– Supreme Administrative Court 4 As 90/2013.
– Supreme Administrative Court 4 As 109/2013.
– Supreme Administrative Court 4 As 75/2012—28.
– Supreme Administrative Court 5 As 158/2012.
– Supreme Administrative Court 7 As 186/2012.
– Supreme Administrative Court 3 As 21/2005.
– Constitutional Court I. ÚS 517/10.
– Municipal Court in Prague 10 A 220/2013.
– Municipal Court in Prague 11 A 77/2012.
1.2 Definitions
Basic statutory definitions are contained in Art. 4 of the GDPR. Personal data are
regarded as “any information relating to an identified or identifiable natural person
(‘data subject’); an identifiable natural person is one who can be identified, directly
or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to
the physical, physiological, genetic, mental, economic, cultural or social identity of
that natural person”. Special categories of personal data (former ‘sensitive personal
data’) whose processing is specifically restricted are defined in Art. 9(1) of the
GDPR as “personal data revealing racial or ethnic origin, political opinions, religious
or philosophical beliefs, or trade union membership, and the processing of genetic
data, biometric data for the purpose of uniquely identifying a natural person, data
concerning health or data concerning a natural person’s sex life or sexual
orientation”.
The scope of the GDPR is limited to the domain of the EU law, so it does not
cover e.g. processing of personal data for security or defence purposes. The GDPR
also does not cover processing of personal data ‘by competent authorities for the
purposes of the prevention, investigation, detection or prosecution of criminal
offences or the execution of criminal penalties, including the safeguarding against
and the prevention of threats to public security’—that area is legislated indirectly
through the Directive (EU) 2016/680. However, if the aforementioned Czech Personal Data Processing Act, and the Amending Act are passed, there will apply
analogical definitions and principles of protection according to the GDPR also in
these areas.
1.3 Institutional Backing
The main responsible authority for administrative protection of personal data is the
Czech Office for the Protection of Personal Data (Úřad pro ochranu o sobních
údajů). We further refer to the Office also as to the Czech Data Protection Authority
National Report: Czech Republic
117
– Supreme Administrative Court 4 As 109/2013.
– Supreme Administrative Court 4 As 75/2012—28.
– Supreme Administrative Court 5 As 158/2012.
– Supreme Administrative Court 7 As 186/2012.
– Supreme Administrative Court 3 As 21/2005.
– Constitutional Court I. ÚS 517/10.
– Municipal Court in Prague 10 A 220/2013.
– Municipal Court in Prague 11 A 77/2012.
1.2 Definitions
Basic statutory definitions are contained in Art. 4 of the GDPR. Personal data are
regarded as “any information relating to an identified or identifiable natural person
(‘data subject’); an identifiable natural person is one who can be identified, directly
or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to
the physical, physiological, genetic, mental, economic, cultural or social identity of
that natural person”. Special categories of personal data (former ‘sensitive personal
data’) whose processing is specifically restricted are defined in Art. 9(1) of the
GDPR as “personal data revealing racial or ethnic origin, political opinions, religious
or philosophical beliefs, or trade union membership, and the processing of genetic
data, biometric data for the purpose of uniquely identifying a natural person, data
concerning health or data concerning a natural person’s sex life or sexual
orientation”.
The scope of the GDPR is limited to the domain of the EU law, so it does not
cover e.g. processing of personal data for security or defence purposes. The GDPR
also does not cover processing of personal data ‘by competent authorities for the
purposes of the prevention, investigation, detection or prosecution of criminal
offences or the execution of criminal penalties, including the safeguarding against
and the prevention of threats to public security’—that area is legislated indirectly
through the Directive (EU) 2016/680. However, if the aforementioned Czech Personal Data Processing Act, and the Amending Act are passed, there will apply
analogical definitions and principles of protection according to the GDPR also in
these areas.
1.3 Institutional Backing
The main responsible authority for administrative protection of personal data is the
Czech Office for the Protection of Personal Data (Úřad pro ochranu o sobních
údajů). We further refer to the Office also as to the Czech Data Protection Authority
National Report: Czech Republic
117
