Information for users pursuant to the Data Act (EU 2023/2854)⚓︎
Product Line: Turris Routers
Publisher: CZ.NIC, z.s.p.o., with its registered office at Milešovská 1136/5, 130 00 Prague 3, Company ID No.: 67985726, Tax ID No.: CZ67985726
Registered in the Association Register maintained by the Municipal Court in Prague, file no. L 58624
Document version: 1.0
Effective date: September 4, 2026
The Turris router may generate during its use data within the meaning of the Data Act. The scope, format, volume and nature of the data generated depend on which features the User activates. Below we provide mandatory information about what data may be generated, how it is processed, where it is stored, how it is transmitted and what are the User’s rights.
1. Generating data in factory settings
The Turris router is configured in the default (factory) settings as a passive network infrastructure. In this mode, the device does not generate or send any data that would meet the definition of “data generated by the use of a connected product” under Article 2(1) of the Data Act. Basic network traffic (packet routing, Internet connectivity) does not result in the creation of data that would be transmitted off-device or stored in a manner relevant under the Data Act.
2. Optional functions that may generate data
Data generation within the meaning of the Data Act only occurs upon voluntary activation of the software subsystems listed below. These subsystems are disabled by factory default.
2.1. Turris Sentinel (security telemetry)
- Types of data: metadata about detected network attacks (e.g. attackers’ IP addresses, attack type, timestamps).
- Expected volume of data: approximately a thousand events per day, depending on the intensity of attacks.
- Data formats: JSON, MsgPack; storing in PostgreSQL.
- Storage: the data is not stored locally but is sent continuously in real time to CZ.NIC servers, where it is stored for a period of one year.
- Transmission: via secure channel (MQTT/TLS).
- Purpose: cyber threat analytics and providing security.
- User access: via continuously updated Sentinel dashboard (may have short delays).
- Sharing with third parties: aggregated statistical data (to the extent of dashboard-presented data) can be shared at the User’s request strictly only for security purposes; raw IP addresses of attackers constitute personal data, and their transfer to a third party is permissible solely for the purposes of ensuring network and information security (legitimate interest of the User/recipient under GDPR); the third party may not use this data for any other purpose and sharing may require technical assurances or NDAs to protect the network integrity.
2.2. PaKon / MorÄŤe (home network monitoring)
- Types of data: network flow statistics (NetFlow/IPFIX), list of visited domains, IDS alerts.
- Expected volume of data: 1 database entry for each active connection
- Data formats: IPFIX/NetFlow, SQLite database.
- Storage: strictly locally on the router (directories
/srv/morce,/srv/pakon). - Retention: automatic data rotation when the full reserved capacity is reached, meaning that older records are overwritten.
- Transmission: no transmission outside the device.
- User access: continuous and real-time via the local reForis or SSH web interface (direct access to the SQLite database).
- Sharing with third parties: possible at the User’s request; as this is personal data, sharing requires legal title under GDPR.
2.3. Updater / Package List
- Types of data: information about the current software version, hardware revision, and list of installed packages.
- Expected volume of data: 10 MiB per day
- Data format: text queries over HTTPS.
- Storage and retention: locally on the device; no permanent user profiles are stored on the CZ.NIC Association servers.
- Statistics (TOS versions used, IP protocols, countries…): processed in near-real time; logs are only needed until the ELK stack processes them for the statistics (in the order of hours at the longest).
- Monitoring: logs are only needed until processed by the Zabbix tool (in the order of hours at the longest).
- Diagnostics: with a view to resolving user-related issues even after periods of time, logs are kept for the last 6 full months.
- Log backups: retained for 120 days (general default backup retention period). The backups are stored on a separate server and are encrypted.
- Transmission: encrypted queries over HTTPS.
- User access: 24/7 access via reForis or SSH.
- Sharing with a third party at the user’s request: YES – the data does not constitute personal data or trade secrets, hence its transfer is not subject to restrictions.
3. User rights under the Data Act
The User has the following rights:
- Right to access data generated by activated functions, in real time for locally stored data (PaKon/MorÄŤe) or through continuously updated reports for cloud services (Sentinel).
- Right to data portability, including the possibility to provide data to a third party.
- Right to free-tier and continuous access to data via a local interface (reForis, SSH).
- Right to deactivate any optional features and thereby immediately stop the generation and transmission of data.
The User can exercise their rights to access data and its portability electronically via email at info@turris.cz.
4. Third-party access
If the User provides data to a third party, the CZ.NIC Association will allow such access under fair, reasonable and non-discriminatory conditions, as set out in Articles 8 to 12 of the Data Act.
5. Data rights, intellectual property protection and cybersecurity
5.1. Scope of User access to data
Under the Data Act, the User may access only data that is a direct product of operation of the hardware they use (hereinafter referred to as “Operational Data”). The Operational Data to which the User has access includes:
- Raw telemetry data generated by the device
- Network traffic logs for a given node
- Volumes of transferred and processed data
- IP addresses of cyberattacks detected strictly on the specific User device
5.2. Exclusion of access and intellectual property protection
The right of access does not apply to data that is the result of software extensions, advanced analytics and development activities of the CZ.NIC Association (hereinafter referred to as “Enriched Data and Know-How”). This data is protected as trade secrets and copyright of the database creator under applicable law. The User does not have access to the following elements, which remain the exclusive property of the Provider:
- The structure of telemetric metadata and internal attack classification keys, which involve creative input and form a protected database structure.
- Methods of combining and aggregating data coming from different users.
- Algorithms and logic for generating a dynamic firewall.
Notice
The terms of use for the software, copyright protection for the firmware, and any restrictions on decompilation or reverse engineering of the source code are governed by the End User License Agreement (EULA) for the Turris OS operating system and generally applicable laws. This informational text serves solely to fulfill pre-contractual disclosure obligations and does not alter these license terms.
5.3. Restrictions and denial of access for cybersecurity reasons
The CZ.NIC Association acts in full compliance with the Data Act (in particular Article 4(2) and Article 5(8)) and cybersecurity regulations (e.g., the NIS 2 Directive). Access to data or its export to third parties may be restricted, suspended, or denied to the extent necessary, based solely on objective risks, if such sharing could demonstrably:
- Compromise the security requirements for the product itself (hardware and its protective functions).
- Cause a system vulnerability that could be exploited by attackers to bypass the firewall.
- Jeopardise cybersecurity of critical information infrastructure, important information systems or operators of essential services.
Any such denial or restriction of access will be duly justified by the Provider based on specific security risks.
6. Right to complain
The User has the right to file a complaint with the competent national supervisory authority in the Czech Republic (the Czech Telecommunications Office and, where protection of personal data is concerned, the Office for Personal Data Protection of the Czech Republic) if they believe that their rights under the Data Act have been violated.