← Regulators
GDPR EU 2016/679 Poland

Who is the UODO: Poland's data regulator and one of the EU's busiest enforcers

The UODO is Poland's GDPR supervisory authority — the Personal Data Protection Office created in 2018 to replace the old GIODO inspectorate, and one of the most active fining regulators in the EU. What it does, who leads it after the 2024 change at the top, and the security-failure cases (Morele.net, Virgin Mobile) that define its enforcement. Every fact sourced.

Poland is one of the busiest GDPR enforcers in the European Union — not by the size of its fines, which are modest, but by how many it issues and how consistently it goes after the same failing: weak security. The regulator behind that record is the Urząd Ochrony Danych Osobowych (UODO), the Personal Data Protection Office. This is a profile of what the UODO is, how it came to replace Poland’s older data inspectorate, who runs it, and what it fines for. Every fact is sourced.

Quick facts

  • Full name: Urząd Ochrony Danych Osobowych (UODO) — the Personal Data Protection Office
  • Role: Poland’s GDPR supervisory authority; a member of the EDPB
  • Founding law: the Personal Data Protection Act of 10 May 2018, under which the office and its President operate (UODO — Sprawozdanie 2024). The 2018 reform replaced the earlier inspectorate, GIODO (the Inspector General for Personal Data Protection), with the UODO
  • Head: the President of the UODO (Prezes UODO)Mirosław Wróblewski, in office since 26 January 2024; Deputy President: Agnieszka Grzelak (UODO)
  • Seat: Warsaw
  • Website: uodo.gov.pl

What the UODO is — and what it is not

The UODO is Poland’s data protection authority (DPA — the independent national regulator that supervises and enforces data-protection law) and its GDPR supervisory authority, one of the 27 national authorities on the EDPB. It was created by the Personal Data Protection Act of 10 May 2018, the law Poland passed to give effect to the GDPR (UODO — Sprawozdanie 2024).

That law also changed the shape of Polish data regulation. The previous authority was GIODO — the Generalny Inspektor Ochrony Danych Osobowych, a single Inspector General. The 2018 reform replaced it with the UODO, an office headed by a President appointed for a fixed term. So when older sources refer to “GIODO,” they mean the UODO’s predecessor.

It is not an AI Act authority and not a court; like every DPA, its AI-relevant work runs through the GDPR.

What the UODO actually does — and what it fines for

The UODO runs the standard supervisory toolkit — complaints, breach notifications, inquiries, corrective orders and administrative fines — and it is a high-volume enforcer: Poland consistently ranks among the most active EU authorities by number of GDPR fines (enforcementtracker.com). Its annual report appends a full list of the administrative fines imposed each year (UODO — Sprawozdanie 2024).

The defining theme of that record is security — Article 32 of the GDPR, the duty to put in place appropriate technical and organisational measures. Two cases set the tone:

  • Morele.net — about €645,000 (PLN ~2.8 million), 2019. The online retailer’s security measures were inadequate to the risk, and the personal data of roughly 2.2 million people ended up in the wrong hands. It was Poland’s first major GDPR fine (EDPB).
  • Virgin Mobile Polska — PLN 1.9 million (about €427,000), 2021. The telecoms reseller lacked appropriate technical and organisational measures, breaching the GDPR’s confidentiality and accountability principles after a data breach (EDPB).

The pattern is consistent: Polish fines tend to follow data breaches caused by weak security, rather than the consent-and-transfer questions that dominate elsewhere. If you process Polish residents’ data, this is the failing the UODO is most likely to pursue.

Who runs it — and the 2024 change at the top

The UODO is led by a President (Prezes UODO), appointed for a fixed term, supported by a Deputy President. The current President is Mirosław Wróblewski, in office since 26 January 2024, and the Deputy President is Agnieszka Grzelak (UODO). Under Wróblewski the office has continued its active enforcement line. Because the leadership changed in 2024, an older source naming a previous President is out of date — the current name is Wróblewski.

What this means for you

  • If you process personal data and reach Polish users: the UODO is your supervisory authority — and a genuinely active one, more likely than most to issue a fine.
  • If your weak point is security: this is exactly where the UODO bites. Morele.net and Virgin Mobile were both Article 32 cases — inadequate technical and organisational measures, followed by a breach. Encryption, access control, monitoring and tested safeguards are the practical defence.
  • If you are a journalist or researcher: “Poland’s privacy regulator” = the Urząd Ochrony Danych Osobowych (UODO), created by the Personal Data Protection Act of 10 May 2018 (successor to GIODO), seated in Warsaw, led by President Mirosław Wróblewski since 26 January 2024.

TL;DR

The UODO (Urząd Ochrony Danych Osobowych) is Poland’s GDPR supervisory authority and a member of the EDPB, created by the Personal Data Protection Act of 10 May 2018 as the successor to the older GIODO inspectorate. It is one of the EU’s most active enforcers by number of fines, and its record is dominated by security failures under Article 32 — the Morele.net (~€645,000) and Virgin Mobile Polska (PLN 1.9 million) breach cases are the templates. It is led by President Mirosław Wróblewski (in office since 26 January 2024), with Deputy President Agnieszka Grzelak.

Sources