🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CZ · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 14 sources retrieved model claude-sonnet-5 ·

Czech Republic

CZ schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 30 claims · 14 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
30Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Full GDPR direct effect plus a settled, in-force national implementing Act and an operational, EDPB-member supervisory authority.

Primary frameworkRegulation (EU) 2016/679 (GDPR), as implemented by Act No. 110/2019 Coll. on Personal Data Processing
Traffic-light rationale — GreenFull GDPR direct effect plus a settled, in-force national implementing Act and an operational, EDPB-member supervisory authority.

Sub-modules (5)

Regulator And AuthorityGreen

ÚOOÚ, seated at Pplk. Sochora 27, Prague 7, is the Czech GDPR supervisory authority and a voting member of the EDPB.

Claims: CLM-CZ-1a2b3c4d

Act And InstrumentsGreen

Act No. 110/2019 Coll. is the core national instrument; it replaced the prior Data Protection Act and transposes the Law Enforcement Directive.

Claims: CLM-CZ-2b3c4d5e

Material ScopeGreen

The Act carries local derogations mainly benefiting public authorities and triggered amendment of over 30 other Czech statutes.

Claims: CLM-CZ-3c4d5e6f

Territorial ScopeGreen

GDPR's extraterritorial rule (targeting/monitoring of EU data subjects) applies directly to non-EU controllers vis-à-vis Czech data subjects.

Claims: CLM-CZ-4d5e6f70

Regulator Registration And FilingAmber

No general controller registration/notification-fee regime (analogous to the UK ICO fee system) was identified for Czech Republic in this research pass; GDPR abolished the EU-wide prior-notification requirement that existed under the pre-2018 regime.

Claims: CLM-CZ-5e6f7081

Category narrative58 words

Czech Republic is an EU Member State operating under the direct-effect GDPR, implemented and supplemented nationally by Act No. 110/2019 Coll. on Personal Data Processing, which establishes the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ) as the supervisory authority, includes local derogations (chiefly for public authorities), and transposes Directive (EU) 2016/680 for law-enforcement/security processing.

Sources and claims (5)
  1. ConfirmedEDPBThe Office for Personal Data Protection (ÚOOÚ), seated at Pplk. Sochora 27, Prague 7, is the Czech Republic's GDPR supervisory authority and a full voting member of the European Data Protection Board.
  2. ConfirmedIAPPAct No. 110/2019 Coll. on Personal Data Processing fully replaces the prior Czech Data Protection Act, establishes the constitution and powers of the Czech Data Protection Office, and transposes Directive (EU) 2016/680 governing processing of personal data for crime prevention/investigation and defense/security purposes.
  3. ConfirmedIAPPThe Data Protection Act includes local derogations and exceptions primarily for public authorities, and its Accompanying Act amends more than 30 other Czech laws in connection with GDPR and Directive 2016/680 implementation.
  4. ConfirmedEUR-LexCompanies not established in the EU must comply with GDPR rules, including as applied by Czech supervisory authority, when they offer goods/services to or monitor the behaviour of individuals in the EU.
  5. UncertainEDPB / ÚOOÚNo distinct Czech controller-registration or filing-fee regime was confirmed in this research pass; GDPR's harmonised approach removed the general prior-notification obligation that existed under the pre-2018 Czech data protection regime.

#

Direct GDPR effect confirmed plus ÚOOÚ consent guidance; special-category specifics not separately verified this pass.

Primary frameworkRegulation (EU) 2016/679 (GDPR) Arts 6, 7, 9
Traffic-light rationale — GreenDirect GDPR effect confirmed plus ÚOOÚ consent guidance; special-category specifics not separately verified this pass.

Sub-modules (4)

Lawful BasesGreen

GDPR Article 6's enumerated lawful bases apply directly, EU-wide, without a substitute Czech list.

Claims: CLM-CZ-6f708192

Special CategoriesAmber

No Czech-specific derogation to GDPR Article 9 special-category rules was identified in this research pass; Article 9 is presumed to apply directly.

Claims: CLM-CZ-8192a3b4

Pseudonymisation And AnonymisationGreen

GDPR's technology-neutral safe-harbours (pseudonymisation, encryption) apply directly in Czech Republic as an EU Member State.

Claims: CLM-CZ-92a3b4c5

Category narrative35 words

GDPR's Article 6 lawful bases, consent standards, and Article 9 special-category rules apply directly as EU law in Czech Republic; ÚOOÚ has supplemented this with national consent guidance. Pseudonymisation/anonymisation safe-harbours follow the GDPR's technology-neutral approach.

