ILN Data Privacy Paper

Czech Republic

the Act No. 480/2004 Coll., on Certain Information Society Services and on Amendments to Certain Acts, as amended (“Act on Certain Information Society Services”) (the dissemination of commercial communications by electronic means, such as by e- mail or telephone, is regulated by this act). This act implements the Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market (“Directive on electronic commerce”) and the Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (“ePrivacy Directive” or “ePD”); the Act No. 127/2005 Coll., on Electronic Communications and on Amendment to Certain Related Acts (Act on Electronic Communications), as amended (this act regulates the marketing phone calls, use of cookies and processing of personal data in telecommunications). This act implements, among others, the Directive (EU) 2018/1972 of the European Parliament and of the Council of 11 December 2018 establishing the European Electronic Communications Code, and also the ePrivacy Directive/ePD; the Act No. 181/2014 Coll., on Cyber ​Security, as amended www.peterkapartners.com/

(with several obligations, for example the registration obligation and the obligation to report security incidents under the Cyber Security Act in addition to obligation to report data breaches under the GDPR/eDP – in case the data breach involves also security incident). 2.3 Upcoming or proposed legislation (if applicable) the new act on cyber s​ecurity replacing the Cyber Security Act mentioned above should be adopted and effective as of October 2024 in the Czech Republic. This new act is implementing the Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive). Scope of Application 3.1. Legislative Scope The general rules for the protection and processing of personal data in the Czech Republic are stipulated in Act No. 110/2019 Coll., on the Processing of Personal Data, as amended (“Act on Processing of Personal Data”), and Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the

Made with FlippingBook - PDF hosting