Traffic-light rationale — GreenFull GDPR direct effect plus a settled, in-force national implementing Act and an operational, EDPB-member supervisory authority.
Sub-modules (5)
Regulator And AuthorityGreen
ÚOOÚ, seated at Pplk. Sochora 27, Prague 7, is the Czech GDPR supervisory authority and a voting member of the EDPB.
Claims: CLM-CZ-1a2b3c4d
Act And InstrumentsGreen
Act No. 110/2019 Coll. is the core national instrument; it replaced the prior Data Protection Act and transposes the Law Enforcement Directive.
Claims: CLM-CZ-2b3c4d5e
Material ScopeGreen
The Act carries local derogations mainly benefiting public authorities and triggered amendment of over 30 other Czech statutes.
Claims: CLM-CZ-3c4d5e6f
Territorial ScopeGreen
GDPR's extraterritorial rule (targeting/monitoring of EU data subjects) applies directly to non-EU controllers vis-à-vis Czech data subjects.
Claims: CLM-CZ-4d5e6f70
Regulator Registration And FilingAmber
No general controller registration/notification-fee regime (analogous to the UK ICO fee system) was identified for Czech Republic in this research pass; GDPR abolished the EU-wide prior-notification requirement that existed under the pre-2018 regime.
Claims: CLM-CZ-5e6f7081
Category narrative58 words
Czech Republic is an EU Member State operating under the direct-effect GDPR, implemented and supplemented nationally by Act No. 110/2019 Coll. on Personal Data Processing, which establishes the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ) as the supervisory authority, includes local derogations (chiefly for public authorities), and transposes Directive (EU) 2016/680 for law-enforcement/security processing.
Sources and claims (5)
ConfirmedEDPB — The Office for Personal Data Protection (ÚOOÚ), seated at Pplk. Sochora 27, Prague 7, is the Czech Republic's GDPR supervisory authority and a full voting member of the European Data Protection Board.
ConfirmedIAPP — Act No. 110/2019 Coll. on Personal Data Processing fully replaces the prior Czech Data Protection Act, establishes the constitution and powers of the Czech Data Protection Office, and transposes Directive (EU) 2016/680 governing processing of personal data for crime prevention/investigation and defense/security purposes.
ConfirmedIAPP — The Data Protection Act includes local derogations and exceptions primarily for public authorities, and its Accompanying Act amends more than 30 other Czech laws in connection with GDPR and Directive 2016/680 implementation.
ConfirmedEUR-Lex — Companies not established in the EU must comply with GDPR rules, including as applied by Czech supervisory authority, when they offer goods/services to or monitor the behaviour of individuals in the EU.
UncertainEDPB / ÚOOÚ — No distinct Czech controller-registration or filing-fee regime was confirmed in this research pass; GDPR's harmonised approach removed the general prior-notification obligation that existed under the pre-2018 Czech data protection regime.
Traffic-light rationale — GreenDirect GDPR effect confirmed plus ÚOOÚ consent guidance; special-category specifics not separately verified this pass.
Sub-modules (4)
Lawful BasesGreen
GDPR Article 6's enumerated lawful bases apply directly, EU-wide, without a substitute Czech list.
Claims: CLM-CZ-6f708192
Consent ThresholdsGreen
ÚOOÚ has issued national guidance on GDPR-compliant consent, emphasising clear, distinguishable, plain-language requests and the Article 7(4) bundling test.
Claims: CLM-CZ-708192a3
Special CategoriesAmber
No Czech-specific derogation to GDPR Article 9 special-category rules was identified in this research pass; Article 9 is presumed to apply directly.
Claims: CLM-CZ-8192a3b4
Pseudonymisation And AnonymisationGreen
GDPR's technology-neutral safe-harbours (pseudonymisation, encryption) apply directly in Czech Republic as an EU Member State.
Claims: CLM-CZ-92a3b4c5
Category narrative35 words
GDPR's Article 6 lawful bases, consent standards, and Article 9 special-category rules apply directly as EU law in Czech Republic; ÚOOÚ has supplemented this with national consent guidance. Pseudonymisation/anonymisation safe-harbours follow the GDPR's technology-neutral approach.
