Law / Czech Republic

Czech Republic

European Union law applies in the Czech Republic The Czech Republic is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of the Czech Republic, described on this page below, applies here too.

17 of 22 named instruments researched to a stage, across all six areas of law we track: 17 in force. As of 14 September 2026.

When they take effect13 of 17 carry a date, 4 do not.
2018: 4 instruments (4 in force) ’18 2019: 1 instrument (1 in force) 2020: 0 instruments ’20 2021: 0 instruments 2022: 2 instruments (2 in force) 2023: 3 instruments (3 in force) 2024: 1 instrument (1 in force) 2025: 2 instruments (2 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 2
  5. Age gating law 2
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (210 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in the Czech Republic and is not restated here; its Article 5 prohibitions and Article 50 disclosure duties are described in the EU jurisdiction's own record. The Czech Republic's own criminal law reaches two forms of AI-generated sexual content that any person may produce, regardless of the EU Act.

Section 191a of the Criminal Code (trestni zakonik, Act No. 40/2009 Coll.) bans producing, importing, distributing, or otherwise supplying pornographic material depicting or otherwise using a person who did not consent to that depiction, a provision broad enough to reach a synthetic or AI-manipulated depiction of a real person's likeness.

Section 192 separately bans producing or distributing pornographic material depicting a child, and its text expressly extends to a person who merely appears to be a child, reaching an AI-generated depiction with no real child victim.

As of September 2026 the government's own Act on Artificial Intelligence, which would designate the Czech Telecommunications Office as the AI Act market-surveillance authority, create a regulatory sandbox, and set national administrative-offence penalties, remains a Ministry of Industry and Trade draft that has completed inter-ministerial comments but has not been submitted to the Government or Parliament, so no national AI Act implementing statute is in force.

AI prohibited practices

Criminal Code Section 191a, Non-Consensual Identity-Based Pornographic Depiction

Zakon c. 40/2009 Sb., trestni zakonik, Sec. 191azakonyprolidi.cz, consolidated text of the trestni zakonik

In force. Binds public and private bodies.

What this law does

Whoever produces, imports, exports, transports, offers, makes publicly accessible, mediates, puts into circulation, sells or otherwise supplies to another a photographic, film, computer, electronic or other pornographic work depicting or otherwise using a person the offender knows did not consent to that depiction or use, faces up to two years' imprisonment, a ban on activity, or forfeiture of property; the offence does not require the image to be a photograph of a real event and reaches a synthetic or digitally altered depiction of a real person's likeness made without consent.

The penalty rises to six months to three years where the act causes significant harm, is committed by a member of an organized group, is committed through the press, film, radio, television, a publicly accessible computer network or a similarly effective means, or is committed to obtain a significant benefit. It rises further to one to five years where it causes large-scale harm, is committed by a group operating across multiple states, or is committed to obtain a large-scale benefit.

What it requires

Criminal Code Section 192, Child Pornography Including a Depiction of a Person Who Appears to Be a Child

Zakon c. 40/2009 Sb., trestni zakonik, Sec. 192zakonyprolidi.cz, consolidated text of the trestni zakonik

In force. Binds public and private bodies.

What this law does

Whoever possesses a photographic, film, computer, electronic or other pornographic work depicting or otherwise using a child or a person who appears to be a child faces up to two years' imprisonment, and the same penalty applies to gaining access to child pornography through information or communication technology; the offence's own text extends to a person who merely appears to be a child, so an entirely AI-generated or synthetic depiction with no real child victim is reached the same way as an authentic image.

Producing, importing, exporting, transporting, offering, making publicly accessible, mediating, putting into circulation, selling, or otherwise supplying such a work, or profiting from it, carries six months to three years. That rises to two to six years or forfeiture of property where committed by an organized group, through the press, film, radio, television, a publicly accessible computer network or a similarly effective means, or to obtain a significant benefit.

It rises further to three to eight years where committed by a group operating across multiple states or to obtain a large-scale benefit.

What it requires

Privacy law6 instruments, 6 in force

Research summary (103 words)

The Czech Republic's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by Act No. 110/2019 Coll. on Personal Data Processing, confirmed at primary source and found to be predominantly procedural with no substantive biometric-specific narrowing.

The genuine Czech national addition surveyed is Acts 179/2024 and 180/2024 Coll., a collective civil court proceeding statute transposing the EU Representative Actions Directive, confirmed in force 1 July 2024 through a private legal database rather than the official gazette. No specific Czech employment-biometric provision was found; this is a genuine gap, not a confirmed absence, since the Labour Code's own text is not independently confirmed.

Breach notification

GDPR Articles 33-34, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34GDPR Arts. 33-34

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify UOOU within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. One commentary source (CMS) states Czech controllers may report a breach in limited scope or with delay in circumstances protecting Czech national interests; Act 110/2019 does not contain such a clause, so it is reported here as an unverified commentary claim rather than a confirmed derogation.

What it requires

Comprehensive regime

Act on Personal Data Processing

Zakon c. 110/2019 Sb., o zpracovani osobnich udajuUOOU, English translation PDF

In force since 24 April 2019. Binds public and private bodies.

What this law does

The Czech Republic gives the General Data Protection Regulation (GDPR) domestic effect through Act No. 110/2019 Coll., in force since 24 April 2019, replacing the pre-GDPR Act No. 101/2000 Coll. Read via the Office for Personal Data Protection's own English translation, it is predominantly procedural: it establishes the supervisory authority's powers, administrative-offense and fine procedures, and processing by competent authorities for criminal-law purposes transposing Directive (EU) 2016/680. It adds no substantive lawful-basis or controller and processor rules beyond GDPR.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c)GDPR Arts. 44-49, 83(5)(c)

In force since 25 May 2018. Binds public and private bodies.

What this law does

A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. Commentary sources confirm the Czech Republic has adopted no further domestic derogation.

What it requires

Data subject rights

GDPR Articles 12-22, Data-Subject Rights

Regulation (EU) 2016/679, Arts. 12-22GDPR Arts. 12-22

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12-22 (access, rectification, erasure, restriction, portability, objection, and Article 22 automated-decision rights) apply directly; Act 110/2019 adds no distinct national rights found, exercisable against the controller within GDPR's own one-month (extendable to three-month) response window.

What it requires

Enforcement supervision

UOOU Enforcement, GDPR Article 82, and the Act on Collective Civil Court Proceeding

Regulation (EU) 2016/679, Arts. 82-83; Zakon c. 179/2024 Sb., o hromadnem obcanskem soudnim rizeni; Zakon c. 180/2024 Sb.zakonyprolidi.cz (unofficial legal database, confirming title and dates)

In force since 1 July 2024. Binds private bodies.

What this law does

UOOU (Office for Personal Data Protection) is the Czech Republic's supervisory authority, empowered under Act 110/2019 to impose General Data Protection Regulation (GDPR) Article 83 fines. GDPR Article 82 arms an individual with a direct private right of action.

The Czech Republic's genuine national addition beyond that baseline is Act No. 179/2024 Coll. on Collective Civil Court Proceeding, together with the accompanying Act No. 180/2024 Coll., in force 1 July 2024, transposing Directive (EU) 2020/1828 on representative actions; only registered qualified entities may bring such an action.

The act's title, in-force date of 1 July 2024, and structure are confirmed through zakonyprolidi.cz, a widely used private legal database rather than the official gazette; as of an October 2025 commentary report only two entities were registered and one unrelated action had been filed.

What it requires

Sensitive categories

GDPR Article 9, Special Categories Including Biometric Data

Regulation (EU) 2016/679, Art. 9UOOU, Act 110/2019 (no biometric provision found)

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) treats biometric data processed for unique identification as a special category, prohibited absent an Article 9(2) ground. Act 110/2019 has no biometric-specific provision narrowing or elaborating this, consistent with two independent commentary sources describing no distinct Czech biometric restriction beyond the general EU-law enabling clause.

General employee monitoring sits in the Labour Code (zakonik prace, Act No. 262/2006 Coll.), but that Act's text is not independently confirmed here, and no specific employment-biometric consent or works-council provision appears in commentary; this is a genuine gap, not a confirmed absence.

What it requires

Scraping law3 instruments, 3 in force

Research summary (201 words)

Czech scraping-relevant law rests on three national instruments beyond the EU-level personal-data and copyright floor described in the EU jurisdiction's own record. Section 230 of the Criminal Code criminalizes gaining unauthorized access to a computer system by overcoming a security measure, so authorization under Czech law turns on whether a technical barrier was circumvented rather than on a website's terms of use alone.

Sections 88 to 94 of the Autorsky zakon give the maker of a database a sui generis right against extraction or re-utilization of the whole or a qualitatively or quantitatively substantial part of its contents, lasting fifteen years and renewed by a fresh substantial investment, transposing the EU Database Directive (96/9/EC).

Sections 39c and 39d of the same Act create the Digital Single Market Copyright Directive's text-and-data-mining exceptions, letting a scraper mine lawfully accessed works for automated analysis unless the rightholder has reserved that use by a machine-readable or other suitable means, with a separate, non-waivable exception for university and cultural-heritage research.

A general unfair-competition clause in the Civil Code (Act No. 89/2012 Coll., Sections 2972 and 2976) reaches conduct such as free-riding on a competitor's business reputation, but it is not documented here as a separate instrument.

Computer misuse

Criminal Code Section 230, Unauthorized Access to a Computer System

Zakon c. 40/2009 Sb., trestni zakonik, Sec. 230zakonyprolidi.cz, consolidated text of the trestni zakonik

In force. Binds public and private bodies.

What this law does

Whoever overcomes a security measure and thereby gains unauthorized access to a computer system or part of it faces up to two years' imprisonment, a ban on activity, or forfeiture of property; authorization under Czech criminal law therefore turns on whether a technical security measure was circumvented, not merely on whether a website's terms of use were violated.

A separate paragraph reaches unauthorized use, deletion, alteration, forgery, insertion or transmission of data, or another interference with a computer system's software or hardware, carrying up to three years.

The penalty rises to six months to four years where the act is committed with intent to cause damage or gain an unauthorized benefit, or to restrict a computer system's functionality; to one to five years where committed by an organized group, causes significant damage, targets a computer system whose disruption would seriously affect the state, public health, safety, the economy, or the population's basic needs, secures a significant benefit, or seriously disrupts a business; and to three to eight years for large-scale damage or a large-scale benefit.

What it requires

Copyright and text and data mining (TDM)

Autorský zákon Sections 39c-39d, Text and Data Mining Exception for Automated Analysis

Zakon c. 121/2000 Sb., o pravu autorskem (autorsky zakon), Sec. 39c and Sec. 39d, as inserted by Zakon c. 429/2022 Sb.zakonyprolidi.cz, consolidated text of the Autorsky zakon

In force since 5 January 2023. Binds public and private bodies.

What this law does

A person does not infringe copyright by reproducing a lawfully accessed work for the purpose of automated textual and data analysis carried out to obtain information such as patterns, trends and correlations, and may keep the resulting copy only for as long as the analysis requires, per Section 39c(1).

That general licence does not apply where the rightholder has expressly reserved the use in a suitable way, including, for a work made available online, a machine-readable reservation, per Section 39c(2); a scraper mining a work so reserved needs the rightholder's authorization.

A separate, non-waivable exception in Section 39d lets a university carrying out scientific research, or a legal person whose main purpose is scientific research or education including research, mine a lawfully accessed work regardless of any rightholder reservation.

What it requires

Database right

Autorský zákon Sections 88-94, Sui Generis Database Right

Zakon c. 121/2000 Sb., o pravu autorskem (autorsky zakon), Sec. 88 to Sec. 94zakonyprolidi.cz, consolidated text of the Autorsky zakon

In force. Binds public and private bodies.

What this law does

A database is a collection of independent works, data or other elements, systematically or methodically arranged and individually accessible by electronic or other means, per Section 88.

Its maker, the person who at their own responsibility obtained, verified or presented its content with a qualitatively or quantitatively substantial investment, holds the exclusive right to use the whole content or a qualitatively or quantitatively substantial part of it and to authorize another to do so, per Sections 88a and 90.

Repeated and systematic extraction or re-utilization of insubstantial parts is also prohibited where it conflicts with the normal exploitation of the database or unreasonably prejudices the maker's legitimate interests. The right lasts fifteen years from the database's making, or from its first making available to the public if that occurs within that period, per Section 93, and a fresh substantial investment in the database restarts the term.

An authorized user who uses the database lawfully made available to the public does not infringe the right by using a qualitatively or quantitatively insubstantial part for any purpose, provided that use is normal, proportionate and not systematic or repeated.

