Back to the blog

Confidentiality clauses under Polish law: which concessions weaken your protection?

Learn why marked-only definitions can exclude oral disclosures and how an objective cure period affects contractual penalties under Polish law.

You are negotiating a consulting agreement, investment agreement, or IT contract. The other party sends you a redline with two requests concerning the confidentiality clause. The first: “only documents expressly marked as confidential are considered confidential". The second: “no contractual penalty is payable if the breach was unintentional and the party remedies it within the specified period". Both sound reasonable. Both are legally permissible. But one renders the protection completely meaningless, while the other — if properly reworded — will strengthen your position in court.

In this article, I will show you how to distinguish a concession worth accepting from one that undermines the entire purpose of the clause. You will learn about the structure of a contractual penalty for breach of confidentiality, understand how a cure period works, and discover why requiring information to be marked as confidential is a trap. At the end, you will find a checklist that you can use to review your own agreement in just a few minutes.

Key concepts before you continue

Before we get into the details of the negotiation, it is worth clarifying a few concepts. Not to give you a lecture, but to make sure you know exactly what changes in your agreement when you accept a particular provision.

Concept What it means in an agreement
Contractual penalty (Article 483 of the Civil Code) An amount payable by a party for breaching a non-monetary obligation — for example, disclosing confidential information. It is payable regardless of whether any loss was incurred.
Reduction of a contractual penalty (Article 484 § 2 of the Civil Code) The court’s right to reduce a penalty if it is grossly excessive or if the obligation has been performed to a significant extent. It does not mean setting the penalty aside — it means reducing it.
Trade secret (Article 11(2) of the Act on Combating Unfair Competition) Information that has commercial value, is not publicly available, and has been subject to measures intended to preserve its confidentiality. Documents do not need to be marked.
Cure period A period during which the breaching party may remedy the effects of a breach before the penalty becomes due. It does not exist as a separate legal concept under the Polish Civil Code — it is a contractual mechanism.
Damages exceeding the penalty (Article 484 § 1, second sentence, of the Civil Code) The right to claim damages exceeding the amount of the contractual penalty — but only if this is expressly stipulated in the agreement. Without such a provision, this avenue is closed.

With these concepts in mind, let us move to the heart of the matter: why one of the counterparty’s requests is worth accepting and the other should be rejected.

Requiring information to be marked as confidential — why it is a trap

How this request arises in negotiations

The other party proposes: “Confidential Information means only materials expressly marked as confidential". They argue that this eliminates the risk of abuse — no one will claim that casual conversations were confidential. It sounds like a sensible way to bring clarity.

Except that in most consulting, transactional, and IT engagements, the most valuable information is not contained in files bearing a confidentiality footer.

What you lose if you agree

With a definition based on markings, the following remain outside the scope of contractual protection:

  1. An investor list provided over the phone
  2. A transaction price discussed at a meeting
  3. The reasons why an investor withdrew, explained via instant messenger
  4. Commercial terms discussed during a video conference
  5. Technical know-how communicated orally to a developer

These are often the most commercially valuable pieces of information in the entire project. Yet your clause protects only attachments bearing the appropriate marking.

What the law says

Article 11(2) of the Act on Combating Unfair Competition (consolidated text, Journal of Laws 2026, item 85) does not list marking materials as a condition for protection. Protection covers information that meets three conditions: it has commercial value, is not publicly available, and has been subject to measures intended to preserve its confidentiality. Courts — including in cases XXIII Zs 24/23 and XXIII Zs 177/24 — apply this three-part test without making protection dependent on the form in which the information is recorded.

Accepting a marking requirement is a concession that gives you less contractual protection than the law does. Protection in tort under the Act on Combating Unfair Competition may still cover oral information — but a claim for a contractual penalty for disclosing unmarked information will be excluded because a closed definition does not cover it.

