Skip to the content
Global Data RulesData governance rules, country by country

Slovenia

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Slovenia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

Slovenia has no general rule that data must stay in the country. It runs on the European rulebook: send data abroad once you have the right paperwork. Three things break that. The company running the new national health record system may not store data outside Slovenia. Government bodies may cloud only their least sensitive data. And working-time records must sit at the Slovenian workplace.

Data governance in Slovenia

The eight things that decide how you handle data about people in Slovenia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Slovenia's privacy rules reach a company with no office there. If you offer goods or services to people in Slovenia, or watch what they do online, the European rules apply to you. Slovenia's own privacy act applies alongside them. There is no size or revenue threshold that lets you out. A company with no office anywhere in Europe must appoint a written representative inside Europe.

What you have to do here:
Appoint a representative

Where the data is allowed to live

In general yes, with paperwork. Slovenia adds no national rule of its own about where data must be stored. But four industries break that answer, and one of them is absolute. Health is the big one. The state company that runs Slovenia's central health record system is banned outright from storing or sending personal data outside Slovenia. Every healthcare provider must connect to that system. Government cloud, employment records and gambling each carry their own restriction.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Slovenia uses the European model. You can send data freely to a country the European Commission has approved. If your destination is not approved, you can still send data. You sign the Commission's standard contract, or use approved group-wide rules, or rely on one of a few narrow exceptions. Slovenia adds nothing of its own. The old Slovenian system, where the Information Commissioner had to authorise each export, was scrapped when the current privacy act arrived in January 2023.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Information Commissioner, and it is really working. In 2025 it opened 464 inspection cases from complaints, plus 102 more from inspection reports. It issued 134 enforcement decisions, fined in 89 of them and gave warnings in 45. It handed down what it calls its largest fine since the European rules began. It handled 153 breach reports. It is small. At the end of 2025 it had one commissioner and 53 staff, and it says openly that it does not have enough people. Cybersecurity is enforced separately by a government office set up for the job.

How long you must keep it — and when to delete it

Both a minimum and a maximum apply, and the minimums are long. A patient's medical file must be kept for ten years after the patient dies. Other basic medical records must be kept for fifteen years. Records of who touched personal data in a computer system must be kept for two years after the end of the year. That rises to five years if the risk is high. Working-time records must be kept at the Slovenian workplace. In the other direction the European rule applies: delete personal data once the purpose is spent.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count three deadlines, not one. A personal data breach goes to the Information Commissioner within 72 hours. If you are an essential or important organisation, a serious cyber incident goes to the government security office. You send an early warning immediately, and in any case within 24 hours. A full report follows within 72 hours, then a final report within one month. Telecoms operators have their own duties on top. Missing the 24-hour warning is the most common failure. It lands while you are still working out what happened.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things that catch people out. A child can consent at 15 in Slovenia, not 16. That is one year younger than the European default. Fingerprints and face scans are banned in the private sector unless a law allows them and the Commissioner approves. Every access to a covered database must be logged, and the log kept two years. Leaking personal data you got through your job is a crime, not just a fine. And working-time records must physically be at the Slovenian workplace, which no cloud contract fixes.

What you have to do here:
Get a parent's consent for children · Keep logs · Register or notify · Hold a security certificate
What it costs if you get it wrong:
Criminal liability

What's changing next

Two dates in the next twelve months matter most. On 19 December 2026 the cybersecurity duties start to apply to organisations newly covered by Slovenia's 2025 Information Security Act. That means registration, security measures and the incident deadlines. On 12 January 2027 the European Data Act bans all cloud switching and data export fees. Behind both sits the roll-out of the national health record system. Its ban on storing data outside Slovenia is already law, but we could not pin down the timetable.

What to do: Diarise 19 December 2026 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries7 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Health and social care

Health and social care data must stay in the country

Official name: Zakon o digitalizaciji zdravstva (ZDigZ) · Uradni list RS, št. 100/25 · Act of parliament

Partly in forceNo — it stays put

Slovenia's one absolute rule. One state-owned company runs the national central health information system and the central electronic health record. It is forbidden by law from transferring or storing personal data outside Slovenian territory. Every healthcare provider in the country must connect its local system to that central infrastructure.

In force since 19 December 2025

Enforced by Ministry of Health

How this country controls where data goes: Not allowed

Not fully verified — see “What we're not sure about” below.
Health and social care

Health data rules

Official name: Zakon o zbirkah podatkov s področja zdravstvenega varstva (ZZPPZ) · Uradni list RS, št. 65/00, 47/15, 31/18 · Act of parliament

In forceYes, with paperwork

Slovenia's health records law sets no rule about where health data is stored. But it sets long minimum keeping periods. A patient's medical file must be kept for ten years after death. Other basic medical documentation must be kept for fifteen years.

