Running commentary · living document · revised 7 July 2026
GDPR
Regulation (EU) 2016/679 on the protection of personal data. What it does, how the
obligations fit together, and a commentary on each of the 99 articles, with the full
text alongside. The article text here is the official English from EUR-Lex; the
citations are held against the source, not against second-hand summaries.
TL;DR
The GDPR unifies the protection of personal data across the EU and reaches even
businesses outside the Union that target people within it. It rests on the principles
in Art. 5 (lawfulness, minimisation, accountability), the six legal bases in Art. 6,
and the catalogue of data-subject rights, from access through erasure to objection.
It imposes compliance that can be demonstrated: records of processing, security, breach
notification within 72 hours, an impact assessment for risky processing, and, where
relevant, a DPO. Transfers outside the EU only through the conditions of Chapter V.
Supervision in the Czech Republic is carried out by the ÚOOÚ, and fines reach up to
EUR 20 million or 4% of worldwide turnover. It applies from 25 May 2018.
The route to compliance
A nine-step compliance guide exists as a Czech-jurisdiction resource, written around
the Czech adaptation Act No. 110/2019 Sb. It is only in Czech:
the route to compliance (in Czech) walks from mapping the
data through legal bases, the duty to inform and records to incidents and demonstrating
compliance, in nine steps, with a template linked at each one.
What the Regulation is about
The GDPR is directly applicable across the Union and technology-neutral. It does not
say what software you may run; it says on what conditions you may process data about
people, and it wants you to be able to demonstrate compliance at any time (the
accountability principle). The approach is risk-based: the more sensitive and extensive
the processing, the more obligations accrue, from records through the impact assessment
to prior consultation with the supervisory authority. The Czech Republic accompanied
the Regulation with Act No. 110/2019 Sb., which designated the ÚOOÚ, lowered the age of
a child's consent to 15 years, and used the opening clauses.
The mechanics of the obligations rest on a pair of roles. The controller determines the
purposes and means and bears the main responsibility; the processor works for it under
a contract pursuant to Art. 28. Around that the obligation chain of Chapter IV is
layered: data protection by design and by default, records of activities, security,
notifying a breach to the authority within 72 hours and, where the risk is high, to the
people affected too, the impact assessment (DPIA), and a DPO wherever Art. 37 requires
one.
Data subjectthe person the data is about
the controller informs (Art. 13 and 14)the data subject exercises rights (Art. 15 to 22)
Controllerdetermines the purposes and means
contract and instructions (Art. 28)processes only for the controller
Processoracts on the controller's instructions
breach notified within 72 hours (Art. 33)
Supervisory authorityin the Czech Republic, the ÚOOÚ
A complaint under Art. 77 goes from the data subject straight to the supervisory authority; compensation under Art. 82 goes to a court.
The second half of the Regulation is about enforcement. The data subject has the
catalogue of rights in Chapter III and three ways to press them: a free complaint to
the ÚOOÚ, an action against the controller, and a claim for compensation for material
and non-material damage under Art. 82. Cross-border cases are run by the lead
supervisory authority under the one-stop-shop, and disputes between authorities are
decided bindingly by the European Data Protection Board.
For this site the GDPR is interesting as a template too. The AI Act follows it with a
similar regulatory logic. It shares extraterritoriality, protection by design and impact
assessment (the parallel between the DPIA and the FRIA), and the logic of Art. 22 on
automated decision-making has its counterpart in the right to an explanation under
Art. 86 of the AI Act. The two regulations layer: an AI system that processes personal
data satisfies both. The comparison runs on the AI Act card (in Czech).
Key parameters
27 April 2016
Adoption of the Regulation; it entered into force on the twentieth day after publication in the Official Journal.
25 May 2018
Application (Art. 99). From this date the GDPR applies directly and, at EU level, replaced Directive 95/46/EC. The Czech Act No. 101/2000 Sb. was not repealed until Act No. 110/2019 Sb., with effect from 24 April 2019.
24 April 2019
The Czech adaptation Act No. 110/2019 Sb., on personal data processing, takes effect. It designates the ÚOOÚ as the supervisory authority, lowers the age of a child's consent to 15 years, and implements the opening clauses.
fines
Two tiers under Art. 83: up to EUR 10 million or 2% of worldwide turnover, and up to EUR 20 million or 4% (the principles, the legal bases, the rights of data subjects, transfers). The higher of the two figures always applies.