What to do instead

Instead of a marking requirement, propose a list of exclusions to the other party. This is a standard mechanism that genuinely addresses the counterparty’s concerns about abuse of the clause without hollowing out the protection:

Exclusion What it means
Publicly available information You do not protect information that is already public
Information known to the party before disclosure You do not restrict knowledge the counterparty already had
Independently developed information You do not restrict the other party’s own research and development
Information disclosed at the request of an authority You do not prevent compliance with a legal obligation

This mechanism eliminates the risk the counterparty is concerned about — without leaving a gap in the protection of information communicated orally or indirectly.

It is also good practice to define the scope of confidential information more precisely by listing relevant categories, such as financial data, commercial terms, technical know-how, and lists of counterparties. Such a list does not make the definition exhaustive — it provides interpretive guidance that clarifies the scope without narrowing it.

Contact us

Cure period — when it protects and when it disarms the clause

The problem with a fault-based test

The other party proposes: “No contractual penalty is payable if the breach was unintentional and the party remedies it within the specified period". At first glance, this seems fair — why impose a penalty for an accident?

The problem is that a fault-based test shifts the dispute to the breaching party’s state of mind. In court, you have to prove that the counterparty acted intentionally. And they will always say: “I did not know the file was confidential", “An employee sent it by accident", “I did not intend to disclose it". In practice, these claims are almost impossible to refute.

The result is that a clause based on fault looks good on paper but is unenforceable in a dispute.

A test that works — objective remediability

Instead of asking “was the breach intentional?", ask a different question: “can the effects of the breach be remedied?". This is an objective test — it does not depend on what the breaching party claims about its intentions.

Type of breach Example Can it be remedied? Consequence
Reversible An employee sends a financial model to the wrong address within the organisation Yes — access can be revoked and copies deleted Cure period: 14 days to remedy the breach
Irreversible Providing an investor list to a competitor No — the information is already in circulation Penalty payable immediately, without notice

Proposed wording of the clause

Below is wording that changes only the date on which the penalty becomes due, not its amount — and only for breaches that are objectively remediable:

“If a breach of the confidentiality obligations arising under the Agreement can objectively be remedied, the Entitled Party shall, before imposing a contractual penalty, give the Breaching Party written notice requiring it to remedy the breach within 14 (fourteen) days from the date on which the notice is received. The contractual penalty shall become payable only if the Breaching Party fails to remedy the breach within that period."

This mechanism provides three benefits:

  1. The written notice requirement creates evidence — you document that the breach occurred and that you identified it. This works in your favour, not against you.
  2. A penalty imposed after an unsuccessful notice to cure is more difficult to reduce — the court can see that you gave the other party an opportunity to remedy the breach and that it failed to do so. An automatic penalty for an incident remedied on the same day is an easy target under Article 484 § 2 of the Civil Code.
  3. Irreversible breaches trigger the penalty immediately — you do not give the counterparty 14 days to “remedy" something that cannot be undone.

Why this strengthens your position in court

Article 484 § 2 of the Civil Code allows a court to reduce a contractual penalty if it is grossly excessive. Courts apply a proportionality test — they compare the penalty with the protected interest, the seriousness of the breach, and its consequences (Szczecin Court of Appeal, I ACa 221/18).

A penalty imposed automatically for a minor, reversible incident that the breaching party remedied on its own initiative is precisely the kind of situation in which a court is likely to reduce it. A penalty imposed after an unsuccessful 14-day notice to cure — much less so.

A cure period does not weaken the clause. It strengthens it by moving the date on which the penalty becomes due to the point at which the breaching party has had an opportunity to remedy the breach and failed to do so.

Five elements of a confidentiality clause you need to check

In addition to the definition of confidential information and the cure period, several other areas regularly cause problems in disputes. Review them in your own agreement.

Damages exceeding the contractual penalty

Article 484 § 1, second sentence, of the Civil Code expressly provides that damages exceeding the amount of the contractual penalty may be claimed only if this has been expressly stipulated in the agreement (Civil Code — consolidated text). Without such a provision — even if your actual loss is many times greater than the penalty — you cannot recover the excess.

Check whether your agreement contains a sentence such as “irrespective of the contractual penalty, the entitled party may claim damages exceeding the amount of the penalty". If not, add one.

