Poland - Data Management Act

Draft Act on Data Management

Projekt ustawy o zarządzaniu danymi

Poland

RAI-PL-NA-DDMPUXX-2024
Draft(Being written or scoped)
BillGovernance and OversightConformity Assessment and Registration
Export PDF

The Draft Act on Data Management (Projekt ustawy o zarządzaniu danymi) implements the EU Data Governance Act (Regulation (EU) 2022/868) into Polish law. It establishes rules for re-use of certain protected public-sector data, creates a registration and supervision regime for data intermediation service providers, and sets up governance roles for the President of the Personal Data Protection Office (UODO) and the President of Statistics Poland (GUS).

Summary

The Draft Act on Data Management (Projekt ustawy o zarządzaniu danymi), prepared by the Ministry of Digitalisation, is designed to transpose and put into effect in Poland the principal elements of the EU Data Governance Act (DGA, Regulation (EU) 2022/868). The Draft focuses on four complementary pillars: (i) enabling controlled re-use of certain categories of protected data held by public-sector bodies (including commercially sensitive, intellectual property-protected, or otherwise protected data) by establishing application, offer and access procedures; (ii) creating a supervised regime for commercial data intermediation services (neutral intermediaries) including a registration requirement and obligations to act neutrally and not use transferred data for their own purposes; (iii) establishing a voluntary registration and trust-mark regime for organisations facilitating altruistic data sharing for public-good purposes (e.g., medical or scientific research); and (iv) setting rules for the transfer of non-personal data to third countries and related enforcement powers. Under the Draft, the President of the Personal Data Protection Office (Prezes UODO) is the competent authority for registering and supervising data intermediation service providers and for overseeing altruism-of-data organisations, while the President of Statistics Poland (Prezes GUS) is designated to provide technical assistance to public-sector bodies seeking to share protected data securely and lawfully.

Procedurally the Draft sets out application and review timelines for public-sector data holders; prescribes that a public-sector body, after receiving a request to re-use protected data, must either present an offer with terms (including fees reflecting marginal costs) or refuse by decision; and allows the public-sector body to request technical assistance from GUS (e.g., pseudonymisation, secure environments, structuring) with specified response timeframes. For data intermediation services, the Draft requires prior notification/registration with UODO and subjects providers to ongoing supervisory powers including corrective measures and administrative fines. The Draft also creates an information point (to be operated by the Ministry of Digitalisation) for users seeking guidance on available datasets and application procedures.

Enforcement provisions mirror the DGA’s tiered approach: administrative fines expressed in euro-equivalents for various breaches (e.g., failure to notify for intermediaries, breaches of registration conditions, unlawful onward transfers of non-personal data to third countries), powers to order suspension or cessation of services, and administrative review mechanisms; longer-term remedies include administrative decisions subject to judicial review. The Draft has been subject to public consultation (deadline 2 October 2024) and was the subject of a positive opinion issued by the Rada Legislacyjna on 20 September 2024. The Draft is explicitly framed as a national implementation instrument intended to ensure Poland can operationalise the DGA and participate in the broader EU data space initiative, with cross-cutting implications for privacy, cybersecurity, public-sector openness and innovation in data-driven services.

Full article

Read full text ↗

Overview

The Draft Act on Data Management translates the EU Data Governance Act (DGA) into national law to enable safer and broader sharing and re-use of public-sector and privately held data. It establishes national institutions and procedures to facilitate re-use of certain protected public-sector datasets, to register and supervise neutral data intermediaries, and to certify organisations engaged in altruistic data sharing. Key national implementers named in the Draft are the President of the Personal Data Protection Office (Prezes UODO) and the President of Statistics Poland (Prezes GUS). For official project information see the Ministry of Digitalisation’s project page (Projekt ustawy o zarządzaniu danymi (gov.pl)) and the Rada Legislacyjna opinion of 20 September 2024 (Rada Legislacyjna – opinion).

Definitions

The Draft defines: "re-use" as use of data held by public-sector bodies for purposes other than original public tasks; "protected data" as categories shielded for confidentiality, intellectual property, personal-data reasons, or other legal protections; "data intermediation services" as neutral third-party offerings that facilitate data exchange (without exploiting the data for their own purposes); and "data altruism" as voluntary sharing of data for general-interest goals. These definitions align closely with terms set out in Regulation (EU) 2022/868 and are tailored to interact with Polish public-administration terminology.

Governance and Institutional Framework

The Draft assigns supervisory and support roles between national authorities. The President of UODO is designated as the competent supervisory authority for registering and monitoring data intermediation service providers and for maintaining the register of organisations of data altruism, including issuing trust marks. The President of GUS is appointed to provide technical assistance to public-sector bodies (secure environments, pseudonymisation, data structuring) to facilitate lawful re-use. The Ministry of Digitalisation is mandated to operate an information point providing guidance on datasets and application pathways. These institutional roles are intended to ensure co‑ordination between data-protection oversight, statistical expertise and user-facing information services; see the project announcement on the Ministry portal (gov.pl – Ministry of Digitalisation) for detail.

Key Focus Areas

The Draft centres on four primary topics: (1) procedures for re‑use of protected public-sector data — including application forms, 14‑day offer acceptance windows and fee principles tied to cost recovery; (2) a registration and supervision regime for data intermediation services requiring notification to UODO, neutrality obligations, and prohibitions on reusing transferred data for proprietary purposes; (3) a voluntary registration and trust-mark scheme for organisations enabling data altruism, with UODO oversight and a dedicated logo to signal compliance; and (4) controls on transfers of non-personal data to third countries, with powers for UODO to open administrative proceedings and impose sanctions for unlawful transfers. Complementary rules address secure environments for data access, technical assistance by GUS, metadata standards and documentation obligations to enhance transparency and interoperability.

