Slovenia
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Slovenia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Slovenia has no general rule that data must stay in the country. It runs on the European rulebook: send data abroad once you have the right paperwork. Three things break that. The company running the new national health record system may not store data outside Slovenia. Government bodies may cloud only their least sensitive data. And working-time records must sit at the Slovenian workplace.
Data governance in Slovenia
The eight things that decide how you handle data about people in Slovenia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Slovenia's privacy rules reach a company with no office there. If you offer goods or services to people in Slovenia, or watch what they do online, the European rules apply to you. Slovenia's own privacy act applies alongside them. There is no size or revenue threshold that lets you out. A company with no office anywhere in Europe must appoint a written representative inside Europe.
- What you have to do here:
- Appoint a representative
Two layers stack up. The General Data Protection Regulation reaches companies outside Europe directly, under its Article 3(2). Article 27 requires a representative based in one of the member states where the affected people are. Slovenia's own act is ZVOP-2 (Zakon o varstvu osebnih podatkov, Official Gazette 163/22). Article 4 sets how far it reaches. It applies to data used in the course of the activities of a business based in Slovenia. It also applies to data about people in Slovenia handled by companies outside the European Union, wherever the work physically happens. ZVOP-2 does not add a separate Slovenia-only representative on top of the European one. Industry laws are narrower and reach only the regulated firm. The Health Digitalisation Act binds healthcare providers operating in Slovenia and the state company running the central system. The Games of Chance Act binds concession holders. The Information Security Act binds essential and important entities providing services in Slovenia.
Sources
- Official sourceUradni list Republike SlovenijeZakon o varstvu osebnih podatkov (ZVOP-2), Official Gazette of the Republic of Slovenia No. 163/22, Article 4 (veljavnost zakona — territorial scope)
uradni-list.si
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeKljučne novosti ZVOP-2 — the Information Commissioner's own summary of the new act, confirming it applies from 26 January 2023
ip-rs.si
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
Where the data is allowed to live
In general yes, with paperwork. Slovenia adds no national rule of its own about where data must be stored. But four industries break that answer, and one of them is absolute. Health is the big one. The state company that runs Slovenia's central health record system is banned outright from storing or sending personal data outside Slovenia. Every healthcare provider must connect to that system. Government cloud, employment records and gambling each carry their own restriction.
Industry by industry, checked on 18 August 2026. HEALTH — data must stay in the country for the central system. The Health Digitalisation Act (Zakon o digitalizaciji zdravstva, ZDigZ, Official Gazette 100/25 of 4 December 2025) creates a wholly state-owned company. That company runs the central health information and communication infrastructure and the central electronic health record. Article 7(7) says the company may not use the personal data for its own purposes. It also says the company may neither transfer nor store that data outside the territory of the Republic of Slovenia. Article 3(2) requires all healthcare providers to connect their local health information systems to that central infrastructure. So the national health record is legally pinned to Slovenian soil. A cloud offer routed through the state company cannot sit abroad. On its face this does not stop a private clinic from using a European cloud for its own local records. That reading is ours, and it is flagged as unconfirmed. GOVERNMENT — data can leave only if conditions are met, but very tight. The Decree on information security in state administration (Uredba o informacijski varnosti v državni upravi, Official Gazette 29/18) allows cloud services in Article 41. It allows them only for information that is unclassified or in the lowest tiers Z1, C1 and R1. It also requires the written approval of the ministry, which must first check the provider's terms. EMPLOYMENT — a copy must stay in the country Since 20 November 2023 there has been a rule about where the record is kept. It is Article 19(5) of the Records in the Field of Labour and Social Security Act as amended (ZEPDSV-A, Official Gazette 50/23). The employer keeps the working-time record and the documents behind it at its registered office, or at the place where the worker performs the work. A cloud copy is fine. An inspector who turns up must still be shown the record on the spot. GAMBLING — a rule about where the company sits, not where the data sits. Only a joint-stock company with its registered seat in Slovenia may organise games of chance (Games of Chance Act, Articles 30 and 55). An internet operator must connect its information system to the supervisory authority's information system (Article 3a). We found no rule requiring the server itself to sit in Slovenia. CHECKED AND NO RULE FOUND ON WHERE DATA MUST BE STORED: banking, payments, insurance, securities, telecoms, education, mapping and aerial survey, and defence-adjacent commercial work. Slovenia's financial regulators point firms at the European digital operational resilience rules. Those rules demand contracts, exit plans and disclosure of where data sits. They do not demand a location. Slovenia's new Aviation Act (ZLet-1, Official Gazette 85/24) contains no aerial-photography permit or imagery-deposit duty of the kind several neighbours have.
Sources
- Official sourceUradni list Republike SlovenijeZakon o digitalizaciji zdravstva (ZDigZ), Official Gazette No. 100/25 of 4 December 2025, Articles 3 and 7
uradni-list.si
“Osebnih podatkov kot pogodbeni obdelovalec ne sme obdelovati za svoje namene in jih ne sme niti prenašati niti hraniti izven ozemlja Republike Slovenije.”