Sources and claims (4)
  1. ConfirmedEUR-LexGDPR establishes a single EU-wide rulebook for data protection, including its Article 6 lawful bases, applicable directly and uniformly in the Czech Republic as an EU Member State.
  2. ConfirmedDataGuidanceÚOOÚ guidance issued in March 2018 requires that requests for consent be presented in a manner clearly distinguishable from other matters, in intelligible and easily accessible form using clear and plain language, and highlights GDPR Article 7(4) on whether consent is improperly bundled with contract performance.
  3. UncertainEUR-LexGDPR Article 9's special-category regime (health, biometric, genetic, ethnic, political, sexual, criminal data) is presumed to apply directly in Czech Republic absent an identified national derogation.
  4. ConfirmedEUR-LexGDPR promotes privacy-enhancing techniques such as pseudonymisation (replacing identifying fields with identification codes) and encryption as recognised safeguards, applicable directly in the Czech Republic.

#

Direct GDPR effect confirmed via official guidance notes; a documented national carve-out exists for law-enforcement/security processing.

Primary frameworkRegulation (EU) 2016/679 (GDPR) Arts 12-22; Act No. 110/2019 Coll. Title III
Traffic-light rationale — GreenDirect GDPR effect confirmed via official guidance notes; a documented national carve-out exists for law-enforcement/security processing.

Sub-modules (5)

Access RightGreen

GDPR governs the subject-access request framework directly in Czechia.

Claims: CLM-CZ-a3b4c5d6

Rectification And ErasureGreen

GDPR's rectification/erasure rights apply directly; no CZ-specific derogation identified beyond the Title III carve-out.

Claims: CLM-CZ-a3b4c5d6

Restriction And ObjectionGreen

GDPR's restriction and objection rights (including profiling opt-out) apply directly in Czechia.

Claims: CLM-CZ-a3b4c5d6

Data PortabilityAmber

GDPR's portability right applies directly; no distinct Czech implementation detail was separately verified.

Claims: CLM-CZ-a3b4c5d6

Deadlines And Response WindowsGreen

Title III of Act No. 110/2019 Coll. restricts ordinary data-subject-rights deadlines/response obligations for criminal-matters and national-security processing by competent authorities.

Claims: CLM-CZ-b4c5d6e7

Category narrative33 words

GDPR governs data subject rights directly in Czechia (access, rectification, erasure, restriction, objection, portability), supplemented by Act No. 110/2019 Coll., whose Title III carves out restrictions for criminal-matters/national-security processing by competent public authorities.

Sources and claims (2)
  1. ConfirmedDataGuidanceThe General Data Protection Regulation governs data subject rights in Czechia, directly conferring rights of access, rectification, erasure, restriction, objection and portability, as supplemented by Act No. 110/2019 Coll. on Personal Data Processing.
  2. ConfirmedDataGuidanceTitle III of Act No. 110/2019 Coll. governs the processing of personal data in relation to criminal matters and national security by competent Czech public authorities and provides restrictions on the rights of data subjects in that context.

#

Well-documented national DPIA and DPO provisions plus an active breach-notification regime evidenced by ÚOOÚ annual-report statistics; ROPA/joint-controller/retention specifics not separately verified this pass.

Primary frameworkRegulation (EU) 2016/679 (GDPR) Arts 24-39; Act No. 110/2019 Coll. §§10, 14, 16(1)(d)
Traffic-light rationale — GreenWell-documented national DPIA and DPO provisions plus an active breach-notification regime evidenced by ÚOOÚ annual-report statistics; ROPA/joint-controller/retention specifics not separately verified this pass.

Sub-modules (7)

Accountability And DpiaGreen

Section 10 of Act No. 110/2019 Coll. introduces a 'legislative DPIA' for all legislative proposals affecting personal data, effective 1 April 2023, replacing the standard Article 35 DPIA for that measure.

Claims: CLM-CZ-c5d6e7f8

Dpo RequirementsGreen

Sections 14 and 16(1)(d) of Act No. 110/2019 Coll., alongside GDPR Arts 37-39, govern DPO appointment; ÚOOÚ requires email notification of DPO appointments with controller and DPO contact details.

