Who is responsible for the data — you or the operator
Your company is the data controller. You decide why the data is collected and what happens to it. The virtual office operator acts on that data on your behalf and, in that role, is a processor. The split sounds formal, but the consequence is practical: if the operator fails, the controller's liability still sits with your company.
The GDPR only permits you to entrust data to a party offering sufficient guarantees of appropriate safeguards. Vetting the operator is therefore not caution or good practice — it is the controller's obligation, which means yours. It is the obligation people forget most often, because it looks like a courtesy towards a supplier.
Controller versus processor
| Comparison criterion | Your company — the controller | The operator — the processor |
|---|---|---|
| Purpose and legal basis of processing | Decides | Does not decide — acts on your behalf |
| Retention period | Decides | Follows the processing agreement |
| Requests from data subjects | Handles them | Passes them to the controller |
| Safeguards around the mail | Vets the operator — an obligation, not a courtesy | Implements them, under Article 32 GDPR |
| Liability after a breach | Stays with your company | Within the processing agreement and only within it |
Myth vs fact
MitThe virtual office processes the letters, so it is responsible for the data.
FaktIt is responsible within the processing agreement and only within it. The legal basis, the purpose, the retention period and handling data subject requests all stay with the controller — with your company.
MitA processing agreement is a formality; the service contract covers it.
FaktThey are two different documents. The first governs the service, the second the processing of personal data. Poland's data protection authority has issued fines both for the absence of a processing agreement and for failing to vet the processor.
MitOnce the contract ends I can demand that all my data be deleted.
FaktNot all of it. Records collected under anti-money-laundering law must be retained by the operator for five years, and the right to erasure does not extend to them.
Why the operator holds your data at all
Providing a registered address is an activity covered by anti-money-laundering law. The operator is an obliged institution and, before releasing the address, has a statutory duty to establish the identity of the client and of the beneficial owner. The ID document it asks for when you sign is not officiousness.
That particular data is not processed on your instruction — it is processed because a statute requires it. Different legal basis, different rules: you cannot withdraw it, and the operator cannot delete the records early even if you both wanted to. It keeps them for five years after the relationship ends. The same duty determines which documents it will ask for when you register a company at the address.
An operator that does not ask for an ID document is not protecting your privacy — it is breaking the law. That one is the risk, not the operator that asks.
A business address for freelancers in Warsaw
For a sole trader the registered address is public in CEIDG, so the address is itself personal data. What that really exposes, and how to limit it, is a separate question.
Read the articleWhat a service contract cannot replace
The address contract governs the service: what the operator does, for how much and for how long. Entrusting personal data takes a separate document, required by Article 28 GDPR, and it has to settle four things. Our contract terms are set out on the virtual office page.
- Scope and purpose
- Retention
- Safeguards
- Sub-processing
What the operator may do with your mail
Protection of correspondence neither begins nor ends with the GDPR. Confidentiality of communication is guaranteed by Article 49 of the Polish Constitution, and reading someone else's letter without authorisation is an offence under Article 267 of the Criminal Code — regardless of what the parties wrote into their contract.
Scanning is lawful because it happens on your instruction and on your behalf. Reading for any other purpose does not become lawful through any contractual clause.
Business mail handling in a virtual office
How collection, notification and second-attempt deliveries actually work — the operational side rather than the legal one.
Read the articleWhat to ask before you entrust the data
An evasive answer to any of the six questions below tells you more about an operator than every assurance about security put together. They concern data processing only — you ask about the service itself separately.
- Will I get a draft processing agreement before I sign the main contract?
- Who, by name, has access to the mail and to its scans?
- How long do you keep scans, and how do you delete them?
- Do you use subcontractors for mail handling or for storing scans?
- Does the data stay within the European Economic Area?
- Which data must you retain under anti-money-laundering law?
How this works at The Nest
We sign the processing agreement as standard, together with the address contract, rather than on request. Access to a letter from the moment it enters the building until it is handed to the client rests with reception alone — not an organisational detail but a security measure, because official and court correspondence contains data no one but the addressee should see.
Data collected under anti-money-laundering law we keep for the five years the statute requires, and we say so before the contract is signed, not after. How the site itself processes data is set out in the privacy policy.
- 01Regulation (EU) 2016/679 (GDPR), Article 28 (processing on behalf of a controller) and Article 32 (security of processing).
- 02Act of 1 March 2018 on counteracting money laundering and terrorist financing — duties of obliged institutions, including providers of a registered seat or address.
- 03Constitution of the Republic of Poland of 2 April 1997, Article 49 (confidentiality of communication).
- 04Act of 6 June 1997 — Criminal Code, Article 267 (breach of confidentiality of correspondence).
- 05Act of 10 May 2018 on the protection of personal data.
- 06Decisions of the President of the Personal Data Protection Office on processing agreements and processor vetting (including DKN.5131.29.2022, DKN.5131.35.2021).
Legal position as at August 2026. This material is informational and does not constitute legal advice. If you are unsure about a controller's obligations, consult a lawyer or a data protection officer.
What people ask most
Your company. It decides the purposes and means of processing, so most GDPR obligations sit with it. The virtual office operator is a processor and acts solely on your documented instructions, within the limits of the processing agreement.
No. They are two separate documents governing two different things: the first the service, the second the processing of personal data. Article 28 GDPR requires the second, and its absence is a breach on the controller's side — your company's.
Not all of it. Data collected under anti-money-laundering law must be retained by the operator for five years after the relationship ends. The right to erasure does not cover processing required by law.
Liability falls on the controller — your company. It is your duty to conclude the agreement and to vet the processor. Poland's data protection authority has fined companies both for the missing agreement and for the failure to vet.
Not if they are separate legal entities. The controller is the specific entity, so each needs its own processing agreement, even where the owner and the operator are the same.
It does not, but any transfer outside the European Economic Area needs its own legal basis and safeguards. So ask directly where the servers holding the scans are — “in the cloud” settles nothing.
A registered address
The address this article is about
Piękna 49, 00-672 Warsaw. A virtual office run on site, not through an intermediary.
- Reception takes in mail the same business day.
- Registered letters left for collection are picked up on your behalf.
- A contract you can show the registry court and the tax office.
