UODO Inspection Step by Step — How It Works and How to Prepare
A UODO inspection can cause concern, especially if a company has never dealt with the supervisory authority before. Most of the uncertainty usually comes from not knowing who may arrive, what they may request and how long the inspection may last.
However, the course of an inspection is regulated in detail by the Polish Data Protection Act. Knowing the procedure helps avoid chaos and organise cooperation with the inspectors properly. It also has practical value. The inspected organisation has not only obligations, but also specific rights. The scope of the authorisation, the way inspection activities are conducted and the right to submit objections to the inspection report are particularly important.
In this article, I explain step by step how a UODO inspection works. I also show how an organisation can prepare and what to expect after the inspection ends.
When Can UODO Carry Out an Inspection?
The President of UODO may conduct inspections under an approved inspection plan. An inspection may also result from information obtained by the authority or from its monitoring of GDPR compliance. In practice, this means that an inspection may be planned or initiated in response to a specific situation. A complaint, a reported personal data breach or information suggesting possible irregularities may all trigger an inspection.
The scope of sector-specific inspections changes from year to year. The 2026 inspection plan included, among others, marketing entities, healthcare providers and organisations operating Public Information Bulletins. UODO also planned inspections of authorities using large-scale EU information systems. In September 2026, the authority expanded inspections in the healthcare sector. At the same time, inspections of online delivery platforms were moved to the first two quarters of 2027.
The Polish Data Protection Act does not establish a general obligation to provide advance notice of an inspection. Therefore, an organisation should also be prepared for a situation in which there is little time to organise documentation beforehand.
Who Conducts the Inspection and How Does It Begin?
The inspection is conducted by a person authorised by the President of UODO. As a rule, this will be an employee of the Office. In certain cases, a representative of another EU supervisory authority may also participate. If the matter requires specialist expertise, the President of UODO may involve an additional expert. This may, for example, be someone with specialist technical knowledge.
The inspection begins after the inspector presents a personal authorisation and official ID. The authorisation should indicate, among other things, the legal basis, the inspected entity and the scope of the inspection. It also includes the start date and expected completion date. For this reason, the document should be read carefully at the outset. The subject-matter scope of the inspection is particularly important. It defines the boundaries within which inspection activities should remain. If justified doubts arise about an inspector’s impartiality, the law provides for the possibility of excluding that person. The President of UODO decides on such exclusion.
How Long Can a UODO Inspection Last?
The law sets a maximum duration for an inspection. As a rule, it may not last longer than 30 days. The period runs from the date the authorisation and the inspector’s identity document are presented. However, the time allowed for signing the inspection report is not included in those 30 days. The period for submitting objections to the report is also excluded. The inspection ends when the inspected entity signs the report. If the entity refuses to sign it, an appropriate note is added to the report.
What Powers Do Inspectors Have?
Inspectors have broad powers. However, this does not mean that they may examine any area of the organisation’s activity. Their actions should remain connected to the scope indicated in the authorisation.
Inspectors may, among other things:
- enter the organisation’s premises and rooms between 6:00 a.m. and 10:00 p.m.,
- review documents and information directly related to the scope of the inspection,
- inspect devices, data carriers and systems used for processing personal data,
- request written and oral explanations,
- question witnesses where necessary to establish the facts,
- commission expert opinions and assessments.
The inspected organisation must also provide the conditions necessary for the inspection to proceed efficiently. It may be required, among other things, to prepare copies or printouts of documents. If the connection between a specific request and the inspection is unclear, it is worth asking the inspectors to clarify it. This helps avoid providing accidental or unnecessary materials.
Rights and Obligations of the Inspected Organisation
Cooperation with inspectors is mandatory. Obstructing or preventing an inspection may result in criminal liability. The law provides for a fine, restriction of liberty or imprisonment of up to two years.
However, cooperation does not mean passively providing every piece of information without oversight. The organisation should structure its communication from the beginning. It is useful to appoint one person to coordinate document sharing and communication with UODO. It is also worth keeping a record of the materials provided. This makes it possible to track which documents the inspectors received and when.
Explanations should be factual, accurate and responsive to the question asked. There is no need to expand answers into areas unrelated to the inspection. It is also useful to ensure the availability of people who genuinely understand the processes under review. This may be the DPO, an IT, HR or marketing employee, or the person responsible for a particular system.
