A public email address does not constitute consent, and a B2B relationship does not exclude PKE. We explain how to conduct prospecting after the 2026 UODO inspection plan covers marketing entities.
In 2026, sales and marketing departments should re-examine outbound practices. The President of the Personal Data Protection Office (UODO) has included "marketing entities" in the 2026 sectoral inspection plan and announced an investigation into the legal basis for data processing in marketing. However, this does not mean the end of outbound sales. This means that a phone number or email address found in the CEIDG (Central Registration and Information on Business), the National Court Register (KRS), a website, or a social media account cannot automatically be considered consent to an offer.
What regulations must be met at the same time?
The legality of a campaign is assessed on two levels: the Electronic Communications Act (ECA) and the GDPR. Compliance with just one of these is not sufficient.
Article 398 of the Personal Data Protection Act prohibits the use of automated calling systems or telecommunications terminal equipment to send commercial information, including direct marketing, without the prior consent of the subscriber or end user. This provision covers, among others, email, telephone, text messages, and instant messaging. It also applies to B2B relationships. Sending an offer to an address such as biuro@spolka.pl may generally be outside the scope of the GDPR if the address does not identify a natural person, but is still subject to the Personal Data Protection Act requirements.
The GDPR, however, addresses the question of whether the data of a specific individual may be processed. An address like firstname.lastname@firma.pl, a direct telephone number, or a professional profile are generally considered personal data. The basis for this may be consent or, in appropriate cases, the legitimate interest of the controller under Article 6(1)(f) of the GDPR. This interest requires a documented balancing test. It is worth noting that even a positive test result does not replace the consent to use email or telephone required by the EPC.
We write more about the limits of legitimate interest in marketing in the article "Marketing based on legitimate interest – when does it not work?".
Can you ask for consent first?
Simply publishing contact information doesn't constitute marketing consent. A first, "neutral" email or phone call is risky if it's actually intended to present an offer or generate interest.
In summary: in the non-final judgment of the Provincial Administrative Court in Warsaw of 17 June 2025, file reference II SA/Wa 1971/24, the majority of the adjudicating panel found that a one-time contact with an entrepreneur whose data was publicly available in the CEIDG (Central Registration and Information on Business), solely for the purpose of establishing consent, did not constitute direct marketing. However, the judgment concerned a specific factual situation and the now-repealed Article 172 of the Telecommunications Law (replaced by the PKE); it also issued a dissenting opinion. Therefore, it does not constitute general consent to sending an offer in the first message. A more detailed discussion of this judgment can be found in our Law Firm's separate analysis.
The safest way to obtain consent is through inbound channels used by businesses: through a form, signing up for a webinar or newsletter, during an industry event, or in response to a customer's actual inquiry. Article 398, paragraph 2 of the Personal Data Protection Act allows for the provision of an electronic address to be considered consent, but only if the recipient provided it specifically for the purpose of receiving commercial information, and not for regular contact.
What results from the decision of the President of the Personal Data Protection Office?
As of August 4, 2026, no decision by the President of the Personal Data Protection Office (UODO) imposing a penalty directly for violating Article 398 of the Personal Data Protection Act (PKE) regarding cold mailing or cold calling has been published in the public database. Sanctions for this provision are imposed by the President of the Office of Electronic Communications (UKE). The UODO, however, examines the legality of data processing, and its 2026 inspection plan confirms that marketing is an area of heightened interest for the authority. You can read more about the scope of the announced inspections in our overview of the UODO plan.
The most recent UODO decision relevant to prospecting is the non-final decision of the President of the UODO of February 16, 2026, file reference DS.523.1901.2022. It concerned a company building a database of information on entrepreneurs from public sources, including the CEIDG, KRS, and GUS. The case was initiated by an individual's complaint about the processing of their personal data by the entrepreneur in violation of the law, in particular the failure to fulfill the information obligation referred to in Article 14 of the GDPR. The President of the UODO refused to uphold the complaint because the controller demonstrated compliance with the information obligation under Article 14 of the GDPR, including providing information about the source of the data, recipients, legitimate interest, and the individual's rights.
