Back to insights
Legal updates

Polish legislation on the collection of data by services incompatible with the Constitution and Union law

The Ombudsman stresses that data collection should be limited to combating major crimes and be controlled by an independent body; the citizen should learn that he has been so watched.

The Ombudsman stresses that data collection should be limited to combating major crimes and be controlled by an independent body; the citizen should learn that he has been so watched.

The Ombudsman stresses that data collection should be limited to combating major crimes and be controlled by an independent body; the citizen should learn that he has been so watched.

However, today the courts actually check this post fact on the basis of general reports of the services – as a result they cannot reliably assess the legitimacy, relevance and purpose of these actions.

In the opinion of the Ministry of Foreign Affairs, the current rules do not prejudice the requirement of proportionality of interference in the right to privacy, freedom of communication and information autonomy The limitation of access to telecommunications data will undoubtedly make it much harder to detect perpetrators of crime - the ministry emphasises.

Following the judgment of the Court of Justice of the European Union 2 March 2021 (case C-746/18 The Ombudsman asked Prime Minister Mateusz Morawiecki to initiate appropriate legislative changes. It is about balancing the need to protect the security of citizens and their right to privacy.

The RPO has long monitored the collection and use of telecommunications data by the police and services, including calls and location of citizens' mobile phones. State security requirements do not mean that such surveillance is not to be subject to restrictions arising from constitutional rights and freedoms. In this respect, the entity has very limited means of direct legal protection.

This is indicated by the latest judgment of the Court of Justice of the European Union 2 March 2021 issued on C-746/18 D.A.'s office.

Judgment of the EU TS

The EU Court ruled that Article 15(1) Directive 2002/58 to 12 July 2002 privacy and electronic communications, and Article 52(1) The EU Charter of Fundamental Rights should be interpreted as opposing national rules allowing public authorities to access a set of traffic data or location data that can provide information on the connections of the user of an electronic communications device or on the location of the terminal device used by him and to draw precise conclusions on his private life, for the purpose of preventing, investigating, detecting and punishing crimes - without limiting such access to proceedings aimed at combating serious crime or preventing serious threats to public security, regardless of the length of time for which access to and the number and type of data has been requested.

TS recalled that Article 15(1) Directive on privacy and electronic communications in relation to Article 7(8)(11) and Article 52(1) The NPP is hindered by legislative measures providing for the prevention of generalised and non-differentiated retention of traffic and location data for these purposes. Only the fight against serious crime and the prevention of serious threats to public security can justify serious interference in the right to respect for private and family life and the right to the protection of personal data, such as those related to the retention of traffic and location data, which can provide information on the connections made by the user of an electronic communications means or on the location of the terminal equipment used by him and allow for precise conclusions on private life.

In any event, interference in these rights is serious, regardless of the length of time it is requested to access these data. In any event, the proportionality requirement should be met and derogations from respect for privacy or personal data should be limited to what is strictly necessary for the purpose of the investigation," the TS stressed.

Polish legislation - contrary to the Constitution and EU law

The Ombudsman points out that Polish law does not meet the requirements of EU law as reflected in this judgment of the TS EU. Adopted 15 January 2016 The amendment to the Police Act gave the services the right to obtain and process telecommunications, Internet and postal data without the knowledge and consent of the person concerned. This right was granted to prevent or detect crimes either to save lives or human health or to support search and rescue activities.

This law does not meet the criteria justifying the limitation of civil rights and freedoms under the Constitution. This calls into question the compatibility of the law with Article 2(30)(47)(49)(51)(2) Constitution in conjunction with Article 31(3) and Article 8 ECHR and Article 7(8) in conjunction with Article 52(1) EU NPP.

The list of offences in which the data may be obtained and processed by individual services is too wide, indicating that the limits in question are exceeded under Article 31(3) the Constitution, Article 8(2) ECHR and Article 52(1) EU NPP.

No specific types of prohibited acts were identified to justify such data on citizens, but the general term "crimes" was used. This means that data may be obtained in respect of all acts which fulfil the characteristics of any crime, including those pursued on application or from a private accusation.

