Art. 398 of Polish Electronic Communications Law in B2B: Eight Criteria for Valid Opt-in Consent

·Article·6 min read·Roman Ledak

Most B2B companies have opt-in consent that does not meet the requirements of Art. 398 PKE – and the validity of consent is determined by specific statutory conditions, not merely by its existence.

Most Polish B2B companies today hold consent in their CRM that, under Art. 398 PKE, does not exist at all – and they only discover this during an inspection or lawsuit. The compliance gap in Polish B2B outbound is widening with the entry into force of Art. 398 PKE, as many companies still believe they have some form of consent, while the implemented structure does not meet statutory criteria and does not protect against UKE sanctions or the personal liability of board members.

Consolidation that invalidated old compliance processes

The Electronic Communications Law of July 12, 2024 consolidated existing regulations contained in Art. 172 of the Telecommunications Law and Art. 10 of the Act on Providing Services by Electronic Means, creating a uniform regime for commercial information and direct marketing. Art. 398 PKE also covers B2B relationships, as contact with a named employee address (john.doe@...) or with a sole proprietor requires prior consent, regardless of the business nature of the relationship. Consequently, popular practices of acquiring databases from public registries or cold calling random numbers have become, as a rule, unlawful.

Public availability of contact details in CEIDG or on websites is not equivalent to consent for marketing contact. The law requires that consent be prior, voluntary, specific, informed, unambiguously expressed, separated by communication channels and purposes, easy to withdraw, and capable of being documented. Separating consent by channels means that one general “marketing consent” checkbox is not enough, as the company must demonstrate separate consent for email, phone, SMS, instant messengers, push notifications, and automatic calling systems, and for a specific processing purpose. The burden of proof rests with the administrator, who must be able to present to the authority the exact moment, form, and content of the expressed consent.

Penalty, the higher of two amounts - what false opt-in costs

For violations of Art. 398 PKE, the President of the Office of Electronic Communications can impose a penalty equal to the higher of two amounts: 3% of the revenue generated in the previous calendar year or PLN 1,000,000. For a company with revenue of PLN 50 million, the sanction can reach PLN 1,500,000. The “higher of two amounts” mechanism means that the penalty scales with the company's growth – the greater the success of outbound, the greater the exposure, so postponing the opt-in process fix systematically increases the stakes. For entities with revenues of several hundred million zlotys, the sanction realistically approaches the 3% turnover limit and threatens financial liquidity and investment capacity.

Concurrently, UODO is authorized to impose a separate penalty of up to EUR 20 million or 4% of annual turnover if the same consent does not meet GDPR requirements. The same flawed consent constitutes a violation of both PKE and GDPR, so UKE and UODO penalties can be applied simultaneously.

The myth that “anything goes in B2B” is no longer valid

Art. 398 PKE also covers B2B relationships, as contact with a named employee address or a sole proprietor requires prior consent, regardless of the business nature of the relationship. Public availability of contact details in CEIDG or on websites is not equivalent to consent for marketing contact. Acquiring mailing lists from intermediaries, using publicly available addresses from CEIDG or websites, and cold calling random numbers have become, as a rule, unlawful without prior, valid opt-in consent from the specific recipient.

Implied, hidden, forced, or overly general consents do not meet the requirements of PKE and GDPR. Typical violations include pre-ticked checkboxes and consent implied by silence, consent hidden in terms and conditions or fine print, consent forced as a condition for service provision, and one general “marketing consent” field instead of separate options for email, phone, SMS, and instant messengers.

Eight criteria for valid opt-in in 2026

1. Prior Consent

Consent must be given before marketing activities begin. Test question: Does the form require selection before the first contact? Typical violation: sending an email requesting consent.

2. Voluntary Consent

Consent must not result from coercion or dependence on service provision. Test question: Is selection a condition for purchase or registration? Typical violation: checkbox required to place an order.

3. Specific Consent

Consent must relate to precisely defined purposes. Test question: Are the purposes precisely listed? Typical violation: general wording “marketing purposes”.

4. Informed Consent

Consent must be preceded by clear information about its consequences. Test question: Does the user see the full scope of processing before giving consent? Typical violation: lack of information about channels and purposes.

5. Unambiguously Expressed Consent

Consent must be expressed through a conscious action by the recipient, without presuming consent from silence or default settings. Test question: Does the system record an active action? Typical violation: pre-ticked fields.

