Law / Czech Republic

UOOU Enforcement, GDPR Article 82, and the Act on Collective Civil Court Proceeding

Regulation (EU) 2016/679, Arts. 82-83; Zakon c. 179/2024 Sb., o hromadnem obcanskem soudnim rizeni; Zakon c. 180/2024 Sb.

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 July 2024.

An enforcement supervision rule binding private bodies.

As of 2 September 2026.

What it requires

  • Expect UOOU to have General Data Protection Regulation (GDPR) Article 83 fining power over your processing of personal data of a person in the Czech Republic.
  • Expect a registered qualified entity to be able to bring a collective civil action, including for a GDPR breach, on behalf of a group of Czech data subjects under Act 179/2024 Coll., in addition to any individual Article 82 claim.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Criminal Code (trestni zakonik, Act 40/2009 Sb.) Section 180, Unauthorised Handling of Personal Data, sits outside the Act 110/2019 Sb. administrative-offence (prestupek) scheme entirely: it is a true criminal offence, prosecuted in the ordinary criminal courts. Paragraph 1 covers, even through mere negligence, unlawfully publishing, communicating, making accessible, otherwise processing, or appropriating personal data collected about another person in connection with the exercise of public power, causing serious harm to that person's rights or legitimate interests, punishable by up to 3 years' imprisonment or a prohibition on activity. Paragraph 2 applies the same penalty to breaching a state-imposed or state-recognised confidentiality duty by unlawfully disclosing personal data obtained through one's profession, employment, or function, again causing serious harm; this paragraph is not limited to the public-power context and can reach a private-sector employee bound by such a duty. Paragraph 3 raises the penalty to 1 to 5 years' imprisonment or an activity ban for aggravating circumstances (an organised group, commission through the press, film, broadcast or a publicly accessible computer network, causing considerable damage, or acting with intent to gain a considerable benefit), and paragraph 4 raises it further to 3 to 8 years' imprisonment for large-scale damage or an intent to gain a large-scale benefit.

Penalty structure

GDPR Article 83(5) sets the higher administrative-fine tier, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher, applied directly by the Office for Personal Data Protection (Urad pro ochranu osobnich udaju, UOOU) without restatement in Czech law, since the GDPR is directly applicable. Act 110/2019 Sb. adds a separate, narrower national ceiling for its own purely domestic administrative offences (Section 63, covering the Act's own purpose-limitation, information, access-request, audit-record and other domestic duties that are not themselves GDPR provisions): a fine of up to CZK 10,000,000 (roughly EUR 400,000). Sections 61(3) and 62(5) let the UOOU refrain from imposing an administrative penalty at all on controllers and processors covered by GDPR Article 83(7) (the Member State public-body derogation), as a matter of the Office's discretion rather than an automatic exemption. Act 179/2024 Sb. (implementing EU Directive 2020/1828 on representative actions) separately gives a qualified consumer-protection entity a collective-action procedure to pursue claims, including a GDPR Article 82 compensation claim, on behalf of a group of data subjects against a trader; it creates no liquidated or per-person damages figure of its own, so it is not recorded under statutory_damages.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Office for Personal Data Protection (Urad pro ochranu osobnich udaju, UOOU), the Czech Republic's GDPR supervisory authority, which adjudicates the administrative offences (prestupky) created by Act 110/2019 Sb.

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

UOOU (Office for Personal Data Protection) is the Czech Republic's supervisory authority, empowered under Act 110/2019 to impose General Data Protection Regulation (GDPR) Article 83 fines. GDPR Article 82 arms an individual with a direct private right of action.

The Czech Republic's genuine national addition beyond that baseline is Act No. 179/2024 Coll. on Collective Civil Court Proceeding, together with the accompanying Act No. 180/2024 Coll., in force 1 July 2024, transposing Directive (EU) 2020/1828 on representative actions; only registered qualified entities may bring such an action.

The act's title, in-force date of 1 July 2024, and structure are confirmed through zakonyprolidi.cz, a widely used private legal database rather than the official gazette; as of an October 2025 commentary report only two entities were registered and one unrelated action had been filed.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

Read the law

zakonyprolidi.cz (unofficial legal database, confirming title and dates)
Chambers and Partners and Cooley commentary (operative detail)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app