Key Data & Cybersecurity Laws
Jump to
Key Data & Cybersecurity Laws Start Comparison
How are data and cybersecurity laws/regulations implemented?

Last review date: 10 January 2025

☒ omnibus – all personal data

☒ sector-specific — e.g., financial institutions, governmental bodies

☒ constitutional

What are the key data privacy laws and regulations?

Last review date: 10 January 2025

Please refer to the EU Chapter for detailed information regarding EU-wide legislation.

What are the key cybersecurity laws and regulations?

Last review date: 10 January 2025

Proceedings to implement Directive (EU) 2022/2555 ("NIS 2") to the Polish legal system have been yet initiated, but the draft is still under discussion.

What are the key laws and regulations relating to non-personal data?

Last review date: 10 January 2025

Please refer to the EU Chapter for detailed information regarding EU-wide legislation.

  • Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonized rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act)
  • Regulation (EU) 2018/1807 of the European Parliament and of the Council of 14 November 2018 on a framework for the free flow of non-personal data in the European Union;
  • Act of 11 August 2021 on open data and reuse of public sector information;
  • Act of 6 September 2001 on access to public information.
Are new or material changes to those key data and cybersecurity laws anticipated in the near future?

Last review date: 10 January 2025

Please refer to the EU Chapter for detailed information regarding EU-wide legislation.

  • Act of 5 July 2018 on the National Cybersecurity Systemis now in the process of being amended to conform to the Directive (EU) 2022/2555 of the European Parliament and of The Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive).
  • Additionally, the “Act on amending certain laws in connection with ensuring the digital operational resilience of the financial sector and the issuance of European green bonds” is in a legislative process with aim of implementing certain rules in relation to DORA in Poland (among others Act of 5 July 2018 on the National Cybersecurity System will be amended)
  • Simultaneously, Polish lawmakers are working on the National Cybersecurity Certification Act, which is intended to ensure proper functioning of the Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on the European Union Agency for Cybersecurity ("ENISA") and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 ("Cybersecurity Act").
  • The new Electronic Communications Law, which implements the Directive of the European Parliament and of the Council (EU) 2018/1972 of 11 December 2018 establishing the European Electronic Communications Code, has been adopted on 12 July 2024 and became applicable (with exceptions) on 10 November 2024.
  • The new Act of Artificial Intelligence Systems is being worked on by the Polish government. The Act will complement the EU AI Act and will introduce to Polish law some obligations related to the EU AI Act. In particular, the subject-matter of the draft Act are issues regarding the national supervisory authority, proceedings before that body, control proceedings, notifying the notification authority, certification, judicial protection of citizens' rights, as well as initiating proceedings and imposing administrative financial penalties for violating the provisions of Art. 5 of Regulation 2024/1689. The Act has not yet been submitted to the Polish parliament. Currently a new version of the draft is being prepared after public consultations that took place in 2024.