Claims: CLM-CZ-d6e7f809

Ropa RequirementsAmber

GDPR Article 30 ROPA obligations apply directly; no CZ-specific derogation identified in this pass.

Joint Controller ArrangementsAmber

GDPR Article 26 joint-controller rules apply directly; no CZ-specific derogation identified.

Security MeasuresAmber

GDPR Article 32 security-of-processing obligations apply directly; no CZ-specific technical standard was separately verified.

Breach NotificationGreen

ÚOOÚ operates an active breach-notification regime; in 2019 it recorded 416 personal-data-breach notifications.

Claims: CLM-CZ-e7f8091a

Retention And DisposalAmber

GDPR's storage-limitation principle applies directly; no CZ-specific retention schedule was identified in this pass.

Category narrative37 words

GDPR's accountability, DPIA, DPO, security, breach-notification and retention obligations apply directly, supplemented by Act No. 110/2019 Coll.'s Section 10 'legislative DPIA' mechanism (effective 1 April 2023) and Sections 14/16(1)(d) DPO provisions, including a defined ÚOOÚ DPO-notification channel.

Sources and claims (3)
  1. ConfirmedDataGuidanceSince 1 April 2023, Section 10 of Act No. 110/2019 Coll. requires a 'legislative DPIA' for every legislative proposal, including subsidiary regulations such as government decrees or ordinances, which under GDPR Article 35(10) replaces the standard Article 35(1) DPIA for that specific legislative measure.
  2. ConfirmedDataGuidanceSections 14 and 16(1)(d) of Act No. 110/2019 Coll., read with GDPR Articles 37-39, govern DPO appointment in the Czech Republic; ÚOOÚ requires notification of DPO appointments by the controller/processor (not the DPO), including the DPO's contact details.
  3. ConfirmedDataGuidanceÚOOÚ's 2019 annual report recorded 2,600 queries, 2,482 complaints, and 416 notifications of personal data breaches, evidencing an operative breach-notification regime.

#

GDPR transfer toolkit applies directly; the EU's new cross-border enforcement procedural regulation is confirmed adopted and published.

Primary frameworkRegulation (EU) 2016/679 (GDPR) Arts 44-49; Regulation (EU) 2025/2518 (procedural rules)
Traffic-light rationale — GreenGDPR transfer toolkit applies directly; the EU's new cross-border enforcement procedural regulation is confirmed adopted and published.

Sub-modules (6)

Transfer MechanismsGreen

GDPR offers a modern toolkit for international transfers — adequacy decisions, SCCs, BCRs, codes of conduct and certification — applicable directly in Czech Republic.

Claims: CLM-CZ-f8091a2b

Adequacy ReceivedGreen

Adequacy is an EU-Commission-level competence; Czech Republic does not operate a separate national adequacy-reception process.

Claims: CLM-CZ-1a2b3c4e

Adequacy GrantedGreen

Adequacy decisions granted to third countries are adopted at EU-Commission level and apply uniformly across all Member States including Czech Republic; no separate CZ national adequacy-granting process exists.

Claims: CLM-CZ-1a2b3c4e

Sccs And BcrsGreen

SCCs and BCRs are available as GDPR transfer mechanisms directly applicable in Czech Republic.

Claims: CLM-CZ-f8091a2b

Transfer Impact AssessmentAmber

The EU-wide post-Schrems II transfer-impact-assessment expectation is presumed to apply in Czech Republic; not separately confirmed via CZ-specific ÚOOÚ guidance in this pass.

Data LocalisationAmber

No CZ-specific data-localisation mandate was identified in this research pass.

Category narrative38 words

As an EU Member State, Czech Republic operates under the GDPR's full cross-border transfer toolkit (adequacy decisions adopted at EU-Commission level, SCCs, BCRs, codes of conduct, certification) and the newly adopted EU procedural regulation for cross-border GDPR enforcement.

Sources and claims (3)
  1. ConfirmedEUR-LexGDPR offers a modern toolkit for international data transfers outside the EU, including European Commission adequacy decisions, pre-approved standard contractual clauses, binding corporate rules, codes of conduct and certification, all directly applicable in the Czech Republic.
  2. ProbableEUR-LexAdequacy decisions under GDPR Article 45 are adopted by the European Commission and apply uniformly across all EU Member States, including the Czech Republic, without a separate Czech national adequacy process.
  3. ConfirmedEUR-LexRegulation (EU) 2025/2518, adopted 26 November 2025 and published in the Official Journal on 12 December 2025, lays down procedural rules for enforcing the GDPR in cross-border cases, aiming to make investigations and complaint-handling faster and more uniform across Member States including the Czech Republic.