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeUredba o informacijski varnosti v državni upravi, Official Gazette No. 29/18, Article 41 (cloud services)
uradni-list.si
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeZakon o spremembah in dopolnitvah Zakona o evidencah na področju dela in socialne varnosti (ZEPDSV-A), Official Gazette No. 50/23, Article 19(5)
uradni-list.si
“Delodajalec evidenco o izrabi delovnega časa in dokumentacijo ... hrani na sedežu oziroma na kraju opravljanja dela delavca”
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeZakon o igrah na srečo (ZIS), consolidated text, Articles 3a, 30 and 55
uradni-list.si
“Posebne igre na srečo sme prirejati kot svojo dejavnost le delniška družba, ki ima sedež na območju Republike Slovenije”
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807 on the free flow of non-personal data, Article 4 — member states may not impose localisation except on public-security grounds
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Slovenia uses the European model. You can send data freely to a country the European Commission has approved. If your destination is not approved, you can still send data. You sign the Commission's standard contract, or use approved group-wide rules, or rely on one of a few narrow exceptions. Slovenia adds nothing of its own. The old Slovenian system, where the Information Commissioner had to authorise each export, was scrapped when the current privacy act arrived in January 2023.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims
The approved list is real and well populated. It covers Andorra, Argentina, Brazil (new, 26 January 2026, mutual), Canada for commercial bodies, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan and Jersey. It also covers New Zealand, South Korea (first review confirmed 23 July 2026) and Switzerland. And it covers the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay and the European Patent Organisation. The United States counts for companies self-certified under the EU-US Data Privacy Framework. No approval decision has been withdrawn or suspended. The 2021 standard contractual clauses, Decision (EU) 2021/914, remain the set in use and are unchanged. New clauses were promised for recipients already covered directly by the Regulation under Article 3(2). Those are still not adopted as at 18 August 2026. Most companies use the 2021 clauses instead, switching off the terms that duplicate. Binding corporate rules remain available. The Article 49 exceptions are narrow and are not for regular or large-scale transfers. You are still expected to write a transfer risk assessment after the Schrems II judgment. The EU-US Data Privacy Framework is still in force and legally valid on 18 August 2026. But it is under pressure on two fronts. The General Court dismissed the Latombe challenge on 3 September 2025. An appeal to the Court of Justice was lodged on 31 October 2025 and is pending. And on 31 July 2026 the European Data Protection Board formally wrote to the Commission. It asked the Commission to examine whether changes to United States institutions affect the decision's validity. The Commission has not suspended or revoked it. Our advice: use it today, but never as your only route. Separately, European Data Protection Board Guidelines 02/2024 confirm that an order from a non-European authority is not by itself a lawful reason to hand data over. Regulation (EU) 2018/1807 forbids Slovenia from making non-personal data stay in the country, except on public-security grounds. That is the ground the health and government-cloud rules would have to justify themselves against if challenged.
Sources
- Official sourceInformacijski pooblaščenec Republike SlovenijeKljučne novosti ZVOP-2 — the Information Commissioner confirms the old national list of adequate countries was repealed and third-country transfers now follow the European Regulation
ip-rs.si
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the Commission's own list of countries found to provide adequate protection
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionCommission Implementing Decision (EU) 2021/914 on standard contractual clauses for transfers to third countries
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEDPB Guidelines 02/2024 on Article 48 — a third-country authority's order is not by itself a lawful basis to disclose
edpb.europa.eu
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Information Commissioner, and it is really working. In 2025 it opened 464 inspection cases from complaints, plus 102 more from inspection reports. It issued 134 enforcement decisions, fined in 89 of them and gave warnings in 45. It handed down what it calls its largest fine since the European rules began. It handled 153 breach reports. It is small. At the end of 2025 it had one commissioner and 53 staff, and it says openly that it does not have enough people. Cybersecurity is enforced separately by a government office set up for the job.
Informacijski pooblaščenec, the Information Commissioner, is both the data protection authority and the freedom-of-information authority. Dr. Jelena Virant Burnik took office as Commissioner in 2024. Its 2025 annual report to the National Assembly gives the numbers. It started 464 inspection procedures on the basis of complaints and 102 on the basis of inspection reports. It sent 176 advisory letters to organisations. It issued 134 decisions in minor-offence proceedings, of which 89 ended in a fine and 45 in a warning. It received 153 personal data breach notifications. Staffing at 31 December 2025 was one appointed official and 53 public employees. The report states plainly that this workforce cannot absorb the growing caseload and the office's widening remit. Our rating is active, not aggressive. Case volume is high and the fines are real, but a small office leans on warnings for minor breaches. The second enforcer is the Government Office for Information Security (Urad Vlade Republike Slovenije za informacijsko varnost, URSIV). It runs registration, incident reporting and supervision under the Information Security Act of 2025. It is publishing guidance, model documents and conference material, which shows a regulator that operates rather than one that exists on paper. The Financial Administration supervises gambling. The Bank of Slovenia supervises banks. The Insurance Supervision Agency supervises insurers, and the Securities Market Agency supervises investment firms. All four are long-established and working.