Sources and claims (4)
ConfirmedEUR-Lex — GDPR establishes a single EU-wide rulebook for data protection, including its Article 6 lawful bases, applicable directly and uniformly in the Czech Republic as an EU Member State.
ConfirmedDataGuidance — ÚOOÚ guidance issued in March 2018 requires that requests for consent be presented in a manner clearly distinguishable from other matters, in intelligible and easily accessible form using clear and plain language, and highlights GDPR Article 7(4) on whether consent is improperly bundled with contract performance.
UncertainEUR-Lex — GDPR Article 9's special-category regime (health, biometric, genetic, ethnic, political, sexual, criminal data) is presumed to apply directly in Czech Republic absent an identified national derogation.
ConfirmedEUR-Lex — GDPR promotes privacy-enhancing techniques such as pseudonymisation (replacing identifying fields with identification codes) and encryption as recognised safeguards, applicable directly in the Czech Republic.
Traffic-light rationale — GreenDirect GDPR effect confirmed via official guidance notes; a documented national carve-out exists for law-enforcement/security processing.
Sub-modules (5)
Access RightGreen
GDPR governs the subject-access request framework directly in Czechia.
Claims: CLM-CZ-a3b4c5d6
Rectification And ErasureGreen
GDPR's rectification/erasure rights apply directly; no CZ-specific derogation identified beyond the Title III carve-out.
Claims: CLM-CZ-a3b4c5d6
Restriction And ObjectionGreen
GDPR's restriction and objection rights (including profiling opt-out) apply directly in Czechia.
Claims: CLM-CZ-a3b4c5d6
Data PortabilityAmber
GDPR's portability right applies directly; no distinct Czech implementation detail was separately verified.
Claims: CLM-CZ-a3b4c5d6
Deadlines And Response WindowsGreen
Title III of Act No. 110/2019 Coll. restricts ordinary data-subject-rights deadlines/response obligations for criminal-matters and national-security processing by competent authorities.
Claims: CLM-CZ-b4c5d6e7
Category narrative33 words
GDPR governs data subject rights directly in Czechia (access, rectification, erasure, restriction, objection, portability), supplemented by Act No. 110/2019 Coll., whose Title III carves out restrictions for criminal-matters/national-security processing by competent public authorities.
Sources and claims (2)
ConfirmedDataGuidance — The General Data Protection Regulation governs data subject rights in Czechia, directly conferring rights of access, rectification, erasure, restriction, objection and portability, as supplemented by Act No. 110/2019 Coll. on Personal Data Processing.
ConfirmedDataGuidance — Title III of Act No. 110/2019 Coll. governs the processing of personal data in relation to criminal matters and national security by competent Czech public authorities and provides restrictions on the rights of data subjects in that context.
Well-documented national DPIA and DPO provisions plus an active breach-notification regime evidenced by ÚOOÚ annual-report statistics; ROPA/joint-controller/retention specifics not separately verified this pass.
Traffic-light rationale — GreenWell-documented national DPIA and DPO provisions plus an active breach-notification regime evidenced by ÚOOÚ annual-report statistics; ROPA/joint-controller/retention specifics not separately verified this pass.
Sub-modules (7)
Accountability And DpiaGreen
Section 10 of Act No. 110/2019 Coll. introduces a 'legislative DPIA' for all legislative proposals affecting personal data, effective 1 April 2023, replacing the standard Article 35 DPIA for that measure.
Claims: CLM-CZ-c5d6e7f8
Dpo RequirementsGreen
Sections 14 and 16(1)(d) of Act No. 110/2019 Coll., alongside GDPR Arts 37-39, govern DPO appointment; ÚOOÚ requires email notification of DPO appointments with controller and DPO contact details.
Claims: CLM-CZ-d6e7f809
Ropa RequirementsAmber
GDPR Article 30 ROPA obligations apply directly; no CZ-specific derogation identified in this pass.
