Skip to content

Evidence request lists

Czech Republic Act on the Protection of Personal Data (Act No. 110/2019 Coll.)

Evidence request list. 21 controls, 21 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CZ 110/2019: HLAVA I - Predmet a Pusobnost

CZ-110-§1
Predmet upravy (subject matter)

The Act adapts and complements the GDPR in Czech law and transposes the Law Enforcement Directive (EU) 2016/680; it governs the processing of personal data and the position of the Office for Personal Data Protection.

Artefacts an auditor will ask for
  • Determination that processing is subject to GDPR as complemented by Act 110/2019
  • Mapping of which Title (GDPR / LED / national security) applies
Where this commonly fails
  • Treating GDPR alone without the national adaptations
  • Ignoring the LED-transposing provisions where applicable
CZ-110-§2-3
Pusobnost zakona a subjekt udaju (scope and data subject)

Sets the scope of the Act and defines the data subject and the bodies to which the Act applies, including how it interacts with directly applicable GDPR.

Artefacts an auditor will ask for
  • Scoping analysis of covered processing and bodies
Where this commonly fails
  • Misjudging scope between GDPR-governed and LED-governed processing

CZ 110/2019: HLAVA II - Zpracovani podle GDPR

CZ-110-§11
Omezeni nekterych prav a povinnosti (restriction of certain rights)

Provides for restrictions of certain data subject rights and controller obligations where necessary and proportionate for specified public-interest objectives, within the limits of GDPR Article 23.

Artefacts an auditor will ask for
  • Documented legal basis and proportionality assessment for each restriction relied on
  • Register of restrictions applied
Where this commonly fails
  • Over-broad restriction of rights without a proportionality assessment
CZ-110-§14
Jmenovani poverence pro ochranu osobnich udaju (DPO designation)

Sets national specifics on the designation of a data protection officer (poverenec), complementing the GDPR DPO requirements.

Artefacts an auditor will ask for
  • DPO designation records and contact details notified to the Office where required
Where this commonly fails
  • No DPO where the Act/GDPR requires one
CZ-110-§16
Zpracovani pro vedecky, historicky nebo statisticky ucel (research and archiving)

Sets safeguards for processing for scientific, historical research, statistical and archiving purposes in the public interest, with appropriate technical and organisational measures.

Artefacts an auditor will ask for
  • Safeguards (minimisation, pseudonymisation) for research/archiving processing
  • Documentation of the public-interest purpose
Where this commonly fails
  • Research processing without the required safeguards
CZ-110-§17
Zakonnost zpracovani pro novinarske, akademicke a umelecke ucely (freedom of expression)

Reconciles personal data protection with freedom of expression and information, setting the lawfulness of, and exemptions for, processing for journalistic, academic, artistic and literary purposes, including protection of the source and content of information.

Artefacts an auditor will ask for
  • Documented reliance on the journalistic/academic/artistic regime and its limits
  • Source-protection measures
Where this commonly fails
  • Claiming the expression exemption beyond journalistic/academic/artistic purposes
CZ-110-§5
Opravneni ke zpracovani pri plneni pravni povinnosti nebo ukolu (public-task lawful basis)

Authorises controllers to process personal data where necessary to comply with a legal obligation or to perform a task carried out in the public interest or in the exercise of official authority, complementing GDPR Article 6.

Artefacts an auditor will ask for
  • Record of the legal obligation or public-task basis relied on per processing
  • Necessity assessment for the public-interest basis
Where this commonly fails
  • Relying on public-task basis without an identified legal duty
  • No necessity assessment
CZ-110-§7
Zpusobilost ditete pro souhlas (child's capacity to consent - age 15)

Sets the age at which a child can validly consent to the processing of personal data in relation to information society services at 15 years; below that age consent must be given or authorised by the holder of parental responsibility.

Artefacts an auditor will ask for
  • Age-verification and parental-consent mechanism using the 15-year threshold
  • Records of consent for under-15 users
Where this commonly fails
  • Applying the GDPR default of 16 instead of the Czech 15
  • No parental consent path for under-15 users
CZ-110-§8
Informacni povinnost (information duty adaptations)

Adapts the controller's information obligations for processing carried out under a legal duty or public task, specifying how and when information must be provided to data subjects.

Artefacts an auditor will ask for
  • Information notices aligned to the Act's adaptations for public-task processing
Where this commonly fails
  • Generic GDPR notice not reflecting the national adaptations

CZ 110/2019: HLAVA III - Zpracovani pro ucely trestniho rizeni (LED)

CZ-110-§24-25
Obecna ustanoveni a zasady pro trestni rizeni (LED general principles)

Transposes the Law Enforcement Directive: general provisions and processing principles for competent authorities processing personal data for the prevention, investigation, detection or prosecution of criminal offences.

