The reason for such modesty in charging was mostly that the breaches of
protection that the Czech DPA was able to fully investigate were of minor relevance.
It was also not rare that the Czech DPA was often, mostly for being understaffed and
subject to political pressures in appointing senior officials (the Inspectors), not able
to establish solid cases against controllers or processors acting in breach of obligations. Low fines were in these cases used to avoid respective decisions being
challenged in judicial review, as it was not economically reasonable for affected
controllers or processors to invest in court litigation against fines worth near to
nothing.
The same are the reasons for which there had been for long time almost missing
relevant Czech court case law. As there had been neither real fear of sanctions nor
reasons for establishment of court cases, there also had been almost missing professional legal expertise. That led to critical shortage of legal experts in the wake of the
GDPR when there emerged a massive market of compliance solutions.
Member states are allowed by Art. 83(7) of the GDPR to legislate specific
limitations of fines charged to public sector bodies. In that respect, it is questionable
whether there applies current limitation of 10 mil. CZK laid down in Czech Act
No. 101/2000 Sb. that is still in force (despite it was substantially materially
derogated by the GDPR—see above). In any case, the same limit of max. 10 mil.
EUR for public sector bodies is now drafted in the pending Personal Data Processing
Act (see above).
Distinction of fines between public sector bodies and other controllers and processors have been recently broadly debated in the Czech Republic. Especially
smaller self governing units, such as towns, feel threatened by limits specified in
Art. 83 of the GDPR. At the same time, specific limitations for public sector bodies
might create unreasonable inequalities and might lead to paradoxical situations, e.g.
in cases when a private establishment acts as a personal data processor for a
controller who is a public sector body. In such cases, that are not rare in the practice
of Czech public sector bodies of all sizes, a controller who sets the purpose of
processing of personal data and gives orders to the processor would be subject to
sanctions theoretically amounting only to a fraction of limits that would apply to the
processor.
Besides administrative fines and corrective measures, there are also available
standard court remedies for material damage or immaterial harm. Material damage is
covered with damages (náhrada škody), while immaterial harm is covered with
satisfactory damages (zadosti učinění).
The court procedure of claiming damages or satisfactory damages depends on the
nature of respective controller or processor. If a controller or processor causes
damage or harm as a public authority acting in its public law capacity, remedies
might be sought through administrative court procedure (Act No. 150/2002 Sb.)
upon the liability for illegal acting of a public body (Act No. 82/1998 Sb.) In all other
cases, data subjects can sue upon standard rules of civil procedure (Act. No. 99/1963
152
R. Polčák et al.
Précédent

- 161/540

Suivant