Skip to the content
Global Data RulesData governance rules, country by country

Czechia

Part of the European Union, so bloc-wide rules apply here too. Checked yesterday.

The answer

Depends on your industryWork: HighEnforcement: Active

Czechia follows the European rulebook. Ordinary data can leave the country, and leave Europe, if you use an approved European transfer route. Two industries differ: online gambling servers must sit inside the European Union, and cloud sold to Czech government at the top security grade must keep data in Europe. The privacy regulator works well, but is banned by law from fining government bodies.

Data governance in Czechia

The eight things that decide how you handle data about people in Czechia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Europe's General Data Protection Regulation applies directly in Czechia, and it reaches a company anywhere in the world that offers goods or services to people in Czechia or watches what they do online. There is no minimum size or revenue. If you are outside Europe and caught by the rules, you must appoint a written representative inside Europe.

High confidenceBloc rulesNational rulesAppoint a local representative

Where the data is allowed to live

In general yes, with paperwork. Czechia adds no national storage rule on top of the European regime, so ordinary personal data can sit in a data centre outside Czechia and outside Europe if you use an approved transfer route. Two sectors break that pattern: online gambling and cloud sold to government at the top security grade. A third, telecoms, has a records-keeping duty that is legally contested.

High confidenceDepends on your industryOnline gamingGovernmentTelecomsDefenceAllowlist

Sending data out of the country

Use one of the European routes. Send data to a country Europe has formally approved, or sign the European standard contract clauses, or set up binding corporate rules for your group. Czechia adds no national approval step and keeps no national list of banned countries. Before you send data somewhere without an approval decision, you are expected to check whether the destination's surveillance laws would undermine your safeguards.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentPut a transfer safeguard in place

The regulator, and whether it actually acts

Yes, the regulators here really work. The Office for Personal Data Protection has a president, Jiří Kaucký, reappointed for a second term by the country's President on 26 August 2025. In 2025 it received 3,854 complaints and notifications, opened 27 inspections and imposed 7 fines totalling about 14.7 million Czech koruna, roughly 700,000 US dollars. It publishes an inspection plan for the year ahead. The cyber agency is busier still. But the privacy office is forbidden by Czech law from fining any government body.

High confidenceActiveDormant

How long you must keep it — and when to delete it

Both directions apply, and they collide. The ceiling comes from the European rule: delete personal data once the purpose is finished. The floors come from sector laws. Telecoms firms must keep records of who contacted whom for six months. Gambling operators must keep customer identification records for ten years and betting records for two. Accounting and tax records run for years and are being rewritten. Where a floor and the ceiling conflict, the floor wins, because keeping data to obey a law is itself a lawful reason to keep it.

Medium confidenceKeep data for a minimum periodDelete data after a periodKeep logs

If something goes wrong

Count three clocks. A personal data breach goes to the privacy office within 72 hours, and to affected people without undue delay if the risk to them is high. A cyber incident at an organisation registered under the Cybersecurity Act goes to the cyber agency within 24 hours if you are in the higher tier, or 72 hours in the lower tier, with a final report inside 30 days. Financial firms have a separate European clock of their own. Many companies are caught by two of these at once.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that cost people their weekend. (1) A Czech child can consent to online services at 15, not 16. (2) Mishandling personal data can be a crime, not just a fine. (3) The privacy office cannot fine a government body at all, so if a public authority leaks your data there is no fine to point at. (4) Telecoms firms must keep six months of contact records that Czechia's own Supreme Court said in January 2026 breaks European law, yet the duty still stands. (5) The Czech platform regulator exists but cannot inspect or fine anybody yet.

High confidenceGet a parent's consent for childrenCriminal liabilityExtra vendor secrecy termsKeep logs

What's changing next

Four things to watch in the next twelve months. Telecoms retention is legally unstable after the Supreme Court's January 2026 ruling and something has to give. The Czech bill that would give the platform regulator real powers is still in parliament. A new law on state data sharing was signed on 28 April 2026 but its obligations only start in 2028 and 2029. And across Europe, cloud switching charges must fall to zero by 12 January 2027.

Medium confidenceProposedPassed, not yet fully in forceMake switching cloud provider possible

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Vyhláška č. 316/2021 Sb., o některých požadavcích pro zápis do katalogu cloud computingu

Government rules · Decree No. 316/2021 Sb., Annex 2 rows 1.3 and 1.4, made under Act No. 365/2000 Sb.

In forceNo — it stays put

To sell cloud to Czech public bodies at the top security grade, a provider must keep customer data at rest inside the European Union or the European Free Trade Association area. The national cyber agency publishes a public list of services that fail this test but stay in the catalogue under an exemption, so it is a wall with a named, visible door.

In force since 1 September 2021

Enforced by National Cyber and Information Security Agency

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Online gaming

Zákon č. 186/2016 Sb., o hazardních hrách

Act of parliament · Act No. 186/2016 Sb., sections 42(5) and 74(2)

In forceNo — it stays put

Czechia's hardest storage wall. The server running an online or technical gambling game must physically sit inside a European Union country, and player identity records must be kept for ten years. Operators must also feed financial and gaming data to the state's system.

In force since 1 January 2017

Enforced by Ministry of Finance

Transfer model: Not allowed

High confidence
Telecoms

Vyhláška č. 357/2012 Sb., o uchovávání, předávání a likvidaci provozních a lokalizačních údajů

Government rules · Decree No. 357/2012 Sb., made under the Electronic Communications Act; upheld in Pl. ÚS 45/17; criticised in 30 Cdo 2556/2025

In forceYes, with paperwork

Czech telecoms operators must keep six months of records showing who contacted whom, when and from where. The Constitutional Court upheld this in 2019. On 8 January 2026 the Supreme Court held that blanket retention conflicts with European Union law and made the state liable, but it cannot repeal the rule, so operators must still comply.

