Chat on WhatsApp

ÚOOÚ + GDPR + cookie banner, what’s required for a Czech store?

GDPR applies in Czechia, enforced by the ÚOÓÚ (Úřad pro ochranu osobních údajů, the Czech Data Protection Authority). The national implementation is Act No. 110/2019 Sb. on personal-data processing.

Concrete Magento checklist:

  • Cookie consent, opt-in for non-essential cookies (analytics, marketing, retargeting). No pre-ticked checkboxes. “Reject all” must be as easy as “Accept all”. Banner in Czech. We typically ship Cookiebot, Cookieyes, or a self-built Magento module wired into the Magento cookie API.
  • Privacy policy in Czech, citing ÚOÓÚ as the supervisory authority, plus the controller’s IČO + DIČ + registered address.
  • Newsletter double opt-in, tick-box on registration is not enough, customer must click a confirmation email.
  • Right-to-access + right-to-erasure, customer account page should expose data download + deletion request flows.
  • Data Processing Agreement with hosting + email + payment providers. Adobe Commerce Cloud Frankfurt is fine for data residency; for ÚOÓÚ-conscious clients, WEDOS / Forpsi / Active 24 (all CZ-based) is the safer optics.
  • Heureka pixel + Google Analytics only fire after consent, we wire Tag Manager conditional triggers.
Was this helpful?