< Back to all clusters
[TECHNOLOGY] · Poland · 8 sources

started · updated

Poland advances cybersecurity laws and data center infrastructure

Poland is undergoing significant digital and cybersecurity transitions. Under the amended National Cybersecurity System (KSC) law, which implements the EU NIS 2 directive, companies in critical sectors—including energy, transport, banking, and water supply—must identify their status as key or important entities by October 2026 to avoid penalties.

Simultaneously, the nation is preparing for a massive expansion in digital infrastructure. Polskie Sieci Energetyczne (PSE) projects that data center capacity will grow from under 250 MW to over 3 GW by 2036 and 5 GW by 2040. This growth is seen as vital for economic competitiveness and data sovereignty, especially as the EU moves toward the Cloud and AI Development Act.

On the regulatory front, the Ministry of Digital Affairs has proposed the ‘Cyber Piątka’ package to strengthen medical data protection through certification and minimum technological requirements. Additionally, the Ministry of Justice has proposed requiring banks and ATM operators to record user images for 90 days to combat payment fraud, with potential fines for individuals who intentionally obscure their faces.

Entities

European Commission · Krajowy System Cyberbezpieczeństwa · Krystian Pypłacz · Ministerstwo Cyfryzacji · Ministerstwo Sprawiedliwości · Polski Związek Centrów Danych · Polskie Sieci Energetyczne · PwC Polska