Czechia's economy runs on a dense network of automotive and industrial suppliers, complemented by a growing engineering and shared-service base around Prague, and buyers in both worlds increasingly run documented vendor checks even for smaller software tools. This page sets out the legal framework that applies here, what a Czech procurement or legal review typically asks for, and how lead.box is set up to answer it.
At a glance
- Framework
- GDPR + Act No. 110/2019 Sb.
- Supervision
- ÚOOÚ (Úřad pro ochranu osobních údajů)
- Usual legal basis
- Legitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
- Processing location
- ISO-certified EU data centres
The legal framework in Czechia
Regulation at a glance
- FrameworkGDPR + Act No. 110/2019 Sb.
- SupervisionÚOOÚ (Úřad pro ochranu osobních údajů)
- Usual legal basisLegitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
- Processing locationISO-certified EU data centres
The GDPR sets the substantive rules across the EU, and Czechia implements it domestically through Act No. 110/2019 Sb. on the Processing of Personal Data, which replaced the country's older data protection act and confirms ÚOOÚ (Úřad pro ochranu osobních údajů) as the national supervisory authority. ÚOOÚ is one of the EU's older data protection bodies, having supervised personal data processing in the country since well before the GDPR came into force, and it carried that experience directly into enforcement of the new regime.
ÚOOÚ has been a comparatively active authority on inspections and formal opinions, publishing detailed positions on camera systems, employee monitoring and, increasingly, website analytics and profiling tools, and it tends to test whether a company's documented legal basis matches what a script actually does on a live site. For a B2B website, that means the record of processing activities and the assessment behind any visitor-identification tool need to hold up to a fairly specific technical question, not just a general statement.
Cookie and similar device-storage rules sit in Act No. 127/2005 Sb. on Electronic Communications, as amended to reflect the ePrivacy Directive, and require prior consent before non-essential cookies are placed. Identification that resolves a visit to a company, without setting advertising identifiers or cross-site tracking cookies, falls outside that specific consent trigger, though everything else running on the site remains the controller's own assessment.
What the Czech market expects
Automotive and manufacturing suppliers in Czechia are used to strict compliance requirements from their own OEM customers, and that discipline carries over into how they vet software vendors: a data processing agreement under Art. 28 GDPR, a named sub-processor list and a clear statement on where data is processed are treated as a baseline, not a bonus question.
Prague's growing engineering and shared-service sector adds a second buyer type, generally faster to move but equally likely to ask for a versioned sub-processor list and a written data-retention policy before sign-off. Documentation in Czech, alongside English, is commonly expected on the customer's own site and speeds up internal legal review considerably.
As elsewhere in the EU, a claim that a tool removes the need for a legal assessment does not survive contact with a reviewer familiar with ÚOOÚ practice. What holds up is a precise account of what is resolved to a company, what is discarded, and where the customer's own responsibility as controller begins.
Start free
Install the snippet and see the first named companies on your own traffic.
What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
Where identification pays off here
The clearest pattern in Czechia sits with automotive and industrial suppliers: engineering and sourcing contacts at OEMs and Tier 1 buyers research a supplier's technical pages, certifications and case studies across several sessions before a formal request for quotation is issued. Seeing that company appear early gives a sales team a real window to reach out while the evaluation is still underway.
Prague's engineering and shared-service scene adds a second, faster-moving pattern: teams evaluating a specialised B2B tool tend to browse integration and pricing pages quietly before a decision-maker gets involved, so even a modest weekly count of identified visits from the right companies already produces a usable outreach list.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
Yes, it is workable under the GDPR and Act No. 110/2019 Sb. provided identification stops at the company and never resolves to an individual employee. The usual legal basis is legitimate interest under Art. 6(1)(f) GDPR, backed by a documented balancing test and disclosed in your privacy policy rather than relying on consent. ÚOOÚ has published formal positions touching on profiling and monitoring tools, and a Czech reviewer will generally expect that balancing test to describe the specific tool in use rather than restate the GDPR in general terms. lead.box acts as processor under a data processing agreement and the final call remains yours as controller. Automotive supply-chain buyers in particular tend to raise this question early, often before pricing, so having a concrete written answer ready avoids a stalled first call.
ÚOOÚ, the Úřad pro ochranu osobních údajů, is Czechia's supervisory authority under both the GDPR and Act No. 110/2019 Sb. It is one of the EU's longer-established data protection bodies, having overseen personal data processing in the country well before the GDPR existed, and it carried that inspection culture directly into current enforcement. ÚOOÚ is comparatively active on formal opinions and inspections, publishing detailed positions on camera systems, employee monitoring and increasingly on website analytics and profiling tools, and it tends to check whether a documented legal basis actually matches what a script does on the live site rather than accepting a general statement. Naming ÚOOÚ directly, and pointing to how it treats company-level rather than individual-level signals, tends to move a Czech legal review forward faster than a generic GDPR reference.
Company-level identification with lead.box does not place advertising identifiers, device fingerprints or cross-site tracking cookies, so it falls outside the prior-consent requirement set out in Section 89 of Act No. 127/2005 Sb. on Electronic Communications, which transposes the ePrivacy Directive into Czech law. That provision requires informed consent before non-essential cookies are stored on a device, and a purely first-party company-resolution signal is generally read as sitting outside that specific trigger. Whether your site needs a banner for other scripts, such as marketing pixels or heatmap tools running alongside lead.box, remains your own assessment as controller, and Czech legal teams typically want that assessment documented separately rather than folded into a single blanket cookie policy statement.
Visitor and personal data concerning EU traffic is processed in ISO-certified EU data centres and is not transferred outside the EU for this purpose, which removes the international-transfer question Czech legal teams tied to automotive OEM compliance programmes often raise first. A data processing agreement under Art. 28 GDPR is available before signature, together with a named and versioned sub-processor list, matching the intake documentation Tier 1 and Tier 2 suppliers already require from their own software vendors as part of OEM-mandated security programmes. Retention periods are limited and stated explicitly in that agreement rather than left open-ended, since vague retention language is one of the more common reasons a reviewer familiar with ÚOOÚ practice sends supplier paperwork back for revision before a purchase order can be raised.
Czech buyers, especially in the automotive and manufacturing supply chain, generally expect a Czech-language privacy policy on their own site even where a vendor's own materials are in English, and treat its absence as a real documentation gap rather than a minor formality during review. This is not a strict GDPR requirement placed on lead.box as vendor, but it directly affects how quickly your own internal legal sign-off moves, since a reviewer working from an ÚOOÚ-style checklist will typically compare the published wording against the legal-basis reasoning expected in Czech-language guidance. lead.box's own legal documents and market pages are structured so the underlying legal basis, data flows and retention terms can be translated or referenced directly into your own Czech-language policy without reconstructing the reasoning.
Invoices should carry your company's DIČ, full registered name and address so they can be booked cleanly against a Czech cost centre without triggering a query from accounting or a mismatch during a VAT audit. Czech finance teams, particularly at OEM-adjacent suppliers used to formal purchase-order discipline, generally expect a subscription invoice to reference a signed contract and DPA number before releasing payment, so keeping procurement, legal and finance aligned on the same reference numbers saves a full review cycle. If your organisation is VAT-registered intra-EU, reverse-charge treatment normally applies to a cross-border SaaS subscription like lead.box, though your own accounting team should confirm the specific treatment for your entity before the first invoice is processed.
Standard web analytics aggregates traffic into sessions and page views; lead.box instead resolves individual visits to the specific company behind them, using IP-to-company matching combined with first-party tracking, so the output is a named account list rather than a traffic chart. It never attempts to identify the individual person browsing, which is the point Czech legal reviewers usually probe first, since identifying a person triggers a materially different and stricter analysis under the GDPR. Because the signal works at company level and does not depend on advertising cookies, it does not compete with the consent-based marketing tools already running on a Prague company's stack; most customers run it alongside existing analytics and feed the resulting company list directly into their CRM or sales outreach tooling instead of replacing anything.
Most Czech customers in the Prague engineering and shared-service scene complete review within one to two weeks once they have the DPA, sub-processor list and a written legal-basis answer in hand, since these teams often run legal and technical evaluation in parallel once a trial shows real identified companies. Automotive and industrial suppliers with formal OEM-driven supplier qualification programmes typically take longer, because lead.box needs to be added as a new approved vendor alongside existing security and compliance checks that were originally designed for hardware and component suppliers. Customers consistently report that having documentation ready in both English and Czech from the outset, rather than producing translations on request, is what shortens this timeline the most.
See which companies are already researching you in Czechia
Install a first-party snippet, watch the first companies appear, and hand your legal or procurement reviewer the documents in the same week.