GDPR Article 32 security-of-processing obligations apply directly; no CZ-specific technical standard was separately verified.
Breach NotificationGreen
ÚOOÚ operates an active breach-notification regime; in 2019 it recorded 416 personal-data-breach notifications.
Claims: CLM-CZ-e7f8091a
Retention And DisposalAmber
GDPR's storage-limitation principle applies directly; no CZ-specific retention schedule was identified in this pass.
Category narrative37 words
GDPR's accountability, DPIA, DPO, security, breach-notification and retention obligations apply directly, supplemented by Act No. 110/2019 Coll.'s Section 10 'legislative DPIA' mechanism (effective 1 April 2023) and Sections 14/16(1)(d) DPO provisions, including a defined ÚOOÚ DPO-notification channel.
Sources and claims (3)
ConfirmedDataGuidance — Since 1 April 2023, Section 10 of Act No. 110/2019 Coll. requires a 'legislative DPIA' for every legislative proposal, including subsidiary regulations such as government decrees or ordinances, which under GDPR Article 35(10) replaces the standard Article 35(1) DPIA for that specific legislative measure.
ConfirmedDataGuidance — Sections 14 and 16(1)(d) of Act No. 110/2019 Coll., read with GDPR Articles 37-39, govern DPO appointment in the Czech Republic; ÚOOÚ requires notification of DPO appointments by the controller/processor (not the DPO), including the DPO's contact details.
ConfirmedDataGuidance — ÚOOÚ's 2019 annual report recorded 2,600 queries, 2,482 complaints, and 416 notifications of personal data breaches, evidencing an operative breach-notification regime.
Traffic-light rationale — GreenGDPR transfer toolkit applies directly; the EU's new cross-border enforcement procedural regulation is confirmed adopted and published.
Sub-modules (6)
Transfer MechanismsGreen
GDPR offers a modern toolkit for international transfers — adequacy decisions, SCCs, BCRs, codes of conduct and certification — applicable directly in Czech Republic.
Claims: CLM-CZ-f8091a2b
Adequacy ReceivedGreen
Adequacy is an EU-Commission-level competence; Czech Republic does not operate a separate national adequacy-reception process.
Claims: CLM-CZ-1a2b3c4e
Adequacy GrantedGreen
Adequacy decisions granted to third countries are adopted at EU-Commission level and apply uniformly across all Member States including Czech Republic; no separate CZ national adequacy-granting process exists.
Claims: CLM-CZ-1a2b3c4e
Sccs And BcrsGreen
SCCs and BCRs are available as GDPR transfer mechanisms directly applicable in Czech Republic.
Claims: CLM-CZ-f8091a2b
Transfer Impact AssessmentAmber
The EU-wide post-Schrems II transfer-impact-assessment expectation is presumed to apply in Czech Republic; not separately confirmed via CZ-specific ÚOOÚ guidance in this pass.
Data LocalisationAmber
No CZ-specific data-localisation mandate was identified in this research pass.
Category narrative38 words
As an EU Member State, Czech Republic operates under the GDPR's full cross-border transfer toolkit (adequacy decisions adopted at EU-Commission level, SCCs, BCRs, codes of conduct, certification) and the newly adopted EU procedural regulation for cross-border GDPR enforcement.
Sources and claims (3)
ConfirmedEUR-Lex — GDPR offers a modern toolkit for international data transfers outside the EU, including European Commission adequacy decisions, pre-approved standard contractual clauses, binding corporate rules, codes of conduct and certification, all directly applicable in the Czech Republic.
ProbableEUR-Lex — Adequacy decisions under GDPR Article 45 are adopted by the European Commission and apply uniformly across all EU Member States, including the Czech Republic, without a separate Czech national adequacy process.
ConfirmedEUR-Lex — Regulation (EU) 2025/2518, adopted 26 November 2025 and published in the Official Journal on 12 December 2025, lays down procedural rules for enforcing the GDPR in cross-border cases, aiming to make investigations and complaint-handling faster and more uniform across Member States including the Czech Republic.
