What is PPK?
In short: according to the Act of October 4, 2018 on Employee Capital Plans (hereinafter referred to as the “PPK Act”), every company/institution that employs at least one person subject to mandatory pension and disability insurance must open a PPK for its employees and contractors (hereinafter referred to as “employees”). PPK are managed by a financial institution based on a PPK management agreement concluded by the employer on behalf of and for the benefit of the employees.

Organizations join the program gradually: after the largest entities employing over 250 people, it was time for smaller ones – first those employing up to 50 people (date of joining PPK: January 1, 2020), then up to 20 people (July 1, 2020), and finally all remaining employing entities (January 1, 2021). The funds accumulated within the PPK, thanks to contributions made by the employee, the employer, and to a small extent also by the state, will be paid out to the employed person (i.e., the PPK participant) upon reaching the age of 60 (regardless of gender and retirement age).
When does GDPR come into play?
Some may think that managing PPK is simply part of the activities performed on employee data, which is why, with an employment process properly adapted to the requirements of GDPR, there is no need to take any additional actions in this regard. Nothing could be further from the truth. Activities related to the management of PPK constitute another processing operation, aimed at a separate processing purpose and therefore requiring specific personal data of employees – in some cases exceeding the scope of data that the employer has about their employee.
What scope of data should the employer obtain from the PPK participant and on what basis?
Employee data that, in accordance with the Act on Employee Capital Plans (PPK), the employer is obliged to collect from the employee and transfer to the appropriate financial institution, referred to as the identifying data of the PPK participant, includes: first name(s), last name, residential address, correspondence address, phone number, email address, PESEL number or date of birth in the case of individuals without a PESEL number, series and number of the identity card or passport number or another document confirming identity in the case of individuals who do not hold Polish citizenship (Article 2(1)(3) of the Act on PPK).
On what legal basis does the employer process the PPK participant's data? The Polish Data Protection Authority (UODO), after weeks of heated discussions among practitioners and employers who had to deal with PPK, issued a position confirming that the acquisition of identifying data occurs on the basis of the premise from Article 6(1)(c) of the GDPR, i.e., a legal obligation imposed on the data controller. It should be noted that, according to Article 221 § 4 of the Labor Code, the employer requests other data than those specified in § 1 and 3 of this article when it is necessary to fulfill an obligation arising from a legal provision – in this situation, the legal provision is indeed the Act on PPK. Without acquiring the identifying data of the PPK participant, the employer is unable to conclude a contract with the chosen financial institution and thus fulfill the obligations imposed on them by the law.
Employee's email address and phone number
Importantly, the same legal basis for processing will also apply to the employee's email address and phone number, but only if the employer possesses this data. Of course, it may happen (especially in the case of older individuals) that the employee does not have an email account or phone.
As indicated by the Polish DPA, there is no provision in the Polish legal system that imposes an obligation on an individual to have such means of communication. Therefore, if an employee has nothing to provide in the fields for email address and phone number, they do not provide anything, and the agreement for the management of the Employee Capital Plans (PPK) can still be concluded and executed.
Note
The employer does not need to obtain separate consent from the employee for the processing of data in the form of a phone number and email address.
Employer and financial institution – sharing data between data controllers or a data processing relationship?
The financial institution as an entity managing the PPK is considered a separate and independent data controller. It is the financial institution, as a party to the agreement with the PPK participant, that bears specific legal obligations arising from the PPK Act. Moreover, the legal relationship between the financial institution and the PPK participant continues even after the termination of employment with a given employer. Therefore, it cannot be concluded that the financial institution acts in any way on behalf of and for the employer – the institution is a separate data controller that processes the personal data of PPK participants in its own name and based on separate legal grounds for processing.
The situation is similar from the perspective of the employer processing the personal data of employees. Some may find the wording taken directly from the PPK Act misleading, suggesting that the employer enters into an agreement with the financial institution for the management of the PPK "on behalf of and for" the employee who has expressed a desire to join the program. However, this does not affect the fact that the employer, in connection with the opening and servicing of the PPK, processes data in the capacity of their "owner," that is, as a data controller. The employer does not act on the instructions of the financial institution in any way but operates independently, fulfilling the obligations imposed on them by law. For this reason, it cannot be concluded that there is a data processing relationship between the financial institution and the employer regarding the processing of employee data. The employer collects data from employees and then shares it with the selected financial institution on the basis of a data controller – data controller relationship.
How long can the employer retain data in connection with the PPK?
Unfortunately, the Act on Employee Capital Plans (PPK) does not explicitly determine the duration for which documentation related to PPK should be retained. A significant number of practitioners hold the view that, according to Article 29(2) of the Act on PPK, this data should be retained until the statute of limitations for claims related to PPK payouts expires, i.e., for 5 years from the date on which the contributions became due.
This position is not shared by the Polish DPA, which on one hand warns data controllers that data should be processed in accordance with the principle of data retention limitation, as stipulated in Article 5(1)(e) of the GDPR, and on the other hand assumes that PPK is a system closely related to the documentation concerning the determination of employee remuneration, therefore, in accordance with Article 125a(4a) of the Act on Pensions and Disability Pensions from the Social Insurance Fund and Article 94(9b) of the Labour Code, the retention period for such documentation should be 10 years. The fact that funds from PPK are paid out independently and do not affect the determination of the right to a pension or disability pension in any way has been overlooked in the position of the Polish DPA. Nevertheless, the guidelines of the Polish DPA from September 2019 remain current in this regard, thus for complete safety, data controllers should comply with these instructions and stay alert for any potential changes to this position in the future.
What obligations does an employer have who has opened a PPK for their employees?
Employer, recruiter, candidate.
GDPR in HR.
- consideration of the processing of data related to the Employee Capital Plans (PPK) as one of the processing activities in the records of processing activities referred to in Article 30(1) GDPR;
- analyzing whether the processing of data within the framework of PPK may pose a high risk to the rights or freedoms of natural persons, and if so – conducting a Data Protection Impact Assessment (DPIA) as referred to in Article 35 GDPR;
- fulfilling the information obligation towards employees in connection with the purpose of taking actions related to PPK. When creating the appropriate privacy notice or modifying the currently used one, attention should be paid to the purpose of processing (in connection with the fulfillment of legal obligations arising from the management of PPK), the data retention period (analogous to the duration of employee documentation retention), and the recipients, among whom a financial institution should be distinguished;
- consideration of the data retention period for documentation related to PPK in the data deletion procedure functioning within the organization and conducting periodic data reviews and deletions.
Summary
In November 2019, the Polish Development Fund estimated that in the first phase, 39% of employees in the largest companies (employing over 250 employees) decided to join PPK, which amounts to approximately 1–1.2 million people, with this number potentially increasing to 5 million as the program develops. These figures speak volumes about the scale of data processing related to PPK and the enormous responsibility of data controllers for its efficient handling and the importance of this task.
Employers should therefore mobilize and take all possible actions that will allow them not only to effectively implement the programs in their organizations but also to efficiently adapt them to the requirements of personal data protection regulations. We hope that the above guidelines will facilitate this process somewhat.


