Part of the AI Regulation News hub.
Poland's data protection authority published four sets of initial questions to ask before building or deploying an AI system
The regulator publishing these says outright that they are not a binding interpretation and that you never have to show anyone your answers. That is what makes them worth using.
Bottom line: Not binding. UODO states the questions are not a binding interpretation of the provisions and do not determine GDPR compliance, and that the answers do not have to be presented to the supervisory authority.
Who this affects: Data protection officers, general counsel, and the procurement and technology leads who actually sign AI vendor contracts, at Polish SMEs, public sector bodies, and organisations training or fine-tuning their own models.
Issue date: 6 August 2026. Comments and experience of using the lists can be sent to UODO until 30 September 2026.
What changed: Four differentiated question sets now exist in Polish, in DOCX form, aimed at different types of organisation and different stages of AI adoption.
Analysis: UODO published its own reason for doing this, and it is a survey finding: between 41 and 58.5 percent of entities do not see a connection between AI tools and personal data processing at all. The lists are aimed at organisations that do not yet know they have a problem, which is why the framing is questions rather than requirements.
Primary sources: UODO announcement (PL) · Initial question lists, PDF (PL) · Covering letter, PDF (PL)
- Instrument (EN)
- Lists of initial questions: personal data protection in the context of artificial intelligence systems
- Authority
- Urzad Ochrony Danych Osobowych (UODO)
- Jurisdiction
- Poland
- Status
- Published, with a feedback window open
- Bindingness
- Expressly non-binding; not a binding interpretation and not determinative of GDPR compliance
- Issue date / next deadline
- 6 August 2026; comments to pytania_inicjalne@uodo.gov.pl until 30 September 2026
- Author
- Prof. UL dr hab. Dominik Lubasz, with other members of the Social Team of Experts to the President of UODO and UODO experts
- Formats
- Two PDFs plus four DOCX checklists
- Primary source
- https://uodo.gov.pl/pl/138/4533
The four sets, and who each is for
UODO prepared four sets matched to different groups and different stages of AI adoption.
The first is for small and medium enterprises using off-the-shelf AI systems. UODO's description is candid about the assumed reader: such organisations do not go through a training stage and do not have extensive legal knowledge. The second is for public sector bodies, and takes account of the principle of legalism and the rules of administrative procedure.
Version 0, described as the zero checklist with a functional approach, is aimed at organisations that fit neither of the first two groups, including those building or fine-tuning their own AI models.
The Extended Version is common to all of the above. It covers not only the GDPR but also signals obligations arising from the AI Act, specifically risk classification and the fundamental rights impact assessment. UODO says it is to be completed where the entry list reveals the conditions described in its own description, in particular the building or fine-tuning of a model, or an effect on the legal situation of individuals.
Why UODO says it published them
The office grounds the exercise in a needs survey conducted by the Social Team of Experts to the President of UODO. Two figures from it appear in the announcement.
Between 41 and 58.5 percent of entities do not perceive a connection between AI tools and the processing of personal data. And 95.9 percent do not consider themselves prepared to deploy AI in compliance with the GDPR.
UODO's diagnosis of the timing problem is the sharper observation. The compliance question, it says, is usually asked once the tool is already running and the decisions about which data is used and which supplier is engaged have already been taken. The purpose of the published questions is to get organisations to ask them before the AI system is switched on.
What the lists are not
The announcement is unusually direct about the limits, and that directness is the point rather than a disclaimer.
The questions will not replace a risk analysis, a data protection impact assessment, or an assessment of the impact on fundamental rights. They are a starting point for those analyses. They are not a binding interpretation of the provisions and do not determine compliance with the GDPR.
Nor is there a filing obligation. UODO states that the answers to the questions do not have to be presented to the supervisory authority. Read together, those statements mean a completed checklist is an internal working document, not a submission and not a safe harbour.
Authorship and the feedback window
The lists were prepared by prof. UL dr hab. Dominik Lubasz, with support from the other members of the Social Team of Experts and from experts at the Personal Data Protection Office.
UODO encourages organisations to pass the material to their data protection officers and to the people responsible for technology purchases and deployments, either in full or in the part addressed to that recipient. The split by audience is meant to be used, in other words, not read cover to cover by everyone.
Until 30 September 2026, comments and experiences from using the lists can be sent to pytania_inicjalne@uodo.gov.pl. UODO says that feedback will be used when the materials are updated, which implies a further version rather than a fixed text.
How to get value out of a non-binding checklist
The honest use case is procurement timing. If your organisation only asks the data protection question after the vendor is chosen and the pilot is live, the checklist changes nothing. If it becomes a gate before the purchase order, it does the work UODO designed it for.
The Extended Version is the one to watch for scope creep. Its trigger, on UODO's description, includes building or fine-tuning a model or affecting the legal situation of individuals. Plenty of organisations that think of themselves as buyers of off-the-shelf tools are in fact fine-tuning on their own data.
One caution: because these lists are non-binding and were written by an expert team rather than adopted as guidance, completing one proves you asked the questions. It does not prove your answers were right, and UODO has said as much.
What we did not verify
We opened the UODO announcement of 6 August 2026 in Polish and took every fact, figure and the quotation from it.
We did not open the two PDFs or the four DOCX checklists, so we describe the sets as UODO describes them and make no claim about the individual questions any list contains. We found no English version. We did not open the linked needs survey, so the two percentages here are as reported by UODO in this announcement.
We do not claim that completing any of these lists satisfies a GDPR or AI Act obligation, because UODO says the opposite. We do not claim a publication date for any updated version.
Poland's regulator has published a pre-deployment questionnaire and simultaneously stripped it of legal weight: not a binding interpretation, not determinative of compliance, never filed with anyone. That combination makes it useful as an internal procurement gate and useless as a defence. Use it before you sign the vendor contract, and send UODO your experience before 30 September 2026 if you want the next version to be better.
Source File
https://uodo.gov.pl/pl/138/4533
Open the UODO announcement dated 06.08.2026 and confirm the four downloadable DOCX versions, the statement that the questions are not a binding interpretation and that answers need not be presented to the supervisory authority, the survey figures of 41 to 58.5 percent and 95.9 percent, and the 30 September 2026 feedback deadline.
Nie sa wiazaca wykladnia przepisow i nie przesadzaja o zgodnosci z RODO. Odpowiedzi na pytania nie trzeba przedstawiac organowi nadzorczemu. UODO announcement, 6 August 2026
FAQ
Are these checklists mandatory in Poland?
No. UODO states that the questions are not a binding interpretation of the provisions, do not determine compliance with the GDPR, and that answers to them do not have to be presented to the supervisory authority.
Which of the four versions applies to my organisation?
UODO matched them to groups: one for small and medium enterprises using ready-made AI systems, one for public sector bodies, and Version 0 for organisations in neither group including those building or fine-tuning their own models. The Extended Version is common to all and is completed where the entry list shows the conditions it describes.
Do the lists cover the AI Act?
Only the Extended Version, and only by way of signal. UODO says it takes account not just of the GDPR but also flags AI Act obligations, specifically risk classification and the assessment of impact on fundamental rights.
Can I still send UODO comments?
Comments and experiences of using the lists can be sent to pytania_inicjalne@uodo.gov.pl until 30 September 2026. UODO says the feedback will be used when the materials are updated.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.