Traffic-light rationale — AmberOne sectoral overlay (telecoms/e-privacy) is well evidenced; other sector modules lack dedicated Czech sectoral sourcing this pass.
Sub-modules (7)
Financial Sector OverlayRed
No dedicated Czech financial-sector data-protection overlay was identified in this pass beyond direct GDPR application.
Health Sector OverlayRed
No dedicated Czech health-sector data-protection overlay was identified in this pass beyond direct GDPR application.
Telecoms And EprivacyGreen
The Electronic Communications Act, as amended, requires opt-in cookie consent and was subject to 2022 ÚOOÚ compliance checks; it was also amended in consultations to transpose the EU Electronic Communications Code.
Claims: CLM-CZ-2b3c4d5f, CLM-CZ-3c4d5e70
Employment DataRed
No dedicated Czech employment-data sectoral overlay was identified in this pass beyond direct GDPR application.
Credit And ScoringRed
No dedicated Czech credit-scoring sectoral overlay was identified in this pass.
EducationRed
No dedicated Czech education-sector data-protection overlay was identified in this pass.
InsuranceRed
No dedicated Czech insurance-sector data-protection overlay was identified in this pass.
Category narrative60 words
The main confirmed sectoral overlay is telecoms/e-privacy: the Electronic Communications Act (Act No. 127/2005 Coll.), as amended (Act No. 374/2021 Coll. and consultations transposing the European Electronic Communications Code, Directive (EU) 2018/1972), imposes opt-in cookie consent and was a 2022 ÚOOÚ control-plan priority. Financial, health, employment, credit-scoring, education and insurance sectoral overlays were not separately confirmed in this research pass.
Sources and claims (2)
ConfirmedDataGuidance — The Czech Electronic Communications Act (Act No. 127/2005 Coll.), as amended by Act No. 374/2021 Coll., requires opt-in consent for cookies, and ÚOOÚ's 2022 control plan specifically targeted compliance checks on this opt-in cookie-consent requirement.
ConfirmedDataGuidance — ÚOOÚ participated in 2020 consultations to amend the Electronic Communications Act transposing the European Electronic Communications Code (Directive (EU) 2018/1972) and proposed a Criminal Code amendment criminalising misuse of personal data.
Traffic-light rationale — AmberCookie and direct-marketing regimes are well evidenced; other adtech sub-areas lack dedicated CZ sourcing.
Sub-modules (6)
Cookies And TrackersAmber
Opt-in cookie consent is required under the amended Electronic Communications Act; ÚOOÚ has also published cookie-consent FAQ guidance (content not independently verified in this pass).
Claims: CLM-CZ-2b3c4d5f
Dark PatternsRed
No dedicated Czech dark-pattern prohibition distinct from GDPR fairness/transparency principles was identified.
Opt Out SignalsRed
No Czech-specific recognition of technical opt-out signals (e.g., GPC) was identified in this pass.
Clean Rooms And DcrRed
No Czech-specific clean-room/data-collaboration-room rules were identified.
Cross Context AdvertisingRed
The CPRA 'sale'/'share' concept is a US state-law construct with no direct Czech/GDPR equivalent; GDPR's consent/legitimate-interest framework applies instead.
Direct MarketingGreen
Act No. 480/2004 Coll. governs unsolicited commercial electronic communications, enforced by ÚOOÚ; this remains one of the most common complaint categories.
Claims: CLM-CZ-5e6f7092
Category narrative56 words
Cookie/tracker consent is governed by the amended Electronic Communications Act requiring opt-in consent. Direct marketing is governed by Act No. 480/2004 Coll. on Certain Information Society Services, with unsolicited-communications complaints a persistent top complaint category at ÚOOÚ. Dark patterns, opt-out signals, clean rooms and cross-context-advertising concepts were not separately confirmed for Czech Republic in this pass.
Sources and claims (1)
ConfirmedDataGuidance — Under Act No. 480/2004 Coll. on Certain Information Society Services, ÚOOÚ monitors and enforces against unsolicited commercial electronic communications; in 2022 there were 906 complaints about such communications, a very similar figure to 2021, making it one of the most common complaint categories after personal-data-security breaches.
