(DPA). The English language website of the Czech DPA is at https://www.uoou.cz/
en/.
The Czech DPA has a general administrative jurisdiction incl. the jurisdiction to
investigate and sanction the processing of personal data. Providers of services of
electronic communications are simultaneously under the administrative jurisdiction
of the Czech Telecommunications Office (Český telekomunikační úřad—English
website is available at https://www.ctu.eu) with regards to protection of privacy in
electronic communications.
The scope of jurisdiction of the Czech DPA does not include processing of
personal data in the judiciary and in the course of criminal investigation and
prosecution. That is due to the principle of distinction of powers between the
administration (part of which is also the Czech DPA) and the judiciary. The
envisaged Personal Data Processing Act and the Amending Act (see above) lay
down supervision powers over processing of personal data in criminal proceedings
for the Supreme Public Prosecutor’s Office. The same draft acts also establishes
supervision over processing of personal data in the judiciary for superior courts and
ultimately for all Czech supreme judicial institutions, i.e. the Supreme Court, the
Supreme Administrative Court and the Constitutional Court.
1.4 Self-Regulation
The regulatory architecture of the GDPR is built on performance-based rules. It
means that black-letter law lays down only basic principles and general requirements, while particular behavioural rules are set up autonomously by regulated
subjects, i.e. controllers and processors. Controllers and processors have to document ways in which they process personal data and adopt efficient protective
measures. In addition, controllers and processors are obliged to autonomously
implement procedures for data subjects to exercise their rights.
1
Relative vagueness of performance-based rules created demand for solutions that
would provide controllers and processors with greater certainty as to compliance of
their autonomously developed measures with legal requirements. The GDPR thus
counts in Art. 42(1) with ‘establishment of data protection certification mechanisms
and of data protection seals and marks, for the purpose of demonstrating compliance
with this Regulation of processing operations by controllers and processors.’
It is also expected that significant role in defining particular rules for typical forms
of processing of personal data will be played by various specific instruments such as
standard data protection clauses, binding corporate rules or codes of conduct. The
adoption procedures of these instruments are legislated in the GDPR, but their mere
1 For more particular explanation of use of behavioural rules in the Czech law, see Polčák et al.
(2018), p. 13.
118
R. Polčák et al.
en/.
The Czech DPA has a general administrative jurisdiction incl. the jurisdiction to
investigate and sanction the processing of personal data. Providers of services of
electronic communications are simultaneously under the administrative jurisdiction
of the Czech Telecommunications Office (Český telekomunikační úřad—English
website is available at https://www.ctu.eu) with regards to protection of privacy in
electronic communications.
The scope of jurisdiction of the Czech DPA does not include processing of
personal data in the judiciary and in the course of criminal investigation and
prosecution. That is due to the principle of distinction of powers between the
administration (part of which is also the Czech DPA) and the judiciary. The
envisaged Personal Data Processing Act and the Amending Act (see above) lay
down supervision powers over processing of personal data in criminal proceedings
for the Supreme Public Prosecutor’s Office. The same draft acts also establishes
supervision over processing of personal data in the judiciary for superior courts and
ultimately for all Czech supreme judicial institutions, i.e. the Supreme Court, the
Supreme Administrative Court and the Constitutional Court.
1.4 Self-Regulation
The regulatory architecture of the GDPR is built on performance-based rules. It
means that black-letter law lays down only basic principles and general requirements, while particular behavioural rules are set up autonomously by regulated
subjects, i.e. controllers and processors. Controllers and processors have to document ways in which they process personal data and adopt efficient protective
measures. In addition, controllers and processors are obliged to autonomously
implement procedures for data subjects to exercise their rights.
1
Relative vagueness of performance-based rules created demand for solutions that
would provide controllers and processors with greater certainty as to compliance of
their autonomously developed measures with legal requirements. The GDPR thus
counts in Art. 42(1) with ‘establishment of data protection certification mechanisms
and of data protection seals and marks, for the purpose of demonstrating compliance
with this Regulation of processing operations by controllers and processors.’
It is also expected that significant role in defining particular rules for typical forms
of processing of personal data will be played by various specific instruments such as
standard data protection clauses, binding corporate rules or codes of conduct. The
adoption procedures of these instruments are legislated in the GDPR, but their mere
1 For more particular explanation of use of behavioural rules in the Czech law, see Polčák et al.
(2018), p. 13.
118
R. Polčák et al.