It is excessive interference in the right to privacy and the right to the protection of personal data, as well as in breach of the principle of information autonomy, expressed Under Articles 47, 49 and 51(2) The Constitution, which also violates the principle of human dignity (Article 30 Constitution).

This gives the services the opportunity to obtain data in proceedings concerning more indefinite criminal offences, regardless of their social harm. This opens up the possibility of using telecommunications, postal and internet data not only when it is actually necessary to detect or prevent crime, but also when it is simply the simplest and most convenient.

The European Court of Human Rights (ECHR) and the EU TS pointed out the need for precise regulation of the scope of offences in which such data can be accessed. The provisions of the Act are therefore also incompatible with Article 8 ECHR and 7 and 8 in conjunction with Article 52(2) EU NPP.

Adam Bodnar stresses that the wide range of information to which the services have access allows for a wide and precise reconstruction of various aspects of private life. It can also lead to building the personal profile of those involved in the communication process, and thus to determining their lifestyle, belonging to social or political organizations, personal preferences or tendencies of those subject to observation.

This is confirmed by the findings of the Supreme Audit Office’s audit “Accession and processing of phone records, location information and other data by authorised entities under Article 180c and d Telecommunications Law Act’.

According to the NIC, these provisions do not sufficiently protect civil rights and freedoms from excessive interference by the state. The system for collecting information on the extent to which phone records, location information and other data are used does not allow to determine the actual number of checks.

There are also no external control mechanisms that would allow verification of the scope of use of telecommunications data by authorised entities, in particular the appropriateness of their acquisition and processing.

Judgment of the Constitutional Tribunal of 2014 and its consequences

The RPO initiated proceedings before the Constitutional Court in case K 23/11. In the judgment of 30 July 2014 The CCC stated the unconstitutionality of some of the contested provisions, which would lead to a system of data processing based on a constitutional standard of privacy protection. Unfortunately, the legislator did not fulfill these hopes. Implementing the judgment of the amendment from 5 January 2016 significantly broadened the possibility of services interfering with citizens' privacy.

The revised rules not only fail to implement the judgment of the Constitutional Tribunal, but seriously violate constitutional rights and human freedoms and international standards. Services have e.g. accessed online data through a fixed link. The collection of this data does not necessarily involve any ongoing conduct. Services no longer have to submit written requests to Internet service providers as before and show for the purposes of the procedures they need.

This means that this data can be collected not only if it is actually necessary to detect or prevent the most serious offences that cannot otherwise be countered (as indicated by standards resulting from the Constitution and European law), but also when it is simply convenient for the services. This represents a risk of serious abuse. On this basis, services can, for example, accurately reproduce different aspects of the private life of a citizen, collect data on lifestyles, views, tastes or inclinations.

Another allegation regarding the amendment is the disproportionately long duration of operational control - to 18 months. In addition, the revised rules limited the legal secrecy of the public trust professions, including lawyers, legal advisers, doctors and journalists. Secrets obtained during surveillance can be used in criminal proceedings when "this is necessary for the sake of the justice system and this cannot be determined on the basis of other evidence".

June 2016 The Venice Commission considered that the amendment gives the services too broad powers that may affect citizens' right to privacy.

She assessed, among other things, that the access of services to the most sensitive telecommunications and internet data should require prior approval of the court; supervision of the collection of less sensitive data should be exercised by an independent body and the body should be informed of their collection; the system of submission of general reports by the services to courts will not be effective.

The Venice Commission recommended, among other things, that the acquisition of the most important telecommunications and online data be limited to the most dangerous situations; that the retention of data be reduced and that legal confidentiality be safeguarded.

Polish solutions are incompatible with the TEU judgment, which stressed that the Privacy and Electronic Communications Directive precludes legislative measures imposing on electronic communications service providers the obligation to prevent, generalised and non-differentiated retention of traffic and location data.

They are also incompatible with that Directive in so far as they allow the use of such data in all proceedings, and not only in proceedings aimed at combating serious crime or preventing serious threats to public safety.

