Confidentiality clauses under Polish law: which concessions weaken your protection?
You are negotiating a consulting, investment, or IT agreement governed by Polish law. The other party returns a draft with two proposed changes to the confidentiality clause:
- Only documents expressly marked “confidential” will be protected.
- No contractual penalty will be payable if a breach was unintentional and the party remedies it within a specified period.
Both proposals sound reasonable, and both are legally permissible. But the first can strip valuable information of contractual protection. The second, if reframed around whether the breach can actually be remedied, can strengthen your position in a dispute.
This article explains how to evaluate those concessions, structure a contractual penalty for breach of confidentiality, and use a cure period without giving the other party time to “fix” a disclosure that cannot be undone. A checklist at the end will help you review your own agreement.
Polish-law concepts to know
| Concept | What it means for your agreement |
|---|---|
| Contractual penalty (Article 483 of the Polish Civil Code) | An agreed amount payable for breach of a nonmonetary obligation, such as a duty not to disclose confidential information. It is payable regardless of whether loss occurred. |
| Judicial reduction of a penalty (Article 484 § 2 of the Civil Code) | A court may reduce a penalty if it is grossly excessive or the obligation has been performed to a significant extent. Reduction does not mean setting the penalty aside. |
| Trade secret (Article 11(2) of the Polish Act on Combating Unfair Competition) | Information with commercial value that is not publicly available and has been subject to measures intended to preserve its confidentiality. Documents do not have to be marked. |
| Cure period | An agreed period for remedying the effects of a breach before a penalty becomes due. It is a contractual mechanism, not a separate institution under the Polish Civil Code. |
| Damages exceeding the penalty (Article 484 § 1, second sentence, of the Civil Code) | The right to claim compensation above the agreed penalty—but only if the agreement expressly reserves that right. |
These distinctions matter because statutory trade-secret protection and a contractual right to a penalty are not the same thing.
Why an “expressly marked confidential” requirement is a trap
What the proposed change appears to achieve
The other party suggests defining confidential information as only materials expressly marked as confidential. Its stated concern may be understandable: it does not want ordinary conversations later characterized as confidential disclosures.
But in consulting, transactions, and IT projects, valuable information often never appears in a marked document. Think of:
- An investor list provided by phone
- A transaction price discussed in a meeting
- An explanation in a messaging app of why an investor withdrew
- Commercial terms discussed by video
- Technical know-how explained orally to a developer
Under a closed definition limited to marked materials, those disclosures fall outside the contractual confidentiality protection, even if they are among the project’s most valuable information.
What Polish trade-secret law does—and does not—require
Article 11(2) of the Act on Combating Unfair Competition (consolidated text, Journal of Laws 2026, item 85) does not make a confidentiality marking a condition of protection. It looks to commercial value, nonpublic character, and measures taken to preserve confidentiality. Courts, including in cases XXIII Zs 24/23 and XXIII Zs 177/24, apply that three-part test without making protection depend on the form in which information was recorded.
An oral disclosure may therefore still qualify for statutory protection under the Act. That does not rescue a contractual-penalty claim if your agreement’s closed definition excludes unmarked information. Agreeing to the marking requirement can leave you with less contractual protection than the statutory trade-secret rules may provide.
Offer exclusions instead
A better response to concerns about an overbroad clause is to define confidential information broadly, then exclude information that:
| Exclusion | Why it matters |
|---|---|
| Is publicly available | You do not claim protection for information already public. |
| Was known to the recipient before disclosure | You do not restrict knowledge the recipient already had. |
| Was independently developed | You do not prevent the other party’s own work. |
| Is disclosed at an authority’s request | You do not obstruct compliance with a legal obligation. |
This addresses the counterparty’s concern without leaving oral or indirect disclosures unprotected. You can also list illustrative categories—financial data, commercial terms, technical know-how, and counterparty lists—while making clear that the list is not exhaustive.
