Law / Czech Republic

Czech Republic

privacy

Czechia's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by Act No. 110/2019 Coll. on Personal Data Processing, read directly and found to be predominantly procedural with no substantive biometric-specific narrowing.

The genuine Czech national addition surveyed in this pass is Acts 179/2024 and 180/2024 Coll., a collective civil court proceeding statute transposing the EU Representative Actions Directive, confirmed in force 1 July 2024 through a private legal database rather than the official gazette. No specific Czech employment-biometric provision was found; this is a genuine gap, not a confirmed absence, since the Labour Code's own text was not read directly.

17 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

GDPR Articles 33-34, Breach Notification

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source GDPR Arts. 33-34

A controller must notify UOOU within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk.

One commentary source (CMS) states Czech controllers may report a breach in limited scope or with delay in circumstances protecting Czech national interests; this session's own direct read of Act 110/2019 did not surface such a clause, so it is reported here as an unverified commentary claim rather than a confirmed derogation.

What it asks of an app

Comprehensive regime

Act on Personal Data Processing

cite Zakon c. 110/2019 Sb., o zpracovani osobnich udaju stage In effect since 2019-04-24 source UOOU, English translation PDF (direct fetch)

Czechia gives the General Data Protection Regulation (GDPR) domestic effect through Act No. 110/2019 Coll., in force since 24 April 2019, replacing the pre-GDPR Act No. 101/2000 Coll. Read via the Office for Personal Data Protection's own English translation, it is predominantly procedural: it establishes the supervisory authority's powers, administrative-offense and fine procedures, and processing by competent authorities for criminal-law purposes transposing Directive (EU) 2016/680. It adds no substantive lawful-basis or controller and processor rules beyond GDPR.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c) stage In effect since 2018-05-25 source GDPR Arts. 44-49, 83(5)(c)

A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. Commentary sources confirm Czechia has adopted no further domestic derogation.

What it asks of an app

Data subject rights

GDPR Articles 12-22, Data-Subject Rights

cite Regulation (EU) 2016/679, Arts. 12-22 stage In effect since 2018-05-25 source GDPR Arts. 12-22

General Data Protection Regulation (GDPR) Articles 12-22 (access, rectification, erasure, restriction, portability, objection, and Article 22 automated-decision rights) apply directly; Act 110/2019 adds no distinct national rights found in this pass, exercisable against the controller within GDPR's own one-month (extendable to three-month) response window.

What it asks of an app

Enforcement supervision

UOOU Enforcement, GDPR Article 82, and the Act on Collective Civil Court Proceeding

cite Regulation (EU) 2016/679, Arts. 82-83; Zakon c. 179/2024 Sb., o hromadnem obcanskem soudnim rizeni; Zakon c. 180/2024 Sb. stage In effect since 2024-07-01 source zakonyprolidi.cz (unofficial legal database, direct fetch, confirming title and dates)

UOOU (Office for Personal Data Protection) is Czechia's supervisory authority, empowered under Act 110/2019 to impose General Data Protection Regulation (GDPR) Article 83 fines. GDPR Article 82 arms an individual with a direct private right of action.

Czechia's genuine national addition beyond that baseline is Act No. 179/2024 Coll. on Collective Civil Court Proceeding, together with the accompanying Act No. 180/2024 Coll., in force 1 July 2024, transposing Directive (EU) 2020/1828 on representative actions; only registered qualified entities may bring such an action.

This session confirmed the act's title, in-force date of 1 July 2024, and structure through zakonyprolidi.cz, a widely used private legal database rather than the official gazette; as of an October 2025 commentary report only two entities were registered and one unrelated action had been filed.

What it asks of an app

Sensitive categories

GDPR Article 9, Special Categories Including Biometric Data

cite Regulation (EU) 2016/679, Art. 9 stage In effect since 2018-05-25 source UOOU, Act 110/2019 (direct read, no biometric provision found)

General Data Protection Regulation (GDPR) Article 9(1) treats biometric data processed for unique identification as a special category, prohibited absent an Article 9(2) ground. A direct read of Act 110/2019 found no biometric-specific provision narrowing or elaborating this, consistent with two independent commentary sources describing no distinct Czech biometric restriction beyond the general EU-law enabling clause.

General employee monitoring sits in the Labour Code (zakonik prace, Act No. 262/2006 Coll.), but this session did not read that Act's text directly and found no specific employment-biometric consent or works-council provision in commentary; this is a genuine gap, not a confirmed absence.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.