Czechia
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Czechia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Czechia follows the European rulebook. Ordinary data can leave the country, and leave Europe, if you use an approved European transfer route. Two industries differ. Online gambling servers must sit inside the European Union. Cloud sold to Czech government at the top security grade must keep data in Europe. The privacy regulator works well. But the law bans it from fining government bodies.
Data governance in Czechia
The eight things that decide how you handle data about people in Czechia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Europe's General Data Protection Regulation applies directly in Czechia. It reaches a company anywhere in the world that offers goods or services to people in Czechia. It also reaches you if you watch what they do online. There is no minimum size or revenue. If you are outside Europe and the rules catch you, you must appoint a written representative inside Europe.
- What you have to do here:
- Appoint a representative
The Czech add-on law is Act No. 110/2019 Sb. on personal data processing. It does not narrow the reach of the European Regulation. It adds Czech-specific detail. That covers the age of a child's consent and the exemption for journalism and academic work. It also covers the status of the Office for Personal Data Protection, and separate rules for police and national security work. The cybersecurity layer is different and narrower. The Cybersecurity Act No. 264/2025 Sb. applies where you supply a listed service in Czechia. It does not depend on where your company is based. A foreign provider caught by it must register on the national cyber agency's portal like anyone else. Over 4,800 organisations had registered by early February 2026. That gives you a sense of how wide the net is drawn.
Sources
- Official sourceÚřad pro ochranu osobních údajůLegal framework for personal data protection — the Regulation and Act No. 110/2019 Sb.
uoou.gov.cz
Link checked 18 August 2026
- Official sourcee-Sbírka, Ministry of the InteriorAct No. 110/2019 Sb. on personal data processing, consolidated text in force from 1 August 2025
e-sbirka.gov.cz
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostMore than 4,800 organisations registered under the new Cybersecurity Act, 11 February 2026
nukib.gov.cz
“K 8. únoru byl počet nahlášených subjektů 4825.”
Link checked 18 August 2026
Where the data is allowed to live
Yes, in general, with paperwork. Czechia adds no national storage rule on top of the European rules. So ordinary personal data can sit in a data centre outside Czechia and outside Europe, if you use an approved transfer route. Two industries break that pattern. They are online gambling and cloud sold to government at the top security grade. A third, telecoms, has a record-keeping duty that is being fought over in court.
Industry by industry, checked on 18 August 2026. GAMBLING. The strictest rule. Under the Gambling Act, the server for an internet game must sit on the territory of a European Union member state. The same goes for the server for technical games. We rate this closed at the European border, not the Czech border. GOVERNMENT CLOUD. A real wall, with a published way out. You may want to be listed in the state's cloud catalogue at the 'high' security grade. Then you must store customer data and certain operational data only in European Union or European Free Trade Association countries. The national cyber agency publishes a list of services that fail this test but stay in the catalogue under an exemption. That list currently includes services from Microsoft Ireland Operations Limited and Amazon Web Services EMEA SARL. We rate this closed, with a case-by-case exemption route. TELECOMS. No rule on where data must sit. But there is a six-month duty to keep traffic and location records. See question seven. BANKING, PAYMENTS, INSURANCE, SECURITIES. We found no rule requiring data to stay in the country, checked 18 August 2026. The Czech National Bank's published position on banking secrecy lets a bank hand customer data to an outsourcing provider without customer consent. The contract must impose secrecy duties matching the bank's own. The Bank's cloud guidance follows the European supervisors' outsourcing guidelines and names no country. Europe's Digital Operational Resilience Regulation has applied since 17 January 2025. It requires supplier contracts to say where data is handled. It does not require any particular location. HEALTH. We found no rule requiring data to stay in the country, checked 18 August 2026, confidence medium. Czech health records law sets long keeping periods. We found no location requirement on the health ministry's own sites. DEFENCE AND CLASSIFIED. Any information system handling classified information must be certified by the national cyber agency before it is switched on. That is an approval step rather than a stated border. It still blocks ordinary foreign cloud. MAPPING AND GEOSPATIAL. We found no rule requiring data to stay in the country, checked 18 August 2026. The land survey office publishes conditions for supplying spatial data and treats much of it as open data. EDUCATION AND E-COMMERCE. We found no rule requiring data to stay in the country, checked 18 August 2026.
Sources
- Official sourceCzech Collection of Laws, notified textAct No. 186/2016 Sb. on gambling — official Czech text, server location provisions
eur-lex.europa.eu
“Server internetové hry a zařízení využívané k provozování číselné loterie ... se musí nacházet na území členského státu Evropské unie”
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostCloud computing — exemptions from the data storage location requirement (official notice board)
nukib.gov.cz
“data zákazníka a specifická provozní data v neaktivním stavu jsou uložena výhradně na území členských států EU a ESVO”
Link checked 18 August 2026
- Official sourceČeská národní bankaCzech National Bank official opinion on banking secrecy, revised 1 February 2023
cnb.cz
“Banka může předat údaje chráněné bankovním tajemstvím osobě, která pro banku zajišťuje určité činnosti v rámci outsourcingu”
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostSecurity of information and communication systems handling classified information
nukib.gov.cz
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Use one of the European routes. Send data to a country Europe has formally approved. Or sign the European standard contract clauses. Or set up binding corporate rules for your group. Czechia adds no national approval step. It keeps no national list of banned countries. Before you send data to a country Europe has not approved, check whether that country's surveillance laws would undermine your safeguards.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent
Europe uses an approved-country list. Approved destinations as at 18 August 2026 are as follows. Andorra, Argentina and Brazil (new, 26 January 2026, mutual). Canada, for commercial organisations only. The Faroe Islands, Guernsey, the Isle of Man, Israel and Japan. Jersey, New Zealand and South Korea (first review confirmed 23 July 2026). Switzerland and the United Kingdom (renewed 19 December 2025, running to 2031). Uruguay and the European Patent Organisation. It covers the United States too, but only for companies signed up to the European Union-United States Data Privacy Framework. None has been withdrawn or suspended. The 2021 standard contractual clauses are still the set to use, and they have not been amended. The promised new clauses, for recipients already directly caught by the European Regulation, have still not been adopted. So most companies use the 2021 clauses and switch off the duplicated terms. Binding corporate rules are still available. The narrow one-off exceptions, such as the person's explicit consent, are not a basis for routine bulk transfers. One point catches people out. European guidance finalised in June 2025 confirms that an order from a foreign authority is not by itself a lawful reason to hand data over. The list is full, and it is the same list for every European Union country. So there is no Czech-specific advantage or trap here. The Czech regulator's own legal page points straight at the European Regulation as the rule that governs.
Sources
- Official sourceÚřad pro ochranu osobních údajůCzech regulator's legal framework page — the European Regulation is the operative instrument
uoou.gov.cz
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the current approved-destination list
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
Yes, the regulators here really work. The Office for Personal Data Protection has a president, Jiří Kaucký. The country's President reappointed him for a second term on 26 August 2025. In 2025 it received 3,854 complaints and notifications. It opened 27 inspections and imposed 7 fines. Those totalled about 14.7 million Czech koruna, roughly 700,000 US dollars. It publishes an inspection plan for the year ahead. The cyber agency is busier still. But Czech law forbids the privacy office from fining any government body.
Four bodies matter. The Office for Personal Data Protection is the general privacy regulator. Its president serves a five-year term. The President of the Republic appoints them on the Senate's proposal. They may serve at most two terms in a row. Its 2025 annual report records 2,514 complaints and 1,340 notifications. That is a 68 percent rise on the year before, and the highest since the European Regulation started. It also records 392 personal data breach reports, 27 inspections opened and 13 completed, and 7 fines totalling 14,671,000 Czech koruna. The largest single fine was 7,500,000 Czech koruna, about 350,000 US dollars, against a private company that misused national identification numbers. It also closed an inspection into facial recognition at Prague's Václav Havel Airport, which was switched off on 1 August 2025. Its published 2026 inspection plan targets several areas. Data protection officers in the public sector. Debt registers. Marketing messages disguised as satisfaction surveys. The gambling exclusion database. Passenger name records. And the European asylum, visa and Schengen systems. That is an active regulator with modest fines, not an aggressive one. The National Cyber and Information Security Agency, known as NÚKIB, runs the Cybersecurity Act. It set up a registration portal and took 4,825 registrations by 8 February 2026. It publishes its own decrees. It keeps the public exemption list for the government cloud catalogue. The Czech Telecommunication Office is the country's Digital Services Coordinator for the European platform rules. There is a real gap here. Its own 2025 annual report says the national enabling law had not been adopted. So it could not certify out-of-court dispute bodies, trusted flaggers or vetted researchers. It could not carry out inspections or impose penalties. It handled 98 complaints in 2025 anyway. So on platform regulation, Czechia is closer to dormant than active. The Czech National Bank supervises banks, insurers, investment firms and payment providers. It is the competent authority for Europe's financial resilience rules, which have applied since 17 January 2025.
Sources
- Official sourceÚřad pro ochranu osobních údajůAnnual Report of the Office for Personal Data Protection for 2025
uoou.gov.cz
Link checked 18 August 2026
- Official sourceÚřad pro ochranu osobních údajůInspection plan for 2026, ref. UOOU-1768/25-1, 18 December 2025
uoou.gov.cz
Link checked 18 August 2026
- Official sourceČeský telekomunikační úřadAnnual report of the Czech Telecommunication Office under Article 55 of the Digital Services Act, 2025
ctu.gov.cz
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostRegistrations under the new Cybersecurity Act, 11 February 2026
nukib.gov.cz
Link checked 18 August 2026
How long you must keep it — and when to delete it
There are rules in both directions, and they collide. The maximum comes from the European rule. Delete personal data once the purpose is finished. The minimums come from industry laws. Telecoms firms must keep records of who contacted whom for six months. Gambling operators must keep customer identification records for ten years and betting records for two. Accounting and tax records run for years, and those rules are being rewritten. Where a minimum and a maximum clash, the minimum wins. Keeping data to obey a law is itself a lawful reason to keep it.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
Minimums we confirmed from official sources. Six months for telecoms traffic and location data under the Electronic Communications Act, with the detail set by Decree No. 357/2012 Sb. Ten years for customer registration and identity data, and for gaming-token transaction records, under the Gambling Act. Two years for betting records. One year for recordings of live betting. Under the Cybersecurity Act, the agency's decrees set logging and record-keeping duties for registered organisations. The supplier-reporting duty for strategically significant services runs to one year from designation. Accounting and tax minimums exist, but we could not tie exact periods to a Czech government page. Treat them as medium confidence. The Accounting Act is being completely rewritten. The Ministry of Finance says a long lead-in is needed, because roughly 150 other laws are affected. The date most often mentioned is 1 January 2027. Do not build a deletion schedule on that assumption without checking. On the maximum side, Czechia adds no national deletion deadline of its own. The general European storage limitation principle applies unchanged. The Czech regulator's 2026 inspection plan targets how long debt registers keep consumer data. That tells you where it expects to find data kept too long.
Sources
- Official sourceCzech Collection of Laws, notified textAct No. 186/2016 Sb. on gambling — retention of registration data (10 years) and betting records (2 years)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceÚstavní soud České republikyConstitutional Court, Pl. ÚS 45/17, 22 May 2019 — six-month telecoms retention upheld
usoud.cz
Link checked 18 August 2026
- Official sourceMinisterstvo průmyslu a obchoduDecree No. 357/2012 Sb. on retention, transfer and destruction of traffic and location data
mpo.gov.cz
Link checked 18 August 2026
- Official sourceMinisterstvo financíMinistry of Finance FAQ on the new accounting legislation — recodification and lead-in time
mf.gov.cz
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
Three deadlines apply. A personal data breach goes to the privacy office within 72 hours. You must also tell affected people without undue delay if the risk to them is high. A cyber incident at an organisation registered under the Cybersecurity Act goes to the cyber agency. That is within 24 hours if you are in the higher tier, or 72 hours in the lower tier. A final report follows inside 30 days. Financial firms have a separate European deadline of their own. Many companies are caught by two of these at once.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Deadline one, privacy. You have 72 hours from becoming aware, reporting to the Office for Personal Data Protection under the European Regulation. The Office received 392 such reports in 2025. Deadline two, cybersecurity. Act No. 264/2025 Sb. has applied since 1 November 2025. An organisation in the higher tier reports within 24 hours of detection. The agency then decides how significant it is. The lower tier reports detailed information within 72 hours, with a final report within 30 days. Deadline three, finance. Europe's Digital Operational Resilience Regulation has applied since 17 January 2025. It sets its own reporting chain for major incidents, running to the Czech National Bank. The overlap is where things go wrong. A registered bank hit by ransomware that exposes customer records is running all three deadlines from the same moment. There are three different recipients, three different forms and three different definitions of what counts. Build the decision tree before the incident, not during it.
Sources
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostAct No. 264/2025 Sb. on cybersecurity — official presentation by the Director of the Regulation Section
portal.nukib.gov.cz
“nabyde účinnosti 1. listopadu 2025”
Link checked 18 August 2026
- Official sourceÚřad pro ochranu osobních údajůAnnual Report 2025 — 392 personal data breach notifications received
uoou.gov.cz
Link checked 18 August 2026
- Official sourceČeská národní bankaDigital operational resilience of the financial market — applies from 17 January 2025
cnb.cz
“Nařízení DORA vstoupilo v platnost 17. ledna 2025”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. (1) A Czech child can consent to online services at 15, not 16. (2) Mishandling personal data can be a crime, not just a fine. (3) The privacy office cannot fine a government body at all. So if a public authority leaks your data, there is no fine to point at. (4) Telecoms firms must keep six months of contact records. Czechia's own Supreme Court said in January 2026 that this breaks European law, yet the duty still stands. (5) The Czech platform regulator exists but cannot inspect or fine anybody yet.
- What you have to do here:
- Get a parent's consent for children · Extra vendor secrecy terms
- What it costs if you get it wrong:
- Criminal liability
One. Act No. 110/2019 Sb. sets the age at which a child can consent to an online service at fifteen. The European default is sixteen. Other member states range from thirteen to sixteen. If your age gate is hard-coded to a single European number, you are wrong in Czechia. Two. Section 180 of the Czech Criminal Code makes unauthorised handling of personal data a crime, carrying a prison sentence. This sits alongside the administrative fine, not instead of it. Individual managers are exposed, not just the company. We could not open an official copy of the section text, so we have marked the prison ranges as unconfirmed. Three. Section 62(5) of Act No. 110/2019 Sb. stops the Office for Personal Data Protection from fining a public authority or public body. The Office has publicly said this is why it could not fine a ministry. It can still issue corrective orders. It cannot fine. So if your data sits with a Czech public authority, there is no financial deterrent. Your leverage is the corrective order and a compensation claim. Four. The Constitutional Court upheld the six-month telecoms retention duty as constitutional in 2019, in case Pl. ÚS 45/17. On 8 January 2026 the Supreme Court ruled in case 30 Cdo 2556/2025. It held that blanket, undifferentiated retention conflicts with European Union law. It ordered the state to apologise to a journalist whose data had been kept. The Supreme Court cannot strike a law down. So the duty still binds operators, while the state is liable for imposing it. That is unstable, and it is the most likely thing to change in the next year. Five. The Czech Telecommunication Office is the named Digital Services Coordinator for the European platform rules. But on its own account for 2025, it lacked the national legal authority to run inspections or impose penalties. It also could not certify dispute bodies, trusted flaggers or vetted researchers. Do not treat a Czech postal address for a platform regulator as a Czech enforcement risk yet. One more trap, for banks. Czech banking secrecy under the Act on Banks is a separate duty from privacy law. Outsourcing is allowed without customer consent. But the contract must impose secrecy duties equal to the bank's own. A standard European supplier contract alone does not meet this.
Sources
- Official sourceCzech Collection of Laws, notified textAct No. 110/2019 Sb., section 7 — a child gains capacity to consent at fifteen
eur-lex.europa.eu
“Dítě nabývá způsobilosti k udělení souhlasu se zpracováním osobních údajů v souvislosti s nabídkou služeb informační společnosti přímo jemu dovršením patnáctého roku věku.”
Link checked 18 August 2026
- Official sourceÚřad pro ochranu osobních údajůThe Office could not fine a ministry — the law does not allow it
uoou.gov.cz
“§ 62 odst. 5 zákona č. 110/2019 Sb., podle kterého nemůže být orgánu veřejné moci a veřejnému subjektu uložena pokuta”
Link checked 18 August 2026
- Official sourceNejvyšší soud České republikySupreme Court judgment 30 Cdo 2556/2025, published on the court's notice board 8 January 2026
nsoud.cz
Link checked 18 August 2026
- Official sourceČeský telekomunikační úřadDigital Services Act annual report 2025 — no national enabling law, so no inspections or sanctions
ctu.gov.cz
Link checked 18 August 2026
What's changing next
Four things to watch in the next twelve months. Telecoms record-keeping is legally unstable after the Supreme Court's January 2026 ruling, and something has to give. The Czech bill that would give the platform regulator real powers is still in parliament. A new law on state data sharing was signed on 28 April 2026, but its duties only start in 2028 and 2029. And across Europe, cloud switching charges must fall to zero by 12 January 2027.
- What you have to do here:
- Make switching cloud provider possible
Dated items. 12 January 2027. Under Europe's Data Act, which has applied since 12 September 2025, all cloud switching charges and data egress fees must be zero. This is a commercial deadline, not a filing deadline. It lands on providers selling into Czechia like everywhere else. The Czech national law naming a competent authority is still pending. The telecoms regulator expects to be named data coordinator. 1 January 2028 and 1 January 2029. Act No. 60/2026 Sb. on data management and controlled access to data was signed on 28 April 2026. It phases in a national data catalogue and central registration of public bodies' datasets. Unknown date, 2026 or 2027. The digital economy bill would give the Czech Telecommunication Office powers to inspect and penalise under the European platform rules. It was moving through the Chamber of Deputies in March 2026. Until it passes, the coordinator has no power to act. Unknown date. A legislative answer to the Supreme Court's data retention ruling. A draft amendment to Decree No. 357/2012 Sb. was in the government's consultation system. Nothing is repealed yet. POWERS THAT CAN BE USED WITHOUT A NEW LAW. These matter more than the bills. First, under the Cybersecurity Act the government can issue a warning about a named supplier of security-critical components for strategically significant services. It can also ban that supplier. This needs no new law and could remove a vendor from your systems overnight. Second, the national cyber agency controls the exemption list for the government cloud catalogue. It could stop publishing an exemption for a named service, which would force public sector customers off it. Third, the cyber agency issues its own decrees setting security measures. So the technical bar can rise without parliament.
Sources
- Official sourcee-Sbírka, Ministry of the InteriorAct No. 60/2026 Sb. on data management and controlled access to data
e-sbirka.gov.cz
Link checked 18 August 2026
- Official sourcePortál otevřených dat České republikyPresident signs the key law for the digital state, 28 April 2026
data.gov.cz
Link checked 18 August 2026
- Official sourceČeský telekomunikační úřadMonitoring report 09/2025 — the Data Act starts to apply; the Office expects to be named data coordinator under a forthcoming adaptation law
ctu.gov.cz
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostAct No. 264/2025 Sb. — government power to warn about or ban a supplier for strategically significant services
portal.nukib.gov.cz
Link checked 18 August 2026
What to do: Diarise 12 January 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: Vyhláška č. 316/2021 Sb., o některých požadavcích pro zápis do katalogu cloud computingu · Decree No. 316/2021 Sb., Annex 2 rows 1.3 and 1.4, made under Act No. 365/2000 Sb. · Government rules
You may want to sell cloud to Czech public bodies at the top security grade. Then you must keep stored customer data inside the European Union or the European Free Trade Association area. The national cyber agency publishes a list of services that fail this test but stay in the catalogue under an exemption. So there is a published way through.
