Back to the blog

Industry Guidelines in Poland: A Practical Compliance Model for Growing Companies

Understand how Polish industry guidelines affect sales and due diligence, then build a four-step model to identify requirements and address compliance gaps.

Industry Guidelines in Poland: A Practical Compliance Model for Growing Companies

Your sales team is close to signing the largest contract in the company’s history. The enterprise client is ready. Then procurement sends a 40-page security questionnaire and a list of required industry standards. Your CTO reviews it and says, “We don’t have half of this.” The deal stalls for three months-or disappears.

This happens to companies whose growth outpaces their compliance processes. In 2024, 74% of Polish companies experienced a cyberattack. Polish authorities have also imposed substantial penalties: in 2025, the Office of Competition and Consumer Protection (UOKiK) issued decisions totaling PLN 1.15 billion. Meanwhile, companies have had to navigate DORA, NIS2, the EU AI Act, and ongoing GDPR requirements.

For founders and executives operating in Poland, industry guidelines may not be binding law, but they can still determine whether a company wins a major customer, passes due diligence, or secures funding. The practical task is to identify which requirements apply, distinguish legal duties from recommendations and commercial expectations, and build a compliance model that supports growth.

The terms you need to know

Term What it means for your company
Industry guidelines Regulatory recommendations, technical standards, market practices, and customer requirements. They do not always have the force of law, but they can affect sales, investment, and audit outcomes.
Compliance Operating in line with applicable laws, standards, and guidelines-not just in written policies, but in processes and employees’ day-to-day conduct.
Due diligence A legal and financial review by an investor, buyer, or partner before a transaction. It can reveal gaps between claimed and actual compliance.
Vendor risk management A customer’s assessment of the risks of working with a supplier, often through security questionnaires, certification requirements, and reviews of procedures.
ISO 27001 An international standard for information security management and a de facto benchmark in many B2B contracts, particularly with customers subject to DORA or NIS2.
SOC 2 A framework for reporting on controls, commonly requested by US customers and international corporations.

Why industry guidelines can stop a deal

The 2024-2025 regulatory wave

Polish technology companies have faced several major EU measures entering into force or becoming applicable over a similar period. Their relevance depends on the company’s activities and role.

Measure Status and timing described in the approved source Businesses identified in the source
DORA (EU Regulation 2022/2554) In force; applies from January 17, 2025 Banks, payment institutions, investment firms, and ICT service providers to the financial sector
NIS2 (EU Directive 2022/2555) The source states an application date of October 18, 2024, with Polish transposition still in progress and an amendment to Poland’s National Cybersecurity System Act expected by the end of 2025 Approximately 30,000 companies in Poland across sectors including energy, transport, healthcare, digital infrastructure, food, waste, and digital services
EU AI Act (EU Regulation 2024/1689) In force; prohibitions apply from February 2, 2025, and provisions concerning high-risk systems from August 2, 2026 Companies using AI in recruitment, performance assessment, or task allocation
GDPR (EU Regulation 2016/679; known in Poland as RODO) In force since 2018; applies on an ongoing basis Controllers and processors of personal data

These measures raise distinct issues, including ICT risk management, incident reporting, AI literacy, and data protection impact assessments. For a company with 50-200 employees and no dedicated compliance team, the work may be spread across IT, HR, operations, and management.

The financial exposure is real

Polish supervisory authorities do more than issue warnings. The approved source lists the following penalties:

Entity Authority Penalty stated in the source Conduct described in the source
Poczta Polska S.A. UODO PLN 27,000,000 Unlawful processing of data concerning 30 million people from Poland’s PESEL population-register database
ING Bank Śląski S.A. UODO PLN 18,400,000 Routine scanning of identity cards in breach of the data minimization principle
McDonald’s Polska UODO PLN 16,932,657 Failure to assess risk when outsourcing data processing and to supervise the processor
DPD Polska UODO PLN 11,460,000 Missing data processing agreements with carriers and inadequate organizational measures
Glovo (Restaurant Partner Polska) UODO PLN 5,898,064 Unlawful collection of identity-document scans from approximately 3.4 million users
ING Bank Śląski S.A. GIIF PLN 21,659,000 Breach of anti-money laundering (AML) obligations, described in the source as a record penalty

UODO is Poland’s personal data protection authority. GIIF is the General Inspector of Financial Information, which has responsibilities in Poland’s AML system. The source points to UODO’s decisions and the Polish Ministry of Finance’s AML information.

