Skip to content
EUMEDIUM coverage

Poland — AI Framework under GDPR (UODO): AI Compliance Requirements

Poland's UODO has issued GDPR-AI guidance requiring DPIAs for AI profiling systems and human review for automated decisions, and retains competence over the AI-GDPR intersection specifically. CYCLE 19 (2026-08-22) UPDATE: the national AI supervisory body previously described only vaguely as "under the Ministry of Digitalization" now has a confirmed name and structure — Poland's draft national AI Act, adopted by the Council of Ministers on 2026-03-31, designates a new Commission for AI Development and Security (KRiBSI) as the primary EU AI Act enforcement authority, with its operational unit nested within the Ministry of Digital Affairs; Poland is one of only two EU countries (with Lithuania) creating a single sole market-surveillance authority for AI Act purposes, and the only one building an entirely new institution for it. KRiBSI's membership embeds sectoral expertise (representatives of the competition authority, financial supervisor, broadcasting council, and telecoms regulator). UODO, UKE (telecoms), and KNF (financial) retain their existing sector-specific competencies alongside KRiBSI. Not yet enacted as of this cycle (draft/Council-of-Ministers-adopted stage) — treat KRiBSI as forthcoming, not yet operational.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2023

Maximum Penalty

€20,000,000 or 4% global turnover (GDPR enforcement by UODO)

What Your Business Must Do

1 compliance requirement identified. Critical requirements carry the highest risk of enforcement action.

DPIA for AI Systems Processing Polish Resident Data

High Priority

UODO requires a DPIA for AI systems involving large-scale profiling, systematic monitoring, or automated decisions affecting Polish residents.

GDPR Arts. 9, 22, 35 (as applied by UODO)

Who Does This Apply To?

Applies to any organisation deploying AI systems that process the personal data of Polish residents — Poland's UODO enforces GDPR-AI obligations while a national AI supervisory body is established under the Ministry of Digitalization for EU AI Act implementation. In scope: AI systems involving large-scale profiling, systematic monitoring, or automated decisions affecting Polish residents (a DPIA is required, with UODO's position treating systems with over 1,000 Polish users and significant decision-making effects as DPIA-triggering), public-space biometric AI (GDPR Art. 9's explicit-processing-basis requirement applies independent of any specific enforcement precedent), and automated HR decisions (Art. 22 human review required). Maximum exposure: €20M or 4% of global turnover.

Recent Regulatory Guidance

guidance2023-11

UODO Position on AI and Personal Data Processing (2023)

UODO issued a formal position clarifying AI-specific GDPR obligations: training data from Polish residents requires documented legal basis; automated HR decisions require GDPR Art. 22 human review; AI systems with >1,000 Polish users and significant decision-making effects require DPIA. Polish DPO must be consulted before AI deployment in sensitive categories.

Frequently Asked Questions

Does Poland — AI Framework under GDPR (UODO) apply to my business?

Poland's UODO has issued GDPR-AI guidance requiring DPIAs for AI profiling systems and human review for automated decisions, and retains competence over the AI-GDPR intersection specifically. CYCLE 19 (2026-08-22) UPDATE: the national AI supervisory… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Poland — AI Framework under GDPR (UODO) is: €20,000,000 or 4% global turnover (GDPR enforcement by UODO). Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Poland — AI Framework under GDPR (UODO)?

The 1 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://uodo.gov.pl/en

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan