sectorial areas that have processing of personal data by electronic means as their core
capacity. Despite of political or academic debate concerning specific regulation of
home banking, unmanned aerial vehicles, mobile health, internet of things devices or
artificial intelligence, there is as of now no draft of such legislation. This is generally
in accordance with the concept of the Czech framework of personal data protection
as being formulated in essentially technology neutral way.
3 Data Protection in the Electronic Communications Sector
In addition to the generally applicable GDPR, processing of personal data is
regulated through specific provisions in the Electronic Communications Act and in
the Act No. 480/2004 Sb. on Certain Information Society Services, which implement
the Directive 2002/58/EC on privacy and electronic communications as amended
through the Directive 2009/136/EC amending Directive 2002/22/EC on universal
service and users’ rights relating to electronic communications networks and services, Directive 2002/58/EC concerning the processing of personal data and the
protection of privacy in the electronic communications sector and Regulation
(EC) No. 2006/2004 on cooperation between national authorities responsible for
the enforcement of consumer protection laws. In the upcoming year 2019, it is
expected that these provisions shall be replaced by the unified European specific
legislation contained in the proposed Regulation concerning the respect for private
life and the protection of personal data in electronic communications and repealing
Directive 2002/58/EC (Regulation on Privacy and Electronic Communications),
currently available in a form of the proposal COM/2017/010 final—2017/03 (COD).
As the Czech Republic is an EU Member State, the core case law concerning the
specific issues of personal data protection in the electronic communication sector is
originated by the Court of Justice of the European Union, in particular:
– case C-461/10, Bonnier Audio AB et al. v Perfect Communication Sweden AB;
– case C-557/07, LSG-Gesellschaft zur Wahrnehmung von Leistungsschutzrechten
GmbH v Tele2 Telecommunication GmbH;
– case C-275/06, Productores de Música de España (Promusicae) v Telefónica de
España SAU;
– joint cases C-293/12 and C-594/12, Digital Rights Ireland; or ¨
– joint cases C.203/15 and C-698/15, Tele2 Sverige.
On the national level, the most significant case law concerns the constitutional
permissibility of data retention legal framework as formerly implemented pursuant
to now invalid Directive 2006/24/EC of the European Parliament and of the Council
of 15 March 2006 on the retention of data generated or processed in connection with
the provision of publicly available electronic communications services or of public
communications networks and amending Directive 2002/58/EC (for details, please
refer to the decision of CJEU in joint cases C-293/12 and C-594/12, Digital Rights
Ireland). This legal framework was brought into the Czech law by the Act
128
R. Polčák et al.
capacity. Despite of political or academic debate concerning specific regulation of
home banking, unmanned aerial vehicles, mobile health, internet of things devices or
artificial intelligence, there is as of now no draft of such legislation. This is generally
in accordance with the concept of the Czech framework of personal data protection
as being formulated in essentially technology neutral way.
3 Data Protection in the Electronic Communications Sector
In addition to the generally applicable GDPR, processing of personal data is
regulated through specific provisions in the Electronic Communications Act and in
the Act No. 480/2004 Sb. on Certain Information Society Services, which implement
the Directive 2002/58/EC on privacy and electronic communications as amended
through the Directive 2009/136/EC amending Directive 2002/22/EC on universal
service and users’ rights relating to electronic communications networks and services, Directive 2002/58/EC concerning the processing of personal data and the
protection of privacy in the electronic communications sector and Regulation
(EC) No. 2006/2004 on cooperation between national authorities responsible for
the enforcement of consumer protection laws. In the upcoming year 2019, it is
expected that these provisions shall be replaced by the unified European specific
legislation contained in the proposed Regulation concerning the respect for private
life and the protection of personal data in electronic communications and repealing
Directive 2002/58/EC (Regulation on Privacy and Electronic Communications),
currently available in a form of the proposal COM/2017/010 final—2017/03 (COD).
As the Czech Republic is an EU Member State, the core case law concerning the
specific issues of personal data protection in the electronic communication sector is
originated by the Court of Justice of the European Union, in particular:
– case C-461/10, Bonnier Audio AB et al. v Perfect Communication Sweden AB;
– case C-557/07, LSG-Gesellschaft zur Wahrnehmung von Leistungsschutzrechten
GmbH v Tele2 Telecommunication GmbH;
– case C-275/06, Productores de Música de España (Promusicae) v Telefónica de
España SAU;
– joint cases C-293/12 and C-594/12, Digital Rights Ireland; or ¨
– joint cases C.203/15 and C-698/15, Tele2 Sverige.
On the national level, the most significant case law concerns the constitutional
permissibility of data retention legal framework as formerly implemented pursuant
to now invalid Directive 2006/24/EC of the European Parliament and of the Council
of 15 March 2006 on the retention of data generated or processed in connection with
the provision of publicly available electronic communications services or of public
communications networks and amending Directive 2002/58/EC (for details, please
refer to the decision of CJEU in joint cases C-293/12 and C-594/12, Digital Rights
Ireland). This legal framework was brought into the Czech law by the Act
128
R. Polčák et al.
