#
Full GDPR direct effect plus a settled, in-force national implementing Act and an operational, EDPB-member supervisory authority.
Sub-modules (5)
Regulator And AuthorityGreen
ÚOOÚ, seated at Pplk. Sochora 27, Prague 7, is the Czech GDPR supervisory authority and a voting member of the EDPB.
Claims (1):
- The Office for Personal Data Protection (ÚOOÚ), seated at Pplk. Sochora 27, Prague 7, is the Czech Republic's GDPR supervisory authority and a full voting member of the European Data Protection Board.
Act And InstrumentsGreen
Act No. 110/2019 Coll. is the core national instrument; it replaced the prior Data Protection Act and transposes the Law Enforcement Directive.
Claims (1):
- Act No. 110/2019 Coll. on Personal Data Processing fully replaces the prior Czech Data Protection Act, establishes the constitution and powers of the Czech Data Protection Office, and transposes Directive (EU) 2016/680 governing processing of personal data for crime prevention/investigation and defense/security purposes.
Material ScopeGreen
The Act carries local derogations mainly benefiting public authorities and triggered amendment of over 30 other Czech statutes.
Claims (1):
- The Data Protection Act includes local derogations and exceptions primarily for public authorities, and its Accompanying Act amends more than 30 other Czech laws in connection with GDPR and Directive 2016/680 implementation.
Territorial ScopeGreen
GDPR's extraterritorial rule (targeting/monitoring of EU data subjects) applies directly to non-EU controllers vis-à-vis Czech data subjects.
Claims (1):
- Companies not established in the EU must comply with GDPR rules, including as applied by Czech supervisory authority, when they offer goods/services to or monitor the behaviour of individuals in the EU.
Regulator Registration And FilingAmber
No general controller registration/notification-fee regime (analogous to the UK ICO fee system) was identified for Czech Republic in this research pass; GDPR abolished the EU-wide prior-notification requirement that existed under the pre-2018 regime.
Claims (1):
- No distinct Czech controller-registration or filing-fee regime was confirmed in this research pass; GDPR's harmonised approach removed the general prior-notification obligation that existed under the pre-2018 Czech data protection regime.
Sources and claims (5)
- ConfirmedEDPB — The Office for Personal Data Protection (ÚOOÚ), seated at Pplk. Sochora 27, Prague 7, is the Czech Republic's GDPR supervisory authority and a full voting member of the European Data Protection Board.observed
- ConfirmedIAPP — Act No. 110/2019 Coll. on Personal Data Processing fully replaces the prior Czech Data Protection Act, establishes the constitution and powers of the Czech Data Protection Office, and transposes Directive (EU) 2016/680 governing processing of personal data for crime prevention/investigation and defense/security purposes.observed
- ConfirmedIAPP — The Data Protection Act includes local derogations and exceptions primarily for public authorities, and its Accompanying Act amends more than 30 other Czech laws in connection with GDPR and Directive 2016/680 implementation.observed
- ConfirmedEUR-Lex — Companies not established in the EU must comply with GDPR rules, including as applied by Czech supervisory authority, when they offer goods/services to or monitor the behaviour of individuals in the EU.observed
- UncertainEDPB / ÚOOÚ — No distinct Czech controller-registration or filing-fee regime was confirmed in this research pass; GDPR's harmonised approach removed the general prior-notification obligation that existed under the pre-2018 Czech data protection regime.observed