Poland Introduces DSA Enforcement Framework: New Supervisory Authorities, Investigations and Fines of up to 6% of Turnover

Poland Introduces DSA Enforcement Framework: New Supervisory Authorities, Investigations and Fines of up to 6% of Turnover

October 8, 2026
1 minutes

KEY FACTS

Poland’s implementing legislation for the DSA was signed by the President on 25 September 2026.

The new rules will enter into force 30 days after publication.

The framework applies to intermediary service providers, including online platforms, hosting providers and online search engines.

Further changes are on the way. Separate legislation concerning blocking orders for illegal content is still under discussion.

On 25 September 2026, the President of Poland signed legislation establishing the national enforcement framework for the Digital Services Act (DSA). The new rules create a domestic supervisory system for intermediary service providers, introduce fines of up to 6% of global turnover, and strengthen the position of affected users by making final administrative decisions finding a DSA infringement binding on civil courts. For online platforms, marketplaces and hosting providers, this marks the beginning of operating under a dedicated national DSA enforcement regime.

Three Authorities, One Enforcement System

Responsibility for supervising compliance with the DSA will be shared among three authorities.

The President of the Office of Electronic Communications (UKE) will serve as the Digital Services Coordinator and will act as the default competent authority. The President of the Office of Competition and Consumer Protection (UOKiK) will oversee infringements affecting consumer interests and selected obligations applicable to online platforms. Matters relating to video-sharing platforms will fall within the competence of the Chairperson of the National Broadcasting Council (KRRiT).

In practice, the division of powers may not always be straightforward. The same incident may fall within the remit of more than one authority. For example, a defective mechanism for reporting illegal content on an online platform may raise both DSA compliance issues and consumer protection concerns.

Businesses should therefore carefully determine which authority may be competent in their particular circumstances. Depending on the nature of the service and the alleged infringement, the same activity may attract the attention of multiple regulators.

A National Council for Digital Services will also operate alongside the UKE President as an advisory body on matters concerning the digital services market.

From Complaint to Decision

The new framework creates a straightforward mechanism for users to report potential DSA infringements. Complaints may be submitted electronically and supported by evidence such as screenshots or recordings. Where another EU Member State’s Digital Services Coordinator has jurisdiction, the Polish authority will forward the complaint accordingly.

Following receipt of information about a potential infringement, the competent authority may request explanations from the provider, granting at least seven days to respond. The authority may also launch an investigation, which should generally be completed within four months, or five months in particularly complex cases, and may conduct inspections, including remotely.

For service providers, the contact point designated under the DSA will become particularly important, as official correspondence will be delivered through that channel.

If an infringement is confirmed, the authority will issue a decision ordering its cessation. Depending on the circumstances, it may also require the provider to publish specific information or the decision itself at its own expense. In the most serious cases, the authority may require warnings to be displayed to users or restrict access to content that infringes the DSA.

Importantly, ending an infringement during the proceedings does not necessarily bring the case to an end. The authority may still issue a decision confirming that an infringement occurred, even if it has already been remedied. The burden of proving that the infringement has ceased rests with the provider.

The legislation also provides a commitment mechanism. Where a provider undertakes to remedy an infringement or its effects, the authority may issue a commitment decision requiring compliance with those undertakings.

Even a single user complaint may therefore lead to a formal investigation, an inspection and the imposition of corrective measures.

Fines of up to 6% of Turnover and Penalties for Non-Cooperation

The new legislation introduces significant financial penalties for breaches of DSA obligations.

In the most serious cases, fines may reach 6% of the provider’s global turnover from the previous financial year.

Failure to cooperate with the authorities may also prove costly. Failure to provide requested information, providing incomplete, inaccurate or misleading information, or obstructing an inspection may result in fines of up to 1% of the provider’s annual income or global turnover. Other persons subject to information obligations may face penalties of up to 1% of their annual income.

The sanctions regime does not stop there. Authorities may also impose periodic penalty payments of up to 5% of the average daily turnover or income for each day of delay in complying with specified decisions or obligations, including the submission of an action plan or cooperation during inspections.

Importantly, remedial action will not necessarily shield a provider from liability. Authorities may still impose penalties even where an infringement has already ceased or its consequences have been remedied. When determining the amount of a fine, authorities will take into account factors such as the nature, gravity, duration and recurrence of the infringement, as well as the provider’s economic capacity.

As a result, regulatory risk extends beyond the infringement itself and includes failure to cooperate effectively with supervisory authorities or delays in complying with regulatory requirements.

Interim Measures and Restrictions on Access to Services

The new rules allow authorities to act before proceedings have been concluded.

Where a DSA infringement appears likely and the provider’s continued activity could result in serious and difficult-to-remedy harm, the authority may temporarily order restrictions on services or require changes to practices that breach the DSA. Such measures may remain in force until a final decision is issued.

In the most serious cases, authorities may require the provider’s management to conduct an internal review and prepare a remediation plan.

Restrictions on access to a service are intended to be a measure of last resort. Where the conditions set out in the DSA are met, the competent authority may apply to the Warsaw Regional Court (Competition and Consumer Protection Court) for an order temporarily restricting access to a service or, where technically necessary, to the relevant online interface.

Filing an appeal will not suspend the effectiveness of such an order. Access restrictions may therefore be implemented while court proceedings are still ongoing. The legislation also provides for an expedited procedure, with no cassation appeal available against the final appellate decision.

These interim measures are intended to enable regulators to respond rapidly to the most serious DSA infringements before administrative proceedings are completed.

Civil liability: administrative decisions may shape the outcome of damages claims

The new rules strengthen the position of users seeking compensation for DSA infringements.

Claims will be heard by regional courts, while the Polish Civil Code will apply to matters not specifically regulated by the DSA.

Administrative and civil proceedings will be closely linked. If the competent authority is investigating the same infringement, the civil court will stay the proceedings until the administrative case is concluded. Moreover, a final decision confirming a DSA infringement will be binding on the civil court as regards the fact that the infringement occurred.

This means that a claimant holding such a decision will not need to prove the infringement again in court. Issues such as the extent of the damage and causation will, however, remain subject to judicial examination.

The legislation also introduces additional support mechanisms. With the user’s consent, the competent authority or a trusted flagger may bring an action on the user’s behalf or join ongoing proceedings.

How to Prepare Your Organisation for the New Rules

Before the new legislation enters into force, organisations should assess their readiness to comply with the new requirements. In particular, businesses should consider:

  • assessing whether their activities qualify as an intermediary service under the DSA and identifying the obligations that apply as a result;
  • determining which authority may be competent in relation to specific obligations and potential infringements;
  • ensuring that the contact point designated under Article 11 DSA is continuously monitored and that any correspondence from authorities is promptly routed to the appropriate team;
  • reviewing existing content reporting, moderation and user complaint-handling mechanisms;
  • preparing procedures for responding to information requests and inspections carried out by supervisory authorities, including remote inspections;
  • assessing the organisation’s readiness to implement interim measures that may be imposed before proceedings are concluded;
  • reviewing terms and conditions, internal policies and agreements with service providers and business partners to ensure a clear allocation of DSA-related responsibilities;
  • monitoring further legislative developments concerning the separate proposal introducing blocking orders for illegal content.

How LYNX Can Help

For many online platforms, hosting providers and other intermediary service providers, the new rules will serve as a catalyst for reviewing DSA compliance, updating internal procedures and preparing for inspections and proceedings conducted by national supervisory authorities.

LYNX supports digital service providers and their business partners in particular with:

  • assessing whether a particular entity falls within the scope of the DSA and identifying the obligations that apply to it;
  • conducting DSA compliance audits and identifying areas requiring remediation;
  • reviewing and updating terms and conditions, content moderation procedures and complaint-handling systems;
  • preparing organisations for inspections and proceedings conducted by UKE, UOKiK and KRRiT;
  • representing clients in administrative and judicial proceedings;
  • reviewing and negotiating agreements with service providers and business partners, including the allocation of responsibilities for complying with DSA requirements.

If you would like to discuss how the new regulations may affect your business, please contact Marcin Kroll, Partner, or Aneta Kiser at LYNX Poland.

We don’t just
advise – we commit.

We think like stakeholders.
We’re by your side to drive results.