In force since 22 July 2000

Enforced by Information Commissioner of the Republic of Slovenia

Not fully verified — see “What we're not sure about” below.
Government

Cloud and outsourcing rules

Official name: Uredba o informacijski varnosti v državni upravi · Uradni list RS, št. 29/18 · Directly binding regulation

In forceYes, with paperwork

A Slovenian state administration body may put information in a public cloud only if that information sits in the lowest security tiers. It also needs written approval from the ministry first. This is not a rule about location. A Slovenian public cloud is treated the same as a foreign one. But it keeps sensitive government data out of commercial clouds entirely.

In force since 5 May 2018

Enforced by Ministry of Digital Transformation

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Zakon o varstvu osebnih podatkov (ZVOP-2) · Uradni list RS, št. 163/22 · Act of parliament

In forceYes — store it anywhere

Slovenia's national privacy act, in force since 26 January 2023. It contains no requirement to keep data in Slovenia. It adds four things on top of the European rules. A low age of child consent, at 15. A near-total ban on biometrics outside the cases a law allows. Detailed video surveillance rules. And a two-year activity log that catches out global logging setups.

In force since 26 January 2023

Enforced by Information Commissioner of the Republic of Slovenia

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Data rules

Official name: Zakon o spremembah in dopolnitvah Zakona o evidencah na področju dela in socialne varnosti (ZEPDSV-A) · Uradni list RS, št. 50/23 · Act of parliament

In forceA copy must stay

Since 20 November 2023 an employer in Slovenia must keep the record of working time at a set place. The same goes for the documents supporting it. That place is its registered office, or where the worker actually works. A foreign employer running everything in an overseas system has a problem a labour inspector can see immediately.

In force since 20 May 2023Enforced from 20 November 2023

Enforced by Labour Inspectorate of the Republic of Slovenia

Not fully verified — see “What we're not sure about” below.

Cyber security rules

Official name: Zakon o informacijski varnosti (ZInfV-1) · Uradni list RS, št. 40/25 · Act of parliament

Partly in forceYes — store it anywhere

Slovenia's cybersecurity law, which brings the European network security rules into national law. It sets no rule about where data must be stored. But it adds a second incident deadline on top of the privacy one. Twenty-four hours for an early warning, 72 hours for the full notification, one month for the final report. Newly covered organisations must comply by 19 December 2026.

In force since 19 June 2025In force now, but not enforced until 19 December 2026

That is a long gap: the duty is real law today, but no penalty can follow until 19 December 2026. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by Government Office for Information Security

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies across the European Union3 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Uredba (EU) 2016/679 Evropskega parlamenta in Sveta (Splošna uredba o varstvu podatkov) · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

The European baseline that governs almost all personal data in Slovenia. It does not require data to stay in Europe. It sets the conditions under which data may leave.

In force since 25 May 2018

Enforced by Information Commissioner of the Republic of Slovenia

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

General data protection law

Official name: Uredba (EU) 2018/1807 o okviru za prosti pretok neosebnih podatkov v Evropski uniji · Regulation (EU) 2018/1807 · Directly binding regulation

In forceYes — store it anywhere

Slovenia is forbidden from forcing non-personal data to be stored on its territory. The only exception is where public security really requires it. Any Slovenian demand to keep data in the country has to justify itself against this rule.

In force since 28 May 2019

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Cloud and outsourcing rules (2027)

Official name: Uredba (EU) 2023/2854 (Akt o podatkih) · Regulation (EU) 2023/2854 · Directly binding regulation

Partly in forceYes — store it anywhere

The European Data Act has applied since 12 September 2025 and gives customers a right to switch cloud providers. Its hardest deadline is 12 January 2027, when all switching charges and data export fees must reach zero.

In force since 12 September 2025In force now, but not enforced until 12 January 2027

That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Who you would hear from

  • Informacijski pooblaščenec Republike Slovenije

    Data protection supervision under the General Data Protection Regulation and ZVOP-2, and freedom of information

    Fully operational. It is headed by dr. Jelena Virant Burnik, who took office in 2024. In 2025 it opened 464 inspection procedures on complaints and 102 on inspection reports. It sent 176 advisory letters. It issued 134 decisions in minor-offence proceedings, of which 89 were fines and 45 warnings. It reports imposing its largest fine since the European rules began. It handled 153 personal data breach notifications. Staff at 31 December 2025 were one appointed official and 53 public employees. The office states openly that this is not enough for its caseload and widening remit.