Unauthorized use of a database is an administrative offence a natural person may be fined up to CZK 150,000 for, and a legal person or a natural person acting in business up to CZK 150,000, before the municipal authority with extended competence in whose district the offence was committed.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (496 words)

The Czech Republic's NIS2 transposition is enacted and in force. Act No. 264/2025 Coll., the Cybersecurity Act (zákon o kybernetické bezpečnosti), was published in the Collection of Laws on 4 August 2025 and, under its own Section 73, entered into force on the first day of the third calendar month following publication, 1 November 2025.

Section 72 repeals the prior Act No. 181/2014 Coll. on cybersecurity outright, along with several of its implementing decrees, so the 2014 regime does not remain in force alongside the new Act.

Sections 3 to 5 bind a poskytovatel regulované služby (provider of a regulated service) drawn from 15 named sectors, including public administration, energy, manufacturing, digital infrastructure and services, financial markets, healthcare, and defence, where the provider is a medium or large enterprise under Commission Recommendation 2003/361/EC or is otherwise significant for essential social, economic or security functions regardless of size.

Section 8 splits providers into a vyšší povinnosti (higher-obligations) regime, matching NIS2's essential-entity class, and a nižší povinnosti (lower-obligations) regime, matching its important-entity class.

Section 18 names an online marketplace, an internet search engine and a social-networking-platform provider, alongside DNS resolution, top-level-domain registry, cloud computing, data-centre, content-delivery-network and trust-service providers, among the regulated services of the digital-infrastructure-and-services sector.

Section 13 requires a regulated-service provider to adopt organisational and technical security measures, listed at Section 14, transposing NIS2 Article 21, and Sections 15 and 16 set a graduated incident-notification clock (an initial report within 24 hours, a follow-up within 72 hours, and a final report within 30 days of the 72-hour report, or a progress report if the incident is still ongoing at that point) transposing NIS2 Article 23.

The Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB, the National Cyber and Information Security Agency), seated in Brno, is the central administrative authority for cybersecurity and receives reports from a higher-obligations provider directly; a lower-obligations provider reports instead to the Národní CERT, the national coordination team NÚKIB may contract out under Section 53.

No instrument reviewed here imposes an independent product-security or market-placement duty on a manufacturer: that rests on the directly applicable Cyber Resilience Act (Regulation (EU) 2024/2847), which is documented at the European Union level and is not restated here.

The Czech Republic's own Cyber Resilience Act (CRA) adaptation act, naming the Czech Trade Inspection Authority (Česká obchodní inspekce) as market-surveillance authority for most product categories and NÚKIB as the national single reporting point, was submitted by the Ministry of Industry and Trade for interministerial comment in July 2026 and was heading to the Chamber of Deputies as of this review, without having been enacted and without affecting the Cyber Resilience Act's own direct applicability.

The Czech Republic has no free-standing reasonable-security or information-security-programme statute reaching a business with no sector gate; personal-data breach notification to the Úřad pro ochranu osobních údajů and to the affected person is separate law, General Data Protection Regulation (GDPR) Articles 33 and 34, which sits in the privacy topic rather than here, as does GDPR Article 32's security-of-processing obligation.

Sector security regimes

Cybersecurity Act (Zákon o kybernetické bezpečnosti), Risk-Management Security Measures

Act No. 264/2025 Coll., Cybersecurity Act, Sections 13-14Act No. 264/2025 Coll., consolidated text, zakonyprolidi.cz, Sections 13-14 and 18

In force 11 months, effective 1 November 2025. Binds public and private bodies.

What this law does

Section 13 requires a provider of a regulated service, within the scope it determines for its own assets, to adopt and implement organisational and technical security measures adequate to secure the regulated service's proper provision and the cybersecurity of its assets.

Section 14(1) sets at least 14 organisational measure categories for a provider in the higher-obligations (essential-entity) regime, including an information security management system, top-management requirements, security roles, security-policy and documentation management, asset, risk, supplier and change management, human-resources security, acquisition and development security, access management, incident handling, business-continuity management and cybersecurity auditing, plus at least 11 technical measure categories including physical security, communications-network security, identity and access-rights administration, event detection, logging and evaluation, application security, cryptographic algorithms, availability assurance, and security of industrial or control-system assets.