When a cure period helps—and when it disables the clause
Avoid making intent the dividing line
The proposed wording—no penalty if the breach was unintentional and remedied on time—moves a dispute toward the breaching party’s state of mind. The parties may then argue over whether someone knew a file was confidential, whether an employee sent it accidentally, or whether disclosure was intended. Proving intent can be difficult in practice.
Instead, ask an observable question: can the effects of this breach objectively be remedied?
| Type of breach | Example | Treatment |
|---|---|---|
| Remediable | An employee sends a financial model to the wrong address within the organization; access can be withdrawn and copies deleted. | Allow a 14-day cure period after notice. |
| Irreversible | An investor list is given to a competitor; the recipient already has the information. | The penalty becomes due immediately, without a notice to cure. |
Whether a breach is remediable depends on its effects, not on the breaching party’s account of its intentions.
Example clause
The following wording makes a cure period relevant only to objectively remediable breaches:
If a breach of the confidentiality obligations under the Agreement can objectively be remedied, the Entitled Party shall, before imposing a contractual penalty, give the Breaching Party written notice requiring it to remedy the breach within 14 (fourteen) days after receipt of the notice. The contractual penalty shall become payable only if the Breaching Party fails to remedy the breach within that period.
The mechanism does not change the amount of the penalty. For a remediable breach, it changes when the penalty becomes due. An irreversible breach should not be made to wait through a period in which no remedy is possible.
Written notice also creates a record of the breach and the opportunity to cure. If the other party does not remedy an objectively remediable breach after receiving notice, that history may help defend the penalty against a request for judicial reduction. An automatic penalty for a minor incident corrected the same day presents a more obvious target.
Under Article 484 § 2 of the Civil Code, a court may reduce a grossly excessive penalty. Courts consider proportionality, including the protected interest, seriousness of the breach, and its consequences; see the Szczecin Court of Appeal, I ACa 221/18. A cure period is therefore not necessarily a concession that weakens protection. Properly limited, it can put the penalty on stronger footing when it is imposed.
Five more provisions to check
1. Can you claim damages above the penalty?
Article 484 § 1, second sentence, of the Civil Code (consolidated text) allows damages exceeding the contractual penalty only if the agreement expressly provides for them. Without that reservation, you cannot claim the excess even if actual loss is much greater than the agreed penalty.
Look for wording along the lines of: The entitled party may claim damages exceeding the contractual penalty. If it is missing, add it.
2. Is there an aggregate cap?
A penalty for each breach, with no overall cap, can produce a very large total when events repeat. Courts consider the aggregate penalties in relation to the value of the agreement; see the Szczecin Court of Appeal, I AGa 320/20.
Consider whether an aggregate cap would help the provision withstand a claim that the total is grossly excessive—particularly if the penalty is tens of thousands of Polish zlotys per incident and repeated breaches are possible.
3. Is the recipient responsible for its people?
Protection can break down at the first subcontractor if the recipient is not responsible for people to whom it discloses the information. Make the recipient liable for the acts and omissions of its employees, advisers, and subcontractors as for its own.
4. How long does confidentiality continue after the contract ends?
Five years is a transactional standard, but there is no single correct period. Directive 2016/943 does not set a maximum term for contractual confidentiality. Statutory protection under Article 11 of the Act on Combating Unfair Competition continues while its conditions are met.
Match the contractual period to the information:
| Information | Suggested approach |
|---|---|
| Technical know-how, such as algorithms or system architecture | Consider a longer period; value may persist for years. |
| Commercial information, such as price lists and terms | Consider a shorter period; it may become outdated sooner. |
| Transaction information, such as valuations and funding-round terms | Consider the transaction cycle. |
5. Does the agreement also permit publicity?
Check provisions allowing either party to name the business relationship or use logos in marketing. Strict confidentiality in one provision and broad permission to provide references in another can create an inconsistency that weakens both in a dispute.
A GDPR reporting deadline is separate from the cure period
One disclosure—for example, a customer list—may breach both the agreement and the GDPR. Article 33(1) of the GDPR requires a qualifying personal data breach to be reported to the President of Poland’s Personal Data Protection Office (UODO) without undue delay and, where feasible, no later than 72 hours after becoming aware of it. The period includes nonworking days; see UODO’s breach-reporting guidance.
A contractual 14-day cure period does not postpone or suspend that obligation. Nor does a contractual penalty replace an administrative fine, or vice versa.
If the agreement involves personal data, distinguish clearly between:
- The processor’s obligation to notify the controller without undue delay under Article 33(2) of the GDPR
- The controller’s statutory 72-hour period for reporting to UODO
- The contractual 14-day cure period, which concerns only when the contractual penalty becomes due
Document the breach and deliver the notice properly
A cure mechanism is useful only if you can show both that the breach occurred and that your notice reached the recipient.
| Delivery method | Evidentiary strength | Point to check |
|---|---|---|
| Poland’s e-Delivery system, from an electronic delivery address | Strongest | Under Article 42 of the Electronic Delivery Act (consolidated text), it has an effect corresponding to registered mail with acknowledgment of receipt. |
| Registered mail with acknowledgment of receipt | Strong | A standard method, though refusal to accept delivery can create difficulties. |
| Email with delivery confirmation and a reply from the recipient | Moderate | It meets the Civil Code’s documentary-form requirement under Article 77², but not written-form requirements without a qualified electronic signature. |
| Sending an email, without more | Weakest | Sending alone does not establish that it reached the recipient. |
A notice to cure should identify:
- The contractual provision breached
- The event and date of breach
- The evidence, or where it can be found
- The contractual penalty amount
- The deadline to remedy the breach—14 days from receipt in the example clause
- The consequence of failing to remedy it on time
Do not assume that an agreement’s requirement for notice “in writing” permits an ordinary email. Polish law distinguishes written form from documentary form, and the particular contract must be interpreted. If you intend to give notice by email, ensure the agreement allows it.
Employees and B2B contractors: different liability rules
The route for holding a team member responsible depends on whether that person is an employee or a genuinely independent business-to-business (B2B) contractor.
| Issue | Employment | B2B contract |
|---|---|---|
| Basis of confidentiality duty | Article 100 § 2(4)–(5) of the Polish Labor Code | Contractual clause |
| Contractual penalty for breach of confidentiality | Permissible within a post-employment non-compete agreement (Supreme Court, II PK 327/10); during employment, employee financial-liability rules restrict its use | Permissible under Articles 483–484 of the Civil Code |
| Liability limit | Unintentional fault: up to three months’ remuneration under Article 119 of the Labor Code; intentional fault: full liability under Article 122 | No statutory cap, but the court may reduce a penalty under Article 484 § 2 of the Civil Code |
| Key risk | Labor Code restrictions may prevent enforcement of a high penalty | A B2B clause may be challenged if the relationship has the characteristics of employment under Article 22 § 1 of the Labor Code |
A confidentiality penalty for a B2B contractor is not subject to the Labor Code liability limits—provided the arrangement is genuinely B2B rather than employment in substance.
Adapting an English-language template for Polish law
IT and investment agreements often start with an English-language template. Terms such as cure period and liquidated damages do not, by themselves, identify the Polish-law mechanism the parties intend. Using English terminology without choosing a governing law also does not select English law; see the Rome I Regulation.
If Polish law is to govern, adapt the clause functionally:
- Specify the governing law under Article 3 of the Rome I Regulation.
- Define confidential information by reference to the Act on Combating Unfair Competition or through a tailored definition with exclusions.
- Identify the sanction as a contractual penalty under Article 483 of the Civil Code, rather than relying on the label “liquidated damages.”
- State the amount or an objective method for calculating it.
- Distinguish remediable breaches from irreversible disclosures.
- Say whether the cure period affects when the penalty becomes due or is instead a prerequisite for terminating the agreement.
If every penalty depends on an unsuccessful cure period, with no exception for irreversible disclosure, the clause may prevent recovery for precisely the disclosure you most need to address. The Polish Supreme Court considered a PLN 100,000 confidentiality penalty in IV CSK 443/18 without questioning the mechanism itself; the clause in that case had been adapted to Polish law.
