by organised evidence.
  6. Inform affected clients, suppliers or employees where this is necessary to prevent further fraud and protect business continuity.

Under Article 33 of the GDPR, a controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.[3] Article 34 may additionally require communication to affected individuals where the breach is likely to result in a high risk.[3] In Poland, the supervisory authority is the President of the Personal Data Protection Office.


Digital identity protection as a compliance issue

Effective identity protection should be part of internal compliance, cybersecurity and fraud prevention procedures. This is particularly relevant for businesses handling employee data, customer records, payment instructions, medical information, financial documents or access to regulated systems.

Practical safeguards include multi-factor authentication, verification procedures for changes to bank account details, separation of payment approval roles, regular access reviews, phishing training and incident-response procedures. Management should also ensure that employees know how to escalate suspicious messages allegedly sent by directors, clients or external advisers.

GDPR Article 32 requires controllers and processors to implement appropriate technical and organisational measures, taking account of the risk, state of the art, implementation costs and the nature of the processing.[3] There is no universal checklist. The appropriate standard depends on the scale of processing, the sensitivity of the data and the foreseeable consequences of a breach.

KKZ lawyers support businesses and individuals in matters involving cybercrime, fraud investigations, criminal notifications, data breach response and reputation protection. More information on related areas is available in the firm’s materials on cybercrime, scams and cybercrime prosecution in Poland.

This is informational material, not legal advice. The correct criminal and regulatory assessment depends on the evidence, the extent of the misuse and the resulting harm.


Where a criminal case concerns identity theft or other digital identity crime, it may be useful to consult the matter with a lawyer, obtain an assessment of the situation and discuss possible steps. Early legal analysis can help secure evidence and identify relevant procedural measures.


FAQ – Identity Theft in Poland

Is identity theft a criminal offence in Poland?

It can be. Article 190a § 2 of the Criminal Code applies where another person is impersonated using their personal data, image or identifying information and material or personal harm results. Other provisions may apply where fraud, unlawful access to systems or forged documents are involved.

What should be done if someone uses a PESEL number without permission?

The affected person should reserve the PESEL number if it has not already been reserved, contact relevant financial institutions, preserve evidence and consider reporting the matter to the Police or Public Prosecutor’s Office. The response should depend on whether actual misuse has occurred.

Does a leaked ID card scan always mean identity fraud?

No. A leak or unauthorised disclosure creates risk, but it does not itself prove that fraud has been committed. It should nevertheless trigger monitoring, account security measures and an assessment of possible personal data breach obligations.

Can a company be liable for personal data theft after a cyberattack?

A company may face GDPR obligations and potential administrative consequences if its security measures were inadequate or if it fails to manage a personal data breach properly. Liability depends on the facts, security controls and compliance with Articles 32 to 34 of the GDPR.

Should a business report identity theft to law enforcement?

Reporting is generally appropriate where there is evidence of fraud, unauthorised system access, false payment instructions, document forgery or other criminal conduct. A well-prepared report should include preserved digital evidence and a clear description of the financial and operational impact.

Does PESEL reservation prevent all forms of ID fraud?

No. PESEL reservation limits the effects of certain transactions carried out by specified institutions, but it does not stop phishing, account takeover, email impersonation or misuse of credentials. Technical and organisational security measures remain necessary.


Bibliography

  • [1] Act of 6 June 1997 – Criminal Code, consolidated text: Journal of Laws of 2025, item 383, in particular Articles 190a, 267, 268a, 269a, 270, 286 and 287.
  • [2] Act of 7 July 2023 amending certain acts in order to limit certain effects of identity theft, Journal of Laws of 2023, item 1394.
  • [3] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 – General Data Protection Regulation, in particular Articles 32, 33 and 34.
  • [4] President of the Personal Data Protection Office, guidance on personal data breach notification: uodo.gov.pl.

Need help?

Maciej Zaborowski

Advocate, Managing Partner

contact@kkz.com.pl

+48 509 211 000

Expert advice

Surveillance and Wiretapping in Poland: Defense Strategies

Read more
Surveillance and Wiretapping in Poland: Defense Strategies

SIM Swapping and Phone Fraud in Poland: Criminal Threat

Read more
SIM Swapping and Phone Fraud in Poland: Criminal Threat

Digital Evidence in Polish Criminal Cases: Admissibility

Read more
Digital Evidence in Polish Criminal Cases: Admissibility
See all Expert advice

How can
we help you?

Contact
the experts
Maciej Zaborowski

Maciej Zaborowski

Advocate, Managing Partner

Paweł Gołębiewski

Paweł Gołębiewski

Attorney-at-law, Head of International Criminal Law Practice

Menu

  • What we do
  • Who we work for
  • Team
  • Experience
  • Awards
  • Expert advice
  • Glossary
  • Guidelines
  • RODO & terms of service
  • Contact
Kancelaria Kopeć Zaborowski Adwokaci i Radcowie Prawni

What we do

  • Expert’s Report on Conditions in the Polish Justice System (Expert Witness)
  • Driving under the influence in Poland
  • Asset recovery in Poland
  • Cybercrime in Poland
  • Extradition in Poland
  • Show more +
  • White-collar crime in Poland
  • Whistleblowers in Poland
  • Letter of safe conduct in Poland
  • Intellectual property protection in Poland
  • Insurance Fraud in Poland
  • European Arrest Warrant in Poland
  • Criminal defense in Poland
  • Red Notice in Poland
  • Interpol in Poland
  • Frauds in Poland
  • Investigative audits and internal investigations in Poland
  • Criminal compliance in Poland
  • Corporate crimes in Poland
  • Money Laundering in Poland
  • Scams in Poland
  • Corruption in Poland
  • VAT Refund Fraud in Poland
  • Organaized Crime in Poland
  • Insider trading and disclosure of inside information in Poland
  • Criminal liability of company officers in Poland
  • Capital Fraud in Poland

Our other services: + Kopeć & Zaborowski + Lawyers in Poland + Kontrola celno-skarbowa + Blokada Konta + ESG w Firmie + Kontrola PIP

Created by Tomczak | Stanisławski

© Copyrights to Kopeć & Zaborowski Law Firm