This decision does not automatically legalize the sending of offers for data from public registers. The database provider itself stated that it does not provide customers with a legal basis for marketing use of the data. Consequently, the database purchaser must independently assess the basis for GDPR use, comply with the disclosure obligation at the first contact, and—regardless of this—obtain the consent required by PKE.
In turn, in the final decision of the President of the Personal Data Protection Office of 16 October 2019, file reference ZSPR.421.7.2019, a fine of PLN 201,559.50 was imposed on the entrepreneur for hindering the withdrawal of consent and further processing of data of persons requesting the cessation of processing.
The practical conclusion remains valid: the answer "please do not write to me again" should trigger a simple blockade of further marketing in all systems and with all campaign implementers.
How to prepare a campaign for audit?
Before launching a campaign, a company should be able to prove the entire data lifecycle and consent. A vendor's blanket assurance that the database is "GDPR compliant" isn't sufficient. If you're a database buyer or have created one yourself and are wondering if you can use it for direct marketing:
- document the content, date and source of the consent, the channels covered and the entity to which it was granted;
- check the database provider's forms, the history of clause changes and the possibility of demonstrating consent for a specific advertiser;
- prepare a clause from Article 14 of the GDPR for data obtained indirectly and a legitimate interest test;
- keep a single register of consents, withdrawals and objections, as well as a block list to prevent a person from being added to the campaign again;
- ensure immediate transfer of cancellations between CRM, call center, agency and mailing tool provider;
- establish the roles of all campaign participants and regulate data entrustment or joint administration accordingly.
What are the penalties for lack of consent?
For violating Article 398 of the EPC, the President of the UKE may impose a fine of up to 3% of revenue generated in the previous calendar year or up to PLN 1 million, whichever is higher. Regardless of this, unlawful data processing may lead to the initiation of proceedings by the President of the UODO and, consequently, the imposition of sanctions under the GDPR. Violating the commercial information rules may also constitute an act of unfair competition and a misdemeanor.
FAQ: cold mailing and telemarketing in 2026.
Does an email address from CEIDG or the company website constitute consent?
No. Public availability of an address does not constitute consent to the sending of commercial information. The basis for data processing under the GDPR and consent to the contact channel under Article 398 of the Personal Data Protection Act must be assessed separately.
Does Article 398 of the PKE apply to B2B contacts?
Yes. The regulation protects every subscriber and end user, not just the consumer. Therefore, the company's email address, business phone number, and general address also require assessment under the EPC.
Does legitimate interest replace consent to email or telephone?
No. Article 6(1)(f) of the GDPR may legalize the processing of personal data under certain conditions, but it does not replace the consent required by PKE to use a specific marketing channel.
Can a purchased lead database be legal?
It may, but the buyer should verify the source of the data, the content and scope of the consents, the possibility of proving them, and compliance with the disclosure obligation. A broker's contractual declaration of "GDPR compliance" alone does not transfer liability to the database seller.
What to do after objecting or withdrawing consent?
Marketing activities must be immediately stopped within the appropriate scope and the data placed on a block list. Notice of opt-out must also be sent to call centers, agencies, and other vendors implementing the campaign.
Is it worth conducting a campaign audit?
Yes. Our law firm can assess lead sources, legitimate interest tests, information clauses, consent terms, data broker agreements, and objection handling. If your organization uses purchased databases, sales automation, or an external call center, it's worth reviewing these processes before the audit. Contact us and schedule a cold mailing or telemarketing audit.
Basics and sources
- UODO sectoral inspection plan for 2026, 8 January 2026.
- Decision of the President of the Personal Data Protection Office of 16 February 2026, DS.523.1901.2022 (not yet final).
- Decision of the President of the Personal Data Protection Office of 16 October 2019, ZSPR.421.7.2019 (final).
- Judgment of the Provincial Administrative Court in Warsaw of 17 June 2025, file reference II SA/Wa 1971/24 (not final).
- Act of 12 July 2024 – Electronic Communications Law, consolidated text as of 7 July 2026; Articles 398, 400, 446 paragraphs 5 and 448.
- Regulation (EU) 2016/679 (GDPR); Articles 6, 7, 13-14 and 21.
This article is for informational purposes only and does not constitute legal advice
Legal status as of August 4 , 2026
Author:
Series editor:
