Skip to the content
Global Data RulesData governance rules, country by country

Slovenia

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

Slovenia has no general rule that data must stay in the country. It runs on the European rulebook: send data abroad once you have the right paperwork. Three things break that. The company running the new national health record system may not store data outside Slovenia. Government bodies may cloud only their least sensitive data. And working-time records must sit at the Slovenian workplace.

Eight questions about Slovenia

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Slovenia's rules apply to my company?

Yes. Slovenia's privacy rules reach a company with no office there. If you offer goods or services to people in Slovenia, or watch what they do online, the European rules apply to you and Slovenia's own privacy act applies alongside them. There is no size or revenue threshold that lets you out. A company with no office anywhere in Europe must appoint a written representative inside Europe.

High confidenceNational rulesAppoint a local representative

Can I store my users' data outside Slovenia?

In general yes, with paperwork — Slovenia adds no national storage-location rule of its own on top of the European regime. But four industries break that answer, and one of them is a hard wall. Health is the big one: the state company that runs Slovenia's central health record system is banned outright from storing or sending personal data outside Slovenia, and every healthcare provider must connect to that system. Government cloud, employment records and gambling each carry their own restriction.

High confidenceDepends on your industryAllowlist

What do I need in place before data leaves Slovenia?

Slovenia uses the European model, and it works like an approved-destinations list with escape hatches. Data may go to a country the European Commission has approved. If the destination is not approved, you can still send data by signing the Commission's standard contract, using approved group-wide rules, or relying on one of a few narrow exceptions. Slovenia adds nothing of its own. The old Slovenian system, where the Information Commissioner had to authorise each export, was scrapped when the current privacy act arrived in January 2023.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesCertification schemeApproved code of conductExplicit consentNeeded for a contractLegal claims

Who enforces the rules in Slovenia, and what can they do?

The Information Commissioner, and it is genuinely working. In 2025 it opened 464 inspection cases from complaints plus 102 more from inspection reports, issued 134 enforcement decisions, fined in 89 of them, gave warnings in 45, and handed down what it calls its largest fine since the European rules began. It handled 153 breach reports. It is small: one commissioner and 53 staff at the end of 2025, and it says openly that it does not have enough people. Cybersecurity is enforced separately by a government office set up for the job.

High confidenceActive

How long do I have to keep the data?

Both directions, and the floors are long. A patient's medical file must be kept for ten years after the patient dies, and other basic medical records for fifteen years. Records of who touched personal data in a computer system must be kept for two years after the end of the year, and up to five if the risk is high. Working-time records must be kept at the Slovenian workplace. In the other direction the European rule applies: delete personal data once the purpose is spent.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

Count three clocks, not one. A personal data breach goes to the Information Commissioner within 72 hours. A serious cyber incident, if you are an essential or important organisation, goes to the government security office immediately and in any case within 24 hours as an early warning, then a full report within 72 hours, then a final report within one month. Telecoms operators have their own duties on top. Missing the 24-hour warning is the most common failure, because it lands while you are still working out what happened.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Slovenia?

Five things that catch people out. A child can consent at 15 in Slovenia, not 16 — one year younger than the European default. Fingerprints and face scans are banned in the private sector unless a law allows them and the Commissioner approves. Every access to a covered database must be logged and the log kept two years. Leaking personal data you got through your job is a crime, not just a fine. And working-time records must physically be at the Slovenian workplace, which no cloud contract fixes.

High confidenceGet a parent's consent for childrenKeep logsRegister or notifyHold a security certificateCriminal liability

What is changing soon in Slovenia?

Two dates in the next twelve months matter most. On 19 December 2026 the cybersecurity duties bite for organisations newly captured by Slovenia's 2025 Information Security Act — registration, security measures and the incident clocks. On 12 January 2027 the European Data Act bans all cloud switching and data export fees. Behind both sits the roll-out of the national health record system, whose ban on storing data outside Slovenia is already law but whose timetable we could not pin down.

Medium confidencePartly in force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    3 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    4 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    7 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules3 rules

Uredba (EU) 2016/679 Evropskega parlamenta in Sveta (Splošna uredba o varstvu podatkov)

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European baseline that governs almost all personal data in Slovenia. It does not require data to stay in Europe; it sets the conditions under which data may leave.

In force since 25 May 2018

Enforced by Information Commissioner of the Republic of Slovenia

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Uredba (EU) 2018/1807 o okviru za prosti pretok neosebnih podatkov v Evropski uniji

Directly binding regulation · Regulation (EU) 2018/1807

In forceYes — store it anywhere

Slovenia is forbidden from forcing non-personal data to be stored on its territory, except where public security genuinely requires it. Any Slovenian localisation demand has to justify itself against this rule.

In force since 28 May 2019

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Uredba (EU) 2023/2854 (Akt o podatkih)

Directly binding regulation · Regulation (EU) 2023/2854

Partly in forceYes — store it anywhere

The European Data Act has applied since 12 September 2025 and gives customers a right to switch cloud providers. Its hardest deadline is 12 January 2027, when all switching charges and data export fees must reach zero.

In force since 12 September 2025But only enforceable from 12 January 2027
High confidence

National rules4 rules

Zakon o varstvu osebnih podatkov (ZVOP-2)

Act of parliament · Uradni list RS, št. 163/22

In forceYes — store it anywhere

Slovenia's national privacy act, in force since 26 January 2023. It contains no requirement to keep data in Slovenia. What it does add on top of the European rules is a low age of child consent (15), a near-total ban on biometrics outside cases a law allows, detailed video surveillance rules, and a two-year processing log that catches out global logging architectures.

In force since 26 January 2023

Enforced by Information Commissioner of the Republic of Slovenia

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Zakon o spremembah in dopolnitvah Zakona o evidencah na področju dela in socialne varnosti (ZEPDSV-A)

Act of parliament · Uradni list RS, št. 50/23

In forceA copy must stay

Since 20 November 2023 an employer in Slovenia must keep the record of working time, and the documents supporting it, at its registered office or at the place where the worker actually works. A foreign employer running everything in an overseas system has a problem a labour inspector can see immediately.

In force since 20 May 2023But only enforceable from 20 November 2023

Enforced by Labour Inspectorate of the Republic of Slovenia

Medium confidence

Zakon o informacijski varnosti (ZInfV-1)

Act of parliament · Uradni list RS, št. 40/25

Partly in forceYes — store it anywhere

Slovenia's cybersecurity law, which brings the European network security rules into national law. It imposes no storage-location rule, but it adds a second incident clock on top of the privacy one: 24 hours for an early warning, 72 hours for the full notification, one month for the final report. Newly captured organisations must be compliant by 19 December 2026.

In force since 19 June 2025But only enforceable from 19 December 2026

Enforced by Government Office for Information Security

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules7 rules

Zakon o digitalizaciji zdravstva (ZDigZ)

Act of parliament · Uradni list RS, št. 100/25 · Health and social care

Partly in forceNo — it stays put

Slovenia's genuine hard wall. The state-owned company that runs the national central health information system and the central electronic health record is forbidden by statute from transferring or storing personal data outside Slovenian territory, and every healthcare provider in the country must connect its local system to that central infrastructure.

In force since 19 December 2025

Enforced by Ministry of Health

Transfer model: Not allowed

Medium confidence

Zakon o zbirkah podatkov s področja zdravstvenega varstva (ZZPPZ)

Act of parliament · Uradni list RS, št. 65/00, 47/15, 31/18 · Health and social care

In forceYes, with paperwork

Slovenia's health records law sets no rule about where health data is stored, but it sets long minimum retention: a patient's medical file must be kept for ten years after death and other basic medical documentation for fifteen years.

In force since 22 July 2000

Enforced by Information Commissioner of the Republic of Slovenia

Medium confidence

Uredba o informacijski varnosti v državni upravi

Directly binding regulation · Uradni list RS, št. 29/18 · Government

In forceYes, with paperwork

A Slovenian state administration body may put information in a public cloud only if that information sits in the lowest security tiers, and only after the ministry gives written approval. It is not a location rule — a Slovenian public cloud is treated the same as a foreign one — but in practice it keeps sensitive government data out of commercial clouds entirely.

In force since 5 May 2018

Enforced by Ministry of Digital Transformation

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence

Who you would hear from

  • Informacijski pooblaščenec Republike Slovenije

    Data protection supervision under the General Data Protection Regulation and ZVOP-2, and freedom of information

    Fully operational. Headed by dr. Jelena Virant Burnik, who took office in 2024. In 2025 it opened 464 inspection procedures on complaints and 102 on inspection reports, sent 176 advisory letters, issued 134 decisions in minor-offence proceedings of which 89 were fines and 45 warnings, and reports imposing its largest fine since the European rules began. It handled 153 personal data breach notifications. Staff at 31 December 2025: one appointed official and 53 public employees. The office states openly that this is not enough for its caseload and widening remit.

  • Urad Vlade Republike Slovenije za informacijsko varnost

    Cybersecurity supervision, registration of essential and important entities, and incident reporting under ZInfV-1

    Operational and publishing actively — leaflets, model incident-response documentation and conference material on the 2025 Information Security Act. It runs the self-registration scheme and the national incident reporting route.

  • Ministrstvo za zdravje

    Health digitalisation, the central electronic health record, and the state company running central health information infrastructure

    Operational. It sponsored the Health Digitalisation Act published on 4 December 2025 and runs the eZdravje programme and its 2026 conference cycle.

  • Finančna uprava Republike Slovenije

    Tax administration and supervision of games of chance, including the live link into online operators' systems

    Operational. It publishes the governing acts and supervision practice for games of chance on its own site.

  • Banka Slovenije

    Banking supervision, payment services, and the register of contracts with third-party technology providers under the European digital operational resilience rules

    Operational. It collects the register of technology-supplier contracts from supervised entities and publishes technical reporting instructions.

  • Agencija za zavarovalni nadzor

    Supervision of insurers, including digital operational resilience

    Operational. It publishes its own guidance on the European digital operational resilience and network security rules.

  • Arhiv Republike Slovenije

    Registration and certification of digital capture and storage services, equipment and software for documentary and archival material

    Operational. Registration and certification are live services with published fees, run through the national business portal.

  • Agencija za komunikacijska omrežja in storitve Republike Slovenije

    Electronic communications regulation under ZEKom-2

    Operational as the sector regulator. We did not verify its data-protection-specific enforcement activity on this run.

  • Ministrstvo za digitalno preobrazbo

    State administration information systems and approval of public cloud use by state bodies

    Operational. Which ministry now signs off cloud approvals under the 2018 decree was not separately confirmed on this run — the decree names 'the ministry' responsible for public administration information systems.

  • Inšpektorat Republike Slovenije za delo

    Enforcement of employment records duties, including where working-time records must be kept

    Operational. It is the body that inspects working-time records on site.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact commencement and phase-in dates of the Health Digitalisation Act (ZDigZ), including when the localisation duty in Article 7(7) starts to bite and by when healthcare providers must connect to the central system.

    The official gazette page for Official Gazette 100/25 truncates before the final and transitional provisions, and the government's legal information system serves its pages through JavaScript that we could not read. The in-force date of 19 December 2025 in this record is the standard fifteen-days-after-publication rule applied to a 4 December 2025 publication, not a quoted commencement article.

  • How far the health localisation duty reaches — whether it binds only the state-owned company running the central health infrastructure, or also its suppliers, sub-processors and individual healthcare providers.

    Article 7(7) on its face binds the company established as the public service provider. We could not find official guidance on whether the ministry reads it as flowing down the supply chain. Treat a foreign sub-processor to that company as high risk until this is clarified.

  • Whether the 2018 Decree on information security in state administration has been amended or replaced since the 2025 Information Security Act, and which ministry now grants cloud approvals.

    The gazette page we read is the original 2018 text. We found no repeal, but we also found no consolidated version on a government domain, and Slovenia has reorganised its digital ministries since 2018.

  • Minimum retention periods for tax, accounting and company records in Slovenia (commonly stated as ten years).

    The Financial Administration's own explanatory document is served as a binary Word file we could not read, and we did not find an equivalent HTML page on a government domain in the time available. The figure is widely repeated by professional sources but is not backed here by a government citation.

  • The value of the Information Commissioner's largest fine in 2025.

    The 2025 annual report states it imposed its highest fine since the European rules began but the figure did not appear in the section we could read.

  • The Constitutional Court's decision U-I-65/13 as read from the court's own site.

    The court's website returned an access error to our fetch on 18 August 2026. The substance — that blanket telecoms retention was annulled and there is no advance bulk retention duty — is taken from the Information Commissioner's own published opinion, which is a regulator source, so the claim stands but the primary court text is unverified on this run.

  • Whether Slovenian gambling rules require the gaming server itself to be located in Slovenia.

    Neither the Games of Chance Act consolidated text nor the November 2025 amending rules notified to the European Commission contain such a requirement in the parts we could read. The full implementing rules sit on the government's JavaScript-driven legal system, which we could not read. Recorded as 'no rule found, checked 18 August 2026' rather than 'no rule exists'.

  • Whether any Slovenian rule requires deposit of aerial survey imagery or maps with the state, as several neighbouring countries do.

    The new Aviation Act of 2024 and the national spatial data portal contain nothing of the kind in the parts we read. Checked 18 August 2026, no rule found, medium confidence.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.