It also states that, by mid-2025, 216 penalty decisions under Poland’s AML Act totaled nearly PLN 48 million. Separately, the EU AI Act provides for penalties of up to EUR 35 million or 7% of global annual turnover for prohibited AI practices. The source includes workplace emotion recognition among the practices prohibited from February 2, 2025.

The practical point is not that every standard in a security questionnaire carries a statutory fine. According to the source, supervisory authorities refer to guidelines, recommendations, and industry standards when assessing due care and determining penalties. Intent is not presented as a prerequisite for liability: authorities look at whether procedures existed, were followed, and reflected what the organization actually did.

Nonbinding does not mean optional in practice

Requirements can acquire force through supervision or contracts even where the underlying guideline is not legislation:

  1. Polish financial supervision. The Polish Financial Supervision Authority (Komisja Nadzoru Finansowego, or KNF) issues recommendations, including Recommendation Z on internal governance. These are not formally statutes. Under KNF’s supervisory review and evaluation process, known as BION, failure to follow recommendations may be treated as a legal and organizational risk. The source identifies potential consequences including administrative penalties, restrictions on activities, demands for changes to governing bodies, and additional capital requirements.

  2. ISO 27001 in supplier selection. ISO 27001 is not, by itself, a general legal requirement. But customers subject to DORA or NIS2 may require it from ICT suppliers. If you supply software to a bank or insurer, lack of certification may cost you the contract.

  3. Enterprise vendor assessments. A corporate customer may require evidence of incident management, data-access controls, and business continuity before procurement can proceed. Incomplete answers can halt a purchase even without a regulator’s involvement.

  4. SOC 2 in international sales. Polish SaaS businesses selling into US markets may be asked for a SOC 2 report as evidence of security controls. For domestic Polish relationships, the source identifies ISO 27001 as the more common benchmark.

The source also describes a more preventive regulatory approach: authorities may examine markets and act on their own findings rather than wait for complaints. Compliance therefore needs to be maintained between inspections, not assembled in response to one.

A useful first step is to classify each requirement by its source and consequence.

Category What it means Examples from the source Potential consequence of a gap
Legal obligation A requirement arising directly from legislation or a regulation; breach may lead to administrative or criminal sanctions GDPR, DORA, EU AI Act, Poland’s AML Act, Polish Labor Code Financial penalties, potential personal liability for management board members, or restrictions on business
Regulatory recommendation Guidance from a supervisory authority that is formally nonbinding but may be used as a benchmark for due care KNF recommendations, UODO guidance, positions of computer security incident response teams (CSIRTs) Adverse supervisory assessment or additional requirements
Market standard or customer requirement A condition set by customers, investors, or auditors rather than a general statutory rule ISO 27001, SOC 2, enterprise security questionnaires Lost contracts, valuation pressure in due diligence, or delayed funding

The distinction guides implementation. Address applicable legal obligations. Assess regulatory recommendations in light of your sector and supervisory exposure. Prioritize market standards according to your customers, sales pipeline, and financing plans.

The categories overlap. The source describes a fintech startup as facing KNF licensing and PSD2 requirements from the outset, despite its smaller scale. It also describes a SaaS supplier to the financial sector as affected by DORA through its role as an ICT provider, even when it is not itself a financial institution. The right starting point is therefore an inventory of what applies to your particular company, on what basis, and with what priority-not an attempt to implement every framework at once.

Build a predictable compliance model in four steps

Step 1: Put the requirements in one inventory

Begin with the five to seven areas most significant to your business. A single working table gives management a clearer view than policies scattered across teams and folders.

Area or process Basis Requirement to check Example status Risk Owner
Personal data protection GDPR-legal obligation Record of processing activities, data processing agreements, data protection impact assessments (DPIAs) Partially compliant High Head of Legal
Information security ISO 27001-market standard Information security management system Not implemented High CTO
Anti-money laundering Polish AML Act-legal obligation where applicable Know-your-customer (KYC) procedures, risk assessment, reporting Compliant Medium Compliance Officer
Digital operational resilience DORA-identified in the source as a legal obligation if the company is an ICT provider to the financial sector ICT risk management, incident reporting Not implemented High CTO
Use of AI EU AI Act-legal obligation where applicable AI literacy, prohibited emotion recognition, assessment of HR-system risks Not determined Medium HR and CTO

Add a reference to the precise requirement and the evidence supporting the status as the inventory develops. The immediate objective is visibility: what is in place, what is missing, and who must act. Without it, management may not see an accumulating problem until a customer review, inspection, or dispute.