#

One sectoral overlay (telecoms/e-privacy) is well evidenced; other sector modules lack dedicated Czech sectoral sourcing this pass.

Primary frameworkAct No. 127/2005 Coll. (Electronic Communications Act), as amended by Act No. 374/2021 Coll.
Traffic-light rationale — AmberOne sectoral overlay (telecoms/e-privacy) is well evidenced; other sector modules lack dedicated Czech sectoral sourcing this pass.

Sub-modules (7)

Financial Sector OverlayRed

No dedicated Czech financial-sector data-protection overlay was identified in this pass beyond direct GDPR application.

Health Sector OverlayRed

No dedicated Czech health-sector data-protection overlay was identified in this pass beyond direct GDPR application.

Telecoms And EprivacyGreen

The Electronic Communications Act, as amended, requires opt-in cookie consent and was subject to 2022 ÚOOÚ compliance checks; it was also amended in consultations to transpose the EU Electronic Communications Code.

Claims: CLM-CZ-2b3c4d5f, CLM-CZ-3c4d5e70

Employment DataRed

No dedicated Czech employment-data sectoral overlay was identified in this pass beyond direct GDPR application.

Credit And ScoringRed

No dedicated Czech credit-scoring sectoral overlay was identified in this pass.

EducationRed

No dedicated Czech education-sector data-protection overlay was identified in this pass.

InsuranceRed

No dedicated Czech insurance-sector data-protection overlay was identified in this pass.

Category narrative60 words

The main confirmed sectoral overlay is telecoms/e-privacy: the Electronic Communications Act (Act No. 127/2005 Coll.), as amended (Act No. 374/2021 Coll. and consultations transposing the European Electronic Communications Code, Directive (EU) 2018/1972), imposes opt-in cookie consent and was a 2022 ÚOOÚ control-plan priority. Financial, health, employment, credit-scoring, education and insurance sectoral overlays were not separately confirmed in this research pass.

Sources and claims (2)
  1. ConfirmedDataGuidanceThe Czech Electronic Communications Act (Act No. 127/2005 Coll.), as amended by Act No. 374/2021 Coll., requires opt-in consent for cookies, and ÚOOÚ's 2022 control plan specifically targeted compliance checks on this opt-in cookie-consent requirement.
  2. ConfirmedDataGuidanceÚOOÚ participated in 2020 consultations to amend the Electronic Communications Act transposing the European Electronic Communications Code (Directive (EU) 2018/1972) and proposed a Criminal Code amendment criminalising misuse of personal data.

#

Cookie and direct-marketing regimes are well evidenced; other adtech sub-areas lack dedicated CZ sourcing.

Primary frameworkAct No. 127/2005 Coll. (Electronic Communications Act); Act No. 480/2004 Coll. on Certain Information Society Services
Traffic-light rationale — AmberCookie and direct-marketing regimes are well evidenced; other adtech sub-areas lack dedicated CZ sourcing.

Sub-modules (6)

Cookies And TrackersAmber

Opt-in cookie consent is required under the amended Electronic Communications Act; ÚOOÚ has also published cookie-consent FAQ guidance (content not independently verified in this pass).

Claims: CLM-CZ-2b3c4d5f

Dark PatternsRed

No dedicated Czech dark-pattern prohibition distinct from GDPR fairness/transparency principles was identified.

Opt Out SignalsRed

No Czech-specific recognition of technical opt-out signals (e.g., GPC) was identified in this pass.

Clean Rooms And DcrRed

No Czech-specific clean-room/data-collaboration-room rules were identified.

Cross Context AdvertisingRed

The CPRA 'sale'/'share' concept is a US state-law construct with no direct Czech/GDPR equivalent; GDPR's consent/legitimate-interest framework applies instead.

Direct MarketingGreen

Act No. 480/2004 Coll. governs unsolicited commercial electronic communications, enforced by ÚOOÚ; this remains one of the most common complaint categories.

Claims: CLM-CZ-5e6f7092

Category narrative56 words

Cookie/tracker consent is governed by the amended Electronic Communications Act requiring opt-in consent. Direct marketing is governed by Act No. 480/2004 Coll. on Certain Information Society Services, with unsolicited-communications complaints a persistent top complaint category at ÚOOÚ. Dark patterns, opt-out signals, clean rooms and cross-context-advertising concepts were not separately confirmed for Czech Republic in this pass.

Sources and claims (1)
  1. ConfirmedDataGuidanceUnder Act No. 480/2004 Coll. on Certain Information Society Services, ÚOOÚ monitors and enforces against unsolicited commercial electronic communications; in 2022 there were 906 complaints about such communications, a very similar figure to 2021, making it one of the most common complaint categories after personal-data-security breaches.

#

Core GDPR Art 22 and state-surveillance carve-out are well evidenced; AI-specific risk-assessment and genetic-data regimes are not yet settled or separately confirmed for CZ.

Primary frameworkRegulation (EU) 2016/679 (GDPR) Art 22; Act No. 110/2019 Coll. Title III (transposing Directive (EU) 2016/680)
Traffic-light rationale — AmberCore GDPR Art 22 and state-surveillance carve-out are well evidenced; AI-specific risk-assessment and genetic-data regimes are not yet settled or separately confirmed for CZ.

Sub-modules (6)

Profiling RestrictionsAmber

GDPR Article 22 profiling restrictions apply directly in Czech Republic as an EU Member State.

Claims: CLM-CZ-a2b3c4d6

Automated Decision Making TransparencyAmber

GDPR Article 22 ADM transparency/explanation rights apply directly; no CZ-specific elaboration was separately confirmed.

Claims: CLM-CZ-a2b3c4d6

Ai Risk AssessmentsAmber

The EU-level Digital Omnibus Regulation proposal, which intersects with GDPR personal-data and profiling concepts, remains in the EU legislative process as of mid-2026, with no binding Czech-specific AI-risk-assessment obligation confirmed yet.

Claims: CLM-CZ-81a2b3c5

Biometric RegimeGreen

ÚOOÚ has flagged systematic supervisory attention to biometric data and CCTV systems as a recurring priority.

Claims: CLM-CZ-6f7081a3

Genetic DataRed

No Czech-specific genetic-data regime distinct from GDPR Article 9 was identified in this pass.

State Surveillance CarveoutsGreen

Act No. 110/2019 Coll. Title III, transposing Directive (EU) 2016/680, establishes a distinct regime with restricted data-subject rights for law-enforcement and national-security processing.

Claims: CLM-CZ-7081a2b4

Category narrative65 words

GDPR Article 22 profiling/ADM restrictions apply directly. ÚOOÚ has flagged biometric data and CCTV as recurring supervisory priorities. Act No. 110/2019 Coll. establishes a distinct Title III/Directive 2016/680 regime for law-enforcement and national-security processing. At EU level, the Digital Omnibus Regulation proposal (still in the legislative process as of mid-2026) may in future affect how GDPR-derived AI-governance concepts are applied, but is not yet binding.

Sources and claims (4)
  1. ProbableEUR-LexGDPR's single EU rulebook, including its Article 22 restrictions on solely-automated decision-making with legal or similarly significant effects, applies directly and uniformly in the Czech Republic.
  2. ConfirmedDataGuidanceÚOOÚ's 2019 annual report states the Office has paid systematic attention to the use of biometric data and CCTV systems, among other supervisory priorities.
  3. ConfirmedIAPPAct No. 110/2019 Coll. transposes Directive (EU) 2016/680, establishing a separate Title III regime for processing of personal data by competent Czech authorities for prevention, investigation, detection or prosecution of criminal offences and for national defense/security, restricting ordinary data-subject rights in that context.
  4. UncertainIAPPAs of mid-2026, the EU's Digital Omnibus Regulation proposal — which intersects with GDPR concepts including personal data and profiling — remains in the EU legislative process, with potential future implications for AI-governance obligations applicable to Czech controllers.

#

The core age-of-consent threshold is well confirmed via primary legislative reporting; other sub-areas lack dedicated CZ sourcing.

Primary frameworkRegulation (EU) 2016/679 (GDPR) Art 8; Act No. 110/2019 Coll.
Traffic-light rationale — GreenThe core age-of-consent threshold is well confirmed via primary legislative reporting; other sub-areas lack dedicated CZ sourcing.

Sub-modules (5)

Age VerificationAmber

No distinct Czech age-verification mechanism/standard was identified in this research pass beyond the GDPR Article 8 age threshold.

Minor Profiling BansRed

No Czech-specific minor-profiling ban distinct from GDPR general principles was identified.

