Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
source GDPR Arts. 33-34
A controller must notify UOOU within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk.
One commentary source (CMS) states Czech controllers may report a breach in limited scope or with delay in circumstances protecting Czech national interests; this session's own direct read of Act 110/2019 did not surface such a clause, so it is reported here as an unverified commentary claim rather than a confirmed derogation.
What it asks of an app →
Comprehensive regime
cite Zakon c. 110/2019 Sb., o zpracovani osobnich udaju
stage In effect
since 2019-04-24
source UOOU, English translation PDF (direct fetch)
Czechia gives the General Data Protection Regulation (GDPR) domestic effect through Act No. 110/2019 Coll., in force since 24 April 2019, replacing the pre-GDPR Act No. 101/2000 Coll. Read via the Office for Personal Data Protection's own English translation, it is predominantly procedural: it establishes the supervisory authority's powers, administrative-offense and fine procedures, and processing by competent authorities for criminal-law purposes transposing Directive (EU) 2016/680. It adds no substantive lawful-basis or controller and processor rules beyond GDPR.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c)
stage In effect
since 2018-05-25
source GDPR Arts. 44-49, 83(5)(c)
A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. Commentary sources confirm Czechia has adopted no further domestic derogation.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Arts. 12-22
stage In effect
since 2018-05-25
source GDPR Arts. 12-22
General Data Protection Regulation (GDPR) Articles 12-22 (access, rectification, erasure, restriction, portability, objection, and Article 22 automated-decision rights) apply directly; Act 110/2019 adds no distinct national rights found in this pass, exercisable against the controller within GDPR's own one-month (extendable to three-month) response window.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83; Zakon c. 179/2024 Sb., o hromadnem obcanskem soudnim rizeni; Zakon c. 180/2024 Sb.
stage In effect
since 2024-07-01
source zakonyprolidi.cz (unofficial legal database, direct fetch, confirming title and dates)
UOOU (Office for Personal Data Protection) is Czechia's supervisory authority, empowered under Act 110/2019 to impose General Data Protection Regulation (GDPR) Article 83 fines. GDPR Article 82 arms an individual with a direct private right of action.
Czechia's genuine national addition beyond that baseline is Act No. 179/2024 Coll. on Collective Civil Court Proceeding, together with the accompanying Act No. 180/2024 Coll., in force 1 July 2024, transposing Directive (EU) 2020/1828 on representative actions; only registered qualified entities may bring such an action.
This session confirmed the act's title, in-force date of 1 July 2024, and structure through zakonyprolidi.cz, a widely used private legal database rather than the official gazette; as of an October 2025 commentary report only two entities were registered and one unrelated action had been filed.
What it asks of an app →
Sensitive categories
cite Regulation (EU) 2016/679, Art. 9
stage In effect
since 2018-05-25
source UOOU, Act 110/2019 (direct read, no biometric provision found)
General Data Protection Regulation (GDPR) Article 9(1) treats biometric data processed for unique identification as a special category, prohibited absent an Article 9(2) ground. A direct read of Act 110/2019 found no biometric-specific provision narrowing or elaborating this, consistent with two independent commentary sources describing no distinct Czech biometric restriction beyond the general EU-law enabling clause.
General employee monitoring sits in the Labour Code (zakonik prace, Act No. 262/2006 Coll.), but this session did not read that Act's text directly and found no specific employment-biometric consent or works-council provision in commentary; this is a genuine gap, not a confirmed absence.
What it asks of an app →