Checklist: review your confidentiality clause
If you answer “no” or “I don’t know” to any question, review that part of the agreement.
| # | Question | Why it matters |
|---|---|---|
| 1 | Does the definition cover information disclosed orally? | A marked-materials-only definition leaves oral disclosures outside contractual protection. |
| 2 | Are sensible exclusions used instead of a marking requirement? | Exclusions address overbreadth without hollowing out the clause. |
| 3 | Is any cure period based on objective remediability? | A test based on whether a breach was unintentional is difficult to apply in a dispute. |
| 4 | Do irreversible breaches trigger the penalty immediately? | Disclosure to a competitor should not wait through a period in which no cure is possible. |
| 5 | Is the right to claim damages above the penalty expressly reserved? | Without express wording, Article 484 § 1 of the Civil Code bars a claim for the excess. |
| 6 | Is an aggregate cap appropriate for per-breach penalties? | Repeated penalties without a cap risk being challenged as grossly excessive. |
| 7 | Is the recipient responsible for people to whom it discloses information? | The chain of protection should include employees, advisers, and subcontractors. |
| 8 | Does the post-termination period fit the information? | Five years may be too short for some technical know-how. |
| 9 | Is the confidentiality clause consistent with publicity and logo-use rights? | Conflicting permissions can weaken both provisions. |
| 10 | Are the notice form and permitted delivery methods consistent? | An email may not satisfy a requirement for notice “in writing.” |
| 11 | For personal data, are the GDPR reporting period and contractual cure period kept separate? | Fourteen contractual days do not extend the applicable 72-hour reporting period. |
| 12 | Is the penalty proportionate to the protected interest? | Too high invites reduction; too low may not deter breach. |
Bring consistency to your agreements
Confidentiality penalties are frequently negotiated in consulting, IT, and transaction documents—and frequently carried over from templates without enough attention to what they actually cover. The problem may not become visible until information has been disclosed.
If your business uses several templates or negotiates with different counterparties, review whether they define confidential information consistently, preserve claims above the penalty, handle reversible and irreversible breaches separately, and extend responsibility through subcontractors. Agree in advance which concessions your negotiators can make and which would undermine the protection you need.
We help businesses audit their confidentiality and contractual-penalty provisions, revise cure mechanisms and exclusions, and set practical negotiation rules. Contact us.
Frequently asked questions
Why reject a definition limited to marked documents?
It can exclude an investor list shared by phone, terms discussed in a meeting, or know-how explained to a developer. Polish trade-secret protection does not require a document to be marked, but a closed contractual definition may still exclude unmarked information from your penalty claim. Offer exclusions for public, previously known, independently developed, and authority-requested disclosures instead.
Does a 14-day cure period give the other party one breach without consequences?
Not if it applies only where the effects can objectively be remedied. An irreversible disclosure should trigger the penalty immediately. For a remediable breach, an unsuccessful notice to cure creates a stronger record than an automatic penalty for an incident corrected the same day.
Can a Polish court reduce a penalty the parties negotiated?
Yes. Under Article 484 § 2 of the Civil Code, a court may reduce a penalty that is grossly excessive or where the obligation was performed to a significant extent. An uncapped total from repeated per-breach penalties is particularly exposed to that argument.
How do I tell whether a breach is remediable?
Ask whether its effects can be reversed. Access to a file sent to the wrong internal address may be withdrawn and copies deleted. Information given to a competitor cannot necessarily be taken back. A court may assess the facts if the parties dispute the classification.
Isn’t statutory trade-secret protection enough without a clause?
Article 11 of the Act on Combating Unfair Competition may protect information with commercial value that is not public and has been subject to confidentiality measures. But a contractual penalty provides a separate route that does not depend on proving loss. The statutory and contractual layers should operate alongside each other.
If I discover a leak, must I send a notice before claiming the penalty?
That depends on the agreed clause and whether the breach is objectively remediable. Under the example mechanism, a remediable breach requires written notice and 14 days to cure; an irreversible breach triggers the penalty immediately. If personal data is involved, assess the separate GDPR notification duties at once—the contractual cure period does not extend them.