ÚOOÚ + GDPR + cookie banner, what’s required for a Czech store?
GDPR applies in Czechia, enforced by the ÚOÓÚ (Úřad pro ochranu osobních údajů, the Czech Data Protection Authority). The national implementation is Act No. 110/2019 Sb. on personal-data processing.
Concrete Magento checklist:
- Cookie consent, opt-in for non-essential cookies (analytics, marketing, retargeting). No pre-ticked checkboxes. “Reject all” must be as easy as “Accept all”. Banner in Czech. We typically ship Cookiebot, Cookieyes, or a self-built Magento module wired into the Magento cookie API.
- Privacy policy in Czech, citing ÚOÓÚ as the supervisory authority, plus the controller’s IČO + DIČ + registered address.
- Newsletter double opt-in, tick-box on registration is not enough, customer must click a confirmation email.
- Right-to-access + right-to-erasure, customer account page should expose data download + deletion request flows.
- Data Processing Agreement with hosting + email + payment providers. Adobe Commerce Cloud Frankfurt is fine for data residency; for ÚOÓÚ-conscious clients, WEDOS / Forpsi / Active 24 (all CZ-based) is the safer optics.
- Heureka pixel + Google Analytics only fire after consent, we wire Tag Manager conditional triggers.