Skip to main content
Virtual office7 July 2026

Virtual office and GDPR — data protection in practice (2026)

How to use a virtual office in line with GDPR: processing agreement (art. 28), address privacy, confidentiality of mail and a compliance checklist.

Natalia Wyszkowska — Office Manager at The Nest
Natalia Wyszkowska
Office Manager

Updated

Virtual office and GDPR — personal data protection

Reading time

6

min

Virtual officePiękna 49

The short answer

Yes — a virtual office can be used in line with the GDPR. The starting point is not the one most people expect: the problem is not that the operator holds too much of your data. Some of it the operator is required by statute to collect and keep for five years. The rest comes down to a single document — the processing agreement.

Who is responsible
Your company is the controller, not the operator. It acts on your documented instructions — but the duty to vet whom you entrust the data to stays on your side.
What the law requires
A separate processing agreement under Article 28 GDPR. A service contract does not replace it, and entrusting data without one is a breach on the controller's side.
Why the operator knows your data
Because providing a registered address falls under anti-money-laundering law. The operator has a statutory duty to establish the client's identity and to retain the records — it cannot delete them on request.
How it works here
We sign the processing agreement together with the main contract, and access to mail from the moment it enters the building until handover rests with reception alone.

Who is responsible for the data — you or the operator

Your company is the data controller. You decide why the data is collected and what happens to it. The virtual office operator acts on that data on your behalf and, in that role, is a processor. The split sounds formal, but the consequence is practical: if the operator fails, the controller's liability still sits with your company.

The GDPR only permits you to entrust data to a party offering sufficient guarantees of appropriate safeguards. Vetting the operator is therefore not caution or good practice — it is the controller's obligation, which means yours. It is the obligation people forget most often, because it looks like a courtesy towards a supplier.

Controller versus processor

Comparison criterionYour company — the controllerThe operator — the processor
Purpose and legal basis of processingDecidesDoes not decide — acts on your behalf
Retention periodDecidesFollows the processing agreement
Requests from data subjectsHandles themPasses them to the controller
Safeguards around the mailVets the operator — an obligation, not a courtesyImplements them, under Article 32 GDPR
Liability after a breachStays with your companyWithin the processing agreement and only within it

Myth vs fact

  1. MitThe virtual office processes the letters, so it is responsible for the data.

    FaktIt is responsible within the processing agreement and only within it. The legal basis, the purpose, the retention period and handling data subject requests all stay with the controller — with your company.

  2. MitA processing agreement is a formality; the service contract covers it.

    FaktThey are two different documents. The first governs the service, the second the processing of personal data. Poland's data protection authority has issued fines both for the absence of a processing agreement and for failing to vet the processor.

  3. MitOnce the contract ends I can demand that all my data be deleted.

    FaktNot all of it. Records collected under anti-money-laundering law must be retained by the operator for five years, and the right to erasure does not extend to them.

Why the operator holds your data at all

Providing a registered address is an activity covered by anti-money-laundering law. The operator is an obliged institution and, before releasing the address, has a statutory duty to establish the identity of the client and of the beneficial owner. The ID document it asks for when you sign is not officiousness.

That particular data is not processed on your instruction — it is processed because a statute requires it. Different legal basis, different rules: you cannot withdraw it, and the operator cannot delete the records early even if you both wanted to. It keeps them for five years after the relationship ends. The same duty determines which documents it will ask for when you register a company at the address.

An operator that does not ask for an ID document is not protecting your privacy — it is breaking the law. That one is the risk, not the operator that asks.

Read next

A business address for freelancers in Warsaw

For a sole trader the registered address is public in CEIDG, so the address is itself personal data. What that really exposes, and how to limit it, is a separate question.

Read the article

What a service contract cannot replace

The address contract governs the service: what the operator does, for how much and for how long. Entrusting personal data takes a separate document, required by Article 28 GDPR, and it has to settle four things. Our contract terms are set out on the virtual office page.

  • Scope and purpose
  • Retention
  • Safeguards
  • Sub-processing

What the operator may do with your mail

Protection of correspondence neither begins nor ends with the GDPR. Confidentiality of communication is guaranteed by Article 49 of the Polish Constitution, and reading someone else's letter without authorisation is an offence under Article 267 of the Criminal Code — regardless of what the parties wrote into their contract.

Scanning is lawful because it happens on your instruction and on your behalf. Reading for any other purpose does not become lawful through any contractual clause.

Read next

Business mail handling in a virtual office

How collection, notification and second-attempt deliveries actually work — the operational side rather than the legal one.

Read the article

What to ask before you entrust the data

An evasive answer to any of the six questions below tells you more about an operator than every assurance about security put together. They concern data processing only — you ask about the service itself separately.

  • Will I get a draft processing agreement before I sign the main contract?
  • Who, by name, has access to the mail and to its scans?
  • How long do you keep scans, and how do you delete them?
  • Do you use subcontractors for mail handling or for storing scans?
  • Does the data stay within the European Economic Area?
  • Which data must you retain under anti-money-laundering law?

How this works at The Nest

We sign the processing agreement as standard, together with the address contract, rather than on request. Access to a letter from the moment it enters the building until it is handed to the client rests with reception alone — not an organisational detail but a security measure, because official and court correspondence contains data no one but the addressee should see.

Data collected under anti-money-laundering law we keep for the five years the statute requires, and we say so before the contract is signed, not after. How the site itself processes data is set out in the privacy policy.

Sources and legal basis
  1. 01Regulation (EU) 2016/679 (GDPR), Article 28 (processing on behalf of a controller) and Article 32 (security of processing).
  2. 02Act of 1 March 2018 on counteracting money laundering and terrorist financing — duties of obliged institutions, including providers of a registered seat or address.
  3. 03Constitution of the Republic of Poland of 2 April 1997, Article 49 (confidentiality of communication).
  4. 04Act of 6 June 1997 — Criminal Code, Article 267 (breach of confidentiality of correspondence).
  5. 05Act of 10 May 2018 on the protection of personal data.
  6. 06Decisions of the President of the Personal Data Protection Office on processing agreements and processor vetting (including DKN.5131.29.2022, DKN.5131.35.2021).

Legal position as at August 2026. This material is informational and does not constitute legal advice. If you are unsure about a controller's obligations, consult a lawyer or a data protection officer.

Remaining questions06

What people ask most

A registered address

The address this article is about

Piękna 49, 00-672 Warsaw. A virtual office run on site, not through an intermediary.

  • Reception takes in mail the same business day.
  • Registered letters left for collection are picked up on your behalf.
  • A contract you can show the registry court and the tax office.

Share this article