Poland - Data Management Act
Draft Act on Data Management
Projekt ustawy o zarządzaniu danymi
Poland
RAI-PL-NA-DDMPUXX-2024The Draft Act on Data Management (Projekt ustawy o zarządzaniu danymi) implements the EU Data Governance Act (Regulation (EU) 2022/868) into Polish law. It establishes rules for re-use of certain protected public-sector data, creates a registration and supervision regime for data intermediation service providers, and sets up governance roles for the President of the Personal Data Protection Office (UODO) and the President of Statistics Poland (GUS).
Summary
The Draft Act on Data Management (Projekt ustawy o zarządzaniu danymi), prepared by the Ministry of Digitalisation, is designed to transpose and put into effect in Poland the principal elements of the EU Data Governance Act (DGA, Regulation (EU) 2022/868). The Draft focuses on four complementary pillars: (i) enabling controlled re-use of certain categories of protected data held by public-sector bodies (including commercially sensitive, intellectual property-protected, or otherwise protected data) by establishing application, offer and access procedures; (ii) creating a supervised regime for commercial data intermediation services (neutral intermediaries) including a registration requirement and obligations to act neutrally and not use transferred data for their own purposes; (iii) establishing a voluntary registration and trust-mark regime for organisations facilitating altruistic data sharing for public-good purposes (e.g., medical or scientific research); and (iv) setting rules for the transfer of non-personal data to third countries and related enforcement powers. Under the Draft, the President of the Personal Data Protection Office (Prezes UODO) is the competent authority for registering and supervising data intermediation service providers and for overseeing altruism-of-data organisations, while the President of Statistics Poland (Prezes GUS) is designated to provide technical assistance to public-sector bodies seeking to share protected data securely and lawfully.
Procedurally the Draft sets out application and review timelines for public-sector data holders; prescribes that a public-sector body, after receiving a request to re-use protected data, must either present an offer with terms (including fees reflecting marginal costs) or refuse by decision; and allows the public-sector body to request technical assistance from GUS (e.g., pseudonymisation, secure environments, structuring) with specified response timeframes. For data intermediation services, the Draft requires prior notification/registration with UODO and subjects providers to ongoing supervisory powers including corrective measures and administrative fines. The Draft also creates an information point (to be operated by the Ministry of Digitalisation) for users seeking guidance on available datasets and application procedures.
Enforcement provisions mirror the DGA’s tiered approach: administrative fines expressed in euro-equivalents for various breaches (e.g., failure to notify for intermediaries, breaches of registration conditions, unlawful onward transfers of non-personal data to third countries), powers to order suspension or cessation of services, and administrative review mechanisms; longer-term remedies include administrative decisions subject to judicial review. The Draft has been subject to public consultation (deadline 2 October 2024) and was the subject of a positive opinion issued by the Rada Legislacyjna on 20 September 2024. The Draft is explicitly framed as a national implementation instrument intended to ensure Poland can operationalise the DGA and participate in the broader EU data space initiative, with cross-cutting implications for privacy, cybersecurity, public-sector openness and innovation in data-driven services.
Full article
Read full text ↗Overview
The Draft Act on Data Management translates the EU Data Governance Act (DGA) into national law to enable safer and broader sharing and re-use of public-sector and privately held data. It establishes national institutions and procedures to facilitate re-use of certain protected public-sector datasets, to register and supervise neutral data intermediaries, and to certify organisations engaged in altruistic data sharing. Key national implementers named in the Draft are the President of the Personal Data Protection Office (Prezes UODO) and the President of Statistics Poland (Prezes GUS). For official project information see the Ministry of Digitalisation’s project page (Projekt ustawy o zarządzaniu danymi (gov.pl)) and the Rada Legislacyjna opinion of 20 September 2024 (Rada Legislacyjna – opinion).
Definitions
The Draft defines: "re-use" as use of data held by public-sector bodies for purposes other than original public tasks; "protected data" as categories shielded for confidentiality, intellectual property, personal-data reasons, or other legal protections; "data intermediation services" as neutral third-party offerings that facilitate data exchange (without exploiting the data for their own purposes); and "data altruism" as voluntary sharing of data for general-interest goals. These definitions align closely with terms set out in Regulation (EU) 2022/868 and are tailored to interact with Polish public-administration terminology.
Governance and Institutional Framework
The Draft assigns supervisory and support roles between national authorities. The President of UODO is designated as the competent supervisory authority for registering and monitoring data intermediation service providers and for maintaining the register of organisations of data altruism, including issuing trust marks. The President of GUS is appointed to provide technical assistance to public-sector bodies (secure environments, pseudonymisation, data structuring) to facilitate lawful re-use. The Ministry of Digitalisation is mandated to operate an information point providing guidance on datasets and application pathways. These institutional roles are intended to ensure co‑ordination between data-protection oversight, statistical expertise and user-facing information services; see the project announcement on the Ministry portal (gov.pl – Ministry of Digitalisation) for detail.
Key Focus Areas
The Draft centres on four primary topics: (1) procedures for re‑use of protected public-sector data — including application forms, 14‑day offer acceptance windows and fee principles tied to cost recovery; (2) a registration and supervision regime for data intermediation services requiring notification to UODO, neutrality obligations, and prohibitions on reusing transferred data for proprietary purposes; (3) a voluntary registration and trust-mark scheme for organisations enabling data altruism, with UODO oversight and a dedicated logo to signal compliance; and (4) controls on transfers of non-personal data to third countries, with powers for UODO to open administrative proceedings and impose sanctions for unlawful transfers. Complementary rules address secure environments for data access, technical assistance by GUS, metadata standards and documentation obligations to enhance transparency and interoperability.
Implementation Framework
The Draft creates procedural timelines and administrative flows: public-sector bodies must evaluate re-use requests and either provide an offer or refuse by a reasoned decision; if assistance is requested, Prezes GUS must respond within 21 days (draft text timelines); data intermediation providers must submit notifications and comply with ongoing supervisory reporting; organisations of data altruism may apply for registration and trust‑mark allocation, subject to review. The Draft contemplates publication of registers, templates for offers, and rules for fees to avoid discriminatory conditions. Administrative decisions (e.g., refusals, fines) are subject to standard administrative appeal and judicial-review channels.
Monitoring and Evaluation
The Draft requires periodic reporting by registered intermediaries and by altruism organisations to the supervising authority (UODO) and mandates that UODO and GUS publish aggregated supervisory statistics and annual activity reports. Monitoring focuses on compliance with neutrality obligations, correct handling of personal-data elements, secure transfer mechanisms, and fidelity to registration conditions. The Draft foresees coordination mechanisms with other oversight institutions (e.g., data-protection authorities and sectoral regulators) to track market development and systemic risks.
Penalties, Liability, and Appeals
The enforcement regime uses administrative decisions and fines calibrated on the DGA framework: examples in the Draft include fines up to EUR 50,000 for failure to notify, up to EUR 500,000 for material breaches of intermediary obligations, and up to EUR 5,000 for breaches by registered altruism organisations. The Draft also allows the imposition of corrective measures (orders to cease or suspend activities) and requires compelled production of documents within 30 days for enforcement purposes. Decisions by UODO are subject to judicial review before administrative courts following Polish administrative-procedure rules.
Relationship to Other Instruments
The Draft explicitly references the EU Data Governance Act (Regulation (EU) 2022/868) as its primary normative source and is designed to operate alongside GDPR and national data‑protection law. It also intersects with Polish laws on public‑sector information re‑use, intellectual property, administrative procedure (k.p.a.), and cybersecurity rules. Rada Legislacyjna’s opinion (20 Sept 2024) addresses specific drafting issues such as the application of administrative‑procedure rules to UODO proceedings; see the Rada Legislacyjna opinion for detailed drafting remarks (Rada Legislacyjna opinion).
International Alignment
The Draft is explicitly designed to implement the EU DGA and to align Polish domestic law with EU harmonisation objectives for a trusted data‑sharing ecosystem. It contains provisions addressing transfers of non‑personal data to third countries and envisages cooperation mechanisms with EU bodies as required by Regulation (EU) 2022/868. The Act therefore supports Poland’s participation in European Data Spaces and is intended to be consistent with overarching EU privacy and cybersecurity frameworks.
