Slovakia
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Slovakia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can store Slovak data abroad. Slovakia has no general rule that data must stay in the country. It follows the European rules. You may send data abroad once you have the right paperwork. Three areas are different. Online gambling servers must be in Slovakia. The most sensitive government data must stay in a Slovak data centre. And anyone who takes aerial survey pictures of Slovakia must give a copy to a Ministry of Defence archive.
Data governance in Slovakia
The eight things that decide how you handle data about people in Slovakia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The rules apply even if you have no office in Slovakia. You are covered if you sell goods or services to people in Slovakia. You are also covered if you track what they do online. There is no minimum size, staff count or revenue that keeps you out. If you have no office anywhere in the European Union, you must name a representative in writing inside the Union. That person can sit in any member state where your customers are. It does not have to be Slovakia.
- What you have to do here:
- Appoint a representative
Two sets of rules stack up. The European General Data Protection Regulation applies directly in Slovakia. Its Article 3(2) reaches companies outside the European Union that offer goods or services to people in the Union, or that watch their behaviour. Article 27 then makes you name a written representative in a member state where those people are. On top of that, section 3(4) of Act 18/2018 Coll. sets Slovakia's own reach. Point (a) catches any company with a registered office, place of business, branch, establishment or permanent home in Slovakia. It applies whether you use the data inside or outside the territory of the Slovak Republic. That wording is the clearest sign in the text that Slovak law does not care where your servers are. Point (c) catches the handling of data about people in Slovakia by a company based outside the member states. There is no Slovak registration or licence to get before you may use personal data. The old notification duty went with the 1998 and 2013 Acts. If you appoint a data protection officer, you must tell the authority, using its own form. Act 18/2018 Coll. is on its way out. The authority has two replacement bills moving through the law-making process. See question eight. On 18 August 2026 they are still only bills.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 18/2018 Z. z. o ochrane osobných údajov — consolidated version in force from 18 August 2026 (as amended by Act 168/2026 Coll.), sections 3, 15, 48, 104
slov-lex.sk
“Tento zákon sa vzťahuje na spracúvanie osobných údajov v rámci činnosti prevádzkovateľa alebo sprostredkovateľa, ktorého sídlo, miesto podnikania, organizačná zložka, prevádzkareň alebo trvalý pobyt je na území Slovenskej republiky, a to bez ohľadu na to, či sa spracúvanie osobných údajov vykonáva na území Slovenskej republiky alebo mimo územia Slovenskej republiky”
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 27, 44-49 and 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyNational legislation — the Slovak data protection authority's own list of the laws in force, still naming Act 18/2018 Coll. as the national data protection law
dataprotection.gov.sk
“Na úrovni Slovenskej republiky je ochrana osobných údajov fyzických osôb upravená: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov”
Link checked 18 August 2026
Where the data is allowed to live
In general, yes, with the standard European paperwork. Nothing in Slovak law says personal data must be kept in Slovakia. The law says the opposite almost word for word. It applies to a Slovak company whether it uses data inside or outside the country. But three activities do force data to stay. Online gambling operators must put their server in Slovakia. The top security tier of government data must stay in a Slovak data centre. And aerial survey images of Slovakia must be handed to a state archive.