Implementation Framework

The Draft creates procedural timelines and administrative flows: public-sector bodies must evaluate re-use requests and either provide an offer or refuse by a reasoned decision; if assistance is requested, Prezes GUS must respond within 21 days (draft text timelines); data intermediation providers must submit notifications and comply with ongoing supervisory reporting; organisations of data altruism may apply for registration and trust‑mark allocation, subject to review. The Draft contemplates publication of registers, templates for offers, and rules for fees to avoid discriminatory conditions. Administrative decisions (e.g., refusals, fines) are subject to standard administrative appeal and judicial-review channels.

Monitoring and Evaluation

The Draft requires periodic reporting by registered intermediaries and by altruism organisations to the supervising authority (UODO) and mandates that UODO and GUS publish aggregated supervisory statistics and annual activity reports. Monitoring focuses on compliance with neutrality obligations, correct handling of personal-data elements, secure transfer mechanisms, and fidelity to registration conditions. The Draft foresees coordination mechanisms with other oversight institutions (e.g., data-protection authorities and sectoral regulators) to track market development and systemic risks.

Penalties, Liability, and Appeals

The enforcement regime uses administrative decisions and fines calibrated on the DGA framework: examples in the Draft include fines up to EUR 50,000 for failure to notify, up to EUR 500,000 for material breaches of intermediary obligations, and up to EUR 5,000 for breaches by registered altruism organisations. The Draft also allows the imposition of corrective measures (orders to cease or suspend activities) and requires compelled production of documents within 30 days for enforcement purposes. Decisions by UODO are subject to judicial review before administrative courts following Polish administrative-procedure rules.

Relationship to Other Instruments

The Draft explicitly references the EU Data Governance Act (Regulation (EU) 2022/868) as its primary normative source and is designed to operate alongside GDPR and national data‑protection law. It also intersects with Polish laws on public‑sector information re‑use, intellectual property, administrative procedure (k.p.a.), and cybersecurity rules. Rada Legislacyjna’s opinion (20 Sept 2024) addresses specific drafting issues such as the application of administrative‑procedure rules to UODO proceedings; see the Rada Legislacyjna opinion for detailed drafting remarks (Rada Legislacyjna opinion).

International Alignment

The Draft is explicitly designed to implement the EU DGA and to align Polish domestic law with EU harmonisation objectives for a trusted data‑sharing ecosystem. It contains provisions addressing transfers of non‑personal data to third countries and envisages cooperation mechanisms with EU bodies as required by Regulation (EU) 2022/868. The Act therefore supports Poland’s participation in European Data Spaces and is intended to be consistent with overarching EU privacy and cybersecurity frameworks.

Implementation Timeline

EventDate
Project published on RCL / made public2024-09-11
Rada Legislacyjna opinion issued2024-09-20
Public consultation deadline2024-10-02
Project adopted by Council of Ministers (government submission to parliament)2025-10-21
Parliamentary readings (expected)To be scheduled after government submission

Sources and References

SourceType
Projekt ustawy o zarządzaniu danymi – Ministry of Digitalisation (gov.pl)Primary Source
Rada Legislacyjna – Opinion (20 September 2024)Primary Source
Regulation (EU) 2022/868 (Data Governance Act) – EUR-LexPrimary Source

Requirements for a company

What an organisation has to do under Poland - Data Management Act, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.

Must do

9
  • Notify UODO before offering data intermediation services.Providers of data intermediation services.
  • Adhere to neutrality obligations as a data intermediary.Providers of data intermediation services.
  • Do not reuse transferred data for proprietary purposes.Providers of data intermediation services.
  • Comply with controls on transferring non-personal data to third countries.Entities transferring non-personal data to third countries.
  • Produce requested documents for enforcement within 30 days.Entities subject to UODO enforcement proceedings.
  • Evaluate re-use requests and provide an offer or reasoned refusal.Public-sector bodies holding protected data.
  • +3 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Apply for registration and a trust mark for data altruism.Organizations enabling data altruism.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Poland - Data Management Act, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers of data intermediation services.Notify UODO before offering data intermediation services.
requiring notification to UODO
Before offering servicesCritical
2Providers of data intermediation services.Adhere to neutrality obligations as a data intermediary.
neutrality obligations
Critical
3Providers of data intermediation services.Do not reuse transferred data for proprietary purposes.
prohibitions on reusing transferred data for proprietary purposes
Critical
4Entities transferring non-personal data to third countries.Comply with controls on transferring non-personal data to third countries.
controls on transfers of non-personal data to third countries
Before transferCritical
5Entities subject to UODO enforcement proceedings.Produce requested documents for enforcement within 30 days.
requires compelled production of documents within 30 days for enforcement purposes
Within 30 daysCritical
6Public-sector bodies holding protected data.Evaluate re-use requests and provide an offer or reasoned refusal.
public-sector bodies must evaluate re-use requests and either provide an offer or refuse by a reasoned decision
Within 14 daysImportant
7Registered data intermediaries and altruism organizations.Submit periodic supervisory reports to UODO.
periodic reporting by registered intermediaries and by altruism organisations to the supervising authority (UODO)
PeriodicImportant
8Public-sector bodies, data intermediaries, altruism organizations.Maintain documentation, metadata standards, and secure environments.
documentation obligations to enhance transparency and interoperability
Important
9Registered organizations of data altruism.Adhere to compliance standards if registered for data altruism.
fines up to EUR 5,000 for breaches by registered altruism organisations
Important
10Organizations enabling data altruism.Apply for registration and a trust mark for data altruism.
a voluntary registration and trust-mark scheme for organisations enabling data altruism
Recommended

© Regulations.AI · updated on 13-Jun-2026