Is Google Analytics Legal in Poland? Cookie Consent, Opera's Impact, and What's Missing

A dark editorial hero. On the right, a dimmed, skeletal recreation of the Google Analytics 4 interface (a 'Google Analytics 4' wordmark, a Home/Reports/Explore/Advertising/Admin menu, and a 'Reports snapshot' panel) sits behind a soft wash of the Polish flag: a light band above a red band. Two lines glow through the ghost panel: a red line reading 'Ad blockers and Opera erase much of the traffic' and an amber line reading 'No analytics exemption: every cookie needs consent.' On the left, the Clickport wordmark and the kicker 'GA4 in Poland' sit above four labelled rows: 'Every analytics cookie needs consent,' 'UODO's enforcement era has begun,' 'Ad blockers rule the Polish browser,' and 'Cookieless analytics needs no banner.'
Legal status re-verified against primary sources in July 2026. Every ruling and figure below links to the original decision or report.

Polish law requires consent for every analytics cookie. No exemptions, no grey areas. Google Analytics' legal status is no different here than in the rest of the EU. But UODO has issued zero decisions on 53 privacy complaints, and Opera's unusually high desktop share makes cookie-based tracking lose more data here than almost anywhere in Europe.

Key Takeaways
  • Poland has no consent exemption for analytics cookies. Under the 2024 Electronic Communications Act, all non-essential cookies require prior opt-in consent, with no distinction between analytics, functional, or advertising cookies.
  • UODO has received 53 complaints from noyb and issued zero decisions on any of them. Five Google Analytics and Facebook Connect complaints have been pending since August 2020. Poland has the worst decision record of any major EU DPA.
  • Poland was the world's #1 country for ad blocker adoption in 2016-2017. Opera, which has a built-in ad blocker and tracker blocker, peaked at 20.84% of Polish desktops in early 2026 (9.4x the global average) and stays several times higher than anywhere else. Combined with cookie consent rejection, cookie-based analytics miss the majority of Polish traffic.
  • The Pegasus spyware scandal revealed that Poland's anti-corruption bureau used NSO Group spyware to hack 33 times into an opposition senator's phone during an election campaign. The European Parliament called it 'the most blatant case' of spyware abuse in the EU.
  • Under new president Miroslaw Wroblewski (from January 2024), UODO issued record fines: EUR 4.4M against ING Bank and EUR 4M against McDonald's Polska. It also fined Poczta Polska EUR 6.4M over the 2020 PESEL scandal, though a court quashed that fine in March 2026 and UODO is appealing.

A country shaped by surveillance

Poland's relationship with privacy is personal. For 45 years under communist rule, the Sluzba Bezpieczenstwa (SB) maintained files on millions of citizens. Neighbors informed on neighbors. Phone calls were tapped. Mail was opened. After 1989, the lustration process of opening those files revealed the scale: the security apparatus had penetrated every layer of society.

That history should have made Poland a privacy leader. Instead, something more complicated happened.

In early 2016, Poland passed surveillance legislation that authorized law enforcement to access metadata without court orders, followed by an anti-terrorism act enabling foreign citizen monitoring without prior judicial approval and 14-day terrorism suspect detention without charges. In May 2024, the European Court of Human Rights ruled this surveillance law violates Article 8 (right to private and family life), finding that Poland lacked "sufficient safeguards against excessive recourse to surveillance." In plain English: the state watched first and answered later.

Then came Pegasus. Between 2017 and 2020, Poland's Central Anti-Corruption Bureau (CBA) deployed NSO Group's Pegasus spyware against opposition politicians, journalists, lawyers, and a prosecutor. Senator Krzysztof Brejza, head of the opposition's campaign team, was hacked 33 times during the 2019 election campaign. Lawyer Roman Giertych was infected 18 times. Prosecutor Ewa Wrzosek, who had investigated whether presidential elections should be postponed during COVID-19, was targeted 6 times. The spyware was purchased using PLN 25 million from the Justice Fund, money designated for crime victims. In plain English: victims' money paid for the spyware.

