Czechia
EU member roped into Europol, Schengen and Prüm data exchange and courted by the NSA for a Third Party SIGINT relationship, with all its traffic transiting DE-CIX where the BND taps cables
Overview
EU Member State: Czechia is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page.
Czechia’s privacy landscape is shaped by its post-communist transformation and deep institutional memory of StB secret police surveillance. The 1991 lustration law barred former StB collaborators from public office, among the most sweeping decommunisation measures in Central Europe. Three intelligence services (BIS, ÚZSI, VZ) were created after StB dissolution, deliberately preventing concentration of intelligence power. Despite formal constraints, the 2013 Nagyová/Nečas scandal revealed military intelligence was used to surveil the PM’s wife. NSA documents describe pursuit of a Third Party SIGINT relationship with Czech intelligence. GRU Unit 29155 was identified as responsible for the 2014 Vrbětice ammunition depot explosions.[1][2]
Czechia’s outward data-sharing runs through its alliances and treaties, each detailed below. It is an NSA Tier B partner (pursued as a Third Party SIGINT relationship, targetable by NSA collection) and a NATO member (since 1999), and its services take part in the Club de Berne intelligence forum, its Counter-Terrorism Group, and Visegrad Group (V4) cooperation; it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks and to Europol and the European Investigation Order, and holds a bilateral mutual legal assistance treaty with the United States. These are the channels through which the domestic protections described below are, in practice, bypassed.[11][12][13][14][15]
International Data Sharing Agreements
Mutual Legal Assistance
EU Member States (26 countries): Czechia cooperates with the other EU states through the EU Convention on Mutual Assistance in Criminal Matters (2000), the Schengen Convention, and the European Investigation Order, which enables binding cross-border evidence requests.
European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols apply between Czechia and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[11]
Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Czechia is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[12]
Bilateral MLAT with the United States: Signed February 4, 1998, in force May 7, 2000. Supplemented by the EU-US MLAT Enhancement (2010). Czechia also maintains bilateral MLA agreements with countries from the former Czechoslovak treaty network; the full set is searchable in the Ministry of Foreign Affairs’ treaty database (Vyhledávání smluv).[9]
Intelligence Cooperation
NATO member since March 1999 (first post-Cold War expansion with Poland and Hungary). Czechia’s services participate in the Club de Berne and its Counter-Terrorism Group (CTG); the Club de Berne keeps no public roster, but it is reported to comprise the intelligence services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland, with the United Kingdom also reported as a member; the CTG comprises the same services plus the United Kingdom.[16] Visegrad Group (V4) intelligence cooperation with Poland, Hungary, and Slovakia. NSA Tier B partner.[10]
EU and Multilateral Frameworks
SIS II: Real-time query and alert sharing across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[13] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange; the framework binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[14] EU-US Umbrella Agreement. SWIFT/TFTP. PNR. Interpol I-24/7. Egmont Group (Czech FAU). Cross-border police cooperation with Germany.
Europol
As an EU member state, Czechia is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Czech person data flowing through Europol is reachable onward.[15]
The Privacy Backdoor Effect
Despite GDPR enforcement and post-StB oversight reforms, alternative access exists:
- NSA Tier B: Third Party SIGINT relationship pursued; Czech persons targetable by NSA
- DE-CIX transit: Landlocked; all international traffic through German/Austrian surveillance infrastructure
- EU Framework: Czech data in SIS II, Prüm, EIO accessible to 27 EU states and through Europol to US FBI
- MLAT/CoE Conventions: the US (1998 bilateral treaty), the 51 parties to the 1959 Convention and the 82 parties to the Budapest Convention can request data through MLA channels
- Vrbětice precedent: GRU operations on Czech soil demonstrated foreign intelligence willingness to operate physically within Czech jurisdiction
- SWIFT/PNR: Financial and travel data subject to US access
Surveillance and Intelligence
Three Intelligence Services
BIS (domestic security): Reports to PM, no executive powers (cannot detain/arrest), surveillance requires High Court chairman authorisation. ÚZSI (foreign civilian): Under Ministry of Interior, HUMINT and SIGINT abroad. VZ (military): Under Ministry of Defence, integrating intelligence and counterintelligence (IMINT, HUMINT, SIGINT, OSINT). Oversight: Chamber of Deputies Standing Commission, five-member Independent Oversight Body (since 2018), and judicial warrant requirements.[4]
Nagyová/Nečas Scandal (2013)
Military intelligence head Jana Nagyová ordered VZ to surveil the PM’s wife using state intelligence resources for personal purposes. PM Nečas resigned June 17, 2013. Nagyová was convicted of abuse of power and ordering unlawful surveillance, confirming that misuse of intelligence tools for personal purposes is criminal under Czech law.[5]
NSA Cooperation
A 2005 NSA SIDtoday document describes the first formal visit to ÚZSI, praising Czech SIGINT professionals as “relatively advanced in FORNSAT collection” with “very good analytic effort against Russian and Ukrainian HF networks” and recommending a Third Party SIGINT relationship. Czechia is listed among countries with Defense Telephone Links to the US. Classified as an NSA Tier B partner.[2]
Vrbětice GRU Explosions (2014)
GRU Unit 29155 agents (the same unit behind the Salisbury nerve agent attack) were identified as responsible for the 2014 Vrbětice ammunition depot explosions. Czech government expelled 18 Russian diplomats in April 2021.[6]
Internet Infrastructure and Transit Exposure
NIX.CZ (Neutral Internet Exchange): 200+ networks, routes two-thirds of Czech domestic traffic, expanded to Bratislava, Vienna, and Frankfurt. Peering.cz across 10 data centres. DE-CIX Prague provides international peering. As a landlocked country, all international traffic transits through Germany (DE-CIX Frankfurt, BND cable interception since 2009) and Austria, exposing Czech traffic to interception outside Czech judicial jurisdiction.[7]
Recent Developments
Supreme Court: Data Retention Violates EU Law (2024–2025): the Supreme Court’s finding that the retention framework violates EU law, with provisions remaining in force pending reform, is detailed under Data Retention above.[8]
NIS2 Cybersecurity Act (2025): Act No. 264/2025 Sb. transposing NIS2, covering ~6,000 entities including critical infrastructure.[3]
CER Critical Infrastructure Act (August 2025): Separate transposition of the CER Directive for physical resilience of critical entities.[3]
Avast Record GDPR Fine (April 2024): ÚOOÚ fined Avast Software for selling user browsing data via subsidiary Jumpshot.[3]
Privacy Framework
The ÚOOÚ (Úřad pro ochranu osobních údajů) enforces the GDPR and Act No. 110/2019 Sb. (Personal Data Processing Act, age of digital consent at 15). Notable: Avast Software record GDPR fine (April 2024) for selling user browsing data via subsidiary Jumpshot. Czechia transposed both the NIS2 and CER Directives in 2025 (see Recent Developments below).[3]
Data Retention
Six-month mandatory retention of traffic and location data (Section 97(3) Electronic Communications Act). Access by police, BIS, VZ, and Czech National Bank. Constitutional Court struck down portions in 2011 as disproportionate; amended provisions adopted 2012. In 2024–2025, the Supreme Court ruled the framework violates EU law, finding it “heads towards preventive retention of virtually all users at all times.” Retention provisions remain in force pending legislative reform.[8]
Pending Legislation
- Data-retention reform: after the 2024–2025 Supreme Court ruling that the Section 97(3) blanket-retention framework violates EU law, the provisions remain in force pending a reform that would narrow retention toward targeted/quick-freeze models consistent with CJEU case law. No replacement has been enacted.[8]
- NIS2 secondary measures: implementing decrees under Act No. 264/2025 Sb. (and the CER Act 266/2025) continue to be issued by NÚKIB, defining obligations for the ~6,000 in-scope entities.[3]
- EU AI Act implementation: Czechia must designate AI market-surveillance authorities and adopt implementing rules; legislation is pending.
