data, which are transmitted via their public communications network and the publicly
available electronic communications services. In particular, such undertakings shall not
admit any wiretapping, message storage, or any other types of interception or monitoring of messages, including the data contained therein and related thereto, by any persons
other than the users, without the consent of the users concerned, unless otherwise
provided in laws [Section 88 of Act No. 141/1961 on criminal procedure (Code of
Criminal Procedure), as subsequently amended.]. This shall not be to the prejudice of the
technical storage of data as needed for message transmission without affecting the
confidentiality principle.
(2) Message means any information being exchanged or transmitted between a finite
number of subscribers or users via the publicly available electronic communications
service, except for the information transmitted as part of the public audio or television
broadcasting via the electronic communications network, unless it can be allocated to an
identifiable subscriber or user receiving that information.
(3) Anybody wishing to use, or using, the electronic communications network for the
storage of data or for gaining access to the data stored in the subscribers’ or users’
terminal equipment shall inform those subscribers or users beforehand in a provable
manner about the extent and purpose of processing such data and shall offer them the
option to refuse such processing. This obligation does not apply to activities relating to
technical storage or access and serving exclusively for the purposes of performing or
facilitating message transmission via the electronic communications network, nor does it
apply to the cases where such technical storage or access activities are needed for the
provision of an information society service explicitly requested by the subscriber
or user.
(4) The undertakings providing public communications networks or publicly available
electronic communications services shall upon request of the subscriber provide such
subscriber free of charge and in a form allowing further electronic processing with the
traffic and location data, which it has at its disposal following this law, if such subscriber
was not able to intercept or storage such data pursuant to a device failure caused by a
cyber security incident [as defined in the Section 7 Subsection 2 of the Act No. 181/2014
Sb. on the Cybersecurity and Change of Related Acts]. The undertaking shall transmit
the data, if technically possible, without due delay, latest within three days following the
delivery of the request or, in case of continuous communication, following the day of its
realization.
The related aspect of electronic communications regulation, that to a certain
degree ensures the protection of confidentiality of the communications data, is the
requirement for adequate security measures to be implemented by the electronic
communications providers in order to protect transmitted data, and obligations in
case of risk of a breach of data security. The specific legal rules include obligation to
implement adequate technical and organisational measures to protect personal data
as well as traffic and location data and the confidentiality of the communication and
obligation to prepare internal technical and organisational regulations to provide data
protection and communications confidentiality.
The following Sections 88 and 88a of the Electronic Communications Act
contain specific rules about the implementation of security measures by electronic
communications providers in order to protect personal data including traffic and
location data, and obligations in case of risk of a breach of security in accordance
with the implementation of the Directive 2002/58/EC on privacy and electronic
communications:
National Report: Czech Republic
131
Précédent

- 140/540

Suivant