podatki.gov.pl - Information on the Processing of Personal Data by the Head of the National Revenue Administration

Information on the Processing of Personal Data by the Head of the National Revenue Administration

Data publikacji: 7/6/2026
Data aktualizacji: 10/5/2026

According to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, as amended), hereinafter referred to as the GDPR, the Controller advises that:

1. IDENTITY AND CONTACT DETAILS OF THE CONTROLLER

The Controller of your personal data is the Head of the National Revenue Administration, who can be contacted by writing to the following address:

  • ul. Świętokrzyska 12, 00-916 Warszawa
  • ePUAP inbox: /bx1qpt265q/SkrytkaESP
  • email: kancelaria@mf.gov.pl
  • electronic service address (ADE): AE:PL-83190-36017-RFBJU-21

2. CONTACT DETAILS OF THE DATA PROTECTION OFFICER

The Data Controller has appointed a Data Protection Officer, who can be contacted by email at iod@mf.gov.pl.

3. PURPOSE OF THE PROCESSING OF PERSONAL DATA AND LEGAL BASIS


The processing of your personal data by the Controller is necessary for the Controller to comply with a legal obligation, as well as to carry out a task carried out in the public interest or in the exercise of official authority vested in the Controller, in accordance with the provisions of law, in particular the Act of 16 November 2016 on the National Revenue Administration, the Act of 29 August 1997—the Tax Ordinance, and the Act of 13 October 1995 on the rules of registration and identification of taxpayers and tax remitters, for the purpose of carrying out the Controller’s statutory tasks, namely:

  • providing service and support to taxpayers and remitters in the proper fulfilment of tax obligations, and service and support to entrepreneurs in the proper fulfilment of customs obligations;
  • collection and reimbursement of taxes and customs duties and enforcement of State Treasury receivables;
  • control of trade in goods abroad;
  • combating tax, financial, and cross-border crime, including the prevention of money laundering and the financing of terrorism.

4. INFORMATION ON DATA RECIPIENTS

In connection with the processing of data for the purposes set out in point 3, the recipients of your personal data may be entities authorised to process such data in accordance with the law. A separate category of recipients comprises entities that process personal data on behalf of the Controller, in particular those with whom contracts have been concluded for the provision of maintenance services for the IT systems used by the Controller.

5. DATA RETENTION PERIOD

Your personal data will be stored for the period necessary to fulfil the purposes of processing set out in point 3 or until the Controller’s obligations have expired; after this period, the data will be archived in accordance with the period specified by law.

6. RIGHTS OF DATA SUBJECTS

The data subject has the right to:

  • access the data, pursuant to Article 15 of the GDPR, subject to the proviso that the personal data disclosed must not reveal classified information or breach any legally protected secrets that the Controller is obliged to maintain, and subject to Article 5 of the Act of 10 May 2018 on the protection of personal data (Article 15 of the GDPR),
  • have their personal data rectified (Article 16 of the GDPR),
  • restrict the processing of their personal data (Article 18 of the GDPR), subject to the cases referred to in Article 18(2) of the GDPR,
  • object to the processing of their personal data (Article 21 of the GDPR),

in the case of processing based on Article 6(1)(e) of the GDPR.

If the data subject finds that the processing of their personal data infringes the law, they have the right to lodge a complaint with the supervisory authority—the President of the Personal Data Protection Office.

7. INFORMATION ON MANDATORY OR VOLUNTARY PROVISION OF PERSONAL DATA

The provision of personal data to the extent required by law is mandatory.

8. INFORMATION ON AUTOMATED DECISION-MAKING, INCLUDING PROFILING

Your data may be processed in an automated manner, which may involve automated decision-making, including profiling, which is carried out by the Controller in accordance with applicable law. This applies to the following:

  • assessing the risk of infringement, where this assessment is based on data provided in submitted documents and established criteria.
  • assessing the risk of infringement, where the assessment is based on data obtained from publicly available registers and social networks, based on established criteria.

The consequence of the assessment in the above cases is automatic classification into a risk group, where classification into an unacceptable risk group may result in a change in the relationship and additional measures provided for by law.

9. INFORMATION ON THE INTENTION TO TRANSFER PERSONAL DATA TO A RECIPIENT IN A THIRD COUNTRY OR AN INTERNATIONAL ORGANISATION

Your personal data may be transferred to third countries (outside the EEA) or to international organisations, where justified and in accordance with the relevant legal provisions.

 

Ustawienia prywatności