Step 2: Test documents against actual practice

An inventory records what should happen. A gap analysis checks what does happen. The source gives examples found in audits:

  • A data protection policy exists but has not been updated for three years and does not cover marketing automation or AI tools.
  • Data processing agreements are in place with major suppliers but missing for 40% of subcontractors.
  • An incident-reporting procedure is written down, but employees do not know whom to notify or by when.
  • Internal working-time rules do not reflect how the company actually works with independent B2B contractors.
  • Sales materials claim ISO 27001 compliance, but the company has completed neither certification nor an internal audit.

Clients and operational teams report that repeated changes affecting data protection, e-commerce, AI, and tax can leave documentation behind operational reality. Staff then rely on judgment rather than a shared procedure.

For a 50-200-person company, the source estimates two to three weeks for a focused gap analysis with law-firm support. That estimate depends on concentrating on priority areas rather than trying to achieve an ideal state immediately.

Step 3: Give management a prioritized remediation plan

Not every gap has the same legal or commercial weight. Present decisions in three groups:

Priority Planning horizon in the source Examples
Critical Implement within 30 days Missing data processing agreements with suppliers; no incident-reporting procedure; use of prohibited AI practices such as emotion recognition in HR
Important Schedule within 90 days Update the data protection policy; introduce AI literacy procedures; review B2B contracts against DORA-related requirements
Improvement Implement in stages ISO 27001 certification; a one-page compliance brief for sales; recurring compliance reviews

This format helps management allocate resources, set an order of work, and decide when external legal input is needed. Without priorities, teams may launch too many projects at once or create elaborate procedures that nobody follows.

Step 4: Name owners and establish recurring reviews

In a multi-team business, compliance, operations, sales, IT, and HR may all touch the same requirement. Give each area a named individual, not just a department, responsible for keeping documents current, monitoring relevant changes, and escalating risks.

Then:

  1. Set a review cycle, such as quarterly reporting on compliance status, new guidance or interpretations, and identified risks.
  2. Train operational teams on changes to their work, rather than asking everyone to study every guideline.
  3. Put an owner and last-review date on each compliance document, including policies, internal instructions, and procedures.
  4. Check that the document reflects practice, rather than retaining a generic template that no longer describes the business.

The source points to the organizational elements in the GDPR’s binding corporate rules (BCR) framework under Article 47-audits, corrective mechanisms, change-reporting procedures, staff training, and designated monitoring responsibility-as a model that can be adapted for managing other industry requirements.

Match the approach to your company’s stage

The right operating model changes as a business grows.

Aspect Startup Scaleup Larger corporation
Typical ownership Founder and accountant, with external legal support where needed Head of Legal or Compliance Officer, often a newly created role Dedicated compliance function, data protection officer (DPO), and risk team
Requirements highlighted in the source GDPR, employment law, intellectual property, and tax; for fintech, PSD2 and AML from the outset Earlier requirements plus ISO 27001, DORA where relevant to ICT supply, NIS2, the EU AI Act, and ESG/CSRD (the source refers to a 250-employee threshold) Sector-specific rules, BCR, nonfinancial reporting, and supply-chain risk management
Typical weakness Processes exist mainly in people’s heads Documents are dispersed or outdated and differ from practice Formal procedures become too heavy and slow decisions
Priority Secure the essentials: contracts, IP, GDPR, and the employment model Run a gap analysis, appoint owners, and establish reviews Improve integration, automation, and continuous compliance

If a scaleup is preparing for investment, due diligence may expose discrepancies between its statements and its operations. Outdated documents and unclear ownership can affect valuation or delay a transaction.

The source gives two to four weeks as an estimate for moving from disorder to a predictable initial model when work is tightly prioritized and supported by a law firm. That is not the same as completing every remediation item. Elsewhere, the source estimates two to three months for fuller work covering document updates, owners, and a functioning review cycle.

