Poland

NSA Tier B partner and Europol, Schengen and Prüm participant that hosted an ECHR-confirmed CIA black site, now the first EU state to prosecute its intelligence chiefs over Pegasus, with five agencies holding warrantless metadata access

← Back to Privacy Law Directory

Overview

EU Member State: Poland is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page.

The Pegasus spyware scandal revealed 578 individuals targeted by three agencies using PLN 25 million diverted from the Justice Fund. In February 2026, the first EU criminal prosecution of intelligence chiefs over Pegasus was launched. The ECHR found three Article 8 violations in Poland’s surveillance regime (Pietrzak, May 2024). Poland hosted a CIA secret detention facility at Stare Kiejkuty (ECHR confirmed 2014). Five intelligence agencies exercise surveillance with ~99% wiretap approval rate and ~2 million annual metadata requests without judicial authorisation. Poland is an NSA Tier B partner.[1][2][3]

Poland’s outward data-sharing runs through its alliances and treaties, each detailed below. It is an NSA Tier B partner (targetable by NSA collection, unlike Five Eyes members) and a NATO member since 1999; it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks and to Europol and the European Investigation Order, and holds a bilateral mutual legal assistance treaty with the United States. These are the channels through which the domestic protections described below are, in practice, bypassed.[19][20][21][22][23]

International Data Sharing Agreements

EU and NATO Framework

NATO member since March 1999; EU member since May 2004. Within the EU, Poland cooperates with the other 26 member states through the EU Convention on Mutual Assistance in Criminal Matters (2000), the Schengen Convention, and the European Investigation Order, which enables binding cross-border evidence requests.[13]

European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols apply between Poland and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[19]

Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Poland is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[20]

SIS II: Real-time query and alert sharing across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[21] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange; the framework binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[22]

Europol

As an EU member state, Poland is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Polish person data flowing through Europol is reachable onward.[23]

NSA Tier B Cooperation

Classified as Tier B under “Focused Cooperation” on computer network exploitation. Not a Five/Nine/Fourteen Eyes member. Polish persons can be targeted by NSA collection under US foreign surveillance authorities.[3]

CIA Black Site: Stare Kiejkuty

The ECHR found “beyond reasonable doubt” that Poland hosted a CIA secret detention facility at Stare Kiejkuty military base (2002–2003). Al Nashiri and Abu Zubaydah rulings (July 24, 2014) found Poland violated Articles 3, 5, 6, 8, and 13 ECHR. EUR 100,000 damages each. Former President Kwasniewski admitted agreeing to host the site.[14]

US-Poland MLAT

Signed July 10, 1996, in force September 17, 1999. Beyond the US, Poland holds bilateral mutual-assistance treaties with several states (including Sweden, 1990); the full set of Polish bilateral treaties is searchable in the Ministry of Foreign Affairs’ treaty database (Internetowa Baza Traktatowa).[15]

The Privacy Backdoor Effect

Despite UODO enforcement and constitutional protections, extensive alternative access exists:

Club de Berne and the Counter Terrorism Group

Poland’s ABW takes part in the Club de Berne (founded 1969), the forum of the heads of the domestic intelligence and security services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland. The Club is a broad, all-source intelligence-sharing body, not a counterterrorism-specific one; its separate offshoot, the Counter Terrorism Group (CTG), created in September 2001, shares terrorism intelligence among the same services plus the United Kingdom and has run a joint operational platform in The Hague with a common database and real-time information system since 2016.[24]

Surveillance and Intelligence

Five Intelligence Agencies

ABW (domestic intelligence), AW (foreign intelligence/SIGINT), CBA (anti-corruption), SKW (military counterintelligence/SIGINT), SWW (military intelligence/SIGINT). All five have operational control (wiretapping) powers and access telecommunications metadata without judicial authorisation. Created after dissolving communist-era services. Wiretap approval rate approximately 99%.[6]

Pegasus Spyware Scandal (2017–2022)