Artefacts an auditor will ask for
  • Identification of competent-authority processing within the LED regime
  • Application of the LED principles to such processing
Where this commonly fails
  • Applying GDPR rules to law-enforcement processing that is governed by the LED Title
CZ-110-§28-29
Prava subjektu udaju v trestnim rizeni (access, rectification, erasure under LED)

Sets the data subject's rights of access, rectification, erasure and restriction in the law-enforcement context, with the permitted limitations.

Artefacts an auditor will ask for
  • Procedure for handling access/rectification/erasure requests in LED processing
  • Records of any limitations applied and their basis
Where this commonly fails
  • No request-handling procedure for LED processing
  • Unjustified blanket limitations
CZ-110-§32
Zamerna a standardni ochrana osobnich udaju (data protection by design and default)

Requires the controlling authority to implement data protection by design and by default and to meet general obligations for law-enforcement processing.

Artefacts an auditor will ask for
  • Data-protection-by-design and default measures for LED processing systems
Where this commonly fails
  • No by-design/by-default controls in law-enforcement systems
CZ-110-§37-38
Posouzeni vlivu a projednani s Uradem (DPIA and prior consultation)

Requires a data protection impact assessment for high-risk law-enforcement processing and prior consultation with the Office (Urad) where required.

Artefacts an auditor will ask for
  • DPIA records for high-risk LED processing
  • Evidence of prior consultation with the Office where required
Where this commonly fails
  • No DPIA for high-risk LED processing
CZ-110-§40
Zabezpeceni zpracovani (security of processing)

Requires appropriate technical and organisational measures to secure personal data processed for law-enforcement purposes, considering the risks of the processing.

Artefacts an auditor will ask for
  • Documented technical and organisational security measures for LED processing
  • Risk-based justification of the measures
Where this commonly fails
  • Security measures not adjusted to law-enforcement data sensitivity
CZ-110-§41-42
Ohlasovani a oznamovani poruseni zabezpeceni (breach notification to Office and data subject)

Requires notification of personal data breaches in law-enforcement processing to the Office (Urad) and, where applicable, communication to the affected data subject.

Artefacts an auditor will ask for
  • Breach notification procedure covering notification to the Urad and to data subjects
  • Breach register
Where this commonly fails
  • No breach notification path for LED processing

CZ 110/2019: HLAVA IV - Narodni bezpecnost

CZ-110-§50
Zpracovani zajistujici obranu a bezpecnost statu (national security and defence processing)

Sets specific rules for processing of personal data carried out to ensure the defence and security of the State, including by intelligence services, with tailored safeguards and oversight.

Artefacts an auditor will ask for
  • Identification of any processing falling under the national-security Title and its specific regime
Where this commonly fails
  • Applying the wrong Title to national-security processing

CZ 110/2019: HLAVA V - Urad (UOOU)

CZ-110-§54
Cinnosti Uradu (functions of the Office for Personal Data Protection)

Sets out the functions of the Office for Personal Data Protection (Urad pro ochranu osobnich udaju), the independent supervisory authority for the Czech Republic.

Artefacts an auditor will ask for
  • Awareness of the Urad as supervisory authority and points of cooperation
  • Records of interaction with the Urad
Where this commonly fails
  • No designated contact for the supervisory authority
CZ-110-§56
Mezinarodni spoluprace (international cooperation)

Provides for the Office's cooperation with supervisory authorities of other Member States and the European Data Protection Board, including the consistency mechanism.

Artefacts an auditor will ask for
  • Awareness of cross-border cooperation and lead-authority arrangements where applicable
Where this commonly fails
  • Ignoring lead-authority/one-stop-shop arrangements for cross-border processing
CZ-110-§57-58
Vyrocni zprava a opravneni Uradu na pristup (annual report and inspection powers)

Provides for the Office's annual report and its powers to access information and premises for the purpose of supervision and inspection.

Artefacts an auditor will ask for
  • Readiness to cooperate with Office inspections and information requests
  • Records produced to the Office during supervision
Where this commonly fails
  • Failure to cooperate with an Office inspection

CZ 110/2019: HLAVA VI + Cast Druha - Prestupky a Zaverecna

CZ-110-§62-64
Prestupky (administrative offences and penalties)

Defines administrative offences under the Act and provides that the Office adjudicates them, including the special rule on shelving a matter; complements the GDPR administrative-fine regime.

Artefacts an auditor will ask for
  • Risk assessment of administrative-offence exposure under the Act and GDPR
  • Compliance evidence available for an Office proceeding
Where this commonly fails
  • Underestimating offence exposure
  • No readiness for an Office proceeding
CZ-110-§66-67
Prechodna a zrusovaci ustanoveni (transitional and repeal)

Sets transitional provisions, repeals the prior Act No. 101/2000 Coll., and sets the Act's effect, governing the move from the previous data protection regime to the GDPR-aligned one.

Artefacts an auditor will ask for
  • Evidence that processing migrated from the repealed Act 101/2000 regime to the Act 110/2019 / GDPR regime
Where this commonly fails
  • Continuing to rely on the repealed Act 101/2000
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.