Industry by industry, all checked 18 August 2026. GAMBLING - data must stay in Slovakia. Section 14(22) of Act 30/2019 Coll. on gambling says the gambling operator must place the server on Slovak territory. The same section makes the server record every game played, and every stake and win. It must also record every change to the game software. For online games it must record every movement in a player's account. Section 14(21) makes the operator give the gambling regulator free online access to that server. This is stricter than Hungary's version, which allows anywhere in the European Economic Area. Rating: data must stay in the country GOVERNMENT - data must stay in Slovakia, but only at the top tier. Section 24a of Act 95/2019 Coll. lets the ministry set standards. Those standards can force public bodies deciding on people's rights and duties to use only cloud services listed in the government cloud catalogue. The binding guidance of 11 April 2025 (ref. 020775/2025/oSBATA, in force from 15 April 2025) sets four categories. Category U4, 'special data', must be stored and used on Slovak territory. It must sit in a data centre within reach of Slovak state authorities, in the private part of the government cloud. Categories U1 to U3 carry no location requirement. But the questionnaire still demands a full list of data centre locations. It flags this as important where personal data would sit outside the European Union. Only the Ministry of the Interior, with the Ministry of Finance data centre, may supply the private infrastructure and platform layers. Registration lasts two years and lapses automatically if you do not renew it. Rating: data must stay in the country for U4, data can leave only if conditions are met below it. MAPPING AND AERIAL IMAGES - a copy must stay. Section 8 of Act 215/1995 Coll. on geodesy and cartography covers anyone who acquires original aerial remote-sensing material or aerial survey photographs. You must report it within 30 days. After you have used it, you must hand it over free of charge to a special archive run by the Ministry of Defence. If you publish maps, you must give the archive of the Geodesy, Cartography and Cadastre Authority two paper copies within 30 days. Add one digital copy if a digital version exists. You must also give one more copy to the Ministry of Defence archive. You keep your own copy and may take it abroad. So this is a copy duty, not a ban on exporting. Rating: a copy must stay in the country BANKING, PAYMENTS, INSURANCE, SECURITIES - we found no rule that data must stay in Slovakia. The central bank's own cloud computing page tells firms that using a public cloud does not remove their responsibility for confidentiality, integrity and availability. It points them to the European Banking Authority outsourcing recommendations. It states no location rule. Its insurance outsourcing page says only critical or important operational functions need advance notice, under section 30(3) of the Insurance Act. It expressly allows providers in other member states or outside Europe that meet Article 274 of Delegated Regulation 2015/35. The Digital Operational Resilience Act has applied to financial firms since 17 January 2025. It makes you name in the contract where the data is handled, with audit rights and an exit plan. That is disclosure, not a rule about location. Rating: data can leave only if conditions are met HEALTH - we found no rule that data must stay in Slovakia. Act 153/2013 Coll. on the national health information system has no rule about location. The national system itself is run by the state and physically in Slovakia. That is a fact about a state system, not a rule binding private companies. What the act does contain is very long keeping times. See question five. TELECOMS - we found no rule that data must stay in Slovakia. Telecoms companies also keep much less data than most people assume. See question five. EDUCATION, ONLINE SHOPPING, SOCIAL MEDIA, ARTIFICIAL INTELLIGENCE - we found no Slovak storage-location rule, checked 18 August 2026. DEFENCE AND CLASSIFIED MATERIAL - we did not research this in depth. Classified information has its own separate law, Act 215/2004 Coll., which we did not check. This record does not cover anything classified.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 30/2019 Z. z. o hazardných hrách, section 14(21) and 14(22) — version in force from 1 January 2026
slov-lex.sk
“Server je prevádzkovateľ hazardnej hry povinný umiestniť na území Slovenskej republiky.”
Link checked 18 August 2026
- Official sourceMinisterstvo investícií, regionálneho rozvoja a informatizácie Slovenskej republiky (Ministry of Investments, Regional Development and Informatisation)Binding methodological guidance no. 020775/2025/oSBATA of 11 April 2025 on entering a cloud service in the government cloud catalogue (effective 15 April 2025), category U4
mirri.gov.sk
“Kategória U4: Špeciálne dáta (Kritická úroveň zabezpečenia) ... dáta úrovne C3I3A3, ktoré však vyžadujú uchovávanie a spracovávanie dát na území SR a v dátovom centre, ktoré je v dosahu štátnych orgánov SR, v privátnej časti vládneho cloudu.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 95/2019 Z. z. o informačných technológiách vo verejnej správe, section 24a (government cloud) — version in force from 30 April 2026
slov-lex.sk
“Štandardy podľa § 24 ods. 1 písm. f) ustanovia úrovne cloudových služieb ... pri ktorých dosiahnutí môže orgán riadenia ... odoberať a využívať len cloudové služby, ktoré sú vládnymi cloudovými službami.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon Národnej rady SR č. 215/1995 Z. z. o geodézii a kartografii, section 8 (duties on aerial survey imagery and published cartographic works) and sections 30-31 (penalties)
slov-lex.sk
“oznamovať nadobudnutie prvotných materiálov leteckého diaľkového prieskumu Zeme a leteckých meračských snímok do 30 dní od ich nadobudnutia a po využití ich bezplatne odovzdať na archívne účely osobitnému archívu zriadenému Ministerstvom obrany Slovenskej republiky”
Link checked 18 August 2026
- Official sourceNárodná banka Slovenska (National Bank of Slovakia)Cloud computing — the Slovak central bank's own guidance page for supervised financial institutions
nbs.sk
“For any use of core banking services in the 'public cloud', an institution is not relieved from its responsibilities with respect to confidentiality, integrity and availability of data.”
