electronic communications, if neither lit. d), nor lit. b) of the Section 3 is applicable
(Section 3 lit. a) of the Act on Cybersecurity).
24
If an entity operating in electronic communications sector is classified as either
the first or the second above described category, it is subject to specific notification
obligation pursuant to Section 8 of the Act on Cybersecurity. This provision states
that such entities are obliged to report cyber security incidents
25 without undue delay
after their detection. In case of classification as an entity operating an important
network (Section 3 lit. b) of the Act on Cybersecurity), such incident is reported to
the administrator of the national CERT.
26 In case of a controller or an operator of
communication system included in the critical information infrastructure (Section 3
lit. d) of the Act on Cybersecurity), such notification is made to the National Office
for Cybersecurity and Information Security (govCERT).
The aforementioned data breaches must be reported regardless of presence or
absence of personal data in the breached dataset. However, this obligation of
notification is without prejudice to any other duty to report data breaches. That
means that entities obliged to notify data breach to CERT unit are, in case that such
breach affected the processed personal data, also obliged to notify the Czech Office
for the Protection of Personal Data as data controllers, either pursuant to Article 33 of
the GDPR or, in case of undertakings providing publicly available electronic
communications service, pursuant to Section 88 Subsection 4 of the Electronic
Communications Act.
3.3 Supervision of the Personal Data Processing
in the Electronic Communication Sector
As implies from Section 87 Subsection 3 of the Electronic Communications Act,
supervision over compliance with the obligations in processing personal data in the
electronic communications sector is provided by the Czech Office for the Protection
of Personal Data in accordance with Act No. 101/2000 Sb., on the Protection of
Personal Data and on Amendment to Some Acts.
27 For future reference, the provisions regarding the competent data protection authority in the Czech data
24 See in Czech: Maisner and Vlachová (2015), pp. 74–76.
25 Pursuant to Section 7 Subsection 2 of the Act on Cybersecurity, “cybernetic security incident” is
defined as a breach of the security of the information in the information systems or a breach of
security of the services or of the security and integrity of the electronic communications networks
due to cybernetic security event. “Cybernetic security event” means, pursuant to Section 7 Subsection 1 of the Act on Cybersecurity, an event, which may cause a breach of security of the
information in the information systems or a breach of security of the services or of the security
and integrity of the electronic communications networks.
26 The national CERT is currently administered by the Czech domain name authority CZ.NIC.
27 See in Czech: Chudomelová et al. (2016), pp. 287–290.
National Report: Czech Republic
135
Précédent

- 144/540

Suivant