Privacy policy requirements in Poland
What a privacy policy has to say if you operate from Poland, which law applies, who enforces it, and which other pages you need alongside it.
The facts for Poland
- Law that applies: the General Data Protection Regulation (GDPR).
- Who enforces it: the Urząd Ochrony Danych Osobowych (UODO).
- Language your users read: Polish. Terms and a privacy policy in a language your buyer does not speak are worth little, whatever they say.
- Published legal notice: not generally required in Poland; the operator details live in the privacy policy and the terms.
- Pages this produces: Privacy Policy, Terms of Service, Account and data deletion page, Cookie Policy, End User License Agreement.
What GDPR asks for that a generic template will not have
A request for access or deletion has to be answered within one month and free of charge, and that month can be extended by two more when the request is genuinely complex, as long as you say so inside the first month.
Being established here is what makes GDPR your regime. It is not the only way a law reaches you: the GDPR follows the user too, so a company anywhere that offers a service to people in Europe, or watches what they do there, is caught by it as well. Which means GDPR is your floor, and the law of the places you sell into can add to it.
- The legal ground for every purpose, named. The regulation lists six; an app almost always relies on consent, contract, legal obligation or legitimate interests.
- Where you rely on legitimate interests, what that interest is.
- Whether data leaves the region, and what makes that lawful.
- Whether there is automated decision making, and what it does.
What every privacy policy has to contain
- Who you are, in a way someone could write to: a name, an address and an address for privacy questions.
- What you collect, item by item, and why you collect each one.
- Who else sees the data: hosting, analytics, payments, crash reporting, and where each of them runs.
- How long you keep it, and what happens when someone deletes their account.
- How to complain to the Urząd Ochrony Danych Osobowych (UODO) if you do not answer.
The pages that go with it in Poland
A privacy policy on its own is rarely the whole requirement. For an app shipping on iOS, Android and the web from Poland, the set is usually: Privacy Policy, Terms of Service, Account and data deletion page, Cookie Policy, End User License Agreement.
Poland does not generally require a separate published legal notice, so the operator details live inside the privacy policy and the terms.
The mistakes that cost people a review
- A policy that names a template company rather than yours.
- A deletion route that only exists inside the app, when the store wants one reachable from a web page.
- A list of what you collect that does not match what the app actually asks for.
- A link that 404s three months later because the page was hosted on a free tier that expired.
Keeping it true after launch
A legal page stops being true the moment the product moves past it, usually by adding a payment provider, an analytics SDK or a sign-in. Under GDPR the drift is yours rather than your vendor's, and the Urząd Ochrony Danych Osobowych (UODO) is who hears about it.
- Re-read it whenever you add a dependency that sees user data.
- Re-check what loads on the page after any change: the cookie notice and the policy have to agree.
- Keep the URL stable. Changing where a policy lives breaks every listing that points at it.
Common questions
Do I need a privacy policy if my app collects almost nothing?
Yes. Both stores require a working privacy policy URL before your listing goes live, whatever the app does. A short and honest policy is fine; a missing one is not.
Can I use a template from another country?
Only as a starting point. A template written for one regime names the wrong law, the wrong authority and sometimes rights that do not exist where you are. Under GDPR the wording and the rights differ from the American and the Brazilian versions.
Who enforces this in Poland, and what can they actually do?
the Urząd Ochrony Danych Osobowych (UODO). They take complaints from your users, can order you to change how you process data, and can fine you. In practice most cases start as a complaint from one person who could not get an answer from you, which is the cheapest thing on this page to avoid.
Does it have to be in Polish?
The safe answer is yes for the market you sell to. A policy nobody can read is treated as a policy nobody agreed to, and store reviewers in Poland read the listing in their own language.
Where should I host it?
Anywhere that will still be there in a year and does not need a login. Store reviewers open the link, and so do the people who use your app.
