Skip to main content
Virtual office7 July 2026

Virtual office and GDPR — data protection in practice (2026)

How to use a virtual office in line with GDPR: processing agreement (art. 28), address privacy, confidentiality of mail and a compliance checklist.

Natalia Wyszkowska — Office Manager at The Nest
Natalia Wyszkowska
Office Manager

Updated

Set The Nest as a preferred source in Google

Your search results will show our articles more often.

Virtual office and GDPR — personal data protection

Reading time

11

min

Virtual officePiękna 49

The short answer

Yes — a virtual office can be used in line with the GDPR. The starting point is not the one most people expect: the problem is not that the operator holds too much of your data. Some of it the operator is required by statute to collect and keep for five years. The rest comes down to a single document — the processing agreement.

Who is responsible
Your company is the controller, not the operator. It acts on your documented instructions — but the duty to vet whom you entrust the data to stays on your side.
What the law requires
A separate processing agreement under Article 28 GDPR. A service contract does not replace it, and entrusting data without one is a breach on the controller's side.
Why the operator knows your data
Because providing a registered address falls under anti-money-laundering law. The operator has a statutory duty to establish the client's identity and to retain the records — it cannot delete them on request.
Whose clock it is
After a breach you have 72 hours to notify the authority. The GDPR gives the operator no deadline at all — the processing agreement has to set one.
How it works here
We sign the processing agreement together with the main contract, and access to mail from the moment it enters the building until handover rests with reception alone.

Who is responsible for the data — you or the operator

Worth saying plainly, because it misleads people: outsourcing the back office lets a company concentrate on its operations, but it does not release it from responsibility for processing personal data. Outsourcing moves the work, not the responsibility for it.

Your company is the data controller. You decide why the data is collected and what happens to it. The virtual office operator acts on that data on your behalf and, in that role, is a processor. The split sounds formal, but the consequence is practical: if the operator fails, the controller's liability still sits with your company.

The GDPR only permits you to entrust data to a party offering sufficient guarantees of appropriate safeguards. Vetting the operator is therefore not caution or good practice — it is the controller's obligation, which means yours. It is the obligation people forget most often, because it looks like a courtesy towards a supplier.

Controller versus processor

Comparison criterionYour company — the controllerThe operator — the processor
Purpose and legal basis of processingDecidesDoes not decide — acts on your behalf
Retention periodDecidesFollows the processing agreement
Requests from data subjectsHandles themPasses them to the controller
Safeguards around the mailVets the operator — an obligation, not a courtesyImplements them, under Article 32 GDPR
Records of processing activitiesKeeps its ownKeeps a record of categories of activities
Liability after a breachStays with your companyWithin the processing agreement and only within it

Myth vs fact

  1. MitThe virtual office processes the letters, so it is responsible for the data.

    FaktIt is responsible within the processing agreement and only within it. The legal basis, the purpose, the retention period and handling data subject requests all stay with the controller — with your company.

  2. MitA processing agreement is a formality; the service contract covers it.

    FaktTwo different documents. The first governs the service, the second the processing of personal data. In decision DKN.5131.29.2022 the Polish supervisory authority imposed a PLN 8,000 fine for exactly these two failures at once: entrusting data without a written agreement, and never verifying the processor.

  3. MitUsing a virtual office requires my consent to data processing.

    FaktConsent is not the legal basis here and you do not have to sign one. The operator processes the data to perform the contract and because a statute requires it.

  4. MitOnce the contract ends I can demand that all my data be deleted.

    FaktNot all of it. Records collected under anti-money-laundering law must be retained by the operator for five years, and the right to erasure does not extend to them.

The question sounds academic and settles something entirely practical: what you can demand and what you cannot. Processing rests on a legal basis rather than on goodwill, and in a virtual office two different bases run at the same time.

01
Performance of the contract

The data needed to deliver the service: who the client is, what address the company is registered at, who the mail may be handed to.

02
Legal obligation

The data the operator must collect because anti-money-laundering law requires it.

Neither of them is consent — and that is the most common misunderstanding here. The consequence is concrete: consent can be withdrawn at any moment, these two bases cannot. If an operator asks you to consent to processing that is necessary to perform the contract, it either misunderstands its own duties or is using consent as an umbrella for something else, such as marketing. Ask what exactly the consent covers.

Consent has one legitimate place in this relationship: purposes beyond the service and beyond the statute. A newsletter, sales material, passing data to a partner. You may refuse that consent and the service has to carry on.

Why the operator holds your data at all

Providing a registered address is an activity covered by anti-money-laundering law. The operator is an obliged institution and, before releasing the address, has a statutory duty to establish the identity of the client and of the beneficial owner. The ID document it asks for when you sign is not officiousness.

That particular data is not processed on your instruction — it is processed because a statute requires it. Different legal basis, different rules: you cannot withdraw it, and the operator cannot delete the records early even if you both wanted to. It keeps them for five years after the relationship ends. The same duty determines which documents it will ask for when you register a company at the address.

An operator that does not ask for an ID document is not protecting your privacy — it is breaking the law. That one is the risk, not the operator that asks.

Read next

Virtual office for freelancers — your CEIDG address is public

For a sole trader the registered address is public in CEIDG, so the address is itself personal data. What that really exposes, and how to limit it, is a separate question.

Read the article

What a service contract cannot replace

The address contract governs the service: what the operator does, for how much and for how long. Entrusting personal data takes a separate document, required by Article 28 GDPR, and it has to settle four things. The Nest virtual office contract terms are set out on the offer page.

01
Scope and purpose

Which categories of data the operator processes in handling your mail, and why. A generic “client data” does not meet this requirement.

02
Retention

How long letters and scans are kept and what happens to them afterwards — return or destruction. This is separate from the five-year retention required by statute.

03
Safeguards

The measures required by Article 32 GDPR: who has physical access to the mail, how scans are secured and who can download them.

04
Sub-processing

Whether the operator uses subcontractors. If it does, that requires your consent and the same obligations imposed on them.

Do you need a record of processing activities?

Most likely yes — and it surprises most sole traders, because Article 30 GDPR opens with an exception that reads like an exemption.

The exception says an organisation employing fewer than 250 people need not keep the record. It then takes that back with three conditions: the duty returns if the processing may result in a risk to the rights and freedoms of individuals, if it is not occasional, or if it covers special categories of data. The second condition swallows the exemption in practice — serving clients, issuing invoices and handling mail are continuous processing, not occasional.

What that means for a virtual office: using one does not create a new duty, it adds an entry to a record you should already keep. You log the mail handling entrusted to a processor — categories of data, purpose, retention period and recipient. GDPR documentation in a small company is usually two things: that record, and the processing agreements with suppliers who handle data on your behalf. The operator keeps its own record of categories of activities — that is its duty, not yours, and it does not replace yours.

Your privacy notice — who has to be told what

Article 13 GDPR requires you to tell the people whose data you collect what happens to it. A privacy notice is not a formality reserved for large companies: it applies to anyone with clients, suppliers or a contact form.

A virtual office enters at one specific point — the categories of recipients. If you entrust your mail to an operator, it is a recipient of the data contained in letters addressed to your company, and your privacy policy should say so. You do not have to name it; a category is enough, for example “providers of mail handling and registered address services”.

Your clients' privacy protection ends exactly where the precision of that wording ends. If your privacy policy mentions no processors at all while you use a virtual office, an accountant and a mail host, it does not match reality.

What the operator may do with your mail

Protection of correspondence neither begins nor ends with the GDPR. Confidentiality of communication is guaranteed by Article 49 of the Polish Constitution, and reading someone else's letter without authorisation is an offence under Article 267 of the Criminal Code — regardless of what the parties wrote into their contract.

Scanning is lawful because it happens on your instruction and on your behalf. Reading for any other purpose does not become lawful through any contractual clause.

Security around the mail is settled not at the level of declarations but at the level of how many people can reach it. Article 32 GDPR speaks of measures appropriate to the risk — for a paper letter from a public authority the appropriate measure is a narrow circle of people and control over handover, not technology. Data security starts here with a closed door, not with software.

Read next

Business mail handling in a virtual office

How collection, notification and second-attempt deliveries actually work — the operational side rather than the legal one.

Read the article

The 72-hour clock is yours, not the operator's

This is the point you will not find in price lists or in most guides, and it decides whether you make it on a bad day. Handing a letter to the wrong person or losing one is a personal data breach — not an organisational hiccup, but an event with its own procedure.

The procedure is asymmetric, and that is the important part:

01
You, as the controller

Article 33(1) GDPR: you notify the supervisory authority without undue delay and no later than 72 hours after becoming aware of the breach. The clock runs from the moment you learn of it, not from the moment it happened.

02
The operator, as the processor

Article 33(2) GDPR: it notifies you “without undue delay”. That is all. The Regulation gives it no deadline measured in hours.

The conclusion is uncomfortable and simple: the operator decides when your clock starts. Until it calls, you have nothing to report — and when it calls a week later, explaining yourself to the authority and to the people whose data leaked falls to you. The text of Article 33 does not fix this. The contract does.

So the processing agreement should carry a deadline measured in hours rather than the phrase “without undue delay”. This is not an unreasonable demand or a favour from the operator: Article 28(3)(f) GDPR obliges the processor to assist the controller in meeting the duties under Articles 32 to 36, which includes Article 33. A deadline in the contract is simply that duty written concretely instead of vaguely.

Two things are worth knowing in advance so you do not lose time in the moment. A notification to the Polish authority is filed electronically only, through biznes.gov.pl, signed with a qualified signature or a Trusted Profile — if you have neither, arrange it before you need it. And if you cannot gather all the information within 72 hours, you file a preliminary notification and complete it later; missing the deadline is worse than an incomplete report.

What to ask before you entrust the data

An evasive answer to any of the seven questions below tells you more about an operator than all of its assurances about security put together. They concern the processing of personal data only — you ask about the service itself separately.

01
Will I get a draft processing agreement before I sign the main contract?
02
Within how many hours will you notify me of a personal data breach?