Education SettingsRed

No Czech education-setting-specific data-protection rule was identified in this pass.

Dependent AdultsRed

No Czech-specific dependent-adult data-protection provision was identified in this pass.

Category narrative45 words

Czech Republic's GDPR-implementing legislative process set the age of a child's own valid consent for information-society-service data processing at 15 years (rejecting a proposal to lower it to 13). Age-verification mechanisms, minor-profiling bans, education-setting rules and dependent-adult protections were not separately confirmed in this pass.

Sources and claims (1)
  1. ConfirmedIAPPThe Czech GDPR-implementing legislative process set the age of a child's own valid consent for information-society-service data processing at 15 years, following parliamentary rejection of a proposal to lower this threshold to 13.

#

Well-documented enforcement powers, a landmark cross-border fine decision, and recent (within-180-day) reporting on regulator capacity strain.

Primary frameworkRegulation (EU) 2016/679 (GDPR) Arts 58, 77-84; Act No. 110/2019 Coll.
Traffic-light rationale — GreenWell-documented enforcement powers, a landmark cross-border fine decision, and recent (within-180-day) reporting on regulator capacity strain.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Act No. 110/2019 Coll. abolished fines for public authorities/bodies and permits ÚOOÚ to drop minor offenses informally.

Claims: CLM-CZ-c4d5e6f8

Enforcement Activity IndexGreen

The Avast case (EUR ~13.9M fine, April 2024 appellate decision) is the standout recent CZ enforcement action; complaint volumes run in the low thousands annually.

Claims: CLM-CZ-d5e6f809

Regulator Funding And CapacityAmber

ÚOOÚ's 2025 annual report notes growing strain on its workforce due to increasing case complexity.

Claims: CLM-CZ-e6f8091a

Collective Redress And Class ActionsRed

No Czech-specific collective-redress/class-action mechanism for data protection claims was identified in this pass.

Private Right Of ActionAmber

GDPR Articles 79 and 82 grant a direct judicial-remedy and compensation right, applicable in Czech Republic as directly-effective EU law.

Claims: CLM-CZ-091a2b3d

Recent Developments 180DGreen

An IAPP analysis published 28 May 2026 reports ÚOOÚ's 2025 annual report noting workforce strain, situating Czech trends within record European DPA fines and breach-notification volumes around GDPR's 10th anniversary.

Claims: CLM-CZ-f8091a2c

Category narrative66 words

ÚOOÚ has full GDPR investigative and corrective powers, tempered by a national derogation abolishing fines against public authorities. Enforcement activity includes a landmark EUR ~13.9M fine against an antivirus-software company (Avast) for unlawful data transfer and misinformation, alongside multi-thousand annual complaint volumes. ÚOOÚ's 2025 annual report notes growing workforce strain amid rising case complexity, echoing a Europe-wide trend of record fines around GDPR's 2026 tenth anniversary.

Sources and claims (5)
  1. ConfirmedIAPPAct No. 110/2019 Coll. abolished administrative fines for all public authorities and bodies (governmental bodies, ministries, municipalities, schools, public hospitals and similar public-interest controllers/processors), and empowers ÚOOÚ to drop minor offenses without initiating formal proceedings and without notifying the person concerned.
  2. ConfirmedEDPBIn the Avast antivirus case, the Czech supervisory authority, acting as Lead Supervisory Authority, issued an administrative appellate decision on 10 April 2024 imposing a fine of approximately EUR 13.9 million for infringement of GDPR Articles 6 and 13, concerning the transfer of pseudonymized browsing-history data of roughly 100 million users to a sister company without a valid legal basis, while misinforming users that the data were anonymized.
  3. ConfirmedIAPPIn its 2025 annual report, ÚOOÚ noted growing strain on its workforce due to the increasing complexity of cases handled.
  4. ConfirmedIAPPAn IAPP analysis published 28 May 2026 reports that ÚOOÚ's 2025 annual report highlighted growing workforce strain from increasingly complex cases, situating Czech enforcement trends within the broader wave of record European DPA fines and breach-notification volumes reported around GDPR's tenth anniversary in May 2026.
  5. ProbableEUR-LexGDPR Articles 79 and 82 grant data subjects in the Czech Republic a direct right to an effective judicial remedy against controllers/processors and a right to compensation for material or non-material damage, applicable directly as EU Regulation provisions.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Czech Republic
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 30 claim(s), 14 source(s) in the cumulative register.