CookieFox

← All posts · · 2 min read

Cookie consent fines in Poland - what the real exposure is

"You risk a 20 million euro fine" is how most articles about cookies open. Reality is more nuanced, and worth knowing before you decide how much to invest. Here is what the sources support - and what circulates with nothing behind it.

Two regulators, two legal bases

In Poland a cookie banner sits under two regimes at once:

  • The President of UKE, under the Electronic Communications Law. The catalogue of infringements is article 444; article 446 sets the amount at up to 3% of the previous year's revenue, or up to PLN 15,000 where there was no revenue. These penalties are discretionary.
  • The President of UODO, under the GDPR, where cookie data is personal data. Here the familiar ceiling applies: EUR 20 million or 4% of worldwide turnover, whichever is higher.

The second exposure is the larger one financially, but also the harder to trigger: it requires showing that personal data is being processed at all.

What has actually happened

As of mid-2026 there is no final Polish penalty imposed for a cookie banner alone. What does matter is the judgment of the Provincial Administrative Court in Warsaw of 11 July 2022 (II SA/Wa 3993/21), which set aside a UODO reprimand: the court held that not every piece of information derived from cookies is automatically personal data. That raised the evidentiary bar for the regulator.

UODO has also not issued banner guidance comparable in weight to the French CNIL, so the working standard comes from the European Data Protection Board.

Be careful what you read

Claims circulate online that we could not trace to any primary source: a supposed "UODO e-commerce guide from March 2025", a "EUR 420,000 fine for a missing Reject button", or a rule that "a banner may cover at most 20% of the screen and must collapse after 5 seconds". Treat them as rumour until you see a decision with a case number.

What this means in practice

The real risk is not a spectacular fine. It is that at an inspection you cannot prove the consent you claim to have collected. What counts is therefore not the banner itself, but whether scripts are genuinely blocked before consent and whether every decision is recorded.

CookieFox blocks trackers until consent and writes every decision to a register you can export to CSV. Try it on your own site, or start with the GDPR consent guide.

A GDPR-compliant cookie banner in minutes

CookieFox scans your site, blocks scripts until consent and keeps a consent register. Deployment is a single line of code.

Create a free account