
Poland adds Cyber Piątka bill to legislative agenda to tighten data security rules
The Polish government entered the Cyber Piątka legislative package into its official work agenda, introducing certification for medical data processors and strict rules for firms handling over 100,000 individuals' records.
Legislative schedule and core provisions
The Polish government formally entered the Cyber Piątka legislative package into its official work agenda, advancing a regulatory framework for digital data protection. Digital Affairs Minister Krzysztof Gawkowski presented the timeline during the 8th Cybersecurity Forum, targeting the completion of internal government consultations within three months. The Ministry of Digital Affairs drafted the initial principles in late August 2026 and projects parliamentary passage in January 2027. Under the proposed statutory provisions, companies that process sensitive medical records will face mandatory security certification and defined baseline technical standards. The reform also obliges service providers to notify patients whenever their health records are transferred to external third-party processors.
- Ministry of Digital Affairs presents the Cyber Piątka regulatory framework
- Draft bill submitted to the government legislative work register
- Internal government consultations take place across a three-month window
- Targeted adoption of the legislation by parliament
Stricter requirements for mass data handlers
The draft legislation establishes clear compliance boundaries for organizations handling personal information at a large scale. Stricter obligations apply specifically to processors handling data across more than 100 separate administrators or managing records of more than 100,000 individuals. Digital infrastructure authorities intend to link commercial data monetization directly to verifiable investments in cybersecurity controls. Patients will also receive automated notifications regarding medical events directly through the official mObywatel and mojeIKP mobile applications. Gawkowski explained the regulatory rationale during an interview with the Polish Press Agency.
This threshold is a clear boundary of responsibility. It is important for companies to know that the state will hold them by the throat, telling them: you cannot process too much data if you do not invest in cybersecurity and the protection of that data. If someone earns money on citizens' data because they process it, because they forward it, they must also know that cybersecurity should be their priority today.
Responses to medical sector breaches
The legislative initiative follows recent data breaches that compromised healthcare information across domestic databases. In response, the Personal Data Protection Office is carrying out formal regulatory inspections across affected entities. The Ministry of Health has concurrently issued specialized cybersecurity guidance directed at healthcare providers and IT contractors. Law enforcement agencies and specialized state cybersecurity units are conducting investigations to identify criminal actors responsible for attacking medical sector infrastructure. Gawkowski noted that commercial enterprises must treat cyber resilience as a core business asset rather than an optional expense.
If you have been infiltrated, your data has been stolen, you lose brand value and that means you will earn less because customers will not trust you. You cannot avoid investing in cybersecurity when a hybrid war is ongoing. Poland is the most attacked country in Europe.
State financing for enterprise cybersecurity
To support compliance and infrastructure upgrades, the Ministry of Digital Affairs is preparing a dedicated funding mechanism for commercial entities. The forthcoming initiative builds on the previous Digitalisation Loan program executed in 2025, which allocated 2.8 billion PLN in financial support for enterprise technology transformation. Polish officials are encouraging business leaders to draw from these available public funds to upgrade system safeguards and defend network perimeters. The government expects the finalised bill to move to parliament once the ministerial review concludes in late 2026.