Only the latter can justify access by public authorities to a set of data which allows for precise conclusions on the private life of data subjects.

Insufficient control of service activities

The current form of control is insufficient. Follow-up checks should not be used by default but may only be permitted exceptionally in situations where immediate action is needed by the services. The provisions do not provide for prior checks.

The data could be properly evaluated for the fulfilment of the criteria of necessity, adequacy and purpose. According to Article 51(2) The Constitution of the Republic of Poland, public authorities cannot obtain, collect and make available information on citizens other than necessary in a democratic legal state.

The current form of control does not guarantee that these rules are actually respected.

No control shall be carried out on the basis of data obtained from Article 20cb(1) Police Act. The Police Act and, by analogy, other laws from any control therefore exclude the collection of data not only specified under Article 179(9) Telecommunications rights, but also the whole Article 161 Telecommunications rights, which significantly extends access to data excluded from any control. This article of the Telecommunications Law refers to more indeterminate ‘other data’.

The EU Court of Justice indicated that the directive precludes national rules granting the prosecution the task of directing preparatory proceedings and acting as public prosecutor in the course of subsequent proceedings - the competence to authorise a public authority to access traffic and location data for the purposes of the investigation.

It is important that the prior review court has all the powers and guarantees necessary to reconcile the individual interests and rights involved.

In the preparatory procedure, such review requires that the court be able to ensure an appropriate balance between the interests related to the need to investigate crime and fundamental rights to respect for private life and the protection of personal data of persons whose data are made available.

However, Polish regulations do not provide for a real control of the collection of citizens' data. The district court has the right to review, but only on the basis of general, collective six-monthly reports of services. The court doesn't have to, but it can only verify that the data has been downloaded correctly.

After inspection, the court may only inform the service concerned of its results, but may not order, for example, the destruction of the collected data or other corrective actions. In practice, this review of the courts is illusory. Secret reports of the services are not public information, although they contain information on the number of telecommunication, postal or online data collected and the legal qualifications of the acts for which they were requested.

„Fruit of poisoned tree’

It is also apparent from the judgment of the TEU that information and evidence obtained in breach of Union law must be excluded. This poses a threat to the principle of adversariality and thus the right to a fair trial.

Meanwhile Article 168a In fact, the Code of Criminal Procedure encourages state services to obtain evidence by committing crimes and breach of procedures, ensuring that they can be used in criminal proceedings. In fact, it invalidates all - and so remains - mechanisms of control over obtaining data about citizens.

It is therefore necessary to provide that evidence collected in violation of law, whether national or Union, cannot be used. They should be eliminated from the evidence underlying the outcome. An urgent amendment should therefore be proposed.  Article 168a k.p.k., restoring its content before the amendment from 2016 In the current version, this provision is manifest and, of course, unconstitutional.

  • A grim testimony about Poland is the maintenance of regulations that encourage state authorities to break the law and ensure that illegal actions will be sanctioned in the criminal trial," said Adam Bodnar.

Reply by Maciej Wąsik, Secretary of State at the Ministry of Foreign Affairs

At the outset, it should be pointed out that Act dated 15 January 2016 amending the Law on the Police and certain other laws, hereinafter referred to as ‘the Amending Act’, aimed at implementing the Constitutional Court (CC) judgment dated 30 July 2014, reference no. K 23/11, concerning the conduct by the uniformed services, special services and competent operational control authorities and the receipt and processing of telecommunications data by the designated entities.

In that judgment, the Constitutional Tribunal stated that Article 20c(1) Act dated 6 April 1990 about the Police and Article 10b(1) Act dated 12 October 1990 o Border Guards by not providing for independent control of the provision of telecommunications data referred to under Article 180c and Article 180d Act dated 16 July 2004 Telecommunications law is incompatible with Article 47 and Article 49 with regard to Article 31(3) Constitution of the Republic of Poland.

In the assessment of the CCC one the requirements to be met by the laws authorising the collection of telecommunications data are the creation of an independent control mechanism.

