Czechia
Part of the European Union, so bloc-wide rules apply here too. Checked yesterday.
The answer
Czechia follows the European rulebook. Ordinary data can leave the country, and leave Europe, if you use an approved European transfer route. Two industries differ: online gambling servers must sit inside the European Union, and cloud sold to Czech government at the top security grade must keep data in Europe. The privacy regulator works well, but is banned by law from fining government bodies.
Data governance in Czechia
The eight things that decide how you handle data about people in Czechia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Europe's General Data Protection Regulation applies directly in Czechia, and it reaches a company anywhere in the world that offers goods or services to people in Czechia or watches what they do online. There is no minimum size or revenue. If you are outside Europe and caught by the rules, you must appoint a written representative inside Europe.
The national top-up law is Act No. 110/2019 Sb. on personal data processing. It does not narrow the territorial reach of the European Regulation; it adds Czech-specific detail such as the age of a child's consent, the journalistic and academic exemption, the status of the Office for Personal Data Protection, and the separate regime for police and national security processing. The cybersecurity layer is different and narrower: the Cybersecurity Act No. 264/2025 Sb. attaches to the provision of a listed service in Czechia rather than to the company's nationality, and a foreign provider caught by it must register on the national cyber agency's portal like anyone else. Over 4,800 organisations had registered by early February 2026, which is a useful sign of how wide the net is drawn in practice.
Sources
- Official sourceÚřad pro ochranu osobních údajůLegal framework for personal data protection — the Regulation and Act No. 110/2019 Sb.
uoou.gov.cz
Link checked 18 August 2026
- Official sourcee-Sbírka, Ministry of the InteriorAct No. 110/2019 Sb. on personal data processing, consolidated text in force from 1 August 2025
e-sbirka.gov.cz
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostMore than 4,800 organisations registered under the new Cybersecurity Act, 11 February 2026
nukib.gov.cz
“K 8. únoru byl počet nahlášených subjektů 4825.”
Link checked 18 August 2026
Where the data is allowed to live
In general yes, with paperwork. Czechia adds no national storage rule on top of the European regime, so ordinary personal data can sit in a data centre outside Czechia and outside Europe if you use an approved transfer route. Two sectors break that pattern: online gambling and cloud sold to government at the top security grade. A third, telecoms, has a records-keeping duty that is legally contested.
Sector by sector, checked on 18 August 2026. GAMBLING — the hardest wall. The Gambling Act requires that the server for an internet game, and the server for technical games, be located on the territory of a European Union member state. Rated data must stay in the country at the European border rather than the Czech border. GOVERNMENT CLOUD — a real wall with a published escape hatch. To be listed in the state's cloud catalogue at the 'high' security grade, a provider must store customer data and certain operational data at rest only in European Union or European Free Trade Association countries. The national cyber agency publishes a list of services that fail this test but are catalogued anyway under an exemption, which currently includes services from Microsoft Ireland Operations Limited and Amazon Web Services EMEA SARL. Rated data must stay in the country with a case-by-case exemption route. TELECOMS — no storage location rule, but a six-month duty to keep traffic and location records, discussed under Q7. BANKING, PAYMENTS, INSURANCE, SECURITIES — no localisation rule found, checked 18 August 2026. The Czech National Bank's published position on banking secrecy allows a bank to hand customer data to an outsourcing provider without customer consent, provided the contract imposes secrecy duties matching the bank's own. The Bank's cloud guidance adopts the European supervisors' outsourcing guidelines and does not name a country. Europe's Digital Operational Resilience Regulation has applied since 17 January 2025 and requires the location of data processing to be written into supplier contracts, but it does not require a location. HEALTH — no localisation rule found, checked 18 August 2026, confidence medium. Czech health records law sets long retention periods but we found no territorial requirement on the health ministry's own sites. DEFENCE AND CLASSIFIED — any information system that handles classified information must be certified by the national cyber agency before it is switched on. That is an approval gate rather than a stated border, but in practice it blocks ordinary foreign cloud. MAPPING AND GEOSPATIAL — no localisation rule found, checked 18 August 2026. The land survey office publishes conditions for supplying spatial data and treats much of it as open data. EDUCATION AND E-COMMERCE — no localisation rule found, checked 18 August 2026.
Sources
- Official sourceCzech Collection of Laws, notified textAct No. 186/2016 Sb. on gambling — official Czech text, server location provisions
eur-lex.europa.eu
“Server internetové hry a zařízení využívané k provozování číselné loterie ... se musí nacházet na území členského státu Evropské unie”
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostCloud computing — exemptions from the data storage location requirement (official notice board)
nukib.gov.cz
“data zákazníka a specifická provozní data v neaktivním stavu jsou uložena výhradně na území členských států EU a ESVO”
Link checked 18 August 2026
- Official sourceČeská národní bankaCzech National Bank official opinion on banking secrecy, revised 1 February 2023
cnb.cz
“Banka může předat údaje chráněné bankovním tajemstvím osobě, která pro banku zajišťuje určité činnosti v rámci outsourcingu”
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostSecurity of information and communication systems handling classified information
nukib.gov.cz
Link checked 18 August 2026
Sending data out of the country
Use one of the European routes. Send data to a country Europe has formally approved, or sign the European standard contract clauses, or set up binding corporate rules for your group. Czechia adds no national approval step and keeps no national list of banned countries. Before you send data somewhere without an approval decision, you are expected to check whether the destination's surveillance laws would undermine your safeguards.
The model is a European allowlist. Approved destinations as at 18 August 2026: Andorra, Argentina, Brazil (new, 26 January 2026, mutual), Canada for commercial organisations only, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the United States but only for companies that have signed up to the European Union-United States Data Privacy Framework, and the European Patent Organisation. None has been withdrawn or suspended. The 2021 standard contractual clauses remain the operative set and have not been amended; the promised new clauses for importers already directly caught by the European Regulation have still not been adopted, so market practice is to use the 2021 clauses and switch off the duplicated terms. Binding corporate rules remain available. The narrow one-off exceptions, such as the individual's explicit consent, are not a basis for routine bulk transfers. A separate point that catches people: European guidance finalised in June 2025 confirms that an order from a foreign authority is not by itself a lawful reason to hand data over. The list is populated and it is the same list for every European Union country, so there is no Czech-specific advantage or trap here. The Czech regulator's own legal framework page points straight at the European Regulation as the operative instrument.
Sources
- Official sourceÚřad pro ochranu osobních údajůCzech regulator's legal framework page — the European Regulation is the operative instrument
uoou.gov.cz
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the current approved-destination list
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
The regulator, and whether it actually acts
Yes, the regulators here really work. The Office for Personal Data Protection has a president, Jiří Kaucký, reappointed for a second term by the country's President on 26 August 2025. In 2025 it received 3,854 complaints and notifications, opened 27 inspections and imposed 7 fines totalling about 14.7 million Czech koruna, roughly 700,000 US dollars. It publishes an inspection plan for the year ahead. The cyber agency is busier still. But the privacy office is forbidden by Czech law from fining any government body.
Four bodies matter. The Office for Personal Data Protection is the general privacy regulator. Its president serves a five-year term, appointed by the President of the Republic on the Senate's proposal, and may serve at most two consecutive terms. Its 2025 annual report records 2,514 complaints and 1,340 notifications, a 68 percent year-on-year rise and the highest since the European Regulation started; 392 personal data breach notifications; 27 inspections opened, 13 completed; 7 fines totalling 14,671,000 Czech koruna; and a largest single fine of 7,500,000 Czech koruna, about 350,000 US dollars, for a private company misusing national identification numbers. It also closed an inspection into facial recognition at Prague's Václav Havel Airport, which was switched off on 1 August 2025. Its published 2026 inspection plan targets data protection officers in the public sector, debt registers, marketing messages disguised as satisfaction surveys, the gambling exclusion database, passenger name records, and the European asylum, visa and Schengen systems. That is an active regulator with modest fine levels, not an aggressive one. The National Cyber and Information Security Agency, known as NÚKIB, runs the Cybersecurity Act. It stood up a registration portal, took 4,825 registrations by 8 February 2026, publishes its own decrees, and maintains the public exemption list for the government cloud catalogue. The Czech Telecommunication Office is the country's Digital Services Coordinator for the European platform rules. Here there is a real gap: its own annual report for 2025 says that because the national enabling law had not been adopted it could not certify out-of-court dispute bodies, trusted flaggers or vetted researchers, and could not carry out inspections or impose penalties. It handled 98 complaints in 2025 anyway. So on platform regulation specifically, Czechia is closer to dormant than active. The Czech National Bank supervises banks, insurers, investment firms and payment providers, and is the competent authority for Europe's financial resilience rules, which have applied since 17 January 2025.
Sources
- Official sourceÚřad pro ochranu osobních údajůAnnual Report of the Office for Personal Data Protection for 2025
uoou.gov.cz
Link checked 18 August 2026
- Official sourceÚřad pro ochranu osobních údajůInspection plan for 2026, ref. UOOU-1768/25-1, 18 December 2025
uoou.gov.cz
Link checked 18 August 2026
- Official sourceČeský telekomunikační úřadAnnual report of the Czech Telecommunication Office under Article 55 of the Digital Services Act, 2025
ctu.gov.cz
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostRegistrations under the new Cybersecurity Act, 11 February 2026
nukib.gov.cz
Link checked 18 August 2026
How long you must keep it — and when to delete it
Both directions apply, and they collide. The ceiling comes from the European rule: delete personal data once the purpose is finished. The floors come from sector laws. Telecoms firms must keep records of who contacted whom for six months. Gambling operators must keep customer identification records for ten years and betting records for two. Accounting and tax records run for years and are being rewritten. Where a floor and the ceiling conflict, the floor wins, because keeping data to obey a law is itself a lawful reason to keep it.
Floors we verified from official sources: six months for telecoms traffic and location data under the Electronic Communications Act, with the detailed scope set by Decree No. 357/2012 Sb.; ten years for customer registration and identity data and for gaming-token transaction records under the Gambling Act; two years for betting records; one year for recordings of live betting. Under the Cybersecurity Act the agency's decrees set logging and record-keeping duties for registered organisations, and the supplier-reporting duty for strategically significant services runs to one year from designation. Accounting and tax floors exist but we could not pin exact periods to a Czech government page during this run, so treat them at medium confidence: the Accounting Act is being completely rewritten and the Ministry of Finance says a long lead-in is needed because roughly 150 other laws are affected, with 1 January 2027 the date most often mentioned. Do not plan a deletion schedule on that assumption without checking. On the ceiling side, Czechia adds no national deletion deadline of its own. The general European storage limitation principle applies unchanged, and the Czech regulator's 2026 inspection plan explicitly targets how long debt registers keep consumer data, which tells you where it expects to find over-retention.
Sources
- Official sourceCzech Collection of Laws, notified textAct No. 186/2016 Sb. on gambling — retention of registration data (10 years) and betting records (2 years)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceÚstavní soud České republikyConstitutional Court, Pl. ÚS 45/17, 22 May 2019 — six-month telecoms retention upheld
usoud.cz
Link checked 18 August 2026
- Official sourceMinisterstvo průmyslu a obchoduDecree No. 357/2012 Sb. on retention, transfer and destruction of traffic and location data
mpo.gov.cz
Link checked 18 August 2026
- Official sourceMinisterstvo financíMinistry of Finance FAQ on the new accounting legislation — recodification and lead-in time
mf.gov.cz
Link checked 18 August 2026
If something goes wrong
Count three clocks. A personal data breach goes to the privacy office within 72 hours, and to affected people without undue delay if the risk to them is high. A cyber incident at an organisation registered under the Cybersecurity Act goes to the cyber agency within 24 hours if you are in the higher tier, or 72 hours in the lower tier, with a final report inside 30 days. Financial firms have a separate European clock of their own. Many companies are caught by two of these at once.
Clock one, privacy: 72 hours from becoming aware, to the Office for Personal Data Protection, under the European Regulation. The Office received 392 such notifications in 2025. Clock two, cybersecurity: under Act No. 264/2025 Sb., in force since 1 November 2025, an organisation in the higher regime reports within 24 hours of detection, and the agency then decides on significance; the lower regime reports detailed information within 72 hours, with a final report within 30 days. Clock three, finance: Europe's Digital Operational Resilience Regulation has applied since 17 January 2025 and sets its own major-incident reporting chain to the Czech National Bank. The overlap is the operational failure point. A registered bank suffering a ransomware attack that exposes customer records is running all three clocks from the same moment, with three different recipients, three different forms and three different definitions of what counts. Build the decision tree before the incident, not during it.
Sources
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostAct No. 264/2025 Sb. on cybersecurity — official presentation by the Director of the Regulation Section
portal.nukib.gov.cz
“nabyde účinnosti 1. listopadu 2025”
Link checked 18 August 2026
- Official sourceÚřad pro ochranu osobních údajůAnnual Report 2025 — 392 personal data breach notifications received
uoou.gov.cz
Link checked 18 August 2026
- Official sourceČeská národní bankaDigital operational resilience of the financial market — applies from 17 January 2025
cnb.cz
“Nařízení DORA vstoupilo v platnost 17. ledna 2025”
Link checked 18 August 2026
What catches people out
Five things that cost people their weekend. (1) A Czech child can consent to online services at 15, not 16. (2) Mishandling personal data can be a crime, not just a fine. (3) The privacy office cannot fine a government body at all, so if a public authority leaks your data there is no fine to point at. (4) Telecoms firms must keep six months of contact records that Czechia's own Supreme Court said in January 2026 breaks European law, yet the duty still stands. (5) The Czech platform regulator exists but cannot inspect or fine anybody yet.
One. Act No. 110/2019 Sb. sets the age at which a child can consent to an information society service at fifteen. The European default is sixteen, and other member states range from thirteen to sixteen. If your age gate is hard-coded to a single European number you are wrong in Czechia. Two. Section 180 of the Czech Criminal Code makes unauthorised handling of personal data a criminal offence, carrying imprisonment. This sits alongside, not instead of, the administrative fine. Individual managers, not just the company, are exposed. We were unable to open an official copy of the section text during this run, so the prison ranges are marked unconfirmed. Three. Section 62(5) of Act No. 110/2019 Sb. prevents the Office for Personal Data Protection from imposing an administrative penalty on a public authority or public body. The Office has publicly said this is why it could not fine a ministry. Corrective orders remain available, fines do not. Practical effect: if your data sits with a Czech public authority, financial deterrence is absent and your leverage is the corrective order and a compensation claim. Four. The six-month telecoms retention duty was upheld as constitutional in 2019 by the Constitutional Court in case Pl. ÚS 45/17. On 8 January 2026 the Supreme Court, in case 30 Cdo 2556/2025, held that blanket and undifferentiated retention conflicts with European Union law and ordered the state to apologise to a journalist whose data had been kept. The Supreme Court cannot strike a law down. So the duty remains binding on operators while the state is simultaneously liable for imposing it. That is an unstable position and it is the single most likely thing to change in the next year. Five. The Czech Telecommunication Office is the designated Digital Services Coordinator for the European platform rules but, on its own account for 2025, lacked the national statutory authorisation to run inspections or impose sanctions, or to certify dispute bodies, trusted flaggers and vetted researchers. Do not read a Czech postal address for a platform regulator as a Czech enforcement risk yet. Bonus trap for banks: Czech banking secrecy under the Act on Banks is a separate duty from privacy law. Outsourcing is allowed without customer consent, but the contract must impose secrecy obligations equivalent to the bank's own. A standard European processor contract alone does not satisfy this.
Sources
- Official sourceCzech Collection of Laws, notified textAct No. 110/2019 Sb., section 7 — a child gains capacity to consent at fifteen
eur-lex.europa.eu
“Dítě nabývá způsobilosti k udělení souhlasu se zpracováním osobních údajů v souvislosti s nabídkou služeb informační společnosti přímo jemu dovršením patnáctého roku věku.”
Link checked 18 August 2026
- Official sourceÚřad pro ochranu osobních údajůThe Office could not fine a ministry — the law does not allow it
uoou.gov.cz
“§ 62 odst. 5 zákona č. 110/2019 Sb., podle kterého nemůže být orgánu veřejné moci a veřejnému subjektu uložena pokuta”
Link checked 18 August 2026
- Official sourceNejvyšší soud České republikySupreme Court judgment 30 Cdo 2556/2025, published on the court's notice board 8 January 2026
nsoud.cz
Link checked 18 August 2026
- Official sourceČeský telekomunikační úřadDigital Services Act annual report 2025 — no national enabling law, so no inspections or sanctions
ctu.gov.cz
Link checked 18 August 2026
What's changing next
Four things to watch in the next twelve months. Telecoms retention is legally unstable after the Supreme Court's January 2026 ruling and something has to give. The Czech bill that would give the platform regulator real powers is still in parliament. A new law on state data sharing was signed on 28 April 2026 but its obligations only start in 2028 and 2029. And across Europe, cloud switching charges must fall to zero by 12 January 2027.
Dated items. 12 January 2027 — under Europe's Data Act, which has applied since 12 September 2025, all cloud switching charges and data egress fees must be zero. This is a hard commercial deadline, not a filing obligation, and it lands on providers selling into Czechia like everywhere else. The Czech national law naming a competent authority is still pending; the telecoms regulator expects to be named data coordinator. 1 January 2028 and 1 January 2029 — Act No. 60/2026 Sb. on data management and controlled access to data, signed on 28 April 2026, phases in a national data catalogue and central registration of public bodies' datasets. Unknown date, 2026 or 2027 — the digital economy bill, which would give the Czech Telecommunication Office inspection and sanction powers under the European platform rules. It was moving through the Chamber of Deputies in March 2026. Until it passes, the coordinator has no teeth. Unknown date — a legislative response to the Supreme Court's data retention ruling. A draft amendment to Decree No. 357/2012 Sb. was in the government's consultation system. Nothing is repealed yet. DORMANT SWITCHES, which matter more than bills. First: under the Cybersecurity Act the government can issue a warning about, or ban, a named supplier of security-critical components for strategically significant services. That power can be exercised without a new law and would remove a vendor from your architecture overnight. Second: the national cyber agency controls the exemption list for the government cloud catalogue and can, in principle, stop publishing an exemption for a named service, which would force public-sector customers off it. Third: the cyber agency issues its own decrees setting security measures, so the technical bar can rise without parliament.
Sources
- Official sourcee-Sbírka, Ministry of the InteriorAct No. 60/2026 Sb. on data management and controlled access to data
e-sbirka.gov.cz
Link checked 18 August 2026
- Official sourcePortál otevřených dat České republikyPresident signs the key law for the digital state, 28 April 2026
data.gov.cz
Link checked 18 August 2026
- Official sourceČeský telekomunikační úřadMonitoring report 09/2025 — the Data Act starts to apply; the Office expects to be named data coordinator under a forthcoming adaptation law
ctu.gov.cz
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostAct No. 264/2025 Sb. — government power to warn about or ban a supplier for strategically significant services
portal.nukib.gov.cz
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Vyhláška č. 316/2021 Sb., o některých požadavcích pro zápis do katalogu cloud computingu
Government rules · Decree No. 316/2021 Sb., Annex 2 rows 1.3 and 1.4, made under Act No. 365/2000 Sb.
To sell cloud to Czech public bodies at the top security grade, a provider must keep customer data at rest inside the European Union or the European Free Trade Association area. The national cyber agency publishes a public list of services that fail this test but stay in the catalogue under an exemption, so it is a wall with a named, visible door.
Enforced by National Cyber and Information Security Agency
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryFor the 'high' security level: customer data and specific operational data at rest must be stored only in European Union or European Free Trade Association countries. The boundary is Europe, not the Czech border.
- Register or notifyA provider must be entered in the state cloud computing catalogue before a public body may buy the service.
- Hold a security certificate
- Prove the data stays under local control
What it costs if you get it wrong
- Order to stopRemoval from, or refusal of entry in, the cloud computing catalogue, which shuts off Czech public-sector sales
Sources
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostCloud computing — exemptions from the data storage requirement (official notice board)
nukib.gov.cz
“data zákazníka a specifická provozní data v neaktivním stavu jsou uložena výhradně na území členských států EU a ESVO”
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostThe agency publishes cloud computing exemptions from the data storage requirement
nukib.gov.cz
Link checked 18 August 2026
- Official sourceDigitální a informační agenturaCloud computing catalogue — registered providers and the Act No. 365/2000 Sb. requirements
dia.gov.cz
“Zapsaní poskytovatelé splnili veškeré požadavky zákona č. 365/2000 Sb. pro zápis do katalogu cloud computingu”
Link checked 18 August 2026
Zákon č. 186/2016 Sb., o hazardních hrách
Act of parliament · Act No. 186/2016 Sb., sections 42(5) and 74(2)
Czechia's hardest storage wall. The server running an online or technical gambling game must physically sit inside a European Union country, and player identity records must be kept for ten years. Operators must also feed financial and gaming data to the state's system.
Enforced by Ministry of Finance
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryThe server for an internet game, and the server for a technical game, must be on the territory of a European Union member state. Hosting the game system in the United States or Asia is not an option.
- Keep data for a minimum period — 10 yearsPlayer registration and identity data, and gaming token transaction records.
- Keep data for a minimum period — 2 yearsBetting records.
- Keep data for a minimum period — 1 yearRecordings relating to live betting.
- Register or notifyLicence from the Ministry of Finance; supervision by the Customs Administration.
- Independent audit
What it costs if you get it wrong
- Loss of your licenceOperating outside the licence conditions
Sources
- Official sourceCzech Collection of Laws, notified textAct No. 186/2016 Sb. on gambling — official Czech text, sections 42(5), 74(2) and retention provisions
eur-lex.europa.eu
“Server internetové hry a zařízení využívané k provozování číselné loterie ... se musí nacházet na území členského státu Evropské unie”
Link checked 18 August 2026
- Official sourceCelní správa České republikyGambling legislation, including Decree No. 208/2017 Sb. on protection and retention of gaming and financial data
celnisprava.gov.cz
Link checked 18 August 2026
Vyhláška č. 357/2012 Sb., o uchovávání, předávání a likvidaci provozních a lokalizačních údajů
Government rules · Decree No. 357/2012 Sb., made under the Electronic Communications Act; upheld in Pl. ÚS 45/17; criticised in 30 Cdo 2556/2025
Czech telecoms operators must keep six months of records showing who contacted whom, when and from where. The Constitutional Court upheld this in 2019. On 8 January 2026 the Supreme Court held that blanket retention conflicts with European Union law and made the state liable, but it cannot repeal the rule, so operators must still comply.
Enforced by Czech Telecommunication Office
Transfer model: Allowlist · Accepted routes: Standard contract clauses, Official 'this country is safe' decision
What it makes you do
- Keep data for a minimum period — 6 monthsTraffic and location data about who communicated with whom, when and from where. Content is not covered.
- Delete data after a period — 6 monthsThe data must be destroyed once the six-month period ends, unless another law requires otherwise.
What it costs if you get it wrong
- Fixed maximum fineFailure to retain or to hand over on a lawful request
- Claims by individualsState liability. The Supreme Court ordered the state to apologise to a journalist whose data was retained under this regime.
Sources
- Official sourceÚstavní soud České republikyConstitutional Court, Pl. ÚS 45/17, 22 May 2019 — six-month retention held constitutional
usoud.cz
Link checked 18 August 2026
- Official sourceNejvyšší soud České republikySupreme Court judgment 30 Cdo 2556/2025, notice board 8 January 2026 — blanket retention contrary to European Union law
nsoud.cz
Link checked 18 August 2026
- Official sourceMinisterstvo průmyslu a obchoduDecree No. 357/2012 Sb. — retention, transfer and destruction of traffic and location data
mpo.gov.cz
Link checked 18 August 2026
Zákon č. 412/2005 Sb., o ochraně utajovaných informací a o bezpečnostní způsobilosti
Act of parliament · Act No. 412/2005 Sb., section 34, with Decree No. 479/2024 Sb. on information security
Any system that handles Czech classified information must be certified by the national cyber agency before it is switched on. There is no stated territorial ban we could confirm, but the certification gate is in practice what stops ordinary foreign cloud being used for this material.
Enforced by National Cyber and Information Security Agency
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Hold a security certificateAn information system handling classified information must be certified by the national cyber agency and approved in writing by a responsible person before it is operated. The approval must be notified to the agency within 30 days.
- Secure the dataFor the higher classification levels, protection against compromising electromagnetic emissions is also required.
What it costs if you get it wrong
- Order to stopOperating an uncertified system for classified information
- Criminal liabilityUnauthorised handling of classified information
Sources
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostSecurity of information and communication systems — certification requirement under section 34
nukib.gov.cz
Link checked 18 August 2026
- Official sourceNárodní bezpečnostní úřadAct No. 412/2005 Sb. on the protection of classified information
nbu.gov.cz
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Zákon č. 110/2019 Sb., o zpracování osobních údajů
Act of parliament · Act No. 110/2019 Sb., consolidated text in force from 1 August 2025
The Czech top-up to Europe's privacy rules. It adds no storage location requirement and no national approval step for sending data abroad. Its two Czech-specific edges are the age of a child's consent, set at fifteen, and a bar on fining public authorities.
Enforced by Office for Personal Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Get a parent's consent for children — applies at: under 15Czechia sets the age of a child's own consent for online services at fifteen, not the European default of sixteen.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Put a transfer safeguard in place
- Appoint a data protection officerRequired for public authorities and for large-scale monitoring or special-category processing.
- Keep records of processing
- Assess high-risk projects
- Appoint a local representativeNon-European controllers caught by the European Regulation must appoint a representative in Europe.
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Fixed maximum fine: €20,000,000 — about $22 millionSame tier, whichever is higher
- Criminal liability: Imprisonment under section 180 of the Criminal CodeUnauthorised handling of personal data
Sources
- Official sourcee-Sbírka, Ministry of the InteriorAct No. 110/2019 Sb., consolidated text in force from 1 August 2025
e-sbirka.gov.cz
Link checked 18 August 2026
- Official sourceCzech Collection of Laws, notified textAct No. 110/2019 Sb. — official Czech text as notified, sections 7, 17 and 62
eur-lex.europa.eu
“Dítě nabývá způsobilosti k udělení souhlasu se zpracováním osobních údajů v souvislosti s nabídkou služeb informační společnosti přímo jemu dovršením patnáctého roku věku.”
Link checked 18 August 2026
- Official sourceÚřad pro ochranu osobních údajůRegulator's own statement that it cannot fine a public authority
uoou.gov.cz
Link checked 18 August 2026
Zákon č. 264/2025 Sb., o kybernetické bezpečnosti
Act of parliament · Act No. 264/2025 Sb., with Decree No. 408/2025 Sb. on regulated services
Czechia's implementation of Europe's second network and information security directive. It imposes no data location rule, but it does hand the government a live power to ban a named supplier from strategically significant services. Registration was due by the end of 2025 and 4,825 organisations had complied by early February 2026.
Enforced by National Cyber and Information Security Agency
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notify — from 1 November 2025Self-identify and report the regulated service on the agency's portal within 60 days. Organisations already in scope on 1 November 2025 had until 31 December 2025.
- Report cyber incidents — within 24 hoursHigher regime.
- Report cyber incidents — within 72 hoursLower regime; detailed information. Final report within 30 days.
- Secure the data
- Written vendor contractFor strategically significant services, suppliers of security-critical components must be reported and the government may issue a warning or a ban.
- Keep logs
What it costs if you get it wrong
- Fixed maximum fine: CZK 250,000,000 — about $12 millionHigher regime, most serious breaches
- Percentage of global turnover: 2% of worldwide annual net turnoverHigher regime, whichever is higher
- Fixed maximum fine: CZK 175,000,000 — about $8 millionLower regime, or 1.4% of worldwide annual net turnover
Sources
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostAct No. 264/2025 Sb. on cybersecurity — official presentation, effective dates, regimes, deadlines and penalties
portal.nukib.gov.cz
“nabyde účinnosti 1. listopadu 2025”
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostMore than 4,800 organisations registered; 4,825 by 8 February 2026
nukib.gov.cz
Link checked 18 August 2026
- Official sourcee-Sbírka, Ministry of the InteriorDecree No. 408/2025 Sb. on regulated services
e-sbirka.gov.cz
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact prison terms in section 180 of the Czech Criminal Code for unauthorised handling of personal data
The police page carrying the section text is blocked to automated fetching by its robots file, and we did not locate an alternative official copy during this run. The existence of the criminal offence is well established; the sentencing ranges are not verified here.
Retention floors for accounting, tax and payroll records, and whether the new Accounting Act changes them
The Ministry of Finance page we opened confirms a complete recodification affecting around 150 laws and a long lead-in, with 1 January 2027 the date most often cited, but it does not state retention periods and we could not confirm the effective date from an official source. Treat any specific number you have seen elsewhere as unverified.
Whether the Czech digital economy bill, which would give the Czech Telecommunication Office inspection and sanction powers under the European platform rules, has passed since March 2026
The Chamber of Deputies bill pages returned 'document not found' to our fetches. Our latest official evidence is the Office's own 2025 annual report saying no adaptation law had been adopted, plus press reporting of a second reading in March 2026. Status as at 18 August 2026 is unverified.
Whether any health-sector data localisation rule exists in Czechia
No rule found, checked 18 August 2026. We reviewed the electronic healthcare framework and the national health information system materials and found retention and interoperability rules but no territorial storage requirement. This is a negative finding at medium confidence, not a proven absence.
Whether Decree No. 316/2021 Sb. and the cloud catalogue criteria were amended or replaced when the new Cybersecurity Act took effect on 1 November 2025
The national cyber agency's live notice board still applies the Annex 2 rows 1.3 and 1.4 storage test and still publishes exemptions against it, so the rule is operative. We did not confirm whether the decree number itself has changed.
Whether the Czech government has actually used its power under the Cybersecurity Act to warn about or ban a named supplier
The power is documented in the agency's own material. We found no published exercise of it, but we could not check the agency's full notice board history.
The precise scope of the gambling server rule, in particular whether backups and analytics copies may sit outside the European Union
The statute requires the server to be on European Union territory. It does not, in the text we read, address secondary copies. Implementing Decree No. 208/2017 Sb. governs protection and retention of gaming and financial data and we did not open its full current text.
60-day cadence. Two things can move quickly. The telecoms retention regime is legally unstable after the January 2026 Supreme Court judgment and a repeal or amendment could land without a long consultation. The national cyber agency controls the government cloud exemption list and the supplier-ban power under the Cybersecurity Act, both of which can change the picture for a named vendor with no new legislation.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Czechia versus
Compare