In force since 1 November 2012

Enforced by Czech Telecommunication Office

Transfer model: Allowlist · Accepted routes: Standard contract clauses, Official 'this country is safe' decision

Medium confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Zákon č. 110/2019 Sb., o zpracování osobních údajů

Act of parliament · Act No. 110/2019 Sb., consolidated text in force from 1 August 2025

In forceYes, with paperwork

The Czech top-up to Europe's privacy rules. It adds no storage location requirement and no national approval step for sending data abroad. Its two Czech-specific edges are the age of a child's consent, set at fifteen, and a bar on fining public authorities.

In force since 24 April 2019

Enforced by Office for Personal Data Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract, Legal claims

High confidence

Zákon č. 264/2025 Sb., o kybernetické bezpečnosti

Act of parliament · Act No. 264/2025 Sb., with Decree No. 408/2025 Sb. on regulated services

In forceYes — store it anywhere

Czechia's implementation of Europe's second network and information security directive. It imposes no data location rule, but it does hand the government a live power to ban a named supplier from strategically significant services. Registration was due by the end of 2025 and 4,825 organisations had complied by early February 2026.

In force since 1 November 2025But only enforceable from 31 December 2025

Enforced by National Cyber and Information Security Agency

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • Úřad pro ochranu osobních údajů

    General privacy law, including police and national security processing

    Fully staffed. President Jiří Kaucký, reappointed for a second five-year term and appointed by the President of the Republic on 26 August 2025. In 2025 it received 3,854 complaints and notifications, opened 27 inspections and imposed 7 fines totalling CZK 14,671,000. It published an inspection plan for 2026. It is barred by section 62(5) of Act No. 110/2019 Sb. from fining public authorities and public bodies.

  • Národní úřad pro kybernetickou a informační bezpečnost

    Cybersecurity, government cloud catalogue security criteria, classified information systems

    Highly active. Ran the registration process under the new Cybersecurity Act from 1 November 2025 and had 4,825 registered entities by 8 February 2026. Issues its own decrees and maintains the public cloud storage exemption list.

  • Český telekomunikační úřad

    Electronic communications, Digital Services Coordinator, expected data coordinator under the Data Act

    Operational as a telecoms regulator, but dormant as a platform regulator. Its own 2025 annual report states that without the national adaptation law it could not certify dispute bodies, trusted flaggers or vetted researchers, and could not carry out inspections or impose sanctions. It handled 98 complaints in 2025 regardless.

  • Česká národní banka

    Banking, insurance, securities, payments; competent authority for the European financial resilience rules

    Active. Publishes binding-in-practice official opinions on banking secrecy and outsourcing, and reporting requirements under the financial resilience rules applying from 17 January 2025.

  • Digitální a informační agentura

    Public administration information systems, cloud computing catalogue, national data catalogue

  • Ministerstvo financí

    Gambling licensing and gambling technical rules; accounting legislation

  • Celní správa České republiky

    State supervision of gambling operations

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact prison terms in section 180 of the Czech Criminal Code for unauthorised handling of personal data

    The police page carrying the section text is blocked to automated fetching by its robots file, and we did not locate an alternative official copy during this run. The existence of the criminal offence is well established; the sentencing ranges are not verified here.

  • Retention floors for accounting, tax and payroll records, and whether the new Accounting Act changes them

    The Ministry of Finance page we opened confirms a complete recodification affecting around 150 laws and a long lead-in, with 1 January 2027 the date most often cited, but it does not state retention periods and we could not confirm the effective date from an official source. Treat any specific number you have seen elsewhere as unverified.

  • Whether the Czech digital economy bill, which would give the Czech Telecommunication Office inspection and sanction powers under the European platform rules, has passed since March 2026

    The Chamber of Deputies bill pages returned 'document not found' to our fetches. Our latest official evidence is the Office's own 2025 annual report saying no adaptation law had been adopted, plus press reporting of a second reading in March 2026. Status as at 18 August 2026 is unverified.

  • Whether any health-sector data localisation rule exists in Czechia

    No rule found, checked 18 August 2026. We reviewed the electronic healthcare framework and the national health information system materials and found retention and interoperability rules but no territorial storage requirement. This is a negative finding at medium confidence, not a proven absence.

  • Whether Decree No. 316/2021 Sb. and the cloud catalogue criteria were amended or replaced when the new Cybersecurity Act took effect on 1 November 2025

    The national cyber agency's live notice board still applies the Annex 2 rows 1.3 and 1.4 storage test and still publishes exemptions against it, so the rule is operative. We did not confirm whether the decree number itself has changed.

  • Whether the Czech government has actually used its power under the Cybersecurity Act to warn about or ban a named supplier

    The power is documented in the agency's own material. We found no published exercise of it, but we could not check the agency's full notice board history.

  • The precise scope of the gambling server rule, in particular whether backups and analytics copies may sit outside the European Union

    The statute requires the server to be on European Union territory. It does not, in the text we read, address secondary copies. Implementing Decree No. 208/2017 Sb. governs protection and retention of gaming and financial data and we did not open its full current text.

60-day cadence. Two things can move quickly. The telecoms retention regime is legally unstable after the January 2026 Supreme Court judgment and a repeal or amendment could land without a long consultation. The national cyber agency controls the government cloud exemption list and the supplier-ban power under the Cybersecurity Act, both of which can change the picture for a named vendor with no new legislation.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Czechia versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.