Skip to the content
Global Data RulesData governance rules, country by country

Czechia

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Czechia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

Czechia follows the European rulebook. Ordinary data can leave the country, and leave Europe, if you use an approved European transfer route. Two industries differ. Online gambling servers must sit inside the European Union. Cloud sold to Czech government at the top security grade must keep data in Europe. The privacy regulator works well. But the law bans it from fining government bodies.

Data governance in Czechia

The eight things that decide how you handle data about people in Czechia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Europe's General Data Protection Regulation applies directly in Czechia. It reaches a company anywhere in the world that offers goods or services to people in Czechia. It also reaches you if you watch what they do online. There is no minimum size or revenue. If you are outside Europe and the rules catch you, you must appoint a written representative inside Europe.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, in general, with paperwork. Czechia adds no national storage rule on top of the European rules. So ordinary personal data can sit in a data centre outside Czechia and outside Europe, if you use an approved transfer route. Two industries break that pattern. They are online gambling and cloud sold to government at the top security grade. A third, telecoms, has a record-keeping duty that is being fought over in court.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Use one of the European routes. Send data to a country Europe has formally approved. Or sign the European standard contract clauses. Or set up binding corporate rules for your group. Czechia adds no national approval step. It keeps no national list of banned countries. Before you send data to a country Europe has not approved, check whether that country's surveillance laws would undermine your safeguards.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

Yes, the regulators here really work. The Office for Personal Data Protection has a president, Jiří Kaucký. The country's President reappointed him for a second term on 26 August 2025. In 2025 it received 3,854 complaints and notifications. It opened 27 inspections and imposed 7 fines. Those totalled about 14.7 million Czech koruna, roughly 700,000 US dollars. It publishes an inspection plan for the year ahead. The cyber agency is busier still. But Czech law forbids the privacy office from fining any government body.

How long you must keep it — and when to delete it

There are rules in both directions, and they collide. The maximum comes from the European rule. Delete personal data once the purpose is finished. The minimums come from industry laws. Telecoms firms must keep records of who contacted whom for six months. Gambling operators must keep customer identification records for ten years and betting records for two. Accounting and tax records run for years, and those rules are being rewritten. Where a minimum and a maximum clash, the minimum wins. Keeping data to obey a law is itself a lawful reason to keep it.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

Three deadlines apply. A personal data breach goes to the privacy office within 72 hours. You must also tell affected people without undue delay if the risk to them is high. A cyber incident at an organisation registered under the Cybersecurity Act goes to the cyber agency. That is within 24 hours if you are in the higher tier, or 72 hours in the lower tier. A final report follows inside 30 days. Financial firms have a separate European deadline of their own. Many companies are caught by two of these at once.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. (1) A Czech child can consent to online services at 15, not 16. (2) Mishandling personal data can be a crime, not just a fine. (3) The privacy office cannot fine a government body at all. So if a public authority leaks your data, there is no fine to point at. (4) Telecoms firms must keep six months of contact records. Czechia's own Supreme Court said in January 2026 that this breaks European law, yet the duty still stands. (5) The Czech platform regulator exists but cannot inspect or fine anybody yet.

What you have to do here:
Get a parent's consent for children · Extra vendor secrecy terms
What it costs if you get it wrong:
Criminal liability

What's changing next

Four things to watch in the next twelve months. Telecoms record-keeping is legally unstable after the Supreme Court's January 2026 ruling, and something has to give. The Czech bill that would give the platform regulator real powers is still in parliament. A new law on state data sharing was signed on 28 April 2026, but its duties only start in 2028 and 2029. And across Europe, cloud switching charges must fall to zero by 12 January 2027.

What you have to do here:
Make switching cloud provider possible

What to do: Diarise 12 January 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Vyhláška č. 316/2021 Sb., o některých požadavcích pro zápis do katalogu cloud computingu · Decree No. 316/2021 Sb., Annex 2 rows 1.3 and 1.4, made under Act No. 365/2000 Sb. · Government rules

In forceNo — it stays put

You may want to sell cloud to Czech public bodies at the top security grade. Then you must keep stored customer data inside the European Union or the European Free Trade Association area. The national cyber agency publishes a list of services that fail this test but stay in the catalogue under an exemption. So there is a published way through.

In force since 1 September 2021

Enforced by National Cyber and Information Security Agency

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Online gaming

Online gaming data must stay in the country

Official name: Zákon č. 186/2016 Sb., o hazardních hrách · Act No. 186/2016 Sb., sections 42(5) and 74(2) · Act of parliament

In forceNo — it stays put

Czechia's strictest storage rule. The server running an online or technical gambling game must sit physically inside a European Union country. Player identity records must be kept for ten years. Operators must also feed financial and gaming data to the state's system.

In force since 1 January 2017

Enforced by Ministry of Finance

How this country controls where data goes: Not allowed

Telecoms

Telecoms rules

Official name: Vyhláška č. 357/2012 Sb., o uchovávání, předávání a likvidaci provozních a lokalizačních údajů · Decree No. 357/2012 Sb., made under the Electronic Communications Act; upheld in Pl. ÚS 45/17; criticised in 30 Cdo 2556/2025 · Government rules

In forceYes, with paperwork

Czech telecoms operators must keep six months of records showing who contacted whom, when and from where. The Constitutional Court upheld this in 2019. On 8 January 2026 the Supreme Court held that blanket retention conflicts with European Union law. It made the state liable. But it cannot repeal the rule. Operators must still comply.