Aggregate cap on penalties

A penalty stipulated for each individual breach without an aggregate cap may be challenged as grossly excessive in the event of repeated breaches. Courts consider the total amount of the penalties in relation to the value of the agreement (Szczecin Court of Appeal, I AGa 320/20).

Consider whether you need an aggregate cap. If the penalty is tens of thousands of Polish zlotys per breach and breaches may be repeated, a cap may protect the clause from being successfully challenged.

Liability for third parties

The chain of protection ends with the first subcontractor unless the party is liable for the persons to whom it discloses information. Add a clause making the party liable for its employees, advisers, and subcontractors as if for its own acts and omissions.

Term after the agreement ends

Five years is the transactional standard, but there is no single “correct" period. Directive 2016/943 does not establish a maximum period of contractual confidentiality (Directive 2016/943). Protection under Article 11 of the Act on Combating Unfair Competition continues for as long as the statutory conditions are met.

Match the period to the type of information:

Type of information Suggested approach
Technical know-how (algorithms, architecture) Longer — its value is maintained for years
Commercial data (price lists, terms) Shorter — it becomes outdated more quickly
Transaction information (valuation, funding-round terms) Dependent on the transaction cycle

Conflict with the right to provide references

Check whether the same agreement contains a clause permitting the parties to disclose the business relationship and use logos in marketing materials. Strict confidentiality in one paragraph and permission to provide references in another creates an inconsistency that weakens both clauses in a dispute.

Contractual penalties for breaches of confidentiality and the GDPR — a deadline you cannot postpone

A single event — such as the disclosure of a customer list — may breach both the agreement and the GDPR. Article 33(1) of the GDPR requires a personal data breach to be reported to the President of the Polish Data Protection Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach (Polish Data Protection Office — reporting breaches). The period begins when the breach is identified and includes non-working days.

A contractual 14-day cure period does not postpone or suspend this obligation. A contractual penalty and an administrative fine are different in nature and do not replace one another.

If your agreement involves the processing of personal data, the clause should distinguish between:

  1. The processor’s obligation to notify the controller without undue delay (Article 33(2) of the GDPR) — a deadline independent of the agreement
  2. The controller’s 72-hour deadline for reporting the breach to the Polish Data Protection Office — a statutory deadline
  3. The contractual cure period (14 days) — applicable solely to when the contractual penalty becomes due, not to public-law obligations

How to document a breach and serve notice

A cure period works only if you can prove two things: that the breach occurred and that the notice reached the addressee.

Hierarchy of evidence of service

Method of service Evidentiary strength Comments
e-Delivery from an electronic delivery address Strongest Has the same effect as registered mail with acknowledgement of receipt (Article 42 of the Electronic Delivery Act — consolidated text)
Registered mail with acknowledgement of receipt Strong Standard method; difficulties may arise if delivery is refused
Email with delivery confirmation and a reply from the recipient Moderate Satisfies documentary form requirements (Article 77² of the Civil Code), but not written form requirements without a qualified electronic signature
Sending an email alone Weakest No evidence that it reached the addressee

What the notice should contain

  1. Identification of the provision of the agreement that has been breached
  2. A description of the event and the date of the breach
  3. Evidence of the breach, or identification of such evidence
  4. The amount of the contractual penalty
  5. The period for remedying the breach (14 days from receipt)
  6. Information about the consequences of failing to comply within the period

Remember: a contractual requirement for something to be “in writing" is not automatically equivalent to documentary form. This depends on the interpretation of the specific agreement. If you want to use email to serve notice, make sure the agreement permits it.

Contractual penalties for employees and B2B contractors

If confidential information is disclosed to your team — employees and B2B contractors — you need to know that the liability rules differ depending on the engagement model.

