Abstrakt v dalším jazyce: Since 2018, when a regulation called GDPR came into effect, all enteprises doing business in the European Union must implement new rules regarding the processing of personal data and generally ensure the privacy of their customers. Special attention is then paid to the online processing of personal data. In the 4 years since the GDPR came into force, the theoretical approaches to implementation as well as the best practices in the field of personal data processing are well known. However, less attention is already paid to the research of real impacts on the business processes of organizations, i.e. real approaches to implementation in the organization, as especially small businesses face a number of barriers and shortcomings that can prevent successful implementation. The presented research aims to close this research gap, using the proven case study methodology. In addition to the summary of the already known scientific knowledge, a case study dealing with the implementation of the GDPR within a small Czech e-shop is compiled. The issue of ensuring privacy in the selected e-shop is examined, the organization's specific approach to GDPR implementation is described, and possible prerequisites for successful implementation are analyzed. In addition to this, attention is paid to possible differences in the implementation of the GDPR in different EU countries. The obtained results of this research expand the previously known theoretical knowledge with new empirical findings, when, despite the successful implementation, the investigated company faced and still faces a number of organizational and technological barriers in the area of ensuring customer privacy.
