{
 "jurisdiction_id": "CZ",
 "jurisdiction": "Czech Republic",
 "url": "https://dataprotection.gi/jurisdictions/czech-republic/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 30,
  "sub_modules": 57,
  "source_register": 14
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/czech-republic/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Full GDPR direct effect plus a settled, in-force national implementing Act and an operational, EDPB-member supervisory authority.",
   "claims": [
    {
     "statement": "The Office for Personal Data Protection (ÚOOÚ), seated at Pplk. Sochora 27, Prague 7, is the Czech Republic's GDPR supervisory authority and a full voting member of the European Data Protection Board.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/about-edpb/our-members_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Act No. 110/2019 Coll. on Personal Data Processing fully replaces the prior Czech Data Protection Act, establishes the constitution and powers of the Czech Data Protection Office, and transposes Directive (EU) 2016/680 governing processing of personal data for crime prevention/investigation and defense/security purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/czech-parliament-approves-bills-implementing-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Data Protection Act includes local derogations and exceptions primarily for public authorities, and its Accompanying Act amends more than 30 other Czech laws in connection with GDPR and Directive 2016/680 implementation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/czech-parliament-approves-bills-implementing-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Companies not established in the EU must comply with GDPR rules, including as applied by Czech supervisory authority, when they offer goods/services to or monitor the behaviour of individuals in the EU.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/CS/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No distinct Czech controller-registration or filing-fee regime was confirmed in this research pass; GDPR's harmonised approach removed the general prior-notification obligation that existed under the pre-2018 Czech data protection regime.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "EDPB / ÚOOÚ",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/article-60-final-decisions/publishable_cz_2019-07_lawfulnessoftheprocessing_decisionpublic.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/czech-republic/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Direct GDPR effect confirmed plus ÚOOÚ consent guidance; special-category specifics not separately verified this pass.",
   "claims": [
    {
     "statement": "GDPR establishes a single EU-wide rulebook for data protection, including its Article 6 lawful bases, applicable directly and uniformly in the Czech Republic as an EU Member State.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/CS/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ÚOOÚ guidance issued in March 2018 requires that requests for consent be presented in a manner clearly distinguishable from other matters, in intelligible and easily accessible form using clear and plain language, and highlights GDPR Article 7(4) on whether consent is improperly bundled with contract performance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/czech-republic-uoou-issues-guidance-consent-under-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 9's special-category regime (health, biometric, genetic, ethnic, political, sexual, criminal data) is presumed to apply directly in Czech Republic absent an identified national derogation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/CS/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR promotes privacy-enhancing techniques such as pseudonymisation (replacing identifying fields with identification codes) and encryption as recognised safeguards, applicable directly in the Czech Republic.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/CS/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/czech-republic/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Direct GDPR effect confirmed via official guidance notes; a documented national carve-out exists for law-enforcement/security processing.",
   "claims": [
    {
     "statement": "The General Data Protection Regulation governs data subject rights in Czechia, directly conferring rights of access, rectification, erasure, restriction, objection and portability, as supplemented by Act No. 110/2019 Coll. on Personal Data Processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/czech-republic-data-subject-rights",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Title III of Act No. 110/2019 Coll. governs the processing of personal data in relation to criminal matters and national security by competent Czech public authorities and provides restrictions on the rights of data subjects in that context.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/czech-republic-data-subject-rights",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/czech-republic/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Well-documented national DPIA and DPO provisions plus an active breach-notification regime evidenced by ÚOOÚ annual-report statistics; ROPA/joint-controller/retention specifics not separately verified this pass.",
   "claims": [
    {
     "statement": "Since 1 April 2023, Section 10 of Act No. 110/2019 Coll. requires a 'legislative DPIA' for every legislative proposal, including subsidiary regulations such as government decrees or ordinances, which under GDPR Article 35(10) replaces the standard Article 35(1) DPIA for that specific legislative measure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/czech-republic-uoou-announces-new-process-dpia",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Sections 14 and 16(1)(d) of Act No. 110/2019 Coll., read with GDPR Articles 37-39, govern DPO appointment in the Czech Republic; ÚOOÚ requires notification of DPO appointments by the controller/processor (not the DPO), including the DPO's contact details.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/czech-republic-data-protection-officer-appointment",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ÚOOÚ's 2019 annual report recorded 2,600 queries, 2,482 complaints, and 416 notifications of personal data breaches, evidencing an operative breach-notification regime.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/czech-republic-uoou-publishes-2019-annual-report",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/czech-republic/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "GDPR transfer toolkit applies directly; the EU's new cross-border enforcement procedural regulation is confirmed adopted and published.",
   "claims": [
    {
