started · updated
Poland's KSeF e-invoicing system faces security and compliance concerns
Poland's implementation of the National e-Invoicing System (KSeF) is raising significant operational and security concerns for businesses. While the system is becoming mandatory for VAT settlements, companies are facing practical challenges. Some businesses report receiving invoices outside the system via PDF or paper, leading to uncertainty regarding the ability to deduct input VAT.
Security concerns have also been raised regarding the system's infrastructure. Critics point to the use of Imperva for security gateway services—a company owned by the French group Thales—and the use of Israeli-based analytical servers. Furthermore, the system's anonymous search function, which allows users to download XML or PDF documents using only five specific data points (document number, invoice number, NIP, name, and total amount), is cited as a potential vulnerability for data theft and cyberattacks.
In related tax compliance matters, the National Revenue Administration has clarified rules regarding payments made to bank accounts not listed on the VAT white list. A recent individual interpretation confirmed that while such errors can be corrected through a refund and re-payment to the correct account, the tax cost can only be recognized in the year the corrective payment is made, potentially requiring a CIT-8 tax return correction.
Entities
Imperva · KSeF · Krajowy System e-Faktur · National Revenue Administration · Thales