Poland

NSA Tier B partner and Europol, Schengen and Prüm participant that hosted an ECHR-confirmed CIA black site, now the first EU state to prosecute its intelligence chiefs over Pegasus, with five agencies holding warrantless metadata access

← Back to Privacy Law Directory

Overview

EU Member State: Poland is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page.

The Pegasus spyware scandal revealed 578 individuals targeted by three agencies using PLN 25 million diverted from the Justice Fund. In February 2026, the first EU criminal prosecution of intelligence chiefs over Pegasus was launched. The ECHR found three Article 8 violations in Poland’s surveillance regime (Pietrzak, May 2024). Poland hosted a CIA secret detention facility at Stare Kiejkuty (ECHR confirmed 2014). Five intelligence agencies exercise surveillance with ~99% wiretap approval rate and ~2 million annual metadata requests without judicial authorisation. Poland is an NSA Tier B partner.[1][2][3]

Poland’s outward data-sharing runs through its alliances and treaties, each detailed below. It is an NSA Tier B partner (targetable by NSA collection, unlike Five Eyes members) and a NATO member since 1999; it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks and to Europol and the European Investigation Order, and holds a bilateral mutual legal assistance treaty with the United States. These are the channels through which the domestic protections described below are, in practice, bypassed.[19][20][21][22][23]

International Data Sharing Agreements

EU and NATO Framework

NATO member since March 1999; EU member since May 2004. Within the EU, Poland cooperates with the other 26 member states through the EU Convention on Mutual Assistance in Criminal Matters (2000), the Schengen Convention, and the European Investigation Order, which enables binding cross-border evidence requests.[13]

European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols apply between Poland and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[19]

Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Poland is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[20]

SIS II: Real-time query and alert sharing across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[21] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange; the framework binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[22]

Europol

As an EU member state, Poland is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Polish person data flowing through Europol is reachable onward.[23]

NSA Tier B Cooperation

Classified as Tier B under “Focused Cooperation” on computer network exploitation. Not a Five/Nine/Fourteen Eyes member. Polish persons can be targeted by NSA collection under US foreign surveillance authorities.[3]

CIA Black Site: Stare Kiejkuty

The ECHR found “beyond reasonable doubt” that Poland hosted a CIA secret detention facility at Stare Kiejkuty military base (2002–2003). Al Nashiri and Abu Zubaydah rulings (July 24, 2014) found Poland violated Articles 3, 5, 6, 8, and 13 ECHR. EUR 100,000 damages each. Former President Kwasniewski admitted agreeing to host the site.[14]

US-Poland MLAT

Signed July 10, 1996, in force September 17, 1999. Beyond the US, Poland holds bilateral mutual-assistance treaties with several states (including Sweden, 1990); the full set of Polish bilateral treaties is searchable in the Ministry of Foreign Affairs’ treaty database (Internetowa Baza Traktatowa).[15]

The Privacy Backdoor Effect

Despite UODO enforcement and constitutional protections, extensive alternative access exists:

Club de Berne and the Counter Terrorism Group

Poland’s ABW takes part in the Club de Berne (founded 1969), the forum of the heads of the domestic intelligence and security services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland. The Club is a broad, all-source intelligence-sharing body, not a counterterrorism-specific one; its separate offshoot, the Counter Terrorism Group (CTG), created in September 2001, shares terrorism intelligence among the same services plus the United Kingdom and has run a joint operational platform in The Hague with a common database and real-time information system since 2016.[24]

Surveillance and Intelligence

Five Intelligence Agencies

ABW (domestic intelligence), AW (foreign intelligence/SIGINT), CBA (anti-corruption), SKW (military counterintelligence/SIGINT), SWW (military intelligence/SIGINT). All five have operational control (wiretapping) powers and access telecommunications metadata without judicial authorisation. Created after dissolving communist-era services. Wiretap approval rate approximately 99%.[6]