6. Consent Separated by Channels and Purposes

Consent must be separate for each channel and purpose. Test question: Does the form contain separate checkboxes for email, phone, and SMS? Typical violation: one “marketing consent” checkbox.

7. Easy to Withdraw Consent

Consent must be possible to withdraw at any time in a manner no more difficult than giving it. Test question: Is the unsubscribe link visible and works with one click? Typical violation: requiring a phone call or letter.

8. Documentable Consent

Consent must be documented in a way that allows for the reconstruction of the circumstances under which it was given. Test question: Does the CRM store the timestamp, form, and content of the consent? Typical violation: only recording the declaration without an audit trail.

Enforcement will come from the market, not just the office

According to Art. 398 sec. 4 PKE, sending commercial information without valid consent constitutes an act of unfair competition, which opens the way for competitors to civil claims for damages and cessation of practices. Enforcement initiative shifts from the office to the market, and a competitor adhering to Art. 398 has an economic interest in suing. UOKiK may treat mass spam as a practice infringing collective consumer interests. Board members may bear personal liability under the Commercial Companies Code if they allowed gross violations of the law – lawsuits may be brought by the company, shareholders, or creditors, and liability extends to private assets and professional reputation. Unawareness of the invalidity of consent does not protect the board. Supervisory boards and investors increasingly demand evidence of real, not merely declarative, compliance.

Opt-in as a lead quality filter

Legal opt-in acts simultaneously as a protective mechanism and a lead quality filter – a process where consent is obtained before the first email contact eliminates the risk of a burned domain and wasted resources on audits and field delegations to individuals who have never given consent. Salespeople then receive only contacts with confirmed cooperation potential – the database stops generating refusals and questions “where did you get my number?”. A precise voice from an ICP in the RES sector states: “Salespeople expect leads on a silver platter, and the call center books us with people without connection conditions for a PV farm. We waste thousands of zlotys on pointless audits and field delegations.” Halting outbound kills sales momentum, continuing it on false consents inflates risk – legal opt-in is the only middle ground.

AGAPE Architecture

AGAPE provides an architecture that implements these requirements in practice, ensuring compliance with Art. 398 PKE already at the stage of the first contact. The architecture that obtains consent before the first email contact is part of the Zero-Hallucination Architecture pillar. Consent documentability is recorded in the system instead of declarations in the CRM. The separation of channels and purposes occurs at the configuration level.

Go through the eight-point checklist with your own form and write in the comments which point proved most difficult to demonstrate to the authority. How do you currently obtain marketing consent in your outbound process?

Key takeaways

  • Art. 398 PKE requires separate, prior consent for each B2B marketing communication channel, eliminating the legality of using public databases without opt-in.
  • Penalties for violating PKE provisions amount to the higher of two sums: 3% of the company's annual revenue or PLN 1,000,000, regardless of sanctions imposed by UODO.
  • Having a profile in CEIDG or publishing an email address on a website does not constitute implied consent for email marketing or cold calling.
  • The requirement for documented consent obliges the administrator to record the exact timestamp, form, and content of the expressed opt-in in the CRM system.

Frequently asked questions (FAQ)

What penalties are imposed for sending cold emails and B2B spam in Poland?
The President of UKE (Office of Electronic Communications) can impose a penalty of up to 3% of annual revenue or PLN 1,000,000 (the higher of the two amounts). Independently, UODO (Personal Data Protection Office) is authorized to impose a penalty of up to EUR 20 million or 4% of turnover for GDPR violations, and aggrieved competitors can file civil lawsuits.
Is one general marketing consent checkbox sufficient in B2B?
No, consent must be precisely separated by communication channels and purposes. The form must include separate consents for email, telephone, SMS, and automatic calling systems.
How to prove the validity of opt-in consent before a UKE inspection?
The administrator is obliged to present exact evidence documenting the moment consent was given, including the timestamp, form, and precise content of the clause. A mere record of the declaration in the CRM database without hard system logs is insufficient.
Are board members personally liable for the lack of outbound consent?
Yes, board members may bear personal financial responsibility under the Commercial Companies Code for allowing egregious violations of law. Unawareness of the invalidity of consents in the company's sales processes does not relieve the board of responsibility.

Does your current consent acquisition process meet the requirements of Art. 398 PKE – tell us in the comments how you obtain opt-in.

Keep reading