Enforced by National Cyber and Information Security Agency
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryAt the 'high' security level, stored customer data and certain operational data must sit only in European Union or European Free Trade Association countries. The line is Europe, not the Czech border.
- Register or notifyA provider must be entered in the state cloud computing catalogue before a public body may buy the service.
- Hold a security certificate
- Prove the data stays under local control
What it costs if you get it wrong
- Order to stopRemoval from, or refusal of entry in, the cloud computing catalogue, which shuts off Czech public-sector sales
Sources
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostCloud computing — exemptions from the data storage requirement (official notice board)
nukib.gov.cz
“data zákazníka a specifická provozní data v neaktivním stavu jsou uložena výhradně na území členských států EU a ESVO”
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostThe agency publishes cloud computing exemptions from the data storage requirement
nukib.gov.cz
Link checked 18 August 2026
- Official sourceDigitální a informační agenturaCloud computing catalogue — registered providers and the Act No. 365/2000 Sb. requirements
dia.gov.cz
“Zapsaní poskytovatelé splnili veškeré požadavky zákona č. 365/2000 Sb. pro zápis do katalogu cloud computingu”
Link checked 18 August 2026
Online gaming data must stay in the country
Official name: Zákon č. 186/2016 Sb., o hazardních hrách · Act No. 186/2016 Sb., sections 42(5) and 74(2) · Act of parliament
Czechia's strictest storage rule. The server running an online or technical gambling game must sit physically inside a European Union country. Player identity records must be kept for ten years. Operators must also feed financial and gaming data to the state's system.
Enforced by Ministry of Finance
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThe server for an internet game, and the server for a technical game, must be on the territory of a European Union member state. Hosting the game system in the United States or Asia is not an option.
- Keep data for a minimum period — 10 yearsPlayer registration and identity data, and gaming token transaction records.
- Keep data for a minimum period — 2 yearsBetting records.
- Keep data for a minimum period — 1 yearRecordings relating to live betting.
- Register or notifyLicence from the Ministry of Finance; supervision by the Customs Administration.
- Independent audit
What it costs if you get it wrong
- Loss of your licenceOperating outside the licence conditions
Sources
- Official sourceCzech Collection of Laws, notified textAct No. 186/2016 Sb. on gambling — official Czech text, sections 42(5), 74(2) and retention provisions
eur-lex.europa.eu
“Server internetové hry a zařízení využívané k provozování číselné loterie ... se musí nacházet na území členského státu Evropské unie”
Link checked 18 August 2026
- Official sourceCelní správa České republikyGambling legislation, including Decree No. 208/2017 Sb. on protection and retention of gaming and financial data
celnisprava.gov.cz
Link checked 18 August 2026
Telecoms rules
Official name: Vyhláška č. 357/2012 Sb., o uchovávání, předávání a likvidaci provozních a lokalizačních údajů · Decree No. 357/2012 Sb., made under the Electronic Communications Act; upheld in Pl. ÚS 45/17; criticised in 30 Cdo 2556/2025 · Government rules
Czech telecoms operators must keep six months of records showing who contacted whom, when and from where. The Constitutional Court upheld this in 2019. On 8 January 2026 the Supreme Court held that blanket retention conflicts with European Union law. It made the state liable. But it cannot repeal the rule. Operators must still comply.
Enforced by Czech Telecommunication Office
How this country controls where data goes: Only approved countries · Accepted routes: Standard contract clauses, Official 'this country is safe' decision
What you have to do
- Keep data for a minimum period — 6 monthsTraffic and location data about who communicated with whom, when and from where. Content is not covered.
- Delete data after a period — 6 monthsThe data must be destroyed once the six-month period ends, unless another law requires otherwise.