Poland's surveillance timeline: from secret police to Pegasus
1944-1989
SB (Sluzba Bezpieczenstwa) maintains surveillance files on millions of Polish citizens.
2009
Panoptykon Foundation established in Warsaw. Named after Bentham's panopticon. Becomes Poland's leading digital rights NGO.
Jan 2016
Poland passes surveillance law allowing metadata access without court orders.
2017-2020
Pegasus spyware deployed against opposition politicians, journalists, lawyers, and a prosecutor.
Apr 2020
Government orders Poczta Polska to process PESEL data of ~30 million citizens for an illegal postal election.
May 2024
Mar 2025
New UODO president fines Poczta Polska EUR 6.4 million for the 2020 data scandal.
Mar 2026
Warsaw Administrative Court quashes the Poczta Polska fine (non-final; UODO appealing to the Supreme Administrative Court).

This context matters for understanding Poland's data protection landscape. The country has deep experience with what happens when personal data is weaponized. But the institutions meant to prevent it have been compromised by the same forces they're supposed to regulate. The Panoptykon Foundation, founded in Warsaw in 2009 and named after Jeremy Bentham's panopticon, has been fighting this fight for over 16 years, documenting surveillance abuses and pushing for stronger data protection. But until recently, the regulators weren't listening.

UODO: 267 people, zero noyb decisions

The Urzad Ochrony Danych Osobowych (UODO) is Poland's data protection authority. It has 267 employees working on a budget of PLN 45.4 million (approximately EUR 10.9 million). It received 6,962 complaints in 2023, and an estimated 8,000+ in 2024. That means thousands of complaints landing every year.

Those aren't bad numbers. UODO has more staff and a larger budget than Austria's DSB (53 staff, EUR 5.9 million). The problem isn't resources. It's what UODO has done with them. When I look at UODO's record, the story isn't money. It's will.

In August 2020, noyb filed 5 complaints with UODO as part of its 101 complaints across the EU targeting Google Analytics and Facebook Connect data transfers. The targets: TVN (player.pl), Telewizja Polska (tvp.pl), Grupa Interia.pl (interia.pl), PKO BP (pkobp.pl), and Onet-RAS Polska (jakdojade.pl). Five major Polish websites. Four using Google Analytics, one using Facebook Connect.

All five complaints are still pending. After more than five years, not a single decision. In other words, five years of silence.

But it's worse than that. According to noyb's DPA tracker, UODO has received 53 total noyb complaints across all projects and has issued zero decisions on any of them. Zero. In other words, the worst record of any major EU DPA. For comparison:

A screenshot of the noyb DPA Decision Tracker page at noyb.eu/en/dpas showing a 10-row table of European data protection authorities ranked by decisions issued, with Poland highlighted in red at the bottom and two red editorial annotations. The table columns are Authority, Country, Complaints received, Decisions issued, Decision rate, and Average time to decision. CNIL (France) leads with 30 decisions on 55 complaints, Garante (Italy) 28 on 37, AEPD (Spain) 24 on 41, DSB (Austria) 21 on 51, BfDI (Germany) 19 on 38, AP (Netherlands) 17 on 56, Datatilsynet (Denmark) 12 on 32, Tietosuoja (Finland) 8 on 19, and Datatilsynet (Norway) 7 on 24. UODO (Poland) sits at the bottom with 0 decisions on 53 complaints and 'n/a (5+ years pending)' in the time column. A Poland Spotlight panel on the right shows the Polish flag and three stats: '0 decisions on 53 noyb complaints,' 'Worst record of any major EU DPA,' '5 GA/FB Connect complaints pending since 8/2020.' One annotation reads 'Zero decisions. Five years pending. Worst record of any major EU DPA.' A second reads 'noyb's own public tracker. The Polish entry has not moved since 2020.'
noyb's own public DPA tracker. Poland sits at the bottom of every comparable EU authority with zero decisions on 53 complaints, including five Google Analytics and Facebook Connect complaints pending since August 2020.

A joint report by noyb and the Panoptykon Foundation documented the systemic problems. Complainants must physically travel to Warsaw to photograph their case files because UODO refuses to provide electronic access. UODO doesn't accept complaints via email. The Polish Code of Administrative Procedure requires cases to be decided within one to two months, but most UODO cases drag on for six months or more. And Jan Nowak, who served as UODO president from 2019 to January 2024, resigned from the ruling Law and Justice party just before his appointment, raising questions about independence.

The most telling example: when the government ordered Poczta Polska to process the personal data of approximately 30 million citizens from the PESEL register for an illegal postal election in April 2020, over 230 citizens filed complaints with UODO. Under Nowak, all were dismissed as "unfounded."