CBA purchased Pegasus with PLN 25 million from the Justice Fund. Three agencies (CBA, ABW, SKW) targeted 578 individuals: 6 in 2017 escalating to 162 in 2021. Citizen Lab identified first targets in December 2021: opposition politician Krzysztof Brejza (hacked 33 times during campaign), lawyer Roman Giertych, and prosecutor Ewa Wrzosek. Senate investigation found “gross violations of constitutional standards.” Former Justice Minister Ziobro arrested (January 2025, 26 charges), fled to Hungary (January 2026), EAW sought (February 2026).[7]

On February 25, 2026, the National Prosecutors’ Office charged former ABW head and SKW head with criminal offences for deploying Pegasus without required IT security accreditation, the first criminal prosecution of intelligence chiefs over Pegasus in any EU member state. Each faces up to three years imprisonment.[8]

ECHR: Pietrzak and Others v. Poland (May 2024)

Three Article 8 ECHR violations: (1) wiretapping regime lacked adequate safeguards; (2) metadata access regime exceeded what is “necessary in a democratic society”; (3) Anti-Terrorism Act secret surveillance lacked independent review. The Constitutional Tribunal’s 2014 ruling requiring independent surveillance oversight has been broadly ignored; 2016 amendments instead expanded powers.[2][9]

Palantir Defense Partnership

MoD signed MOU (December 2024) and Letter of Intent (October 2025) with Palantir covering battlefield management, logistics, AI, and cybersecurity across the Polish Armed Forces. Poland’s NATO-leading ~5% GDP defence spending drives aggressive US defence tech partnerships. Because Palantir is subject to the CLOUD Act, Polish Armed Forces operational data is accessible to US authorities without Polish consent.[10]

Internet Infrastructure

EPIX (Poland’s largest IXP, 3.5+ Tbps, 850+ users, Warsaw/Katowice/Poznan). PLIX/Equinix Warsaw (241 ISP members, 460+ ports). ~500 km Baltic coastline; connectivity relies primarily on terrestrial fibre to Germany, Czech Republic, and Lithuania. Landlocked for cables: international traffic transits through neighbouring countries including Germany (DE-CIX/BND cable interception).[11]

Privacy Framework

The UODO enforces the GDPR. Major fines: Poczta Polska PLN 27.1M (30 million citizens’ data for postal election), ING Bank PLN 18.4M (identity document scanning), McDonald’s PLN 16.9M (failed risk analysis). The Personal Data Protection Act (2018) supplements the GDPR. The Electronic Communications Law (November 2024) expanded scope to email, messaging, and video conferencing. Police Act (1990) and Anti-Terrorism Act (2016) provide surveillance authorities. Chat Control: Poland opposes mandatory scanning of encrypted communications.[4][5]

After a delayed transposition, the amended Act on the National Cybersecurity System (KSC), implementing the EU NIS2 Directive, entered into force on April 3, 2026. It expands the regime from roughly 400 operators of essential services to over 42,000 entities, with registration in the S46 system due by October 3, 2026, cybersecurity measures by April 3, 2027, and full enforcement of administrative fines from April 3, 2028.[16]

Data Retention

12-month mandatory retention of telecommunications metadata (reduced from 24 months in January 2013). Nine entities authorised to access retained data (Police, Border Guard, Military Police, ABW, SKW, CBA, Customs, fiscal authorities, prosecutors/courts). Intelligence agencies access metadata without judicial authorisation and without independent oversight. The Constitutional Tribunal’s 2014 ruling that this access violated privacy rights has not been effectively implemented.[12]

