Law note · Czechia
GDPR Articles 33-34, Breach Notification
A controller must notify UOOU within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk.
One commentary source (CMS) states Czech controllers may report a breach in limited scope or with delay in circumstances protecting Czech national interests; this session's own direct read of Act 110/2019 did not surface such a clause, so it is reported here as an unverified commentary claim rather than a confirmed derogation.
What it asks of an app
- Notify UOOU within 72 hours of becoming aware of a personal-data breach affecting a person in Czechia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics
Primary source: GDPR Arts. 33-34
CMS commentary (unverified against Act 110/2019's own text)