New leadership, new enforcement

That changed on January 26, 2024, when Miroslaw Wroblewski took over as UODO president. Wroblewski spent 17 years at Poland's Office of the Commissioner for Human Rights and served on the EU Fundamental Rights Agency board. He's an academic with nearly 100 publications on constitutional law and human rights.

His first year was a signal. In March 2025, Wroblewski fined Poczta Polska EUR 6.4 million (PLN 27.1 million) for the same data breach his predecessor had dismissed. The Minister of Digital Affairs was fined separately for authorizing the transfer. Wroblewski stated: "The fact that personal data from the PESEL register were illegitimately made available and processed by Poczta Polska jeopardised the proper exercise of citizens' rights under the Constitution."

The story didn't end there. In March 2026, the Warsaw Administrative Court quashed the fine (case II SA/Wa 837/25), ruling that Poczta Polska was bound to follow the Prime Minister's April 2020 order while it still enjoyed a presumption of validity. The judgment is non-final, and UODO is appealing to the Supreme Administrative Court. So the flagship fine of the new era is, for now, back in court.

Wroblewski's tenure still brought record fines:

UODO's biggest fines: a new era under Wroblewski
Poczta Polska (quashed on appeal, Mar 2026; UODO appealing)
Illegally processed ~30 million citizens' PESEL data for postal voting (2020)
EUR 6.4M
ING Bank Slaski
Scanned identity documents of ~4.24 million customers without necessity assessment
EUR 4.4M
McDonald's Polska
Employee data breach: names, PESEL numbers, passport details exposed by misconfigured server
EUR 4.0M
DPD Polska
Failed to conclude data processing agreements with external carriers
EUR 2.6M
2025 priorities include health data security, children's data (especially images), and documentation of data breaches. Sources: UODO Poczta Polska decision, EDPB ING Bank decision, EDPB McDonald's decision

Complaints to UODO have increased significantly in 2025. Data breach notifications reached 14,842 in 2024, up from 12,772 in 2022. That means complaints and breaches both climbing at once. UODO created a new department dedicated to preliminary complaint review to handle the increased volume.

The question Polish website owners should be asking: if UODO is finally waking up, how long before it turns its attention to cookies and analytics?

The rules you're actually subject to

Cookie consent in Poland is governed by the Electronic Communications Act of July 12, 2024 (Prawo komunikacji elektronicznej), which replaced the old Telecommunications Law. Cookie consent is now in Articles 398-400 of the new law.

The requirements are straightforward.

Prior consent is required for all non-essential cookies. Under Article 399, users must receive advance notice in an "unambiguous, simple and understandable manner" about the purpose of storing cookies, and consent must be obtained after providing this information. Consent must comply with GDPR standards: freely given, specific, informed, and unambiguous.

There are only two exemptions. A cookie is exempt if it's necessary for transmitting messages via public telecommunications networks, or for delivering an electronically-rendered service the user explicitly requested. Session cookies, shopping carts, consent status storage. That's the full list.

There is no analytics exemption. This is critical. Unlike France, which offers a consent exemption for audience measurement (CNIL evaluated 23 tools before moving to provider self-assessment in 2026), Poland makes no distinction between essential, functional, analytical, and advertising cookies. If your analytics tool sets a cookie and the cookie isn't technically necessary for delivering the service, you need consent. Period.

Enforcement is split between two authorities. UKE (Urzad Komunikacji Elektronicznej, Office of Electronic Communications) handles cookie consent violations under the Electronic Communications Act. Fines: up to 3% of company revenue or PLN 1,000,000, whichever is higher. Individual managers can be fined up to 300% of their monthly salary. UODO handles the GDPR layer on top: up to EUR 20 million or 4% of global turnover. A single non-compliant cookie banner could trigger enforcement from both. In practice, one bad banner can put you in front of two regulators.

