{"id":117,"date":"2026-01-20T00:00:00","date_gmt":"2026-01-19T23:00:00","guid":{"rendered":"https:\/\/helloblog.io\/cs\/gdpr-checklist-pro-majitele-webu\/"},"modified":"2026-01-20T00:00:00","modified_gmt":"2026-01-19T23:00:00","slug":"gdpr-checklist-pro-majitele-webu","status":"publish","type":"post","link":"https:\/\/helloblog.io\/cs\/gdpr-checklist-pro-majitele-webu\/","title":{"rendered":"GDPR checklist pro majitele web\u016f: praktick\u00fd a kompletn\u00ed tah\u00e1k (v\u010detn\u011b WordPressu)"},"content":{"rendered":"\n<p>GDPR (General Data Protection Regulation) pat\u0159\u00ed mezi nejtvrd\u0161\u00ed a z\u00e1rove\u0148 nejucelen\u011bj\u0161\u00ed pravidla ochrany soukrom\u00ed na sv\u011bt\u011b. A nen\u00ed to t\u00e9ma jen pro korpor\u00e1ty: i mal\u00fd blog, e\u2011shop nebo SaaS projekt \u0159e\u0161\u00ed osobn\u00ed \u00fadaje (t\u0159eba e\u2011mail, IP adresu, faktura\u010dn\u00ed \u00fadaje, identifik\u00e1tory cookies). Jakmile zpracov\u00e1v\u00e1\u0161 osobn\u00ed \u00fadaje osob v EU, GDPR se t\u011b t\u00fdk\u00e1 \u2013 i kdy\u017e firmu provozuje\u0161 mimo EU.<\/p>\n\n\n\n<p>Riziko nen\u00ed jen teoretick\u00e9. Za poru\u0161en\u00ed pravidel mohou padat pokuty a\u017e do v\u00fd\u0161e <strong>20 milion\u016f EUR nebo 4 % celosv\u011btov\u00e9ho ro\u010dn\u00edho obratu<\/strong> (podle toho, co je vy\u0161\u0161\u00ed). Vedle pokut mohou \u00fa\u0159ady na\u0159\u00eddit omezen\u00ed zpracov\u00e1n\u00ed, v\u00fdmaz dat nebo i z\u00e1kaz ur\u010dit\u00fdch operac\u00ed s daty.<\/p>\n\n\n\n<div class=\"wp-block-group callout callout-warning is-style-warning is-layout-flow wp-block-group-is-layout-flow\" style=\"border-width:1px;border-radius:8px;padding-top:1rem;padding-right:1.5rem;padding-bottom:1rem;padding-left:1.5rem\">\n\n<h4 class=\"wp-block-heading callout-title\">Pozn\u00e1mka k odpov\u011bdnosti<\/h4>\n\n\n<p>Tenhle \u010dl\u00e1nek je praktick\u00fd checklist a pr\u016fvodce implementac\u00ed \u2013 nen\u00ed to pr\u00e1vn\u00ed poradenstv\u00ed. U slo\u017eit\u011bj\u0161\u00edch p\u0159\u00edpad\u016f (profilov\u00e1n\u00ed, citliv\u00e1 data, mezin\u00e1rodn\u00ed p\u0159enosy) d\u00e1v\u00e1 smysl konzultace s pr\u00e1vn\u00edkem nebo specialistou na privacy.<\/p>\n\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Co p\u0159esn\u011b je GDPR (a kdy se t\u011b t\u00fdk\u00e1)<\/h2>\n\n\n\n<p><strong>GDPR<\/strong> je evropsk\u00e9 na\u0159\u00edzen\u00ed o ochran\u011b osobn\u00edch \u00fadaj\u016f \u00fa\u010dinn\u00e9 od <strong>25. kv\u011btna 2018<\/strong>. Definuje pravidla pro to, jak organizace osobn\u00ed \u00fadaje sb\u00edraj\u00ed, pou\u017e\u00edvaj\u00ed, ukl\u00e1daj\u00ed a sd\u00edl\u00ed. Plat\u00ed nejen pro subjekty usazen\u00e9 v EU, ale i pro ty mimo EU, pokud zpracov\u00e1vaj\u00ed osobn\u00ed \u00fadaje rezident\u016f EU.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Nejd\u0159\u00edv si ujasni roli: Controller vs. Processor<\/h2>\n\n\n\n<p>V praxi se hodn\u011b v\u011bc\u00ed l\u00e1me na tom, jestli jsi <strong>Data Controller<\/strong> (spr\u00e1vce) nebo <strong>Data Processor<\/strong> (zpracovatel). A klidn\u011b m\u016f\u017ee\u0161 b\u00fdt oboj\u00ed \u2013 typicky u SaaS, kdy pro vlastn\u00ed marketing vystupuje\u0161 jako spr\u00e1vce, ale pro z\u00e1kazn\u00edka zpracov\u00e1v\u00e1\u0161 data jako zpracovatel.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>Data Controllers (spr\u00e1vci):<\/strong> ur\u010duj\u00ed, <em>pro\u010d<\/em> a <em>jak<\/em> se osobn\u00ed \u00fadaje zpracov\u00e1vaj\u00ed. Nesou hlavn\u00ed odpov\u011bdnost za soulad s GDPR.<\/li>\n\n\n<li><strong>Data Processors (zpracovatel\u00e9):<\/strong> t\u0159et\u00ed strany, kter\u00e9 zpracov\u00e1vaj\u00ed data pro spr\u00e1vce (nap\u0159. hosting, e\u2011mailing, analytika, helpdesk). Mus\u00ed m\u00edt odpov\u00eddaj\u00edc\u00ed technick\u00e1 a organiza\u010dn\u00ed opat\u0159en\u00ed.<\/li>\n\n\n<li><strong>Data Subjects (subjekty \u00fadaj\u016f):<\/strong> fyzick\u00e9 osoby, jejich\u017e \u00fadaje zpracov\u00e1v\u00e1\u0161. GDPR chr\u00e1n\u00ed jejich pr\u00e1va.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">7 princip\u016f GDPR, kter\u00e9 se propisuj\u00ed do v\u0161eho<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li><strong>Z\u00e1konnost, korektnost a transparentnost:<\/strong> zpracov\u00e1vej leg\u00e1ln\u011b a srozumiteln\u011b vysv\u011btli, co s daty d\u011bl\u00e1\u0161.<\/li>\n\n\n<li><strong>\u00da\u010delov\u00e9 omezen\u00ed (purpose limitation):<\/strong> sb\u00edrej data jen pro konkr\u00e9tn\u00ed legitimn\u00ed \u00fa\u010dely.<\/li>\n\n\n<li><strong>Minimalizace dat:<\/strong> ber jen minimum, kter\u00e9 opravdu pot\u0159ebuje\u0161.<\/li>\n\n\n<li><strong>P\u0159esnost:<\/strong> udr\u017euj data aktu\u00e1ln\u00ed a opraviteln\u00e9.<\/li>\n\n\n<li><strong>Omezen\u00ed ulo\u017een\u00ed (storage limitation):<\/strong> neukl\u00e1dej d\u00e9le, ne\u017e je nutn\u00e9.<\/li>\n\n\n<li><strong>Integrita a d\u016fv\u011brnost:<\/strong> chra\u0148 data p\u0159ed neopr\u00e1vn\u011bn\u00fdm p\u0159\u00edstupem vhodn\u00fdmi opat\u0159en\u00edmi.<\/li>\n\n\n<li><strong>Odpov\u011bdnost (accountability):<\/strong> mus\u00ed\u0161 b\u00fdt schopn\u00fd dolo\u017eit, \u017ee pravidla dodr\u017euje\u0161.<\/li>\n\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Kompletn\u00ed GDPR compliance checklist (pro weby a online slu\u017eby)<\/h2>\n\n\n\n<p>N\u00ed\u017ee je checklist rozd\u011blen\u00fd do oblast\u00ed. U ka\u017ed\u00e9ho bodu uv\u00e1d\u00edm, na koho typicky dopad\u00e1 (<strong>Data Controller<\/strong>, <strong>Data Processor<\/strong>) a p\u0159id\u00e1v\u00e1m p\u0159esn\u00e9 odkazy na \u010dl\u00e1nky GDPR, proto\u017ee p\u0159i auditu je to \u010dasto to prvn\u00ed, co se \u0159e\u0161\u00ed.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Data<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1) M\u00e1\u0161 seznam v\u0161ech typ\u016f osobn\u00edch \u00fadaj\u016f, jejich zdroj, sd\u00edlen\u00ed, \u00fa\u010del a dobu uchov\u00e1n\u00ed<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Jde o praktick\u00fd invent\u00e1\u0159 toho, jak\u00e9 \u201esloupce\u201c osobn\u00edch \u00fadaj\u016f dr\u017e\u00ed\u0161 (nap\u0159. jm\u00e9no, adresa, e\u2011mail, rodn\u00e9 \u010d\u00edslo, identifik\u00e1tory za\u0159\u00edzen\u00ed), odkud se berou, komu je p\u0159ed\u00e1v\u00e1\u0161, pro\u010d je pot\u0159ebuje\u0161 a jak dlouho je dr\u017e\u00ed\u0161.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 30<\/strong> \u2013 Records of processing activities<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2) M\u00e1\u0161 seznam m\u00edst, kde osobn\u00ed \u00fadaje ukl\u00e1d\u00e1\u0161, a popsan\u00e9 datov\u00e9 toky<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Nejde jen o datab\u00e1ze (t\u0159eba MySQL), ale i o offline \u00falo\u017ei\u0161t\u011b (pap\u00edr, exporty, lok\u00e1ln\u00ed soubory). D\u016fle\u017eit\u00e9 jsou i vazby: odkud kam data te\u010dou (web \u2192 CRM \u2192 e\u2011mailing \u2192 \u00fa\u010detnictv\u00ed atd.).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 30<\/strong> \u2013 Records of processing activities<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3) M\u00e1\u0161 ve\u0159ejn\u011b dostupn\u00e9 Privacy Policy, kter\u00e9 popisuje procesy kolem osobn\u00edch \u00fadaj\u016f<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Privacy Policy by m\u011blo pokr\u00fdvat, jak data zpracov\u00e1v\u00e1\u0161, a ide\u00e1ln\u011b obsahovat (nebo odkazovat na) typy osobn\u00edch \u00fadaj\u016f, kter\u00e9 dr\u017e\u00ed\u0161, a kde se nach\u00e1z\u00ed.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 30<\/strong> \u2013 Records of processing activities<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4) V Privacy Policy uv\u00e1d\u00ed\u0161 pr\u00e1vn\u00ed titul (lawful basis), pro\u010d data zpracov\u00e1v\u00e1\u0161<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller<\/em><\/p>\n\n\n\n<p>Mus\u00ed b\u00fdt jasn\u00e9, na jak\u00e9m pr\u00e1vn\u00edm z\u00e1klad\u011b data zpracov\u00e1v\u00e1\u0161 \u2013 nap\u0159\u00edklad pln\u011bn\u00ed smlouvy.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 6<\/strong> \u2013 Lawfulness of processing<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Accountability &#038; management<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">5) M\u00e1\u0161 jmenovan\u00e9ho Data Protection Officer (DPO), pokud je to povinn\u00e9<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>DPO (pov\u011b\u0159enec pro ochranu osobn\u00edch \u00fadaj\u016f) je povinn\u00fd jen ve t\u0159ech situac\u00edch:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Zpracov\u00e1n\u00ed prov\u00e1d\u00ed org\u00e1n ve\u0159ejn\u00e9 moci nebo ve\u0159ejn\u00fd subjekt (mimo soudy, pokud jednaj\u00ed v soudn\u00ed pravomoci).<\/li>\n\n\n<li>Hlavn\u00ed \u010dinnosti vy\u017eaduj\u00ed pravideln\u00e9 a systematick\u00e9 monitorov\u00e1n\u00ed subjekt\u016f \u00fadaj\u016f ve velk\u00e9m rozsahu (dle povahy\/rozsahu\/\u00fa\u010delu).<\/li>\n\n\n<li>Hlavn\u00ed \u010dinnosti spo\u010d\u00edvaj\u00ed ve zpracov\u00e1n\u00ed ve velk\u00e9m rozsahu zvl\u00e1\u0161tn\u00edch kategori\u00ed \u00fadaj\u016f (citliv\u00e1 data) dle <strong>Article 9<\/strong> a osobn\u00edch \u00fadaj\u016f o odsouzen\u00edch a trestn\u00fdch \u010dinech dle <strong>Article 10<\/strong>.<\/li>\n\n<\/ol>\n\n\n\n<p>Pokud DPO pot\u0159ebuje\u0161, m\u011bl by m\u00edt znalost GDPR pravidel i intern\u00edch proces\u016f pr\u00e1ce s osobn\u00edmi \u00fadaji.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 37<\/strong> \u2013 Designation of the data protection officer<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">6) Zvy\u0161uje\u0161 pov\u011bdom\u00ed u decision maker\u016f o GDPR pravidlech<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Kl\u00ed\u010dov\u00ed lid\u00e9 (v\u010detn\u011b t\u011bch, kdo rozhoduj\u00ed o produktech, marketingu a n\u00e1kupech n\u00e1stroj\u016f) mus\u00ed m\u00edt aktu\u00e1ln\u00ed p\u0159ehled o pravidlech ochrany dat.