Pending Legislation

Sources

[1] UODO: About the Office – Enforcement statistics, Poczta Polska/ING/McDonald’s fines
[2] HUDOC: Pietrzak and Others v. Poland (May 2024) – Three Article 8 violations
[4] ICLG: Data Protection – Poland – Personal Data Protection Act 2018, Electronic Communications Law
[5] EDRi: Chat Control – Poland opposes mandatory scanning
[6] Library of Congress: Intelligence Activities – Poland – Five agencies, warrantless metadata access, 99% wiretap approval
[7] Citizen Lab: Polish Pegasus Targets (December 2021) – Brejza (33 hacks), Giertych, Wrzosek, 578 total targets
[9] Constitutional Tribunal: K 23/11 (July 2014) – Surveillance ruling broadly ignored
[10] Defence24: Palantir Poland LoI (October 2025) – MoD partnership, CLOUD Act exposure
[11] EPIX – 3.5+ Tbps, 850+ users, Poland’s largest IXP
[12] Open Net: Poland Data Retention – 12-month retention, nine entities, warrantless access
[13] Wikipedia: Poland in the EU – NATO 1999, EU 2004, SIS II, EIO, Prüm
[14] Wikipedia: CIA Black Sites – Poland – Stare Kiejkuty, ECHR Al Nashiri and Abu Zubaydah rulings
[15] US DOJ: MLATs (April 2022) – US-Poland MLAT signed July 1996, in force September 1999
[16] Bird & Bird: NIS2 Directive Implementation in Poland (2026) – Amended Act on the National Cybersecurity System (KSC) entered into force April 3, 2026; scope expanded from ~400 operators of essential services to 42,000+ entities; S46 registration by October 3, 2026; cybersecurity measures by April 3, 2027; administrative fines enforced from April 3, 2028
[17] Panoptykon Foundation: Surveillance in Poland Under Scrutiny of Court – Civil-society-driven reform proposals requiring agencies to disclose intended technical means to courts and courts to justify approvals/rejections; Senate proposal for an independent “institution of legal protection” cooperating with the Human Rights Commissioner, UODO, and Supreme Audit Office; context of ECHR Pietrzak v. Poland (2024) finding the metadata/retention regime exceeded necessity
[18] Recording Law: Poland Data Privacy Laws (2026) – Draft Act on Artificial Intelligence Systems adopted by the Council of Ministers March 31, 2026 and submitted to Parliament; new Commission for AI Development and Security (KRiBSI) as primary national supervisory authority with UODO in a coordinating role; division of competence between KRiBSI and UODO on AI decisions involving personal data unresolved as of May 2026, with UODO arguing that enforcement involving personal data requires meaningful participation in decision-making rather than consultation; UODO 2026 sectoral inspection plan published January 8, 2026 covering five priority areas including health-data security, marketing entities and online delivery platforms
[19] Council of Europe Treaty Office: European Convention on Mutual Assistance in Criminal Matters (ETS No. 30) – Chart of signatures and ratifications; 51 parties as of July 2026 (all 46 Council of Europe member states plus Chile, Israel, Mongolia, the Republic of Korea and Russia), Poland among them
[20] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026 (45 Council of Europe member states plus 37 non-member states), Poland among them
[21] European Commission: Schengen Area – The 29 states of the Schengen Area (all EU members except Ireland and Cyprus, plus the non-EU associates Iceland, Liechtenstein, Norway and Switzerland; Bulgaria and Romania became full members January 1, 2025), Poland among them
[22] Wikipedia: Prüm Convention – The Prüm framework for automated DNA, fingerprint and vehicle-data exchange; binds all 27 EU member states plus the non-EU Schengen associates Iceland, Liechtenstein, Norway and Switzerland (31 in all); Prüm II (2024) adds facial images and police records
[23] Europol: Operational Agreements – Europol is constituted by the 27 EU member states (Poland among them) and maintains operational cooperation agreements permitting exchange of personal data with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, the United States) plus Denmark under a separate agreement, and with Eurojust, Frontex and Interpol
[24] Wikipedia: Club de Berne – informal forum (founded 1969) of the heads of the domestic intelligence and security services of the 27 EU member states plus Norway and Switzerland; its separate post-9/11 offshoot the Counter Terrorism Group (September 2001) additionally includes the United Kingdom and has operated a joint platform in The Hague with a common database and real-time information system since 2016
[25] Taylor Wessing: Poland’s New AI Systems Act (2026) – the Sejm passed the Act on artificial intelligence systems on June 11, 2026, now before the Senate; KRiBSI becomes the sole national market-surveillance authority for AI (Poland and Lithuania are the only EU states with a single such authority), collegiate membership drawing on the competition, financial, broadcasting and telecoms regulators; UODO holds a cooperating role without voting rights, which it has publicly contested
← Back to Privacy Law Directory