Poland vs. France: analytics consent requirements
Poland (Electronic Communications Act)
No consent exemption for analytics
No approved tools list
All analytics cookies need consent
Legitimate interest does not apply
Dual enforcement: UKE + UODO
France (CNIL)
Formal consent exemption since 2020
23 tools evaluated (2020-2025)
Exempt tools: no banner needed
Self-assessment framework from 2026
Single enforcer: CNIL handles everything
Cookieless analytics (no device storage at all) avoid the Electronic Communications Act consent requirement entirely, because no data is stored on or read from the user's device. Sources: ICLG Poland, DLA Piper

One important detail: UODO's only cookie-related decision so far came in late 2021, a reprimand (not a fine) in the iSecure case that treated cookie IDs and IP addresses as personal data and called browser-settings consent "passive and tacit, and thus invalid." But the courts overturned it. The Warsaw Administrative Court annulled the decision (case II SA/Wa 3993/21, 2022) and the Supreme Administrative Court upheld the annulment (III OSK 2595/22, October 2025), holding that IP addresses and cookie identifiers aren't automatically personal data and require case-by-case proof that a specific person can be identified. So Poland has no standing cookie precedent at all. (Separately, a 2021 decision against Interia Group addressed data access rights under GDPR Article 15, ordering the company to disclose behavioral profiling categories created through cookies.)

And there's no official UODO guidance on cookie banners. Polish website owners are operating without a playbook from their own regulator. Our cookie banner decision flowchart fills that gap with the general EU compliance checks.

Google Analytics: the silence

Every major DPA in Europe has taken a position on Google Analytics. Austria ruled it illegal in December 2021. France followed in February 2022. Italy, Denmark, Finland, Sweden, and Norway all issued their own rulings. Even Germany's courts reached the same conclusion without a formal DPA ban. The EDPB set up a task force to coordinate a consistent approach.

UODO said nothing.

Five complaints about Google Analytics and Facebook Connect on major Polish websites have been pending since August 2020. TVN, Telewizja Polska, Interia, PKO BP, Onet-RAS. Five years, seven months. No decisions. No statements. No guidance.

The practical result: Polish websites continue to use Google Analytics freely. There is no domestic regulatory pressure. No Polish court has ruled on analytics legality. No company has been warned, fined, or even formally questioned about GA usage.

The EU-US Data Privacy Framework (adopted July 2023) technically resolved the Schrems II transfer issue for DPF-certified companies like Google. But that only addresses the data transfer layer. The cookie consent layer remains: Google Analytics sets cookies, Polish law requires consent for analytics cookies, and consent means losing most of your visitor data.

And the DPF itself is under threat. Philippe Latombe, a French member of parliament, has appealed to the CJEU to overturn it. The US Privacy and Civil Liberties Oversight Board (PCLOB), cited 31 times in the adequacy decision as a crucial oversight mechanism, has been gutted by the Trump administration. If the DPF falls, Google Analytics faces the same illegal transfer status it had in 2022 across Europe, including in Poland, whether UODO has ruled or not.

For the full EU-wide picture, see our detailed analysis of Google Analytics' legal status.

The Opera problem: why Poland loses more data than anywhere

This is where Poland's story gets unique. Every country loses analytics data to cookie consent rejection and ad blockers. Poland loses more than most, and the reason is a browser. I went looking for why Poland loses so much data, and it kept coming back to one browser.

Opera surged to 20.84% of Polish desktops in early 2026, 9.4x the global average of 2.21% at its February peak. It has eased since, to around 12% by mid-2026, but that's still one of the highest Opera shares anywhere in the world. For a stretch, one in five Polish desktops ran Opera. In practice, that's a fifth of desktops with a tracker blocker baked in.

Why? Opera's desktop development hub is in Wroclaw, Poland. All desktop browser development happens there. The browser has deep roots in the Polish market going back over a decade. Opera GX, their gaming browser, has driven recent growth. And critically: Opera includes a built-in ad blocker and tracker blocker.

