Poland's Data Management Act Takes Effect, Reshaping Oversight of Data Sharing

Poland's Data Management Act Takes Effect, Reshaping Oversight of Data Sharing

By
Key Takeaways
  • Poland Implements the Data Governance Act: Poland's Data Management Act entered into force on July 23, 2026, providing the national legal framework needed for the EU Data Governance Act (DGA) to operate fully within the country's legal system.
  • UODO Assumes New Regulatory Powers: Poland's Personal Data Protection Office (UODO) is now the competent authority for supervising data intermediation services, registering recognized data altruism organizations, and enforcing certain DGA provisions governing transfers of non-personal data to third countries.
  • Data Intermediaries Gain EU-Wide Market Access: Organizations intending to provide data intermediation services must notify UODO before commencing operations. Once notified, they are authorized to offer those services across all EU member states under the DGA.
  • Voluntary Recognition for Data Altruism Organizations: Eligible organizations may apply for registration with UODO as EU-recognized data altruism organizations, allowing them to use an official EU designation and logo recognized throughout the bloc.
Deep Dive

Poland's Data Management Act took effect Thursday, completing a piece of legal architecture that has been waiting for its final support. The European Union's Data Governance Act has applied across the bloc since 2023. What entered into force now is the national legislation that gives the regulation a fully functioning home inside Poland's legal system.

The practical consequence is immediate. Poland's Personal Data Protection Office (UODO) is no longer concerned solely with privacy. As of July 23, it assumes responsibility for supervising data intermediation services, registering recognized data altruism organizations, and enforcing parts of the EU framework governing transfers of non-personal data to third countries.

The shift says something about where European regulators believe the next phase of data governance is headed. The question is no longer only whether organizations collect data lawfully. It is increasingly how data moves between organizations, who can be trusted to broker those exchanges, and what public benefit can be created without sacrificing control.

A New Gatekeeper for Data Markets

The Data Governance Act was written to encourage data sharing without eroding confidence in it. European lawmakers have long argued that enormous volumes of industrial, public-sector and personal data remain underused because organizations hesitate to share them. The DGA attempts to lower that barrier by creating trusted intermediaries and common rules across the European Union.

Poland's new law assigns responsibility for that framework to UODO. The authority now becomes the competent regulator for data intermediation services under Article 13 of the DGA, the registration of recognized data altruism organizations under Article 23, and enforcement involving obligations governing transfers of non-personal data to third countries under Articles 5(14) and 31.

Those responsibilities extend well beyond traditional privacy supervision. They place UODO at the center of a market designed to facilitate lawful data sharing rather than simply police unlawful processing.

Notification Opens the Door to the Entire EU

For organizations seeking to operate as data intermediation service providers, the new regime begins with a notification. From July 23, any provider intending to offer those services must notify UODO in accordance with Article 11 of the DGA. Once that notification has been submitted, the provider may begin operating under the conditions laid out in Chapter III of the regulation.

The effect reaches beyond Poland's borders. A notification submitted to UODO authorizes the provider to offer data intermediation services throughout every EU member state. Providers may also ask UODO to verify their compliance with Articles 11 and 12 of the DGA. If the authority confirms compliance, the provider may use the designation "Union-recognised data intermediation service provider" together with the common European logo in its communications.

The European Commission maintains a public register of all notified data intermediation service providers across the European Union, with national authorities forwarding successful notifications for inclusion.

What Counts as a Data Intermediation Service?

The DGA is careful about its definitions because it is creating a new category of regulated business rather than expanding an old one.

A data intermediation service exists to establish commercial relationships between data holders or data subjects on one side and prospective data users on the other. Those relationships may be created through technical infrastructure, legal arrangements or other means that enable data sharing.

The regulation expressly includes platforms that facilitate data exchanges, infrastructures connecting data holders with data users, services helping individuals exercise GDPR rights relating to personal data sharing, and data cooperatives.

Just as important is what the definition excludes. Businesses that obtain data, enrich or transform it, and then license the resulting product are not treated as data intermediaries under the DGA because they are no longer merely connecting parties. Services focused on copyrighted content also fall outside the framework, as do internal data-sharing systems used within a single organization or corporate group, and public-sector data-sharing services that are not intended to establish commercial relationships.

Recognition for Data Altruism

The legislation also opens Poland's registration system for data altruism organizations. Any organization meeting the requirements set out in Article 18 of the DGA may apply for inclusion in the national public register maintained by UODO. Registration remains voluntary. Organizations are not prohibited from conducting data altruism activities if they choose not to register.

Recognition nevertheless carries practical value. Once registered, an organization may describe itself as an "EU-recognized data altruism organization" and use the common European logo. That recognition is valid across all EU member states rather than only in Poland.

Where an application contains all required information, UODO must determine whether the organization satisfies the statutory requirements and, if it does, complete registration within 12 weeks.

Building Trust Before Building Markets

Data altruism occupies a distinctive place within the DGA because it is not built around commercial exchange. The regulation defines it as the voluntary sharing of personal or non-personal data for objectives serving the general interest, without payment beyond reimbursement of the costs involved in making the data available. Those public-interest purposes include healthcare, scientific research, combating climate change, improving mobility, developing official statistics, strengthening public services and informing public policy.

That idea sits alongside the broader ambition running through the Data Governance Act itself. Rather than compelling organizations to share more data, the framework attempts to make sharing trustworthy enough that more organizations choose to participate. European lawmakers have tied that objective to the creation of common European data spaces spanning sectors such as health, mobility and the environment, while reducing fragmentation across the single market and giving businesses, including small and medium-sized enterprises and startups, a more predictable legal foundation for data-driven innovation.

Poland's legislation does not change those ambitions. It gives them an institution, a regulator and a process. For organizations operating in the emerging European data economy, that is when a regulation begins to matter.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

Oops! Something went wrong