Section 14(2) sets a reduced 13-category combined list for a provider in the lower-obligations (important-entity) regime. Section 18 extends this duty expressly to a provider of DNS resolution, trust, top-level-domain registry, cloud computing, data-centre, content-delivery-network, online-marketplace, internet-search-engine, social-networking-platform, managed-service or managed-security-service offerings, transposing NIS2 Article 21.

What it requires

Vulnerability and incident reporting

Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification

Act No. 264/2025 Coll., Cybersecurity Act, Sections 15-16Act No. 264/2025 Coll., consolidated text, zakonyprolidi.cz, Sections 15-16

In force 11 months, effective 1 November 2025. Binds public and private bodies.

What this law does

Section 15 requires a provider in the higher-obligations regime to report a qualifying cybersecurity incident directly to NÚKIB, and a provider in the lower-obligations regime to report to the Národní CERT. Section 16 sets a graduated notification clock, transposing NIS2 Article 23.

An initial report is due no later than 24 hours after detecting the incident, giving the provider's identifying details, basic incident data, and whether the provider believes the incident was caused by an unlawful intervention or could have a cross-border impact.

For an incident with significant impact, a follow-up report is due no later than 72 hours after detection, updating that assessment and giving an initial evaluation of the incident's impact and, where available, indicators of compromise.

An interim report is due on NÚKIB's or the Národní CERT's request, and a final report is due no later than 30 days after the 72-hour report; if the incident is still ongoing at that point, a progress report is due instead, followed by a final report within 30 days of resolution. A provider reports through NÚKIB's Portál Úřadu where possible; a higher-obligations provider otherwise emails NÚKIB or uses its data-box address, and a lower-obligations provider does the same with the Národní CERT.

What it requires

Age gating law2 instruments, 2 in force

Research summary (185 words)

The Czech Republic layers two national age-verification duties on top of the EU Audiovisual Media Services Directive floor described in the EU jurisdiction's own record.

Section 6a of Act No. 132/2010 Coll. on audiovisual media services on demand, inserted by Act No. 242/2022 Coll., requires a provider of an on-demand audiovisual media service to use age-verification tools or other technical measures to keep minors from ordinarily seeing or hearing a programme capable of harming their physical, psychological or moral development, such as pornography or gross gratuitous violence.

Act No. 242/2022 Coll. itself, the national transposition of the video-sharing-platform rules the 2018 AVMSD amendment added, separately requires a provider of a video-sharing platform service to introduce and operate an age-verification system for platform users confronting such content, alongside parental-control tools, a notice-and-action system, and a media-literacy obligation, enforced by the Council for Radio and Television Broadcasting.

A parallel duty binds television and radio broadcasters under Act No. 231/2001 Coll. in materially the same terms. A minor's digital-consent age under the General Data Protection Regulation (GDPR) is a privacy matter and is covered in the jurisdiction's privacy record rather than here.

Adult content age verification (AV)

Act No. 132/2010 Coll., Section 6a, Age Verification for On-Demand Audiovisual Media Services

Zakon c. 132/2010 Sb., o audiovizualnich medialnich sluzbach na vyzadani, Sec. 6a, as inserted by Zakon c. 242/2022 Sb., Sec. 17 point 5zakonyprolidi.cz, consolidated text of Act No. 132/2010 Coll.

In force since 15 September 2022. Binds private bodies.

What this law does

A provider of an audiovisual media service on demand must choose suitable measures so that a programme capable of disrupting a minor's physical, psychological or moral development, such as pornography or gross gratuitous violence, cannot ordinarily be seen or heard by a minor; those measures include age-verification tools or other technical measures that prevent a minor from accessing the programme.

The provider must also give sufficient, freely and easily accessible information about the potentially harmful content a programme carries. Personal data of minors collected for this purpose may not be processed for commercial ends such as direct marketing, profiling or behaviourally targeted advertising. A breach of this duty is an administrative offence the Council for Radio and Television Broadcasting may fine up to CZK 2,000,000.

Note and primary source

Act No. 242/2022 Coll., Protection Measures Including Age Verification for Video-Sharing Platform Services

Zakon c. 242/2022 Sb., o sluzbach platforem pro sdileni videonahravek, Sec. 7, Sec. 8 and Sec. 11zakonyprolidi.cz, consolidated text of Act No. 242/2022 Coll.