Pegasus Spyware Scandal (2017–2022)

CBA purchased Pegasus with PLN 25 million from the Justice Fund. Three agencies (CBA, ABW, SKW) targeted 578 individuals: 6 in 2017 escalating to 162 in 2021. Citizen Lab identified first targets in December 2021: opposition politician Krzysztof Brejza (hacked 33 times during campaign), lawyer Roman Giertych, and prosecutor Ewa Wrzosek. Senate investigation found “gross violations of constitutional standards.” Former Justice Minister Ziobro arrested (January 2025, 26 charges), fled to Hungary (January 2026), EAW sought (February 2026).[7]

On February 25, 2026, the National Prosecutors’ Office charged former ABW head and SKW head with criminal offences for deploying Pegasus without required IT security accreditation, the first criminal prosecution of intelligence chiefs over Pegasus in any EU member state. Each faces up to three years imprisonment.[8]

ECHR: Pietrzak and Others v. Poland (May 2024)

Three Article 8 ECHR violations: (1) wiretapping regime lacked adequate safeguards; (2) metadata access regime exceeded what is “necessary in a democratic society”; (3) Anti-Terrorism Act secret surveillance lacked independent review. The Constitutional Tribunal’s 2014 ruling requiring independent surveillance oversight has been broadly ignored; 2016 amendments instead expanded powers.[2][9]

Palantir Defense Partnership

MoD signed MOU (December 2024) and Letter of Intent (October 2025) with Palantir covering battlefield management, logistics, AI, and cybersecurity across the Polish Armed Forces. Poland’s NATO-leading ~5% GDP defence spending drives aggressive US defence tech partnerships. Because Palantir is subject to the CLOUD Act, Polish Armed Forces operational data is accessible to US authorities without Polish consent.[10]

Internet Infrastructure

EPIX (Poland’s largest IXP, 3.5+ Tbps, 850+ users, Warsaw/Katowice/Poznan). PLIX/Equinix Warsaw (241 ISP members, 460+ ports). ~500 km Baltic coastline; connectivity relies primarily on terrestrial fibre to Germany, Czech Republic, and Lithuania. Landlocked for cables: international traffic transits through neighbouring countries including Germany (DE-CIX/BND cable interception).[11]

Recent Developments

Act on Artificial Intelligence Systems signed (July 24, 2026): Poland’s AI Act implementing statute completed its passage. The government bill (Sejm print 2443) arrived in the Sejm on April 9, 2026, passed third reading on June 11, 2026 by 421 votes to 3 with 18 abstentions, went to the Senate, which returned it with amendments on June 25; the Sejm accepted part of those amendments on July 3 and sent the text to the President the same day. The President signed it on July 24, 2026, and it was published as Dz.U. 2026 poz. 1003, with its provisions taking effect in August 2026.[26]

The Act creates the Commission for the Development and Security of Artificial Intelligence (KRiBSI) as the single national authority for market surveillance of AI systems and of general-purpose AI models under Regulation (EU) 2024/1689. Poland and Lithuania are the only member states to designate one authority rather than distributing the function across sectoral regulators, and Poland is alone in building a new institution to hold it. KRiBSI is collegiate, embedding the competition, financial-supervision, broadcasting, and telecoms regulators; it also hears complaints from citizens and administers regulatory sandboxes. The chair is to be appointed within two months of entry into force and the full Commission within three.[25][26]

The UODO question, answered from the published Act: the exclusion survived. Under Article 19(1) of the Act as published (Dz.U. 2026 poz. 1003), KRiBSI consists of the Chair, two Deputy Chairs, and four members designated by the competition authority (UOKiK), the financial supervisor (KNF), the broadcasting council (KRRiT), and the telecoms regulator (UKE). The data protection authority is not among them. Article 19(3) provides that representatives of ministers and of the national authorities and public bodies referred to in Article 77(1) of the AI Act, the fundamental-rights supervisors, may attend sittings “bez prawa głosu,” without the right to vote, and Article 19(2) lets the Chair invite others to speak with an advisory voice only. That is the channel through which Poland’s data protection authority participates in AI supervision.[27]