Prepare a one-page compliance brief for sales

A short, accurate compliance brief can help your team respond to enterprise procurement without rebuilding the same answers for every prospective customer. It should state:

  1. Which applicable requirements and industry standards the company meets, such as GDPR-related requirements, ISO 27001, or relevant EU AI Act requirements.
  2. How compliance is managed: review cadence, process ownership, and incident-reporting arrangements.
  3. Who owns each area, with a name, role, and contact point.
  4. Which audits or certifications the company has actually completed, with dates.

Use it in enterprise sales to answer security questionnaires, in due diligence to show how responsibilities are organized, and in partnerships or tenders as supporting material. Keep claims precise: an internal control, an audit, and a certification are not interchangeable.

How we support companies operating in Poland

Organizing industry-guideline compliance does not necessarily require a large in-house department. It does require a clear diagnosis of the applicable requirements, the gaps between documents and practice, and the order in which those gaps should be closed.

We work with founders, COOs, and legal teams in SaaS, fintech, and e-commerce. Our support can include:

  • A requirements inventory distinguishing legislation, supervisory expectations, and customer or market requirements.
  • A gap analysis comparing documentation with how the business actually operates.
  • A prioritized remediation plan that gives management decisions to make, rather than only a long legal memorandum.
  • Compliance documentation-including policies, internal procedures, data processing agreements, and incident-reporting processes-aligned with the company’s operating model.
  • Named process owners and recurring reviews so compliance does not end when an initial project closes.
  • A one-page compliance brief for enterprise sales, investment processes, or due diligence.

If you need to map requirements, assess gaps, or prepare a Polish business for due diligence, contact us.

Frequently asked questions

How can I identify the requirements that apply to my company?

Start with three questions. First, what sector do you operate in and which Polish authority supervises relevant activities? For example, KNF is relevant to financial-sector activity, while UODO is the Polish personal data protection authority. Second, who are your customers? Selling ICT services to the financial sector can bring DORA-related requirements into the supplier relationship. Third, what do customers require in their contracts and security questionnaires?

Use the answers to build an initial requirements map. Seek advice where your role, regulatory status, or customer obligations are unclear.

Can a nonbinding guideline really block sales or investment?

Yes. A customer can make security evidence or certification a procurement condition. Missing ISO 27001 certification, outdated data protection documents, or no incident-reporting procedure may stall a deal if the customer requires them. Investors and buyers also compare compliance statements with documents and actual processes. Gaps can prolong due diligence, affect valuation, or block a transaction.

How long does it take for a company with 50-200 employees to get organized?

The source’s planning estimates are two to three weeks for a focused inventory and gap analysis with law-firm support, followed by roughly another week for a prioritized plan. It places critical changes in a 30-day implementation category and estimates two to three months for fuller organization, including document updates, named owners, and recurring reviews. The scope and starting position will determine the actual timetable.

Can we implement changes in stages?

Yes. The recommended approach is to separate critical gaps, which the source says to address within 30 days, from important work to schedule within 90 days and longer-term improvements to implement in stages. Put issues that expose the company to sanctions or block active sales first. Then address audit readiness, valuation concerns, and measures that build longer-term credibility.

Who should monitor requirements if we have no compliance department?

Appoint a named owner for each area. In a 50-200-person company, the source suggests the CTO for information security and technical requirements; the Head of Legal or COO for GDPR and contracts; the HR Manager for employment and HR-related AI issues; and the CFO for AML and tax. The relevant mix depends on the business. Owners can report during quarterly reviews, with an external law firm providing ongoing support where there is no in-house legal lead.

What will auditors or investors check during due diligence?

They commonly look for a mapped set of applicable requirements; current policies, procedures, and agreements; evidence that employees follow those documents; clear ownership; any completed audits or certifications, including ISO 27001 or SOC 2 where relevant; and a process for periodic review. A recurring concern is the gap between what the company claims and what its records and day-to-day practices demonstrate.

Industry guidelines are not simply a checklist for a future audit. In Poland-facing operations, they can shape regulatory exposure, customer procurement, and investment outcomes. Start by mapping what matters to your business now, test it against practice, prioritize the gaps, and make someone accountable for keeping the model current.

RECOMMENDED

this could be interesting to you

Real work, real outcomes - compliance, technology, transactions, and the everyday legal support businesses run on.