Sources
- Official sourceInformacijski pooblaščenec Republike SlovenijeLetno poročilo Informacijskega pooblaščenca za leto 2025 — annual report to the National Assembly, caseload, fines and staffing figures
ip-rs.si
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeInformacijska pooblaščenka — the office's own page on the current Commissioner
ip-rs.si
Link checked 18 August 2026
- Official sourceUrad Vlade Republike Slovenije za informacijsko varnostZložeka ZInfV-1 — the Government Office for Information Security's own leaflet on registration and duties under the 2025 Information Security Act
gov.si
Link checked 18 August 2026
How long you must keep it — and when to delete it
Both a minimum and a maximum apply, and the minimums are long. A patient's medical file must be kept for ten years after the patient dies. Other basic medical records must be kept for fifteen years. Records of who touched personal data in a computer system must be kept for two years after the end of the year. That rises to five years if the risk is high. Working-time records must be kept at the Slovenian workplace. In the other direction the European rule applies: delete personal data once the purpose is spent.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
MINIMUMS. Health. The Health Care Databases Act sets the periods in its Annex 1. That is Zakon o zbirkah podatkov s področja zdravstvenega varstva, ZZPPZ, Official Gazette 65/00 with later amendments. The Information Commissioner's published opinion says the medical file and the description of illness are kept for ten years after the patient's death. Other basic medical documentation is kept for fifteen years. A living patient's file may not be destroyed, however long since their last visit. Access and activity logs. Article 22 of ZVOP-2 covers named databases. You must record each collection, change, access, disclosure and deletion, with a timestamp and the user's identity. You must keep the contents of that log for two years after the end of the calendar year. That extends to five years where a risk assessment justifies it. This is the duty most often missed by organisations whose global logging pipeline deletes records after 30 or 90 days. Employment. Working-time records and the documents behind them must be held at the employer's registered office or the worker's place of work. Tax and accounting minimums also exist under Slovenian tax and company law, and are typically ten years. We could not verify those periods against a government page. See the unconfirmed list. MAXIMUM. Slovenia has no deletion deadline separate from the European one. Personal data must not be kept in a form that identifies people for longer than the purpose requires, and people can ask for erasure. Where a minimum and a maximum collide, the specific legal keeping period wins for as long as it runs. Deletion becomes due the moment it expires. The Commissioner puts it this way. Once the set period has passed, access is no longer possible, because the data must by then be destroyed, deleted, blocked or anonymised.
Sources
- Official sourceInformacijski pooblaščenec Republike SlovenijeRok hrambe zdravstvenega kartona pacienta — the Information Commissioner on medical file retention under ZZPPZ, Annex 1
ip-rs.si
“se zdravstveni karton in popis bolezni hrani 10 let po smrti bolnika”
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeZVOP-2, Article 22 — traceability of processing and retention of processing logs
uradni-list.si
“Vsebina dnevnika obdelave se hrani dve leti od zaključka koledarskega leta”
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeSmernice za izvajalce zdravstvenih storitev — Information Commissioner guidelines for healthcare providers, on traceability and on destruction once the retention period expires
ip-rs.si
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count three deadlines, not one. A personal data breach goes to the Information Commissioner within 72 hours. If you are an essential or important organisation, a serious cyber incident goes to the government security office. You send an early warning immediately, and in any case within 24 hours. A full report follows within 72 hours, then a final report within one month. Telecoms operators have their own duties on top. Missing the 24-hour warning is the most common failure. It lands while you are still working out what happened.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Deadline one. Article 33 of the General Data Protection Regulation. Tell the Information Commissioner without undue delay, and where possible within 72 hours of becoming aware. Tell the affected people without undue delay where the risk to them is high. The Commissioner received 153 such notifications in 2025. Deadline two. The Information Security Act 2025 (Zakon o informacijski varnosti, ZInfV-1, Official Gazette 40/25), for essential and important entities. The Government Office for Information Security sets out the sequence. An early warning immediately, and in any case within 24 hours. A notification within 72 hours. A final report no later than one month. Healthcare providers are expressly listed as an essential sector. So a Slovenian hospital hit by ransomware is running deadlines one and two at the same time. Deadline three. Telecoms operators under the Electronic Communications Act 2022 have separate security-incident and personal-data-breach duties to their own regulator. The European rules on notification by telecoms providers still apply to them as well. A fourth deadline exists for banks, insurers and investment firms. Major information and communications technology incidents must be reported under the European digital operational resilience rules, which have applied since 17 January 2025.
Sources
- Official sourceMinistrstvo za zdravje / Urad Vlade RS za informacijsko varnostPredstavitev zakonodajnih obveznosti po ZInfV-1 za izvajalce v zdravstvu — official presentation setting out the 24-hour, 72-hour and one-month incident deadlines and the 2025/2026 commencement dates
gov.si
“nemudoma/v 24 urah ... v 72 urah ... najpozneje v enem mesecu”
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeZakon o informacijski varnosti (ZInfV-1), Official Gazette No. 40/25 of 4 June 2025
uradni-list.si
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeInformation Commissioner annual report 2025 — 153 personal data breach notifications handled
ip-rs.si
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things that catch people out. A child can consent at 15 in Slovenia, not 16. That is one year younger than the European default. Fingerprints and face scans are banned in the private sector unless a law allows them and the Commissioner approves. Every access to a covered database must be logged, and the log kept two years. Leaking personal data you got through your job is a crime, not just a fine. And working-time records must physically be at the Slovenian workplace, which no cloud contract fixes.
- What you have to do here:
- Get a parent's consent for children · Keep logs · Register or notify · Hold a security certificate
- What it costs if you get it wrong:
- Criminal liability
(1) AGE 15. Article 8 of ZVOP-2 sets the age at which a child can validly consent to an online service at 15. A product built to a single European age of 16 is wrong in Slovenia, but wrong in the permissive direction, which is the safer error. A product built to 13 is wrong in the dangerous direction. (2) BIOMETRICS. The Information Commissioner says that using biometric data contrary to ZVOP-2 is banned outright. Linking biometric databases and sending such data abroad is restricted unless a law allows it. Private-sector use is confined to specific purposes and needs the Commissioner's approval. You cannot simply buy a face-recognition time clock and switch it on. (3) LOGGING. Article 22 of ZVOP-2 requires an activity log for named databases. It must record who did what to which personal data, and when. You keep it for two years after the calendar year ends, and up to five years on a risk assessment. This is a Slovenian addition to the European rules, and it lands on your architecture rather than your paperwork. (4) CRIMINAL LIABILITY. Article 143 of the Criminal Code makes misuse of personal data an offence. The Commissioner says the ordinary forms, under the first and second paragraphs, carry a fine or up to one year in prison. Prosecution is time-barred six years after the act. This applies to individuals, not only to companies. (5) RECORDS AT THE WORKPLACE. Article 19(5) of the amended labour records act covers the working-time record and its supporting documents. They must be kept at the employer's registered office, or at the place where the worker works. A foreign employer with staff in Slovenia and everything in a foreign system has a problem an inspector can see. (6) ONE MORE TRAP: E-ARCHIVING. Anyone offering digital capture or storage services for documentary material in Slovenia must register with the Archives of the Republic of Slovenia. You register at least eight days before you start. For archival material you may use only equipment and services certified by the state archive. Certification fees run from about 300 to 2,000 euros (roughly 330 to 2,200 US dollars). This catches document-management suppliers who assume a standard data protection contract is enough.
Sources
- Official sourceUradni list Republike SlovenijeZVOP-2, Articles 8 and 22 — child consent at 15, and the processing log
uradni-list.si
“Privolitev otroka za uporabo storitev informacijske družbe ... je veljavna, če je otrok star 15 let ali več.”
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeKljučne novosti ZVOP-2 — the Commissioner on the biometrics prohibition, private-sector approval, video surveillance and the processing log
ip-rs.si
“Obdelava biometričnih osebnih podatkov v nasprotju z ZVOP-2 je prepovedana.”
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeZloraba osebnih podatkov — the Commissioner on the criminal offence under Article 143 of the Criminal Code
ip-rs.si
“denarna kazen ali zapor do enega leta”
Link checked 18 August 2026
- Official sourcePortal SPOT, Government of the Republic of SloveniaZajemanje ali hranjenje gradiva v digitalni obliki — the official business portal's statement of the registration and certification duties owed to the Archives of the Republic of Slovenia
spot.gov.si
“morajo za varstvo arhivskega gradiva v digitalni obliki uporabljati le pri državnem arhivu certificirano opremo in storitve”
Link checked 18 August 2026
What's changing next
Two dates in the next twelve months matter most. On 19 December 2026 the cybersecurity duties start to apply to organisations newly covered by Slovenia's 2025 Information Security Act. That means registration, security measures and the incident deadlines. On 12 January 2027 the European Data Act bans all cloud switching and data export fees. Behind both sits the roll-out of the national health record system. Its ban on storing data outside Slovenia is already law, but we could not pin down the timetable.
19 DECEMBER 2026 — the Information Security Act (ZInfV-1) came into force on 19 June 2025. Organisations already covered by the previous act had until 19 June 2026 to comply. Newly covered essential and important entities have until 19 December 2026. You register yourself with the Government Office for Information Security. That is a change from the old system, where the state decided who was covered. 12 JANUARY 2027 — the European Data Act requires all cloud switching charges and data export fees to fall to zero. That Act has applied since 12 September 2025. Its Chapter VII also limits access by non-European governments to non-personal data held in Europe. HEALTH ROLL-OUT — the Health Digitalisation Act was published on 4 December 2025. It creates the state-owned company for central health information infrastructure. It requires every healthcare provider to connect. And it forbids that company from transferring or storing personal data outside Slovenia. Its start and phase-in dates are the single most important thing we could not confirm from a government text. POWERS ALREADY HELD, which could change your answer with no consultation. (1) The ministry's power under the state administration information security decree to grant or refuse cloud approvals. It can also move information into a tier where public cloud is simply not available. (2) The government's power to widen who counts as an essential or important entity, by decree under the Information Security Act. (3) The Article 7 duty in the health act to keep data in Slovenia. How far it reaches into sub-suppliers is untested, and the ministry could read it broadly with no new law. At European level, the EU-US Data Privacy Framework is the largest single point of failure. It is valid today, but it is under appeal at the Court of Justice. It is also the subject of a formal European Data Protection Board letter to the Commission, dated 31 July 2026.
Sources
- Official sourceMinistrstvo za zdravje / Urad Vlade RS za informacijsko varnostOfficial presentation on ZInfV-1 duties — entry into force 19 June 2025, compliance 19 June 2026 for existing entities and 19 December 2026 for newly captured essential and important entities
gov.si
“stopil v veljavo 19. 6. 2025”
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeZakon o digitalizaciji zdravstva (ZDigZ), Official Gazette No. 100/25 of 4 December 2025
uradni-list.si
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) — switching charges must reach zero by 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Diarise 19 December 2026 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries7 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Health and social care data must stay in the country
Official name: Zakon o digitalizaciji zdravstva (ZDigZ) · Uradni list RS, št. 100/25 · Act of parliament
Slovenia's one absolute rule. One state-owned company runs the national central health information system and the central electronic health record. It is forbidden by law from transferring or storing personal data outside Slovenian territory. Every healthcare provider in the country must connect its local system to that central infrastructure.
Enforced by Ministry of Health
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryArticle 7(7): the state-owned company running the central health information and communication infrastructure may neither transfer nor store personal data outside Slovenia. It may not use that data for its own purposes.
- Written vendor contractThe company handles the health data entrusted to it on behalf of others, under contract.
- Secure the data
Sources
- Official sourceUradni list Republike SlovenijeZakon o digitalizaciji zdravstva (ZDigZ), Uradni list RS 100/25 of 4 December 2025, Articles 3(2) and 7(7)
uradni-list.si
“Osebnih podatkov kot pogodbeni obdelovalec ne sme obdelovati za svoje namene in jih ne sme niti prenašati niti hraniti izven ozemlja Republike Slovenije.”
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeUradni list RS No. 100/25 — publication record for the Health Digitalisation Act
uradni-list.si
Link checked 18 August 2026
Health data rules
Official name: Zakon o zbirkah podatkov s področja zdravstvenega varstva (ZZPPZ) · Uradni list RS, št. 65/00, 47/15, 31/18 · Act of parliament
Slovenia's health records law sets no rule about where health data is stored. But it sets long minimum keeping periods. A patient's medical file must be kept for ten years after death. Other basic medical documentation must be kept for fifteen years.
Enforced by Information Commissioner of the Republic of Slovenia
What you have to do
- Keep data for a minimum period — 10 yearsMedical file and description of illness: 10 years after the patient's death. A living patient's file may not be destroyed however long since the last visit.
- Keep data for a minimum period — 15 yearsOther basic medical documentation: 15 years.
- Delete data after a periodOnce the statutory period expires the record must be destroyed, deleted, blocked or anonymised, and access is no longer lawful.
Sources
- Official sourceInformacijski pooblaščenec Republike SlovenijeRok hrambe zdravstvenega kartona pacienta — Information Commissioner opinion citing Annex 1 of ZZPPZ
ip-rs.si
“se zdravstveni karton in popis bolezni hrani 10 let po smrti bolnika”
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeRoki hrambe zdravstvene dokumentacije — the Commissioner confirms the periods are fixed by ZZPPZ and cannot be shortened for practical reasons
ip-rs.si
“roke hrambe zdravstvene dokumentacije opredeljuje zakon in na njem temelječi predpisi”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Uredba o informacijski varnosti v državni upravi · Uradni list RS, št. 29/18 · Directly binding regulation
A Slovenian state administration body may put information in a public cloud only if that information sits in the lowest security tiers. It also needs written approval from the ministry first. This is not a rule about location. A Slovenian public cloud is treated the same as a foreign one. But it keeps sensitive government data out of commercial clouds entirely.
Enforced by Ministry of Digital Transformation
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyArticle 41: use of public cloud services requires the written approval of the ministry, which must first review the provider's terms of service.
- Secure the dataCloud may be used only for information assets that are unclassified or in the lowest tiers Z1, C1 and R1.
Sources
- Official sourceUradni list Republike SlovenijeUredba o informacijski varnosti v državni upravi, Uradni list RS 29/18, Article 41 (cloud computing services)
uradni-list.si
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijePravilniki o uporabi informacijskih storitev v oblaku — Information Commissioner opinion on internal cloud-use rules in the public sector
ip-rs.si
Link checked 18 August 2026
Personal data needs a security certification
Official name: Zakon o varstvu dokumentarnega in arhivskega gradiva ter arhivih (ZVDAGA) · ZVDAGA and its implementing decree on protection of documentary and archival material · Act of parliament
Slovenia regulates the business of digital document storage itself. Anyone offering capture or storage services must register with the national archive first. For archival material, you may use only equipment and services the archive has certified. There is no requirement that the copies sit in Slovenia, but there must be two of them in geographically separated places.
Enforced by Archives of the Republic of Slovenia
What you have to do
- Register or notifyIf you provide digital capture or storage services, equipment or software, you must register with the Archives of the Republic of Slovenia. Register at least eight days before you start offering the service.
- Hold a security certificateFor archival material in digital form, only equipment and services certified by the state archive may be used. Certification fees run from about 300 to 2,000 euros (roughly $330 to $2,200).
- Secure the dataAt least two copies at two geographically separated locations, so that loss of data is prevented. No requirement that either location be in Slovenia.
Sources
- Official sourcePortal SPOT, Government of the Republic of SloveniaZajemanje ali hranjenje gradiva v digitalni obliki — official business portal statement of registration, certification and two-copy duties
spot.gov.si
“najmanj dveh kopij podatkov na dveh geografsko oddaljenih lokacijah tako, da se prepreči izguba podatkov”
Link checked 18 August 2026
Record-keeping rules for tax and accounts
Official name: Zakon o igrah na srečo (ZIS) · Zakon o igrah na srečo, consolidated text, with the Rules on organising games of chance over the internet or other telecommunications means · Act of parliament
Online gambling in Slovenia is a rule about where the company sits, not where the data sits. Only a Slovenian-registered joint-stock company can hold the concession. Its system must be wired into the tax authority's own system for live supervision. We found no rule requiring the server itself to be in Slovenia.
Enforced by Financial Administration of the Republic of Slovenia
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyOnly a joint-stock company with its registered seat in Slovenia may hold a concession for classical or special games of chance (Articles 30 and 55). A foreign operator cannot be licensed from abroad.
- Independent auditArticle 3a: an operator offering games over the internet must connect its information system to the supervisory authority's information system. Since the November 2025 amending rules, it must also send event and transaction data through a single official web service.
Sources
- Official sourceUradni list Republike SlovenijeZakon o igrah na srečo, consolidated text, Articles 3a, 30, 55 and 92
uradni-list.si
“Klasične igre na srečo sme trajno prirejati kot svojo dejavnost le delniška družba, ki ima sedež na območju Republike Slovenije”
Link checked 18 August 2026
- Official sourceEuropean Commission, Technical Regulation Information SystemPravilnik o dopolnitvah Pravilnika o prirejanju iger na srečo preko interneta oziroma drugih telekomunikacijskih sredstev, notified 11 November 2025 — no server-location requirement in the text
technical-regulation-information-system.ec.europa.eu
Link checked 18 August 2026
- Official sourceFinančna uprava Republike SlovenijeIgre na srečo — the Financial Administration's own page on the governing acts and the concession requirement
fu.gov.si
Link checked 18 August 2026
Telecoms rules
Official name: Zakon o elektronskih komunikacijah (ZEKom-2) · Uradni list RS, št. 130/22 · Act of parliament
Slovenia has no blanket telecoms data retention. The Constitutional Court struck the old bulk retention rules down in 2014 and ordered the retained data deleted. The 2022 replacement law did not restore them. Traffic data may be kept only as long as billing needs it. There is also a narrow allowance for locating emergency callers.
Enforced by Agency for Communication Networks and Services
What you have to do
- Delete data after a periodTraffic data may be kept for billing and interconnection settlement only until payment is complete. It may not be kept longer than the limitation period. That usually means the current month plus about three months.
- Secure the data
Sources
- Official sourceInformacijski pooblaščenec Republike SlovenijeHramba podatkov v prometu elektronskih komunikacij — the Information Commissioner confirms there is no advance, bulk retention duty after the Constitutional Court's annulment
ip-rs.si
Link checked 18 August 2026
- Official sourceLink may be brokenUstavno sodišče Republike SlovenijeOdločba Ustavnega sodišča U-I-65/13 — annulment of the blanket electronic communications data retention provisions
us-rs.si
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeZakon o elektronskih komunikacijah (ZEKom-2), Uradni list RS 130/22 of 11 October 2022
uradni-list.si
Link checked 18 August 2026
Banking rules
Official name: Uredba (EU) 2022/2554 o digitalni operativni odpornosti za finančni sektor (DORA) · Regulation (EU) 2022/2554 · Directly binding regulation
Slovenian banking, insurance and securities rules contain nothing about where data must be stored that we could find. Financial firms are governed by the European digital operational resilience rules, which have applied since 17 January 2025. Those rules require firms to disclose where data sits, keep a register of technology suppliers and plan their exit. They do not require anything to be kept in Slovenia.
Enforced by Bank of Slovenia
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Written vendor contractContracts with technology suppliers must say where data is used and stored. They must also give audit rights and exit plans.
- Keep records of how you use dataA register of contractual arrangements with third-party technology providers, reported to the supervisor.
- Report cyber incidents
Sources
- Official sourceAgencija za zavarovalni nadzorKrepitev kibernetske varnosti — the Slovenian Insurance Supervision Agency on the digital operational resilience rules and their 17 January 2025 application date
a-zn.si
“bo začela veljati 16. 1. 2023, uporabljati pa se bo začela 17. 1. 2025”
Link checked 18 August 2026
- Official sourceBanka SlovenijePoročanje o registru pogodb s tretjimi ponudniki storitev IKT — Bank of Slovenia reporting page for the register of technology supplier contracts
bsi.si
Link checked 18 August 2026
- Official sourceLink may be brokenAgencija za trg vrednostnih papirjevDORA Regulation Guidelines — the Securities Market Agency's guidance page for investment firms
a-tvp.si
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Zakon o varstvu osebnih podatkov (ZVOP-2) · Uradni list RS, št. 163/22 · Act of parliament
Slovenia's national privacy act, in force since 26 January 2023. It contains no requirement to keep data in Slovenia. It adds four things on top of the European rules. A low age of child consent, at 15. A near-total ban on biometrics outside the cases a law allows. Detailed video surveillance rules. And a two-year activity log that catches out global logging setups.
Enforced by Information Commissioner of the Republic of Slovenia
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Get a parent's consent for children — applies at: under 15 — Article 8 sets valid consent to information society services at 15 years, one year below the European default
- Keep logs — 2 yearsArticle 22: an activity log recording collection, change, access, disclosure and deletion, with time and user identity. Keep it two years after the end of the calendar year, or up to five on a risk assessment.
- Appoint a data protection officerThe data protection officer must have legal capacity, relevant knowledge and no relevant criminal conviction. Conflicts of interest are spelled out. An outside officer is allowed in the private sector.
- Secure the data
- Keep records of how you use data
- Put a transfer safeguard in place
What it costs if you get it wrong
- Percentage of global turnover: €20,000,000 or 4% of worldwide annual turnover, whichever is higher — about $22 millionThe Commissioner applies the European fine levels; ZVOP-2 removed the old national criminal-style provisions of the 1999 and 2004 acts
- Criminal liability: Fine or imprisonment up to 1 year (up to 2 years in aggravated forms)Misuse of personal data under Article 143 of the Criminal Code — a separate track from the administrative fine, and it attaches to individuals
Sources
- Official sourceUradni list Republike SlovenijeZakon o varstvu osebnih podatkov (ZVOP-2), Uradni list RS 163/22, Articles 4, 8 and 22
uradni-list.si
“Vsebina dnevnika obdelave se hrani dve leti od zaključka koledarskega leta”
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeKljučne novosti ZVOP-2 — the Information Commissioner's own summary: application from 26 January 2023, biometrics prohibition, video surveillance, processing logs, data protection officer conditions, repeal of the old national adequacy list
ip-rs.si
Link checked 18 August 2026
Data rules
Official name: Zakon o spremembah in dopolnitvah Zakona o evidencah na področju dela in socialne varnosti (ZEPDSV-A) · Uradni list RS, št. 50/23 · Act of parliament
Since 20 November 2023 an employer in Slovenia must keep the record of working time at a set place. The same goes for the documents supporting it. That place is its registered office, or where the worker actually works. A foreign employer running everything in an overseas system has a problem a labour inspector can see immediately.
Enforced by Labour Inspectorate of the Republic of Slovenia
What you have to do
- Keep the data in the countryArticle 19(5): the working-time record and the documents behind it are kept at the employer's registered office. They can instead be kept where the worker performs the work. A cloud copy abroad is allowed. The record must still be produced on the spot.
- Keep records of how you use data
What it costs if you get it wrong
- Fixed maximum fineLabour inspectorate fines for failing to keep or produce the working-time record
Sources
- Official sourceUradni list Republike SlovenijeZEPDSV-A, Uradni list RS 50/23, Article 19(5) and the commencement article
uradni-list.si
“Delodajalec evidenco o izrabi delovnega časa in dokumentacijo ... hrani na sedežu oziroma na kraju opravljanja dela delavca”
Link checked 18 August 2026
Cyber security rules
Official name: Zakon o informacijski varnosti (ZInfV-1) · Uradni list RS, št. 40/25 · Act of parliament
Slovenia's cybersecurity law, which brings the European network security rules into national law. It sets no rule about where data must be stored. But it adds a second incident deadline on top of the privacy one. Twenty-four hours for an early warning, 72 hours for the full notification, one month for the final report. Newly covered organisations must comply by 19 December 2026.
That is a long gap: the duty is real law today, but no penalty can follow until 19 December 2026. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by Government Office for Information Security
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notify — from 19 December 2026Self-registration with the Government Office for Information Security. Organisations already covered by the previous act had until 19 June 2026; newly captured essential and important entities have until 19 December 2026.
- Report cyber incidents — within 24 hoursEarly warning immediately and in any case within 24 hours.
- Report cyber incidents — within 72 hoursFull incident notification within 72 hours. Final report within one month.
- Secure the data
Sources
- Official sourceUradni list Republike SlovenijeZakon o informacijski varnosti (ZInfV-1), Uradni list RS 40/25 of 4 June 2025
uradni-list.si
Link checked 18 August 2026
- Official sourceMinistrstvo za zdravje / Urad Vlade RS za informacijsko varnostOfficial presentation of ZInfV-1 duties — entry into force 19 June 2025, compliance dates 19 June 2026 and 19 December 2026, incident deadlines
gov.si
“stopil v veljavo 19. 6. 2025”
Link checked 18 August 2026
- Official sourceUrad Vlade RS za informacijsko varnostZložeka ZInfV-1 — the Government Office for Information Security's leaflet on self-registration
gov.si
Link checked 18 August 2026
General data protection law (2008)
Official name: Kazenski zakonik (KZ-1), 143. člen — zloraba osebnih podatkov · Criminal Code, Article 143 · Act of parliament
Misusing personal data is a crime in Slovenia, not only an administrative matter. The ordinary forms carry a fine or up to a year in prison. Prosecution can be brought up to six years after the act. It applies to the individual, not just the employer.
Enforced by Information Commissioner of the Republic of Slovenia
What it costs if you get it wrong
- Criminal liability: Fine or imprisonment up to 1 year for the ordinary formsUnlawful processing or disclosure of personal data; prosecution is time-barred six years after the act
Sources
- Official sourceInformacijski pooblaščenec Republike SlovenijeZloraba osebnih podatkov — the Information Commissioner on Article 143 of the Criminal Code, its penalties and the six-year limitation period
ip-rs.si
“denarna kazen ali zapor do enega leta”
Link checked 18 August 2026
Applies across the European Union3 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Uredba (EU) 2016/679 Evropskega parlamenta in Sveta (Splošna uredba o varstvu podatkov) · Regulation (EU) 2016/679 · Directly binding regulation
The European baseline that governs almost all personal data in Slovenia. It does not require data to stay in Europe. It sets the conditions under which data may leave.
Enforced by Information Commissioner of the Republic of Slovenia
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of how you use data
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a representativeRequired where you have no place of business in the European Union.
- Put a transfer safeguard in placePlus a documented transfer impact assessment after the Schrems II judgment.
- Do not hand data to foreign authorities on demandAn order from a non-European authority is not by itself a lawful reason to hand data over (European Data Protection Board Guidelines 02/2024).
- Delete data after a period
- Get a parent's consent for children — applies at: 15 in Slovenia — Slovenia used the national option to lower the age below 16
What it costs if you get it wrong
- Percentage of global turnover: €20,000,000 or 4% of worldwide group turnover, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: €10,000,000 or 2% of worldwide group turnover, whichever is higher — about $11 millionController and processor duties, including security and breach notification
- Order to stopOrder to stop processing or to suspend flows to a third country — often worse commercially than the fine
- Claims by individualsCompensation claims by affected individuals
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679, Chapter V (transfers) and Article 83 (fines)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeZakon o varstvu osebnih podatkov — the Slovenian regulator's own legislation page, confirming the Regulation plus ZVOP-2 as the applicable framework
ip-rs.si
Link checked 18 August 2026
General data protection law
Official name: Uredba (EU) 2018/1807 o okviru za prosti pretok neosebnih podatkov v Evropski uniji · Regulation (EU) 2018/1807 · Directly binding regulation
Slovenia is forbidden from forcing non-personal data to be stored on its territory. The only exception is where public security really requires it. Any Slovenian demand to keep data in the country has to justify itself against this rule.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807, Article 4
eur-lex.europa.eu
Link checked 18 August 2026
Cloud and outsourcing rules (2027)
Official name: Uredba (EU) 2023/2854 (Akt o podatkih) · Regulation (EU) 2023/2854 · Directly binding regulation
The European Data Act has applied since 12 September 2025 and gives customers a right to switch cloud providers. Its hardest deadline is 12 January 2027, when all switching charges and data export fees must reach zero.
That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
What you have to do
- Make switching cloud provider possible — from 12 January 2027All switching charges and data egress fees must be zero from 12 January 2027.
- Do not hand data to foreign authorities on demandChapter VII limits access by non-European governments to non-personal data held in the European Union.
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act), Chapters VI and VII
eur-lex.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact commencement and phase-in dates of the Health Digitalisation Act (ZDigZ), including when the localisation duty in Article 7(7) starts to bite and by when healthcare providers must connect to the central system.
We could not confirm the date this Act came into force. The official gazette page for Official Gazette 100/25 stops before the final and transitional rules, and we could not read the government's legal information system. The date of 19 December 2025 in this record comes from the standard rule of fifteen days after publication, applied to a 4 December 2025 publication. It is not quoted from a start-date article.
How far the health localisation duty reaches — whether it binds only the state-owned company running the central health infrastructure, or also its suppliers, sub-processors and individual healthcare providers.
We could not confirm how far this ban reaches down the supply chain. On its face, Article 7(7) binds the company set up as the public service provider. We found no official guidance on whether the ministry reads it as flowing down to suppliers. Treat a foreign sub-supplier to that company as high risk until this is settled.
Whether the 2018 Decree on information security in state administration has been amended or replaced since the 2025 Information Security Act, and which ministry now grants cloud approvals.
We could not confirm that this is the current version. The gazette page we read is the original 2018 text. We found no repeal, but we also found no consolidated version on a government website. Slovenia has reorganised its digital ministries since 2018, so check before you rely on it.
Minimum retention periods for tax, accounting and company records in Slovenia (commonly stated as ten years).
We could not confirm this figure against a government source. The Financial Administration's own explanatory document is a Word file we could not read, and we found no equivalent web page on a government site. Professional sources repeat the figure widely, but no government citation backs it here.
The value of the Information Commissioner's largest fine in 2025.
We could not confirm the size of the largest fine. The 2025 annual report says the Commissioner imposed its highest fine since the European rules began. The figure did not appear in the part of the report we could read.
The Constitutional Court's decision U-I-65/13 as read from the court's own site.
We could not read the court's own text of this judgment, because its website returned an access error on 18 August 2026. The substance comes instead from the Information Commissioner's published opinion, which is a regulator source. That substance is: blanket telecoms retention was annulled, and there is no advance bulk retention duty. The claim stands, but the original court text is unverified.
Whether Slovenian gambling rules require the gaming server itself to be located in Slovenia.
We found no rule requiring this, but we could not read every source. Neither the consolidated Games of Chance Act nor the November 2025 amending rules contain such a requirement in the parts we could read. Those rules were notified to the European Commission. The full implementing rules sit on a government legal system we could not read. Record this as no rule found on 18 August 2026, not as no rule exists.
Whether any Slovenian rule requires deposit of aerial survey imagery or maps with the state, as several neighbouring countries do.
We found no rule of this kind, but we could not read everything. The new Aviation Act of 2024 and the national spatial data portal contain nothing of the kind in the parts we read. Checked 18 August 2026, with medium confidence.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.