The Inspection Report — a Document That Should Not Be Signed Automatically
After completing the inspection activities, the inspectors prepare an inspection report. The document includes, among other things, the scope and dates of the inspection and a description of the facts established. It should also include information relevant to the later assessment of processing compliance. The report is extremely important because it records the findings made during the inspection. It should therefore not be treated as a mere formality.
The inspected organisation has 7 days from receiving the report to sign it or submit written objections. If the objections are justified, the inspectors may amend or supplement the relevant part of the report. They may also conduct additional inspection activities. If the objections are rejected, the organisation should receive information together with the reasons. It is therefore worth using the available time to compare the report carefully with the documents and the actual course of the inspection.
What Happens After the Inspection?
The inspection itself does not mean that a fine will be imposed. Its main purpose is to establish the facts. If the information collected indicates a possible infringement, the President of UODO initiates separate administrative proceedings. This follows directly from Article 90 of the Polish Data Protection Act. Only in those proceedings does the authority make a legal assessment and apply measures provided for under the GDPR.
Depending on the case, this may include a warning, an order to bring processing into compliance or a restriction on processing. In certain cases, the authority may also impose an administrative fine. It is therefore important to distinguish between the two stages. The inspection primarily establishes the facts. The administrative proceedings lead to a formal decision.
The Role of the DPO and Lawyer During an Inspection
The DPO can play an important role during an inspection. The officer knows the organisation’s documentation, previous analyses and adopted data protection solutions. They can therefore explain how the compliance framework works and support communication with the authority. However, the proper allocation of responsibilities must be maintained.
The DPO advises and monitors compliance, but does not replace the controller or management. The officer should also not assume responsibility for the organisation’s business decisions. Legal support is particularly useful when analysing the scope of the inspection and preparing the organisation’s position. It may also be highly valuable when drafting objections to the inspection report and in subsequent proceedings.
How to Prepare a Company Before an Inspection Begins
The worst time to organise the entire GDPR framework is the day the inspection starts. It is therefore worth preparing a simple internal procedure in advance. The organisation should know who receives the inspectors, who contacts management and who is responsible for documents. It is also useful to define how the DPO, IT department and legal counsel will be involved.
Documentation should be up to date and consistent with actual practice. UODO highlights, among other things, the importance of records of processing activities, procedures, risk assessments and data processing agreements. Technical safeguards, system update rules and backup procedures should also be reviewed in advance. UODO also recommends checking whether recommendations from previous audits have been implemented. A GDPR audit remains a useful preparation tool. It allows the organisation to conduct its own assessment before the supervisory authority does.
Common Mistakes During a UODO Inspection
No established procedure. Employees do not know who to notify or who is authorised to provide documents.
Failure to verify the authorisation. The organisation does not check the scope of the inspection and operates without clearly defined boundaries from the outset.
Chaotic document sharing. There is no record of the materials provided to inspectors.
Overly extensive explanations. Responses go far beyond the questions asked and the subject matter of the inspection.
Obstructing inspection activities. Failure to cooperate may lead to serious legal consequences.
Automatically signing the report. The organisation does not use the seven-day period to review the findings and submit objections if necessary.
Organising GDPR compliance only during the inspection. Documentation should reflect the organisation’s earlier and actual practice.
UODO Inspection — Practical Checklist
- Check the authorisation and the inspector’s ID, especially the scope and expected duration of the inspection.
- Notify the responsible persons, including management, the DPO and, where appropriate, legal counsel.
- Appoint a person to coordinate the inspection and communication with UODO.
- Provide inspectors with appropriate conditions for carrying out their activities in accordance with the law.
- Keep a record of documents, copies and information provided.
- Provide factual and precise explanations corresponding to the scope of the inspection.
- Involve employees who understand the processes and systems under review.
- Review the inspection report carefully before signing it.
- If necessary, use the seven-day period to submit objections.
- After the inspection, prepare for further proceedings if the authority identifies a possible infringement.
Do You Need Support During a UODO Inspection?
A UODO inspection follows a formally defined procedure. In practice, however, the way the organisation manages the inspection can have a significant impact.
At Dr Joanna Maniszewska-Ejsmont Law Firm, we support organisations both before and during UODO inspections.
We help verify the scope of the inspection, structure communication with the authority and prepare the necessary explanations. We also analyse the inspection report and prepare objections to its contents. If further proceedings are initiated, we provide legal support and representation before the President of UODO. We can also conduct an audit in advance and prepare the organisation for a potential inspection.

SkoContact us — we will help you organise the process and go through the inspection in accordance with the procedure and without unnecessary disruption.
