# Poland

> Poland (KNF · GIIF): The one EU state with no functioning licensing regime. Region: Europe. Regime still forming: No settled rule on confidentiality yet; the framework is in draft or newly in force.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Europe
- Subject: The one EU state with no functioning licensing regime
- Authority: KNF · GIIF
- Stance on on-chain confidentiality: Regime still forming. No settled rule on confidentiality yet; the framework is in draft or newly in force.
- Tags: no national act, presidential veto, no competent authority, passporting in
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-poland

## What it actually says

Poland is the exception that shows how the EU framework behaves when a member state cannot implement it. Three presidential vetoes have blocked the national act, so no authority has been designated to licence providers. Meanwhile the European deadline passed regardless: since July 2026, serving the Polish market without authorisation breaches Union law, and the only lawful route in is cross-border activity by firms licensed elsewhere. Around two thousand registered operators are caught between the two. The substance of the dispute is directly relevant here, because the objections concerned how long a regulator may freeze accounts and block domains without a court, which is the supervisory-power question underneath most privacy arguments.

## The instruments that matter

- **Three presidential vetoes**: the crypto market bill was vetoed on 1 December 2025, again on 12 February 2026, and a third time in June 2026 after the Sejm passed a revised version on 15 May 2026
- **No competent authority designated**: the vetoed bill would have empowered the financial supervision authority to supervise the market, licence operators and impose penalties; without it, the regulator cannot grant authorisations
- **The perimeter closed anyway on 1 July 2026**: providing crypto-asset services without authorisation from that date breaches Union law, leaving cross-border service by firms licensed in other member states as the only lawful route
- **Roughly 2,000 registered firms in limbo**: with no domestic licensing path, operators have been seeking authorisation in other member states and passporting back

## Sources

- [Why Poland is the only EU country where firms cannot get a licence](https://www.coindesk.com/policy/2026/07/01/why-poland-is-the-only-eu-country-where-crypto-firms-can-t-get-a-mica-license)
- [Third veto and the deadline](https://www.cryptotimes.io/2026/06/12/poland-president-vetoes-crypto-bill-for-third-time-triggers-mica-deadline-crisis/)

## Related entries

- [Ukraine](https://www.sodalabs.xyz/privacy-hub/regulation/jur-ukraine): The law that passed and never commenced
- [Austria](https://www.sodalabs.xyz/privacy-hub/regulation/jur-austria): EU baseline, with an early transition close
- [Belgium](https://www.sodalabs.xyz/privacy-hub/regulation/jur-belgium): EU baseline, with no national layer on confidentiality
- [Czechia](https://www.sodalabs.xyz/privacy-hub/regulation/jur-czechia): EU baseline, supervised by the central bank
- [Denmark](https://www.sodalabs.xyz/privacy-hub/regulation/jur-denmark): EU baseline, with tax as the historic pressure point
- [Estonia](https://www.sodalabs.xyz/privacy-hub/regulation/jur-estonia): The licence cull that reshaped the European market