In force since 1 November 2012

Enforced by Czech Telecommunication Office

How this country controls where data goes: Only approved countries · Accepted routes: Standard contract clauses, Official 'this country is safe' decision

Not fully verified — see “What we're not sure about” below.

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Zákon č. 110/2019 Sb., o zpracování osobních údajů · Act No. 110/2019 Sb., consolidated text in force from 1 August 2025 · Act of parliament

In forceYes, with paperwork

The Czech add-on to Europe's privacy rules. It adds no requirement about where data must be stored. It adds no national approval step for sending data abroad. Two things are Czech-specific. The age of a child's consent is fifteen. And the regulator cannot fine public authorities.

In force since 24 April 2019

Enforced by Office for Personal Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract, Legal claims

Government data rules

Official name: Zákon č. 264/2025 Sb., o kybernetické bezpečnosti · Act No. 264/2025 Sb., with Decree No. 408/2025 Sb. on regulated services · Act of parliament

In forceYes — store it anywhere

Czechia's version of Europe's second network and information security directive. It says nothing about where data must sit. But it gives the government a live power to ban a named supplier from strategically significant services. Registration was due by the end of 2025. By early February 2026, 4,825 organisations had complied.

In force since 1 November 2025Enforced from 31 December 2025

Enforced by National Cyber and Information Security Agency

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Úřad pro ochranu osobních údajů

    General privacy law, including police and national security processing

    Fully staffed. President Jiří Kaucký was reappointed for a second five-year term by the President of the Republic on 26 August 2025. In 2025 it received 3,854 complaints and notifications. It opened 27 inspections and imposed 7 fines totalling CZK 14,671,000. It published an inspection plan for 2026. Section 62(5) of Act No. 110/2019 Sb. bars it from fining public authorities and public bodies.

  • Národní úřad pro kybernetickou a informační bezpečnost

    Cybersecurity, government cloud catalogue security criteria, classified information systems

    Highly active. It ran the registration process under the new Cybersecurity Act from 1 November 2025. It had 4,825 registered organisations by 8 February 2026. It issues its own decrees. It keeps the public cloud storage exemption list.

  • Český telekomunikační úřad

    Electronic communications, Digital Services Coordinator, expected data coordinator under the Data Act

    Operational as a telecoms regulator, but dormant as a platform regulator. Its own 2025 annual report says the national adaptation law was missing. Without it, the office could not certify dispute bodies, trusted flaggers or vetted researchers. It could not run inspections or impose penalties. It handled 98 complaints in 2025 anyway.

  • Česká národní banka

    Banking, insurance, securities, payments; competent authority for the European financial resilience rules

    Active. It publishes official opinions on banking secrecy and outsourcing, which banks follow as binding. It also publishes reporting requirements under the financial resilience rules that apply from 17 January 2025.

  • Digitální a informační agentura

    Public administration information systems, cloud computing catalogue, national data catalogue

  • Ministerstvo financí

    Gambling licensing and gambling technical rules; accounting legislation

  • Celní správa České republiky

    State supervision of gambling operations

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact prison terms in section 180 of the Czech Criminal Code for unauthorised handling of personal data

    We could not confirm the prison sentences for this offence. The police page carrying the text blocks automated access. We found no other official copy. The crime itself is well established. If this matters to you, check the Criminal Code text.

  • Retention floors for accounting, tax and payroll records, and whether the new Accounting Act changes them

    We could not confirm the accounting and tax record-keeping periods, or the start date of the rewritten law. The Ministry of Finance page we opened confirms a complete rewrite affecting around 150 laws, with a long lead-in. The date most often cited is 1 January 2027. The page does not state keeping periods. Treat any specific number you have seen elsewhere as unconfirmed.

  • Whether the Czech digital economy bill, which would give the Czech Telecommunication Office inspection and sanction powers under the European platform rules, has passed since March 2026

    We could not confirm how far this bill has got. The Chamber of Deputies bill pages returned 'document not found' for us. Our latest official evidence is the Office's own 2025 annual report, which says no adaptation law had been adopted. Press reports say there was a second reading in March 2026. The status as at 18 August 2026 is unconfirmed.

  • Whether any health-sector keeping data in the country rule exists in Czechia

    We found no rule requiring health data to stay in Czechia, checked 18 August 2026. We reviewed the electronic healthcare rules and the national health information system materials. We found keeping periods and interoperability rules, but nothing about location. This is medium confidence, not proof that no rule exists. If you handle patient data, check with the health ministry.

  • Whether Decree No. 316/2021 Sb. and the cloud catalogue criteria were amended or replaced when the new Cybersecurity Act took effect on 1 November 2025

    We could not confirm the current decree number for this rule. The national cyber agency's live notice board still applies the Annex 2 rows 1.3 and 1.4 storage test. It still publishes exemptions against it, so the rule is in force. We did not confirm whether the decree number itself has changed.

  • Whether the Czech government has actually used its power under the Cybersecurity Act to warn about or ban a named supplier

    We could not confirm that this power has ever been used. It is documented in the agency's own material. We found no published use of it. We could not check the agency's full notice board history.

  • The precise scope of the gambling server rule, in particular whether backups and analytics copies may sit outside the European Union

    We could not confirm how the rule treats backup copies. The statute requires the server to be on European Union territory. The text we read does not mention secondary copies. Implementing Decree No. 208/2017 Sb. governs protection and keeping of gaming and financial data. We did not open its full current text. If you run gambling servers, check before you place backups outside the European Union.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.