Czechia

EU member roped into Europol, Schengen and Prüm data exchange and courted by the NSA for a Third Party SIGINT relationship, with all its traffic transiting DE-CIX where the BND taps cables

← Back to Privacy Law Directory

Overview

EU Member State: Czechia is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page.

Czechia’s privacy landscape is shaped by its post-communist transformation and deep institutional memory of StB secret police surveillance. The 1991 lustration law barred former StB collaborators from public office, among the most sweeping decommunisation measures in Central Europe. Three intelligence services (BIS, ÚZSI, VZ) were created after StB dissolution, deliberately preventing concentration of intelligence power. Despite formal constraints, the 2013 Nagyová/Nečas scandal revealed military intelligence was used to surveil the PM’s wife. NSA documents describe pursuit of a Third Party SIGINT relationship with Czech intelligence. GRU Unit 29155 was identified as responsible for the 2014 Vrbětice ammunition depot explosions.[1][2]

Czechia’s outward data-sharing runs through its alliances and treaties, each detailed below. It is an NSA Tier B partner (pursued as a Third Party SIGINT relationship, targetable by NSA collection) and a NATO member (since 1999), and its services take part in the Club de Berne intelligence forum, its Counter-Terrorism Group, and Visegrad Group (V4) cooperation; it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks and to Europol and the European Investigation Order, and holds a bilateral mutual legal assistance treaty with the United States. These are the channels through which the domestic protections described below are, in practice, bypassed.[11][12][13][14][15]

International Data Sharing Agreements

Mutual Legal Assistance

EU Member States (26 countries): Czechia cooperates with the other EU states through the EU Convention on Mutual Assistance in Criminal Matters (2000), the Schengen Convention, and the European Investigation Order, which enables binding cross-border evidence requests.

European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols apply between Czechia and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[11]

Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Czechia is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[12]

Bilateral MLAT with the United States: Signed February 4, 1998, in force May 7, 2000. Supplemented by the EU-US MLAT Enhancement (2010). Czechia also maintains bilateral MLA agreements with countries from the former Czechoslovak treaty network; the full set is searchable in the Ministry of Foreign Affairs’ treaty database (Vyhledávání smluv).[9]

Intelligence Cooperation

NATO member since March 1999 (first post-Cold War expansion with Poland and Hungary). Czechia’s services participate in the Club de Berne and its Counter-Terrorism Group (CTG); the Club de Berne keeps no public roster, but it is reported to comprise the intelligence services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland, with the United Kingdom also reported as a member; the CTG comprises the same services plus the United Kingdom.[16] Visegrad Group (V4) intelligence cooperation with Poland, Hungary, and Slovakia. NSA Tier B partner.[10]

EU and Multilateral Frameworks

SIS II: Real-time query and alert sharing across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[13] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange; the framework binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[14] EU-US Umbrella Agreement. SWIFT/TFTP. PNR. Interpol I-24/7. Egmont Group (Czech FAU). Cross-border police cooperation with Germany.

Europol

As an EU member state, Czechia is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Czech person data flowing through Europol is reachable onward.[15]

The Privacy Backdoor Effect

Despite GDPR enforcement and post-StB oversight reforms, alternative access exists:

Surveillance and Intelligence

Three Intelligence Services

BIS (domestic security): Reports to PM, no executive powers (cannot detain/arrest), surveillance requires High Court chairman authorisation. ÚZSI (foreign civilian): Under Ministry of Interior, HUMINT and SIGINT abroad. VZ (military): Under Ministry of Defence, integrating intelligence and counterintelligence (IMINT, HUMINT, SIGINT, OSINT). Oversight: Chamber of Deputies Standing Commission, five-member Independent Oversight Body (since 2018), and judicial warrant requirements.[4]

Nagyová/Nečas Scandal (2013)

Military intelligence head Jana Nagyová ordered VZ to surveil the PM’s wife using state intelligence resources for personal purposes. PM Nečas resigned June 17, 2013. Nagyová was convicted of abuse of power and ordering unlawful surveillance, confirming that misuse of intelligence tools for personal purposes is criminal under Czech law.[5]

NSA Cooperation

A 2005 NSA SIDtoday document describes the first formal visit to ÚZSI, praising Czech SIGINT professionals as “relatively advanced in FORNSAT collection” with “very good analytic effort against Russian and Ukrainian HF networks” and recommending a Third Party SIGINT relationship. Czechia is listed among countries with Defense Telephone Links to the US. Classified as an NSA Tier B partner.[2]

Vrbětice GRU Explosions (2014)

GRU Unit 29155 agents (the same unit behind the Salisbury nerve agent attack) were identified as responsible for the 2014 Vrbětice ammunition depot explosions. Czech government expelled 18 Russian diplomats in April 2021.[6]

Internet Infrastructure and Transit Exposure

NIX.CZ (Neutral Internet Exchange): 200+ networks, routes two-thirds of Czech domestic traffic, expanded to Bratislava, Vienna, and Frankfurt. Peering.cz across 10 data centres. DE-CIX Prague provides international peering. As a landlocked country, all international traffic transits through Germany (DE-CIX Frankfurt, BND cable interception since 2009) and Austria, exposing Czech traffic to interception outside Czech judicial jurisdiction.[7]

Recent Developments

Supreme Court: Data Retention Violates EU Law (2024–2025): the Supreme Court’s finding that the retention framework violates EU law, with provisions remaining in force pending reform, is detailed under Data Retention above.[8]

NIS2 Cybersecurity Act (2025): Act No. 264/2025 Sb. transposing NIS2, covering ~6,000 entities including critical infrastructure.[3]

CER Critical Infrastructure Act (August 2025): Separate transposition of the CER Directive for physical resilience of critical entities.[3]

Avast Record GDPR Fine (April 2024): ÚOOÚ fined Avast Software for selling user browsing data via subsidiary Jumpshot.[3]

Privacy Framework

The ÚOOÚ (Úřad pro ochranu osobních údajů) enforces the GDPR and Act No. 110/2019 Sb. (Personal Data Processing Act, age of digital consent at 15). Notable: Avast Software record GDPR fine (April 2024) for selling user browsing data via subsidiary Jumpshot. Czechia transposed both the NIS2 and CER Directives in 2025 (see Recent Developments below).[3]

Data Retention

Six-month mandatory retention of traffic and location data (Section 97(3) Electronic Communications Act). Access by police, BIS, VZ, and Czech National Bank. Constitutional Court struck down portions in 2011 as disproportionate; amended provisions adopted 2012. In 2024–2025, the Supreme Court ruled the framework violates EU law, finding it “heads towards preventive retention of virtually all users at all times.” Retention provisions remain in force pending legislative reform.[8]

Pending Legislation

Sources

[1] Wikipedia: StB – Secret police dissolved February 1990, lustration law October 1991
[2] The Intercept: SIDtoday “Czech Mates” – NSA visit to ÚZSI, Third Party SIGINT recommendation
[3] GDPRhub: ÚOOÚ (Czech Republic) – Avast fine, NIS2/CER transposition, Act 110/2019
[4] BIS: Official Website – Domestic security, no executive powers, High Court authorisation
[5] Wikipedia: 2013 Czech Political Crisis – Nagyová convicted, PM Nečas resignation
[6] Wikipedia: Vrbětice Explosions – GRU Unit 29155, 18 Russian diplomats expelled
[7] NIX.CZ – 200+ networks, two-thirds of Czech traffic, expanded to Frankfurt/Vienna
[8] EDRi: Czech Supreme Court Data Retention Ruling – Violates EU law, reform pending
[9] US DOJ: MLATs (April 2022) – US-Czech MLAT signed February 4, 1998, in force May 7, 2000
[10] Wikipedia: Visegrad Group – V4 intelligence cooperation, NATO since 1999
[11] Council of Europe Treaty Office: European Convention on Mutual Assistance in Criminal Matters (ETS No. 30) – Chart of signatures and ratifications; 51 parties as of July 2026 (all 46 Council of Europe member states plus Chile, Israel, Mongolia, the Republic of Korea and Russia), Czechia among them
[12] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026 (45 Council of Europe member states plus 37 non-member states), Czechia among them
[13] European Commission: Schengen Area – The 29 states of the Schengen Area (all EU members except Ireland and Cyprus, plus the non-EU associates Iceland, Liechtenstein, Norway and Switzerland; Bulgaria and Romania became full members January 1, 2025), Czechia among them
[14] Wikipedia: Prüm Convention – The Prüm framework for automated DNA, fingerprint and vehicle-data exchange; binds all 27 EU member states plus the non-EU Schengen associates Iceland, Liechtenstein, Norway and Switzerland (31 in all); Prüm II (2024) adds facial images and police records
[15] Europol: Operational Agreements – Europol is constituted by the 27 EU member states (Czechia among them) and maintains operational cooperation agreements permitting exchange of personal data with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, the United States) plus Denmark under a separate agreement, and with Eurojust, Frontex and Interpol
[16] about:intel: The Club de Berne – The voluntary intelligence-sharing forum (no public membership roster) reported to comprise the intelligence services of the 27 EU member states plus Norway and Switzerland, with the United Kingdom also reported; its Counter Terrorism Group (CTG) comprises the same services plus the UK; Czechia’s services are participants
← Back to Privacy Law Directory