Its remaining statutory roles are narrow and, with one exception, tied to the regulatory sandbox. Article 20(1)(3) obliges the Commission to cooperate with the President of UODO in the matters covered by Article 57(10) of the AI Act, the sandbox provision. Article 92 has UODO issue opinions on regulatory expectations for personal-data processing inside the sandbox, expressly without prejudice to its GDPR supervisory powers. The exception is appointments: under Article 32(2) UODO designates one of the five members of the panel that recruits the Deputy Chairs, alongside one from the Polish Academy of Sciences and one from the Social Council. The Chair is appointed and dismissed by the Sejm with the Senate’s consent for a five-year term, renewable once. A separate Social Council for Artificial Intelligence (Article 45), nine to fifteen members chosen by the Commission for two-year terms from candidates put forward by the Ombudsman, the Children’s, Patients’ and SME Ombudsmen, the Chief Labour Inspector, local government, chambers of commerce, trade unions, universities, employers’ organisations, and NGOs working on AI, human rights, technological justice, digital education, and information security, advises the Commission and can move the Sejm to dismiss the Chair. UODO is not among the bodies entitled to nominate to it either.[27]

That matters more than an institutional turf question because of what the Act lets the new body do with personal data. Article 39 authorises the Chair, the Deputy Chairs, the members, and the ministry staff serving the Commission to process personal data including special-category data under GDPR Article 9(1) and criminal-conviction data under Article 10, to the extent necessary for its tasks. Article 40 extends processing to data obtained in the course of AI supervision concerning users of information systems and of telecommunications terminal equipment, the terminal equipment itself, and data collected by essential-service operators, digital service providers, and the key and important entities under the National Cybersecurity System Act, excluding only what is covered by electronic-communications secrecy, plus data held by public bodies. Article 41 sets deletion at ten years after the close of proceedings, with a necessity review at least every five. Article 42(3) allows the Commission to pass legally protected secrets, trade secrets included, to bodies entitled under the statute governing information exchange with law enforcement authorities of EU member states, third countries, EU agencies, and international organisations. So Poland has created a regulator that may handle sensitive and criminal data, reach data held by cybersecurity-regulated operators, keep it for a decade, and route protected information abroad through law-enforcement channels, and has given its data protection authority a seat at the table without a vote.[27]

Privacy Framework

The UODO enforces the GDPR. Major fines: Poczta Polska PLN 27.1M (30 million citizens’ data for postal election), ING Bank PLN 18.4M (identity document scanning), McDonald’s PLN 16.9M (failed risk analysis). The Personal Data Protection Act (2018) supplements the GDPR. The Electronic Communications Law (November 2024) expanded scope to email, messaging, and video conferencing. Police Act (1990) and Anti-Terrorism Act (2016) provide surveillance authorities. Chat Control: Poland opposes mandatory scanning of encrypted communications.[4][5]

After a delayed transposition, the amended Act on the National Cybersecurity System (KSC), implementing the EU NIS2 Directive, entered into force on April 3, 2026. It expands the regime from roughly 400 operators of essential services to over 42,000 entities, with registration in the S46 system due by October 3, 2026, cybersecurity measures by April 3, 2027, and full enforcement of administrative fines from April 3, 2028.[16]

Data Retention

12-month mandatory retention of telecommunications metadata (reduced from 24 months in January 2013). Nine entities authorised to access retained data (Police, Border Guard, Military Police, ABW, SKW, CBA, Customs, fiscal authorities, prosecutors/courts). Intelligence agencies access metadata without judicial authorisation and without independent oversight. The Constitutional Tribunal’s 2014 ruling that this access violated privacy rights has not been effectively implemented.[12]

Pending Legislation

Sources

[1] UODO: About the Office – Enforcement statistics, Poczta Polska/ING/McDonald’s fines
[2] HUDOC: Pietrzak and Others v. Poland (May 2024) – Three Article 8 violations
[4] ICLG: Data Protection – Poland – Personal Data Protection Act 2018, Electronic Communications Law
[5] EDRi: Chat Control – Poland opposes mandatory scanning
[6] Library of Congress: Intelligence Activities – Poland – Five agencies, warrantless metadata access, 99% wiretap approval
[7] Citizen Lab: Polish Pegasus Targets (December 2021) – Brejza (33 hacks), Giertych, Wrzosek, 578 total targets
[9] Constitutional Tribunal: K 23/11 (July 2014) – Surveillance ruling broadly ignored
[10] Defence24: Palantir Poland LoI (October 2025) – MoD partnership, CLOUD Act exposure
[11] EPIX – 3.5+ Tbps, 850+ users, Poland’s largest IXP
[12] Open Net: Poland Data Retention – 12-month retention, nine entities, warrantless access
[13] Wikipedia: Poland in the EU – NATO 1999, EU 2004, SIS II, EIO, Prüm
[14] Wikipedia: CIA Black Sites – Poland – Stare Kiejkuty, ECHR Al Nashiri and Abu Zubaydah rulings
[15] US DOJ: MLATs (April 2022) – US-Poland MLAT signed July 1996, in force September 1999
[16] Bird & Bird: NIS2 Directive Implementation in Poland (2026) – Amended Act on the National Cybersecurity System (KSC) entered into force April 3, 2026; scope expanded from ~400 operators of essential services to 42,000+ entities; S46 registration by October 3, 2026; cybersecurity measures by April 3, 2027; administrative fines enforced from April 3, 2028
[17] Panoptykon Foundation: Surveillance in Poland Under Scrutiny of Court – Civil-society-driven reform proposals requiring agencies to disclose intended technical means to courts and courts to justify approvals/rejections; Senate proposal for an independent “institution of legal protection” cooperating with the Human Rights Commissioner, UODO, and Supreme Audit Office; context of ECHR Pietrzak v. Poland (2024) finding the metadata/retention regime exceeded necessity
[18] Recording Law: Poland Data Privacy Laws (2026) – Draft Act on Artificial Intelligence Systems adopted by the Council of Ministers March 31, 2026 and submitted to Parliament; new Commission for AI Development and Security (KRiBSI) as primary national supervisory authority with UODO in a coordinating role; division of competence between KRiBSI and UODO on AI decisions involving personal data unresolved as of May 2026, with UODO arguing that enforcement involving personal data requires meaningful participation in decision-making rather than consultation; UODO 2026 sectoral inspection plan published January 8, 2026 covering five priority areas including health-data security, marketing entities and online delivery platforms
[19] Council of Europe Treaty Office: European Convention on Mutual Assistance in Criminal Matters (ETS No. 30) – Chart of signatures and ratifications; 51 parties as of July 2026 (all 46 Council of Europe member states plus Chile, Israel, Mongolia, the Republic of Korea and Russia), Poland among them
[20] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026 (45 Council of Europe member states plus 37 non-member states), Poland among them
[21] European Commission: Schengen Area – The 29 states of the Schengen Area (all EU members except Ireland and Cyprus, plus the non-EU associates Iceland, Liechtenstein, Norway and Switzerland; Bulgaria and Romania became full members January 1, 2025), Poland among them
[22] Wikipedia: Prüm Convention – The Prüm framework for automated DNA, fingerprint and vehicle-data exchange; binds all 27 EU member states plus the non-EU Schengen associates Iceland, Liechtenstein, Norway and Switzerland (31 in all); Prüm II (2024) adds facial images and police records
[23] Europol: Operational Agreements – Europol is constituted by the 27 EU member states (Poland among them) and maintains operational cooperation agreements permitting exchange of personal data with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, the United States) plus Denmark under a separate agreement, and with Eurojust, Frontex and Interpol