A screenshot of the Opera browser Settings page in Polish UI with the Prywatność i bezpieczeństwo section selected, showing the built-in ad blocker and tracker blocker both enabled, with three red editorial annotations. The Blokuj reklamy section has a green toggle in the ON position with the note 'Aktywne od momentu instalacji' and three filter lists checked (EasyList, EasyPrivacy, Polish Ads Filter highlighted in red) plus a stat 'W tym tygodniu zablokowano: 12 847 reklam.' The Blokuj śledzenie section has a green toggle ON and four checked tracker categories (Trackery analityczne with Google Analytics, Adobe Analytics, Mixpanel listed as examples; Trackery reklamowe; Trackery społecznościowe; Trackery od stron trzecich) plus a stat 'W tym tygodniu zablokowano: 8 924 trackery.' A Cookies i dane stron section sits below. One annotation reads 'Built-in. Enabled by default since 2016.' A second reads 'Google Analytics is blocked at the browser level. Before your tracker even loads.' A third reads 'Opera is 20.84% of Polish desktops. 9.4x the global average. Built in Wroclaw.'
Opera browser settings on a Polish system. The built-in ad blocker, tracker blocker, and Polish-community-maintained filter list are all enabled by default. Google Analytics is blocked before the tracker even loads.
A screenshot of StatCounter Global Stats showing Browser Market Share Poland Desktop for February 2026, with two red editorial annotations. The left panel is a horizontal bar chart with Chrome at 54.36% (blue), Opera at 20.84% (orange-red, highlighted with a red dashed border and a small Polish flag icon), Edge at 10.21%, Firefox at 9.78%, Safari at 2.42%, and Other at 2.39%. The right panel compares Global Average vs Poland: Chrome 64.72% global vs 54.36% Poland (10.36 pp below), Opera 2.21% global vs 20.84% Poland (Poland 9.4x global average, highlighted in red bold), Edge 13.05% vs 10.21%, Firefox 6.14% vs 9.78% (1.6x), Safari 8.71% vs 2.42% (3.6x below). A footnote credits StatCounter Global Stats, February 2026. One annotation reads 'Opera 20.84% on Polish desktops. 9.4x the global average. The Polish-Opera anomaly.' A second reads 'Built in Wroclaw. Polish users have stayed loyal for 25+ years. With built-in tracker blocker since 2016.'
StatCounter's public dashboard, February 2026. Opera hit 20.84% of Polish desktops that month, 9.4x the global average. It has eased toward 12% since, but the Polish-Opera anomaly is real and remains a major reason cookie-based analytics undercount Polish traffic.

But Opera is just the start. Poland was the world's #1 country for ad blocker adoption in 2016-2017, driven by Polish websites that overloaded pages with intrusive advertising. Ad blocker usage remains around 34% today, above the global average. In practice, a third of Poles block ads outright. The Polish community maintains three dedicated ad filter lists: Polish Ads Filter (723 GitHub stars, 30,000+ commits), Polish Annoyance Filters, and EasyList Polish.

On mobile, 30% of Polish users are on iOS/Safari with ITP cookie restrictions. Firefox, with Enhanced Tracking Protection, holds 9.8% on desktop.

Now add cookie consent rejection. When Polish visitors encounter a legally compliant banner, the majority reject analytics cookies.

Where your Polish visitor data disappears
Cookie consent rejected
Visitors who click Reject All on a compliant banner
~65-75%
Ad blockers + Opera built-in blocker
Block analytics scripts entirely. Poland has a ~34% ad blocker rate and one of Europe's highest Opera shares.
~30-40%
Privacy browsers (Safari ITP, Firefox ETP)
Block or partition third-party cookies
~20%
What cookie-based analytics actually see
After consent rejection, ad blockers, Opera, and browser blocking
~20-30%
Poland's combination of Opera, ad blockers, and consent rejection creates the widest data gap in Europe. In practice, the widest analytics blind spot on the continent. The only fix is analytics that don't depend on cookies or consent.

Poland has 34.1 million internet users (89.8% penetration), an e-commerce market approaching PLN 150 billion (approximately EUR 35 billion), and over 2.5 million .pl domains. If you're running cookie-based analytics on a Polish website, you're making business decisions based on a minority of your actual traffic. In practice, a huge market measured through a keyhole.

Poland's homegrown alternative

There's an irony in Poland's analytics landscape. The country's data protection authority has been the slowest in Europe to act on Google Analytics. But Poland is also home to one of Europe's most successful privacy-first analytics companies.

Piwik PRO was founded in Wroclaw in 2013 by Maciej Zawadzinski (CEO of Clearcode, a Wroclaw software house) and Matthieu Aubry (creator of the original Piwik open-source project, now Matomo). What started as commercial support for the open-source project became a full enterprise analytics platform.

