Skip to the content
Global Data RulesData governance rules, country by country

Slovakia

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Slovakia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

You can store Slovak data abroad. Slovakia has no general rule that data must stay in the country. It follows the European rules. You may send data abroad once you have the right paperwork. Three areas are different. Online gambling servers must be in Slovakia. The most sensitive government data must stay in a Slovak data centre. And anyone who takes aerial survey pictures of Slovakia must give a copy to a Ministry of Defence archive.

Data governance in Slovakia

The eight things that decide how you handle data about people in Slovakia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The rules apply even if you have no office in Slovakia. You are covered if you sell goods or services to people in Slovakia. You are also covered if you track what they do online. There is no minimum size, staff count or revenue that keeps you out. If you have no office anywhere in the European Union, you must name a representative in writing inside the Union. That person can sit in any member state where your customers are. It does not have to be Slovakia.

What you have to do here:
Appoint a representative

Where the data is allowed to live

In general, yes, with the standard European paperwork. Nothing in Slovak law says personal data must be kept in Slovakia. The law says the opposite almost word for word. It applies to a Slovak company whether it uses data inside or outside the country. But three activities do force data to stay. Online gambling operators must put their server in Slovakia. The top security tier of government data must stay in a Slovak data centre. And aerial survey images of Slovakia must be handed to a state archive.

What to do: Plan for a database inside Slovakia: this data is not allowed to leave.

Sending data out of the country

Slovakia uses the European model. You can only send data freely to approved countries. Data may go to any country the European Commission has decided is safe enough. It may go anywhere else if you sign the Commission's standard contract, use approved group-wide rules, or fit one of a few narrow exceptions. The approved list is real and long. It includes the United Kingdom, Switzerland, Japan, South Korea, and Canada for commercial bodies. The United States counts only for companies signed up to the transatlantic scheme. Slovakia adds nothing of its own on top.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract · Legal claims

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Office for Personal Data Protection of the Slovak Republic. It is real, staffed and busy. In 2025 it issued 542 final fines worth about 468,000 euros (roughly 510,000 US dollars). It collected about 411,000 euros of that. That is a very high number of fines but a very small average, about 860 euros each. It has around 60 staff and got 20 extra posts in 2025. Cybersecurity incidents go to a separate body, the National Security Authority.

How long you must keep it — and when to delete it

There is no single rule on how long you keep data. The general privacy rule is to delete data when you no longer need it. Against that sit long minimum keeping times. Accounts and financial statements: ten years. Entries in the national health registers: up to one hundred years after the person dies. Telecoms companies keep far less than most people assume. Slovakia scrapped blanket call-record keeping after its Constitutional Court struck it down. Operators now keep only what a court order covers.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are two deadlines and they are different. A personal data breach goes to the privacy authority within 72 hours of you finding out. It also goes to the affected people quickly, if the risk to them is high. A cybersecurity incident at a regulated organisation goes to the National Security Authority twice. First a warning within 24 hours. Then a fuller report within 72 hours. If you are both, you file both, to two different bodies.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things are not in the summary. Public bodies can be fined the full amount, with no discount. Mishandling personal data you got through your job is a crime, not just a fine. The age of consent for online services is 16, not 13. The rule on dead people's data changed today. And there is no European workaround for the gambling server rule.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability

What's changing next

The whole national privacy law is being replaced by two new laws. One is general. The other covers police and courts. Both are still bills and have no legal effect. Act 18/2018 was amended today, 18 August 2026, mostly to remove dead people from its scope. Public bodies face a bigger data-registration duty from 1 January 2027. And all cloud switching and data export fees across Europe must drop to zero by 12 January 2027.

What to do: Diarise 1 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries7 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Online gaming data must stay in the country

Official name: Zákon č. 30/2019 Z. z. o hazardných hrách a o zmene a doplnení niektorých zákonov, § 14 ods. 21 a 22 · Act No. 30/2019 Coll., section 14(21) and 14(22) · Act of parliament

In forceNo — it stays put

If you run online or terminal gambling, your server must be inside Slovakia. You must also give the regulator free online access to it. There is no way around this by using another European country.

In force since 1 March 2019

Enforced by Gambling Regulatory Authority

How this country controls where data goes: Not allowed

Government

Government data must stay in the country

Official name: Metodické usmernenie č. 020775/2025/oSBATA z 11. 4. 2025 pre proces zaradenia cloudovej služby do katalógu vládnych cloudových služieb, vydané podľa § 24a zákona č. 95/2019 Z. z. · Binding methodological guidance no. 020775/2025/oSBATA, issued under section 24a of Act No. 95/2019 Coll. · Government rules

In forceNo — it stays put

Slovak public bodies handling the top security tier of data have one option. They must use a cloud service that keeps that data inside Slovakia. The data centre must be within reach of the Slovak state. Lower tiers have no location rule. They must still disclose every data centre location.

In force since 15 April 2025

Enforced by Ministry of Investments, Regional Development and Informatisation

How this country controls where data goes: Not allowed

Government

Cloud and outsourcing rules

Official name: Zákon č. 95/2019 Z. z. o informačných technológiách vo verejnej správe, § 24a Vládny cloud · Act No. 95/2019 Coll., section 24a, as amended by Act No. 67/2026 Coll. · Act of parliament

Partly in forceYes, with paperwork

The law behind the government cloud. Most of it is already in force. More data-registration duties for public bodies start on 1 January 2027. So parts of the current text do not apply yet.

In force since 1 May 2019Enforced from 30 April 2026

Enforced by Ministry of Investments, Regional Development and Informatisation

How this country controls where data goes: Only approved countries

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law (2018)

Official name: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov · Act No. 18/2018 Coll., as last amended by Act No. 168/2026 Coll. · Act of parliament

In forceYes — store it anywhere

Slovakia's national privacy law. It does not require data to be kept in Slovakia. It says so directly: it applies whether you use the data inside or outside the country. It sets the age for online consent at 16. It applies the full European maximum fines to public bodies too.

In force since 25 May 2018

Enforced by Office for Personal Data Protection of the Slovak Republic

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

General data protection law (Legislative process files LP/2025/305 and LP/2025/306)

Official name: Návrh zákona o zabezpečení ochrany fyzických osôb pri spracúvaní osobných údajov (LP/2025/305) a návrh zákona o ochrane fyzických osôb pri spracúvaní osobných údajov príslušnými orgánmi (LP/2025/306) · Legislative process files LP/2025/305 and LP/2025/306 · Draft law

ProposedNot yet established

Two draft laws would split the current privacy act in two. One would be general. One would cover police and justice. They are bills only. As at 18 August 2026 the regulator's own legislation page still lists only the 2018 act. Do not plan around them as binding.

Enforced by Office for Personal Data Protection of the Slovak Republic

Cyber security rules

Official name: Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplnení niektorých zákonov · Act No. 69/2018 Coll., transposing Directive (EU) 2022/2555 (NIS2) by Act No. 366/2024 Coll., further amended by Acts 318/2025 and 67/2026 Coll. · Act of parliament

In forceYes — store it anywhere

Slovakia's cybersecurity law. It brought in the European NIS2 rules from 1 January 2025. It says nothing about where data must be stored. But it adds a second incident deadline: 24 hours for a first warning, then 72 hours for the fuller report. That goes to a different regulator from the privacy one.

In force since 1 April 2018Enforced from 1 January 2025

Enforced by National Security Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies across the European Union3 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Nariadenie Európskeho parlamentu a Rady (EÚ) 2016/679 (všeobecné nariadenie o ochrane údajov) · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

The European rules that cover almost all personal data in Slovakia. They do not require data to stay in Europe. They set the conditions for sending data out.

In force since 25 May 2018

Enforced by European Data Protection Board

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

General data protection law

Official name: Nariadenie (EÚ) 2018/1807 o rámci pre voľný tok neosobných údajov v Európskej únii · Regulation (EU) 2018/1807 · Directly binding regulation

In forceYes — store it anywhere

Slovakia may not force non-personal data to be stored inside the country. The only exception is where public security truly requires it. Any Slovak demand for local storage has to meet that test.

In force since 28 May 2019

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Cloud and outsourcing rules (2027)

Official name: Nariadenie (EÚ) 2023/2854 o harmonizovaných pravidlách týkajúcich sa spravodlivého prístupu k údajom a ich používania (akt o údajoch) · Regulation (EU) 2023/2854 (Data Act) · Directly binding regulation

Partly in forceYes — store it anywhere

The European Data Act has applied since 12 September 2025. It gives customers the right to switch cloud providers. Its firmest deadline is 12 January 2027. From then, all switching charges and data export fees must be zero.

In force since 12 September 2025In force now, but not enforced until 12 January 2027

That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Úrad na ochranu osobných údajov Slovenskej republiky

    General data protection supervision under the General Data Protection Regulation and Act 18/2018 Coll.

    Fully operational. The chair is Zuzana Valková. Tomáš Danč has been deputy chair since 24 October 2024. It has around 60 staff, plus 20 extra posts granted in 2025. Its 2025 budget was about 4.9 million euros. In 2025 it issued 542 final fines worth about 468,000 euros and collected about 411,000 euros. It also issued 10 procedural fines and received 177 breach reports. It is hiring: it published four internal vacancy notices in August 2026 alone.

  • Národný bezpečnostný úrad

    Cybersecurity supervision under Act 69/2018 Coll., incident reporting, cybersecurity auditor certification

    Operational. It runs the national cybersecurity incident reporting scheme. It also certifies the auditors who must sign off the higher government cloud categories.

  • Ministerstvo investícií, regionálneho rozvoja a informatizácie Slovenskej republiky

    Government cloud catalogue and public administration information technology standards under Act 95/2019 Coll.

    Operational. It keeps the government cloud catalogue. It issued the binding guidance of 11 April 2025 that makes category U4 data stay in Slovakia.

  • Národná banka Slovenska

    Supervision of banks, payment institutions, insurers and securities firms, including outsourcing and cloud arrangements

    Operational. It publishes its own positions on cloud computing and outsourcing. It issues guidance in its official bulletin.

  • Úrad pre reguláciu hazardných hier

    Licensing and supervision of gambling operators, including the requirement that the operator's server sits in Slovakia

    Operational as the licensing regulator. We did not check how often it has enforced the server location rule.

  • Úrad geodézie, kartografie a katastra Slovenskej republiky

    Geodesy and cartography, the state documentation archive and the aerial imagery deposit duties under Act 215/1995 Coll.

    Operational. Fines under the geodesy act are very small, up to 3,300 euros for a company. We found no evidence that the aerial imagery deposit duty is actively enforced.

  • Európsky výbor pre ochranu údajov

    Consistency and guidance across the European Union; the Slovak authority is a member

    Operational. The Slovak authority joined its 2026 coordinated enforcement action on transparency.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the two replacement data protection bills (LP/2025/305 and LP/2025/306) have not been submitted to or passed by the National Council.

    We could not confirm how far the two replacement bills have got in parliament. The regulator's own legislation page still listed Act 18/2018 Coll. as the law in force on 18 August 2026, and no replacement act appears in the collection of laws. We could not check the parliamentary record itself. Treat the 2018 act as the law and watch for a new one.

  • That no localisation rule exists for banking, payments, insurance or securities data in Slovakia.

    We found no rule about where financial data must be stored. The central bank's own cloud computing and insurance outsourcing pages set no location rule. But we did not read the full text of the Banking Act (483/2001 Coll.), the Payment Services Act (492/2009 Coll.) or the Securities Act (566/2001 Coll.). We did not examine the banking secrecy rules. If you are a bank, payment firm or broker, check those before you rely on this. Checked 18 August 2026.

  • That Slovak health law imposes no storage-location rule on private healthcare providers.

    We found no rule that health data must stay in Slovakia. We searched the National Health Information System Act (153/2013 Coll.) and found no territorial storage rule. But we did not read the Healthcare Act (576/2004 Coll.) in full, and that law covers medical records held by individual providers. If you handle patient records, check it before you rely on this. Checked 18 August 2026.

  • How often, if ever, the gambling server-location rule and the aerial imagery deposit duty are actually enforced.

    We could not confirm whether these two rules are enforced. The wording in the law is clear. But we found no published enforcement decisions from the Gambling Regulatory Authority or the Geodesy, Cartography and Cadastre Authority. A rule that is never enforced carries a different risk from one that is policed. Assume it applies to you and plan for it.

  • The precise content of Act 67/2026 Coll., which amended both the cybersecurity act and the public administration information technology act with effect from 30 April 2026 and again from 1 January 2027.

    We could not confirm why this amendment was made or whether more changes follow. We did confirm the amendment and its start dates from the official version history, and we read the combined texts. We also identified the 2027 changes to the central metadata duties. We did not get the explanatory memorandum that would set out the reasoning.

  • Whether the defence and classified information regime (Act 215/2004 Coll.) imposes additional storage-location duties.

    We did not research classified information. If your data is classified under Slovak law, this record does not cover it. Get specific advice before you rely on anything here.

  • The average and maximum size of individual fines issued by the Slovak data protection authority in 2025.

    We could not confirm the size of the largest fine. The annual report gives only the total: 542 fines worth about 468,000 euros. It gives no breakdown by decision, and full decisions are not published. The average of roughly 860 euros is our own arithmetic, not a figure the authority states.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.