A company website in Poland: what the law requires
A company website in Poland is not just design and copy. There is a set of things that must be on it: company details in a defined scope, a privacy policy, a cookie consent that actually works, and for a shop a set of terms as well. Missing the first group is an offence punishable by a fine; breaches on the data side draw UODO sanctions, which in Polish practice have run from 10,000 to 50,000 zł for small shops.
Below is a checklist without the legal phrasing: what exactly belongs on the site, how the requirements differ for a sole trader and for a limited company, why an "Accept" button with no "Reject" button counts as a breach, and how all of it looks on a live example — this very site.

Why this is not a formality
Two separate mechanisms, and both work without warning.
The first is the duty to identify yourself when providing services electronically. It comes from the Act on providing services by electronic means; missing or incomplete details are an offence punishable by a fine. The second is data protection: privacy policy, consents, cookies. Here the supervisor is UODO, the ceiling is the European one (up to EUR 20 million or 4% of turnover), and actual decisions against small Polish shops run into tens of thousands of złoty.
On top of that there is UOKiK, which actively checks consumer rights in online trade. A separate authority with separate sanctions.
Company details: the minimum that has to be visible
The basic set for anyone providing services through a website: company name, address, and an electronic contact address. Plus the NIP tax number. If the activity requires a licence or permit — information about it and about the authority that issued it.
For a limited company (sp. z o.o.) the list is longer: the full company name, registered office and address, the KRS number together with the registry court, the tax number and the share capital.
Where to put it: in the footer on every page, or on a separate contact page linked from the footer. The practical point is that the details should be findable without searching.
The privacy policy
This is not a template copied from someone else's site — in an inspection the first thing done is comparing the policy against what the site actually does. A mismatch is worse than a modest but honest document.
What belongs in it:
- who the data controller is — with the same details as in the footer;
- what data is collected: contact form, analytics, orders, newsletter;
- for what purpose and on what legal basis — consent, contract, legitimate interest;
- how long it is kept and who it goes to — including external services: analytics, mailing platform, payment provider, hosting;
- the person's rights: access, rectification, erasure, withdrawal of consent, complaint to UODO.
One point that is often forgotten: if analytics or an advertising pixel runs on the site, data leaves the company. That has to be stated plainly.
The cookie banner: where the breach usually is
The most common mistake looks harmless: a banner with a single "Accept" button and a "Learn more" link. Consent in that form is not freely given — refusing is not as easy as agreeing.
How it should work:
- Refusing is no harder than accepting. Both buttons on the banner's first screen, equally prominent.
- Categories kept separate. Necessary, analytics, marketing — individually, so only some can be switched on.
- Nothing loads before consent. If analytics and pixels fire before the click, the banner is pointless: the data has already gone.
- The decision can be changed. A permanent link to consent settings, usually in the footer.
- Silence is not consent. Scrolling, closing the banner with an X, or continuing to browse do not count as agreement.
Terms and conditions: who needs them
If goods or services are sold through the site, terms are mandatory. The document sets out the rules: who the seller is, what exactly is sold, how an order is placed, how and when payment and delivery happen, how a complaint is made, and how the right of withdrawal works.
Even with no sales, just an enquiry form, it is worth describing the rules for providing services through the site — this is the "terms of providing services by electronic means" the statute refers to.
Consumer rights that must be stated before purchase
- 14 days to withdraw from a distance contract without giving a reason — with the list of exceptions (for example, goods made to individual order).
- The full price before the order is placed: delivery, fees and mandatory surcharges visible before confirmation, not appearing at the last step.
- A clear complaints procedure — where to write and within what time a reply comes.
- Honest discounts. If you show a struck-through old price, the lowest price from the past 30 days must appear next to it — an Omnibus directive requirement, and it does get checked.
Accessibility — now on this list too
Since 28 June 2025 the act on the accessibility of products and services has applied. Micro-firms are exempt for services, but the exemption stops working once the company grows or acts as a manufacturer. The breakdown with dates, sanctions and a fifteen-minute site check is in a separate article: Website accessibility law in Poland.
Forms: do not collect just in case
The rule is simple: every field on a form should be needed in order to answer the enquiry. A date of birth on a "write to us" form is data you then have to store, protect and justify during an inspection.
And two practical requirements: a consent box must not be pre-ticked, and consent to a newsletter must be separate from consent to handling the enquiry. One checkbox covering everything is invalid.
How we did it here — you can check
None of this is theoretical for us: it all runs on our own site, and every statement above can be verified right now.
- Company details — in the footer on every page, in all four languages of the site.
- A consent banner with separate categories and equally prominent buttons; the decision can be changed at any time on the Consent settings page, linked from the footer.
- Analytics runs through a tag manager and does not start before consent — meaning that until the click the counter does not work at all, rather than "works but anonymously".
- The privacy policy describes exactly what happens: which services are connected and what data reaches them.
A twenty-minute checklist
- Open your site in a private window. Find the name, address and tax number in the footer; for a limited company also the KRS number, court and share capital.
- Check the cookie banner: is there a reject button on the first screen, and is it next to the accept button.
- Open developer tools and see whether analytics loads before "Accept" is clicked.
- Read your own privacy policy and compare it with reality: is every connected service named there.
- If you sell — check that the terms exist, that the 14 days are stated, and that the full price is visible before order confirmation.
- Check the forms: no pre-ticked consents and no unnecessary fields.
In short
There is not much that is mandatory, and nearly all of it is done once: company details in the footer, an honest privacy policy, a cookie banner with a real choice, terms if you sell, and consumer rights stated before purchase. The expensive part is rarely the missing document — it is the gap between what the documents say and what the site actually does.
If you would like someone to walk this list with you and say what is missing, write to us.
Victor Parhimchik, founder of the IT Deweloper web studio




