country: Poland framework: GDPR region: EU language: pl version: 2024-06 status: published last_updated: 2025-06-30 source_verified: true authority: Urzad Ochrony Danych Osobowych (UODO) – Polish Data Protection Authority notes: - Poland enforces GDPR alongside the Polish Personal Data Protection Act of 10 May 2018. - The UODO issues frequent guidance, especially for the public sector, education, health, and labor monitoring. categories: - name: Full Name type: direct_identifier subtype: personal_name required_masking: true tags: - pii citations: - regulation: GDPR article: 4(1) category_tags: - core - identity - name: Email Address type: direct_identifier subtype: digital_contact required_masking: true tags: - pii citations: - regulation: GDPR article: 4(1) category_tags: - core - contact - name: Phone Number type: direct_identifier subtype: telecom_contact required_masking: true tags: - pii citations: - regulation: GDPR article: 4(1) category_tags: - core - contact - name: IP Address type: indirect_identifier subtype: network_identifier required_masking: true tags: - tracking citations: - regulation: GDPR recital: '30' - authority: UODO guideline: Cookies i dane z urządzeń końcowych url: https://uodo.gov.pl/pl/138/1169 category_tags: - digital - behavioral - name: PESEL Number (Polish National Identification Number) type: national_identifier subtype: government_id required_masking: true tags: - pii - national_id - government_id citations: - regulation: GDPR article: '87' - national_law: Personal Data Protection Act 2018 article: '10' description: Processing PESEL numbers must be legally justified category_tags: - identity - sensitive - name: Health Data (medical history, e-prescriptions, hospitalization records) type: special_category subtype: health required_masking: true tags: - phi - sensitive - tracking citations: - regulation: GDPR article: 9(1) - authority: UODO guideline: Przetwarzanie danych zdrowotnych url: https://uodo.gov.pl/pl/225/1055 category_tags: - health - sensitive - name: Biometric Data (fingerprints, face scans) type: special_category subtype: biometric required_masking: true tags: - biometric - sensitive citations: - regulation: GDPR article: 9(1) category_tags: - biometric - sensitive - name: Location Data (school check-ins, employee GPS) type: behavioral subtype: geolocation required_masking: true tags: - tracking citations: - regulation: GDPR article: 4(1) category_tags: - tracking - digital - name: Cookie Identifiers / Device Fingerprints type: indirect_identifier subtype: device_id required_masking: true tags: - tracking - online_identifier - pii citations: - regulation: GDPR recital: '30' - authority: UODO guideline: Cookies i dane z urządzeń końcowych url: https://uodo.gov.pl/pl/138/1169 category_tags: - tracking - digital - name: Employment Records (job performance, camera footage, access logs) type: contextual_identifier subtype: hr_data required_masking: true tags: - pii - hr_data - workplace_monitoring citations: - regulation: GDPR article: '88' - national_law: Labor Code (Kodeks pracy) section: Art. 22[2] description: Employee monitoring allowed with proper notification and purpose category_tags: - employment - sensitive