Core GDPR Art 22 and state-surveillance carve-out are well evidenced; AI-specific risk-assessment and genetic-data regimes are not yet settled or separately confirmed for CZ.
Primary frameworkRegulation (EU) 2016/679 (GDPR) Art 22; Act No. 110/2019 Coll. Title III (transposing Directive (EU) 2016/680)
Traffic-light rationale — AmberCore GDPR Art 22 and state-surveillance carve-out are well evidenced; AI-specific risk-assessment and genetic-data regimes are not yet settled or separately confirmed for CZ.
Sub-modules (6)
Profiling RestrictionsAmber
GDPR Article 22 profiling restrictions apply directly in Czech Republic as an EU Member State.
Claims: CLM-CZ-a2b3c4d6
Automated Decision Making TransparencyAmber
GDPR Article 22 ADM transparency/explanation rights apply directly; no CZ-specific elaboration was separately confirmed.
Claims: CLM-CZ-a2b3c4d6
Ai Risk AssessmentsAmber
The EU-level Digital Omnibus Regulation proposal, which intersects with GDPR personal-data and profiling concepts, remains in the EU legislative process as of mid-2026, with no binding Czech-specific AI-risk-assessment obligation confirmed yet.
Claims: CLM-CZ-81a2b3c5
Biometric RegimeGreen
ÚOOÚ has flagged systematic supervisory attention to biometric data and CCTV systems as a recurring priority.
Claims: CLM-CZ-6f7081a3
Genetic DataRed
No Czech-specific genetic-data regime distinct from GDPR Article 9 was identified in this pass.
State Surveillance CarveoutsGreen
Act No. 110/2019 Coll. Title III, transposing Directive (EU) 2016/680, establishes a distinct regime with restricted data-subject rights for law-enforcement and national-security processing.
Claims: CLM-CZ-7081a2b4
Category narrative65 words
GDPR Article 22 profiling/ADM restrictions apply directly. ÚOOÚ has flagged biometric data and CCTV as recurring supervisory priorities. Act No. 110/2019 Coll. establishes a distinct Title III/Directive 2016/680 regime for law-enforcement and national-security processing. At EU level, the Digital Omnibus Regulation proposal (still in the legislative process as of mid-2026) may in future affect how GDPR-derived AI-governance concepts are applied, but is not yet binding.
Sources and claims (4)
ProbableEUR-Lex — GDPR's single EU rulebook, including its Article 22 restrictions on solely-automated decision-making with legal or similarly significant effects, applies directly and uniformly in the Czech Republic.
ConfirmedDataGuidance — ÚOOÚ's 2019 annual report states the Office has paid systematic attention to the use of biometric data and CCTV systems, among other supervisory priorities.
ConfirmedIAPP — Act No. 110/2019 Coll. transposes Directive (EU) 2016/680, establishing a separate Title III regime for processing of personal data by competent Czech authorities for prevention, investigation, detection or prosecution of criminal offences and for national defense/security, restricting ordinary data-subject rights in that context.
UncertainIAPP — As of mid-2026, the EU's Digital Omnibus Regulation proposal — which intersects with GDPR concepts including personal data and profiling — remains in the EU legislative process, with potential future implications for AI-governance obligations applicable to Czech controllers.
Traffic-light rationale — GreenThe core age-of-consent threshold is well confirmed via primary legislative reporting; other sub-areas lack dedicated CZ sourcing.
Sub-modules (5)
Age VerificationAmber
No distinct Czech age-verification mechanism/standard was identified in this research pass beyond the GDPR Article 8 age threshold.
Parental ConsentGreen
The age of consent for a child's own consent to information-society-service processing is set at 15 years under the Czech GDPR-implementing legislation, following rejection of a proposal to lower it to 13.
Claims: CLM-CZ-b3c4d5e7
Minor Profiling BansRed
No Czech-specific minor-profiling ban distinct from GDPR general principles was identified.
Education SettingsRed
No Czech education-setting-specific data-protection rule was identified in this pass.