Link checked 18 August 2026
- Official sourceNárodná banka Slovenska (National Bank of Slovakia)Outsourcing — the Slovak central bank's own position for insurance undertakings
nbs.sk
“Povinnosť poisťovne oznamovať Národnej banke Slovenska zámer zveriť výkon funkcií alebo činností inej osobe sa v súlade s § 30 ods. 3 zákona o poisťovníctve vzťahuje len na výkon kritických alebo dôležitých operačných funkcií”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 18/2018 Z. z. o ochrane osobných údajov — consolidated version in force from 18 August 2026 (as amended by Act 168/2026 Coll.), sections 3, 15, 48, 104
slov-lex.sk
“Tento zákon sa vzťahuje na spracúvanie osobných údajov v rámci činnosti prevádzkovateľa alebo sprostredkovateľa, ktorého sídlo, miesto podnikania, organizačná zložka, prevádzkareň alebo trvalý pobyt je na území Slovenskej republiky, a to bez ohľadu na to, či sa spracúvanie osobných údajov vykonáva na území Slovenskej republiky alebo mimo územia Slovenskej republiky”
Link checked 18 August 2026
What to do: Plan for a database inside Slovakia: this data is not allowed to leave.
Sending data out of the country
Slovakia uses the European model. You can only send data freely to approved countries. Data may go to any country the European Commission has decided is safe enough. It may go anywhere else if you sign the Commission's standard contract, use approved group-wide rules, or fit one of a few narrow exceptions. The approved list is real and long. It includes the United Kingdom, Switzerland, Japan, South Korea, and Canada for commercial bodies. The United States counts only for companies signed up to the transatlantic scheme. Slovakia adds nothing of its own on top.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract · Legal claims
Section 48 of Act 18/2018 Coll. copies Chapter V of the European General Data Protection Regulation. There are three routes, in order. First, the European Commission has decided the destination country is safe enough. If not, second, you use approved safeguards. If not, third, you rely on one of a few narrow exceptions. The Slovak authority runs the forms for notifying and approving transfers outside Europe, for approving contract clauses, and for approving company-wide rules. It lists them on its own site. The 2021 standard contract clauses (Decision (EU) 2021/914) are still the ones to use and have not been changed. New clauses were promised for receivers already covered by the Regulation under Article 3(2). They are still not adopted as at 18 August 2026. You are also expected to write down a risk check on the destination country, following the Schrems II ruling. The EU-US Data Privacy Framework is still in force and legally valid on 18 August 2026. It is under pressure. The General Court dismissed the Latombe challenge on 3 September 2025. An appeal to the Court of Justice was lodged on 31 October 2025 and is still pending. On 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether changes in United States institutions affect the decision. The Commission has not suspended or revoked it. Our advice: you can use it, but never as your only route. Separately, European Data Protection Board Guidelines 02/2024 confirm one point. An order from a foreign authority is not on its own a legal reason to hand data over. Regulation (EU) 2018/1807 stops Slovakia forcing non-personal data to stay in the country, unless public security requires it. That is the only ground the gambling and government cloud rules could rest on.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 18/2018 Z. z. o ochrane osobných údajov — consolidated version in force from 18 August 2026 (as amended by Act 168/2026 Coll.), sections 3, 15, 48, 104
slov-lex.sk
“Tento zákon sa vzťahuje na spracúvanie osobných údajov v rámci činnosti prevádzkovateľa alebo sprostredkovateľa, ktorého sídlo, miesto podnikania, organizačná zložka, prevádzkareň alebo trvalý pobyt je na území Slovenskej republiky, a to bez ohľadu na to, či sa spracúvanie osobných údajov vykonáva na území Slovenskej republiky alebo mimo územia Slovenskej republiky”
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the Commission's own list of countries found to provide adequate protection
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionCommission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEDPB Guidelines 02/2024 on Article 26 GDPR — a third-country authority's order is not by itself a lawful basis to disclose
edpb.europa.eu
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union, Article 4
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyNational legislation — the Slovak data protection authority's own list of the laws in force, still naming Act 18/2018 Coll. as the national data protection law
dataprotection.gov.sk
“Na úrovni Slovenskej republiky je ochrana osobných údajov fyzických osôb upravená: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov”
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Office for Personal Data Protection of the Slovak Republic. It is real, staffed and busy. In 2025 it issued 542 final fines worth about 468,000 euros (roughly 510,000 US dollars). It collected about 411,000 euros of that. That is a very high number of fines but a very small average, about 860 euros each. It has around 60 staff and got 20 extra posts in 2025. Cybersecurity incidents go to a separate body, the National Security Authority.
The authority (Úrad na ochranu osobných údajov Slovenskej republiky) is led by chair Zuzana Valková. Tomáš Danč became deputy chair with effect from 24 October 2024. Its own 2025 annual report gives the numbers used above. It adds 10 procedural fines, 177 breach reports received (a 45% rise on the year before), 59 internal appeals lodged and 66 decided. Its 2025 budget was about 4.9 million euros. Its enforcement pattern is unusual: very high volume, very low value. A large share of the 2025 caseload came from a wave of anonymous mass complaints. Those said municipalities were publishing contracts in the Central Register of Contracts without blacking out enough personal data. The office must examine each one by law. It is also active in the European Data Protection Board and has joined the Board's 2026 coordinated enforcement action on transparency. We rate it an active regulator rather than aggressive. Fines are frequent and routine. But the office is small, the amounts are modest by European standards, and we found no large proactive investigations of major platforms. Other regulators. The National Security Authority (Národný bezpečnostný úrad) supervises cybersecurity under Act 69/2018 Coll. and can fine up to 10 million euros or 2% of turnover. The National Bank of Slovakia supervises financial firms. The Gambling Regulatory Authority supervises the gambling server rule. The Geodesy, Cartography and Cadastre Authority supervises the mapping deposit duties.
Sources
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyReport on the state of personal data protection for 2025 — the Slovak data protection authority's own annual report (sanctions, staffing, breach statistics)
dataprotection.gov.sk
“V roku 2025 úrad za porušenie právnych predpisov v oblasti ochrany osobných údajov právoplatne uložil 542 pokút v súhrnnej výške 468 000 Eur.”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyAnnual reports index of the Slovak data protection authority, showing the 2025 report published
dataprotection.gov.sk
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 69/2018 Z. z. o kybernetickej bezpečnosti — version in force from 30 April 2026, incident reporting and penalties
slov-lex.sk
“bez zbytočného odkladu, avšak najneskôr do 24 hodín od jeho zistenia sa hlási včasné [varovanie] ... bez zbytočného odkladu, avšak najneskôr do 72 hodín od jeho zistenia sa hlási oznámenie”
Link checked 18 August 2026
- Official sourceNárodný bezpečnostný úrad (National Security Authority)Cybersecurity — the National Security Authority's own cybersecurity pages
nbu.gov.sk
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is no single rule on how long you keep data. The general privacy rule is to delete data when you no longer need it. Against that sit long minimum keeping times. Accounts and financial statements: ten years. Entries in the national health registers: up to one hundred years after the person dies. Telecoms companies keep far less than most people assume. Slovakia scrapped blanket call-record keeping after its Constitutional Court struck it down. Operators now keep only what a court order covers.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
THE MAXIMUM. Article 5(1)(e) of the European General Data Protection Regulation applies directly. You may not keep personal data in a form that identifies someone for longer than you need it. Act 18/2018 Coll. adds no general Slovak maximum. The data protection authority has treated keeping camera recordings for longer than 72 hours as a point of concern. THE MINIMUM. Accounting: section 35 of Act 431/2002 Coll. covers financial statements, the annual report, accounting records, inventory lists and the chart of accounts. All must be kept for ten years following the year they relate to. Audit reports: ten years as well. Sustainability reporting: five years. Before a company is wound up it must tell the tax office who will hold its accounting papers. Health: the annexes to Act 153/2013 Coll. set keeping times for the national health registers. That is up to one hundred years after the death of the person. Contact-person data is kept for five years after that role ends. Gambling: section 14(22) of Act 30/2019 Coll. makes the Slovak server record all games, stakes, winnings, software changes and player-account movements. Mapping: aerial survey images must be kept in a state archive permanently. WHICH RULE WINS. Slovakia does what most European Union countries do. A specific legal duty to keep something is a legal duty under Article 6(1)(c) of the Regulation, and it beats a deletion request. But it wins only for the data and the period the law actually names. A ten-year accounting duty does not let you keep a whole customer record for ten years. TELECOMS. On 29 April 2015 the Constitutional Court, in PL. ÚS 10/2014 (published as no. 139/2015 Coll.), struck down the blanket keeping rules in the old Act 351/2011 Coll. It struck down the linked powers in the Criminal Procedure Code and the Police Act too. It found them incompatible with the Constitution, the Charter of Fundamental Rights and Freedoms and the European Convention. The replacement law, Act 452/2021 Coll., does not bring blanket keeping back. Its section 112(2) is much narrower. An operator keeps traffic, location and communicating-party data only where a court authorisation covers it. A later court authorisation or a court order under the Criminal Procedure Code also counts. There is a separate ordinary rule that traffic data may be kept until the time limit for challenging or enforcing an invoice runs out. Anyone still citing a six-month Slovak telecoms keeping period is quoting a law that was struck down eleven years ago.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 431/2002 Z. z. o účtovníctve, section 35 — ten-year retention of accounting records
slov-lex.sk
“účtovná závierka, výkazy vybraných údajov z účtovných závierok podľa § 17a a 22 a výročná správa počas desiatich rokov nasledujúcich po roku, ktorého sa týkajú”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 153/2013 Z. z. o národnom zdravotníckom informačnom systéme, Annex — retention periods for the national health registers
slov-lex.sk
“Doba uchovávania osobných údajov dotknutej osoby ... Sto rokov po smrti dotknutej osoby”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 452/2021 Z. z. o elektronických komunikáciách, sections 112 and 117 — targeted retention only under a court order
slov-lex.sk
“Podnik je na účely poskytovania údajov podľa § 117 ods. 6 povinný uchovávať prevádzkové údaje, lokalizačné údaje a údaje komunikujúcich strán, na ktoré sa vzťahuje súhlas súdu alebo dodatočný súhlas súdu podľa § 117 ods. 7 a 8 alebo príkaz súdu podľa Trestného poriadku.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRFinding of the Constitutional Court of the Slovak Republic, file PL. ÚS 10/2014 of 29 April 2015, published as no. 139/2015 Coll. — blanket telecoms data retention held unconstitutional
slov-lex.sk
“Ustanovenia § 58 ods. 5 až 7 a § 63 ods. 6 zákona č. 351/2011 Z. z. o elektronických komunikáciách v znení neskorších predpisov, § 116 zákona č. 301/2005 Z. z. Trestný poriadok v znení neskorších predpisov a § 76a ods. 3 zákona Národnej rady Slovenskej republiky č. 171/1993 Z. z. o Policajnom zbore v znení neskorších predpisov nie sú v súlade s ...”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyReport on the state of personal data protection for 2025 — the Slovak data protection authority's own annual report (sanctions, staffing, breach statistics)
dataprotection.gov.sk
“V roku 2025 úrad za porušenie právnych predpisov v oblasti ochrany osobných údajov právoplatne uložil 542 pokút v súhrnnej výške 468 000 Eur.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are two deadlines and they are different. A personal data breach goes to the privacy authority within 72 hours of you finding out. It also goes to the affected people quickly, if the risk to them is high. A cybersecurity incident at a regulated organisation goes to the National Security Authority twice. First a warning within 24 hours. Then a fuller report within 72 hours. If you are both, you file both, to two different bodies.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
DEADLINE ONE - privacy. Article 33 of the European General Data Protection Regulation covers this. Tell the supervisory authority as soon as you can, and within 72 hours of finding out where possible. You can skip this if the breach is unlikely to put people's rights at risk. Article 34: tell the affected people as soon as you can where the risk is high. The Slovak authority takes reports through its own form on the national portal. Its 2025 report complains that companies often bypass the form and file something too brief to assess. It received 177 reports in 2025. If you handle data for another company, tell that company as soon as you can. DEADLINE TWO - cybersecurity. Act 69/2018 Coll. brought in the NIS2 Directive through Act 366/2024 Coll., with effect from 1 January 2025, and was amended again in 2026. You must send an early warning as soon as you can and within 24 hours of detecting a significant incident. Then a fuller report as soon as you can and within 72 hours. You must also answer a request for information from the authority within 72 hours. Fines reach 10 million euros or 2% of worldwide turnover for essential organisations, and 7 million euros or 1.4% for important ones. WHERE PEOPLE GET CAUGHT OUT. The two sets of rules cover overlapping but different organisations, and they go to different regulators. The 24-hour cybersecurity warning falls a full day before the privacy deadline. A ransomware attack on a Slovak hospital or energy supplier triggers both. Financial firms have a third deadline under the Digital Operational Resilience Act. Build one incident process that starts the 24-hour clock by default. Then step down if it turns out you do not need it.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 69/2018 Z. z. o kybernetickej bezpečnosti — version in force from 30 April 2026, incident reporting and penalties
slov-lex.sk
“bez zbytočného odkladu, avšak najneskôr do 24 hodín od jeho zistenia sa hlási včasné [varovanie] ... bez zbytočného odkladu, avšak najneskôr do 72 hodín od jeho zistenia sa hlási oznámenie”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyReport on the state of personal data protection for 2025 — the Slovak data protection authority's own annual report (sanctions, staffing, breach statistics)
dataprotection.gov.sk
“V roku 2025 úrad za porušenie právnych predpisov v oblasti ochrany osobných údajov právoplatne uložil 542 pokút v súhrnnej výške 468 000 Eur.”
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 27, 44-49 and 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 69/2018 Coll. on cybersecurity — official version history showing the NIS2 transposition by Act 366/2024 Coll. effective 1 January 2025
slov-lex.sk
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things are not in the summary. Public bodies can be fined the full amount, with no discount. Mishandling personal data you got through your job is a crime, not just a fine. The age of consent for online services is 16, not 13. The rule on dead people's data changed today. And there is no European workaround for the gambling server rule.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
1. PUBLIC BODIES GET NO DISCOUNT. Many European Union countries cap or waive fines on public authorities. Slovakia does the opposite and says so in the text. Section 104(1)(a) of Act 18/2018 Coll. applies the ceiling of 10 million euros or 2% of turnover to public authorities and public-law institutions too. Section 104(1)(c) does the same for public bodies that handle data on behalf of someone else. Municipalities and state agencies are squarely covered. In 2025 they were the single largest source of complaints. 2. IT IS A CRIME. Section 374 of the Criminal Code (Act 300/2005 Coll.) makes one thing a crime. That is disclosing, sharing or publishing someone else's personal data in breach of a legal duty. It applies where you got the data through public authority, through the exercise of constitutional rights, or through your own profession, employment or office. The penalty is up to one year in prison. It rises to two years where it seriously harms the person's rights, is done publicly, or is done in a more serious manner. This attaches to individual employees, not just to the company. 3. AGE SIXTEEN. Section 15(1) of Act 18/2018 Coll. sets the age at which a child can agree to an online service at 16. Slovakia did not use the option to lower it to 13. Below 16, a legal representative must give or approve the consent. You must make reasonable efforts to check that, using the technology available. A product built for the United States age of 13 breaks Slovak law. 4. DEAD PEOPLE'S DATA CHANGED ON 18 AUGUST 2026. Until today, Act 18/2018 Coll. had an unusual Slovak rule. Where the person had died, a close relative could give the consent the law required. That consent was invalid if even one close relative objected in writing. Act 168/2026 Coll., in force from 18 August 2026, deletes that mechanism. It now leaves dead people out of the Act altogether. If your Slovak consent process relied on the relative-consent rule, it is now built on a rule that no longer exists. The same goes for genealogy, archive and funeral products. This change is one day old and the plain-language guidance has not caught up. 5. NO EUROPEAN WORKAROUND FOR THE GAMBLING SERVER. Slovakia says 'on the territory of the Slovak Republic', not 'in the European Economic Area'. An operator licensed elsewhere in the Union cannot serve Slovak players from a Dutch or Maltese data centre. The regulator must also be given free online access to that Slovak server. 6. ONE MORE - CONTRACT PUBLICATION. Slovak public bodies must publish their contracts in the Central Register of Contracts. So your commercial agreement with a Slovak ministry or municipality becomes public. Any personal data in it has to be blacked out first. The privacy authority is now receiving mass complaints about failures to do that.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 18/2018 Z. z. o ochrane osobných údajov — consolidated version in force from 18 August 2026 (as amended by Act 168/2026 Coll.), sections 3, 15, 48, 104