[24] Wikipedia: Club de Berne – informal forum (founded 1969) of the heads of the domestic intelligence and security services of the 27 EU member states plus Norway and Switzerland; its separate post-9/11 offshoot the Counter Terrorism Group (September 2001) additionally includes the United Kingdom and has operated a joint platform in The Hague with a common database and real-time information system since 2016
[25] Taylor Wessing: Poland’s New AI Systems Act (2026) – the Sejm passed the Act on artificial intelligence systems on June 11, 2026, now before the Senate; KRiBSI becomes the sole national market-surveillance authority for AI (Poland and Lithuania are the only EU states with a single such authority), collegiate membership drawing on the competition, financial, broadcasting and telecoms regulators; UODO holds a cooperating role without voting rights, which it has publicly contested
[26] Sejm RP: Przebieg procesu legislacyjnego, druk nr 2443 (Rządowy projekt ustawy o systemach sztucznej inteligencji) – official legislative record: bill received April 9, 2026, first reading April 29, committee report June 2, second reading June 10, third reading June 11, 2026 carried 421 to 3 with 18 abstentions; Senate position with amendments June 25; Sejm accepted part of the amendments July 3 and transmitted the Act to the President the same day; President signed the Act on July 24, 2026; published at Dz.U. poz. 1003. The Act governs the organisation and exercise of market surveillance over AI systems and general-purpose AI models under Regulation (EU) 2024/1689, with the Commission for the Development and Security of Artificial Intelligence responsible for control and for supporting development
[27] Dziennik Ustaw: Ustawa z dnia 3 lipca 2026 r. o systemach sztucznej inteligencji (Dz.U. 2026 poz. 1003) – the Act as published on July 27, 2026 (34 pages). Art. 19(1): KRiBSI comprises the Chair, two Deputy Chairs and four members designated by UOKiK, KNF, KRRiT and UKE; Art. 19(2): the Chair may invite others to attend with an advisory voice; Art. 19(3): representatives of ministers and of the national authorities and public bodies under Art. 77(1) of Regulation 2024/1689 may attend “bez prawa głosu”, without the right to vote; Art. 19(4): Chair, Deputies and members are independent in that function. Art. 20(1)(3): the Commission cooperates with the President of UODO in the matters covered by Art. 57(10) of Regulation 2024/1689; Art. 92: UODO issues opinions on regulatory expectations for personal-data processing in the regulatory sandbox, without prejudice to its powers under Regulation 2016/679 and having regard to Art. 57(12). Art. 28: the Chair is appointed and dismissed by the Sejm with the Senate’s consent for a five-year term, maximum two terms; Art. 32(2): the five-member recruitment panel for Deputy Chairs includes one representative designated by the President of UODO, one by the Social Council and one by the Polish Academy of Sciences. Art. 39: the Chair, Deputies, members and serving ministry staff process personal data including data under Arts. 9(1) and 10 of Regulation 2016/679; Art. 40: processing extends to data on users of information systems and telecommunications terminal equipment, on that equipment, and data collected by essential-service operators, digital service providers and key and important entities under the National Cybersecurity System Act (excluding data covered by electronic-communications secrecy) and by public bodies; Art. 41: deletion ten years after the close of proceedings, with a necessity review at least every five years; Art. 42: processing of legally protected secrets including trade secrets, and transmission of them to bodies entitled under the Act on exchange of information with law-enforcement authorities of EU member states, third countries, EU agencies and international organisations. Art. 45: the Social Council for Artificial Intelligence, nine to fifteen members elected by the Commission for two-year terms from candidates nominated by the Ombudsman, the Children’s, Patients’ and SME Ombudsmen, the Chief Labour Inspector, the local-government side of the Joint Commission, chambers of commerce, representative trade unions, higher-education and research bodies, employers’ organisations and NGOs
← Back to Privacy Law Directory