Today, Piwik PRO serves the European Commission, the Government of the Netherlands, the Council of Europe, and enterprise clients including Airbus and Credit Agricole. It sits alongside the broader privacy-first analytics ecosystem covered in our privacy-friendly analytics guide, and we ranked it against the rest of the field in our GA alternatives comparison. In November 2023, Piwik PRO merged with Cookie Information (a Danish consent management platform), backed by Kirk Kapital, the investment vehicle of the LEGO founding family. The combined entity has over 225 employees, 10,000 user organizations, and subscription revenue exceeding DKK 150 million (approximately EUR 20 million). In other words, a Polish privacy-analytics success story.

Piwik PRO is ISO 27001 and SOC 2 Type II certified, CNIL consent-exempt when properly configured, and EU-hosted. Google's former Head of Web Analytics for Europe, Brian Clifton, joined as advisor in 2023.

Poland also has Gemius, founded in Warsaw in 1999, which provides the standard digital audience measurement across Central and Eastern Europe. Their gemiusAudience product is the currency for digital advertising in Poland and a dozen other CEE markets.

The tools exist. The expertise is Polish. The market just hasn't been forced to move yet, because the regulator hasn't acted. I'll be honest: the talent to fix this was here all along.

What's coming in 2026 and beyond

Three developments will reshape Poland's analytics landscape.

1. The Digital Omnibus would override Poland's lack of guidance. This matters more for Poland than for most countries. France already has an exemption framework. Austria's strict position would be overridden. But Poland has had no guidance at all. The Omnibus would give Polish website owners their first clear legal path to consent-free analytics.

2. UODO under Wroblewski may finally address cookies and analytics.

With rising complaint volumes, record fines issued, and a new department for preliminary complaint review, UODO's enforcement trajectory is clear. The 53 unanswered noyb complaints represent a backlog that Wroblewski inherited, not one he created. Whether he acts on the Google Analytics complaints specifically is uncertain, but the DPF has reduced the urgency of the transfer question. The cookie consent question, however, remains entirely unresolved.

3. The DPF is under active legal challenge. If it falls, even UODO would have no choice but to act.

Check your own site
See what your site loads before consent.
Paste your URL into the free GDPR checker. It reads your page source, identifies every tracking script, and checks whether each one is gated behind consent, which is where UODO's guidance starts. No signup, about thirty seconds.
Scan your site for trackers →

What this means for your website

If you run a website that serves Polish visitors, here's a practical assessment. If I were you, I'd start by checking what your own banner leaks.

If you're using Google Analytics with a cookie banner: UODO hasn't acted, so there's no domestic enforcement pressure today. But you're losing an unusually high share of your visitor data. Poland's combination of high ad blocker usage, Opera's unusually high desktop share with built-in blocking, and cookie consent rejection means your analytics see a smaller slice of actual traffic than in almost any other European market. You're making decisions for a PLN 150 billion e-commerce market based on incomplete data. In other words, a huge market judged on a fraction of it.

If your cookie banner isn't compliant: The risk is growing. UODO under Wroblewski has issued more fines in 2025 than in the previous three years combined. UKE can fine up to 3% of revenue separately. Noyb's 53 pending complaints represent a queue that will eventually get processed. That means the backlog is a clock, not a wall. And noyb, now a Qualified Entity for EU-wide class actions, can bring cases on behalf of affected individuals across all member states.

If you want to see nearly all your traffic and eliminate the risk: Cookieless analytics don't trigger the Electronic Communications Act consent requirement. No banner needed. You see the visitors cookie tools miss, close to all of them, including the Opera users and ad blocker users you're currently missing entirely.

Poland has a complicated relationship with surveillance and privacy. The country that endured decades of secret police files, that was targeted by its own government with Pegasus spyware, that has a data protection authority only now beginning to function independently. Polish website owners, perhaps more than anyone in Europe, understand why privacy matters. The tools to protect your visitors' privacy and see nearly all your traffic at the same time already exist. One of them was built in Wroclaw.

One more thing, because this is a legal topic: I'm not a lawyer and this article isn't legal advice. It's a founder's map of the terrain, with every claim linked to the ruling or the source it came from. If your setup is complicated, show this to your DPO or lawyer.

And if you're staring at a Polish cookie banner decision right now and something here doesn't match what you're seeing, email me. I answer every email.

David Karpik

David Karpik

Founder of Clickport Analytics
Building privacy-focused analytics for website owners who respect their visitors.

Comments

Loading comments...

Leave a comment