Dependent AdultsRed
No Czech-specific dependent-adult data-protection provision was identified in this pass.
Category narrative45 words
Czech Republic's GDPR-implementing legislative process set the age of a child's own valid consent for information-society-service data processing at 15 years (rejecting a proposal to lower it to 13). Age-verification mechanisms, minor-profiling bans, education-setting rules and dependent-adult protections were not separately confirmed in this pass.
Sources and claims (1)
ConfirmedIAPP — The Czech GDPR-implementing legislative process set the age of a child's own valid consent for information-society-service data processing at 15 years, following parliamentary rejection of a proposal to lower this threshold to 13.
Traffic-light rationale — GreenWell-documented enforcement powers, a landmark cross-border fine decision, and recent (within-180-day) reporting on regulator capacity strain.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
Act No. 110/2019 Coll. abolished fines for public authorities/bodies and permits ÚOOÚ to drop minor offenses informally.
Claims: CLM-CZ-c4d5e6f8
Enforcement Activity IndexGreen
The Avast case (EUR ~13.9M fine, April 2024 appellate decision) is the standout recent CZ enforcement action; complaint volumes run in the low thousands annually.
Claims: CLM-CZ-d5e6f809
Regulator Funding And CapacityAmber
ÚOOÚ's 2025 annual report notes growing strain on its workforce due to increasing case complexity.
Claims: CLM-CZ-e6f8091a
Collective Redress And Class ActionsRed
No Czech-specific collective-redress/class-action mechanism for data protection claims was identified in this pass.
Private Right Of ActionAmber
GDPR Articles 79 and 82 grant a direct judicial-remedy and compensation right, applicable in Czech Republic as directly-effective EU law.
Claims: CLM-CZ-091a2b3d
Recent Developments 180DGreen
An IAPP analysis published 28 May 2026 reports ÚOOÚ's 2025 annual report noting workforce strain, situating Czech trends within record European DPA fines and breach-notification volumes around GDPR's 10th anniversary.
Claims: CLM-CZ-f8091a2c
Category narrative66 words
ÚOOÚ has full GDPR investigative and corrective powers, tempered by a national derogation abolishing fines against public authorities. Enforcement activity includes a landmark EUR ~13.9M fine against an antivirus-software company (Avast) for unlawful data transfer and misinformation, alongside multi-thousand annual complaint volumes. ÚOOÚ's 2025 annual report notes growing workforce strain amid rising case complexity, echoing a Europe-wide trend of record fines around GDPR's 2026 tenth anniversary.
Sources and claims (5)
ConfirmedIAPP — Act No. 110/2019 Coll. abolished administrative fines for all public authorities and bodies (governmental bodies, ministries, municipalities, schools, public hospitals and similar public-interest controllers/processors), and empowers ÚOOÚ to drop minor offenses without initiating formal proceedings and without notifying the person concerned.
ConfirmedEDPB — In the Avast antivirus case, the Czech supervisory authority, acting as Lead Supervisory Authority, issued an administrative appellate decision on 10 April 2024 imposing a fine of approximately EUR 13.9 million for infringement of GDPR Articles 6 and 13, concerning the transfer of pseudonymized browsing-history data of roughly 100 million users to a sister company without a valid legal basis, while misinforming users that the data were anonymized.
ConfirmedIAPP — In its 2025 annual report, ÚOOÚ noted growing strain on its workforce due to the increasing complexity of cases handled.
ConfirmedIAPP — An IAPP analysis published 28 May 2026 reports that ÚOOÚ's 2025 annual report highlighted growing workforce strain from increasingly complex cases, situating Czech enforcement trends within the broader wave of record European DPA fines and breach-notification volumes reported around GDPR's tenth anniversary in May 2026.
ProbableEUR-Lex — GDPR Articles 79 and 82 grant data subjects in the Czech Republic a direct right to an effective judicial remedy against controllers/processors and a right to compensation for material or non-material damage, applicable directly as EU Regulation provisions.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Czech Republic
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 30 claim(s), 14 source(s) in the cumulative register.