What it costs if you get it wrong
- Fixed maximum fineFailure to retain or to hand over on a lawful request
- Claims by individualsState liability. The Supreme Court ordered the state to apologise to a journalist whose data was retained under this regime.
Sources
- Official sourceÚstavní soud České republikyConstitutional Court, Pl. ÚS 45/17, 22 May 2019 — six-month retention held constitutional
usoud.cz
Link checked 18 August 2026
- Official sourceNejvyšší soud České republikySupreme Court judgment 30 Cdo 2556/2025, notice board 8 January 2026 — blanket retention contrary to European Union law
nsoud.cz
Link checked 18 August 2026
- Official sourceMinisterstvo průmyslu a obchoduDecree No. 357/2012 Sb. — retention, transfer and destruction of traffic and location data
mpo.gov.cz
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Zákon č. 412/2005 Sb., o ochraně utajovaných informací a o bezpečnostní způsobilosti · Act No. 412/2005 Sb., section 34, with Decree No. 479/2024 Sb. on information security · Act of parliament
Any system that handles Czech classified information must be certified by the national cyber agency before it is switched on. We could confirm no stated ban on foreign locations. But the certification step is what stops ordinary foreign cloud being used for this material.
Enforced by National Cyber and Information Security Agency
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Hold a security certificateAn information system handling classified information must be certified by the national cyber agency. A responsible person must also approve it in writing before it is used. The approval must be reported to the agency within 30 days.
- Secure the dataFor the higher classification levels, protection against compromising electromagnetic emissions is also required.
What it costs if you get it wrong
- Order to stopOperating an uncertified system for classified information
- Criminal liabilityUnauthorised handling of classified information
Sources
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostSecurity of information and communication systems — certification requirement under section 34
nukib.gov.cz
Link checked 18 August 2026
- Official sourceNárodní bezpečnostní úřadAct No. 412/2005 Sb. on the protection of classified information
nbu.gov.cz
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Zákon č. 110/2019 Sb., o zpracování osobních údajů · Act No. 110/2019 Sb., consolidated text in force from 1 August 2025 · Act of parliament
The Czech add-on to Europe's privacy rules. It adds no requirement about where data must be stored. It adds no national approval step for sending data abroad. Two things are Czech-specific. The age of a child's consent is fifteen. And the regulator cannot fine public authorities.
Enforced by Office for Personal Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Get a parent's consent for children — applies at: under 15Czechia sets the age of a child's own consent for online services at fifteen, not the European default of sixteen.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Put a transfer safeguard in place
- Appoint a data protection officerRequired for public authorities. Also required for large-scale monitoring, or for using special categories of data.
- Keep records of how you use data
- Assess high-risk projects
- Appoint a representativeIf you are based outside Europe and the European Regulation catches you, appoint a representative in Europe.
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Fixed maximum fine: €20,000,000 — about $22 millionSame tier, whichever is higher
- Criminal liability: Imprisonment under section 180 of the Criminal CodeUnauthorised handling of personal data
Sources
- Official sourcee-Sbírka, Ministry of the InteriorAct No. 110/2019 Sb., consolidated text in force from 1 August 2025
e-sbirka.gov.cz
Link checked 18 August 2026
- Official sourceCzech Collection of Laws, notified textAct No. 110/2019 Sb. — official Czech text as notified, sections 7, 17 and 62
eur-lex.europa.eu
“Dítě nabývá způsobilosti k udělení souhlasu se zpracováním osobních údajů v souvislosti s nabídkou služeb informační společnosti přímo jemu dovršením patnáctého roku věku.”
Link checked 18 August 2026
- Official sourceÚřad pro ochranu osobních údajůRegulator's own statement that it cannot fine a public authority
uoou.gov.cz
Link checked 18 August 2026
Government data rules
Official name: Zákon č. 264/2025 Sb., o kybernetické bezpečnosti · Act No. 264/2025 Sb., with Decree No. 408/2025 Sb. on regulated services · Act of parliament
Czechia's version of Europe's second network and information security directive. It says nothing about where data must sit. But it gives the government a live power to ban a named supplier from strategically significant services. Registration was due by the end of 2025. By early February 2026, 4,825 organisations had complied.
