TerraLex Guide to Data Protection

Welcome to the Terralex cross-border guide to data protection

Data protection continues to be a top issue for companies around the globe. With the ever-changing technology and responding legislation, it is important that businesses be prepared to handle a patchwork of data protection regulations. This guide, prepared by TerraLex members from around the globe, provides initial guidance on some of the key aspects to consider.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Czech Republic TerraLex Guide to Data Protection Guide

Authors:
Pavel Jakab
Date posted:
27/04/2021
Last update:
31/07/2026

Legislation and regulations

What national laws regulate the processing of personal data in your jurisdiction?

The main laws on personal data processing in the Czech Republic are:

  • the act no. 110/2019 Coll., on personal data processing, as amended (Act), which supplements the GDPR and transposes, inter alia, Directive (EU) 2016/680 into Czech law, and
  • the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (General Data Protection Regulation) (GDPR).

To whom do the laws apply?

The Act transposes the applicable regulations of the European Union (Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA); simultaneously, it follows on from directly applicable regulation of the European Union (GDPR) and, to satisfy the right of every person to protection of privacy, provides for the rights and obligations in personal data processing.

The Act provides for the following:

  • Personal data processing pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) (Title II of the Act);
  • Personal data processing by the competent authorities for the purpose of prevention, investigation, or detection of criminal offences, prosecution of criminal offences, execution of criminal penalties and protective measures, ensuring security of the Czech Republic and ensuring public policy and national security, including search for persons and objects (Title III of the Act);
  • Personal data processing in ensuring the defence and security interests of the Czech Republic (Title IV of the Act);
  • Other processing of personal data that form or are intended to form part of a filing system or that are processed wholly or partly by automated means, other than personal data processing by a natural person in the course of a purely personal or household activity; and
  • The status and powers of the Office for Personal Data Protection (hereinafter the “Office”) (Title V of the Act).

Scope of protection

What type of data is covered by the law?

Personal data as defined in the GDPR; a data subject shall mean a natural person to whom personal data are related.

What are the main exemptions (if any)?

The provisions of Title II of the Act apply to personal data processing pursuant to the GDPR. The provisions of this Title and the GDPR also apply to the processing of personal data that form or are intended to form part of a filing system or that is wholly or partly carried out by automated means, other than personal data processing by a natural person in the course of a purely personal or household activity:

  • In the course of activities which fall outside the scope of EU law or the scope of Title III or IV; or
  • In the course of activities which fall within the scope of Chapter 2 of Title V of the Treaty on the EU.

The main exemptions are the following:

  • Under section 6 of the Act, in ensuring a protected interest (as defined in section 6(2)), controllers are not obliged to assess compatibility of purposes other than for which personal data were collected before processing of personal data for such other purpose, unless another legal regulation states otherwise and if this is necessary and proportionate for compliance with a)An obligation imposed on the controller; or b)A task carried out in the public interest laid down by a legal regulation or in the exercise of official authority vested in the controller.
  • Under section 7 of the Act, a child shall enjoy the capacity to grant consent to personal data processing in relation to an offer of information society services addressed directly to a child from fifteen years of age.
  • Under section 8 of the Act, if the controller carries out personal data processing pursuant to Section 5 above and is obliged to provide information to the data subject pursuant to Art. 13 or Art. 14 (1), (2) and (4) of the GDPR, the controller may provide such information in a manner enabling remote access within a scope appropriate to the personal data processing usually carried out by the controller.
  • Under section 9 of the Act, if the controller has the obligation to communicate to the recipient a rectification, restriction of processing and/or erasure of personal data, it may do so by means of a change of the personal data in the filing system, provided that the controller regularly discloses its valid contents to the recipient.
  • Under section 10 of the Act, the controller need not carry out assessment of the impact of data processing on personal data protection prior to commencement of personal data processing if it is required to carry out such processing under a legal regulation

What rights do the laws grant to the data owners?

The data ore owned by the data subjects. The rights of the data subjects under the Act are, in general, the same as under the GDPR.

Processing requirement and main obligations

What are the lawful grounds for processing personal data or sensitive personal data (if different)?

Generally, the lawful grounds for processing of personal data under the Act are the same as under the GDPR. There are some special provisions on the processing of personal data:

  • Under section 16 of the Act, personal data processing for purposes of scientific or historical research or for statistical purposes (Title II of the Act);
  • Under section 17 of the Act, personal data processing for journalistic purposes or purposes of academic, artistic, or literary expression (Tittle II of the Act);
  • Under section 24 and following of the Act, personal data processing by the competent authorities for the purpose of prevention, investigation, or detection of criminal offences, prosecution of criminal offences, execution of criminal penalties and protective measures, ensuring security of the Czech Republic, and ensuring public policy and national security, including search for persons and objects (Title III of the Act);
  • Under section 43 and following of the Act, personal data processing in ensuring the defence and security interests of the Czech Republic (Title IV of the Act).

What are the main obligations imposed by the law?

The main obligations under the Act are generally the same as under the GDPR.

Do the laws establish a data retention period to be observed?

In many different laws (mainly, in the tax laws, the laws on social and health insurance and the laws on accounting) there are special provisions on retention periods in particular cases (the retention periods for particular documents, including personal data, are usually from 5 to 45 years in these cases).

Must the data processing activities be recorded under the law?

Generally, the requirements for recording of personal data activities under Title II of the Act are the same as under the GDPR. The Act includes some special requirements in this regard for the processing of personal data in Titles III and IV (i.e., personal data processing for the purpose of prevention, investigation, or detection of crimes, and personal data processing in ensuring the defence and security interests of the Czech Republic).

National authority and DPO

Is there a Data Protection National Authority? If so, what is the National Authority main role?

Yes, the Czech Office for Personal Data Protection (Office). The Office is the central administrative authority in the field of personal data protection within the scope laid down by the Act, other legal regulations, international treaties that form part of the national laws, and the directly applicable regulations of the European Union.

Does the law impose the obligation of designating a data protection officer (DPO)? If so, what is the role of the DPO under the law?

Yes, under section 14 of the Act, in addition to the public authorities, authorities established by law that perform tasks laid down by law in the public interest also have the obligation to designate a data protection officer (DPO) pursuant to Art 37 (1)(a) of the GDPR. The role of the DPO under the Act is the same as under the GDPR.

Cross-border transfers

What rules regulate the transfer of data outside your jurisdiction?

There are no special rules for data transfers in the Act. Generally, the rules for transfers of data outside the EU are the same as under the GDPR, i.e., the rules in article 44 and following of the GDPR apply.

Is it necessary to notify the National Authority prior to the international transfer?

In some cases, if there are no other options or tools for transfers of the data outside the EU. Generally, the rules for transfers of data outside the EU are the same as under the GDPR, i.e., the rules in article 44 and following of the GDPR apply.

Security standards, data breaches, and sanctions

Do the laws impose any information security standards and/or requirements?

Not specifically, only in very general way. The Act includes such general requirements, for example, in Titles III and IV (i.e., personal data processing for the purpose of prevention, investigation or detection of crimes, and personal data processing in ensuring defence and security interests of the Czech Republic). Some other laws impose such standards/requirements in general way for specific purposes, namely the act no. 264/2025 Coll., on Cybersecurity, as amended (Act on Cybersecurity) - as of 1 November 2025, the new Act on Cybersecurity has been in force, replacing the previous regulatory framework and implementing the NIS2 Directive. The new Act on Cybersecurity requires providers of regulated services to implement organizational and technical security measures. Detailed requirements are laid down in implementing decrees applicable to the higher and lower obligation regimes.

Do the laws establish any kind of mandatory notification duty?

Yes, duty to notify data breaches. Generally, the duty to notify data breaches under the Act is based on the same principles as under the articles 33 and 34 of the GDPR (some special requirements are included in section 41, Title III, of the Act).

There are also special provisions on notification duty in special laws such as the Act no. 127/ 2005, on Electronic Communications, as amended, and the Act No. 264/2025 Coll., on Cybersecurity, as amended:

  • notification duty towards the Czech Office for Personal Data Protection and data subjects, as applicable (Art. 88(4) and (5) of the Act No. 127/2005 Coll., as amended (data breaches)),
  • notification duty towards the Czech Telecommunication Office (Art. 98(4) of the Act No. 127/2005 Coll., as amended (serious violations of security and loss of integrity of network)), and
  • notification duty towards the National Cyber and Information Security Agency (NÚKIB) or the national Computer Emergency Response Team (National CERT) and users of regulated services, as applicable (Art. 15 and following of the Act No. 264/2025 Coll., as amended (cybersecurity incidents)).

What are the sanctions for noncompliance with data protection laws?

The sanctions under the Act are generally the same as under the GDPR with some exceptions (see below). In the event of breach of an obligation laid down by the Act or imposed on its basis in personal data processing under Title II or III or under the GDPR, the Office may impose a measure to remedy the determined shortcomings and set a reasonable deadline for remedy.

When imposing fines, the main exemptions from the GDPR are the following:

  • The Office shall waive administrative punishment with respect to controllers and processors set out in Art. 83 (7) of the GDPR (i.e., public authorities) for breaches of Title II of the Act,
  • Breaches of Titles III and IV of the Act may be subject to a fine of up to CZK 10,000,000 (i.e., the amount of the fine is limited).

Other comments

Other comments

The derivations under the Act from the rules stipulated in the GDPR are not substantial. For more details, see above. It is necessary to understand the structure of the Act, the rules in Title II apply to personal data processed by, for example, general business, while the rules in Title III and IV apply to specific processing of personal data (i.e., personal data processing for the purpose of prevention, investigation, or detection of crimes, and personal data processing in ensuring the defence and security interests of the Czech Republic).

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.