GDPR is not a one-off privacy policy or a file of consent forms. A company operating in Poland must be able to explain and demonstrate how it collects, uses, shares, protects and deletes personal data — from recruitment and payroll to customer service, accounting, marketing and cloud systems.
What counts as personal data and processing?
Personal data is any information relating to an identified or identifiable living person. Processing includes collecting, recording, organising, reading, changing, sending, storing, combining, restricting, deleting and destroying such information — electronically or on paper.
- Common business data: names, contact details, PESEL, identification and payroll data, bank account, signatures, CVs, performance records, customer correspondence, IP addresses and online identifiers.
- Special categories include health, biometric data used for identification, racial or ethnic origin, political opinions, religion, trade-union membership, genetic data and data about sex life or sexual orientation. Criminal-conviction data follows a separate restrictive rule.
Does GDPR apply to a small company?
Company size does not create a general exemption. GDPR applies to organisations established in the EU that process personal data and, in specified cases, to organisations outside the EU offering goods or services to people in the EU or monitoring their behaviour. A sole trader with employees, customers, website analytics or a mailing list can therefore be covered.
Controller, processor and DPO are different roles
- Controller — decides why and how personal data is processed. An employer is normally controller of employee data.
- Processor — processes data on the controller’s documented instructions, for example a payroll, hosting or IT provider in an appropriate setup.
- Joint controllers — jointly determine purposes and essential means and must transparently allocate responsibilities.
- Data Protection Officer (DPO) — independently advises, monitors compliance and acts as a contact point; the organisation remains accountable.
The seven operating principles
- Lawfulness, fairness and transparency.
- Purpose limitation — do not reuse data for an incompatible purpose without a valid route.
- Data minimisation — collect only what is necessary.
- Accuracy — keep data correct and current.
- Storage limitation — define and enforce retention.
- Integrity and confidentiality — use risk-appropriate security.
- Accountability — be able to demonstrate every preceding point.
Choose the legal basis before collecting data
Every ordinary personal-data operation needs a basis under Article 6. The basis must match the real purpose and be recorded before processing begins; it cannot be selected retrospectively merely because it is convenient.
- Consent — freely given, specific, informed, unambiguous and withdrawable.
- Contract or pre-contract steps — only when the processing is objectively necessary for that contract with the person.
- Legal obligation — for example statutory payroll, social-security, tax or accounting duties.
- Legitimate interests — only after identifying a lawful interest, showing necessity and balancing it against the person’s rights and reasonable expectations.
- Vital interests and public task — relevant in narrower situations.
Special-category and criminal-conviction data
A basis under Article 6 is not enough for special-category data: one of the Article 9 exceptions must also apply. Criminal-conviction data may be processed only under official authority or when Union or national law provides appropriate safeguards. Limit access, document the rule and apply stronger controls.
Employee and candidate data
- Recruitment — request only data permitted by labour law and necessary for the role; define a separate rule for future recruitment.
- Employment and payroll — identify statutory fields, recipients, access rights and retention for personnel, payroll, tax, ZUS and benefit records.
- Health and benefit data — process only where labour or social-security law and Article 9 permit it.
- Monitoring — define a lawful purpose, necessity, proportionality, retention and notices; follow the Polish Labour Code.
- Private phone or email — do not turn data obtained in recruitment into a permanent work channel without a valid, genuinely voluntary basis.
Outsourcing payroll does not transfer the employer’s accountability. The employer remains controller of employee data, while the payroll provider will usually act as processor for instructed operations. The Article 28 agreement, access model, incident route and return or deletion of data must match the service in practice.
Privacy notices are more than a website policy
Articles 13 and 14 require clear information about the controller, purposes, legal bases, recipients, transfers, retention, rights, complaint route and any relevant automated decision-making. Give the notice at collection when data comes from the person; for indirect collection, follow the Article 14 timing and exceptions. Prepare notices for candidates, employees, clients, contact persons, contractors and website users where relevant.
How to handle individual rights
- Information and access, including a copy of personal data.
- Rectification of inaccurate or incomplete data.
- Erasure and restriction where the legal conditions are met.
- Portability for automated processing based on consent or contract and data provided by the person.
- Objection, including an unconditional right to object to direct marketing.
- Protection against specified decisions based solely on automated processing.
Create one intake and verification process. The controller normally responds within one month; it may extend by two further months for a complex request if it informs the person within the first month. Verify identity proportionately, protect other people’s rights, document the search and explain any refusal together with the complaint and court routes.
Retention needs a schedule, not ‘keep everything’
Define retention by purpose and data category. Combine statutory periods, the active contractual or employment relationship, limitation periods and documented operational need. Set deletion or anonymisation triggers in paper archives, email, shared drives, business systems and backups, while preserving data subject to a valid hold.
Record of processing activities
A record of processing activities is the company’s data map. It should reflect actual operations such as recruitment, employment, payroll, client onboarding, invoicing, support, marketing, access control and website analytics. Keep it current and available to the supervisory authority.
