Czech Republic
Czech Republic Data Privacy Laws: GDPR, Act 110/2019 & ÚOOÚ Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 21 primary sources cited on this page. How we verify our legal content

Czech Republic data privacy law combines the directly applicable EU GDPR with Act No. 110/2019 Coll. (ZZOOU), which took effect on 24 April 2019 and adds national rules on public bodies, criminal-justice processing, and enforcement. The Office for Personal Data Protection (UOOU) serves as the independent supervisory authority.
The Czech Republic occupies an instructive position in the European data protection landscape. As an EU member state, it applies the GDPR directly, but the national implementing legislation and the enforcement practice of the UOOU give Czech data protection a character of its own. The landmark Avast Software case, in which the UOOU imposed one of the largest GDPR penalties ever seen in Central Europe before a court sent the amount back for reconsideration in September 2025, signals that the UOOU is prepared to deploy its full enforcement arsenal. Meanwhile, the authority's proactive challenge to consent-or-pay models used by Czech media publishers placed it ahead of many EU peers.
This guide covers the full scope of Czech data protection law: from the constitutional roots through the statutory framework, the UOOU's powers, data subject rights, international transfers, the EU AI Act overlay, and the compliance priorities that matter most in 2025 and 2026.
Quick Answer
The Czech Republic's data privacy regime rests on three pillars. The EU General Data Protection Regulation (GDPR) applies directly as EU law, setting the overarching rules for all personal data processing. Act No. 110/2019 Coll. (ZZOOU) is the national implementing statute, adding Czech-specific rules on public authorities, law enforcement processing, and procedural matters. The Office for Personal Data Protection (UOOU) is the independent regulator that enforces both instruments.
For most businesses operating in the Czech Republic, GDPR compliance is the operative standard. The ZZOOU matters most for public bodies, for organizations processing data in a law enforcement context, and for certain situations where the GDPR expressly permits national variation.
Constitutional Basis: Charter of Fundamental Rights and Freedoms
Czech data protection law has a constitutional foundation that predates both the GDPR and the 2019 implementing statute. The Charter of Fundamental Rights and Freedoms, enacted in 1991 and carrying the same legal force as the Czech Constitution itself, protects personal data at the highest normative level.
Article 10(3) of the Charter provides that everyone has the right to protection from unauthorized gathering, publication, or other misuse of their personal data. This provision sits alongside Article 10(1), which protects human dignity and personal integrity, and Article 10(2), which guards against unauthorized interference in personal and family life.
The Charter's constitutional status means that any statute permitting personal data processing must be consistent with these protections. The Czech Constitutional Court has drawn on Article 10 in cases involving state surveillance, biometric data collection, and the scope of public registers. This constitutional grounding is why Czech data protection law cannot be reduced simply to GDPR compliance: the GDPR operates within a constitutional framework that independently constrains what Czech legislators and public authorities can authorize.
The GDPR and Act No. 110/2019 Coll.: The Statutory Framework
How the Two Instruments Interact
The GDPR is a directly applicable EU regulation. It does not need to be transposed into Czech law; it creates rights and obligations that apply automatically to all natural and legal persons in the Czech Republic. Any provision of the ZZOOU that conflicts with the GDPR is displaced by the regulation.
The ZZOOU (Act No. 110/2019 Coll. on Processing of Personal Data) performs three distinct functions. First, it exercises the opening clauses of the GDPR, which permit or require member states to specify national rules in particular areas. Second, it transposes Directive 2016/680 (the Law Enforcement Directive) for data processing in criminal-justice contexts. Third, it governs processing that falls outside the scope of EU law, including certain national security and intelligence-related activities.
The Act replaced the earlier Act No. 101/2000 Coll. on the Protection of Personal Data, which had implemented the 1995 EU Data Protection Directive. The gap between the GDPR's application date (25 May 2018) and the ZZOOU's entry into force (24 April 2019) meant that for nearly a year the GDPR applied directly in the Czech Republic without a completed domestic adaptation statute.
The Act in force today is not the 2019 text. It has been amended three times. Act No. 448/2024 Coll. applied from 1 January 2025. Act No. 218/2025 Coll. applied from 1 July 2025 and moved collection of fines imposed by the Office to the Customs Administration. Act No. 230/2025 Coll. applied from 1 August 2025 and inserted sections 39a to 39c on isolated systems, meaning AI systems used for real-time remote biometric identification of people, for law enforcement processing under Head III, with matching offences in section 63(2).
Work from the consolidated version in force since 1 August 2025. The Office's English translation of the Act is headed as the consolidated version of 24 April 2019 and does not carry any of these amendments.
Key National Choices Under the ZZOOU
Several aspects of the ZZOOU reflect deliberate Czech policy choices that differ from the approaches taken by other member states.
The most significant is the complete exemption of public bodies from GDPR administrative fines. The Czech legislator exercised the discretion provided by Article 83(7) of the GDPR to exclude government entities from the UOOU's fining power for GDPR violations. Czech ministries, municipalities, regional governments, state agencies, and other public bodies cannot be fined by the UOOU under the GDPR, regardless of the seriousness of a violation. The authority retains power to issue corrective orders, but the absence of financial penalties has attracted criticism from data protection practitioners who argue that it reduces the incentive for public sector compliance.
For processing under the Law Enforcement Directive portion of the Act, public bodies can be fined, but the ceiling is capped at CZK 10 million (approximately EUR 400,000), substantially below the GDPR's standard framework.
The digital consent age is set at 15. Children aged 15 and older may independently consent to information society services. Children under 15 require parental or guardian authorization.
The ZZOOU also provides that controllers may limit or delay personal data breach notifications to the UOOU if notification would compromise the defense or security interests of the Czech Republic, a derogation available to national security and intelligence bodies.
The UOOU: Czech Data Protection Authority

The Office for Personal Data Protection (Urad pro ochranu osobnich udaju, UOOU) is the Czech Republic's independent supervisory authority for data protection. It was established under the predecessor 2000 Act and reconstituted under the ZZOOU as the single authority responsible for enforcing the GDPR, the Law Enforcement Directive, and other data protection statutes in the Czech Republic.
Structure and Resources
The UOOU had 118 systemised service and employment posts at both 1 January and 31 December 2025, all based in Prague. Chapter 343 of the state budget approved CZK 209.1 million in expenditure for the Office for 2025, of which CZK 172.9 million was drawn.
Under section 52 of the Act the authority is led by a President appointed and removed by the President of the Republic on the proposal of the Senate, for a five-year term and no more than two consecutive terms. The Office also has two vice-presidents, elected by the Senate on the President's proposal.
First-instance decisions are issued by the Office itself, and the President of the Office decides objections (rozklad) against them. The office of UOOU inspector was abolished by the 2019 Act; section 66(3) keeps it alive only as a transitional arrangement for an inspector already serving in 2019.
Title V of the ZZOOU establishes the UOOU as a central administrative authority independent of government direction on individual cases. This independence is reinforced by section 52(7), under which the President can be removed only if he ceases to satisfy one of the conditions for appointment listed in section 52(3) to (6), such as integrity, the required qualifications, or the bar on incompatible offices.
Supervisory Powers
The UOOU holds the full range of investigative and corrective powers provided by the GDPR. It can conduct inspections on its own initiative or in response to complaints. It can access business premises, obtain documents, and interview staff. It can issue warnings and reprimands, order controllers and processors to bring processing into compliance, impose temporary or permanent processing bans, order the suspension of data flows to third countries, and impose administrative fines.
Beyond GDPR enforcement, the UOOU also supervises compliance with the Electronic Communications Act (No. 127/2005 Coll.) regarding cookie consent and the processing of traffic data, and with Act No. 480/2004 Coll. regarding unsolicited commercial communications. In the AI context, no Czech authority has yet been designated under the EU AI Act. The Office would take on market surveillance and fundamental-rights functions for defined high-risk AI systems only once the national adaptation law is passed.
Advisory and Guidance Functions
The UOOU publishes guidance on topics ranging from CCTV methodology to DPO appointment requirements. It provides opinions on draft legislation that may affect personal data processing, and it participates in the European Data Protection Board alongside the supervisory authorities of other member states. The authority maintains a public registry of appointed DPOs and provides official forms for data breach notifications.
Legal Bases for Processing
Processing of personal data in the Czech Republic normally rests on one of the six lawful bases in Article 6 of the GDPR. The ZZOOU adds one national ground of its own, in section 17(1): personal data may also be processed where that serves, in a proportionate way, journalistic purposes or the purposes of academic, artistic or literary expression.
Consent must be freely given, specific, informed, and unambiguous. It must involve an affirmative act rather than silence, pre-ticked boxes, or inactivity. Controllers must be able to demonstrate that consent was obtained and must make withdrawal as easy as giving consent. The UOOU's challenge to consent-or-pay models underlines the authority's strict approach to the freedom requirement: consent given under financial pressure to avoid a paywall may not satisfy the freely-given test.
Contractual necessity allows processing needed to perform a contract to which the data subject is a party, or to take pre-contractual steps at the data subject's request.
Legal obligation covers processing required to comply with Czech or EU law.
Vital interests allow processing to protect life where the data subject cannot consent.
Public task or official authority covers processing by public bodies and organizations exercising delegated public functions.
Legitimate interests allows private organizations to process data for a genuine purpose that is not overridden by the data subject's rights. This is the most complex basis and requires a documented three-part balancing test.
For special category data (health, genetic, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation, or criminal convictions), one of the additional grounds in Article 9 of the GDPR must also be satisfied. The section 17(1) expression ground is the Czech addition, and it reaches this data: the Act directs that in judging proportionality account is also taken of whether the processing involves data under Article 9(1) or Article 10 of the GDPR.
Data Subject Rights
Czech residents enjoy the data subject rights in Articles 12 to 22 of the GDPR, subject to the national restrictions set out below. Controllers must respond to requests without undue delay and within one calendar month. In cases of complexity or volume, the response period may be extended by a further two months, provided the controller informs the data subject of the extension and the reasons within the initial one-month window.
The right of access entitles individuals to confirmation of whether their data is processed and, if so, a copy of the data along with information about purposes, categories, recipients, retention periods, and the existence of other rights.
The right to rectification requires correction of inaccurate personal data and completion of incomplete data, having regard to the purposes of processing.
The right to erasure (the right to be forgotten) applies in defined circumstances, including where data is no longer necessary for the original purpose, where consent is withdrawn and no other basis applies, or where data has been unlawfully processed.
The right to restriction allows data subjects to suspend processing while contesting accuracy, or while awaiting the outcome of an objection.
Data portability entitles individuals to receive data in a structured, commonly used, machine-readable format, and to transmit it to another controller, where processing is based on consent or contract and carried out by automated means.
The right to object applies to processing based on legitimate interests or public task, including profiling on those bases. Controllers must cease processing unless they demonstrate compelling legitimate grounds that override the data subject's interests. The right to object to direct marketing is absolute and must always be honored.
Protection from automated decision-making entitles individuals to human review of decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects.
National Restrictions on These Rights
The ZZOOU cuts these rights back in defined situations. Section 11(1) allows Articles 12 to 22, and Article 5 to the corresponding extent, to be applied only proportionately or to be deferred where that is necessary and proportionate to protect an interest listed in section 6(2). A controller that does this must notify the Office without undue delay. Section 16(3) restricts Articles 15, 16, 18 and 21 for scientific and historical research and for statistics.
The largest carve-out serves journalism and academic, artistic or literary expression under section 17(1). Sections 18 to 23 then disapply or dilute the information duties in Articles 12(1) and (2), 13(1) to (3) and 14, the right of access in Article 15, and the rules on rectification, erasure, restriction, notification of recipients and objection. Section 19(2) is the sharpest of them: the right of access does not apply at all to personal data the controller has not published and processes only for a section 17(1) purpose. Section 17(2) adds that such processing enjoys a right to protection of the source and content of information and needs no permission from the Office.
The UOOU handles complaints from individuals who believe their rights have not been respected. Submissions rose sharply in 2025: the Office received 3,854 complaints and other submissions, more than 68 percent above 2024 and the highest figure since the GDPR began to apply, of which 2,514 were complaints.
Data Protection Officers
The DPO appointment requirements in the Czech Republic follow Articles 37 to 39 of the GDPR without material modification by the ZZOOU.
A DPO must be appointed by any public authority or public body (with the exception of courts acting in their judicial capacity). In the private sector, a DPO is mandatory for organizations whose core activities require large-scale, regular, and systematic monitoring of individuals, or whose core activities consist of large-scale processing of special category data or data relating to criminal convictions.
The DPO may be an employee or an external contractor. The person appointed must have expert knowledge of data protection law and practice sufficient for the role. The UOOU has published guidance emphasizing that DPOs require genuine operational independence: they must not receive instructions on how to exercise their tasks, must not be penalized for doing their job, and must have direct access to senior management.
The UOOU maintains a public register of DPOs. Controllers required to appoint a DPO must communicate the DPO's contact details to the UOOU and publish them.
Employee Monitoring and the Labour Code
Czech employers face a national rule that is stricter than the GDPR and easy to miss. Section 316 of Act No. 262/2006 Coll., the Labour Code, governs monitoring at work and applies on top of the GDPR analysis.
Section 316(2) prohibits an employer, without a serious reason arising from the special nature of its activity, from invading an employee's privacy at the workplace and in the employer's common areas by subjecting the employee to open or covert surveillance, to interception and recording of telephone calls, to checks on email, or to checks on letters addressed to the employee.
Section 316(3) requires an employer that does have such a serious reason to inform employees directly of the scope of the monitoring and the way it is carried out. Section 316(1) separately allows the employer to check, in a proportionate way, that employees are not using its equipment, including computers and telecommunications equipment, for private purposes without consent.
Section 316(4) bars the employer from seeking information that does not directly relate to the work, naming pregnancy, family and financial circumstances, sexual orientation, origin, trade union membership, membership of political parties or movements, religious affiliation and criminal record. The employer may not obtain that information through third parties either.
The practical point is that an employer can satisfy the GDPR balancing test and still be unlawful under section 316(2), because that provision asks a different question: whether there is a serious reason rooted in the nature of the business at all.
Biometric attendance systems are where the Office is currently active. Its 2025 annual report describes completed inspections in which one employer processed fingerprint hashes with no Article 6(1) basis, and another breached the minimisation principle in Article 5(1)(c) by keeping fingerprint templates when access cards and a reception log were already in use. The Office advises controllers to test necessity and proportionality, and to prefer less invasive means, before installing such a system.
Personal Data Breach Notification

Controllers must notify the UOOU without undue delay, and where feasible within 72 hours of becoming aware of a personal data breach, if the breach is likely to result in a risk to the rights and freedoms of natural persons. Where notification is not made within 72 hours, the controller must provide a reasoned explanation for the delay.
If the breach is likely to result in a high risk to the rights and freedoms of individuals, the controller must also notify the affected data subjects directly without undue delay. The notification must describe the nature of the breach, provide contact details of the DPO or other relevant contact, describe the likely consequences, and set out the measures taken or proposed.
The UOOU provides official notification forms and guidance on its website. In its 2025 annual report, published on 18 March 2026, the authority recorded 392 breach notifications, the highest figure since the GDPR began to apply, plus 193 supplementary filings. Negligence was the leading cause with 190 cases, ahead of cyberattacks with 120, technical error with 45, intentional conduct with 31 and break-ins with 6.
Reporting has not risen every year. The Office logged 294 notifications in 2021, 313 in 2022 and 383 in 2023, then 336 in 2024, before the 2025 record.
The ZZOOU contains a derogation for national security contexts: controllers processing data for defense or national security purposes may limit or delay notifications to the extent necessary and proportionate to protect those interests.
Article 33 reporting to the UOOU is not the only incident duty. Act No. 264/2025 Coll., the Czech cybersecurity act implementing NIS2, took effect on 1 November 2025 and is supervised by NUKIB. Many organizations that must notify the UOOU of a personal data breach will owe a separate incident report under that Act, on its own timetable and to a different regulator.
International Data Transfers
The Czech Republic applies the GDPR's Chapter V framework for transferring personal data to countries outside the European Economic Area without any material national modifications.
Standard Transfer Mechanisms
Transfers to countries covered by a European Commission adequacy decision require no additional safeguards. The Commission's current list is Andorra, Argentina, Brazil, Canada (commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States (commercial organisations participating in the EU-US Data Privacy Framework), Uruguay and the European Patent Organisation.
Singapore is not on that list. A transfer of personal data to Singapore needs a Chapter V safeguard such as the standard contractual clauses.
Where no adequacy decision exists, controllers must implement appropriate safeguards. The most commonly used instrument is the European Commission's standard contractual clauses (SCCs), updated in 2021. Controllers using SCCs must also conduct transfer impact assessments to evaluate whether the law and practice of the recipient country undermines the SCCs' protections.
Binding corporate rules are available for intra-group transfers within multinational enterprises. Other mechanisms include approved codes of conduct and certification schemes.
Derogations under Article 49 of the GDPR are available for specific situations including explicit consent, contract performance necessity, public interest, legal claims, and vital interests, but these are narrow exceptions and cannot serve as routine transfer mechanisms.
The Avast Lesson on Pseudonymized Data
The UOOU's enforcement action against Avast Software is often read as a transfer case. It was not decided under Chapter V. Avast treated browsing data as anonymized on the basis that it had been pseudonymized before it went to its subsidiary Jumpshot. The authority found that pseudonymized data tied to a unique identifier remained personal data because re-identification of at least some users was technically feasible.
The two offences found were sending that data to Jumpshot with no lawful basis under Article 6(1) of the GDPR, and failing to tell users at the point of collection what the purposes and the legal basis of the processing were, contrary to Article 13(1)(c). The Municipal Court in Prague upheld both findings on 30 September 2025. Nothing in the case turned on Articles 44 to 49.
The lesson still bites for transfers. Pseudonymization does not take data outside the GDPR, so it is no substitute for a lawful basis and no substitute for a Chapter V transfer safeguard.
EU AI Act Interaction
The EU AI Act (Regulation 2024/1689) entered into force on 1 August 2024 and applies in phases across the EU, including the Czech Republic. Regulation (EU) 2026/1744, the Digital Omnibus on AI of 8 July 2026, amended it with effect from 27 July 2026 and moved several of those dates.
The Article 50 transparency duties still apply from 2 August 2026, with a grace period to 2 December 2026 for marking of synthetic content by systems already on the market. The obligations for Annex III high-risk systems now apply from 2 December 2027, and those for Annex I high-risk systems from 2 August 2028. The Ministry of Industry and Trade set out the same three dates in its release of 29 July 2026.
The interaction between the AI Act and the GDPR is significant because many high-risk AI systems process personal data, meaning both regimes apply simultaneously.
Which Czech Authority Supervises AI
None yet. The Office's 2024 annual report records that by the end of 2024 the Czech Republic had not decided which public body would act as market surveillance authority under Article 3(26) and Article 70(1) of the AI Act. Its 2025 annual report, published on 18 March 2026, goes further and notes that the government had not even tabled the adaptation bill.
Under the Ministry of Industry and Trade's draft, published on 26 September 2025, supervision would be split. The Czech Telecommunications Office would become the single point of contact, with the Czech National Bank and the UOOU supervising within their own sectors. The Office for Technical Standardisation would be the notifying authority and would accredit conformity assessment bodies. The Public Defender of Rights would carry the fundamental-rights role under Article 77.
The UOOU itself expects to act, once that law passes, as an Article 77 body for defined high-risk AI systems, as a market surveillance authority under Article 74(8), and as a conformity assessment body under Article 43(1), while keeping its GDPR role. Until then its jurisdiction over an AI system rests on the GDPR, not on the AI Act.
Czech National AI Legislation
The Czech Republic is preparing a national Act on Artificial Intelligence to supply the institutional, procedural and penalty machinery the EU AI Act leaves to member states. The Ministry of Industry and Trade published its draft on 26 September 2025 and put it through interministerial comment. The Czech government has allocated CZK 232 million from the state budget for AI Act implementation in 2026 to 2028 and created new posts at the relevant authorities. As of 10 September 2026 the adaptation law has not been enacted.
The draft would also create a national regulatory sandbox and allow a warning instead of immediate penalty proceedings for a less serious breach. Organizations deploying high-risk AI systems in the Czech Republic should follow its progress, because it will settle inspection powers, sanction levels, and the precise scope of each authority's jurisdiction. Note that the Czech Telecommunications Office's own AI page says the same thing the Office's reports do: the AI Act requires national adaptation legislation for the institutional and sanction machinery, and that legislation is not in place.
Practical Intersection for Businesses
Organizations using AI systems to process personal data of Czech residents face compliance obligations under both regimes. An AI system that makes automated decisions affecting individuals engages both the GDPR's Article 22 protections and, if it qualifies as high-risk under the AI Act's Annex III, the Act's requirements for transparency, human oversight, and technical documentation, which apply from 2 December 2027. Privacy impact assessments and AI conformity assessments will increasingly need to be conducted in parallel.
Penalties and UOOU Enforcement
The Standard Fine Framework
The GDPR's two-tier administrative fine structure applies in the Czech Republic for private sector controllers and processors. The lower tier, covering violations such as failures in security measures, breach notification, DPO appointment, and data protection by design, carries a maximum of EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. The upper tier, covering violations of core principles such as the legal basis for processing, the rights of data subjects, and restrictions on international transfers, carries a maximum of EUR 20 million or 4% of total worldwide annual turnover, whichever is higher.
The Avast decision is by a wide margin the largest penalty the Office has ever decided, and the Office still describes it that way in its 2025 annual report. The amount is not currently in force: on 30 September 2025 the Municipal Court in Prague quashed the part of the appellate decision that confirmed the fine and returned the case to the Office.
The Avast Software Case and the 2025 Court Judgment

The UOOU's most consequential enforcement action is the case against Avast Software s.r.o., in which the Office imposed a fine of CZK 351 million (approximately EUR 13.9 million). The UOOU President confirmed that decision on 10 April 2024. The Municipal Court in Prague then set part of it aside on 30 September 2025, so the penalty is back before the Office.
Background. Avast operated a suite of antivirus software and browser extensions used by hundreds of millions of people worldwide. Through these tools, the company collected internet browsing history tied to a unique identifier assigned to each device. This data was transferred to Jumpshot, Inc., a subsidiary that sold analytical products to marketing clients describing consumer behavior and preferences.
Violations found. The UOOU found two offences under section 62(1) of the ZZOOU: a breach of Article 6(1) of the GDPR (no lawful basis for the processing) and a breach of Article 13(1)(c) (failure to give data subjects the purposes and the legal basis at the point of collection). Avast had described the data transfers as involving anonymized data used for trend analytics. The authority found that the browsing history, although pseudonymized, constituted personal data because re-identification of at least some affected individuals was possible through the unique identifier. No lawful basis existed for sending the data to Jumpshot. Users were not adequately informed of the purposes of the processing or of its legal basis. The penalty was set under Article 83(5) of the GDPR.
Procedural history. The Czech SA served as the lead supervisory authority under the GDPR's one-stop-shop cooperation mechanism, given Avast's EU establishment in the Czech Republic. The first-instance decision was issued on 14 March 2022. Avast filed an administrative appeal, and the UOOU President issued the appellate decision confirming the fine on 10 April 2024. The European Data Protection Board was involved as part of the cooperation procedure.
The 2025 judgment. Avast then brought an administrative action. On 30 September 2025 the Municipal Court in Prague, in judgment 5 A 56/2024-206, agreed that Avast had committed both offences but quashed the appellate decision in two respects: the wording inserted into the first-instance finding describing the conduct as covering pseudonymized browsing data relating to roughly 100,000,000 users, and the confirmation of the amount of the fine.
The court held that neither the decision nor the file explained how many users were actually affected, and that this figure is essential to assessing the seriousness of the offence and the size of the penalty. It returned the case to the Office to deal only with the number of affected users and the level of the sanction, and directed it to address Avast's own analysis putting the figure at 54.6 million. A cassation complaint to the Supreme Administrative Court is available. As of 10 September 2026 the Office had published no replacement decision, so the fine amount remains unsettled.
Significance. CZK 351 million is the largest fine the Office has ever decided, but it is subject to the 2025 remittal and should not be reported as a standing penalty. The findings of infringement survived judicial review, so the case remains authority that pseudonymization alone does not render data non-personal where re-identification stays technically feasible. It also shows how long a contested Czech enforcement action can run: the conduct dates from 2019 and the penalty was still unsettled in 2026.
Consent-or-Pay Model Challenge
In a notable enforcement initiative in 2024, the UOOU became one of the first EU data protection authorities to challenge the consent-or-pay model used by online publishers. Several major Czech media groups, including Czech News Centre, Mafra, Economia, and Seznam, introduced cookie walls requiring users to either consent to behavioral tracking or pay for an ad-free version of their services. The UOOU launched an investigation into whether consent given under these conditions is genuinely freely given within the meaning of the GDPR.
This action aligned with broader European scrutiny of consent-or-pay practices. The European Data Protection Board issued Opinion 08/2024 on valid consent in the context of consent-or-pay models deployed by large online platforms, and the European Commission found in July 2024 that Meta's equivalent model failed to comply with the EU Digital Markets Act.
Other Notable Enforcement Actions
Spam campaign. In a decision the Office announced in September 2020 as its largest ever for spam, the UOOU imposed a fine of CZK 6 million for a mass marketing campaign that sent unsolicited commercial emails to nearly 500,000 recipients without adequate consent. This case demonstrated the authority's reach in electronic marketing enforcement.
CCTV cases. The UOOU has pursued multiple enforcement actions involving video surveillance, including improper camera use in residential buildings, workplaces, and public-facing commercial premises. The authority has developed detailed CCTV methodology that goes beyond the bare GDPR framework.
Public Body Exemption
Czech public bodies are fully exempt from GDPR administrative fines. Government entities that violate GDPR obligations face corrective orders from the UOOU but not financial penalties. This choice, made under Article 83(7) of the GDPR, has attracted criticism from civil society organizations and data protection practitioners who argue that the absence of financial consequences weakens public sector compliance incentives.
2026 Enforcement Priorities and Recent Developments
The UOOU published its 2026 control plan on 16 February 2026. It names four areas for audit: the position of data protection officers in the public sector, personal data processing in debtor registers, processing within the information database under section 15a(1) of Act No. 186/2016 Coll. on gambling, and processing connected with the Schengen area. The Office is also taking part in the European Data Protection Board's 2026 coordinated enforcement action on the transparency principle and information duties.
The 2025 control plan, now superseded, had named three different areas.
Loyalty program data processing. The authority examined whether retailers who condition price discounts on customer participation in loyalty schemes comply with GDPR requirements. This area involves questions about whether consent is genuinely voluntary when the alternative is paying higher prices, whether the volume of data collected is proportionate to the stated purpose, and whether retention periods are justified.
CCTV in public transport. The UOOU scrutinized video surveillance systems operated by public transport providers, applying its updated CCTV methodology to evaluate compliance with purpose limitation, retention limits, signage requirements, and data subject rights.
Online comparison service marketing. The authority investigated practices of providers offering insurance, loan, and similar comparison services who send commercial communications to individuals who have previously used their platforms. That sector had not previously been subject to comprehensive UOOU audit.
AI oversight is expected to grow once the adaptation law passes, but the Office has no EU AI Act role until then, so its AI-adjacent work runs through the GDPR. Its 2025 annual report describes completed inspections of biometric attendance systems in the private sector and of the automated facial recognition used with the camera system at Vaclav Havel Airport Prague, which the Office found incompatible with Article 10 of the Law Enforcement Directive because no provision of the Police Act expressly authorised processing biometric data for unique identification. The police deactivated that system on 1 August 2025 and deleted the biometric data; the High Court in Prague later permitted its operation by a resolution dated 30 December 2025.
Act on Digital Economics. The earlier bill lapsed when the 2021 to 2025 parliamentary term ended without it being debated. The government re-tabled it on 12 December 2025 as Chamber of Deputies print 69. It cleared its first reading on 10 March 2026, passed its second reading on 1 July 2026, and the guarantor Economic Committee delivered its position on 4 September 2026, leaving the bill awaiting a third reading. The direction of travel is toward tighter rules on commercial communications, but the bill has been amended in committee, so check the enrolled text before relying on any specific requirement such as periodic renewal of marketing consent.
2025 Annual Report highlights. The UOOU published its 2025 annual report on 18 March 2026. It records 392 reported data breaches, negligence rather than cyberattack as the leading cause, and 3,854 complaints and other submissions, more than 68 percent above 2024. It records that the government had not yet tabled the AI Act adaptation bill. It also flags Regulation (EU) 2025/2518 of 26 November 2025, which adds procedural rules for enforcing the GDPR in cross-border cases; that regulation entered into force on 12 December 2025 and applies from 2 April 2027.
Electronic Marketing and Cookies
The Czech Republic implements the ePrivacy Directive through Act No. 480/2004 Coll. on Certain Information Society Services and Act No. 127/2005 Coll. on Electronic Communications.
Prior opt-in consent is required for marketing emails, SMS messages, and other electronic commercial communications. A limited exception applies for existing customers in relation to their own similar products or services, provided the customer was given a clear opportunity to opt out at the time of collection and in each subsequent message.
Since 1 January 2022, opt-in consent is also required for non-essential cookies and similar tracking technologies. Section 89(3) of Act No. 127/2005 Coll., in the wording given to it by Act No. 374/2021 Coll., requires prior demonstrable consent to the scope and purpose of any storage of data on, or access to data in, a user's terminal equipment. The exception is technical storage or access needed purely to transmit a message, or needed to provide a service the user has expressly requested.
The UOOU is the authority that supervises and enforces this rule. The Czech Telecommunications Office is not. Section 88(3) of the same Act expressly carves checks on compliance with personal data protection duties out of that office's inspection power, and the Act creates no offence for breach of section 89(3).
Business Compliance Guidance
Organizations operating in the Czech Republic should treat GDPR compliance as the baseline requirement, supplemented by awareness of the specific Czech national choices.
For controllers relying on pseudonymization, the Avast case is a direct warning. Pseudonymized data remains personal data if re-identification is technically feasible. Relying on pseudonymization as the basis for a transfer to a third party, or as a substitute for a lawful transfer mechanism, creates serious liability risk.
For retailers and loyalty programs, the UOOU's loyalty-scheme inspections should prompt a review of how consent is obtained for loyalty scheme participation, what data is collected relative to the discount offered, how long that data is retained, and whether participation requirements are proportionate.
For employers, section 316 of the Labour Code is a separate hurdle from the GDPR. Ask first whether there is a serious reason arising from the special nature of the business before introducing any monitoring caught by section 316(2), then inform employees directly of its scope and method.
For public transport operators and CCTV users more broadly, the authority's updated CCTV methodology should be applied to all existing surveillance deployments. Key questions include whether a legitimate interest assessment has been conducted and documented, whether signage is compliant, and whether retention periods reflect genuine operational needs.
For organizations deploying AI systems, the intersection of the GDPR and the EU AI Act means that privacy impact assessments should be integrated with any conformity or risk assessment required under the AI Act framework. Until the Czech adaptation law is passed, though, the Office acts on AI through its GDPR powers rather than through the AI Act, so the immediate exposure is a GDPR one.
For public bodies, the fine exemption does not eliminate compliance risk. The UOOU retains authority to issue corrective orders, and reputational consequences of public enforcement action are significant regardless of whether a fine is attached.
The age of digital consent (15 years) is lower than in several other EU member states, which have set the age at 16. Organizations offering information society services to Czech users must implement age verification or parental consent mechanisms consistent with the 15-year threshold.
Disclaimer: This article provides general information about the Czech Republic's data privacy laws and is not legal advice. Data protection law changes frequently. Consult a qualified attorney licensed in the Czech Republic for guidance on your specific situation. See also our related pages on Czech Republic recording laws and EU data privacy laws.
Frequently Asked Questions
What is the Czech Republic's main data protection law?
Czech data protection rests on two instruments. The EU GDPR applies directly as EU law and sets the overarching standards. Act No. 110/2019 Coll. on Processing of Personal Data (ZZOOU), in force since 24 April 2019, supplements the GDPR with national provisions on public bodies, law enforcement data processing, and procedural matters. The constitutional basis is Article 10(3) of the Czech Charter of Fundamental Rights and Freedoms.
Who enforces data protection law in the Czech Republic?
The Office for Personal Data Protection (Urad pro ochranu osobnich udaju, UOOU) is the sole data protection supervisory authority in the Czech Republic. It is an independent authority based in Prague, with 118 systemised posts as at the start and end of 2025. It enforces the GDPR, the ZZOOU, and related legislation including electronic communications and anti-spam rules. Complaints can be filed at uoou.gov.cz.
What was the largest GDPR fine in the Czech Republic?
The UOOU imposed CZK 351 million (approximately EUR 13.9 million) on Avast Software s.r.o. for sending pseudonymized browsing data to its subsidiary Jumpshot with no lawful basis under Article 6(1) and for failing to tell users the purposes and legal basis of that processing under Article 13(1)(c). The UOOU President confirmed the decision on 10 April 2024. On 30 September 2025 the Municipal Court in Prague upheld both findings of infringement but quashed the amount of the fine and the finding that roughly 100 million users were affected, sending the case back to the Office to redetermine the number of users and the penalty. No replacement figure has been issued, so the amount is unsettled.
Can Czech government bodies be fined for GDPR violations?
No. The Czech Republic used Article 83(7) of the GDPR to fully exempt public bodies from GDPR administrative fines. Czech ministries, municipalities, state agencies, and other public bodies cannot be fined by the UOOU under the GDPR. The UOOU can still issue corrective orders against public entities. Under the Law Enforcement Directive portion of the ZZOOU, public body fines are capped at CZK 10 million (approximately EUR 400,000).
What is the age of digital consent in the Czech Republic?
The Czech Republic set the age of digital consent at 15 years old. Children aged 15 and older can independently consent to information society services such as social media platforms. Children under 15 require parental or guardian authorization. This threshold is lower than in several other EU member states.
What are the UOOU's enforcement priorities in 2026?
The UOOU's 2026 control plan, published on 16 February 2026, names four areas: the position of data protection officers in the public sector, personal data processing in debtor registers, processing within the gambling information database under section 15a(1) of Act No. 186/2016 Coll., and processing connected with the Schengen area. The Office is also joining the European Data Protection Board's 2026 coordinated action on transparency and information duties. It has no EU AI Act role until the Czech adaptation law is passed. The 2025 plan, now superseded, covered loyalty schemes, CCTV in public transport and online comparison services.
Does the EU AI Act affect data privacy obligations in the Czech Republic?
Yes, but not yet through a Czech AI regulator. The EU AI Act (Regulation 2024/1689) entered into force on 1 August 2024 and applies in phases. Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved the Annex III high-risk obligations to 2 December 2027 and the Annex I obligations to 2 August 2028, while Article 50 transparency still applies from 2 August 2026. The Czech Republic has not enacted its adaptation law, so no national AI Act authority is designated; under the Ministry of Industry and Trade draft the Public Defender of Rights would take the Article 77 fundamental-rights role and the UOOU would be a sectoral market surveillance authority. Until then the UOOU's hold on an AI system is its GDPR jurisdiction.
What rules apply to international data transfers from the Czech Republic?
The Czech Republic applies the GDPR Chapter V transfer framework without national modifications. Transfers to countries with a European Commission adequacy decision (including the UK, the US under the EU-US Data Privacy Framework, Japan and Brazil) may proceed without additional safeguards; Singapore is not on the Commission's list. Transfers to non-adequate countries require appropriate safeguards, most commonly the EU standard contractual clauses. The Avast case was decided under Article 6(1) and Article 13(1)(c) rather than Chapter V, but it confirms that pseudonymized data tied to a unique identifier is still personal data, so pseudonymization removes neither the need for a lawful basis nor the need for a transfer safeguard.
Updates
Corrected the Avast case throughout: the CZK 351 million fine and the finding that about 100 million users were affected were quashed by the Municipal Court in Prague on 30 September 2025 and sent back to the Office, with the two findings of infringement upheld, and the case was decided under Articles 6(1) and 13(1)(c) rather than the GDPR's transfer chapter. Removed the false statement that the Czech Republic has designated EU AI Act authorities and replaced it with the unenacted Ministry of Industry and Trade draft, added the post-Omnibus AI Act dates, deleted the claim that Singapore has an EU adequacy decision and gave the Commission's current list, described the three 2024 to 2025 amendments to Act No. 110/2019 Coll., added the Act's journalistic and expression derogations and its restrictions on data subject rights, moved cookie supervision from the Czech Telecommunication Office to the UOOU, replaced the abolished inspector structure with the Office's current decision and appeal structure, added section 316 of the Labour Code on employee monitoring, and updated the enforcement priorities and statistics to the 2026 control plan and the 2025 annual report.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Expanded to full audit-and-evolve refresh: added constitutional basis (Charter Art. 10), EU AI Act overlay, consent-or-pay enforcement, Act on Digital Economics, 2024 annual report data, detailed Avast procedural history, and DPO + special category sections.
Reviewed and approved by an editor
Initial publication covering GDPR + Act 110/2019 framework, UOOU powers, Avast fine, and 2025 enforcement priorities.
Sources and References
- UOOU Official Website(uoou.gov.cz).gov
- UOOU About the Czech DPA(uoou.gov.cz).gov
- UOOU Avast Fine Announcement(uoou.gov.cz).gov
- Act No. 110/2019 Coll. (ZZOOU) - consolidated Czech text in force from 1 August 2025(zakonyprolidi.cz)
- EDPB Avast Fine Announcement(edpb.europa.eu).gov
- Czech Charter of Fundamental Rights and Freedoms(usoud.cz).gov
- CMS Expert Guide Czech Republic(cms.law)
- CMS GDPR Enforcement Tracker Czech Republic(cms.law)
- DLA Piper Czech Republic Data Protection(dlapiperdataprotection.com)
- Linklaters Data Protected Czech Republic(linklaters.com)
- CMS AI Laws Czech Republic(cms.law)
- EDPB Opinion 08/2024 Consent or Pay(edpb.europa.eu).gov
- EU AI Act Implementation Timeline(ai-act-service-desk.ec.europa.eu).gov
- Municipal Court in Prague, judgment 5 A 56/2024-206 of 30 September 2025 (Avast Software s.r.o. v UOOU)(msp.gov.cz).gov
- Municipal Court in Prague, press release on the judgment of 30 September 2025(msp.gov.cz).gov
- UOOU Annual Report 2025 (published 18 March 2026)(uoou.gov.cz).gov
- UOOU Annual Report 2024(uoou.gov.cz).gov
- UOOU Control Plan for 2026 (16 February 2026)(uoou.gov.cz).gov
- Ministry of Industry and Trade - draft Czech AI Act adaptation law (26 September 2025)(mpo.gov.cz).gov
- Ministry of Industry and Trade - AI Act amendment and new guidance, phased application dates (29 July 2026)(mpo.gov.cz).gov
- Czech Telecommunication Office - Artificial Intelligence (national adaptation legislation still required)(ctu.gov.cz).gov
- European Commission - Adequacy decisions(commission.europa.eu).gov
- Regulation (EU) 2026/1744 (Digital Omnibus on AI, 8 July 2026)(eur-lex.europa.eu).gov
- Regulation (EU) 2025/2518 (additional procedural rules for GDPR enforcement, applies from 2 April 2027)(eur-lex.europa.eu).gov
- Chamber of Deputies, print 69 - government bill on the digital economy (state of proceedings)(public.psp.cz).gov
- UOOU - largest spam fine in its history, CZK 6 million (25 September 2020)(uoou.gov.cz).gov
- UOOU - cookies require consent from the start of 2022(uoou.gov.cz).gov
- Act No. 110/2019 Coll. - version history (amended by 448/2024, 218/2025 and 230/2025 Coll.)(zakonyprolidi.cz)
- Act No. 127/2005 Coll. on Electronic Communications, ss. 88(3) and 89(3)(zakonyprolidi.cz)
- Act No. 262/2006 Coll., the Labour Code, s. 316 (workplace monitoring)(zakonyprolidi.cz)