     "statement": "GDPR offers a modern toolkit for international data transfers outside the EU, including European Commission adequacy decisions, pre-approved standard contractual clauses, binding corporate rules, codes of conduct and certification, all directly applicable in the Czech Republic.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/CS/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Adequacy decisions under GDPR Article 45 are adopted by the European Commission and apply uniformly across all EU Member States, including the Czech Republic, without a separate Czech national adequacy process.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/CS/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Regulation (EU) 2025/2518, adopted 26 November 2025 and published in the Official Journal on 12 December 2025, lays down procedural rules for enforcing the GDPR in cross-border cases, aiming to make investigations and complaint-handling faster and more uniform across Member States including the Czech Republic.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/CS/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/czech-republic/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "One sectoral overlay (telecoms/e-privacy) is well evidenced; other sector modules lack dedicated Czech sectoral sourcing this pass.",
   "claims": [
    {
     "statement": "The Czech Electronic Communications Act (Act No. 127/2005 Coll.), as amended by Act No. 374/2021 Coll., requires opt-in consent for cookies, and ÚOOÚ's 2022 control plan specifically targeted compliance checks on this opt-in cookie-consent requirement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/czech-republic-uoou-publishes-2022-control-plan",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ÚOOÚ participated in 2020 consultations to amend the Electronic Communications Act transposing the European Electronic Communications Code (Directive (EU) 2018/1972) and proposed a Criminal Code amendment criminalising misuse of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/czech-republic-uoou-reports-three-bills-personal-data-protection",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/czech-republic/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie and direct-marketing regimes are well evidenced; other adtech sub-areas lack dedicated CZ sourcing.",
   "claims": [
    {
     "statement": "Under Act No. 480/2004 Coll. on Certain Information Society Services, ÚOOÚ monitors and enforces against unsolicited commercial electronic communications; in 2022 there were 906 complaints about such communications, a very similar figure to 2021, making it one of the most common complaint categories after personal-data-security breaches.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/czech-republic-uoou-publishes-2022-annual-report",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/czech-republic/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Core GDPR Art 22 and state-surveillance carve-out are well evidenced; AI-specific risk-assessment and genetic-data regimes are not yet settled or separately confirmed for CZ.",
   "claims": [
    {
     "statement": "GDPR's single EU rulebook, including its Article 22 restrictions on solely-automated decision-making with legal or similarly significant effects, applies directly and uniformly in the Czech Republic.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/CS/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ÚOOÚ's 2019 annual report states the Office has paid systematic attention to the use of biometric data and CCTV systems, among other supervisory priorities.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/czech-republic-uoou-publishes-2019-annual-report",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Act No. 110/2019 Coll. transposes Directive (EU) 2016/680, establishing a separate Title III regime for processing of personal data by competent Czech authorities for prevention, investigation, detection or prosecution of criminal offences and for national defense/security, restricting ordinary data-subject rights in that context.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/czech-parliament-approves-bills-implementing-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of mid-2026, the EU's Digital Omnibus Regulation proposal — which intersects with GDPR concepts including personal data and profiling — remains in the EU legislative process, with potential future implications for AI-governance obligations applicable to Czech controllers.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-iapp-europe-gdpr-anniversary-2025-annual-reports-and-looking-ahead",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "green",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/czech-republic/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "The core age-of-consent threshold is well confirmed via primary legislative reporting; other sub-areas lack dedicated CZ sourcing.",
   "claims": [
    {
     "statement": "The Czech GDPR-implementing legislative process set the age of a child's own valid consent for information-society-service data processing at 15 years, following parliamentary rejection of a proposal to lower this threshold to 13.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/czech-parliament-approves-bills-implementing-gdpr",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/czech-republic/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Well-documented enforcement powers, a landmark cross-border fine decision, and recent (within-180-day) reporting on regulator capacity strain.",
   "claims": [
    {
     "statement": "Act No. 110/2019 Coll. abolished administrative fines for all public authorities and bodies (governmental bodies, ministries, municipalities, schools, public hospitals and similar public-interest controllers/processors), and empowers ÚOOÚ to drop minor offenses without initiating formal proceedings and without notifying the person concerned.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/czech-parliament-approves-bills-implementing-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In the Avast antivirus case, the Czech supervisory authority, acting as Lead Supervisory Authority, issued an administrative appellate decision on 10 April 2024 imposing a fine of approximately EUR 13.9 million for infringement of GDPR Articles 6 and 13, concerning the transfer of pseudonymized browsing-history data of roughly 100 million users to a sister company without a valid legal basis, while misinforming users that the data were anonymized.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2024/czech-sa-imposed-fine-139-million-eur-infringement-art-6-and-art-13-gdpr_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In its 2025 annual report, ÚOOÚ noted growing strain on its workforce due to the increasing complexity of cases handled.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-iapp-europe-gdpr-anniversary-2025-annual-reports-and-looking-ahead",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "An IAPP analysis published 28 May 2026 reports that ÚOOÚ's 2025 annual report highlighted growing workforce strain from increasingly complex cases, situating Czech enforcement trends within the broader wave of record European DPA fines and breach-notification volumes reported around GDPR's tenth anniversary in May 2026.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-iapp-europe-gdpr-anniversary-2025-annual-reports-and-looking-ahead",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Articles 79 and 82 grant data subjects in the Czech Republic a direct right to an effective judicial remedy against controllers/processors and a right to compensation for material or non-material damage, applicable directly as EU Regulation provisions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/CS/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}