For each operation record the purpose, categories of people and data, recipients, transfers outside the EEA, retention and — where possible — a general description of security measures. Processors maintain a record of categories of processing performed for controllers.
Vendors and Article 28 agreements
- Confirm whether the vendor is processor, controller or joint controller for each operation.
- Assess competence, security, locations, access, incident history and subcontracting.
- Put the Article 28 terms in writing: instructions, confidentiality, security, subprocessors, support with rights and breaches, end-of-service deletion or return, and audit information.
- Maintain an approved-vendor and subprocessor list and update it before a new tool receives live data.
Cloud, SaaS and AI tools: check the data route
Before uploading employee, client or document data, identify where it is stored and remotely accessed, who can use it, whether it trains a model, how long logs and prompts remain, and whether deletion is effective. A transfer outside the EEA must comply with Chapter V in addition to all other GDPR rules — for example through an adequacy decision or appropriate safeguards such as SCCs, with the required assessment and supplementary measures.
Security must match the risk
- Role-based access and least privilege; prompt onboarding, role changes and offboarding.
- Multi-factor authentication, secure configuration, patching and endpoint protection.
- Encryption or pseudonymisation where appropriate; secure transfer and disposal.
- Tested backups, recovery procedures, logging and alerting.
- Confidentiality obligations, practical training, phishing tests and a clear incident channel.
- Regular risk reviews and audits with tracked remediation.
When is a DPIA required?
Carry out a Data Protection Impact Assessment before processing that is likely to create a high risk to people — for example large-scale special-category data, systematic large-scale monitoring, or systematic and extensive automated evaluation producing legal or similarly significant effects. Describe necessity, proportionality, risks and safeguards; consult the authority when high residual risk remains.
Does the company need a Data Protection Officer?
A DPO is mandatory for public authorities and bodies, for core activities involving regular and systematic large-scale monitoring, or core activities involving large-scale processing of special-category or criminal-conviction data. A voluntary DPO must still receive independence, resources, early involvement and direct access to top management. The DPO advises and monitors; management and the controller make compliance decisions.
Personal-data breach: the 72-hour process
A personal-data breach includes accidental or unlawful loss, destruction, alteration, unauthorised disclosure or access, and loss of availability such as ransomware. Every breach must be documented, but not every security incident contains personal data and not every personal-data breach is notified to the authority.
- Contain the incident, preserve evidence and open the breach log.
- Establish when the organisation became aware with reasonable certainty, what data and people are affected, and which systems and recipients are involved.
- Assess likely impact on people, not only loss to the company.
- Notify the competent authority without undue delay and, where feasible, within 72 hours unless the breach is unlikely to result in risk; explain a late notification and submit information in phases if necessary.
- Inform affected people without undue delay where high risk is likely, unless a statutory exception applies.
- Record the facts, assessment, decision, communications and remediation for every breach.
Fines are only one enforcement tool
Depending on the provision, maximum administrative fines can reach €10 million or 2% of worldwide annual turnover, or €20 million or 4%, whichever is higher. These are ceilings, not automatic tariffs. Authorities assess the individual case and may also issue warnings, reprimands, processing restrictions, deletion or compliance orders. Individuals can also seek compensation for qualifying damage.
A practical implementation plan
- Appoint a management owner and, if required, an independent DPO.
- Map processing, systems, paper files, recipients, transfers and owners.
- Classify controller/processor roles and legal bases, including Article 9 conditions.
- Update the record of processing, retention schedule and privacy notices.
- Review employee data, monitoring, recruitment and payroll access.
- Audit processors, Article 28 agreements, subprocessors and foreign transfers.
- Apply risk-based security, access reviews, backup tests and secure disposal.
- Implement one-month rights-request and 72-hour breach workflows.
- Run DPIAs before high-risk projects and include privacy by design in change approval.
- Train staff, test the procedures and report open risks to management.
Five myths to remove from company procedures
- ‘We need consent for everything’ — false; select the correct legal basis.
- ‘Every company needs a DPO’ — false; test Article 37.
- ‘A small company is exempt’ — false; only limited derogations exist.
- ‘Every erasure request means delete everything’ — false; rights have conditions and exceptions.
- ‘A privacy policy and processor contract complete GDPR’ — false; compliance must operate across the data lifecycle.
inPL can organise personal-data flows within payroll and HR, accounting and process outsourcing, including access, document routes, vendor interfaces and operational deadlines. Legal conclusions, DPO decisions and high-risk assessments should be confirmed by the appropriate data-protection specialist.
Legal and procedural information verified on 18 August 2026. The article applies the GDPR rules currently in force, including the existing limited Article 30(5) derogation. The EU simplification package that would amend record-keeping rules reached only a provisional political agreement on 9 June 2026 and still requires formal adoption; do not implement the proposed thresholds as current law. Recheck EU law, Polish law, UODO and EDPB guidance before publication and material process changes.