Poland
NSA Tier B partner and Europol, Schengen and Prüm participant that hosted an ECHR-confirmed CIA black site, now the first EU state to prosecute its intelligence chiefs over Pegasus, with five agencies holding warrantless metadata access
Overview
EU Member State: Poland is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page.
The Pegasus spyware scandal revealed 578 individuals targeted by three agencies using PLN 25 million diverted from the Justice Fund. In February 2026, the first EU criminal prosecution of intelligence chiefs over Pegasus was launched. The ECHR found three Article 8 violations in Poland’s surveillance regime (Pietrzak, May 2024). Poland hosted a CIA secret detention facility at Stare Kiejkuty (ECHR confirmed 2014). Five intelligence agencies exercise surveillance with ~99% wiretap approval rate and ~2 million annual metadata requests without judicial authorisation. Poland is an NSA Tier B partner.[1][2][3]
Poland’s outward data-sharing runs through its alliances and treaties, each detailed below. It is an NSA Tier B partner (targetable by NSA collection, unlike Five Eyes members) and a NATO member since 1999; it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks and to Europol and the European Investigation Order, and holds a bilateral mutual legal assistance treaty with the United States. These are the channels through which the domestic protections described below are, in practice, bypassed.[19][20][21][22][23]
International Data Sharing Agreements
EU and NATO Framework
NATO member since March 1999; EU member since May 2004. Within the EU, Poland cooperates with the other 26 member states through the EU Convention on Mutual Assistance in Criminal Matters (2000), the Schengen Convention, and the European Investigation Order, which enables binding cross-border evidence requests.[13]
European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols apply between Poland and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[19]
Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Poland is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[20]
SIS II: Real-time query and alert sharing across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[21] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange; the framework binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[22]
Europol
As an EU member state, Poland is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Polish person data flowing through Europol is reachable onward.[23]
NSA Tier B Cooperation
Classified as Tier B under “Focused Cooperation” on computer network exploitation. Not a Five/Nine/Fourteen Eyes member. Polish persons can be targeted by NSA collection under US foreign surveillance authorities.[3]
CIA Black Site: Stare Kiejkuty
The ECHR found “beyond reasonable doubt” that Poland hosted a CIA secret detention facility at Stare Kiejkuty military base (2002–2003). Al Nashiri and Abu Zubaydah rulings (July 24, 2014) found Poland violated Articles 3, 5, 6, 8, and 13 ECHR. EUR 100,000 damages each. Former President Kwasniewski admitted agreeing to host the site.[14]
US-Poland MLAT
Signed July 10, 1996, in force September 17, 1999. Beyond the US, Poland holds bilateral mutual-assistance treaties with several states (including Sweden, 1990); the full set of Polish bilateral treaties is searchable in the Ministry of Foreign Affairs’ treaty database (Internetowa Baza Traktatowa).[15]
The Privacy Backdoor Effect
Despite UODO enforcement and constitutional protections, extensive alternative access exists:
- NSA Tier B: Bilateral SIGINT partnership outside GDPR frameworks; Polish persons targetable by NSA
- CIA precedent: Stare Kiejkuty established US intelligence operations on Polish soil outside Polish oversight
- Five agencies: ABW, AW, CBA, SKW, SWW operate under Police Act and Anti-Terrorism Act, exempt from data protection supervision
- EU Framework: Polish data in SIS II, Prüm, EIO accessible to 27 EU states and through Europol to US FBI
- MLAT/CoE Conventions: the US, the 51 parties to the 1959 Convention and the 82 parties to the Budapest Convention can request data through MLA channels
- Palantir CLOUD Act: Polish Armed Forces data on US-controlled platform accessible without Polish consent
- SWIFT/PNR: Financial and travel data subject to US access
Club de Berne and the Counter Terrorism Group
Poland’s ABW takes part in the Club de Berne (founded 1969), the forum of the heads of the domestic intelligence and security services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland. The Club is a broad, all-source intelligence-sharing body, not a counterterrorism-specific one; its separate offshoot, the Counter Terrorism Group (CTG), created in September 2001, shares terrorism intelligence among the same services plus the United Kingdom and has run a joint operational platform in The Hague with a common database and real-time information system since 2016.[24]
Surveillance and Intelligence
Five Intelligence Agencies
ABW (domestic intelligence), AW (foreign intelligence/SIGINT), CBA (anti-corruption), SKW (military counterintelligence/SIGINT), SWW (military intelligence/SIGINT). All five have operational control (wiretapping) powers and access telecommunications metadata without judicial authorisation. Created after dissolving communist-era services. Wiretap approval rate approximately 99%.[6]
Pegasus Spyware Scandal (2017–2022)
CBA purchased Pegasus with PLN 25 million from the Justice Fund. Three agencies (CBA, ABW, SKW) targeted 578 individuals: 6 in 2017 escalating to 162 in 2021. Citizen Lab identified first targets in December 2021: opposition politician Krzysztof Brejza (hacked 33 times during campaign), lawyer Roman Giertych, and prosecutor Ewa Wrzosek. Senate investigation found “gross violations of constitutional standards.” Former Justice Minister Ziobro arrested (January 2025, 26 charges), fled to Hungary (January 2026), EAW sought (February 2026).[7]
On February 25, 2026, the National Prosecutors’ Office charged former ABW head and SKW head with criminal offences for deploying Pegasus without required IT security accreditation, the first criminal prosecution of intelligence chiefs over Pegasus in any EU member state. Each faces up to three years imprisonment.[8]
ECHR: Pietrzak and Others v. Poland (May 2024)
Three Article 8 ECHR violations: (1) wiretapping regime lacked adequate safeguards; (2) metadata access regime exceeded what is “necessary in a democratic society”; (3) Anti-Terrorism Act secret surveillance lacked independent review. The Constitutional Tribunal’s 2014 ruling requiring independent surveillance oversight has been broadly ignored; 2016 amendments instead expanded powers.[2][9]
Palantir Defense Partnership
MoD signed MOU (December 2024) and Letter of Intent (October 2025) with Palantir covering battlefield management, logistics, AI, and cybersecurity across the Polish Armed Forces. Poland’s NATO-leading ~5% GDP defence spending drives aggressive US defence tech partnerships. Because Palantir is subject to the CLOUD Act, Polish Armed Forces operational data is accessible to US authorities without Polish consent.[10]
Internet Infrastructure
EPIX (Poland’s largest IXP, 3.5+ Tbps, 850+ users, Warsaw/Katowice/Poznan). PLIX/Equinix Warsaw (241 ISP members, 460+ ports). ~500 km Baltic coastline; connectivity relies primarily on terrestrial fibre to Germany, Czech Republic, and Lithuania. Landlocked for cables: international traffic transits through neighbouring countries including Germany (DE-CIX/BND cable interception).[11]
Privacy Framework
The UODO enforces the GDPR. Major fines: Poczta Polska PLN 27.1M (30 million citizens’ data for postal election), ING Bank PLN 18.4M (identity document scanning), McDonald’s PLN 16.9M (failed risk analysis). The Personal Data Protection Act (2018) supplements the GDPR. The Electronic Communications Law (November 2024) expanded scope to email, messaging, and video conferencing. Police Act (1990) and Anti-Terrorism Act (2016) provide surveillance authorities. Chat Control: Poland opposes mandatory scanning of encrypted communications.[4][5]
After a delayed transposition, the amended Act on the National Cybersecurity System (KSC), implementing the EU NIS2 Directive, entered into force on April 3, 2026. It expands the regime from roughly 400 operators of essential services to over 42,000 entities, with registration in the S46 system due by October 3, 2026, cybersecurity measures by April 3, 2027, and full enforcement of administrative fines from April 3, 2028.[16]
Data Retention
12-month mandatory retention of telecommunications metadata (reduced from 24 months in January 2013). Nine entities authorised to access retained data (Police, Border Guard, Military Police, ABW, SKW, CBA, Customs, fiscal authorities, prosecutors/courts). Intelligence agencies access metadata without judicial authorisation and without independent oversight. The Constitutional Tribunal’s 2014 ruling that this access violated privacy rights has not been effectively implemented.[12]
Pending Legislation
- Surveillance oversight reform (post-Pegasus): following the Senate inquiry and civil-society “How to saddle Pegasus” recommendations, proposals would require agencies (Police, ABW, and others) to disclose to courts the technical means they intend to use and oblige courts to justify both approvals and rejections; the Senate has also proposed an independent “institution of legal protection” cooperating with the Human Rights Commissioner, the data-protection authority (UODO), and the Supreme Audit Office. No reform has yet been enacted.[17]
- ECHR Pietrzak compliance (data retention / metadata): the 2024 ruling found Poland’s metadata-access and retention regime exceeded what is “necessary in a democratic society,” requiring reform of judicial authorisation and retention limits that remains outstanding.[17]
- NIS2 / KSC (cybersecurity): the amended National Cybersecurity System Act entered into force April 3, 2026, with phased compliance deadlines (S46 registration by October 3, 2026; measures by April 3, 2027; fines from April 3, 2028).[16]
- “Social-media free speech” bill: a government proposal framed around protecting social-media users would introduce data-retention duties, a contested definition of “unlawful content,” and a new oversight body, drawing civil-society criticism.
- Act on Artificial Intelligence Systems (AI Act implementation): adopted by the Council of Ministers on March 31, 2026, and passed by the Sejm on June 11, 2026; the Act is now before the Senate. It creates the Commission for AI Development and Security (KRiBSI) as the sole national market-surveillance authority for AI, an entirely new institution (Poland and Lithuania are the only EU states designating a single AI authority) with a collegiate structure embedding the competition authority, financial supervisor, broadcasting council, and telecoms regulator. UODO is relegated to a cooperating role without voting rights, which it has publicly contested: enforcement touching personal data, it argues, requires meaningful participation in the decision, not consultation. The structural question of whether Poland’s data-protection authority retains authority over algorithmic systems remains live in the Senate.[18][25]