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 25<\/strong> \u2013 Data protection by design and by default<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">7) Technick\u00e1 bezpe\u010dnost je aktu\u00e1ln\u00ed<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>U SaaS typicky pom\u00e1h\u00e1 jet podle security checklist\u016f, aby byla implementovan\u00e1 odpov\u00eddaj\u00edc\u00ed technick\u00e1 opat\u0159en\u00ed.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 25<\/strong> \u2013 Data protection by design and by default<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">8) \u0160kol\u00ed\u0161 zam\u011bstnance (data protection awareness)<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Processor<\/em><\/p>\n\n\n\n<p>Hodn\u011b incident\u016f vznik\u00e1 \u201ep\u0159es \u010dlov\u011bka\u201c \u2013 n\u011bkdo s p\u0159\u00edstupem do intern\u00edch syst\u00e9m\u016f nev\u011bdomky pom\u016f\u017ee \u00fato\u010dn\u00edkovi. \u0160kolen\u00ed a intern\u00ed postupy jsou sou\u010d\u00e1st ochrany.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 25<\/strong> \u2013 Data protection by design and by default<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">9) M\u00e1\u0161 seznam sub\u2011processors a zmi\u0148uje\u0161 je v Privacy Policy<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Processor<\/em><\/p>\n\n\n\n<p>Pokud vyu\u017e\u00edv\u00e1\u0161 sub\u2011processory (dal\u0161\u00ed dodavatele, kte\u0159\u00ed pro tebe zpracov\u00e1vaj\u00ed data), mus\u00ed o tom z\u00e1kazn\u00edci v\u011bd\u011bt a souhlasit s t\u00edm p\u0159ijet\u00edm Privacy Policy.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 28<\/strong> \u2013 Processor<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">10) Pokud p\u016fsob\u00ed\u0161 mimo EU, m\u00e1\u0161 z\u00e1stupce v EU<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Kdy\u017e m\u00e1\u0161 firmu mimo EU, ale sb\u00edr\u00e1\u0161 data ob\u010dan\u016f EU, m\u011bl bys m\u00edt jmenovan\u00e9ho z\u00e1stupce v n\u011bkter\u00e9m \u010dlensk\u00e9m st\u00e1t\u011b. \u00da\u0159ady ho mus\u00ed b\u00fdt schopn\u00e9 kontaktovat kv\u016fli z\u00e1le\u017eitostem zpracov\u00e1n\u00ed.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 27<\/strong> \u2013 Representatives of controllers or processors not established in the Union<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">11) Incidenty (data breaches) hl\u00e1s\u00ed\u0161 \u00fa\u0159adu i dot\u010den\u00fdm lidem<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Poru\u0161en\u00ed zabezpe\u010den\u00ed osobn\u00edch \u00fadaj\u016f se hl\u00e1s\u00ed do <strong>72 hodin<\/strong> m\u00edstn\u00edmu dozorov\u00e9mu \u00fa\u0159adu. V ozn\u00e1men\u00ed typicky uv\u00e1d\u00ed\u0161, jak\u00e1 data unikla, jak\u00e9 jsou dopady a jak\u00e1 protiopat\u0159en\u00ed jsi zavedl. Pokud unikl\u00e1 data nebyla \u0161ifrovan\u00e1, m\u00e1\u0161 obvykle povinnost informovat i dot\u010den\u00e9 subjekty \u00fadaj\u016f.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 33<\/strong> \u2013 Notification of a personal data breach to the supervisory authority; GDPR <strong>Article 34<\/strong> \u2013 Communication of a personal data breach to the data subject<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">12) Se v\u0161emi Processory, kter\u00fdm p\u0159ed\u00e1v\u00e1\u0161 data, m\u00e1\u0161 smlouvu<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller<\/em><\/p>\n\n\n\n<p>Smlouva m\u00e1 obsahovat explicitn\u00ed instrukce pro ukl\u00e1d\u00e1n\u00ed\/zpracov\u00e1n\u00ed dat. M\u00e1 popisovat p\u0159edm\u011bt a dobu zpracov\u00e1n\u00ed, povahu a \u00fa\u010del zpracov\u00e1n\u00ed, typ osobn\u00edch \u00fadaj\u016f a kategorie subjekt\u016f \u00fadaj\u016f, plus povinnosti a pr\u00e1va spr\u00e1vce. Typicky sem spad\u00e1 t\u0159eba smlouva s hostingem. Stejn\u00e9 po\u017eadavky plat\u00ed i tehdy, kdy\u017e processor zapoj\u00ed sub\u2011processora.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 28<\/strong> \u2013 Processor; GDPR <strong>Article 29<\/strong> \u2013 Processing under the authority of the controller or processor<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Nov\u00e1 pr\u00e1va (praktick\u00e1 vymahatelnost na webu)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">13) U\u017eivatel\u00e9 si um\u00ed jednodu\u0161e vy\u017e\u00e1dat p\u0159\u00edstup ke sv\u00fdm dat\u016fm<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>M\u011bl by existovat jasn\u00fd proces, jak vy\u0159izuje\u0161 \u017e\u00e1dosti o p\u0159\u00edstup (DSAR).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 15<\/strong> \u2013 Right of access by the data subject<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">14) U\u017eivatel\u00e9 si um\u00ed jednodu\u0161e opravit\/aktualizovat \u00fadaje<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Pot\u0159ebuje\u0161 mechanismus, kter\u00fdm lze opravit nep\u0159esn\u00e1 data.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 16<\/strong> \u2013 Right to rectification<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">15) Automaticky ma\u017ee\u0161 data, kter\u00e1 u\u017e nepot\u0159ebuje\u0161<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Maz\u00e1n\u00ed by nem\u011blo b\u00fdt ru\u010dn\u00ed ritu\u00e1l jednou za rok. P\u0159\u00edklad: automaticky odstranit data z\u00e1kazn\u00edk\u016f, kte\u0159\u00ed neobnovili smlouvu.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 5<\/strong> \u2013 Principles relating to processing of personal data<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">16) U\u017eivatel\u00e9 si um\u00ed jednodu\u0161e vy\u017e\u00e1dat v\u00fdmaz (right to be forgotten)<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Mus\u00ed\u0161 m\u00edt proces pro \u017e\u00e1dosti o v\u00fdmaz.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 17<\/strong> \u2013 Right to erasure (&#8216;right to be forgotten&#8217;)<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">17) U\u017eivatel\u00e9 si um\u00ed vy\u017e\u00e1dat omezen\u00ed zpracov\u00e1n\u00ed<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>U\u017eivatel\u00e9 maj\u00ed pr\u00e1vo omezit, jak data zpracov\u00e1v\u00e1\u0161.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 18<\/strong> \u2013 Right to restriction of processing<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">18) U\u017eivatel\u00e9 si um\u00ed vy\u017e\u00e1dat p\u0159ed\u00e1n\u00ed dat (data portability)<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>P\u0159enositelnost znamen\u00e1 dodat data ve strukturovan\u00e9m, b\u011b\u017en\u011b pou\u017e\u00edvan\u00e9m, strojov\u011b \u010diteln\u00e9m form\u00e1tu \u2013 u\u017eivateli nebo t\u0159et\u00ed stran\u011b.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 20<\/strong> \u2013 Right to data portability<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">19) U\u017eivatel\u00e9 mohou snadno vzn\u00e9st n\u00e1mitku proti profilov\u00e1n\u00ed \/ automatizovan\u00e9mu rozhodov\u00e1n\u00ed<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller<\/em><\/p>\n\n\n\n<p>T\u00fdk\u00e1 se jen p\u0159\u00edpad\u016f, kdy d\u011bl\u00e1\u0161 profilov\u00e1n\u00ed nebo automatizovan\u00e9 rozhodov\u00e1n\u00ed, kter\u00e9 m\u016f\u017ee m\u00edt na \u010dlov\u011bka dopad.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 22<\/strong> \u2013 Automated individual decision-making, including profiling<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Souhlas (Consent)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">20) Pokud jede\u0161 na souhlas, mus\u00ed b\u00fdt svobodn\u00fd, konkr\u00e9tn\u00ed, informovan\u00fd a odvolateln\u00fd<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller<\/em><\/p>\n\n\n\n<p>Kdy\u017e na webu sb\u00edr\u00e1\u0161 osobn\u00ed \u00fadaje na z\u00e1klad\u011b souhlasu, mus\u00ed b\u00fdt viditeln\u011b dostupn\u00e1 Privacy Policy a mus\u00ed b\u00fdt jasn\u00e9, \u017ee u\u017eivatel souhlas\u00ed s podm\u00ednkami. Souhlas vy\u017eaduje aktivn\u00ed \u00fakon \u2013 <strong>p\u0159edza\u0161krtnut\u00e9 checkboxy jsou nep\u0159\u00edpustn\u00e9<\/strong>.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 7<\/strong> \u2013 Conditions for consent<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">21) Privacy Policy je napsan\u00e9 jasn\u011b a srozumiteln\u011b<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller<\/em><\/p>\n\n\n\n<p>Text nesm\u00ed skr\u00fdvat z\u00e1m\u011br, m\u00e1 b\u00fdt jednoduch\u00fd a pochopiteln\u00fd. U slu\u017eeb pro d\u011bti m\u00e1 b\u00fdt pochopiteln\u00fd i jim (co nejv\u00edc plain language). Pokud tohle nespln\u00ed\u0161, m\u016f\u017ee to zneplatnit souhlas \/ dohodu.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 7.2<\/strong> \u2013 Conditions for consent<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">22) Odvol\u00e1n\u00ed souhlasu je stejn\u011b snadn\u00e9 jako jeho ud\u011blen\u00ed<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller<\/em><\/p>\n\n\n\n<p>U\u017eivatel by nem\u011bl absolvovat slo\u017eit\u011bj\u0161\u00ed cestu, ne\u017e kdy\u017e souhlas d\u00e1val.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 7.3<\/strong> \u2013 Conditions for consent<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">23) U d\u011btsk\u00fdch dat ov\u011b\u0159uje\u0161 v\u011bk a \u0159e\u0161\u00ed\u0161 souhlas z\u00e1konn\u00e9ho z\u00e1stupce<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller<\/em><\/p>\n\n\n\n<p>U d\u011bt\u00ed mlad\u0161\u00edch <strong>16 let<\/strong> mus\u00ed\u0161 zajistit souhlas z\u00e1konn\u00e9ho z\u00e1stupce. Pokud se souhlas d\u00e1v\u00e1 p\u0159es web, m\u011bl bys se rozumn\u011b pokusit ov\u011b\u0159it, \u017ee ho opravdu d\u00e1v\u00e1 z\u00e1stupce (a ne d\u00edt\u011b).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 8<\/strong> \u2013 Conditions applicable to child&#8217;s consent in relation to information society services<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">24) P\u0159i aktualizaci Privacy Policy informuje\u0161 st\u00e1vaj\u00edc\u00ed z\u00e1kazn\u00edky<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller<\/em><\/p>\n\n\n\n<p>Typicky e\u2011mailem dop\u0159edu s jednoduch\u00fdm vysv\u011btlen\u00edm, co se zm\u011bnilo.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 7<\/strong> \u2013 Conditions for consent<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Follow\u2011up (pravideln\u00e9 revize)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">25) Pravideln\u011b reviduje\u0161 politiky a zm\u011bny v tom, kam data te\u010dou<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller<\/em><\/p>\n\n\n\n<p>Nejde jen o \u201ejednou nastavit a hotovo\u201c. Kontroluj zm\u011bny proces\u016f, efektivitu opat\u0159en\u00ed a tak\u00e9 zm\u011bny ve st\u00e1tech, do kter\u00fdch data pos\u00edl\u00e1\u0161 (a jejich re\u017eim ochrany).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 25<\/strong> \u2013 Data protection by design and by default<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Speci\u00e1ln\u00ed p\u0159\u00edpady<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">26) V\u00ed\u0161, kdy mus\u00ed\u0161 ud\u011blat DPIA (Data Protection Impact Assessment)<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller<\/em><\/p>\n\n\n\n<p>DPIA je na m\u00edst\u011b u vysoce rizikov\u00fdch zpracov\u00e1n\u00ed \u2013 typicky velk\u00fd rozsah, profilov\u00e1n\u00ed a dal\u0161\u00ed \u010dinnosti s vysok\u00fdm rizikem pro pr\u00e1va a svobody lid\u00ed.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 35<\/strong> \u2013 Data protection impact assessment<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">27) Data mimo EU pos\u00edl\u00e1\u0161 jen tam, kde je odpov\u00eddaj\u00edc\u00ed ochrana (nebo m\u00e1\u0161 SCC\/BCR)<\/h4>\n\n\n\n<p><em>Plat\u00ed pro: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>P\u0159enosy mimo EU mus\u00ed\u0161 m\u00edt o\u0161et\u0159en\u00e9 a tyto p\u0159eshrani\u010dn\u00ed toky tak\u00e9 uv\u00e1d\u011bt v Privacy Policy. Pro zem\u011b bez odpov\u00eddaj\u00edc\u00ed ochrany se typicky pou\u017e\u00edvaj\u00ed <strong>Standard Contractual Clauses (SCCs)<\/strong> nebo <strong>Binding Corporate Rules (BCRs)<\/strong>.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 45<\/strong> \u2013 Transfers on the basis of an adequacy decision<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Pr\u00e1va u\u017eivatel\u016f (Data Subject Rights) \u2013 co mus\u00ed\u0161 um\u011bt obslou\u017eit<\/h2>\n\n\n\n<p>GDPR d\u00e1v\u00e1 lidem, jejich\u017e data zpracov\u00e1v\u00e1\u0161, konkr\u00e9tn\u00ed pr\u00e1va. Z implementa\u010dn\u00edho pohledu je d\u016fle\u017eit\u00e9, aby bylo jasn\u00e9: (1) jak \u017e\u00e1dost p\u0159ijme\u0161, (2) jak ov\u011b\u0159\u00ed\u0161 identitu, (3) jak data dohled\u00e1\u0161 nap\u0159\u00ed\u010d syst\u00e9my, (4) jak to cel\u00e9 zdokumentuje\u0161.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Right to transparent information<\/h3>\n\n\n\n<p>Spr\u00e1vce m\u00e1 p\u0159ijmout vhodn\u00e1 opat\u0159en\u00ed a poskytnout informace o zpracov\u00e1n\u00ed stru\u010dn\u011b, transparentn\u011b, srozumiteln\u011b a snadno dostupn\u011b, jasn\u00fdm a jednoduch\u00fdm jazykem \u2013 obzvl\u00e1\u0161\u0165 pokud je informace ur\u010den\u00e1 d\u00edt\u011bti. Informace maj\u00ed b\u00fdt poskytnut\u00e9 p\u00edsemn\u011b nebo jin\u00fdmi prost\u0159edky, v\u010detn\u011b elektronick\u00fdch, pokud je to vhodn\u00e9.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 12<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Right to receive specific information when personal data are collected directly<\/h3>\n\n\n\n<p>Pokud data sb\u00edr\u00e1\u0161 p\u0159\u00edmo od \u010dlov\u011bka, mus\u00ed dostat konkr\u00e9tn\u00ed informace, v\u010detn\u011b:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Toto\u017enost a kontaktn\u00ed \u00fadaje spr\u00e1vce<\/li>\n\n\n<li>Kontaktn\u00ed \u00fadaje DPO (pokud se uplatn\u00ed)<\/li>\n\n\n<li>\u00da\u010dely zpracov\u00e1n\u00ed a pr\u00e1vn\u00ed z\u00e1klad<\/li>\n\n\n<li>Opr\u00e1vn\u011bn\u00e9 z\u00e1jmy spr\u00e1vce (pokud se uplatn\u00ed)<\/li>\n\n\n<li>P\u0159\u00edjemci nebo kategorie p\u0159\u00edjemc\u016f osobn\u00edch \u00fadaj\u016f<\/li>\n\n\n<li>Informace o p\u0159ed\u00e1v\u00e1n\u00ed do t\u0159et\u00edch zem\u00ed<\/li>\n\n<\/ol>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 13<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Right to receive specific information when personal data are not collected directly<\/h3>\n\n\n\n<p>Pokud data z\u00edsk\u00e1\u0161 z jin\u00fdch zdroj\u016f ne\u017e p\u0159\u00edmo od subjektu \u00fadaj\u016f, mus\u00ed\u0161 poskytnout obdobn\u00e9 informace, v\u010detn\u011b kategori\u00ed dot\u010den\u00fdch osobn\u00edch \u00fadaj\u016f a zdroje dat.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 14<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Right of access<\/h3>\n\n\n\n<p>U\u017eivatel m\u00e1 pr\u00e1vo z\u00edskat potvrzen\u00ed, zda jeho data zpracov\u00e1v\u00e1\u0161, a tak\u00e9 p\u0159\u00edstup k informac\u00edm:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>\u00fa\u010dely zpracov\u00e1n\u00ed<\/li>\n\n\n<li>kategorie dot\u010den\u00fdch osobn\u00edch \u00fadaj\u016f<\/li>\n\n\n<li>p\u0159\u00edjemci, kter\u00fdm data byla nebo budou zp\u0159\u00edstupn\u011bna<\/li>\n\n\n<li>pl\u00e1novan\u00e1 doba uchov\u00e1n\u00ed<\/li>\n\n\n<li>existence pr\u00e1v na opravu, v\u00fdmaz, omezen\u00ed a n\u00e1mitku<\/li>\n\n\n<li>pr\u00e1vo podat st\u00ed\u017enost u dozorov\u00e9ho \u00fa\u0159adu<\/li>\n\n\n<li>informace o zdroji dat (pokud nebyla z\u00edsk\u00e1na od subjektu)<\/li>\n\n\n<li>existence automatizovan\u00e9ho rozhodov\u00e1n\u00ed v\u010detn\u011b profilov\u00e1n\u00ed<\/li>\n\n<\/ul>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 15<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Right to rectification<\/h3>\n\n\n\n<p>Pr\u00e1vo na opravu nep\u0159esn\u00fdch \u00fadaj\u016f bez zbyte\u010dn\u00e9ho odkladu a dopln\u011bn\u00ed ne\u00fapln\u00fdch \u00fadaj\u016f.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 16<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Right to erasure (&#8220;right to be forgotten&#8221;)<\/h3>\n\n\n\n<p>Pr\u00e1vo na v\u00fdmaz nastupuje zejm\u00e9na, kdy\u017e:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Data u\u017e nejsou pot\u0159ebn\u00e1 pro p\u016fvodn\u00ed \u00fa\u010del.<\/li>\n\n\n<li>Odvol\u00e1\u0161 souhlas a neexistuje jin\u00fd pr\u00e1vn\u00ed d\u016fvod ke zpracov\u00e1n\u00ed.<\/li>\n\n\n<li>Vznesl(a) jsi n\u00e1mitku a neexistuj\u00ed p\u0159eva\u017euj\u00edc\u00ed opr\u00e1vn\u011bn\u00e9 d\u016fvody.<\/li>\n\n\n<li>Data byla zpracov\u00e1na protipr\u00e1vn\u011b.<\/li>\n\n\n<li>Data se mus\u00ed vymazat kv\u016fli spln\u011bn\u00ed pr\u00e1vn\u00ed povinnosti.<\/li>\n\n\n<li>Data byla z\u00edsk\u00e1na v souvislosti se slu\u017ebami informa\u010dn\u00ed spole\u010dnosti nab\u00eddnut\u00fdmi d\u00edt\u011bti.<\/li>\n\n<\/ol>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 17<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Right to restriction of processing<\/h3>\n\n\n\n<p>Pr\u00e1vo na omezen\u00ed zpracov\u00e1n\u00ed typicky nast\u00e1v\u00e1, kdy\u017e:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Rozporuje\u0161 p\u0159esnost dat (na dobu ov\u011b\u0159en\u00ed).<\/li>\n\n\n<li>Zpracov\u00e1n\u00ed je protipr\u00e1vn\u00ed a m\u00edsto v\u00fdmazu chce\u0161 omezen\u00ed.<\/li>\n\n\n<li>Spr\u00e1vce data u\u017e nepot\u0159ebuje, ale ty je pot\u0159ebuje\u0161 pro pr\u00e1vn\u00ed n\u00e1roky.<\/li>\n\n\n<li>Vznesl(a) jsi n\u00e1mitku a \u010dek\u00e1 se na ov\u011b\u0159en\u00ed opr\u00e1vn\u011bn\u00fdch d\u016fvod\u016f.<\/li>\n\n<\/ol>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 18<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Right to be notified regarding rectification, erasure, or restriction<\/h3>\n\n\n\n<p>Spr\u00e1vce m\u00e1 ozn\u00e1mit opravu, v\u00fdmaz nebo omezen\u00ed ka\u017ed\u00e9mu p\u0159\u00edjemci, kter\u00e9mu byly \u00fadaje zp\u0159\u00edstupn\u011bny \u2013 pokud to nen\u00ed nemo\u017en\u00e9 nebo nep\u0159im\u011b\u0159en\u011b n\u00e1ro\u010dn\u00e9.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 19<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Right to data portability<\/h3>\n\n\n\n<p>Pr\u00e1vo z\u00edskat osobn\u00ed \u00fadaje ve strukturovan\u00e9m, b\u011b\u017en\u011b pou\u017e\u00edvan\u00e9m a strojov\u011b \u010diteln\u00e9m form\u00e1tu a p\u0159edat je jin\u00e9mu spr\u00e1vci bez p\u0159ek\u00e1\u017eek.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 20<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Right to object<\/h3>\n\n\n\n<p>Pr\u00e1vo vzn\u00e9st n\u00e1mitku kdykoliv (s ohledem na konkr\u00e9tn\u00ed situaci) proti zpracov\u00e1n\u00ed zalo\u017een\u00e9mu na opr\u00e1vn\u011bn\u00fdch z\u00e1jmech nebo ve\u0159ejn\u00e9m z\u00e1jmu, v\u010detn\u011b profilov\u00e1n\u00ed.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 21<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Right not to be subject to automated decision-making<\/h3>\n\n\n\n<p>Pr\u00e1vo neb\u00fdt p\u0159edm\u011btem rozhodnut\u00ed zalo\u017een\u00e9ho v\u00fdhradn\u011b na automatizovan\u00e9m zpracov\u00e1n\u00ed (v\u010detn\u011b profilov\u00e1n\u00ed), kter\u00e9 m\u00e1 pr\u00e1vn\u00ed \u00fa\u010dinky nebo podobn\u011b v\u00fdznamn\u011b ovliv\u0148uje.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 22<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Praktick\u00e9 implementa\u010dn\u00ed kroky (co na webu re\u00e1ln\u011b ud\u011blat)<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1) Zabezpe\u010d web a infrastrukturu<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Nainstaluj <strong>SSL certifik\u00e1t<\/strong> (HTTPS), aby se data \u0161ifrovala mezi webem a serverem.<\/li>\n\n\n<li>Pou\u017e\u00edvej <strong>siln\u00e1 hesla<\/strong> pro v\u0161echny admin \u00fa\u010dty.<\/li>\n\n\n<li>P\u0159idej <strong>extra ochranu<\/strong> pro zpracov\u00e1n\u00ed platebn\u00edch informac\u00ed.<\/li>\n\n\n<li>Pou\u017eij <strong>CDN<\/strong> poskytovatele, kter\u00fd pom\u00e1h\u00e1 chr\u00e1nit proti DDoS \u00fatok\u016fm.<\/li>\n\n\n<li>Nasa\u010f <strong>anti\u2011virus software<\/strong> pro prevenci neopr\u00e1vn\u011bn\u00e9ho p\u0159\u00edstupu.<\/li>\n\n\n<li><strong>Minimalizuj sb\u011br dat<\/strong> \u2013 sb\u00edrej jen to, co je nutn\u00e9.<\/li>\n\n\n<li>P\u0159ed ulo\u017een\u00edm data <strong>pseudonymizuj nebo anonymizuj<\/strong>, pokud to d\u00e1v\u00e1 smysl.<\/li>\n\n\n<li>D\u011blej <strong>z\u00e1lohy<\/strong> do v\u00edce bezpe\u010dn\u00fdch lokac\u00ed.<\/li>\n\n\n<li><strong>Ma\u017e data<\/strong>, jakmile u\u017e nejsou pot\u0159eba.<\/li>\n\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">2) P\u0159idej cookie consent banner (a ud\u011blej ho spr\u00e1vn\u011b)<\/h3>\n\n\n\n<p>Pokud pou\u017e\u00edv\u00e1\u0161 <strong>ne\u2011nezbytn\u00e9 cookies<\/strong>, pot\u0159ebuje\u0161 <strong>explicitn\u00ed souhlas p\u0159ed jejich aktivac\u00ed<\/strong>.<\/p>\n\n\n\n<p>Cookie banner mus\u00ed splnit:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>Blokovat cookies do ud\u011blen\u00ed souhlasu:<\/strong> na\u010d\u00edst jen nezbytn\u00e9 cookies, dokud u\u017eivatel neodsouhlas\u00ed.<\/li>\n\n\n<li><strong>Jednoduch\u00fd a jasn\u00fd jazyk:<\/strong> vysv\u011btlit, jak\u00e9 cookies pou\u017e\u00edv\u00e1\u0161 a pro\u010d.<\/li>\n\n\n<li><strong>Rovnocenn\u00e9 volby Accept\/Reject:<\/strong> neukr\u00fdvat odm\u00edtnut\u00ed.<\/li>\n\n\n<li><strong>Granul\u00e1rn\u00ed volby:<\/strong> mo\u017enost vybrat konkr\u00e9tn\u00ed kategorie cookies.<\/li>\n\n\n<li><strong>Mo\u017enost odvol\u00e1n\u00ed souhlasu:<\/strong> jednoduch\u00e1 zm\u011bna preferenc\u00ed pozd\u011bji.<\/li>\n\n\n<li><strong>Evidence souhlasu:<\/strong> ukl\u00e1dat volby v\u010detn\u011b \u010dasov\u00e9 zna\u010dky, aby \u0161ly dolo\u017eit.<\/li>\n\n<\/ul>\n\n\n\n<div class=\"wp-block-group callout callout-warning is-style-warning is-layout-flow wp-block-group-is-layout-flow\" style=\"border-width:1px;border-radius:8px;padding-top:1rem;padding-right:1.5rem;padding-bottom:1rem;padding-left:1.5rem\">\n\n<h4 class=\"wp-block-heading callout-title\">D\u016fle\u017eit\u00e9<\/h4>\n\n\n<p>Scrollov\u00e1n\u00ed nebo ne\u010dinnost u\u017eivatele nen\u00ed souhlas.<\/p>\n\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">3) Zkontroluj formul\u00e1\u0159e na webu<\/h3>\n\n\n\n<p>Ka\u017ed\u00fd formul\u00e1\u0159, kter\u00fd sb\u00edr\u00e1 osobn\u00ed \u00fadaje, mus\u00ed b\u00fdt nastaven\u00fd tak, aby byl v souladu s GDPR:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>P\u0159idej <strong>privacy statement<\/strong>: pro\u010d data pot\u0159ebuje\u0161.<\/li>\n\n\n<li>Pou\u017eij <strong>neza\u0161krtnut\u00fd checkbox<\/strong> pro souhlas (pokud je souhlas pr\u00e1vn\u00ed z\u00e1klad).<\/li>\n\n\n<li>Pro marketing dej <strong>odd\u011blen\u00fd opt\u2011in<\/strong> (zvl\u00e1\u0161\u0165 souhlas).<\/li>\n\n\n<li>Odkazuj na <strong>Privacy Policy<\/strong>.<\/li>\n\n\n<li>Pi\u0161 <strong>jasn\u011b a jednodu\u0161e<\/strong>.<\/li>\n\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4) Z\u00edskej souhlas pro marketingov\u00e9 e\u2011maily<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Pou\u017e\u00edvej jen <strong>clear opt\u2011in<\/strong>: neza\u0161krtnut\u00fd checkbox p\u0159\u00edmo pro e\u2011mailov\u00fd souhlas.<\/li>\n\n\n<li>Zave\u010f <strong>double opt\u2011in<\/strong>: potvrzen\u00ed registrace p\u0159es e\u2011mail.<\/li>\n\n\n<li>Udr\u017euj <strong>z\u00e1znamy o souhlasu<\/strong>: datum, \u010das, metoda, \u00fa\u010del.<\/li>\n\n\n<li>Do ka\u017ed\u00e9ho e\u2011mailu dej viditeln\u00fd <strong>unsubscribe link<\/strong>: ide\u00e1ln\u011b na jeden klik.<\/li>\n\n\n<li>Odhl\u00e1\u0161en\u00ed zpracuj rychle: ide\u00e1ln\u011b do <strong>24 hodin<\/strong>.<\/li>\n\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">5) P\u0159iprav se na incidenty (data breach)<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Ozn\u00e1m dozorov\u00e9mu \u00fa\u0159adu do <strong>72 hodin<\/strong>.<\/li>\n\n\n<li>Informuj dot\u010den\u00e9 u\u017eivatele, pokud existuje <strong>vysok\u00e9 riziko<\/strong> pro jejich pr\u00e1va.<\/li>\n\n\n<li>V\u0161echno <strong>zdokumentuj<\/strong> (accountability).<\/li>\n\n\n<li>Aktualizuj postupy a politiky tak, aby se situace neopakovala.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">WordPress specifika: na co si d\u00e1t pozor<\/h2>\n\n\n\n<p>Pokud provozuje\u0161 web na WordPressu, GDPR se dot\u00fdk\u00e1 hlavn\u011b plugin\u016f, t\u00e9mat a toho, jak pracuj\u00ed s cookies a formul\u00e1\u0159i. Praktick\u00fd baseline:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Udr\u017euj <strong>WordPress core<\/strong>, t\u00e9mata a pluginy aktu\u00e1ln\u00ed.<\/li>\n\n\n<li>Pou\u017e\u00edvej kontaktn\u00ed formul\u00e1\u0159e, kter\u00e9 um\u00ed <strong>GDPR consent checkboxy<\/strong>.<\/li>\n\n\n<li>Nainstaluj funk\u010dn\u00ed \u0159e\u0161en\u00ed pro <strong>cookie consent<\/strong>.<\/li>\n\n\n<li>Pou\u017e\u00edvej <strong>GDPR\u2011compliant analytics<\/strong> (a hl\u00eddej, jak\u00e9 cookies a identifik\u00e1tory pou\u017e\u00edv\u00e1).<\/li>\n\n\n<li>Reviduj, jak pluginy sb\u00edraj\u00ed data (kde, pro\u010d, komu je pos\u00edlaj\u00ed).<\/li>\n\n\n<li>Implementuj funkce pro <strong>export a v\u00fdmaz u\u017eivatelsk\u00fdch dat<\/strong>.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Sankce za poru\u0161en\u00ed GDPR (pokuty i dal\u0161\u00ed opat\u0159en\u00ed)<\/h2>\n\n\n\n<p>GDPR rozli\u0161uje dv\u011b \u00farovn\u011b pokut:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>Ni\u017e\u0161\u00ed \u00farove\u0148 poru\u0161en\u00ed:<\/strong> a\u017e <strong>10 milion\u016f EUR<\/strong> nebo <strong>2 %<\/strong> celosv\u011btov\u00e9ho ro\u010dn\u00edho obratu.<\/li>\n\n\n<li><strong>Vy\u0161\u0161\u00ed \u00farove\u0148 poru\u0161en\u00ed:<\/strong> a\u017e <strong>20 milion\u016f EUR<\/strong> nebo <strong>4 %<\/strong> celosv\u011btov\u00e9ho ro\u010dn\u00edho obratu.<\/li>\n\n<\/ul>\n\n\n\n<p>Krom\u011b pokut m\u016f\u017ee dozorov\u00fd \u00fa\u0159ad tak\u00e9:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>ud\u011blit varov\u00e1n\u00ed<\/li>\n\n\n<li>do\u010dasn\u011b nebo trvale zak\u00e1zat zpracov\u00e1n\u00ed<\/li>\n\n\n<li>na\u0159\u00eddit v\u00fdmaz dat<\/li>\n\n\n<li>omezit mezin\u00e1rodn\u00ed p\u0159enosy dat<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What is a GDPR compliance checklist?<\/h3>\n\n\n\n<p>GDPR compliance checklist je seznam krok\u016f, kter\u00e9 je pot\u0159eba ud\u011blat, abys byl v souladu s GDPR. Pom\u00e1h\u00e1 odhalit slab\u00e1 m\u00edsta v ochran\u011b dat a napl\u00e1novat n\u00e1pravu.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Who is responsible for GDPR compliance?<\/h3>\n\n\n\n<p>Prim\u00e1rn\u011b <strong>data controller<\/strong> (typicky majitel webu nebo firma). Povinnosti ale maj\u00ed i <strong>data processors<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Does GDPR apply to US businesses?<\/h3>\n\n\n\n<p>Ano, pokud zpracov\u00e1vaj\u00ed osobn\u00ed \u00fadaje rezident\u016f EU \u2013 bez ohledu na to, kde firma s\u00eddl\u00ed.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What is the maximum penalty for non-compliance?<\/h3>\n\n\n\n<p>A\u017e <strong>20 milion\u016f EUR<\/strong> nebo <strong>4 %<\/strong> ro\u010dn\u00edho celosv\u011btov\u00e9ho obratu (podle toho, co je vy\u0161\u0161\u00ed).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Do I need a cookie banner?<\/h3>\n\n\n\n<p>Ano, pokud web pou\u017e\u00edv\u00e1 jak\u00e9koliv <strong>ne\u2011nezbytn\u00e9 cookies<\/strong> a m\u00e1 n\u00e1v\u0161t\u011bvn\u00edky z EU.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Do I need a Data Protection Officer?<\/h3>\n\n\n\n<p>Jen pokud: (1) jsi org\u00e1n ve\u0159ejn\u00e9 moci, (2) hlavn\u00ed \u010dinnost vy\u017eaduje velkoobjemov\u00e9, systematick\u00e9 monitorov\u00e1n\u00ed lid\u00ed, nebo (3) ve velk\u00e9m zpracov\u00e1v\u00e1\u0161 citliv\u00e1 data.<\/p>\n\n\n<div class=\"references-section\">\n                <h2>Reference \/ Zdroje<\/h2>\n                <ul class=\"references-list\"><li><a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\" target=\"_blank\" rel=\"noopener noreferrer\">Regulation (EU) 2016\/679 (General Data Protection Regulation)<\/a><\/li><\/ul>\n            <\/div>","protected":false},"excerpt":{"rendered":"<p>GDPR nen\u00ed jen pr\u00e1vn\u00ed formalita: jakmile na webu sb\u00edr\u00e1\u0161 nebo zpracov\u00e1v\u00e1\u0161 osobn\u00ed \u00fadaje lid\u00ed z EU, spad\u00e1\u0161 do pravidel hry. Tohle je kompletn\u00ed, prakticky pojat\u00fd checklist, podle kter\u00e9ho si m\u016f\u017ee\u0161 ud\u011blat po\u0159\u00e1dek v datech, souhlasech, pr\u00e1vech u\u017eivatel\u016f i zabezpe\u010den\u00ed.<\/p>\n","protected":false},"author":34,"featured_media":116,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[37,86,85,88,10],"class_list":["post-117","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bezpecnost","tag-bezpecnost","tag-cookies","tag-gdpr","tag-ochrana-osobnich-udaju","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/helloblog.io\/cs\/wp-json\/wp\/v2\/posts\/117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/helloblog.io\/cs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/helloblog.io\/cs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/helloblog.io\/cs\/wp-json\/wp\/v2\/users\/34"}],"replies":[{"embeddable":true,"href":"https:\/\/helloblog.io\/cs\/wp-json\/wp\/v2\/comments?post=117"}],"version-history":[{"count":0,"href":"https:\/\/helloblog.io\/cs\/wp-json\/wp\/v2\/posts\/117\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/helloblog.io\/cs\/wp-json\/wp\/v2\/media\/116"}],"wp:attachment":[{"href":"https:\/\/helloblog.io\/cs\/wp-json\/wp\/v2\/media?parent=117"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/helloblog.io\/cs\/wp-json\/wp\/v2\/categories?post=117"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/helloblog.io\/cs\/wp-json\/wp\/v2\/tags?post=117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}