  • Urad Vlade Republike Slovenije za informacijsko varnost

    Cybersecurity supervision, registration of essential and important entities, and incident reporting under ZInfV-1

    Operational and publishing actively. It puts out leaflets, model incident-response documents and conference material on the 2025 Information Security Act. It runs the self-registration scheme and the national incident reporting route.

  • Ministrstvo za zdravje

    Health digitalisation, the central electronic health record, and the state company running central health information infrastructure

    Operational. It sponsored the Health Digitalisation Act published on 4 December 2025 and runs the eZdravje programme and its 2026 conference cycle.

  • Finančna uprava Republike Slovenije

    Tax administration and supervision of games of chance, including the live link into online operators' systems

    Operational. It publishes the governing acts and supervision practice for games of chance on its own site.

  • Banka Slovenije

    Banking supervision, payment services, and the register of contracts with third-party technology providers under the European digital operational resilience rules

    Operational. It collects the register of technology-supplier contracts from supervised entities and publishes technical reporting instructions.

  • Agencija za zavarovalni nadzor

    Supervision of insurers, including digital operational resilience

    Operational. It publishes its own guidance on the European digital operational resilience and network security rules.

  • Arhiv Republike Slovenije

    Registration and certification of digital capture and storage services, equipment and software for documentary and archival material

    Operational. Registration and certification are live services with published fees, run through the national business portal.

  • Agencija za komunikacijska omrežja in storitve Republike Slovenije

    Electronic communications regulation under ZEKom-2

    Operational as the industry regulator. We did not verify what it does specifically on data protection enforcement.

  • Ministrstvo za digitalno preobrazbo

    State administration information systems and approval of public cloud use by state bodies

    Operational. We did not separately confirm which ministry now signs off cloud approvals under the 2018 decree. The decree names 'the ministry' responsible for public administration information systems.

  • Inšpektorat Republike Slovenije za delo

    Enforcement of employment records duties, including where working-time records must be kept

    Operational. It is the body that inspects working-time records on site.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact commencement and phase-in dates of the Health Digitalisation Act (ZDigZ), including when the localisation duty in Article 7(7) starts to bite and by when healthcare providers must connect to the central system.

    We could not confirm the date this Act came into force. The official gazette page for Official Gazette 100/25 stops before the final and transitional rules, and we could not read the government's legal information system. The date of 19 December 2025 in this record comes from the standard rule of fifteen days after publication, applied to a 4 December 2025 publication. It is not quoted from a start-date article.

  • How far the health localisation duty reaches — whether it binds only the state-owned company running the central health infrastructure, or also its suppliers, sub-processors and individual healthcare providers.

    We could not confirm how far this ban reaches down the supply chain. On its face, Article 7(7) binds the company set up as the public service provider. We found no official guidance on whether the ministry reads it as flowing down to suppliers. Treat a foreign sub-supplier to that company as high risk until this is settled.

  • Whether the 2018 Decree on information security in state administration has been amended or replaced since the 2025 Information Security Act, and which ministry now grants cloud approvals.

    We could not confirm that this is the current version. The gazette page we read is the original 2018 text. We found no repeal, but we also found no consolidated version on a government website. Slovenia has reorganised its digital ministries since 2018, so check before you rely on it.

  • Minimum retention periods for tax, accounting and company records in Slovenia (commonly stated as ten years).

    We could not confirm this figure against a government source. The Financial Administration's own explanatory document is a Word file we could not read, and we found no equivalent web page on a government site. Professional sources repeat the figure widely, but no government citation backs it here.

  • The value of the Information Commissioner's largest fine in 2025.

    We could not confirm the size of the largest fine. The 2025 annual report says the Commissioner imposed its highest fine since the European rules began. The figure did not appear in the part of the report we could read.

  • The Constitutional Court's decision U-I-65/13 as read from the court's own site.

    We could not read the court's own text of this judgment, because its website returned an access error on 18 August 2026. The substance comes instead from the Information Commissioner's published opinion, which is a regulator source. That substance is: blanket telecoms retention was annulled, and there is no advance bulk retention duty. The claim stands, but the original court text is unverified.

  • Whether Slovenian gambling rules require the gaming server itself to be located in Slovenia.

    We found no rule requiring this, but we could not read every source. Neither the consolidated Games of Chance Act nor the November 2025 amending rules contain such a requirement in the parts we could read. Those rules were notified to the European Commission. The full implementing rules sit on a government legal system we could not read. Record this as no rule found on 18 August 2026, not as no rule exists.

  • Whether any Slovenian rule requires deposit of aerial survey imagery or maps with the state, as several neighbouring countries do.

    We found no rule of this kind, but we could not read everything. The new Aviation Act of 2024 and the national spatial data portal contain nothing of the kind in the parts we read. Checked 18 August 2026, with medium confidence.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.