Dashboard / Global Laws / CZ-DPA-110-2019

🇨🇿Act No. 110/2019 Coll. on Personal Data Processing

← Back to laws in Czechia

Act No. 110/2019 Coll. on Personal Data Processing

Act No. 110/2019 Coll. on Personal Data Processing

Czechia applies this national law alongside the GDPR. The summary below concentrates on the national overlay so that the GDPR baseline is not duplicated.

Current official version

Status: Current official e-Sbírka text effective 1 August 2025

Citation: Act No. 110/2019 Coll., especially ss. 7-17, 39a-39c and 62

Regulator: Office for Personal Data Protection (ÚOOÚ)

Source basis: Official current e-Sbírka text effective 1 August 2025 archived and cross-checked on 22 August 2026; the ÚOOÚ English PDF was a translation aid only.

How the national law fits with GDPR

The Act supplements the GDPR, extends selected protections to additional processing, implements the Law Enforcement Directive and regulates the Czech supervisory authority.

National additions and variations

  • Section 7 sets 15 as the age at which a child may consent to a directly offered information-society service.
  • Sections 11 and 12 permit only necessary and proportionate postponement or limitation of specified rights and breach communications for protected interests and require prompt notification to ÚOOÚ.
  • Section 14 extends the public-sector DPO duty to statutory bodies performing legally assigned public-interest tasks.
  • Section 16 specifies research and statistics safeguards, including operation logs retained for at least two years, access restrictions, pseudonymisation, encryption and testing.
  • Sections 39a-39c, inserted with effect from 1 August 2025, tightly regulate real-time remote biometric identification in isolated international-airport systems, including judicial authorisation, DPO oversight, access logging and deletion rules.
Implementation boundary

The official English translation is the 24 April 2019 version and does not include the 2025 biometric-system amendments. The current Czech e-Sbírka text controls.

Operational approach

First maintain the GDPR control set. Then document whether this country is in scope and apply the national controls to the affected people, systems and processing. Keep article-level evidence for child consent, employment, special-category or criminal data, research, electronic communications, identifiers, surveillance and any rights restriction relied upon.

What this means for you

Do not treat GDPR compliance as automatic compliance with Act 110/2019. Record the national trigger, the responsible owner, the local procedure and the current official source reviewed.