However, the CCC does not indicate what the procedure for access to telecommunications data is to look like, in particular whether it is necessary for each type of data retained to be authorised to be made available. Not all information causes the same intensity of interference in freedom and human rights.

According to the CCC, it is therefore not excluded, as regards the provision of telecommunications data in the course of operational and investigative activities, to introduce, as a rule, a follow-up control.

Under the revised rules Article 20c(1) Police Act and Article 10b(1) Whereas the Border Guard Laws are entitled to obtain so-called metadata to prevent or detect crimes and tax offences, Police also to save lives or human health or support search and rescue activities. It should also be noted that this data may only be obtained to the extent necessary to carry out the statutory tasks of the designated formations, with a list of prohibited acts for which the Border Guard has been authorised to recognise, prevent and detect, determine, Article 1(2)(4) and section 2a The Border Guard Act.

On the other hand, referring to the judgment of the Court of Justice of the European Union (TSEU) cited in his speech dated 2 March 2021 on C-746/18 (The case of the Prosecution) and the reservation concerning the use by the legislator in the Law on the Police and Border Guards for the general definition of the offence should be noted that, in accordance with the above-mentioned ruling of the TEU, access by public authorities to a set of traffic or location data which may provide information on the connections made by the user or on the location of the device used by him and allow for precise conclusions on his private life, for the purposes of prevention, investigation, detection and prosecution of crimes, should be limited to proceedings aimed at combating serious crime or preventing serious threats to public security.

It should be indicated that the CSF has not defined exhaustive a catalogue of offences, for the prevention and detection of which state institutions may obtain telecommunications data. Nor has the very concept of serious crime been defined.

In the Polish legal system, the division of prohibited acts into serious offences and other offences was adopted.

This distinction also relates, inter alia, to the assessment of the harmfulness of a particular category of acts and their universality, which consequently translates into a differentiation of the type of sanctions envisaged for offences and offences and their severity.

It is clear from the provisions of the Pragmatic Services Act that they do not have the power to obtain so-called metadata for the purpose of conducting infringement proceedings.

The above appears to justify the conclusion that, when introducing the division of prohibited offences into offences, the legislator has determined which of them are serious and which do not belong to that category.

As a result, both Article 20c Police Act, as well as Article 10b The Border Guard Act does not prejudice, in the scope under consideration, the requirement of proportionality of interference in the right to privacy, freedom of communication and the right to information autonomy.

At the same time, I would like to point out that the lack of a strong and effective response by public authorities to criminal acts can lead to a sense of impunity for their perpetrators.

Furthermore, when considering the possible narrowing of the directory of offences for which telecommunications data could be obtained, it should be borne in mind that, given the universality of the mobile communication tool, the restriction of access to telecommunications data for services will undoubtedly lead to a significant obstacle to the detection of offenders.

In particular, where a prohibited act is committed by electronic means.

It should also be clarified that the powers of services under the law of pragmatic law under the Minister competent for Home Affairs do not oblige telecommunications service providers to provide unlimited and mass data.

There is also no possibility and basis for any search by the services of telecommunications business databases and electronic service providers. The access of authorised entities to this data is targeted as it takes place upon request, in relation to the individualisation of a particular person, place or device.

It needs to be stressed that, in order to prevent crimes, services are obliged to take swift and decisive action.

In such situations, often the only effective solution, which will provide at the very beginning of the investigation process numerous information necessary for further action, including identifying the circle of persons involved in the crime, will be to obtain telecommunications data.

The mode by which the telecommunications operator, postal operator or service provider provides electronic data services shall determine Article 20c(2) Police Act and Article 10b(2) The Border Guard Act. In accordance with the provisions cited above, the entities concerned shall make the data available:

an officer indicated in the written application, respectively, in the case of the Police: Chief of the Main Police, Chief of the CBŚP, Chief of the BSWP, Chief of the Provincial Police or a person authorised by them, and in the case of the Border Guard - Chief of the BSWSG or Head of the Border Guard Branch or a person authorised by them;

at the oral request of an officer with written authorisation of the persons concerned Under point 1;

via a telecommunications network to an officer with written authorisation of the persons concerned Under point 1.