Element Employment contract B2B contract
Basis of the confidentiality obligation Article 100 § 2(4)–(5) of the Labour Code Contractual clause
Contractual penalty for breach of confidentiality Permissible under a post-employment non-compete agreement (Supreme Court, II PK 327/10); during employment — restricted by the rules on employees’ financial liability Permissible under Articles 483–484 of the Civil Code
Liability cap Unintentional fault: up to three months’ remuneration (Article 119 of the Labour Code); intentional fault: full liability (Article 122 of the Labour Code) No statutory cap; subject to reduction under Article 484 § 2 of the Civil Code
Risk Labour Code restrictions may prevent enforcement of a high penalty A B2B clause may be challenged if the relationship has the characteristics of employment (Article 22 § 1 of the Labour Code)

Conclusion: for B2B contractors, a contractual penalty for breach of confidentiality is permissible and is not subject to Labour Code limits — but only if the relationship is genuinely B2B rather than disguised employment.

A clause based on a common-law template — what to change to make it work under Polish law

Many agreements — particularly in the IT sector and in transactions involving foreign investors — contain confidentiality clauses copied from common-law templates. Polish law does not use concepts such as “cure period" or “liquidated damages" (Rome I Regulation). Using English terminology without a choice-of-law clause does not result in English law being selected.

For a clause based on an English-language template to work under Polish law, it must be adapted functionally:

  1. Specify the governing law (Article 3 of the Rome I Regulation)
  2. Define confidential information in line with Polish law, either by referring to the Act on Combating Unfair Competition or by using your own definition with a list of exclusions
  3. Classify the sanction as a contractual penalty under Article 483 of the Civil Code — not as “liquidated damages"
  4. Specify the amount or an objective method for calculating it
  5. Distinguish between remediable and irreversible breaches
  6. Specify whether the cure period is a condition for the penalty becoming due or a prerequisite for terminating the agreement

A clause that makes the sanction dependent solely on the unsuccessful expiry of a cure period — without distinguishing between remediable and irreversible breaches — may prevent recovery of a penalty for a disclosure whose effects cannot be reversed. The Supreme Court considered a penalty of PLN 100,000 for breach of confidentiality (Supreme Court, IV CSK 443/18) without questioning the mechanism itself — but in that case the clause had been adapted to Polish law.

Checklist for a confidentiality clause with a contractual penalty

Use the checklist below to review your own agreement. Each item is a specific question — if the answer is “no" or “I don’t know", you have an area that needs to be corrected.

No. Question What to look out for
1 Does the definition of confidential information cover information communicated orally? If it is limited to marked materials, oral information is outside the scope of contractual protection
2 Is a list of exclusions used instead of a marking requirement? Exclusions for public, previously known, independently developed information and information disclosed at an authority’s request protect the counterparty without hollowing out the clause
3 Is the cure period based on objective remediability? A fault-based test based on whether the breach was unintentional is impossible to apply in evidentiary terms
4 Do irreversible breaches trigger the penalty immediately? Without this distinction, a penalty for disclosing an investor list to a competitor is delayed by 14 days
5 Has the right to claim damages exceeding the penalty been reserved? Without an express provision, such damages cannot be claimed (Article 484 § 1, second sentence, of the Civil Code)
6 Is there an aggregate cap where a penalty applies to each breach? The absence of a cap for repeated breaches creates a risk that the penalty will be challenged as grossly excessive
7 Is the party liable for the persons to whom it discloses information? Without such a clause, the chain of protection ends with the first subcontractor
8 Is the post-termination confidentiality period appropriate for the type of information? 5 years is standard — but it may be too short for technical know-how
9 Does the confidentiality clause conflict with the right to provide references? Confidentiality in one paragraph and permission to use logos in another creates an inconsistency
10 Must notice be given in writing, and does the agreement permit email? Inconsistent form requirements may prevent effective service
11 For personal data, does the clause distinguish between the GDPR deadline (72h) and the cure period (14 days)? The 14-day contractual period does not postpone the obligation to report the breach to the Polish Data Protection Office
12 Is the penalty proportionate to the protected interest? Too high — risk of reduction; too low — no deterrent effect

Bring consistency to the confidentiality clauses in your agreements

A confidentiality clause with a contractual penalty is one of the most frequently negotiated elements of consulting, IT, and transactional agreements. It is also one of the most frequently drafted incorrectly — because parties copy templates, accept seemingly reasonable concessions, and discover the problem only when a dispute arises.