Case law in a nutshell
The decisions that the practice of the GDPR actually stands on, one sentence each. The
links lead to the primary sources; the selection also draws on the overviews at the
gdpr.cz portal, and the annotations are my own. For Articles 4, 6, 7, 15, 22, 26, 32,
45, 57 and 82 the same decisions are worked directly into the commentary.
C-582/14 Breyer (2016): a dynamic IP address is personal data where the controller has a legal means to re-identify the person.
C-673/17 Planet49 (2019): a pre-ticked box is not consent; for cookies an active expression of will is required.
C-40/17 Fashion ID (2019): a website with an embedded social-network button is a joint controller for the collection and transmission of visitors' data.
C-311/18 Schrems II (2020): the Privacy Shield is struck down; standard contractual clauses require an assessment and, where needed, additional safeguards.
C-252/21 Meta Platforms (2023): compliance with the GDPR may also be assessed by a competition authority, and personalised advertising without a proper legal basis does not stand.
C-300/21 and C-340/21 (2023): compensation takes more than the infringement alone, yet there is no threshold of seriousness, and the fear of misuse of data after a leak can be enough.
C-579/21 Pankki S (2023): the right of access also covers information on when and why the data was accessed.
C-446/21 Schrems v. Meta and C-621/22 KNLTB (2024): advertising data is subject to minimisation, with no unlimited time or scope, and a legitimate interest can be a purely commercial one.
C-394/23 Mousse (ECLI:EU:C:2025:2, 9 January 2025): the title "Mr" or "Ms" is not necessary for selling a ticket; minimisation applies even to small form fields.
C-416/23 (ECLI:EU:C:2025:3, 9 January 2025): an authority may not shelve complaints because of their number; only manifestly unfounded or excessive ones may be refused.
C-203/22 (ECLI:EU:C:2025:117, 27 February 2025): in automated decision-making a meaningful explanation of the procedure used is owed, and trade secrets are not an absolute bar.
T-354/22 Bindl (ECLI:EU:T:2025:4, 8 January 2025): the General Court ordered the Commission to pay EUR 400 in non-material damage for the unlawful transfer of an IP address to the United States (Regulation 2018/1725, the GDPR's counterpart for the EU institutions).
T-553/23 Latombe (ECLI:EU:T:2025:831, 3 September 2025): the EU–US Data Privacy Framework held before the General Court and the action was dismissed (an appeal has been brought against the judgment).
C-413/23 P EDPS v. SRB (ECLI:EU:C:2025:645, 4 September 2025): whether pseudonymised data is personal data is assessed relatively, by the means available to the particular actor. On appeal the Court of Justice set aside the General Court's judgment and referred the case back, holding that for the controller's duty to inform, identifiability is assessed from the controller's standpoint at the moment of collection (Regulation 2018/1725, the GDPR's counterpart for the EU institutions).
C-97/23 P WhatsApp (ECLI:EU:C:2026:81, 10 February 2026): a binding decision of the European Data Protection Board can be challenged directly before the EU courts (the Court of Justice dealt with admissibility; the General Court will decide the merits).
The Regulation comes with paperwork. A set of templates written from scratch against the
text of the Regulation covers the controller's basic documentation (clause, records,
policy, processor contract, balancing test), consents, the DPO, personal data breaches,
handling requests and letters to data subjects. They are a Czech-jurisdiction resource,
in Czech: all 35 templates → (in Czech)
Article-by-article commentary
All 99 articles by chapter, each with a short commentary. Open an article and inside
there is the full text as well. The commentary deepens as it goes.
Chapter I · Art. 1–4
General provisions
The purpose, which processing the Regulation covers, how far it reaches, and the glossary of terms.
A twofold purpose: the protection of natural persons when personal data is processed, and the free movement of data within the Union. Both sides of the coin are used in interpretation; protection is not an end in itself and must not become a barrier to the internal market.
It covers wholly or partly automated processing and the manual processing of data held in a filing system. Outside its scope are purely personal or household activity, activity outside the scope of Union law, and the criminal-law field (covered by Directive (EU) 2016/680, in the Czech Republic Title III of Act No. 110/2019 Sb.).