Clarification of the regulations mentioned above are the provisions Article 20c(4) Police Act and Article 10b(4) Border Guard Act specifying that data may be made available via a telecommunications network only if it provides for the possibility to identify the person receiving the data, their type and the time at which it was obtained, as well as technical and organisational safeguards preventing access to the unauthorised person.

This mechanism ensures the internal verification of telecommunications data collection cases.

This purpose is also served by the provisions requiring authorised entities (Chief Chief, CBŚP Chief, BSWP Chief and Provincial Commandant and Border Guard Chief, BSWSG Chief and Border Guard Branch Commandant) to keep records of requests for communication, postal and online data.

As regards the way in which the police and the Border Guard control over the acquisition of metadata is shaped, it should be pointed out that the existing arrangements provide for mechanisms to enable the district court competent for the premises of the requesting Police or Border Guard (Article 20ca Police Act and Article 10ba Border Guard Act). The competent authority which has requested shall, in accordance with the rules on the protection of classified information, transmit to the district court, during six-month periods, a report covering:

  • the number of cases of collection during the reporting period of telecommunications, postal or internet data and the type of such data;
  • the legal qualifications of the acts for which telecommunications, postal or online data have been requested, or information on the collection of data to save life or human health or support search or rescue activities.

The district court may consult the documents justifying the provision of the data in question. The provisions thus shaped, falling within the scope authorised by the judgment of the Constitutional Tribunal reference no.

K 23/11, allow the court, as an independent judicial authority, to freely shape the way in which the checks are carried out. It is up to the court to decide whether and to what extent specific material will be examined and what will be the criterion for selecting the cases in which an in-depth review will be carried out.

In addition, an additional element of the verification of the obtaining of telecommunications data by the Police and Border Guard is the procedure specified under Article 20c(6) and 7 Police Act and Article 10b(6)(7)) The Border Guard Act.

In accordance with the provisions cited above, those data which are relevant for criminal proceedings shall be communicated by the competent authority to the Prosecutor, who shall decide on the extent and manner of use of the information provided.

On the other hand, telecommunications data which are not relevant to criminal proceedings are subject to immediate, police and protocolatory destruction.

Concerning the question 12 the monthly storage period should be considered to be optimal for the efficiency of the services authorised to use them. It is defined on the basis of Act dated 16 November 2012 amending the Act – Telecommunications Law and some other laws that shortened the retention period of data from 24 to 12 months. As can be seen from the justification for the CJEU judgment in the Prosecution case, a similar retention period applies in most EU Member States.

It is important for the assessment of the solutions adopted in individual EU Member States in the scope analysed to be specific to the detection process, which determines the need to ensure adequate means of monitoring the obtaining of telecommunications data by authorised entities. In Poland, the burden of the detection process is concentrated on the stage of operational and investigative activities, not on the stage of the criminal process, as is the case in many Western European countries.

Concerning the Ombudsman’s concerns about Article 168a Act dated 6 June 1997 The Code of Criminal Procedure should state that it is a general provision which lays down rules on the admissibility of evidence under criminal proceedings in all types of cases.

Thus, the aforementioned regulation does not apply only to evidence obtained by stopping traffic and location data. Therefore, the analysis of the appropriateness of the proposed amendment of the above-mentioned general provision in the area of the criminal procedure relates to the jurisdiction of the Minister of Justice.

Continue exploring our insights.

View all insights
Legal updates

Revolutionary Reform of the PiP

12 March 2026 The Senate accepted without amendment the amendment of the Act on State Labour Inspection.

Legal updates

Property Heritage: a simpler way to enter a perpetual book

From 17 March 2026 new rules are in force which significantly simplify the procedure for disclosing property rights acquired through inheritance or recovery.

Legal updates

Deformalisation of the cassation complaint

On 5 March 2026 a very important composition resolution has been passed 7 Supreme Court judges.