Implementation Timeline
| Event | Date |
|---|---|
| Project published on RCL / made public | 2024-09-11 |
| Rada Legislacyjna opinion issued | 2024-09-20 |
| Public consultation deadline | 2024-10-02 |
| Project adopted by Council of Ministers (government submission to parliament) | 2025-10-21 |
| Parliamentary readings (expected) | To be scheduled after government submission |
Sources and References
| Source | Type |
|---|---|
| Projekt ustawy o zarządzaniu danymi – Ministry of Digitalisation (gov.pl) | Primary Source |
| Rada Legislacyjna – Opinion (20 September 2024) | Primary Source |
| Regulation (EU) 2022/868 (Data Governance Act) – EUR-Lex | Primary Source |
Requirements for a company
What an organisation has to do under Poland - Data Management Act, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.
Must do
9- Notify UODO before offering data intermediation services.Providers of data intermediation services.
- Adhere to neutrality obligations as a data intermediary.Providers of data intermediation services.
- Do not reuse transferred data for proprietary purposes.Providers of data intermediation services.
- Comply with controls on transferring non-personal data to third countries.Entities transferring non-personal data to third countries.
- Produce requested documents for enforcement within 30 days.Entities subject to UODO enforcement proceedings.
- Evaluate re-use requests and provide an offer or reasoned refusal.Public-sector bodies holding protected data.
- +3 more in the table below
Must not do
0Nothing in this category.
Should do
1- Apply for registration and a trust mark for data altruism.Organizations enabling data altruism.
Should not do
0Nothing in this category.
Who must do what
The obligations under Poland - Data Management Act, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Providers of data intermediation services. | Notify UODO before offering data intermediation services. “requiring notification to UODO” | Before offering services | — | Critical |
| 2 | Providers of data intermediation services. | Adhere to neutrality obligations as a data intermediary. “neutrality obligations” | — | — | Critical |
| 3 | Providers of data intermediation services. | Do not reuse transferred data for proprietary purposes. “prohibitions on reusing transferred data for proprietary purposes” | — | — | Critical |
| 4 | Entities transferring non-personal data to third countries. | Comply with controls on transferring non-personal data to third countries. “controls on transfers of non-personal data to third countries” | Before transfer | — | Critical |
| 5 | Entities subject to UODO enforcement proceedings. | Produce requested documents for enforcement within 30 days. “requires compelled production of documents within 30 days for enforcement purposes” | Within 30 days | — | Critical |
| 6 | Public-sector bodies holding protected data. | Evaluate re-use requests and provide an offer or reasoned refusal. “public-sector bodies must evaluate re-use requests and either provide an offer or refuse by a reasoned decision” | Within 14 days | — | Important |
| 7 | Registered data intermediaries and altruism organizations. | Submit periodic supervisory reports to UODO. “periodic reporting by registered intermediaries and by altruism organisations to the supervising authority (UODO)” | Periodic | — | Important |
| 8 | Public-sector bodies, data intermediaries, altruism organizations. | Maintain documentation, metadata standards, and secure environments. “documentation obligations to enhance transparency and interoperability” | — | — | Important |
| 9 | Registered organizations of data altruism. | Adhere to compliance standards if registered for data altruism. “fines up to EUR 5,000 for breaches by registered altruism organisations” | — | — | Important |
| 10 | Organizations enabling data altruism. | Apply for registration and a trust mark for data altruism. “a voluntary registration and trust-mark scheme for organisations enabling data altruism” | — | — | Recommended |
Related Regulations
Act on Open Data and Re-use of Public Sector Information (Ustawa o otwartych danych i ponownym wykorzystywaniu informacji sektora publicznego)
Poland91% similar
Draft Act on Artificial Intelligence Systems (Projekt ustawy o systemach sztucznej inteligencji)
Poland90% similar
Draft Act on the Management of Selected Categories of Public Sector Data (data governance bill supporting AI/data reuse)
Slovakia90% similar
Law 5188/2025: Measures for the implementation of the Data Governance Act and the National Strategy for public sector data
Greece88% similar
Poland AI Regulation Overview
Poland86% similar
© Regulations.AI · updated on 13-Jun-2026