If your company uses multiple agreement templates, negotiates confidentiality with different counterparties, and has no consistent rules, it is worth conducting a review. Check whether definitions of confidential information narrow the scope of protection, whether contractual penalties are likely to withstand scrutiny in court, whether cure periods disarm the clauses, and whether the chain of protection ends with subcontractors.

This is exactly the kind of work we help with — auditing confidentiality and contractual penalty clauses in the templates you use, introducing proven mechanisms such as lists of exclusions, cure periods based on an objective test, aggregate penalty caps, and liability for subcontractors, as well as establishing negotiation guidelines on which concessions can be made and which cannot.

Contact us

Frequently asked questions

The other party wants only documents marked as confidential to be treated as confidential. Why shouldn’t I agree?

Because the most valuable information — an investor list provided over the phone, a transaction price discussed at a meeting, or commercial terms shared via instant messenger — does not end up in files bearing a confidentiality footer. With a definition based on markings, your clause protects only attachments bearing the appropriate marking. Article 11(2) of the Act on Combating Unfair Competition does not require materials to be marked — it requires measures to be taken to preserve confidentiality. Accepting a marking requirement gives you less contractual protection than the law does. Instead, propose a list of exclusions covering public information, previously known information, independently developed information, and information disclosed at the request of an authority.

If I agree to a 14-day cure period, am I not giving the counterparty a free pass for one breach without consequences?

No — provided that the cure period applies only to breaches that are objectively remediable. Irreversible breaches, such as providing confidential data to a competitor, trigger the penalty immediately without notice. A cure period postpones the date on which the penalty becomes due, not its amount. And a penalty imposed after an unsuccessful notice to cure is much more difficult to challenge in court than an automatic penalty for an incident remedied on the same day.

Can a court reduce a contractual penalty that I negotiated?

Yes. Article 484 § 2 of the Civil Code allows a court to reduce a penalty if it is grossly excessive or if the obligation has been performed to a significant extent. Courts apply a proportionality test — they compare the penalty with the protected interest, the seriousness of the breach, and its consequences. Reduction means reducing the penalty, not setting it aside. A penalty imposed for each breach without an aggregate cap is particularly vulnerable to this challenge where breaches are repeated.

How do I know whether a breach is “objectively remediable"?

The question is whether the effects of the breach can be reversed. An employee sent a file to the wrong address within the organisation — access can be revoked and copies deleted. This is a remediable breach. A customer list was provided to a competitor — the information is already in circulation and the effect cannot be reversed. This is an irreversible breach. In the event of a dispute, the court will assess this, but the test is objective, based on the facts, rather than subjective, based on the breaching party’s intentions.

Doesn’t the Act on Combating Unfair Competition protect me anyway, even without a contractual clause?

Article 11 of the Act on Combating Unfair Competition protects trade secrets — but only if three conditions are met: commercial value, lack of public availability, and the implementation of protective measures. Statutory protection exists independently of the agreement, but pursuing claims under it is more difficult and time-consuming than enforcing a contractual penalty. A contractual penalty clause gives you a faster tool that is easier to prove — the penalty is payable regardless of whether you can demonstrate a loss. This is why both layers of protection, statutory and contractual, should operate in parallel.

What should I do if I discover a leak — do I have to send a notice first, or can I impose the penalty immediately?

It depends on how the clause is structured and on the nature of the breach. If the clause provides for a cure period and the breach is objectively remediable, you first send written notice allowing 14 days to remedy it. If the breach is irreversible, the penalty is payable immediately. Regardless of this, if the breach concerns personal data, you are required to report it to the Polish Data Protection Office within 72 hours — the contractual cure period does not postpone this deadline.

POLECANE

mogą Cię zaciekawić

Wybrane przykłady projektów, w których wspieraliśmy firmy w sprawach prawnych — od doradztwa regulacyjnego i compliance, przez projekty technologiczne, po transakcje i bieżącą obsługę biznesu.