5.2 Cybersecurity and Information Transfer
The Act No. 181/2014 Sb., on Cybersecurity requires controllers of important
systems and critical information infrastructure to share data on cyber security
incidents with the Governmental CERT (Computer Emergency Response Team)
that is operated by the National Cyber and Information Security Agency. Section 8
of the Cybersecurity Act states that:
Public authorities and natural and legal persons set out in § 3 b) to e) are obliged to report
cyber security incidents in their important network, critical information infrastructure information system, critical information infrastructure communication system or important
information system immediately after their detection.
This data may also contain personal data, which is why the National Cyber and
Information Security Agency and its employees are required to keep it confidential,
as is prescribed by section 10 as follows:
(1) Employees of the Czech Republic working for the Agency, taking part in solving cyber
security incident, are bound by confidentiality about incidents record data. Confidentiality lasts even after the termination of the labour law relationship towards the Agency.
(2) The director of the Agency may waive incidents evidence data confidentiality of persons
set out in paragraph 1, together with determination of the data and waiver extent.
Incident data can be only shared with other public authorities if it is necessary for
fulfilling tasks within their authority.
61
The National CERT generally falls within the application of the private law.
Therefore, General Data Protection Regulation applies for any data processing
conducted by it. This situation is not so clear in the case of the Government
CERT. The wording of section 41 of the proposal of Personal Data Processing Act
states that the provisions in question are to be used when there is processing of
personal data for “the purpose of defence and security interests of the Czech
Republic”. However, the explanatory report to the proposal mentions only duties
of intelligence services, the army and during crises. Therefore, it is not entirely clear
whether processing of personal data conducted by the Government CERT during
fulfilling of its duties should be covered by the third part of the proposed act.
6 Remedies and Sanctions
The overall regulatory philosophy of the GDPR has changed, compared to previous
legislation, from liability to compliance. The GDPR lays down, besides mere
protective obligations, a system of various regulatory instruments designed to
61 Section 9 subsection 3 of the act No. 181/2014 Sb., on Cybersecurity. The relationship of data
protection and cybersecurity was in analysed in e.g. Harašta and Míšek (2015), pp. 21–42
(in Czech). For more information on Czech legislative approach to cybersecurity see (in Czech)
e.g. Polčák 2015, pp. 95–149.
150
R. Polčák et al.
The Act No. 181/2014 Sb., on Cybersecurity requires controllers of important
systems and critical information infrastructure to share data on cyber security
incidents with the Governmental CERT (Computer Emergency Response Team)
that is operated by the National Cyber and Information Security Agency. Section 8
of the Cybersecurity Act states that:
Public authorities and natural and legal persons set out in § 3 b) to e) are obliged to report
cyber security incidents in their important network, critical information infrastructure information system, critical information infrastructure communication system or important
information system immediately after their detection.
This data may also contain personal data, which is why the National Cyber and
Information Security Agency and its employees are required to keep it confidential,
as is prescribed by section 10 as follows:
(1) Employees of the Czech Republic working for the Agency, taking part in solving cyber
security incident, are bound by confidentiality about incidents record data. Confidentiality lasts even after the termination of the labour law relationship towards the Agency.
(2) The director of the Agency may waive incidents evidence data confidentiality of persons
set out in paragraph 1, together with determination of the data and waiver extent.
Incident data can be only shared with other public authorities if it is necessary for
fulfilling tasks within their authority.
61
The National CERT generally falls within the application of the private law.
Therefore, General Data Protection Regulation applies for any data processing
conducted by it. This situation is not so clear in the case of the Government
CERT. The wording of section 41 of the proposal of Personal Data Processing Act
states that the provisions in question are to be used when there is processing of
personal data for “the purpose of defence and security interests of the Czech
Republic”. However, the explanatory report to the proposal mentions only duties
of intelligence services, the army and during crises. Therefore, it is not entirely clear
whether processing of personal data conducted by the Government CERT during
fulfilling of its duties should be covered by the third part of the proposed act.
6 Remedies and Sanctions
The overall regulatory philosophy of the GDPR has changed, compared to previous
legislation, from liability to compliance. The GDPR lays down, besides mere
protective obligations, a system of various regulatory instruments designed to
61 Section 9 subsection 3 of the act No. 181/2014 Sb., on Cybersecurity. The relationship of data
protection and cybersecurity was in analysed in e.g. Harašta and Míšek (2015), pp. 21–42
(in Czech). For more information on Czech legislative approach to cybersecurity see (in Czech)
e.g. Polčák 2015, pp. 95–149.
150
R. Polčák et al.
