Business obligations, registers and licences · Czechia and Slovakia
GDPR and personal data protection
We set up data protection for your business or online store under GDPR and Slovak Act No. 18/2018 Z. z., from a processing audit through policies, consent and cookies to processor agreements. Practical and tailored to your business, rather than a hundred pages nobody will use.
- For businesses and online stores
- Cookies under Act 452/2021
- Prices agreed upfront
What we'll do for you
A GDPR setup for Czech and Slovak businesses, from analysis to complete documentation ready for use.
Select an item to see the details.
-
Initial consultation and analysis
We map the data you process, the purposes, recipients and weak points.
-
GDPR documentation
Privacy policies, records of processing activities and internal rules tailored to your company.
-
Consent and information obligations
Appropriate legal bases, consent where genuinely required and information for data subjects.
-
Cookies and the website
A cookie banner and consent arrangements under Act No. 452/2021 Z. z. on Electronic Communications, aligned with the website's actual configuration.
-
Processor agreements
Data processing agreements with accountants, marketing agencies, cloud providers and others who access the data.
-
Data protection impact assessment (DPIA)
If you plan processing that poses a high risk to data subjects, such as large-scale monitoring, profiling or sensitive data processing, we prepare the data protection impact assessment required by GDPR.
-
Handover and guidance
We hand over documentation ready for use and explain how to apply it in practice. On request, we add separate team training on handling personal data.
Deliverablecomplete GDPR documentation ready to implement
How it works
Does this process fit your matter? Describe it to the attorney →
- Analysisday 0
We establish what you process, why and where the risks lie, and determine the scope of work accordingly.
- Documentation
We prepare tailored documentation, consents and agreements and align them with your website and processes.
- Implementation and guidanceat your convenience
We help put the documents into practice and explain to the team how to handle the data.
No-obligation enquiry
Ready to start?
Send us an enquiry. We reply within 24 hours with a price confirmation and next steps. The first 30-minute consultation is free and commits you to nothing.
- 1Send your enquiry via this form
- 2Within 24 h you get a price confirmation and plan
- 3We start work only after your approval
Not keen on calls or email? Message us on WhatsApp →
Prefer to book a time right away? Book a consultation →
Or email us about this matter.
What clients ask
Didn’t find your question? Ask us directly →
Who does GDPR apply to?
In practice, almost every business processing personal data, including information about customers, employees or suppliers. The activity matters, not the size of the company. Even a small online store or sole trader with a client database has obligations under GDPR and Act No. 18/2018 Z. z.
Do cookies require consent?
Under Act No. 452/2021 Z. z., storing cookies and similar technologies that are not necessary for the website to function, particularly analytics and marketing cookies, requires demonstrable visitor consent. Necessary cookies do not require consent. We configure the banner to match the website's actual behaviour.
Must I have a data protection officer (DPO)?
A DPO is required particularly for large-scale systematic monitoring, large-scale processing of special categories of data and public authorities. Most ordinary businesses do not need one. We assess your activities and recommend a solution.
When do I need a data protection impact assessment (DPIA)?
When planned processing is likely to result in a high risk to data subjects' rights, typically systematic large-scale monitoring, such as extensive CCTV systems, large-scale processing of sensitive data or automated profiling with legal effects. We assess whether the requirement applies during the initial analysis and, if so, prepare the DPIA as part of the documentation.
What happens if GDPR is breached?
The Regulation permits fines of up to twenty million euros or 4% of worldwide annual turnover, whichever is higher. In practice, the authority often first seeks remedial action, but properly prepared documentation is the best defence during an inspection or complaint.
Do I need a processor agreement?
Yes, if someone processes data for you — an accountant, marketing agency, cloud provider or email marketing provider. You need a personal data processing agreement with all such parties. We prepare agreements or review those presented to you.
How long does a GDPR setup take?
For an ordinary business or online store, generally days to weeks depending on the complexity of processing. After the initial analysis, we explain the precise scope and estimated duration and confirm the price in advance.
Legal Q&A
Common questions on this topic
-
When does the AI Act apply, and who does it cover?
The AI Act applies progressively: the first general provisions and prohibitions from 2 February 2025, rules for general-purpose AI models from 2 August 2025, with 2 August 2026 remaining the general application date. Regulation (EU) 2026/1744, however, postponed Chapter III, Sections 1 to 3, except Article 6(5): until 2 December 2027 for high-risk systems under Annex III and until 2 August 2028 for systems linked to regulated products under Annex I. It covers providers and businesses deploying AI; their specific duties depend on their role and the system.
Read the answer -
What duties apply when I process customers' personal data under the GDPR?
You may process customer personal data only with a valid legal basis, most commonly contract performance, a legal obligation, legitimate interests or consent. Core duties include informing individuals, enabling them to exercise their rights, securing the data appropriately and notifying the supervisory authority of serious breaches without undue delay. The scope depends on what you process and why.
Read the answer -
What must we do to make shop and workplace CCTV lawful?
CCTV is lawful when its legal basis is documented in advance, generally legitimate interests under Article 6(1)(f) GDPR, and everyone entering the monitored area receives the required information. A balancing test comparing your interests with the privacy intrusion must exist before cameras start operating. At work, Section 13(4) of the Labour Code additionally requires prior consultation with employee representatives on the monitoring mechanism and notification to employees.
Read the answer
Further reading
AML amendment: goAML registration by 30 November 2026 and stricter beneficial owner verification
AML amendment Act No. 73/2026 Z. z. has applied since 1 June 2026. Obliged entities must register in the Financial Intelligence Unit’s goAML system by 30 November 2026 and must not rely solely on the register of legal entities when verifying beneficial owners.
Read more →
Conflicts of interest in public procurement: when bidders risk exclusion
A former employee on the contracting authority’s side, a designer included in the bid or personal links to the committee: Public Procurement Office guidance No. 3/2026 explains which connections create conflicts and when exclusion follows. Potential influence, disclosure and mitigation are decisive.
Read more →
MiCA CASP authorisation: preparing your application to NBS
Crypto-asset services in the EU require CASP authorisation, and Slovakia’s transitional period for former crypto trade licences ended on 30 December 2025. Delegated Regulation (EU) 2025/305 defines the NBS application requirements, and subsequent changes restart assessment.
Read more →