Territorial scope. Besides establishment in the EU, it also reaches controllers in third countries who offer goods or services to people in the EU or monitor their behaviour. The extraterritorial template later taken over by the AI Act in Art. 2.
A glossary of 26 definitions. Personal data is drawn broadly (identifiability, even indirect, is enough), and processing is practically any operation on data. The key split is between the controller (who determines the purposes and means) and the processor (who processes for the controller); the whole Regulation's allocation of duties hangs on it. A dynamic IP address is personal data where the controller has a legal means to re-identify the person (C-582/14 Breyer), and whether pseudonymised data is personal data is judged relatively, by the means available to the particular actor (C-413/23 P EDPS v. SRB).
Chapter II · Art. 5–11
Principles
The most-cited part of the Regulation. The principles of processing, the legal bases, and the special regimes for sensitive data.
Seven principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and over them all accountability, the duty not only to comply but to be able to demonstrate it. A breach of the principles sits in the top fine tier of Art. 83(5).
Six legal bases: consent, contract, legal obligation, vital interests, public interest and legitimate interests. Legitimate interests requires a balancing test against the rights of the data subject. Paragraph 4 deals with the compatibility of a new purpose with the original one. The first question in any analysis of processing is which basis it rests on. A legitimate interest can be a purely commercial one (C-621/22 KNLTB), yet Meta's personalised advertising could not rest on it, and a breach of the Regulation may also be assessed by a competition authority (C-252/21 Meta Platforms).
Consent must be demonstrable, clearly separated from other matters, and as easy to withdraw as it was to give. Paragraph 4 targets coerced consent: performance of a contract must not be conditional on consent that the performance does not need. A pre-ticked box is not consent (C-673/17 Planet49).
A child's consent for information-society services. The default threshold is 16 years, and States may lower it to 13. The Czech Republic lowered it to 15 years (§ 7 of Act No. 110/2019 Sb.).
Special categories (health, biometrics for identification, beliefs, orientation and others) may in principle not be processed unless one of ten exceptions applies, among them explicit consent, employment and social law, vital interests, health care or public health.
Data on convictions and criminal offences may be processed only by a public authority, or by anyone else only on the basis of a law providing appropriate safeguards.
A controller need not acquire additional identifying data just to comply with the Regulation. If it cannot identify the data subject, the rights under Art. 15 to 20 do not apply, unless the data subject supplies the identification themselves.
Chapter III · Art. 12–23
Rights of the data subject
The catalogue of rights that requests, complaints and disputes rest on.
The modalities for exercising rights. Communication is to be concise, intelligible and free of charge; the reply comes without undue delay and within one month at the latest, extendable by two months for complex requests. Manifestly unfounded or excessive requests may be refused or charged for, and the burden of proof is on the controller.
The information to be provided where data is obtained directly from the data subject: the identity of the controller, the purposes and legal bases, the recipients, the storage period, the rights, and any automated decision-making. The basis of every privacy notice.
The same for data obtained elsewhere, with the source and the categories of data added, within one month or at the first contact. Exceptions apply, among others, for disproportionate effort in archiving and research.
The right of access: confirmation that processing is taking place, information about it, and a copy of the data being processed. The copy must not adversely affect the rights of others. In practice the most frequently exercised right and the gateway to disputes. The data subject has the right to know when and why their data was accessed (C-579/21 Pankki S), and in automated decision-making to receive a meaningful explanation of the procedure used, with trade secrets not being an absolute bar (C-203/22).
The right to erasure where the purpose has fallen away, consent has been withdrawn, an objection has succeeded, or the processing was unlawful. Exceptions for freedom of expression, legal obligations, public health, archiving, and the establishment, exercise or defence of legal claims. For data that has been made public, a duty to inform other controllers is added.
Portability: the data provided by the data subject in a machine-readable format, and where feasible transmitted directly to another controller. Only for processing based on consent or contract and carried out by automated means.
An objection to processing based on legitimate or public interest: the controller must demonstrate compelling legitimate grounds, otherwise it must stop. Against direct marketing the objection is absolute; after it the processing must cease.
The right not to be subject to a decision based solely on automated processing with legal or similarly significant effects, subject to exceptions (contract, legal basis, explicit consent) and safeguards including human intervention. According to the CJEU judgment in C-634/21 SCHUFA (7 December 2023), an automated credit-scoring assessment is already such a decision where a third party draws on it decisively for its own decision. The forerunner of Art. 86 of the AI Act, which addresses the same situation from the procedural side.
Member States and the Union may restrict the rights by law for listed interests (security, criminal proceedings, the administration of justice and others), only to the extent necessary.
Chapter IV · Art. 24–43
Controller and processor
The core of the obligations for businesses. Accountability, processor contracts, records, security, incidents, the DPIA and the DPO.
The responsibility of the controller: to put in place appropriate technical and organisational measures according to the nature and risks of the processing, and to be able to demonstrate them. The risk-based approach that then returns in Art. 25, 32 and 35.
Data protection by design and by default. Data protection is built into the design of systems, and the default settings process only the necessary minimum. The sister principle to the design requirements in the AI Act.
Joint controllers allocate their duties by an arrangement and make the essence of it available to data subjects. The data subject may exercise their rights against any of them, and the arrangement does not bind anyone externally. A website operator who embeds a social-network button that collects visitors' data is also a joint controller (C-40/17 Fashion ID).
A processor acts only under a contract with the mandatory content of paragraph 3: the controller's instructions, confidentiality, security, the conditions for engaging sub-processors, cooperation, erasure or return at the end, and audit rights. The most frequently reviewed contract type in the whole Regulation.
Records of processing activities for both controllers and processors. The exemption for organisations under 250 employees is full of holes (it does not apply to non-occasional processing, to risk, or to special categories), so in practice almost everyone keeps records.
Security appropriate to the risk, with pseudonymisation and encryption expressly named, the ability to ensure confidentiality, integrity, availability and resilience, recovery after an incident, and regular testing of the effectiveness of the measures. A successful hacker attack does not in itself mean the measures were inappropriate; appropriateness is judged against the risk (C-340/21).
A personal data breach is notified to the supervisory authority without undue delay, where feasible within 72 hours, unless the risk to people's rights is unlikely. A processor notifies the controller without undue delay. Internal records of all breaches are mandatory in every case, including those not notified.
Where the risk to people is high, the breach is communicated to them too, in clear terms and with recommendations. Exceptions apply where there was effective protection (encryption), where subsequent measures were taken, or where it would take disproportionate effort (then a public communication).
A data protection impact assessment (DPIA) before processing that is likely to be high-risk, typically a systematic and extensive evaluation of people including profiling, large-scale processing of special categories, or systematic monitoring of public areas. The ÚOOÚ maintains a list of operations that always require a DPIA. The methodological forerunner of the FRIA in Art. 27 of the AI Act.
Where a DPIA shows a high residual risk that the controller cannot mitigate, it goes to the supervisory authority for prior consultation before processing.
A data protection officer is mandatory for public authorities, for large-scale regular and systematic monitoring, and for large-scale processing of special categories. There may be one for a group, and the DPO may be internal or external.
The position of the DPO: involvement in all data protection matters, resources, independence (no instructions on how to perform the role, no dismissal for performing it) and direct access to top management.
The tasks of the DPO: to inform and advise, monitor compliance, advise on the DPIA, and act as the contact point for the authority and for data subjects.
The general principle: a transfer outside the EU only where the conditions of Chapter V are met, including for onward transfers. The level of protection must not be undermined by the transfer.
A transfer on the basis of a Commission adequacy decision, in which case no specific authorisation is needed. For the United States the current decision is the one for the EU–US Data Privacy Framework. History shows that such decisions fall at the Court of Justice (C-311/18 Schrems II), while the current framework has so far held before the General Court (T-553/23 Latombe).
Without an adequacy decision, appropriate safeguards step in, most often the Commission's standard contractual clauses, and further binding corporate rules, approved codes or certifications.
Binding corporate rules (BCR) for transfers within a group, with their required content and approval by the supervisory authority through the consistency mechanism.
A judgment or decision of a third-country authority does not by itself justify a transfer; it is recognised only on the basis of an international agreement. A safeguard against foreign orders being enforced directly against European data.
Derogations for specific situations: explicit consent after being warned of the risks, necessity for a contract, legal claims, vital interests and others. They are read narrowly, as a last resort, not a routine channel.
Each State sets up an independent supervisory authority. In the Czech Republic this is the Úřad pro ochranu osobních údajů (Office for Personal Data Protection, ÚOOÚ) under Act No. 110/2019 Sb.
The authority's members are appointed transparently, with qualifications required and safeguards against dismissal on grounds other than those set by law.
The lead supervisory authority, determined by the controller's main establishment, handles cross-border cases (the one-stop-shop). One point of contact for data subjects, one main counterpart for cross-border controllers.
A catalogue of tasks: to monitor and enforce, raise awareness, handle complaints, cooperate, keep the DPIA lists and more. Handling complaints is free of charge. A high number of complaints does not relieve the authority of its duty to deal with them; only manifestly unfounded or excessive requests may be refused or charged for (C-416/23).
Powers that are investigative (information, audits, access to premises), corrective (warnings, reprimands, orders, limitation up to a ban on processing, ordering erasure, and fines) and authorising or advisory. A ban on processing can hurt more than a fine.
The mechanics of cooperation between the lead authority and the authorities concerned: draft decisions, relevant and reasoned objections, and referral to the Board where there is disagreement.
Binding dispute resolution by the Board, among other things where there are relevant objections to a lead authority's draft decision. The final word in cross-border cases.
The European Data Protection Board (EDPB), a body of the Union made up of the heads of the national authorities and the European Data Protection Supervisor.
The tasks of the Board: consistent application, guidelines and recommendations (in practice a key source of interpretation), opinions and binding decisions.
The right to lodge a complaint with a supervisory authority, in particular in the place of residence, place of work or place of the infringement. The free and most common entry point into enforcement.
A judicial remedy directly against the controller or processor, independently of a complaint to an authority. Proceedings may be brought where the establishment is or where the data subject resides.
Non-profit bodies may represent the data subject, and (where the State allows it) act even without a mandate. The collective dimension, which the Representative Actions Directive builds on, and to whose annex the AI Act added itself in Art. 110.
The right to compensation for material and non-material damage. The controller is liable for infringements of the Regulation, the processor only for its own specific duties or for going beyond the instructions, jointly and severally with a right of recourse. Exemption only on proof that it is in no way responsible for the damage. An infringement of the Regulation does not by itself found a claim, but the damage need not cross any threshold of seriousness (C-300/21), and the fear of misuse of data after a leak can itself be non-material damage (C-340/21).
Two fine tiers: up to EUR 10 million or 2% of turnover (among others the controller and processor duties in Art. 8, 11, 25 to 39, 42, 43) and up to EUR 20 million or 4% of turnover (the principles, the legal bases, the rights of data subjects, transfers). The criteria in paragraph 2 (nature, intent, mitigation, recidivism, cooperation) are the checklist for arguing about the amount.
Reconciliation with the right to freedom of expression and information: States set exceptions for journalism and academic, artistic and literary expression. In the Czech Republic, § 17 et seq. of Act No. 110/2019 Sb.
An opening clause for the employment context: States may lay down more specific rules for processing in employment relationships (recruitment, performance of the contract, management and termination, monitoring).
Safeguards for archiving in the public interest, scientific and historical research and statistics (minimisation, pseudonymisation) and possible derogations from the rights of data subjects.
Churches and religious associations with comprehensive rules already in place may continue to apply them, provided they bring them into line, under a specific supervision.
Repeal of Directive 95/46/EC; references to it are read as references to the Regulation. Continuity of interpretation, the old case law remains usable where the text carried over.
The relationship to the e-Privacy Directive (2002/58/EC): where ePrivacy imposes specific obligations (cookies, electronic marketing), the GDPR does not add a second round of the same duties.
EDPB Opinion 28/2024 on AI models and personal data (18 December 2024), edpb.europa.eu: the legal basis, model anonymisation, and the liability of the deploying entity.
Act No. 110/2019 Sb., on personal data processing, Zákony pro lidi (in Czech).
gdpr.cz, a practical Czech portal (news, fines, tools; run by TAYLLORCOX), in Czech.