Czech Republic Act on the Protection of Personal Data (Act No. 110/2019 Coll.)
Evidence request list. 21 controls, 21 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
CZ 110/2019: HLAVA I - Predmet a Pusobnost
The Act adapts and complements the GDPR in Czech law and transposes the Law Enforcement Directive (EU) 2016/680; it governs the processing of personal data and the position of the Office for Personal Data Protection.
- Determination that processing is subject to GDPR as complemented by Act 110/2019
- Mapping of which Title (GDPR / LED / national security) applies
- Treating GDPR alone without the national adaptations
- Ignoring the LED-transposing provisions where applicable
Sets the scope of the Act and defines the data subject and the bodies to which the Act applies, including how it interacts with directly applicable GDPR.
- Scoping analysis of covered processing and bodies
- Misjudging scope between GDPR-governed and LED-governed processing
CZ 110/2019: HLAVA II - Zpracovani podle GDPR
Provides for restrictions of certain data subject rights and controller obligations where necessary and proportionate for specified public-interest objectives, within the limits of GDPR Article 23.
- Documented legal basis and proportionality assessment for each restriction relied on
- Register of restrictions applied
- Over-broad restriction of rights without a proportionality assessment
Sets national specifics on the designation of a data protection officer (poverenec), complementing the GDPR DPO requirements.
- DPO designation records and contact details notified to the Office where required
- No DPO where the Act/GDPR requires one
Sets safeguards for processing for scientific, historical research, statistical and archiving purposes in the public interest, with appropriate technical and organisational measures.
- Safeguards (minimisation, pseudonymisation) for research/archiving processing
- Documentation of the public-interest purpose
- Research processing without the required safeguards
Reconciles personal data protection with freedom of expression and information, setting the lawfulness of, and exemptions for, processing for journalistic, academic, artistic and literary purposes, including protection of the source and content of information.
- Documented reliance on the journalistic/academic/artistic regime and its limits
- Source-protection measures
- Claiming the expression exemption beyond journalistic/academic/artistic purposes
Authorises controllers to process personal data where necessary to comply with a legal obligation or to perform a task carried out in the public interest or in the exercise of official authority, complementing GDPR Article 6.
- Record of the legal obligation or public-task basis relied on per processing
- Necessity assessment for the public-interest basis
- Relying on public-task basis without an identified legal duty
- No necessity assessment
Sets the age at which a child can validly consent to the processing of personal data in relation to information society services at 15 years; below that age consent must be given or authorised by the holder of parental responsibility.
- Age-verification and parental-consent mechanism using the 15-year threshold
- Records of consent for under-15 users
- Applying the GDPR default of 16 instead of the Czech 15
- No parental consent path for under-15 users
Adapts the controller's information obligations for processing carried out under a legal duty or public task, specifying how and when information must be provided to data subjects.
- Information notices aligned to the Act's adaptations for public-task processing
- Generic GDPR notice not reflecting the national adaptations
CZ 110/2019: HLAVA III - Zpracovani pro ucely trestniho rizeni (LED)
Transposes the Law Enforcement Directive: general provisions and processing principles for competent authorities processing personal data for the prevention, investigation, detection or prosecution of criminal offences.
- Identification of competent-authority processing within the LED regime
- Application of the LED principles to such processing
- Applying GDPR rules to law-enforcement processing that is governed by the LED Title
Sets the data subject's rights of access, rectification, erasure and restriction in the law-enforcement context, with the permitted limitations.
- Procedure for handling access/rectification/erasure requests in LED processing
- Records of any limitations applied and their basis
- No request-handling procedure for LED processing
- Unjustified blanket limitations
Requires the controlling authority to implement data protection by design and by default and to meet general obligations for law-enforcement processing.
- Data-protection-by-design and default measures for LED processing systems
- No by-design/by-default controls in law-enforcement systems
Requires a data protection impact assessment for high-risk law-enforcement processing and prior consultation with the Office (Urad) where required.
- DPIA records for high-risk LED processing
- Evidence of prior consultation with the Office where required
- No DPIA for high-risk LED processing
Requires appropriate technical and organisational measures to secure personal data processed for law-enforcement purposes, considering the risks of the processing.
- Documented technical and organisational security measures for LED processing
- Risk-based justification of the measures
- Security measures not adjusted to law-enforcement data sensitivity
Requires notification of personal data breaches in law-enforcement processing to the Office (Urad) and, where applicable, communication to the affected data subject.
- Breach notification procedure covering notification to the Urad and to data subjects
- Breach register
- No breach notification path for LED processing
CZ 110/2019: HLAVA IV - Narodni bezpecnost
Sets specific rules for processing of personal data carried out to ensure the defence and security of the State, including by intelligence services, with tailored safeguards and oversight.
- Identification of any processing falling under the national-security Title and its specific regime
- Applying the wrong Title to national-security processing
CZ 110/2019: HLAVA V - Urad (UOOU)
Sets out the functions of the Office for Personal Data Protection (Urad pro ochranu osobnich udaju), the independent supervisory authority for the Czech Republic.
- Awareness of the Urad as supervisory authority and points of cooperation
- Records of interaction with the Urad
- No designated contact for the supervisory authority
Provides for the Office's cooperation with supervisory authorities of other Member States and the European Data Protection Board, including the consistency mechanism.
- Awareness of cross-border cooperation and lead-authority arrangements where applicable
- Ignoring lead-authority/one-stop-shop arrangements for cross-border processing
Provides for the Office's annual report and its powers to access information and premises for the purpose of supervision and inspection.
- Readiness to cooperate with Office inspections and information requests
- Records produced to the Office during supervision
- Failure to cooperate with an Office inspection
CZ 110/2019: HLAVA VI + Cast Druha - Prestupky a Zaverecna
Defines administrative offences under the Act and provides that the Office adjudicates them, including the special rule on shelving a matter; complements the GDPR administrative-fine regime.
- Risk assessment of administrative-offence exposure under the Act and GDPR
- Compliance evidence available for an Office proceeding
- Underestimating offence exposure
- No readiness for an Office proceeding
Sets transitional provisions, repeals the prior Act No. 101/2000 Coll., and sets the Act's effect, governing the move from the previous data protection regime to the GDPR-aligned one.
- Evidence that processing migrated from the repealed Act 101/2000 regime to the Act 110/2019 / GDPR regime
- Continuing to rely on the repealed Act 101/2000
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.