Plan kontroli sektorowych UODO na 2026 rok: kto znajdzie się pod lupą i jak przygotować firmę lub organizację na kontrolę

UODO's Sectoral Inspection Plan for 2026: Who Will Be Under Scrutiny and How to Prepare Your Company or Organization for an Inspection

News

UODO's Sectoral Inspection Plan for 2026: Who Will Be Under Scrutiny and How to Prepare Your Company or Organization for an Inspection

by ecommerce legal on Mar 16, 2026

Changing the priorities of a supervisory authority is rarely accidental. When the President of the Personal Data Protection Office (UODO) publishes a sectoral inspection plan, it practically sends a clear signal to the market: in these areas, "something was not working" in recent months – there were incidents, there were complaints, there were recurring errors in the application of regulations – and it is precisely there that a real, operational verification of compliance with the GDPR will be launched in 2026. In January 2026, UODO identified five sectors that will be subject to sectoral inspections, with a clear emphasis on data security and data processing practices in mass and sensitive environments.

From a compliance perspective, it is worth looking at this plan not as a "list of potential troubles," but as a map of risks that can be mitigated – provided that preparations begin before the first letter arrives, and the IT, legal, HR, and operational teams start working together, not in parallel.

What exactly does the UODO inspection plan for 2026 cover?

UODO indicated the following areas for sectoral inspections in 2026:

  1. bodies that process personal data in Large-Scale EU Systems, including the processing of SIS/VIS personal data based on the provisions of the Act of August 24, 2007, on the participation of the Republic of Poland in the Schengen Information System and the Visa Information System, implementing acts, and European Union regulations, which will constitute a continuation of the inspections from 2025;

  2. medical entities – processing of personal data using video monitoring, especially concerning children, including in hospital pediatric wards, clinics, and/or children's outpatient clinics;

  3. entities operating the Public Information Bulletin (BIP) – the manner of processing personal data in connection with the obligation to maintain BIP, particularly regarding data anonymization and making available the course of municipal council sessions;

  4. marketing entities – particularly regarding the legal bases for processing personal data for marketing purposes;

  5. online delivery platforms – processing of personal data in connection with providing intermediary services for the sale of goods and services via online applications.

UODO emphasizes that the plan includes sectors where incidents have been recorded and those that, due to complaints and reported infringements, have been deemed particularly problematic. This is a well-thought-out selection, with fully justified intentions.

It is also worth noting that the SIS/VIS component is a continuation of the direction from 2025, when large-scale EU systems were also included in the sectoral inspection plan.

What will inspectors pay attention to?

In practice, sectoral inspections rarely end with checking a single document. They are more likely a test of the consistency of the entire data protection system: whether the organization can prove compliance (accountability), whether it has processes adequate to the risk, whether "paper safeguards" have counterparts in systems, authorizations, and daily practice.

The most common areas of interest include:

  • legality and transparency of processing (legal basis, information obligation, lack of "default consent");

  • minimization and adequacy (whether the scope of data and retention period are actually necessary);

  • security (Art. 32 GDPR) understood as a set of real controls: access, logs, encryption, segmentation, backups, tests;

  • incident and breach management (procedures, registers, response time, corrective actions);

  • supplier relationships (data processing agreements, transfers, subcontractor chain, auditability).

The 2026 plan suggests that UODO will be particularly sensitive to two types of situations: first, data processing in "sensitive" contexts (children, health, public sphere), and second, mass and platform-based processing, where it is easy to lose control over the data lifecycle.

Video monitoring in medical entities: patient safety versus privacy

In the healthcare sector, video monitoring is one of the most conflict-generating tools: on the one hand, it is supposed to genuinely increase safety, but on the other hand, it operates permanently and may cover particularly intimate situations where patient privacy should be the standard, not the exception.

In the context of the Polish legal system, it is crucial that video monitoring in medical facilities is regulated by Article 23a of the Act on Medical Activity, and UODO itself has for years signaled interpretational problems and risks associated with excessive or poorly designed monitoring – especially in rooms where health services are provided.

In the 2026 inspection plan, UODO explicitly points to monitoring in medical entities, "especially concerning children," including in pediatric wards and clinics. This is significant because children are a category of persons requiring increased protection, not only in terms of communication, but primarily in terms of process design: purpose → scope → access → retention → technical limitations, including even camera placement and exclusion of sensitive zones.

The most frequently questioned and verified aspects are:

  • whether monitoring is truly necessary for a specific purpose and whether there are less intrusive means,

  • whether the organizational regulations of the facility correctly describe the principles of monitoring and the areas covered by observation,

  • who has access to images/recordings, how authorizations are granted, and whether audit trails exist,

  • how retention and destruction of recordings are carried out (whether automatic deletion actually works, or if it's just a policy statement),

  • whether patients/guardians receive clear information about monitoring and their rights, and whether staff are trained.

UODO also signaled a broader problem: the very construction of regulations can lead to "too broad" interpretations, and monitoring should only be implemented when necessary and when the purpose justifies observation. In 2026, it is precisely the practice of "necessity" and "proportionality" that may be verified most directly.

BIP under scrutiny: anonymization, transparency, and session recordings – a test of process maturity

The third area of sectoral inspections concerns entities operating the Public Information Bulletin (BIP), and UODO explicitly highlights two aspects: anonymization and making available the course of municipal council sessions.

