Welcome to the new website of the Czech Statistical Office! Thank you for your feedback.

Skip to content

Information from the conducted proportionality test to identify public interest for the use of web analytics on the CZSO website

What is the purpose of processing?

Statistical evaluation of current traffic, loading of information pages and the running of the application, control of spent funds and subsequent informing of control institutions and the public. Ensuring the security of the network and information, i.e. the ability of the system to withstand, at a given level of reliability, random events or illegal or malicious actions threatening the availability, authenticity, correctness and confidentiality of stored or transmitted personal data and the security of related services provided or accessible through these systems.

Is the processing necessary to fulfill one or more specific objectives of the organization?

For the purposes of implementing the performance of the state statistical service and in connection with the use of the funds spent, it is necessary to monitor the level of services provided, adequately maintain and configure the optimal scaling of the performance of technical solutions, provide the public with information about their activities in an appropriate manner and at the same time act with the care of a proper manager (e.g. control activity, effective use of funds, evaluation of the quality of services provided, creation of reports and evaluation).

Does the GDPR include a specific processing activity as a legitimate act?

Recital (49) GDPR - Processing of personal data to the extent absolutely necessary and reasonable to ensure the security of the network and information, i.e. the ability of the network or information system to withstand, at a given level of reliability, random events or illegal or malicious actions threatening availability, authenticity, correctness and confidentiality of stored or transmitted personal data and the security of related services provided or accessible through these networks and systems implemented by public authorities […] represents the legitimate interest of the data controller concerned. For example, a legitimate interest could be to prevent unauthorized access to electronic communications networks and the spread of malicious code, and to prevent denial-of-service attacks and damage to computer and electronic communications systems.

Why is the processing important for other parties to whom the data is to be made available?

For website operation purposes, and following the use of the funds spent, it is necessary to provide the public with information about their activities in an appropriate manner and at the same time to act with the care of a proper manager (e.g. control activities, effective use of funds, evaluation of the quality of services provided, creation of reports and evaluation).

Does the processing have or can it have possible negative effects on the rights of the individual?

In compliance with all security principles and contractual conditions with subprocessors, the processing should not have negative effects on the rights of individuals.

Can a third party be harmed if the processing does not take place?

Yes, from the point of view of the security and efficiency of the Administrator's activities, if the processing is not carried out, harm may occur directly to the data subject.

Is there an imbalance in the relative position between the organization and the individual?

Yes, the Administrator is a public authority and the site visitor is a natural person.

Is the data subject informed of fair processing, if so, how? Are the processing purposes sufficiently clear and obvious?

Yes, general and detailed information is provided on the Administrator's website. The Czech Statistical Office informs users about the scope and purpose of data processing and also allows them, where possible, to influence such processing at any time by changing the settings for storing cookies in the user's browser.

Can the scope of processing be modified to reduce / mitigate any underlying risks or damage to privacy?

A consistent minimization of the stored data is applied and the anonymization of IP addresses is set, which practically excludes the identification of specific natural persons. The data is not used for marketing or other than declared purposes.