Enforced by National Cyber and Information Security Agency
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notify — from 1 November 2025Identify yourself and report the regulated service on the agency's portal within 60 days. Organisations already covered on 1 November 2025 had until 31 December 2025.
- Report cyber incidents — within 24 hoursHigher tier.
- Report cyber incidents — within 72 hoursLower tier, detailed information. Final report within 30 days.
- Secure the data
- Written vendor contractFor strategically significant services, you must report suppliers of security-critical components. The government may then issue a warning or a ban.
- Keep logs
What it costs if you get it wrong
- Fixed maximum fine: CZK 250,000,000 — about $12 millionHigher regime, most serious breaches
- Percentage of global turnover: 2% of worldwide annual net turnoverHigher regime, whichever is higher
- Fixed maximum fine: CZK 175,000,000 — about $8 millionLower regime, or 1.4% of worldwide annual net turnover
Sources
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostAct No. 264/2025 Sb. on cybersecurity — official presentation, effective dates, regimes, deadlines and penalties
portal.nukib.gov.cz
“nabyde účinnosti 1. listopadu 2025”
Link checked 18 August 2026
- Official sourceNárodní úřad pro kybernetickou a informační bezpečnostMore than 4,800 organisations registered; 4,825 by 8 February 2026
nukib.gov.cz
Link checked 18 August 2026
- Official sourcee-Sbírka, Ministry of the InteriorDecree No. 408/2025 Sb. on regulated services
e-sbirka.gov.cz
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact prison terms in section 180 of the Czech Criminal Code for unauthorised handling of personal data
We could not confirm the prison sentences for this offence. The police page carrying the text blocks automated access. We found no other official copy. The crime itself is well established. If this matters to you, check the Criminal Code text.
Retention floors for accounting, tax and payroll records, and whether the new Accounting Act changes them
We could not confirm the accounting and tax record-keeping periods, or the start date of the rewritten law. The Ministry of Finance page we opened confirms a complete rewrite affecting around 150 laws, with a long lead-in. The date most often cited is 1 January 2027. The page does not state keeping periods. Treat any specific number you have seen elsewhere as unconfirmed.
Whether the Czech digital economy bill, which would give the Czech Telecommunication Office inspection and sanction powers under the European platform rules, has passed since March 2026
We could not confirm how far this bill has got. The Chamber of Deputies bill pages returned 'document not found' for us. Our latest official evidence is the Office's own 2025 annual report, which says no adaptation law had been adopted. Press reports say there was a second reading in March 2026. The status as at 18 August 2026 is unconfirmed.
Whether any health-sector keeping data in the country rule exists in Czechia
We found no rule requiring health data to stay in Czechia, checked 18 August 2026. We reviewed the electronic healthcare rules and the national health information system materials. We found keeping periods and interoperability rules, but nothing about location. This is medium confidence, not proof that no rule exists. If you handle patient data, check with the health ministry.
Whether Decree No. 316/2021 Sb. and the cloud catalogue criteria were amended or replaced when the new Cybersecurity Act took effect on 1 November 2025
We could not confirm the current decree number for this rule. The national cyber agency's live notice board still applies the Annex 2 rows 1.3 and 1.4 storage test. It still publishes exemptions against it, so the rule is in force. We did not confirm whether the decree number itself has changed.
Whether the Czech government has actually used its power under the Cybersecurity Act to warn about or ban a named supplier
We could not confirm that this power has ever been used. It is documented in the agency's own material. We found no published use of it. We could not check the agency's full notice board history.
The precise scope of the gambling server rule, in particular whether backups and analytics copies may sit outside the European Union
We could not confirm how the rule treats backup copies. The statute requires the server to be on European Union territory. The text we read does not mention secondary copies. Implementing Decree No. 208/2017 Sb. governs protection and keeping of gaming and financial data. We did not open its full current text. If you run gambling servers, check before you place backups outside the European Union.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.