Regulatory, ESG, Cybersecurity, Data Privacy

Our firm provides comprehensive legal advisory in the fields of regulation, data privacy, and cybersecurity. We specialize in compliance with data protection laws, cyber threats, and environmental, social, and governance (ESG) standards. We assist clients in managing risks, ensuring compliance, and protecting their legal and business interests in these rapidly evolving areas.

Client credentials

Cryptelo s.r.o.

Weinhold Legal provided comprehensive legal advice to Cryptelo s.r.o. in the preparation and successful implementation of the issue of its own cryptographic CRL under the so-called ICO - initial coin offer. Cryptelo s.r.o. deals with the encryption of data for the commercial sphere with the highest level of security. The resources obtained at ICO are used to further develop its products. The public phase of the ICO ended on 30th April, 2018, with the acquisition of digital resources to the satisfaction of the client.

Show more

ThreatMark

Weinhold Legal has successfully advised Czech technology company ThreatMark in its Series A financing round, securing an investment exceeding $23 million from London-based Octopus Ventures and global investment firm The Riverside Company.

Show more

Resistant AI

Weinhold Legal is proud to have advised to Resistant AI, a Czech-based fintech firm specializing in AI-powered fraud prevention, in its $25 million Series B funding round. Led by DTCP Growth, with continued support from Experian, Notion Capital, and GV (formerly Google Ventures), this round brings the total capital raised by the company to $53 million. Resistant AI is also supported by the local VC fund, Credo Ventures.

Show more

Wienerberger

Weinhold Legal advised the Wienerberger Group on a comprehensive GDPR readiness project. The firm continues to provide day-to-day data protection advice across the group in the Czech Republic and Slovakia and acts as Data Protection Officer (DPO) for all group companies in both jurisdictions.

Show more

Lagardère Travel Retail

Weinhold Legal advised Lagardère on a comprehensive GDPR readiness project, including support in handling personal data breaches and incidents. The firm continues to provide ongoing compliance support, covering key regulatory areas such as the implementation of whistleblowing frameworks.

Show more
Show all credentials

Meet the team

Key Contacts

If you need assistance in Regulatory, ESG, Cybersecurity, Data Privacy, please do not hesitate to contact us.

+
Managing Associates

Tereza Hošková

Managing Associate

Tereza Hošková

Managing Associate

Public Procurement

Regulatory, ESG, Cybersecurity, Data Privacy

Foreign lawyers’ coordination

Pharmaceuticals, Healthcare

View profile
+
Partners & Associate Partners

Martin Lukáš

Partner

Martin Lukáš

Partner

IT & IP Law

Retail & e-commerce

Public Procurement

Multidisciplinary coordination

View profile
+
Associates and Professional staff

Nikola Faltová

Senior Associate

Nikola Faltová

Senior Associate

Regulatory, ESG, Cybersecurity, Data Privacy

View profile
+
Associates and Professional staff

Karolína Šindelářová

Senior Associate

Karolína Šindelářová

Senior Associate

Regulatory, ESG, Cybersecurity, Data Privacy

Mergers & Acquisitions

Corporate Law

View profile
+
Associates and Professional staff

Monika Švaříčková

Senior Associate

Monika Švaříčková

Senior Associate

Regulatory, ESG, Cybersecurity, Data Privacy

View profile

We are recognized by the media

See all media recognitions

21.10.2025

New Critical Infrastructure Act in relation to the new Cybersecurity Act (CZ)

On August 19, 2025, a completely new Act 266/2025 Coll., on the resilience of critical infrastructure entities and on amendments to related acts (hereinafter referred to as the “ZoKI”) entered into force. This Act removes the issue of critical infrastructure from the current Crisis Act and introduces a separate legal regulation of the resilience of critical entities. The new regulation responds in particular to the requirements of Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC (hereinafter referred to as the “CER”), which it transposes into the Czech legal order. The aim of the ZoKI is to strengthen the resilience of basic services necessary for the functioning of the state and thus prepare the Czech Republic for current threats, such as cyber attacks or sabotage of critical systems.

Open in a new window

25.04.2025

European Commission proposal to relax ESG reporting rules (CZ)

On 26 February 2025, the European Commission published two new legislative proposals, called Omnibus I and Omnibus II. The proposals, which are to affect several European regulations related to sustainability and ESG, aim to reduce the administrative burden on companies, improve sustainability rules and free up investment. The omnibus packages are intended to ease the administrative burden on small and medium-sized enterprises (SMEs) the most. What specific measures has the European Commission proposed? The following article explains this.

Open in a new window

10.01.2025

Notification of breaches under GDPR – when should breaches be reported and is reporting incidents electronically via the Personal Data Protection Office form really effective? (CZ)

With increasing digitalization, the need for personal data protection is becoming increasingly important. In order to respond effectively and quickly to personal data breaches, the General Data Protection Regulation[1] (hereinafter referred to as the “GDPR”) has established the obligation to notify breaches to the supervisory authority. This role is performed by the Office for Personal Data Protection (hereinafter referred to as the “OPO”).

Open in a new window

27.12.2024

What new does the draft law on cybersecurity bring, not only in the area of ​​sanctions for its violation? (CZ)

The draft law on cyber security (parliamentary press no. 759) is a transposition of the European security directive NIS 2. In addition to implementing the European regulation into the Czech legal system, its main purpose is to set at least a basic level of cyber security in organizations that provide their services in sectors important for the functioning of the state, such as energy, state administration, the food industry or healthcare.

Open in a new window
See all media recognitions

Let’s talk about
your case

Start the conversation and we’ll take it from there.

Get in touch
with us

Office Prague 

View on Map

Office Brno

View on Map

Get in touch with us

Get the news from the world of law

How we handle personal data is described here.

Omlouváme se, ale pro tuhle stránku neexistuje překlad