EnglishCS
Czech Republic flag

Czech Republic

Czech Republic Data Privacy Laws: GDPR, Act 110/2019 & ÚOOÚ Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 21 primary sources cited on this page. How we verify our legal content

Czech Republic Data Privacy Laws: GDPR, Act 110/2019 & ÚOOÚ Guide (2026)

Frequently Asked Questions

What is the Czech Republic's main data protection law?

Czech data protection rests on two instruments. The EU GDPR applies directly as EU law and sets the overarching standards. Act No. 110/2019 Coll. on Processing of Personal Data (ZZOOU), in force since 24 April 2019, supplements the GDPR with national provisions on public bodies, law enforcement data processing, and procedural matters. The constitutional basis is Article 10(3) of the Czech Charter of Fundamental Rights and Freedoms.

Who enforces data protection law in the Czech Republic?

The Office for Personal Data Protection (Urad pro ochranu osobnich udaju, UOOU) is the sole data protection supervisory authority in the Czech Republic. It is an independent authority based in Prague, with 118 systemised posts as at the start and end of 2025. It enforces the GDPR, the ZZOOU, and related legislation including electronic communications and anti-spam rules. Complaints can be filed at uoou.gov.cz.

What was the largest GDPR fine in the Czech Republic?

The UOOU imposed CZK 351 million (approximately EUR 13.9 million) on Avast Software s.r.o. for sending pseudonymized browsing data to its subsidiary Jumpshot with no lawful basis under Article 6(1) and for failing to tell users the purposes and legal basis of that processing under Article 13(1)(c). The UOOU President confirmed the decision on 10 April 2024. On 30 September 2025 the Municipal Court in Prague upheld both findings of infringement but quashed the amount of the fine and the finding that roughly 100 million users were affected, sending the case back to the Office to redetermine the number of users and the penalty. No replacement figure has been issued, so the amount is unsettled.

Can Czech government bodies be fined for GDPR violations?

No. The Czech Republic used Article 83(7) of the GDPR to fully exempt public bodies from GDPR administrative fines. Czech ministries, municipalities, state agencies, and other public bodies cannot be fined by the UOOU under the GDPR. The UOOU can still issue corrective orders against public entities. Under the Law Enforcement Directive portion of the ZZOOU, public body fines are capped at CZK 10 million (approximately EUR 400,000).

What is the age of digital consent in the Czech Republic?

The Czech Republic set the age of digital consent at 15 years old. Children aged 15 and older can independently consent to information society services such as social media platforms. Children under 15 require parental or guardian authorization. This threshold is lower than in several other EU member states.

What are the UOOU's enforcement priorities in 2026?

The UOOU's 2026 control plan, published on 16 February 2026, names four areas: the position of data protection officers in the public sector, personal data processing in debtor registers, processing within the gambling information database under section 15a(1) of Act No. 186/2016 Coll., and processing connected with the Schengen area. The Office is also joining the European Data Protection Board's 2026 coordinated action on transparency and information duties. It has no EU AI Act role until the Czech adaptation law is passed. The 2025 plan, now superseded, covered loyalty schemes, CCTV in public transport and online comparison services.

Does the EU AI Act affect data privacy obligations in the Czech Republic?

Yes, but not yet through a Czech AI regulator. The EU AI Act (Regulation 2024/1689) entered into force on 1 August 2024 and applies in phases. Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved the Annex III high-risk obligations to 2 December 2027 and the Annex I obligations to 2 August 2028, while Article 50 transparency still applies from 2 August 2026. The Czech Republic has not enacted its adaptation law, so no national AI Act authority is designated; under the Ministry of Industry and Trade draft the Public Defender of Rights would take the Article 77 fundamental-rights role and the UOOU would be a sectoral market surveillance authority. Until then the UOOU's hold on an AI system is its GDPR jurisdiction.

What rules apply to international data transfers from the Czech Republic?

The Czech Republic applies the GDPR Chapter V transfer framework without national modifications. Transfers to countries with a European Commission adequacy decision (including the UK, the US under the EU-US Data Privacy Framework, Japan and Brazil) may proceed without additional safeguards; Singapore is not on the Commission's list. Transfers to non-adequate countries require appropriate safeguards, most commonly the EU standard contractual clauses. The Avast case was decided under Article 6(1) and Article 13(1)(c) rather than Chapter V, but it confirms that pseudonymized data tied to a unique identifier is still personal data, so pseudonymization removes neither the need for a lawful basis nor the need for a transfer safeguard.

Updates

Corrected the Avast case throughout: the CZK 351 million fine and the finding that about 100 million users were affected were quashed by the Municipal Court in Prague on 30 September 2025 and sent back to the Office, with the two findings of infringement upheld, and the case was decided under Articles 6(1) and 13(1)(c) rather than the GDPR's transfer chapter. Removed the false statement that the Czech Republic has designated EU AI Act authorities and replaced it with the unenacted Ministry of Industry and Trade draft, added the post-Omnibus AI Act dates, deleted the claim that Singapore has an EU adequacy decision and gave the Commission's current list, described the three 2024 to 2025 amendments to Act No. 110/2019 Coll., added the Act's journalistic and expression derogations and its restrictions on data subject rights, moved cookie supervision from the Czech Telecommunication Office to the UOOU, replaced the abolished inspector structure with the Office's current decision and appeal structure, added section 316 of the Labour Code on employee monitoring, and updated the enforcement priorities and statistics to the 2026 control plan and the 2025 annual report.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Expanded to full audit-and-evolve refresh: added constitutional basis (Charter Art. 10), EU AI Act overlay, consent-or-pay enforcement, Act on Digital Economics, 2024 annual report data, detailed Avast procedural history, and DPO + special category sections.

Reviewed and approved by an editor

Initial publication covering GDPR + Act 110/2019 framework, UOOU powers, Avast fine, and 2025 enforcement priorities.

Sources and References

  1. UOOU Official Website(uoou.gov.cz).gov
  2. UOOU About the Czech DPA(uoou.gov.cz).gov
  3. UOOU Avast Fine Announcement(uoou.gov.cz).gov
  4. Act No. 110/2019 Coll. (ZZOOU) - consolidated Czech text in force from 1 August 2025(zakonyprolidi.cz)
  5. EDPB Avast Fine Announcement(edpb.europa.eu).gov
  6. Czech Charter of Fundamental Rights and Freedoms(usoud.cz).gov
  7. CMS Expert Guide Czech Republic(cms.law)
  8. CMS GDPR Enforcement Tracker Czech Republic(cms.law)
  9. DLA Piper Czech Republic Data Protection(dlapiperdataprotection.com)
  10. Linklaters Data Protected Czech Republic(linklaters.com)
  11. CMS AI Laws Czech Republic(cms.law)
  12. EDPB Opinion 08/2024 Consent or Pay(edpb.europa.eu).gov
  13. EU AI Act Implementation Timeline(ai-act-service-desk.ec.europa.eu).gov
  14. Municipal Court in Prague, judgment 5 A 56/2024-206 of 30 September 2025 (Avast Software s.r.o. v UOOU)(msp.gov.cz).gov
  15. Municipal Court in Prague, press release on the judgment of 30 September 2025(msp.gov.cz).gov
  16. UOOU Annual Report 2025 (published 18 March 2026)(uoou.gov.cz).gov
  17. UOOU Annual Report 2024(uoou.gov.cz).gov
  18. UOOU Control Plan for 2026 (16 February 2026)(uoou.gov.cz).gov
  19. Ministry of Industry and Trade - draft Czech AI Act adaptation law (26 September 2025)(mpo.gov.cz).gov
  20. Ministry of Industry and Trade - AI Act amendment and new guidance, phased application dates (29 July 2026)(mpo.gov.cz).gov
  21. Czech Telecommunication Office - Artificial Intelligence (national adaptation legislation still required)(ctu.gov.cz).gov
  22. European Commission - Adequacy decisions(commission.europa.eu).gov
  23. Regulation (EU) 2026/1744 (Digital Omnibus on AI, 8 July 2026)(eur-lex.europa.eu).gov
  24. Regulation (EU) 2025/2518 (additional procedural rules for GDPR enforcement, applies from 2 April 2027)(eur-lex.europa.eu).gov
  25. Chamber of Deputies, print 69 - government bill on the digital economy (state of proceedings)(public.psp.cz).gov
  26. UOOU - largest spam fine in its history, CZK 6 million (25 September 2020)(uoou.gov.cz).gov
  27. UOOU - cookies require consent from the start of 2022(uoou.gov.cz).gov
  28. Act No. 110/2019 Coll. - version history (amended by 448/2024, 218/2025 and 230/2025 Coll.)(zakonyprolidi.cz)
  29. Act No. 127/2005 Coll. on Electronic Communications, ss. 88(3) and 89(3)(zakonyprolidi.cz)
  30. Act No. 262/2006 Coll., the Labour Code, s. 316 (workplace monitoring)(zakonyprolidi.cz)
Share: