Slovenia
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Slovenia has no general rule that data must stay in the country. It runs on the European rulebook: send data abroad once you have the right paperwork. Three things break that. The company running the new national health record system may not store data outside Slovenia. Government bodies may cloud only their least sensitive data. And working-time records must sit at the Slovenian workplace.
Eight questions about Slovenia
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Slovenia's rules apply to my company?
Yes. Slovenia's privacy rules reach a company with no office there. If you offer goods or services to people in Slovenia, or watch what they do online, the European rules apply to you and Slovenia's own privacy act applies alongside them. There is no size or revenue threshold that lets you out. A company with no office anywhere in Europe must appoint a written representative inside Europe.
Two layers stack. The General Data Protection Regulation reaches non-European controllers directly under its Article 3(2), and Article 27 requires a representative established in one of the member states where the affected people are. Slovenia's own act, ZVOP-2 (Zakon o varstvu osebnih podatkov, Official Gazette 163/22), sets its territorial reach in Article 4: it applies to processing carried out in the course of the activities of an establishment in Slovenia, and to processing of people in Slovenia by controllers outside the European Union, regardless of where the processing physically happens. ZVOP-2 does not add a separate Slovenia-only representative on top of the European one. Sector statutes are narrower and reach only the regulated firm: the Health Digitalisation Act binds healthcare providers operating in Slovenia and the state company running the central system, the Games of Chance Act binds concession holders, and the Information Security Act binds essential and important entities providing services in Slovenia.
Sources
- Official sourceUradni list Republike SlovenijeZakon o varstvu osebnih podatkov (ZVOP-2), Official Gazette of the Republic of Slovenia No. 163/22, Article 4 (veljavnost zakona — territorial scope)
uradni-list.si
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeKljučne novosti ZVOP-2 — the Information Commissioner's own summary of the new act, confirming it applies from 26 January 2023
ip-rs.si
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
Can I store my users' data outside Slovenia?
In general yes, with paperwork — Slovenia adds no national storage-location rule of its own on top of the European regime. But four industries break that answer, and one of them is a hard wall. Health is the big one: the state company that runs Slovenia's central health record system is banned outright from storing or sending personal data outside Slovenia, and every healthcare provider must connect to that system. Government cloud, employment records and gambling each carry their own restriction.
Sector by sector, checked on 18 August 2026. HEALTH — data must stay in the country for the central system. The Health Digitalisation Act (Zakon o digitalizaciji zdravstva, ZDigZ, Official Gazette 100/25 of 4 December 2025) creates a wholly state-owned company to run the central health information and communication infrastructure and the central electronic health record. Article 7(7) says of that company: 'Osebnih podatkov kot pogodbeni obdelovalec ne sme obdelovati za svoje namene in jih ne sme niti prenašati niti hraniti izven ozemlja Republike Slovenije' — as a contractual processor it may not process the personal data for its own purposes and may neither transfer nor store them outside the territory of the Republic of Slovenia. Article 3(2) requires all healthcare providers to connect their local health information systems to that central infrastructure. The practical effect is that the national health record is legally pinned to Slovenian soil, and a cloud offer routed through the state company cannot sit abroad. It does not, on its face, stop an individual private clinic from using a European cloud for its own local records — but that reading is ours and is flagged as unconfirmed. GOVERNMENT — data can leave with the right paperwork, but very tight. The Decree on information security in state administration (Uredba o informacijski varnosti v državni upravi, Official Gazette 29/18) allows cloud services in Article 41 only for information assets that are unclassified or in the lowest tiers Z1, C1 and R1, and only with the written approval of the ministry, which must first check the provider's terms. EMPLOYMENT — a copy must stay in the country. Since 20 November 2023, Article 19(5) of the Records in the Field of Labour and Social Security Act as amended (ZEPDSV-A, Official Gazette 50/23) requires the employer to keep the working-time record and the underlying documents 'na sedežu oziroma na kraju opravljanja dela delavca' — at its registered office or at the place where the worker performs the work. A cloud copy is fine; an inspector turning up must still be shown the record on the spot. GAMBLING — establishment wall rather than a data wall. Only a joint-stock company with its registered seat in Slovenia may organise games of chance (Games of Chance Act, Articles 30 and 55), and an internet operator must connect its information system to the supervisory authority's information system (Article 3a). We found no provision requiring the server itself to sit in Slovenia. CHECKED AND NO STORAGE-LOCATION RULE FOUND: banking, payments, insurance, securities, telecoms, education, mapping and aerial survey, and defence-adjacent commercial work. Slovenia's financial regulators point firms at the European digital operational resilience rules, which demand contracts, exit plans and disclosure of where data sits, but not a location. Slovenia's new Aviation Act (ZLet-1, Official Gazette 85/24) contains no aerial-photography permit or imagery-deposit duty of the kind several neighbours have.
Sources
- Official sourceUradni list Republike SlovenijeZakon o digitalizaciji zdravstva (ZDigZ), Official Gazette No. 100/25 of 4 December 2025, Articles 3 and 7
uradni-list.si
“Osebnih podatkov kot pogodbeni obdelovalec ne sme obdelovati za svoje namene in jih ne sme niti prenašati niti hraniti izven ozemlja Republike Slovenije.”
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeUredba o informacijski varnosti v državni upravi, Official Gazette No. 29/18, Article 41 (cloud services)
uradni-list.si
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeZakon o spremembah in dopolnitvah Zakona o evidencah na področju dela in socialne varnosti (ZEPDSV-A), Official Gazette No. 50/23, Article 19(5)
uradni-list.si
“Delodajalec evidenco o izrabi delovnega časa in dokumentacijo ... hrani na sedežu oziroma na kraju opravljanja dela delavca”
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeZakon o igrah na srečo (ZIS), consolidated text, Articles 3a, 30 and 55
uradni-list.si
“Posebne igre na srečo sme prirejati kot svojo dejavnost le delniška družba, ki ima sedež na območju Republike Slovenije”
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807 on the free flow of non-personal data, Article 4 — member states may not impose localisation except on public-security grounds
eur-lex.europa.eu
Link checked 18 August 2026
What do I need in place before data leaves Slovenia?
Slovenia uses the European model, and it works like an approved-destinations list with escape hatches. Data may go to a country the European Commission has approved. If the destination is not approved, you can still send data by signing the Commission's standard contract, using approved group-wide rules, or relying on one of a few narrow exceptions. Slovenia adds nothing of its own. The old Slovenian system, where the Information Commissioner had to authorise each export, was scrapped when the current privacy act arrived in January 2023.
The approved list is real and populated: Andorra, Argentina, Brazil (new, 26 January 2026, mutual), Canada for commercial bodies, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the United States for entities self-certified under the EU-US Data Privacy Framework, and the European Patent Organisation. No adequacy decision has been withdrawn or suspended. The 2021 standard contractual clauses, Decision (EU) 2021/914, remain the operative set and are unamended; the promised new clauses for importers already directly subject to the Regulation under Article 3(2) are still not adopted as at 18 August 2026, and market practice is to use the 2021 clauses with duplicative terms disapplied. Binding corporate rules remain available. Article 49 derogations are narrow and are not for systematic or large-scale transfers. A transfer impact assessment is still expected after Schrems II. The EU-US Data Privacy Framework is still in force and legally valid on 18 August 2026 but is under pressure on two fronts: the General Court dismissed the Latombe challenge on 3 September 2025 and an appeal to the Court of Justice was lodged on 31 October 2025 and is pending; and on 31 July 2026 the European Data Protection Board formally wrote to the Commission asking it to examine whether United States institutional changes affect the decision's validity. The Commission has not suspended or revoked it. Practical advice: usable today, never as your only mechanism. Separately, European Data Protection Board Guidelines 02/2024 confirm that an order from a third-country authority is not by itself a lawful basis to hand data over. Regulation (EU) 2018/1807 forbids Slovenia from imposing localisation on non-personal data except on public-security grounds — the ground the health and government-cloud rules would have to justify themselves against if challenged.
Sources
- Official sourceInformacijski pooblaščenec Republike SlovenijeKljučne novosti ZVOP-2 — the Information Commissioner confirms the old national list of adequate countries was repealed and third-country transfers now follow the European Regulation
ip-rs.si
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the Commission's own list of countries found to provide adequate protection
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionCommission Implementing Decision (EU) 2021/914 on standard contractual clauses for transfers to third countries
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEDPB Guidelines 02/2024 on Article 48 — a third-country authority's order is not by itself a lawful basis to disclose
edpb.europa.eu
Link checked 18 August 2026
Who enforces the rules in Slovenia, and what can they do?
The Information Commissioner, and it is genuinely working. In 2025 it opened 464 inspection cases from complaints plus 102 more from inspection reports, issued 134 enforcement decisions, fined in 89 of them, gave warnings in 45, and handed down what it calls its largest fine since the European rules began. It handled 153 breach reports. It is small: one commissioner and 53 staff at the end of 2025, and it says openly that it does not have enough people. Cybersecurity is enforced separately by a government office set up for the job.
Informacijski pooblaščenec (the Information Commissioner) is both the data protection authority and the freedom-of-information authority. Dr. Jelena Virant Burnik took office as Commissioner in 2024. Its 2025 annual report to the National Assembly records 464 inspection procedures started on the basis of complaints, 102 started on inspection reports, 176 advisory letters to controllers, 134 decisions in minor-offence proceedings of which 89 ended in a fine and 45 in a warning, and 153 personal data breach notifications received. Staffing at 31 December 2025 was one appointed official and 53 public employees, and the report states plainly that the existing workforce cannot absorb the growing caseload and the office's widening remit. Rating: active, not aggressive — high case volume, real fines, but a small office that leans on warnings for minor breaches. The second enforcer is the Government Office for Information Security (Urad Vlade Republike Slovenije za informacijsko varnost, URSIV), which runs registration, incident reporting and supervision under the Information Security Act of 2025 and which is publishing guidance, model documents and conference material — evidence of an operating regulator rather than a paper one. The Financial Administration supervises gambling, the Bank of Slovenia supervises banks, the Insurance Supervision Agency insurers and the Securities Market Agency investment firms; all four are long-established and operational.
Sources
- Official sourceInformacijski pooblaščenec Republike SlovenijeLetno poročilo Informacijskega pooblaščenca za leto 2025 — annual report to the National Assembly, caseload, fines and staffing figures
ip-rs.si
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeInformacijska pooblaščenka — the office's own page on the current Commissioner
ip-rs.si
Link checked 18 August 2026
- Official sourceUrad Vlade Republike Slovenije za informacijsko varnostZložeka ZInfV-1 — the Government Office for Information Security's own leaflet on registration and duties under the 2025 Information Security Act
gov.si
Link checked 18 August 2026
How long do I have to keep the data?
Both directions, and the floors are long. A patient's medical file must be kept for ten years after the patient dies, and other basic medical records for fifteen years. Records of who touched personal data in a computer system must be kept for two years after the end of the year, and up to five if the risk is high. Working-time records must be kept at the Slovenian workplace. In the other direction the European rule applies: delete personal data once the purpose is spent.
FLOORS. Health: the Health Care Databases Act (Zakon o zbirkah podatkov s področja zdravstvenega varstva, ZZPPZ, Official Gazette 65/00 with later amendments) sets the periods in its Annex 1 — the Information Commissioner's published opinion states that the medical file and the description of illness are kept for ten years after the patient's death, and other basic medical documentation for fifteen years, and that a living patient's file may not be destroyed however long since their last visit. Access and processing logs: Article 22 of ZVOP-2 requires controllers of designated databases to record each collection, change, access, disclosure and deletion with a timestamp and user identity, and to keep the content of that log for two years after the end of the calendar year, extendable to five years where a risk assessment justifies it — this is the obligation most often missed by organisations whose global logging pipeline expires records after 30 or 90 days. Employment: working-time records and the underlying documents must be held at the employer's registered office or the worker's place of work. Tax and accounting minimums also exist under Slovenian tax and company law and are typically ten years, but we could not verify those periods against a government page on this run — see the unconfirmed list. CEILING. There is no Slovenian deletion clock separate from the European one: personal data must not be kept in identifiable form for longer than the purpose requires, and individuals can ask for erasure. Where a floor and a ceiling collide, the specific statutory retention period wins for as long as it runs, and deletion becomes due the moment it expires — the Commissioner puts it as: once the prescribed period has passed, access is no longer possible because the data must by then be destroyed, deleted, blocked or anonymised.
Sources
- Official sourceInformacijski pooblaščenec Republike SlovenijeRok hrambe zdravstvenega kartona pacienta — the Information Commissioner on medical file retention under ZZPPZ, Annex 1
ip-rs.si
“se zdravstveni karton in popis bolezni hrani 10 let po smrti bolnika”
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeZVOP-2, Article 22 — traceability of processing and retention of processing logs
uradni-list.si
“Vsebina dnevnika obdelave se hrani dve leti od zaključka koledarskega leta”
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeSmernice za izvajalce zdravstvenih storitev — Information Commissioner guidelines for healthcare providers, on traceability and on destruction once the retention period expires
ip-rs.si
Link checked 18 August 2026
What happens if there is a breach?
Count three clocks, not one. A personal data breach goes to the Information Commissioner within 72 hours. A serious cyber incident, if you are an essential or important organisation, goes to the government security office immediately and in any case within 24 hours as an early warning, then a full report within 72 hours, then a final report within one month. Telecoms operators have their own duties on top. Missing the 24-hour warning is the most common failure, because it lands while you are still working out what happened.
Clock one: Article 33 of the General Data Protection Regulation — notify the Information Commissioner without undue delay and where feasible within 72 hours of becoming aware, and tell affected individuals without undue delay where the risk to them is high. The Commissioner received 153 such notifications in 2025. Clock two: the Information Security Act 2025 (Zakon o informacijski varnosti, ZInfV-1, Official Gazette 40/25) for essential and important entities. The Government Office for Information Security states the sequence as an early warning 'nemudoma / v 24 urah' (immediately, within 24 hours), a notification 'v 72 urah' (within 72 hours), and a final report 'najpozneje v enem mesecu' (no later than one month). Healthcare providers are expressly listed as an essential sector, so a Slovenian hospital hit by ransomware is running clocks one and two simultaneously. Clock three: telecoms operators under the Electronic Communications Act 2022 have separate security-incident and personal-data-breach duties to the sector regulator, and the European rules on notification by telecoms providers still apply to them. A fourth clock exists for banks, insurers and investment firms: major information and communications technology incidents must be reported under the European digital operational resilience rules, which have applied since 17 January 2025.
Sources
- Official sourceMinistrstvo za zdravje / Urad Vlade RS za informacijsko varnostPredstavitev zakonodajnih obveznosti po ZInfV-1 za izvajalce v zdravstvu — official presentation setting out the 24-hour, 72-hour and one-month incident deadlines and the 2025/2026 commencement dates
gov.si
“nemudoma/v 24 urah ... v 72 urah ... najpozneje v enem mesecu”
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeZakon o informacijski varnosti (ZInfV-1), Official Gazette No. 40/25 of 4 June 2025
uradni-list.si
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeInformation Commissioner annual report 2025 — 153 personal data breach notifications handled
ip-rs.si
Link checked 18 August 2026
What trips people up in Slovenia?
Five things that catch people out. A child can consent at 15 in Slovenia, not 16 — one year younger than the European default. Fingerprints and face scans are banned in the private sector unless a law allows them and the Commissioner approves. Every access to a covered database must be logged and the log kept two years. Leaking personal data you got through your job is a crime, not just a fine. And working-time records must physically be at the Slovenian workplace, which no cloud contract fixes.
(1) AGE 15. Article 8 of ZVOP-2 sets the age at which a child can validly consent to an online service at 15: 'Privolitev otroka za uporabo storitev informacijske družbe ... je veljavna, če je otrok star 15 let ali več.' Products built to a single European age of 16 are wrong in Slovenia in the permissive direction, which is the safer error, but products built to 13 are wrong in the dangerous direction. (2) BIOMETRICS. The Information Commissioner states that processing biometric data contrary to ZVOP-2 is prohibited outright, that linking biometric databases and transferring such data is restricted unless a law allows it, and that private-sector use is confined to specific purposes and requires the Commissioner's approval. A face-recognition time clock cannot simply be bought and switched on. (3) LOGGING. Article 22 of ZVOP-2 requires a processing log for designated databases recording who did what to which personal data and when, kept for two years after the calendar year ends and up to five years on a risk assessment. This is a Slovenian addition to the European rules and it bites on architecture, not paperwork. (4) CRIMINAL LIABILITY. Article 143 of the Criminal Code makes misuse of personal data an offence. The Commissioner states that the ordinary forms under the first and second paragraphs carry a fine or imprisonment of up to one year, and that prosecution is time-barred six years after the act. This attaches to individuals, not only to companies. (5) RECORDS AT THE WORKPLACE. Article 19(5) of the amended labour records act requires the working-time record and its supporting documents to be kept at the employer's registered office or at the place where the worker works. A foreign employer with staff in Slovenia and everything in a foreign system has a problem an inspector can see. (6) BONUS TRAP — E-ARCHIVING. Anyone offering digital capture or storage services for documentary material in Slovenia must register with the Archives of the Republic of Slovenia at least eight days before starting, and for archival material may use only equipment and services certified by the state archive. Certification fees run from about 300 to 2,000 euros (roughly $330 to $2,200). This catches document-management vendors who assume a standard processor contract is enough.
Sources
- Official sourceUradni list Republike SlovenijeZVOP-2, Articles 8 and 22 — child consent at 15, and the processing log
uradni-list.si
“Privolitev otroka za uporabo storitev informacijske družbe ... je veljavna, če je otrok star 15 let ali več.”
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeKljučne novosti ZVOP-2 — the Commissioner on the biometrics prohibition, private-sector approval, video surveillance and the processing log
ip-rs.si
“Obdelava biometričnih osebnih podatkov v nasprotju z ZVOP-2 je prepovedana.”
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeZloraba osebnih podatkov — the Commissioner on the criminal offence under Article 143 of the Criminal Code
ip-rs.si
“denarna kazen ali zapor do enega leta”
Link checked 18 August 2026
- Official sourcePortal SPOT, Government of the Republic of SloveniaZajemanje ali hranjenje gradiva v digitalni obliki — the official business portal's statement of the registration and certification duties owed to the Archives of the Republic of Slovenia
spot.gov.si
“morajo za varstvo arhivskega gradiva v digitalni obliki uporabljati le pri državnem arhivu certificirano opremo in storitve”
Link checked 18 August 2026
What is changing soon in Slovenia?
Two dates in the next twelve months matter most. On 19 December 2026 the cybersecurity duties bite for organisations newly captured by Slovenia's 2025 Information Security Act — registration, security measures and the incident clocks. On 12 January 2027 the European Data Act bans all cloud switching and data export fees. Behind both sits the roll-out of the national health record system, whose ban on storing data outside Slovenia is already law but whose timetable we could not pin down.
19 DECEMBER 2026 — the Information Security Act (ZInfV-1) entered into force on 19 June 2025. Organisations already covered by the previous act had until 19 June 2026 to comply; newly captured essential and important entities have until 19 December 2026. Self-registration with the Government Office for Information Security is the mechanism, and it is a change from the old regime where the state designated who was in scope. 12 JANUARY 2027 — the European Data Act, applicable since 12 September 2025, requires all cloud switching charges and data egress fees to fall to zero. Its Chapter VII also restricts third-country government access to non-personal data held in Europe. HEALTH ROLL-OUT — the Health Digitalisation Act was published on 4 December 2025. It creates the state-owned company for central health information infrastructure, requires every healthcare provider to connect, and forbids that company from transferring or storing personal data outside Slovenia. The commencement and phase-in dates are the single most important thing we could not confirm from a government text on this run. DORMANT SWITCHES — powers already held that could change the picture with no consultation: (1) the ministry's power under the state administration information security decree to grant or refuse cloud approvals, and to reclassify information assets into a tier where public cloud is simply not available; (2) the government's power to widen the scope of essential and important entities by decree under the Information Security Act; (3) the Article 7 localisation duty in the health act, whose reach into sub-processors and suppliers is untested and could be read broadly by the ministry without any new law. At European level, the EU-US Data Privacy Framework remains the largest single point of failure: valid today, appealed to the Court of Justice, and the subject of a formal European Data Protection Board letter to the Commission on 31 July 2026.
Sources
- Official sourceMinistrstvo za zdravje / Urad Vlade RS za informacijsko varnostOfficial presentation on ZInfV-1 duties — entry into force 19 June 2025, compliance 19 June 2026 for existing entities and 19 December 2026 for newly captured essential and important entities
gov.si
“stopil v veljavo 19. 6. 2025”
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeZakon o digitalizaciji zdravstva (ZDigZ), Official Gazette No. 100/25 of 4 December 2025
uradni-list.si
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) — switching charges must reach zero by 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
3 rules here
Layer 2
National rules
Added by this country on top of any bloc rules.
4 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
7 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules3 rules
Uredba (EU) 2016/679 Evropskega parlamenta in Sveta (Splošna uredba o varstvu podatkov)
Directly binding regulation · Regulation (EU) 2016/679
The European baseline that governs almost all personal data in Slovenia. It does not require data to stay in Europe; it sets the conditions under which data may leave.
Enforced by Information Commissioner of the Republic of Slovenia
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of processing
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a local representativeRequired where there is no establishment in the European Union.
- Put a transfer safeguard in placePlus a documented transfer impact assessment after the Schrems II judgment.
- Do not hand data to foreign authorities on demandA third-country authority's order is not by itself a lawful basis to disclose (EDPB Guidelines 02/2024).
- Delete data after a period
- Get a parent's consent for children — applies at: 15 in Slovenia — Slovenia used the national option to lower the age below 16
What it costs if you get it wrong
- Percentage of global turnover: €20,000,000 or 4% of worldwide group turnover, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: €10,000,000 or 2% of worldwide group turnover, whichever is higher — about $11 millionController and processor duties, including security and breach notification
- Order to stopOrder to stop processing or to suspend flows to a third country — often worse commercially than the fine
- Claims by individualsCompensation claims by affected individuals
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679, Chapter V (transfers) and Article 83 (fines)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeZakon o varstvu osebnih podatkov — the Slovenian regulator's own legislation page, confirming the Regulation plus ZVOP-2 as the applicable framework
ip-rs.si
Link checked 18 August 2026
Uredba (EU) 2018/1807 o okviru za prosti pretok neosebnih podatkov v Evropski uniji
Directly binding regulation · Regulation (EU) 2018/1807
Slovenia is forbidden from forcing non-personal data to be stored on its territory, except where public security genuinely requires it. Any Slovenian localisation demand has to justify itself against this rule.
Transfer model: No restriction · Accepted routes: Nothing required
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807, Article 4
eur-lex.europa.eu
Link checked 18 August 2026
Uredba (EU) 2023/2854 (Akt o podatkih)
Directly binding regulation · Regulation (EU) 2023/2854
The European Data Act has applied since 12 September 2025 and gives customers a right to switch cloud providers. Its hardest deadline is 12 January 2027, when all switching charges and data export fees must reach zero.
What it makes you do
- Make switching cloud provider possible — from 12 January 2027All switching charges and data egress fees must be zero from 12 January 2027.
- Do not hand data to foreign authorities on demandChapter VII restricts third-country government access to non-personal data held in the European Union.
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act), Chapters VI and VII
eur-lex.europa.eu
Link checked 18 August 2026
National rules4 rules
Zakon o varstvu osebnih podatkov (ZVOP-2)
Act of parliament · Uradni list RS, št. 163/22
Slovenia's national privacy act, in force since 26 January 2023. It contains no requirement to keep data in Slovenia. What it does add on top of the European rules is a low age of child consent (15), a near-total ban on biometrics outside cases a law allows, detailed video surveillance rules, and a two-year processing log that catches out global logging architectures.
Enforced by Information Commissioner of the Republic of Slovenia
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Get a parent's consent for children — applies at: under 15 — Article 8 sets valid consent to information society services at 15 years, one year below the European default
- Keep logs — 2 yearsArticle 22: a processing log recording collection, change, access, disclosure and deletion with time and user identity; kept two years after the end of the calendar year, extendable to five on a risk assessment.
- Appoint a data protection officerThe data protection officer must have legal capacity, relevant knowledge and no relevant criminal conviction; conflicts of interest are spelled out; external officers are allowed in the private sector.
- Secure the data
- Keep records of processing
- Put a transfer safeguard in place
What it costs if you get it wrong
- Percentage of global turnover: €20,000,000 or 4% of worldwide annual turnover, whichever is higher — about $22 millionThe Commissioner applies the European fine levels; ZVOP-2 removed the old national criminal-style provisions of the 1999 and 2004 acts
- Criminal liability: Fine or imprisonment up to 1 year (up to 2 years in aggravated forms)Misuse of personal data under Article 143 of the Criminal Code — a separate track from the administrative fine, and it attaches to individuals
Sources
- Official sourceUradni list Republike SlovenijeZakon o varstvu osebnih podatkov (ZVOP-2), Uradni list RS 163/22, Articles 4, 8 and 22
uradni-list.si
“Vsebina dnevnika obdelave se hrani dve leti od zaključka koledarskega leta”
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeKljučne novosti ZVOP-2 — the Information Commissioner's own summary: application from 26 January 2023, biometrics prohibition, video surveillance, processing logs, data protection officer conditions, repeal of the old national adequacy list
ip-rs.si
Link checked 18 August 2026
Zakon o spremembah in dopolnitvah Zakona o evidencah na področju dela in socialne varnosti (ZEPDSV-A)
Act of parliament · Uradni list RS, št. 50/23
Since 20 November 2023 an employer in Slovenia must keep the record of working time, and the documents supporting it, at its registered office or at the place where the worker actually works. A foreign employer running everything in an overseas system has a problem a labour inspector can see immediately.
Enforced by Labour Inspectorate of the Republic of Slovenia
What it makes you do
- Keep the data in the countryArticle 19(5): the working-time record and the documents behind it are kept at the employer's registered office or at the place where the worker performs the work. A cloud copy abroad is allowed; the record must still be produced on the spot.
- Keep records of processing
What it costs if you get it wrong
- Fixed maximum fineLabour inspectorate fines for failing to keep or produce the working-time record
Sources
- Official sourceUradni list Republike SlovenijeZEPDSV-A, Uradni list RS 50/23, Article 19(5) and the commencement article
uradni-list.si
“Delodajalec evidenco o izrabi delovnega časa in dokumentacijo ... hrani na sedežu oziroma na kraju opravljanja dela delavca”
Link checked 18 August 2026
Zakon o informacijski varnosti (ZInfV-1)
Act of parliament · Uradni list RS, št. 40/25
Slovenia's cybersecurity law, which brings the European network security rules into national law. It imposes no storage-location rule, but it adds a second incident clock on top of the privacy one: 24 hours for an early warning, 72 hours for the full notification, one month for the final report. Newly captured organisations must be compliant by 19 December 2026.
Enforced by Government Office for Information Security
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notify — from 19 December 2026Self-registration with the Government Office for Information Security. Organisations already covered by the previous act had until 19 June 2026; newly captured essential and important entities have until 19 December 2026.
- Report cyber incidents — within 24 hoursEarly warning immediately and in any case within 24 hours.
- Report cyber incidents — within 72 hoursFull incident notification within 72 hours; final report within one month.
- Secure the data
Sources
- Official sourceUradni list Republike SlovenijeZakon o informacijski varnosti (ZInfV-1), Uradni list RS 40/25 of 4 June 2025
uradni-list.si
Link checked 18 August 2026
- Official sourceMinistrstvo za zdravje / Urad Vlade RS za informacijsko varnostOfficial presentation of ZInfV-1 duties — entry into force 19 June 2025, compliance dates 19 June 2026 and 19 December 2026, incident deadlines
gov.si
“stopil v veljavo 19. 6. 2025”
Link checked 18 August 2026
- Official sourceUrad Vlade RS za informacijsko varnostZložeka ZInfV-1 — the Government Office for Information Security's leaflet on self-registration
gov.si
Link checked 18 August 2026
Kazenski zakonik (KZ-1), 143. člen — zloraba osebnih podatkov
Act of parliament · Criminal Code, Article 143
Misusing personal data is a crime in Slovenia, not only an administrative matter. The ordinary forms carry a fine or up to a year in prison, and prosecution can be brought up to six years after the act. It bites the individual, not just the employer.
Enforced by Information Commissioner of the Republic of Slovenia
What it costs if you get it wrong
- Criminal liability: Fine or imprisonment up to 1 year for the ordinary formsUnlawful processing or disclosure of personal data; prosecution is time-barred six years after the act
Sources
- Official sourceInformacijski pooblaščenec Republike SlovenijeZloraba osebnih podatkov — the Information Commissioner on Article 143 of the Criminal Code, its penalties and the six-year limitation period
ip-rs.si
“denarna kazen ali zapor do enega leta”
Link checked 18 August 2026
Industry rules7 rules
Zakon o digitalizaciji zdravstva (ZDigZ)
Act of parliament · Uradni list RS, št. 100/25 · Health and social care
Slovenia's genuine hard wall. The state-owned company that runs the national central health information system and the central electronic health record is forbidden by statute from transferring or storing personal data outside Slovenian territory, and every healthcare provider in the country must connect its local system to that central infrastructure.
Enforced by Ministry of Health
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryArticle 7(7): the state-owned company running the central health information and communication infrastructure may neither transfer nor store personal data outside the territory of Slovenia, and may not process it for its own purposes.
- Written vendor contractThe company acts as a contractual processor for the health data entrusted to it.
- Secure the data
Sources
- Official sourceUradni list Republike SlovenijeZakon o digitalizaciji zdravstva (ZDigZ), Uradni list RS 100/25 of 4 December 2025, Articles 3(2) and 7(7)
uradni-list.si
“Osebnih podatkov kot pogodbeni obdelovalec ne sme obdelovati za svoje namene in jih ne sme niti prenašati niti hraniti izven ozemlja Republike Slovenije.”
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeUradni list RS No. 100/25 — publication record for the Health Digitalisation Act
uradni-list.si
Link checked 18 August 2026
Zakon o zbirkah podatkov s področja zdravstvenega varstva (ZZPPZ)
Act of parliament · Uradni list RS, št. 65/00, 47/15, 31/18 · Health and social care
Slovenia's health records law sets no rule about where health data is stored, but it sets long minimum retention: a patient's medical file must be kept for ten years after death and other basic medical documentation for fifteen years.
Enforced by Information Commissioner of the Republic of Slovenia
What it makes you do
- Keep data for a minimum period — 10 yearsMedical file and description of illness: 10 years after the patient's death. A living patient's file may not be destroyed however long since the last visit.
- Keep data for a minimum period — 15 yearsOther basic medical documentation: 15 years.
- Delete data after a periodOnce the statutory period expires the record must be destroyed, deleted, blocked or anonymised, and access is no longer lawful.
Sources
- Official sourceInformacijski pooblaščenec Republike SlovenijeRok hrambe zdravstvenega kartona pacienta — Information Commissioner opinion citing Annex 1 of ZZPPZ
ip-rs.si
“se zdravstveni karton in popis bolezni hrani 10 let po smrti bolnika”
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijeRoki hrambe zdravstvene dokumentacije — the Commissioner confirms the periods are fixed by ZZPPZ and cannot be shortened for practical reasons
ip-rs.si
“roke hrambe zdravstvene dokumentacije opredeljuje zakon in na njem temelječi predpisi”
Link checked 18 August 2026
Uredba o informacijski varnosti v državni upravi
Directly binding regulation · Uradni list RS, št. 29/18 · Government
A Slovenian state administration body may put information in a public cloud only if that information sits in the lowest security tiers, and only after the ministry gives written approval. It is not a location rule — a Slovenian public cloud is treated the same as a foreign one — but in practice it keeps sensitive government data out of commercial clouds entirely.
Enforced by Ministry of Digital Transformation
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyArticle 41: use of public cloud services requires the written approval of the ministry, which must first review the provider's terms of service.
- Secure the dataCloud may be used only for information assets that are unclassified or in the lowest tiers Z1, C1 and R1.
Sources
- Official sourceUradni list Republike SlovenijeUredba o informacijski varnosti v državni upravi, Uradni list RS 29/18, Article 41 (cloud computing services)
uradni-list.si
Link checked 18 August 2026
- Official sourceInformacijski pooblaščenec Republike SlovenijePravilniki o uporabi informacijskih storitev v oblaku — Information Commissioner opinion on internal cloud-use rules in the public sector
ip-rs.si
Link checked 18 August 2026
Zakon o varstvu dokumentarnega in arhivskega gradiva ter arhivih (ZVDAGA)
Act of parliament · ZVDAGA and its implementing decree on protection of documentary and archival material
Slovenia regulates the business of digital document storage itself. Anyone offering capture or storage services must register with the national archive first, and for archival material may use only equipment and services the archive has certified. There is no requirement that the copies sit in Slovenia, but there must be two of them in geographically separated places.
Enforced by Archives of the Republic of Slovenia
What it makes you do
- Register or notifyA provider of digital capture or storage services, equipment or software must register with the Archives of the Republic of Slovenia at least eight days before starting to offer the service.
- Hold a security certificateFor archival material in digital form, only equipment and services certified by the state archive may be used. Certification fees run from about 300 to 2,000 euros (roughly $330 to $2,200).
- Secure the dataAt least two copies at two geographically separated locations, so that loss of data is prevented. No requirement that either location be in Slovenia.
Sources
- Official sourcePortal SPOT, Government of the Republic of SloveniaZajemanje ali hranjenje gradiva v digitalni obliki — official business portal statement of registration, certification and two-copy duties
spot.gov.si
“najmanj dveh kopij podatkov na dveh geografsko oddaljenih lokacijah tako, da se prepreči izguba podatkov”
Link checked 18 August 2026
Zakon o igrah na srečo (ZIS)
Act of parliament · Zakon o igrah na srečo, consolidated text, with the Rules on organising games of chance over the internet or other telecommunications means · Online gaming
Online gambling in Slovenia is an establishment wall rather than a data wall. Only a Slovenian-registered joint-stock company can hold the concession, and its system must be wired into the tax authority's own system for live supervision. We found no rule requiring the server itself to be in Slovenia.
Enforced by Financial Administration of the Republic of Slovenia
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyOnly a joint-stock company with its registered seat in Slovenia may hold a concession for classical or special games of chance (Articles 30 and 55). A foreign operator cannot be licensed from abroad.
- Independent auditArticle 3a: an operator offering games over the internet must connect its information system to the supervisory authority's information system, and since the November 2025 amending rules must transmit event and transaction data through a single official web service.
Sources
- Official sourceUradni list Republike SlovenijeZakon o igrah na srečo, consolidated text, Articles 3a, 30, 55 and 92
uradni-list.si
“Klasične igre na srečo sme trajno prirejati kot svojo dejavnost le delniška družba, ki ima sedež na območju Republike Slovenije”
Link checked 18 August 2026
- Official sourceEuropean Commission, Technical Regulation Information SystemPravilnik o dopolnitvah Pravilnika o prirejanju iger na srečo preko interneta oziroma drugih telekomunikacijskih sredstev, notified 11 November 2025 — no server-location requirement in the text
technical-regulation-information-system.ec.europa.eu
Link checked 18 August 2026
- Official sourceFinančna uprava Republike SlovenijeIgre na srečo — the Financial Administration's own page on the governing acts and the concession requirement
fu.gov.si
Link checked 18 August 2026
Zakon o elektronskih komunikacijah (ZEKom-2)
Act of parliament · Uradni list RS, št. 130/22 · Telecoms
Slovenia has no blanket telecoms data retention. The Constitutional Court struck the old bulk retention rules down in 2014 and ordered the retained data deleted, and the 2022 replacement law did not restore them. Traffic data may be kept only as long as billing needs it, plus narrow emergency-location processing.
Enforced by Agency for Communication Networks and Services
What it makes you do
- Delete data after a periodTraffic data may be kept for billing and interconnection settlement only until payment is complete and no longer than the limitation period — in practice the current month plus about three months.
- Secure the data
Sources
- Official sourceInformacijski pooblaščenec Republike SlovenijeHramba podatkov v prometu elektronskih komunikacij — the Information Commissioner confirms there is no advance, bulk retention duty after the Constitutional Court's annulment
ip-rs.si
Link checked 18 August 2026
- Official sourceLink may be brokenUstavno sodišče Republike SlovenijeOdločba Ustavnega sodišča U-I-65/13 — annulment of the blanket electronic communications data retention provisions
us-rs.si
Link checked 18 August 2026
- Official sourceUradni list Republike SlovenijeZakon o elektronskih komunikacijah (ZEKom-2), Uradni list RS 130/22 of 11 October 2022
uradni-list.si
Link checked 18 August 2026
Uredba (EU) 2022/2554 o digitalni operativni odpornosti za finančni sektor (DORA)
Directly binding regulation · Regulation (EU) 2022/2554 · Finance
Slovenian banking, insurance and securities regulation contains no storage-location rule that we could find. Financial firms are governed by the European digital operational resilience rules, applicable since 17 January 2025, which require them to disclose where data sits, keep a register of technology suppliers and plan their exit — but not to keep anything in Slovenia.
Enforced by Bank of Slovenia
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Written vendor contractContracts with technology suppliers must state where data is processed and stored, and provide audit rights and exit plans.
- Keep records of processingA register of contractual arrangements with third-party technology providers, reported to the supervisor.
- Report cyber incidents
Sources
- Official sourceAgencija za zavarovalni nadzorKrepitev kibernetske varnosti — the Slovenian Insurance Supervision Agency on the digital operational resilience rules and their 17 January 2025 application date
a-zn.si
“bo začela veljati 16. 1. 2023, uporabljati pa se bo začela 17. 1. 2025”
Link checked 18 August 2026
- Official sourceBanka SlovenijePoročanje o registru pogodb s tretjimi ponudniki storitev IKT — Bank of Slovenia reporting page for the register of technology supplier contracts
bsi.si
Link checked 18 August 2026
- Official sourceLink may be brokenAgencija za trg vrednostnih papirjevDORA Regulation Guidelines — the Securities Market Agency's guidance page for investment firms
a-tvp.si
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact commencement and phase-in dates of the Health Digitalisation Act (ZDigZ), including when the localisation duty in Article 7(7) starts to bite and by when healthcare providers must connect to the central system.
The official gazette page for Official Gazette 100/25 truncates before the final and transitional provisions, and the government's legal information system serves its pages through JavaScript that we could not read. The in-force date of 19 December 2025 in this record is the standard fifteen-days-after-publication rule applied to a 4 December 2025 publication, not a quoted commencement article.
How far the health localisation duty reaches — whether it binds only the state-owned company running the central health infrastructure, or also its suppliers, sub-processors and individual healthcare providers.
Article 7(7) on its face binds the company established as the public service provider. We could not find official guidance on whether the ministry reads it as flowing down the supply chain. Treat a foreign sub-processor to that company as high risk until this is clarified.
Whether the 2018 Decree on information security in state administration has been amended or replaced since the 2025 Information Security Act, and which ministry now grants cloud approvals.
The gazette page we read is the original 2018 text. We found no repeal, but we also found no consolidated version on a government domain, and Slovenia has reorganised its digital ministries since 2018.
Minimum retention periods for tax, accounting and company records in Slovenia (commonly stated as ten years).
The Financial Administration's own explanatory document is served as a binary Word file we could not read, and we did not find an equivalent HTML page on a government domain in the time available. The figure is widely repeated by professional sources but is not backed here by a government citation.
The value of the Information Commissioner's largest fine in 2025.
The 2025 annual report states it imposed its highest fine since the European rules began but the figure did not appear in the section we could read.
The Constitutional Court's decision U-I-65/13 as read from the court's own site.
The court's website returned an access error to our fetch on 18 August 2026. The substance — that blanket telecoms retention was annulled and there is no advance bulk retention duty — is taken from the Information Commissioner's own published opinion, which is a regulator source, so the claim stands but the primary court text is unverified on this run.
Whether Slovenian gambling rules require the gaming server itself to be located in Slovenia.
Neither the Games of Chance Act consolidated text nor the November 2025 amending rules notified to the European Commission contain such a requirement in the parts we could read. The full implementing rules sit on the government's JavaScript-driven legal system, which we could not read. Recorded as 'no rule found, checked 18 August 2026' rather than 'no rule exists'.
Whether any Slovenian rule requires deposit of aerial survey imagery or maps with the state, as several neighbouring countries do.
The new Aviation Act of 2024 and the national spatial data portal contain nothing of the kind in the parts we read. Checked 18 August 2026, no rule found, medium confidence.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Slovenia versus Argentina
- Slovenia versus Armenia
- Slovenia versus Australia
- Slovenia versus Austria
- Slovenia versus Azerbaijan
- Slovenia versus Brazil
- Slovenia versus Bulgaria
- Slovenia versus Cambodia
- Slovenia versus Canada
- Slovenia versus China
- Slovenia versus Croatia
- Slovenia versus Cyprus
- Slovenia versus Estonia
- Slovenia versus France
- Slovenia versus Georgia
- Slovenia versus Germany
- Slovenia versus Greece
- Slovenia versus Hong Kong SAR
- Slovenia versus Hungary
- Slovenia versus Iceland
- Slovenia versus India
- Slovenia versus Indonesia
- Slovenia versus Ireland
- Slovenia versus Israel
- Slovenia versus Italy
- Slovenia versus Japan
- Slovenia versus Latvia
- Slovenia versus Lithuania
- Slovenia versus Luxembourg
- Slovenia versus Malta
- Slovenia versus Mexico
- Slovenia versus Mongolia
- Slovenia versus Nepal
- Slovenia versus Netherlands
- Slovenia versus Poland
- Slovenia versus Russia
- Slovenia versus Saudi Arabia
- Slovenia versus Serbia
- Slovenia versus Singapore
- Slovenia versus Slovakia
- Slovenia versus South Korea
- Slovenia versus Spain
- Slovenia versus Sri Lanka
- Slovenia versus Sweden
- Slovenia versus Switzerland
- Slovenia versus Taiwan
- Slovenia versus Thailand
- Slovenia versus Turkey
- Slovenia versus Ukraine
- Slovenia versus United Arab Emirates
- Slovenia versus United Kingdom
- Slovenia versus United States
- Slovenia versus Uzbekistan