{"id":140,"date":"2026-01-20T00:00:00","date_gmt":"2026-01-19T23:00:00","guid":{"rendered":"https:\/\/helloblog.io\/sk\/gdpr-checklist-pre-majitelov-webov\/"},"modified":"2026-01-20T00:00:00","modified_gmt":"2026-01-19T23:00:00","slug":"gdpr-checklist-pre-majitelov-webov","status":"publish","type":"post","link":"https:\/\/helloblog.io\/sk\/gdpr-checklist-pre-majitelov-webov\/","title":{"rendered":"GDPR checklist pre majite\u013eov webov: praktick\u00fd n\u00e1vod, \u010do mus\u00ed\u0161 ma\u0165 v poriadku"},"content":{"rendered":"\n<p>GDPR (General Data Protection Regulation) patr\u00ed medzi najpr\u00edsnej\u0161ie a z\u00e1rove\u0148 najkomplexnej\u0161ie pravidl\u00e1 ochrany osobn\u00fdch \u00fadajov. Ak sprac\u00fava\u0161 osobn\u00e9 \u00fadaje obyvate\u013eov E\u00da \u2013 \u010di u\u017e prev\u00e1dzkuje\u0161 mal\u00fd blog, e\u2011shop alebo SaaS \u2013 GDPR sa \u0165a t\u00fdka bez oh\u013eadu na to, kde m\u00e1\u0161 firmu alebo servery.<\/p>\n\n\n\n<p>Riziko nie je len reputa\u010dn\u00e9. V pr\u00edpade nedodr\u017eania m\u00f4\u017eu pokuty dosiahnu\u0165 a\u017e <strong>20 mili\u00f3nov \u20ac alebo 4 % z celosvetov\u00e9ho ro\u010dn\u00e9ho obratu<\/strong> (pod\u013ea toho, \u010do je vy\u0161\u0161ie). Okrem pok\u00fat m\u00f4\u017eu \u00farady nariadi\u0165 aj obmedzenie sprac\u00favania, z\u00e1kaz sprac\u00favania alebo vymazanie d\u00e1t.<\/p>\n\n\n\n<div class=\"wp-block-group callout callout-warning is-style-warning is-layout-flow wp-block-group-is-layout-flow\" style=\"border-width:1px;border-radius:8px;padding-top:1rem;padding-right:1.5rem;padding-bottom:1rem;padding-left:1.5rem\">\n\n<h4 class=\"wp-block-heading callout-title\">D\u00f4le\u017eit\u00e9<\/h4>\n\n\n<p>Toto je technicko-procesn\u00fd checklist pre weby a online slu\u017eby. Nie je to pr\u00e1vne poradenstvo. Pri \u0161pecifick\u00fdch situ\u00e1ci\u00e1ch (napr. citliv\u00e9 \u00fadaje, ve\u013ek\u00e9 objemy, profilovanie) je rozumn\u00e9 rie\u0161i\u0165 veci s kvalifikovan\u00fdm pr\u00e1vnikom alebo DPO.<\/p>\n\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">\u010co je GDPR a na koho sa vz\u0165ahuje<\/h2>\n\n\n\n<p>GDPR je nariadenie E\u00da \u00fa\u010dinn\u00e9 od <strong>25. m\u00e1ja 2018<\/strong>, ktor\u00e9 nastavuje pravidl\u00e1, ako organiz\u00e1cie m\u00f4\u017eu zbiera\u0165, pou\u017e\u00edva\u0165, uklada\u0165 a zdie\u013ea\u0165 osobn\u00e9 \u00fadaje. Plat\u00ed pre firmy v E\u00da aj mimo nej \u2013 rozhoduj\u00face je, \u010di sprac\u00fava\u0161 osobn\u00e9 \u00fadaje \u013eud\u00ed v E\u00da.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Najprv si ujasni rolu: controller vs. processor<\/h2>\n\n\n\n<p>V praxi sa ve\u013ea probl\u00e9mov za\u010d\u00edna t\u00fdm, \u017ee si firma nespr\u00e1vne ur\u010d\u00ed, \u010di je <strong>Data Controller<\/strong> (prev\u00e1dzkovate\u013e) alebo <strong>Data Processor<\/strong> (sprostredkovate\u013e). M\u00f4\u017ee\u0161 by\u0165 aj oboje \u2013 napr\u00edklad ke\u010f sprac\u00fava\u0161 d\u00e1ta vlastn\u00fdch z\u00e1kazn\u00edkov (controller), ale z\u00e1rove\u0148 hostuje\u0161 alebo sprac\u00fava\u0161 d\u00e1ta pre in\u00e9ho klienta (processor).<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>Data Controllers<\/strong>: ur\u010duj\u00fa \u201epre\u010do\u201c a \u201eako\u201c sa osobn\u00e9 \u00fadaje sprac\u00favaj\u00fa. Nes\u00fa hlavn\u00fa zodpovednos\u0165 za s\u00falad s GDPR.<\/li>\n\n\n<li><strong>Data Processors<\/strong>: sprac\u00favaj\u00fa osobn\u00e9 \u00fadaje v mene controllera. Musia ma\u0165 primeran\u00e9 technick\u00e9 a organiza\u010dn\u00e9 opatrenia.<\/li>\n\n\n<li><strong>Data Subjects<\/strong>: dotknut\u00e9 osoby \u2013 \u013eudia, ktor\u00fdch \u00fadaje sprac\u00fava\u0161. GDPR chr\u00e1ni ich pr\u00e1va.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">7 princ\u00edpov GDPR, ktor\u00e9 sa ti bud\u00fa vraca\u0165 v ka\u017edom audite<\/h2>\n\n\n\n<p>Sk\u00f4r ne\u017e za\u010dne\u0161 \u201eod\u0161krt\u00e1va\u0165\u201c, oplat\u00ed sa dr\u017ea\u0165 v hlave princ\u00edpy, pod\u013ea ktor\u00fdch sa posudzuje prakticky v\u0161etko:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li><strong>Z\u00e1konnos\u0165, spravodlivos\u0165 a transparentnos\u0165<\/strong>: sprac\u00favaj \u00fadaje leg\u00e1lne a jasne informuj, \u010do s nimi rob\u00ed\u0161.<\/li>\n\n\n<li><strong>Obmedzenie \u00fa\u010delu<\/strong>: zbieraj \u00fadaje len na konkr\u00e9tne a legit\u00edmne \u00fa\u010dely.<\/li>\n\n\n<li><strong>Minimaliz\u00e1cia \u00fadajov<\/strong>: zbieraj len minimum, ktor\u00e9 naozaj potrebuje\u0161.<\/li>\n\n\n<li><strong>Spr\u00e1vnos\u0165<\/strong>: \u00fadaje musia by\u0165 presn\u00e9 a aktualizovan\u00e9.<\/li>\n\n\n<li><strong>Obmedzenie uchov\u00e1vania<\/strong>: nesmie\u0161 dr\u017ea\u0165 \u00fadaje dlh\u0161ie, ne\u017e je potrebn\u00e9.<\/li>\n\n\n<li><strong>Integrita a d\u00f4vernos\u0165<\/strong>: chr\u00e1\u0148 \u00fadaje pred neopr\u00e1vnen\u00fdm pr\u00edstupom primeran\u00fdmi bezpe\u010dnostn\u00fdmi opatreniami.<\/li>\n\n\n<li><strong>Zodpovednos\u0165 (accountability)<\/strong>: mus\u00ed\u0161 vedie\u0165 preuk\u00e1za\u0165, \u017ee GDPR dodr\u017eiava\u0161.<\/li>\n\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Kompletn\u00fd GDPR compliance checklist<\/h2>\n\n\n\n<p>Ni\u017e\u0161ie je checklist rozdelen\u00fd do oblast\u00ed. Pri ka\u017edom bode je uveden\u00e9, \u010di sa typicky t\u00fdka controllera, processora alebo oboch \u2013 a je pripojen\u00fd aj relevantn\u00fd \u010dl\u00e1nok GDPR, ktor\u00fd sa v praxi pou\u017e\u00edva ako opora pri auditoch.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1) D\u00e1ta (invent\u00fara, toky, dokument\u00e1cia)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">M\u00e1\u0161 zoznam v\u0161etk\u00fdch typov osobn\u00fdch \u00fadajov, zdroj, \u00fa\u010del, zdie\u013eanie a dobu uchov\u00e1vania<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Potrebn\u00e9 je ma\u0165 preh\u013ead \u201e\u010do presne dr\u017e\u00ed\u0161\u201c \u2013 re\u00e1lne typy \u00fadajov (napr. meno, adresa, rodn\u00e9 \u010d\u00edslo\/ID, e\u2011mail, IP adresa pod\u013ea kontextu), odkia\u013e sa ber\u00fa, komu ich poskytuje\u0161, na ak\u00fd \u00fa\u010del ich sprac\u00fava\u0161 a ako dlho ich uchov\u00e1va\u0161.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 30 \u2013 Records of processing activities<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">M\u00e1\u0161 zoznam miest, kde osobn\u00e9 \u00fadaje uklad\u00e1\u0161, a vie\u0161 pop\u00edsa\u0165 tok d\u00e1t medzi nimi<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Nie je to len datab\u00e1za typu MySQL\/PostgreSQL. Zapo\u010d\u00edtaj aj offline \u00falo\u017eisk\u00e1 (papier, exporty, CSV v zdie\u013eanom disku, logy, helpdesk). Zmysel je vedie\u0165 vysvetli\u0165, kadia\u013e d\u00e1ta te\u010d\u00fa \u2013 od formul\u00e1ra, cez CRM, e\u2011mailing, analytiku a\u017e po z\u00e1lohy.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 30 \u2013 Records of processing activities<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">M\u00e1\u0161 verejne dostupn\u00e9 z\u00e1sady ochrany osobn\u00fdch \u00fadajov (Privacy Policy) a pokr\u00fdvaj\u00fa cel\u00fd \u017eivotn\u00fd cyklus d\u00e1t<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Privacy Policy m\u00e1 pop\u00edsa\u0165 v\u0161etky procesy spojen\u00e9 so sprac\u00favan\u00edm osobn\u00fdch \u00fadajov. Dokument by mal obsahova\u0165 (alebo aspo\u0148 odkazova\u0165 na) typy \u00fadajov, ktor\u00e9 dr\u017e\u00ed\u0161, a kde ich dr\u017e\u00ed\u0161.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 30 \u2013 Records of processing activities<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">V Privacy Policy m\u00e1\u0161 uveden\u00fd pr\u00e1vny z\u00e1klad, pre\u010do \u00fadaje sprac\u00fava\u0161<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller<\/em><\/p>\n\n\n\n<p>Nesta\u010d\u00ed nap\u00edsa\u0165, \u017ee \u201esprac\u00favame \u00fadaje\u201c. Potrebuje\u0161 uvies\u0165 pr\u00e1vny d\u00f4vod (lawful basis), napr\u00edklad plnenie zmluvy.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 6 \u2013 Lawfulness of processing<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2) Zodpovednos\u0165 a riadenie (accountability &#038; management)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">M\u00e1\u0161 ur\u010den\u00fa zodpovedn\u00fa osobu \/ DPO, ak to tvoja situ\u00e1cia vy\u017eaduje<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Data Protection Officer (DPO) je povinn\u00fd len v troch scen\u00e1roch:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Sprac\u00favanie vykon\u00e1va org\u00e1n verejnej moci alebo verejn\u00fd subjekt, okrem s\u00fadov pri v\u00fdkone ich s\u00fadnej pr\u00e1vomoci.<\/li>\n\n\n<li>Hlavn\u00e9 \u010dinnosti spo\u010d\u00edvaj\u00fa v spracovate\u013esk\u00fdch oper\u00e1ci\u00e1ch, ktor\u00e9 vzh\u013eadom na svoju povahu, rozsah a\/alebo \u00fa\u010dely vy\u017eaduj\u00fa pravideln\u00e9 a systematick\u00e9 monitorovanie dotknut\u00fdch os\u00f4b vo ve\u013ekom rozsahu.<\/li>\n\n\n<li>Hlavn\u00e9 \u010dinnosti spo\u010d\u00edvaj\u00fa vo ve\u013ekoplo\u0161nom sprac\u00favan\u00ed osobitn\u00fdch kateg\u00f3ri\u00ed \u00fadajov (citliv\u00e9 \u00fadaje) pod\u013ea Article 9 a osobn\u00fdch \u00fadajov t\u00fdkaj\u00facich sa ods\u00faden\u00ed za trestn\u00e9 \u010diny a priestupky pod\u013ea Article 10.<\/li>\n\n<\/ol>\n\n\n\n<p>Ak DPO potrebuje\u0161, mus\u00ed rozumie\u0165 GDPR usmerneniam a z\u00e1rove\u0148 ma\u0165 preh\u013ead o intern\u00fdch procesoch, kde sa osobn\u00e9 \u00fadaje pou\u017e\u00edvaj\u00fa.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 37 \u2013 Designation of the data protection officer<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Decision makeri vedia, \u010do GDPR vy\u017eaduje (a ich vedomosti s\u00fa aktu\u00e1lne)<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>K\u013e\u00fa\u010dov\u00ed \u013eudia musia ma\u0165 aktu\u00e1lne znalosti o ochrane \u00fadajov. V praxi to znamen\u00e1 pravideln\u00fd refresh a jasn\u00e9 pravidl\u00e1 \u201ekto m\u00f4\u017ee rozhodn\u00fa\u0165 o \u010dom\u201c (napr. zavedenie nov\u00e9ho trackingu, nov\u00fd newsletter tool, nov\u00e9 integra\u010dn\u00e9 webhooky).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 25 \u2013 Data protection by design and by default<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Technick\u00e9 zabezpe\u010denie je aktu\u00e1lne a primeran\u00e9<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Najm\u00e4 pri SaaS je rozumn\u00e9 za\u010da\u0165 security checklistami a ma\u0165 pod kontrolou z\u00e1kladn\u00e9 technick\u00e9 opatrenia (hardening, patchovanie, pr\u00edstupy, logging).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 25 \u2013 Data protection by design and by default<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">T\u00edm je vy\u0161kolen\u00fd na ochranu \u00fadajov (najm\u00e4 ak si processor)<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Processor<\/em><\/p>\n\n\n\n<p>Ve\u013ea incidentov vznik\u00e1 t\u00fdm, \u017ee niekto s pr\u00edstupom k intern\u00fdm syst\u00e9mom nalet\u00ed soci\u00e1lnemu in\u017einierstvu alebo sprav\u00ed \u201enevinn\u00fa\u201c chybu. \u0160kolenie m\u00e1 by\u0165 praktick\u00e9: phishing, pr\u00e1ca s exportmi, zdie\u013eanie pr\u00edstupov, pr\u00e1ca s ticketmi obsahuj\u00facimi osobn\u00e9 \u00fadaje.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 25 \u2013 Data protection by design and by default<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">M\u00e1\u0161 zoznam sub-processors a Privacy Policy ich pou\u017e\u00edvanie explicitne spom\u00edna<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Processor<\/em><\/p>\n\n\n\n<p>Ak vyu\u017e\u00edva\u0161 \u010fal\u0161\u00edch dod\u00e1vate\u013eov, ktor\u00ed sprac\u00favaj\u00fa d\u00e1ta (sub-processors), z\u00e1kazn\u00edk o tom mus\u00ed vedie\u0165 a s\u00fahlasi\u0165 s t\u00fdm t\u00fdm, \u017ee akceptuje tvoje z\u00e1sady.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 28 \u2013 Processor<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Ak si mimo E\u00da, m\u00e1\u0161 ur\u010den\u00e9ho z\u00e1stupcu v E\u00da<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Ak podnik\u00e1\u0161 mimo E\u00da a zbiera\u0161 d\u00e1ta ob\u010danov E\u00da, potrebuje\u0161 ur\u010di\u0165 z\u00e1stupcu v niektorom \u010dlenskom \u0161t\u00e1te. Tento z\u00e1stupca rie\u0161i ot\u00e1zky s\u00favisiace so sprac\u00favan\u00edm a mus\u00ed by\u0165 kontaktovate\u013en\u00fd aj lok\u00e1lnym \u00faradom.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 27 \u2013 Representatives of controllers or processors not established in the Union<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Incidenty (data breaches) vie\u0161 nahlasova\u0165 \u00faradu aj dotknut\u00fdm osob\u00e1m<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>\u00danik osobn\u00fdch \u00fadajov mus\u00ed\u0161 nahl\u00e1si\u0165 pr\u00edslu\u0161n\u00e9mu dozorn\u00e9mu org\u00e1nu do <strong>72 hod\u00edn<\/strong>. V hl\u00e1sen\u00ed m\u00e1 by\u0165 jasn\u00e9, ak\u00e9 d\u00e1ta unikli, ak\u00e9 s\u00fa d\u00f4sledky a ak\u00e9 protiopatrenia si prijal. Ak d\u00e1ta neboli \u0161ifrovan\u00e9, typicky mus\u00ed\u0161 incident ozn\u00e1mi\u0165 aj dotknut\u00fdm osob\u00e1m (data subjects).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 33 \u2013 Notification of a personal data breach to the supervisory authority; GDPR Article 34 \u2013 Communication of a personal data breach to the data subject<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">S ka\u017ed\u00fdm processorom, ktor\u00e9mu odovzd\u00e1va\u0161 d\u00e1ta, m\u00e1\u0161 zmluvu (DPA) s jasn\u00fdmi pokynmi<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller<\/em><\/p>\n\n\n\n<p>Zmluva m\u00e1 obsahova\u0165 explicitn\u00e9 pokyny k ukladaniu a sprac\u00favaniu d\u00e1t: predmet a trvanie sprac\u00favania, povahu a \u00fa\u010del sprac\u00favania, typy osobn\u00fdch \u00fadajov, kateg\u00f3rie dotknut\u00fdch os\u00f4b a povinnosti\/pr\u00e1va controllera.<\/p>\n\n\n\n<p>Typick\u00fd pr\u00edklad je hosting. Rovnak\u00e9 po\u017eiadavky platia aj vtedy, ke\u010f processor zapoj\u00ed sub-processora, aby mu pomohol plni\u0165 spracovate\u013esk\u00e9 \u010dinnosti pre controllera.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 28 \u2013 Processor; GDPR Article 29 \u2013 Processing under the authority of the controller or processor<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3) Nov\u00e9 pr\u00e1va pou\u017e\u00edvate\u013eov (praktick\u00e9 procesy, nie len text na webe)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">Pou\u017e\u00edvate\u013e vie jednoducho po\u017eiada\u0165 o pr\u00edstup k svojim \u00fadajom<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Mus\u00ed\u0161 ma\u0165 jasn\u00fd proces, ako vybavuje\u0161 \u017eiadosti o pr\u00edstup (access requests) \u2013 kto ich prij\u00edma, ako overuje\u0161 identitu, kde \u00fadaje n\u00e1jde\u0161 a v akom form\u00e1te ich poskytne\u0161.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 15 \u2013 Right of access by the data subject<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Pou\u017e\u00edvate\u013e vie svoje \u00fadaje opravi\u0165 a udr\u017eiava\u0165 presn\u00e9<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Potrebn\u00fd je mechanizmus na opravu nepresn\u00fdch \u00fadajov \u2013 typicky self\u2011service profil alebo jasn\u00fd support proces.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 16 \u2013 Right to rectification<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u00dadaje, ktor\u00e9 u\u017e nepotrebuje\u0161, sa automaticky ma\u017e\u00fa<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Mazanie by malo by\u0165 automatizovan\u00e9. Napr\u00edklad ak z\u00e1kazn\u00edk neobnov\u00ed zmluvu, d\u00e1ta by nemali zosta\u0165 ulo\u017een\u00e9 \u201enav\u017edy len pre istotu\u201c.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 5 \u2013 Principles relating to processing of personal data<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Pou\u017e\u00edvate\u013e vie jednoducho po\u017eiada\u0165 o vymazanie (right to be forgotten)<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Implementuj proces na vybavenie \u017eiadost\u00ed o vymazanie. D\u00f4le\u017eit\u00e9 je, aby si vedel zmaza\u0165 d\u00e1ta naprie\u010d syst\u00e9mami (produk\u010dn\u00e1 DB, CRM, helpdesk, marketing n\u00e1stroje, exporty), a z\u00e1rove\u0148 vedel vysvetli\u0165 pr\u00edpadn\u00e9 z\u00e1konn\u00e9 v\u00fdnimky.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 17 \u2013 Right to erasure (&#8216;right to be forgotten&#8217;)<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Pou\u017e\u00edvate\u013e vie po\u017eiada\u0165 o obmedzenie sprac\u00favania<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Dotknut\u00e1 osoba m\u00e1 pr\u00e1vo obmedzi\u0165 sprac\u00favanie \u2013 napr\u00edklad k\u00fdm prever\u00ed\u0161 sporn\u00fa spr\u00e1vnos\u0165 \u00fadajov.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 18 \u2013 Right to restriction of processing<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Pou\u017e\u00edvate\u013e vie po\u017eiada\u0165 o prenosite\u013enos\u0165 \u00fadajov (data portability)<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Prenosite\u013enos\u0165 znamen\u00e1, \u017ee vie\u0161 poskytn\u00fa\u0165 \u00fadaje v \u0161trukt\u00farovanom, be\u017ene pou\u017e\u00edvanom a strojovo \u010ditate\u013enom form\u00e1te \u2013 a to bu\u010f priamo osobe, alebo tretej strane.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 20 \u2013 Right to data portability<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Pou\u017e\u00edvate\u013e vie namieta\u0165 proti profilovaniu a automatizovan\u00e9mu rozhodovaniu<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller<\/em><\/p>\n\n\n\n<p>Toto rie\u0161i\u0161 vtedy, ak rob\u00ed\u0161 profilovanie alebo automatizovan\u00e9 rozhodovanie, ktor\u00e9 m\u00f4\u017ee ma\u0165 dopad na \u010dloveka (napr. rozhodovanie o ponuke, pr\u00edstupe, cene).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 22 \u2013 Automated individual decision-making, including profiling<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4) S\u00fahlas (consent) \u2013 ke\u010f na \u0148om stoj\u00ed sprac\u00favanie<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">S\u00fahlas je dobrovo\u013en\u00fd, konkr\u00e9tny, informovan\u00fd a odvolate\u013en\u00fd<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller<\/em><\/p>\n\n\n\n<p>Ak sprac\u00favanie stoj\u00ed na s\u00fahlase, pou\u017e\u00edvate\u013e mus\u00ed ma\u0165 jasn\u00fd pr\u00edstup k inform\u00e1ci\u00e1m (link na Privacy Policy) a s\u00fahlas mus\u00ed by\u0165 dan\u00fd akt\u00edvnym \u00fakonom. <strong>Predza\u0161krtnut\u00e9 checkboxy nie s\u00fa pr\u00edpustn\u00e9.<\/strong><\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 7 \u2013 Conditions for consent<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Privacy Policy je nap\u00edsan\u00e1 jasne a zrozumite\u013ene<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller<\/em><\/p>\n\n\n\n<p>Text nesmie skr\u00fdva\u0165 z\u00e1mer a m\u00e1 by\u0165 nap\u00edsan\u00fd jednoducho. Ak poskytuje\u0161 slu\u017eby de\u0165om, mus\u00ed by\u0165 zrozumite\u013en\u00fd aj pre ne \u2013 inak sa m\u00f4\u017ee sta\u0165, \u017ee s\u00fahlas bude spochybnite\u013en\u00fd.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 7.2 \u2013 Conditions for consent<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Odvolanie s\u00fahlasu je rovnako jednoduch\u00e9 ako jeho udelenie<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller<\/em><\/p>\n\n\n\n<p>Pou\u017e\u00edvate\u013e nesmie ma\u0165 pocit, \u017ee odhl\u00e1si\u0165 sa je \u201ezlo\u017eitej\u0161ie ne\u017e prihl\u00e1si\u0165 sa\u201c.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 7.3 \u2013 Conditions for consent<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Pri sprac\u00favan\u00ed \u00fadajov det\u00ed overuje\u0161 vek a vy\u017eaduje\u0161 s\u00fahlas z\u00e1konn\u00e9ho z\u00e1stupcu<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller<\/em><\/p>\n\n\n\n<p>Pri de\u0165och mlad\u0161\u00edch ako 16 rokov mus\u00ed\u0161 zabezpe\u010di\u0165 s\u00fahlas z\u00e1konn\u00e9ho z\u00e1stupcu. Ak sa s\u00fahlas d\u00e1va cez web, mal by si sa rozumne pok\u00fasi\u0165 overi\u0165, \u017ee ho naozaj dal rodi\u010d\/z\u00e1stupca (a nie die\u0165a).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 8 \u2013 Conditions applicable to child&#8217;s consent in relation to information society services<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Pri aktualiz\u00e1cii Privacy Policy informuje\u0161 existuj\u00facich z\u00e1kazn\u00edkov<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller<\/em><\/p>\n\n\n\n<p>Napr\u00edklad e\u2011mailom ozn\u00e1mi\u0161, \u017ee sa z\u00e1sady menia, a \u013eudskou re\u010dou vysvetl\u00ed\u0161, \u010do sa zmenilo.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 7 \u2013 Conditions for consent<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5) Follow-up: pravideln\u00e9 rev\u00edzie<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">Pravidelne reviduje\u0161 politiky, ich efekt\u00edvnos\u0165 a zmeny v krajin\u00e1ch, kam te\u010d\u00fa d\u00e1ta<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller<\/em><\/p>\n\n\n\n<p>GDPR compliance sa \u010dasom rozpadne, ak nerob\u00ed\u0161 pravideln\u00fa \u00fadr\u017ebu: zmeny v procesoch, nov\u00e9 n\u00e1stroje, zmeny v sprac\u00favan\u00ed a aj to, kam sa d\u00e1ta pren\u00e1\u0161aj\u00fa (najm\u00e4 mimo E\u00da).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 25 \u2013 Data protection by design and by default<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6) \u0160peci\u00e1lne pr\u00edpady<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">Vie\u0161, kedy mus\u00ed\u0161 robi\u0165 DPIA pri vysokorizikovom sprac\u00favan\u00ed<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller<\/em><\/p>\n\n\n\n<p>DPIA (Data Protection Impact Assessment) sa typicky rie\u0161i pri ve\u013ekoplo\u0161nom sprac\u00favan\u00ed, profilovan\u00ed a \u010fal\u0161\u00edch \u010dinnostiach s vysok\u00fdm rizikom pre pr\u00e1va a slobody \u013eud\u00ed. Ak do tejto kateg\u00f3rie spad\u00e1\u0161, DPIA nie je \u201enice to have\u201c, ale o\u010dak\u00e1van\u00fd krok.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 35 \u2013 Data protection impact assessment<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Prenos d\u00e1t mimo E\u00da rob\u00ed\u0161 len do kraj\u00edn s primeranou ochranou (alebo pou\u017e\u00edva\u0161 SCC\/BCR)<\/h4>\n\n\n\n<p><em>Plat\u00ed pre: Data Controller, Data Processor<\/em><\/p>\n\n\n\n<p>Ak posiela\u0161 d\u00e1ta mimo E\u00da, v Privacy Policy m\u00e1 by\u0165 tak\u00e9to cezhrani\u010dn\u00e9 pr\u00fadenie d\u00e1t priznan\u00e9. Pri prenosoch do kraj\u00edn bez primeranosti (non-adequate) sa pou\u017e\u00edvaj\u00fa <strong>Standard Contractual Clauses (SCCs)<\/strong> alebo <strong>Binding Corporate Rules (BCRs)<\/strong>.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 45 \u2013 Transfers on the basis of an adequacy decision<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Pr\u00e1va dotknut\u00fdch os\u00f4b (User Rights \/ Data Subject Rights) \u2013 \u010do mus\u00ed\u0161 vedie\u0165 pokry\u0165<\/h2>\n\n\n\n<p>Ni\u017e\u0161ie s\u00fa pr\u00e1va, ktor\u00e9 m\u00e1 ka\u017ed\u00e1 dotknut\u00e1 osoba (data subject). Aj ke\u010f ako v\u00fdvoj\u00e1r \u010dasto rie\u0161i\u0161 najm\u00e4 technick\u00fa implement\u00e1ciu, tieto body sa premietaj\u00fa do procesov podpory, exportov, mazania aj do textov na webe.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Pr\u00e1vo na transparentn\u00e9 inform\u00e1cie<\/h3>\n\n\n\n<p>Controller m\u00e1 prija\u0165 primeran\u00e9 opatrenia, aby poskytol inform\u00e1cie o sprac\u00favan\u00ed stru\u010dne, transparentne, zrozumite\u013ene a \u013eahko pr\u00edstupne, jasn\u00fdm a jednoduch\u00fdm jazykom \u2013 zvl\u00e1\u0161\u0165, ak s\u00fa inform\u00e1cie ur\u010den\u00e9 die\u0165a\u0165u. Inform\u00e1cie maj\u00fa by\u0165 poskytnut\u00e9 p\u00edsomne alebo in\u00fdmi prostriedkami vr\u00e1tane elektronick\u00fdch.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 12<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Pr\u00e1vo na inform\u00e1cie pri priamom zbere osobn\u00fdch \u00fadajov<\/h3>\n\n\n\n<p>Ak zbiera\u0161 \u00fadaje priamo od \u010dloveka (napr. cez formul\u00e1r), mus\u00ed dosta\u0165 aspo\u0148 tieto inform\u00e1cie:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Identita a kontaktn\u00e9 \u00fadaje controllera<\/li>\n\n\n<li>Kontaktn\u00e9 \u00fadaje DPO (ak je relevantn\u00e9)<\/li>\n\n\n<li>\u00da\u010dely sprac\u00favania a pr\u00e1vny z\u00e1klad<\/li>\n\n\n<li>Opr\u00e1vnen\u00e9 z\u00e1ujmy controllera (ak s\u00fa relevantn\u00e9)<\/li>\n\n\n<li>Pr\u00edjemcovia alebo kateg\u00f3rie pr\u00edjemcov osobn\u00fdch \u00fadajov<\/li>\n\n\n<li>Inform\u00e1cie o prenosoch do tret\u00edch kraj\u00edn<\/li>\n\n<\/ol>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 13<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Pr\u00e1vo na inform\u00e1cie pri nepriamom zbere osobn\u00fdch \u00fadajov<\/h3>\n\n\n\n<p>Ak \u00fadaje nez\u00edskava\u0161 priamo od \u010dloveka (napr. ich dostane\u0161 od partnera), mus\u00ed\u0161 poskytn\u00fa\u0165 podobn\u00fd bal\u00edk inform\u00e1ci\u00ed, vr\u00e1tane kateg\u00f3ri\u00ed dotknut\u00fdch \u00fadajov a zdroja.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 14<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Pr\u00e1vo na pr\u00edstup (access)<\/h3>\n\n\n\n<p>\u010clovek m\u00e1 pr\u00e1vo z\u00edska\u0165 potvrdenie, \u010di sa jeho \u00fadaje sprac\u00favaj\u00fa, a pr\u00edstup k inform\u00e1ci\u00e1m vr\u00e1tane:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>\u00fa\u010dely sprac\u00favania<\/li>\n\n\n<li>kateg\u00f3rie osobn\u00fdch \u00fadajov<\/li>\n\n\n<li>pr\u00edjemcovia, ktor\u00fdm boli alebo bud\u00fa \u00fadaje spr\u00edstupnen\u00e9<\/li>\n\n\n<li>predpokladan\u00e1 doba uchov\u00e1vania<\/li>\n\n\n<li>existencia pr\u00e1v na opravu, vymazanie, obmedzenie a namietanie<\/li>\n\n\n<li>pr\u00e1vo poda\u0165 s\u0165a\u017enos\u0165 dozorn\u00e9mu org\u00e1nu<\/li>\n\n\n<li>inform\u00e1cie o zdroji \u00fadajov (ak neboli z\u00edskan\u00e9 priamo)<\/li>\n\n\n<li>existencia automatizovan\u00e9ho rozhodovania vr\u00e1tane profilovania<\/li>\n\n<\/ul>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 15<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Pr\u00e1vo na opravu (rectification)<\/h3>\n\n\n\n<p>Dotknut\u00e1 osoba m\u00e1 pr\u00e1vo bez zbyto\u010dn\u00e9ho odkladu opravi\u0165 nepresn\u00e9 \u00fadaje a doplni\u0165 ne\u00fapln\u00e9 \u00fadaje.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 16<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Pr\u00e1vo na vymazanie (right to be forgotten)<\/h3>\n\n\n\n<p>Vymazanie mus\u00ed\u0161 umo\u017eni\u0165, ak nastane niektor\u00e1 z t\u00fdchto situ\u00e1ci\u00ed:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>\u00dadaje u\u017e nie s\u00fa potrebn\u00e9 na p\u00f4vodn\u00fd \u00fa\u010del.<\/li>\n\n\n<li>Osoba odvol\u00e1 s\u00fahlas a neexistuje in\u00fd pr\u00e1vny z\u00e1klad sprac\u00favania.<\/li>\n\n\n<li>Osoba namieta sprac\u00favanie a neexistuj\u00fa nadraden\u00e9 legit\u00edmne d\u00f4vody.<\/li>\n\n\n<li>\u00dadaje boli sprac\u00favan\u00e9 nez\u00e1konne.<\/li>\n\n\n<li>\u00dadaje musia by\u0165 vymazan\u00e9 kv\u00f4li splneniu pr\u00e1vnej povinnosti.<\/li>\n\n\n<li>\u00dadaje boli z\u00edskan\u00e9 v s\u00favislosti so slu\u017ebami informa\u010dnej spolo\u010dnosti pon\u00faknut\u00fdmi die\u0165a\u0165u.<\/li>\n\n<\/ol>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 17<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Pr\u00e1vo na obmedzenie sprac\u00favania<\/h3>\n\n\n\n<p>Obmedzenie sprac\u00favania sa uplatn\u00ed, ke\u010f:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Osoba spochybn\u00ed spr\u00e1vnos\u0165 \u00fadajov (na \u010das potrebn\u00fd na overenie).<\/li>\n\n\n<li>Sprac\u00favanie je nez\u00e1konn\u00e9 a osoba nes\u00fahlas\u00ed s vymazan\u00edm.<\/li>\n\n\n<li>Controller u\u017e \u00fadaje nepotrebuje, ale osoba ich potrebuje na pr\u00e1vne n\u00e1roky.<\/li>\n\n\n<li>Osoba namietala sprac\u00favanie, k\u00fdm sa over\u00ed opr\u00e1vnenos\u0165 d\u00f4vodov.<\/li>\n\n<\/ol>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 18<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Pr\u00e1vo by\u0165 informovan\u00fd o oprave, vymazan\u00ed alebo obmedzen\u00ed u pr\u00edjemcov<\/h3>\n\n\n\n<p>Controller m\u00e1 ozn\u00e1mi\u0165 opravu, vymazanie alebo obmedzenie sprac\u00favania ka\u017ed\u00e9mu pr\u00edjemcovi, ktor\u00e9mu boli \u00fadaje poskytnut\u00e9 \u2013 pokia\u013e to nie je nemo\u017en\u00e9 alebo by to nevy\u017eadovalo neprimeran\u00e9 \u00fasilie.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 19<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Pr\u00e1vo na prenosite\u013enos\u0165 \u00fadajov<\/h3>\n\n\n\n<p>Osoba m\u00e1 pr\u00e1vo dosta\u0165 svoje \u00fadaje v \u0161trukt\u00farovanom, be\u017ene pou\u017e\u00edvanom a strojovo \u010ditate\u013enom form\u00e1te a m\u00e1 pr\u00e1vo prenies\u0165 ich k in\u00e9mu controllerovi bez prek\u00e1\u017eok.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 20<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Pr\u00e1vo namieta\u0165<\/h3>\n\n\n\n<p>Osoba m\u00f4\u017ee z d\u00f4vodov s\u00favisiacich s jej konkr\u00e9tnou situ\u00e1ciou kedyko\u013evek namieta\u0165 sprac\u00favanie zalo\u017een\u00e9 na opr\u00e1vnen\u00fdch z\u00e1ujmoch alebo verejnom z\u00e1ujme \u2013 vr\u00e1tane profilovania.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 21<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Pr\u00e1vo neby\u0165 predmetom v\u00fdlu\u010dne automatizovan\u00e9ho rozhodovania<\/h3>\n\n\n\n<p>Osoba m\u00e1 pr\u00e1vo neby\u0165 predmetom rozhodnutia zalo\u017een\u00e9ho v\u00fdlu\u010dne na automatizovanom sprac\u00favan\u00ed (vr\u00e1tane profilovania), ak m\u00e1 pr\u00e1vne \u00fa\u010dinky alebo na \u0148u podobne v\u00fdznamne vpl\u00fdva.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR Article 22<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Praktick\u00e9 implementa\u010dn\u00e9 kroky pre web (od security po marketing)<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1) Zabezpe\u010d web (minimum, ktor\u00e9 by malo by\u0165 samozrejmos\u0165ou)<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Nain\u0161taluj <strong>SSL certifik\u00e1t<\/strong> a pou\u017e\u00edvaj <strong>HTTPS<\/strong>, aby sa \u0161ifroval prenos d\u00e1t medzi webom a serverom.<\/li>\n\n\n<li>Pou\u017e\u00edvaj <strong>siln\u00e9 hesl\u00e1<\/strong> pre v\u0161etky admin \u00fa\u010dty.<\/li>\n\n\n<li>Pri sprac\u00favan\u00ed platieb pridaj <strong>extra ochranu<\/strong> pre pr\u00e1cu s platobn\u00fdmi \u00fadajmi.<\/li>\n\n\n<li>Pou\u017ei <strong>CDN poskytovate\u013ea<\/strong>, ktor\u00fd pom\u00e1ha s ochranou proti <strong>DDoS<\/strong> \u00fatokom.<\/li>\n\n\n<li>Nasa\u010f <strong>anti-virus<\/strong> (resp. primeran\u00e9 anti-malware opatrenia) na prevenciu neopr\u00e1vnen\u00e9ho pr\u00edstupu.<\/li>\n\n\n<li><strong>Minimalizuj zber d\u00e1t<\/strong> \u2013 zbieraj iba to, \u010do je naozaj potrebn\u00e9.<\/li>\n\n\n<li>Pred ulo\u017een\u00edm \u00fadaje <strong>pseudonymizuj alebo anonymizuj<\/strong>, ak to d\u00e1va zmysel a je to mo\u017en\u00e9.<\/li>\n\n\n<li>Rob <strong>z\u00e1lohy<\/strong> do viacer\u00fdch bezpe\u010dn\u00fdch lokal\u00edt.<\/li>\n\n\n<li>Nastav <strong>mazanie d\u00e1t<\/strong>, ke\u010f u\u017e nie s\u00fa potrebn\u00e9.<\/li>\n\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">2) Cookie consent banner (spr\u00e1vne, nie len \u201eaby nie\u010do bolo\u201c)<\/h3>\n\n\n\n<p>Ak pou\u017e\u00edva\u0161 na webe nevyhnutn\u00e9 vs. nevyhnutn\u00e9 (non-essential) cookies, pri t\u00fdch nevyhnutn\u00fdch to b\u00fdva o opr\u00e1vnenom z\u00e1ujme \/ technickej potrebe, ale pri marketingov\u00fdch a analytick\u00fdch \u010dasto potrebuje\u0161 <strong>v\u00fdslovn\u00fd s\u00fahlas pred aktiv\u00e1ciou<\/strong>.<\/p>\n\n\n\n<p>Cookie banner mus\u00ed sp\u013a\u0148a\u0165 tieto po\u017eiadavky:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>Blokova\u0165 cookies do udelenia s\u00fahlasu<\/strong>: na\u010d\u00edtaj iba nevyhnutn\u00e9 cookies, k\u00fdm pou\u017e\u00edvate\u013e neopt\u2011in.<\/li>\n\n\n<li><strong>Jednoduch\u00fd a jasn\u00fd jazyk<\/strong>: vysvetli, ak\u00e9 cookies pou\u017e\u00edva\u0161 a pre\u010do.<\/li>\n\n\n<li><strong>Rovnocenn\u00e9 tla\u010didl\u00e1 prija\u0165\/odmietnu\u0165<\/strong>: neukr\u00fdvaj odmietnutie.<\/li>\n\n\n<li><strong>Granul\u00e1rne vo\u013eby<\/strong>: umo\u017eni vybra\u0165 kateg\u00f3rie cookies.<\/li>\n\n\n<li><strong>Mo\u017enos\u0165 odvola\u0165 s\u00fahlas<\/strong>: pou\u017e\u00edvate\u013e mus\u00ed vedie\u0165 nesk\u00f4r zmeni\u0165 preferencie.<\/li>\n\n\n<li><strong>Z\u00e1znam o s\u00fahlase<\/strong>: ukladaj vo\u013eby s \u010dasovou pe\u010diatkou (timestamp), aby si vedel preuk\u00e1za\u0165 s\u00falad.<\/li>\n\n<\/ul>\n\n\n\n<div class=\"wp-block-group callout callout-info is-style-info is-layout-flow wp-block-group-is-layout-flow\" style=\"border-width:1px;border-radius:8px;padding-top:1rem;padding-right:1.5rem;padding-bottom:1rem;padding-left:1.5rem\">\n\n<h4 class=\"wp-block-heading callout-title\">Pozn\u00e1mka k s\u00fahlasu<\/h4>\n\n\n<p>Scrollovanie alebo pas\u00edvne spr\u00e1vanie nie je s\u00fahlas. S\u00fahlas mus\u00ed by\u0165 akt\u00edvny \u00fakon.<\/p>\n\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">3) Rev\u00edzia formul\u00e1rov na webe<\/h3>\n\n\n\n<p>Ka\u017ed\u00fd formul\u00e1r, ktor\u00fd zbiera osobn\u00e9 \u00fadaje (kontakt, objedn\u00e1vka, registr\u00e1cia, dopyt), m\u00e1 ma\u0165 GDPR-friendly UX aj texty:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Kr\u00e1tke <strong>privacy vyhl\u00e1senie<\/strong>, pre\u010do \u00fadaje potrebuje\u0161.<\/li>\n\n\n<li><strong>Neza\u0161krtnut\u00fd checkbox<\/strong> pre s\u00fahlas (ak ide o sprac\u00favanie na z\u00e1klade s\u00fahlasu).<\/li>\n\n\n<li><strong>Samostatn\u00fd opt\u2011in<\/strong> pre marketing (oddelen\u00e9 od s\u00fahlasu s vybaven\u00edm dopytu).<\/li>\n\n\n<li>Odkaz na <strong>Privacy Policy<\/strong>.<\/li>\n\n\n<li><strong>Jasn\u00fd, jednoduch\u00fd jazyk<\/strong>.<\/li>\n\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4) S\u00fahlas pre marketingov\u00e9 e\u2011maily<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Pou\u017ei iba <strong>clear opt\u2011in<\/strong>: neza\u0161krtnut\u00fd checkbox \u0161pecificky pre e\u2011mailov\u00fd s\u00fahlas.<\/li>\n\n\n<li>Implementuj <strong>double opt\u2011in<\/strong>: potvrdenie prihl\u00e1senia cez e\u2011mail.<\/li>\n\n\n<li>Udr\u017eiavaj <strong>z\u00e1znamy o s\u00fahlase<\/strong>: d\u00e1tum, \u010das, sp\u00f4sob a \u00fa\u010del.<\/li>\n\n\n<li>Do ka\u017ed\u00e9ho e\u2011mailu daj <strong>vidite\u013en\u00fd unsubscribe link<\/strong> (ide\u00e1lne na jedno kliknutie).<\/li>\n\n\n<li>Odhl\u00e1senia sprac\u00favaj r\u00fdchlo \u2013 ide\u00e1lne <strong>do 24 hod\u00edn<\/strong>.<\/li>\n\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">5) Pripravenos\u0165 na \u00fanik d\u00e1t (data breach)<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Nahl\u00e1s incident dozorn\u00e9mu org\u00e1nu do <strong>72 hod\u00edn<\/strong>.<\/li>\n\n\n<li>Ak je vysok\u00e9 riziko pre pr\u00e1va dotknut\u00fdch os\u00f4b, informuj aj <strong>pou\u017e\u00edvate\u013eov<\/strong>.<\/li>\n\n\n<li>V\u0161etko <strong>zdokumentuj<\/strong> (accountability).<\/li>\n\n\n<li>Uprav intern\u00e9 postupy a opatrenia, aby sa incident neopakoval.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">WordPress \u0161pecifik\u00e1: \u010do si postr\u00e1\u017ei\u0165 na typickom webe<\/h2>\n\n\n\n<p>Pri WordPress weboch sa GDPR l\u00e1me hlavne na pluginoch a integr\u00e1ci\u00e1ch. Technicky m\u00f4\u017ee\u0161 ma\u0165 pekn\u00fa Privacy Policy, ale ak plugin potichu posiela d\u00e1ta tretej strane, je probl\u00e9m.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Udr\u017eiavaj WordPress core, t\u00e9my a pluginy <strong>aktualizovan\u00e9<\/strong>.<\/li>\n\n\n<li>Pou\u017e\u00edvaj kontaktn\u00e9 formul\u00e1re, ktor\u00e9 podporuj\u00fa <strong>consent checkboxy<\/strong>.<\/li>\n\n\n<li>Nain\u0161taluj a spr\u00e1vne nastav <strong>cookie consent rie\u0161enie<\/strong> (vr\u00e1tane blokovania do s\u00fahlasu).<\/li>\n\n\n<li>Pou\u017e\u00edvaj <strong>GDPR-compliant analytiku<\/strong> (najm\u00e4 z poh\u013eadu cookies a prenosov).<\/li>\n\n\n<li>Skontroluj, ako jednotliv\u00e9 pluginy <strong>zbieraj\u00fa d\u00e1ta<\/strong> (formul\u00e1re, logy, embedded slu\u017eby).<\/li>\n\n\n<li>Implementuj funkcie na <strong>export a vymazanie pou\u017e\u00edvate\u013esk\u00fdch d\u00e1t<\/strong>.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Pokuty a \u010fal\u0161ie d\u00f4sledky<\/h2>\n\n\n\n<p>GDPR rozli\u0161uje dve \u00farovne pok\u00fat:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>Ni\u017e\u0161ia \u00farove\u0148 poru\u0161enia<\/strong>: a\u017e <strong>10 mili\u00f3nov \u20ac<\/strong> alebo <strong>2 %<\/strong> z celosvetov\u00e9ho ro\u010dn\u00e9ho obratu.<\/li>\n\n\n<li><strong>Vy\u0161\u0161ia \u00farove\u0148 poru\u0161enia<\/strong>: a\u017e <strong>20 mili\u00f3nov \u20ac<\/strong> alebo <strong>4 %<\/strong> z celosvetov\u00e9ho ro\u010dn\u00e9ho obratu.<\/li>\n\n<\/ul>\n\n\n\n<p>Okrem finan\u010dn\u00fdch sankci\u00ed m\u00f4\u017eu \u00farady napr\u00edklad vyda\u0165 varovanie, do\u010dasne alebo trvalo zak\u00e1za\u0165 sprac\u00favanie, nariadi\u0165 vymazanie d\u00e1t alebo obmedzi\u0165 prenosy d\u00e1t.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ (naj\u010dastej\u0161ie ot\u00e1zky)<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u010co je GDPR compliance checklist?<\/h3>\n\n\n\n<p>Je to zoznam konkr\u00e9tnych krokov, ktor\u00e9 potrebuje\u0161 spravi\u0165, aby si sp\u013a\u0148al po\u017eiadavky GDPR. Pom\u00e1ha n\u00e1js\u0165 slab\u00e9 miesta v procesoch ochrany osobn\u00fdch \u00fadajov a systematicky ich opravi\u0165.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Kto je zodpovedn\u00fd za GDPR compliance?<\/h3>\n\n\n\n<p>Prim\u00e1rnu zodpovednos\u0165 m\u00e1 data controller (typicky majite\u013e webu alebo firma). Aj data processor m\u00e1 v\u0161ak vlastn\u00e9 povinnosti a mus\u00ed zavies\u0165 technick\u00e9 a organiza\u010dn\u00e9 opatrenia.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Plat\u00ed GDPR aj pre firmy v USA?<\/h3>\n\n\n\n<p>\u00c1no \u2013 ak sprac\u00fava\u0161 osobn\u00e9 \u00fadaje \u013eud\u00ed z E\u00da, GDPR sa uplat\u0148uje bez oh\u013eadu na to, kde je firma registrovan\u00e1.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ak\u00e1 je maxim\u00e1lna pokuta za nedodr\u017eanie?<\/h3>\n\n\n\n<p>A\u017e <strong>20 mili\u00f3nov \u20ac alebo 4 %<\/strong> z celosvetov\u00e9ho ro\u010dn\u00e9ho obratu (pod\u013ea toho, \u010do je vy\u0161\u0161ie).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Potrebujem cookie banner?<\/h3>\n\n\n\n<p>\u00c1no, ak pou\u017e\u00edva\u0161 nevyhnutn\u00e9 cookies (napr. marketingov\u00e9 alebo analytick\u00e9) a m\u00e1\u0161 n\u00e1v\u0161tevn\u00edkov z E\u00da. Vtedy mus\u00ed\u0161 z\u00edska\u0165 s\u00fahlas pred ich aktiv\u00e1ciou.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Potrebujem Data Protection Officer (DPO)?<\/h3>\n\n\n\n<p>Len vtedy, ak: (1) si org\u00e1n verejnej moci, (2) tvoje hlavn\u00e9 \u010dinnosti zah\u0155\u0148aj\u00fa rozsiahle a systematick\u00e9 monitorovanie \u013eud\u00ed, alebo (3) sprac\u00fava\u0161 citliv\u00e9 \u00fadaje vo ve\u013ekom rozsahu.<\/p>\n\n\n<div class=\"references-section\">\n                <h2>Referencie \/ Zdroje<\/h2>\n                <ul class=\"references-list\"><li><a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\" target=\"_blank\" rel=\"noopener noreferrer\">Regulation (EU) 2016\/679 of the European Parliament and of the Council (General Data Protection Regulation)<\/a><\/li><\/ul>\n            <\/div>","protected":false},"excerpt":{"rendered":"<p>GDPR nie je jednorazov\u00fd \u201epapier do \u0161upl\u00edka\u201c, ale s\u00fabor konkr\u00e9tnych procesov, ktor\u00e9 mus\u00ed\u0161 vedie\u0165 preuk\u00e1za\u0165. Tento checklist ti pom\u00f4\u017ee krok za krokom skontrolova\u0165, \u010di tvoj web (a najm\u00e4 zber d\u00e1t okolo neho) sp\u013a\u0148a z\u00e1kladn\u00e9 po\u017eiadavky.<\/p>\n","protected":false},"author":36,"featured_media":139,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[37,86,84,85,10],"class_list":["post-140","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bezpecnost","tag-bezpecnost","tag-cookies","tag-gdpr","tag-privacy","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/helloblog.io\/sk\/wp-json\/wp\/v2\/posts\/140","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/helloblog.io\/sk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/helloblog.io\/sk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/helloblog.io\/sk\/wp-json\/wp\/v2\/users\/36"}],"replies":[{"embeddable":true,"href":"https:\/\/helloblog.io\/sk\/wp-json\/wp\/v2\/comments?post=140"}],"version-history":[{"count":0,"href":"https:\/\/helloblog.io\/sk\/wp-json\/wp\/v2\/posts\/140\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/helloblog.io\/sk\/wp-json\/wp\/v2\/media\/139"}],"wp:attachment":[{"href":"https:\/\/helloblog.io\/sk\/wp-json\/wp\/v2\/media?parent=140"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/helloblog.io\/sk\/wp-json\/wp\/v2\/categories?post=140"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/helloblog.io\/sk\/wp-json\/wp\/v2\/tags?post=140"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}