podatki.gov.pl - Information Clause of the Minister of Finance and Economy

Information Clause of the Minister of Finance and Economy

Data publikacji: 7/6/2026
Data aktualizacji: 10/5/2026

According to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, as amended), hereinafter referred to as the GDPR, the Controller advises that:

1. IDENTITY AND CONTACT DETAILS OF THE CONTROLLER 

The Controller of your personal data is the Minister for Finance and Economy, who can be contacted by writing to the following address:

  • ul. Świętokrzyska 12, 00-916 Warszawa
  • ePUAP inbox: /bx1qpt265q/SkrytkaESP
  • email: kancelaria@mf.gov.pl
  • electronic service address (ADE): AE:PL-83190-36017-RFBJU-21

2. CONTACT DETAILS OF THE DATA PROTECTION OFFICER 

The Data Controller has appointed a Data Protection Officer, who can be contacted by email at iod@mf.gov.pl. 

3. PURPOSE OF THE PROCESSING OF PERSONAL DATA AND LEGAL BASIS 

The processing of your personal data by the Controller is necessary for the Controller to comply with a legal obligation, as well as to carry out a task carried out in the public interest or in the exercise of official authority vested in the Controller, in accordance with the provisions of law, in particular the Act of 4 September 1997 on government administration departments, the Act of 16 November 2016 on the National Revenue Administration, and the Act of 29 August 1997—the Tax Ordinance.

4. INFORMATION ON DATA RECIPIENTS 

In connection with the processing of data for the purposes set out in point 3, the recipients of the personal data provided may be entities authorised to process such data in accordance with the law. A separate category of recipients comprises entities that process personal data on behalf of the Controller, in particular those with whom contracts have been concluded for the provision of maintenance services for the IT systems used by the Controller. 

5. DATA RETENTION PERIOD

Your personal data will be stored for the period necessary to fulfil the purposes of processing set out in point 3 or until the Controller’s obligations have expired; after this period, the data will be archived in accordance with the period specified by law.

6. RIGHTS OF DATA SUBJECTS 

The data subject has the right to:

  • access the data, pursuant to Article 15 of the GDPR, subject to the proviso that the personal data disclosed must not reveal classified information or breach any legally protected secrets that the Controller is obliged to maintain, and subject to Article 5 of the Act of 10 May 2018
    on the protection of personal data (Article 15 of the GDPR),
  • have their personal data rectified (Article 16 of the GDPR),
  • restrict the processing of their personal data (Article 18 of the GDPR), subject to the cases referred to in Article 18(2) of the GDPR,
  • object to the processing of their personal data (Article 21 of the GDPR), in the case of processing based on Article  6(1)(e) of the GDPR).

 

If the data subject finds that the processing of their personal data infringes the law, they have the right to lodge a complaint with the supervisory authority—the President of the Personal Data Protection Office.

7. INFORMATION ON MANDATORY OR VOLUNTARY PROVISION OF PERSONAL DATA 

The provision of personal data to the extent required by law is mandatory. 

8. INFORMATION ON AUTOMATED DECISION-MAKING, INCLUDING PROFILING

Your data may be processed in an automated manner, which may involve automated decision-making, including profiling, which is carried out by the Controller in accordance with applicable law.
 This applies to the following:

  • assessing the risk of infringement, where this assessment is based on data provided in submitted documents and established criteria,
  • assessing the risk of infringement, where the assessment is based on data obtained from publicly available registers and social networks, based on established criteria.

The consequence of the assessment in the above cases is automatic classification into a risk group, where classification into an unacceptable risk group may result in a change in the relationship and additional measures provided for by law. 

9. INFORMATION ON THE INTENTION TO TRANSFER PERSONAL DATA TO A RECIPIENT IN A THIRD COUNTRY OR AN INTERNATIONAL ORGANISATION

Your personal data may be transferred to third countries (outside the EEA) or to international organisations, where justified and in accordance with the relevant legal provisions.

Ustawienia prywatności