The UODO 2026 Inspection Plan — Who’s in Scope and How to Prepare
At the start of each year, the President of Poland’s Data Protection Authority (UODO) publishes a sectoral inspection plan. For many companies it is just an announcement that passes unnoticed. In practice it is one of the most important compliance documents of the year — a map of the areas where the authority sees the biggest problems and plans to pay a visit.
The plan for 2026 (published on 8 January 2026 under Article 78 of the Data Protection Act) carries an important signal for smaller businesses. Among the sectors selected are those where micro and small enterprises operate every day — marketing and online delivery platforms. And UODO makes clear that it does not intend to give them any leniency.
This article explains what the sectoral inspection plan is, who is in scope in 2026, what the authority actually looks at, and how to prepare your company for an inspection — before the inspectors knock on the door.
What the Sectoral Inspection Plan Is
The sectoral inspection plan is a document published at the start of the year in which the President of UODO indicates the categories of entities and processing areas that will undergo detailed scrutiny that year. It is not drawn up at random — it is based on an analysis of incoming complaints, reported breaches and experience from earlier inspections. If a sector appears in the plan, it signals recurring problems and heightened regulatory risk.
For organisations in the selected sectors, this is a real opportunity: they have time to review their arrangements and fill gaps before the authority does it for them.
Five Sectors in Scope in 2026
The 2026 plan covers five categories of entities:
Bodies processing data in EU large-scale systems. A continuation of 2025 inspections concerning processing in systems such as SIS and VIS.
Healthcare entities — CCTV monitoring. Inspectors will check the security of data when using monitoring in healthcare facilities, with particular attention to children’s data (for example on paediatric wards). Key issues will be the necessity and proportionality of monitoring, especially in rooms where health services are provided.
Entities running Public Information Bulletins (BIP). Here UODO highlights two threads: anonymisation and the publication of municipal council session records. This is a sensitive intersection of the right to public information and data protection.
Marketing entities. The main focus will be the legal bases for processing data for marketing purposes — consent or legitimate interest — and, for consent, particularly how it was obtained. The scope is not limited to agencies: it covers all organisations doing marketing with personal data, including those using CRM and marketing automation systems, sending newsletters or running prospecting (cold outreach).
Online delivery platforms. Inspections will concern the processing of data in connection with intermediation in the sale of goods and services via internet applications.
Why This Matters for Small Businesses
Two of the selected sectors — marketing and online delivery platforms — are areas where a great many micro and small enterprises operate. And here comes a key point: in higher-risk sectors, UODO does not provide any leniency for smaller entities. If a company runs marketing or sells through an e-commerce app, the authority will assess the legality of consents, profiling and record-keeping just as it would for a large enterprise.
What is more, staying off the plan does not mean peace of mind. An inspection may also be triggered by a complaint or a reported breach, and at every inspection UODO verifies the general GDPR requirements — documentation, security and risk management. The plan sets priorities, but it does not exhaust the authority’s field of action.
What UODO Actually Looks At
Enforcement statistics are a good complement to the plan. Summaries show that in 2025 the vast majority of administrative fines (over 60%) concerned inadequate data security — a lack of appropriate technical and organisational measures, misconfigurations, no testing of safeguards, or the use of outdated technologies. A significant share of decisions (around 56%) also concerned failures in documenting the controller’s actions — situations where it was impossible to show that procedures had actually been implemented or to present documentation confirming compliance.
The conclusion is simple: regardless of sector, two areas decide the outcome of an inspection — genuine data security (Article 32 GDPR) and the ability to demonstrate compliance (accountability, Article 5(2) GDPR). This is not “paper for paper’s sake” — it is the evidence the authority will demand.
How a UODO Inspection Works
It is worth knowing what to expect. An inspection is carried out on the basis of a named authorisation, and its duration may not exceed 30 days from when the authorisation is presented. During the inspection, inspectors may request access to IT systems, documentation and correspondence, and obtain explanations from employees. Obstructing the inspection or failing to cooperate exposes the entity to additional sanctions, regardless of the merits. After the inspection, administrative proceedings may be opened, leading to a decision — from a reprimand to an administrative fine.
How to Prepare Your Company — A Practical Checklist
Preparing for an inspection is, in essence, bringing the organisation into GDPR compliance. It is worth going through the following areas:
- Legal bases for processing — especially in marketing: verify whether you rely on consent or legitimate interest, and whether consents were obtained correctly (freely given, specific, informed).
- Up-to-date documentation — policies, the record of processing activities (ROPA), privacy notices, procedures.
- Data processing agreements — with tool providers (CRM, marketing automation, platforms, hosting, cloud).
- Risk analysis and security measures — genuine implementation of Article 32 measures, their testing and updating.
- Breach procedure — readiness to assess and report a breach to UODO within 72 hours.
- Handling data subjects’ rights — procedures for access, erasure, objection, portability.
- Monitoring — if you use it, verify necessity and proportionality (especially in healthcare facilities).
- DPO and conflict of interest — check that the officer is genuinely independent and that the conflict analysis has been documented.
- Inspection readiness — establish who is responsible for contact with the authority and where the complete, up-to-date documentation is kept.
A GDPR Audit — The Best Preparation for an Inspection
The most effective way to prepare is a GDPR audit — a “dry run” inspection carried out before the authority does it. A well-conducted audit identifies gaps in legal bases, documentation and safeguards, assesses the real risk, and ends with a concrete remediation plan. As a result, you fix any shortcomings on your own terms — not under the pressure of ongoing proceedings and the threat of a fine.
If your company operates in one of the sectors covered by the 2026 plan — marketing, delivery platforms, healthcare — an audit is particularly advisable. But even outside those sectors, a compliance review ahead of a potential inspection is the cheapest form of risk management.
Checklist — UODO Inspection Readiness
- Verified legal bases for processing (especially marketing).
- Up-to-date documentation: policies, ROPA, privacy notices.
- Data processing agreements concluded with all providers.
- Risk analysis carried out and documented; Article 32 measures implemented.
- Breach-handling procedure (72-hour reporting).
- Procedures for handling data subjects’ rights.
- Monitoring compliant with necessity and proportionality.
- An independent DPO and a documented conflict-of-interest analysis.
- A designated contact for the authority and well-organised documentation.
Need to Prepare Your Company for a UODO Inspection?
The 2026 sectoral inspection plan shows that UODO is paying ever closer attention to sectors where smaller businesses operate — and does not treat them leniently. The best time to review compliance is before an inspection. At the Law Office of Dr Joanna Maniszewska-Ejsmont, we carry out GDPR audits — from legal bases and documentation, through security measures, to inspection readiness — ending with a concrete remediation plan.

Check the details of our GDPR audit service and get in touch — we will help you prepare your organisation before UODO does it for you.