In force since 15 September 2022. Binds private bodies.

What this law does

A provider of a video-sharing platform service must adopt measures protecting minors from programmes, user-uploaded videos and commercial communications capable of harming their physical, psychological or moral development, and content of that kind may not be made available so that a minor could ordinarily see or hear it; the measures must include, among others, the introduction and operation of an age-verification system for platform users confronting such content, together with easily usable content-rating tools, parental-control systems, and a transparent notice-and-complaint procedure.

The most harmful content, such as pornography or gross gratuitous violence, must be subject to the strictest access-control measures. A provider that fails to introduce these protection measures commits an administrative offence the Council for Radio and Television Broadcasting may fine up to CZK 500,000.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (197 words)

The Czech Republic transposed the EU Digital Single Market Copyright Directive's press-publisher right and text-and-data-mining exception into its own Copyright Act (Autorsky zakon, Act No. 121/2000 Coll.) through amending Act No. 429/2022 Coll. A press publisher established in the EU or EEA holds an exclusive two-year online reproduction and making-available right at Section 87b, exempting bare hyperlinks and the use of individual words or very short extracts, and an information-society service provider negotiating a licence to use a press publication must deal in good faith, on equal and non-discriminatory terms; if the parties cannot agree a fee within 60 days, either side may ask the Ministry of Culture to set it, a national dispute-resolution mechanism beyond the Directive's own text.

Sections 39c and 39d create the Directive's two text-and-data-mining exceptions: a general licence for automated textual and data analysis subject to a rightholder's machine-readable opt-out, and a broader, non-waivable exception for universities and cultural-heritage institutions conducting scientific research.

The Czech Republic has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act, and no hot-news or misappropriation doctrine distinct from the ordinary unfair-competition clause was confirmed in the sources checked.

Press publishers' right

Autorský zákon Section 87b, Press Publisher Neighbouring Right

Zakon c. 121/2000 Sb., o pravu autorskem (autorsky zakon), Sec. 87b, as inserted by Zakon c. 429/2022 Sb.zakonyprolidi.cz, consolidated text of the Autorsky zakon

In force since 5 January 2023. Binds private bodies.

What this law does

A press publisher established in an EU or EEA member state holds the exclusive right to reproduce its press publication and make it available online, and an information-society service provider needs the publisher's authorization before using it, per Section 87b(3)-(4). The right does not reach an individual private user's non-commercial use, a bare hyperlink, or the use of single words or very short, insignificant extracts, per Section 87b(8).

It lasts two years from the publication's release, per Section 87b(6). A service provider negotiating the required authorization must deal with the publisher in good faith on equal and non-discriminatory terms and pay a reasonable fee, per Section 87b(9); if the parties cannot agree a fee within 60 days of the start of negotiations, either side may ask the Ministry of Culture to set it, per Section 87b(11)-(12).

A service provider that fails to negotiate in good faith or refuses to supply the data the Ministry needs to set the fee commits an administrative offence the competent municipal authority may fine up to CZK 500,000 or 1 percent of the offender's total annual worldwide turnover, whichever is higher.

Note and primary source

Text and data mining (TDM) opt-out

Autorský zákon Sections 39c-39d, Text and Data Mining Exception Bearing on News Indexing

Zakon c. 121/2000 Sb., o pravu autorskem (autorsky zakon), Sec. 39c and Sec. 39d, as inserted by Zakon c. 429/2022 Sb.zakonyprolidi.cz, consolidated text of the Autorsky zakon

In force since 5 January 2023. Binds public and private bodies.

What this law does

A person does not infringe copyright by reproducing a work, including a press publication, for the purpose of automated textual and data analysis carried out to obtain information such as patterns, trends and correlations, and may keep the copy only for as long as that analysis requires, per Section 39c(1).

That general licence does not apply to a work whose author has expressly reserved the analysis in a suitable way, including through machine-readable means for a work made available online, per Section 39c(2); a news aggregator indexing text so reserved therefore needs the rightholder's authorization.

A separate, non-waivable exception in Section 39d lets a university carrying out scientific research, or a legal person whose main purpose is scientific research or education including research, mine a lawfully accessed work without regard to any rightholder reservation.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.