Business obligations, registers and licences · Czechia and Slovakia

GDPR and personal data protection

We set up data protection for your business or online store under GDPR and Slovak Act No. 18/2018 Z. z., from a processing audit through policies, consent and cookies to processor agreements. Practical and tailored to your business, rather than a hundred pages nobody will use.

  • For businesses and online stores
  • Cookies under Act 452/2021
  • Prices agreed upfront
5.0 of 70 reviews on Google

What we'll do for you

A GDPR setup for Czech and Slovak businesses, from analysis to complete documentation ready for use.

Select an item to see the details.

  • Initial consultation and analysis

    We map the data you process, the purposes, recipients and weak points.

  • GDPR documentation

    Privacy policies, records of processing activities and internal rules tailored to your company.

  • Consent and information obligations

    Appropriate legal bases, consent where genuinely required and information for data subjects.

  • Cookies and the website

    A cookie banner and consent arrangements under Act No. 452/2021 Z. z. on Electronic Communications, aligned with the website's actual configuration.

  • Processor agreements

    Data processing agreements with accountants, marketing agencies, cloud providers and others who access the data.

  • Data protection impact assessment (DPIA)

    If you plan processing that poses a high risk to data subjects, such as large-scale monitoring, profiling or sensitive data processing, we prepare the data protection impact assessment required by GDPR.

  • Handover and guidance

    We hand over documentation ready for use and explain how to apply it in practice. On request, we add separate team training on handling personal data.

Deliverablecomplete GDPR documentation ready to implement

How it works

Does this process fit your matter? Describe it to the attorney →

  1. Analysisday 0

    We establish what you process, why and where the risks lie, and determine the scope of work accordingly.

  2. Documentation

    We prepare tailored documentation, consents and agreements and align them with your website and processes.

  3. Implementation and guidanceat your convenience

    We help put the documents into practice and explain to the team how to handle the data.

within 24 h We respond within 24 hours of your enquiry with the next steps and a price. You pay nothing before then.
CZ and SK GDPR under Slovak and Czech rules handled by one firm, with a lawyer admitted to both the Czech and Slovak Bars.
practical Documentation you will actually use, rather than a package that ends up in a drawer.

No-obligation enquiry

Ready to start?

Send us an enquiry. We reply within 24 hours with a price confirmation and next steps. The first 30-minute consultation is free and commits you to nothing.

  1. 1Send your enquiry via this form
  2. 2Within 24 h you get a price confirmation and plan
  3. 3We start work only after your approval
Mgr. Patrik Tulinský, LL.M. Czech and Slovak attorney · SAK 300422 · ČAK 19654

Not keen on calls or email? Message us on WhatsApp →
Prefer to book a time right away? Book a consultation →
Or email us about this matter.

For our conflict-of-interest check.
Add details such as deadline, documents and attachments (optional)
Is a deadline running?
Anything served by a court or authority gets priority.
Documents for this matter
Tick what you have at hand. We will fill in the rest together.
PDF, Word, images, ZIP… max 10 MB per file, 30 MB total.

Submitting this form does not create an engagement or attorney-client relationship. Before taking on a matter we run a conflict-of-interest check, so please do not send sensitive originals until we confirm the matter together.

What clients ask

Didn’t find your question? Ask us directly →

Who does GDPR apply to?

In practice, almost every business processing personal data, including information about customers, employees or suppliers. The activity matters, not the size of the company. Even a small online store or sole trader with a client database has obligations under GDPR and Act No. 18/2018 Z. z.

Do cookies require consent?

Under Act No. 452/2021 Z. z., storing cookies and similar technologies that are not necessary for the website to function, particularly analytics and marketing cookies, requires demonstrable visitor consent. Necessary cookies do not require consent. We configure the banner to match the website's actual behaviour.

Must I have a data protection officer (DPO)?

A DPO is required particularly for large-scale systematic monitoring, large-scale processing of special categories of data and public authorities. Most ordinary businesses do not need one. We assess your activities and recommend a solution.

When do I need a data protection impact assessment (DPIA)?

When planned processing is likely to result in a high risk to data subjects' rights, typically systematic large-scale monitoring, such as extensive CCTV systems, large-scale processing of sensitive data or automated profiling with legal effects. We assess whether the requirement applies during the initial analysis and, if so, prepare the DPIA as part of the documentation.

What happens if GDPR is breached?

The Regulation permits fines of up to twenty million euros or 4% of worldwide annual turnover, whichever is higher. In practice, the authority often first seeks remedial action, but properly prepared documentation is the best defence during an inspection or complaint.

Do I need a processor agreement?

Yes, if someone processes data for you — an accountant, marketing agency, cloud provider or email marketing provider. You need a personal data processing agreement with all such parties. We prepare agreements or review those presented to you.

How long does a GDPR setup take?

For an ordinary business or online store, generally days to weeks depending on the complexity of processing. After the initial analysis, we explain the precise scope and estimated duration and confirm the price in advance.

Legal Q&A

Common questions on this topic

Request a GDPR audit