If the answer is “without undue delay”, Article 33 has been copied out and nothing has been promised.

03
Who, by name, has access to the mail and to its scans?
04
How long do you keep scans, and how do you delete them?
05
Do you use subcontractors for mail handling or for storing scans?
06
Does the data stay within the European Economic Area?
07
Which data must you retain under anti-money-laundering law?

How this works at The Nest

We sign the processing agreement as standard, together with the address contract, rather than on request. Access to a letter from the moment it enters the building until it is handed to the client rests with reception alone — not an organisational detail but a security measure, because official and court correspondence contains data no one but the addressee should see.

Around two thousand items of mail a year pass through the address at Piękna 49, and most of them are registered letters. Reception takes in mail the same business day, and where a registered letter has been left for collection we pick it up at the post office on the client's behalf. The shorter the journey and the fewer hands on it, the fewer places where data protection could fail.

Data collected under anti-money-laundering law we keep for the five years the statute requires, and we say so before the contract is signed, not after. How the site itself processes data is set out in the privacy policy.

Sources and legal basis
  1. 01Regulation (EU) 2016/679 (GDPR), Article 28 (processing on behalf of a controller) and Article 32 (security of processing) and Article 33 (notification of a personal data breach).
  2. 02Act of 1 March 2018 on counteracting money laundering and terrorist financing — duties of obliged institutions, including providers of a registered seat or address.
  3. 03Constitution of the Republic of Poland of 2 April 1997, Article 49 (confidentiality of communication).
  4. 04Act of 6 June 1997 — Criminal Code, Article 267 (breach of confidentiality of correspondence).
  5. 05Act of 10 May 2018 on the protection of personal data.
  6. 06Biznes.gov.pl — the Polish procedure for notifying a personal data breach: electronic filing only, qualified signature or Trusted Profile, preliminary and supplementary notifications.
  7. 07Decision of the President of the Polish DPA of 16 August 2022, DKN.5131.29.2022 — PLN 8,000 fine for entrusting processing without a written agreement and for failing to verify the processor.
  8. 08Decision of the President of the Polish DPA, DKN.5131.35.2021 — breach of Articles 28(1)–(3) and 32 GDPR by both the controller and the processor.

Legal position as at August 2026. This material is informational and does not constitute legal advice. If you are unsure about a controller's obligations, consult a lawyer or a data protection officer.

FAQ10

Virtual office and GDPR — questions and answers

Who is the data controller — my company or the virtual office?

Your company. It decides the purposes and means of processing, so most GDPR obligations sit with it. The virtual office operator is a processor and acts solely on your documented instructions, within the limits of the processing agreement.

Does the service contract replace a processing agreement?

No. They are two separate documents governing two different things: the first the service, the second the processing of personal data. Article 28 GDPR requires the second, and its absence is a breach on the controller's side — your company's.

Can I demand deletion of all my data once the contract ends?

Not all of it. Data collected under anti-money-laundering law must be retained by the operator for five years after the relationship ends. The right to erasure does not cover processing required by law.

What happens if I entrust data without a processing agreement?

The liability falls on the controller, that is on your company — you are the one required to conclude the agreement and to verify the processor. In decision DKN.5131.29.2022 the Polish supervisory authority imposed a PLN 8,000 fine on exactly these grounds, and for both failures at once: no written processing agreement, and no verification of the party the data went to.

I run several companies — is one processing agreement enough?

Not if they are separate legal entities. The controller is the specific entity, so each needs its own processing agreement, even where the owner and the operator are the same.

Does the data have to be processed inside the EU?

It does not, but any transfer outside the European Economic Area needs its own legal basis and safeguards. So ask directly where the servers holding the scans are — “in the cloud” settles nothing.

Do I need a record of processing activities if I use a virtual office?

Most likely yes, but not because of the virtual office. The exemption for companies with fewer than 250 employees does not apply when processing is not occasional — and serving clients and handling mail is exactly that. Entrusting your mail to an operator is one more entry in a record you should keep anyway.

Do I have to mention the virtual office in my privacy policy?

You should cover it under the categories of recipients, because the operator processes data contained in mail addressed to you. You do not have to give its name — a category is enough, for example “providers of mail handling and registered address services”.

How quickly must the operator tell me about a data breach?

The GDPR sets no deadline in hours — Article 33(2) says only “without undue delay”. The 72-hour deadline in Article 33(1) applies to you as the controller and runs from the moment you learn of the breach. In practice the operator decides when your clock starts, which is why a deadline measured in hours belongs in the processing agreement.

Does the operator need my consent to process the data?

No. The basis is performance of the contract and a duty under anti-money-laundering law, not consent. That has a practical effect: neither basis can be withdrawn. Consent covers only additional purposes such as marketing, and you may refuse it without affecting the service.

A registered address

The address this article is about

Piękna 49, 00-672 Warsaw. A virtual office run on site, not through an intermediary.

  • Reception takes in mail the same business day.
  • Reception signs for registered letters from the postman, who comes every day.
  • A contract you can show the registry court and the tax office.

Share this article