This is the intersection of two legal orders: the right to public information and data protection. In practice, problems do not arise from the idea of transparency itself, but from the lack of a process that establishes anonymization rules, verifies documents before publication, defines exceptions and publication channels, and also controls what happens to the material after publication (e.g., requests to delete or restrict access to specific data in a recording).

In its materials regarding the transmission and recording of sessions of local government bodies, UODO emphasizes, among other things, that recordings of sessions are published in the BIP and on the local government unit's website, and publication "in other places" should only occur when the administrator has full control over the data and can fulfill GDPR obligations. In the context of inspections, this means that publishing a recording on an external platform may be confronted with questions about real control over the data lifecycle.

Weak points that may be revealed as a result of inspections:

  • anonymization performed ad hoc, without a standard and without verification,

  • lack of distinction between data that must remain public and data that should be anonymized,

  • publication of video materials without considering "sensitive" scenarios (e.g., statements from residents),

  • lack of a mechanism to respond to requests for exercising rights – especially when a recording is an element of "recording" the session but contains excessive data.

Marketing entities: verification of legal bases

The fourth area of the plan is marketing entities, particularly regarding the legal bases for processing data for marketing purposes. This foreshadows inspections that may affect not only classic agencies but also companies conducting intensive internal marketing: e-commerce, subscription services, telemarketing, B2B lead generation, CRMs, automation, and profiling.

In 2026, it will be impossible to discuss legal bases in marketing without addressing the electronic communication regime. After the Electronic Communication Law came into force, Article 398 of the ECL, among others, became crucial, as it directly establishes a consent model before using end devices and automatic calling systems for direct marketing.

What does this mean in practice for inspections?

UODO may verify not only the basis itself from Article 6 of the GDPR but the entire architecture of acquiring and managing consents:

  • whether consents are specific, channel-separated, and provable,

  • whether unsubscribe/opt-out mechanisms work in compliance with requirements in each channel,

  • whether "legitimate interest" is not used as a universal alibi for activities that actually require consent under sectoral regulations,

  • whether profiling and segmentation have appropriate bases and are transparently described.

For marketing organizations, this is a good time to test the entire chain: from data source, through CRM and marketing automation integrations, to communication and consents, including relationships with subcontractors.

Online delivery platforms: mass data, geolocation, and the risk of losing control over the ecosystem

The fifth area of the plan is online delivery platforms, meaning data processing in connection with providing intermediary services for the sale of goods and services via online applications.

This is a sector where data is processed "in motion" and "in real time," including users, restaurants, shops, couriers, payments, location, ratings, customer support. In such models, the danger often lies in the organization having a highly developed product but not an equally mature personal data protection model. It sometimes happens that the company does not even know who is the administrator of what, who is the processor, what the supplier chain looks like, where logs go, how long location data lives, and how it is secured.

Therefore, inspections may delve into technical and operational levels: geolocation retention, employee access to courier and customer data, environment separation, access logging, incident management, and whether in-app communication corresponds to what actually happens in the systems.

SIS/VIS and large-scale EU systems: continuation of inspections and emphasis on systems with the highest sensitivity

In the 2026 plan, UODO maintains the inspection of bodies processing data in large-scale EU systems, including SIS/VIS, as a continuation of activities from 2025. This signals that the topic has not been closed, and the supervisory authority sees the need for further verification of compliance in environments where the scale and sensitivity of data are highest, and access to systems requires a rigorous regime of authorizations, controls, and audits.

Consequences: not just a fine, but an obligation to rebuild processes

The risk of inspection is not only the prospect of an administrative monetary penalty. In practice, equally severe consequences can include: compliance orders, processing restrictions, the need to rebuild systems, "freezing" marketing campaigns, and in the public sector – public pressure related to a breach of trust.

It is worth remembering that Polish regulations provide statutory limits on the amount of fines for some public entities, but limiting the amount does not eliminate the risk of decisions and remedial obligations.

UODO's sectoral inspection plan for 2026 is clear: the supervisory authority will look into organizations where processing is either particularly sensitive (children, health, public sphere), or particularly mass and platform-based (marketing, intermediary applications), or particularly system-critical (SIS/VIS).

The good news is that most risks can be reduced without a revolution, provided that the organization stops treating compliance as a set of documents and starts treating it as a system that genuinely needs to function and respect applicable legal provisions. The bad news: if this system does not work, a sectoral inspection is one of the fastest ways for this to come to light.

Article prepared by Alicja Christensen, lawyer at ecommerce.legal

 

Tags:

Latest articles

Reforma PIP w 2026 roku - dlaczego przedsiębiorcy e-commerce powinni przyjrzeć się swoim kontraktom B2B?

PIP reform in 2026 - why e-commerce entrepreneurs should review their B2B contracts?

Read More
RODO na nowo - czyli jak Digital Omnibus ma zamiar zmienić europejskie prawa o ochronie danych osobowych?

GDPR anew - how the Digital Omnibus intends to change European data protection laws?

Read More
Digital Fairness Act a model biznesowy e-commerce - gdzie leży realne ryzyko dla sklepów internetowych?

Digital Fairness Act and the e-commerce business model - where do the real risks lie for online stores?

Read More
Google analizuje regulaminy i wiarygodność sklepów. Czy Twój e-commerce przejdzie ten audyt?

Google analyzes terms and conditions and the credibility of online stores. Will your e-commerce pass this audit?

Read More
View More