slov-lex.sk
“Tento zákon sa vzťahuje na spracúvanie osobných údajov v rámci činnosti prevádzkovateľa alebo sprostredkovateľa, ktorého sídlo, miesto podnikania, organizačná zložka, prevádzkareň alebo trvalý pobyt je na území Slovenskej republiky, a to bez ohľadu na to, či sa spracúvanie osobných údajov vykonáva na území Slovenskej republiky alebo mimo územia Slovenskej republiky”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 300/2005 Z. z. Trestný zákon, section 374 — unauthorised handling of personal data
slov-lex.sk
“Kto neoprávnene poskytne, sprístupní alebo zverejní ... osobné údaje o inom získané v súvislosti s výkonom svojho povolania, zamestnania alebo funkcie a tým poruší všeobecne záväzným právnym predpisom ustanovenú povinnosť, potrestá sa odňatím slobody až na jeden rok.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 30/2019 Z. z. o hazardných hrách, section 14(21) and 14(22) — version in force from 1 January 2026
slov-lex.sk
“Server je prevádzkovateľ hazardnej hry povinný umiestniť na území Slovenskej republiky.”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyReport on the state of personal data protection for 2025 — the Slovak data protection authority's own annual report (sanctions, staffing, breach statistics)
dataprotection.gov.sk
“V roku 2025 úrad za porušenie právnych predpisov v oblasti ochrany osobných údajov právoplatne uložil 542 pokút v súhrnnej výške 468 000 Eur.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 18/2018 Coll. — official version history, showing the amendment by Act 168/2026 Coll. taking effect on 18 August 2026
slov-lex.sk
Link checked 18 August 2026
What's changing next
The whole national privacy law is being replaced by two new laws. One is general. The other covers police and courts. Both are still bills and have no legal effect. Act 18/2018 was amended today, 18 August 2026, mostly to remove dead people from its scope. Public bodies face a bigger data-registration duty from 1 January 2027. And all cloud switching and data export fees across Europe must drop to zero by 12 January 2027.
ALREADY HAPPENED, TODAY. Act 168/2026 Coll. amended Act 18/2018 Coll. with effect from 18 August 2026. Dead people are removed from the Act's scope. The Ministry of Justice is added to the list of authorities that may handle data for law enforcement. A new rule covers passing on data received from a country outside Europe. It is linked to Act 167/2026 Coll. on international judicial cooperation in criminal matters. BILLS, NOT LAW. On 11 March 2025 the data protection authority announced it was replacing Act 18/2018 Coll. with two separate statutes. One would be general. One would cover police and justice work under Directive (EU) 2016/680. Both went to consultation between ministries as files LP/2025/305 and LP/2025/306, with comments due by 1 July 2025. There are three stated aims. End the two-track system that copies the directly applicable Regulation into national law. Cut the burden of impact assessments. Bring in codes of conduct and certification supervised by the authority. As at 18 August 2026 the authority's own national legislation page still lists only Act 18/2018 Coll. No replacement act appears in the collection of laws. A great deal of Slovak commentary from late 2025 and 2026 announces a 'new data protection act from 2026' as though it were settled. It is not. Treat it as a bill. DATED CHANGES. 1 January 2027: Act 95/2019 Coll., as amended by Act 67/2026 Coll., widens what public bodies must publish into the central metadata system. That now covers more than technical details of their systems. It also covers the registers they run, the data those registers hold, and the legal basis for using that data. It expressly says this must not reveal personal data, directly or indirectly. 12 January 2027: the European Data Act's firmest deadline. From then, all cloud switching charges and data export fees must be zero. 30 April 2026 has already passed. Act 67/2026 Coll. amended both the cybersecurity act and the public administration IT act on that date. POWERS THAT COULD CHANGE THINGS WITHOUT WARNING. First, the government cloud categories are set by ministry guidance, not by a law passed in parliament. The ministry can redefine what falls into category U4, the tier that must stay in Slovakia. It can do that by publishing a new document, without parliament and without consultation. Registrations lapse every two years, so a change would take effect within one renewal cycle. Second, the gambling regulator's power to demand free online access to the operator's Slovak server is open-ended. The Ministry of Finance sets its scope by decree. Third, the cybersecurity authority's powers under Act 69/2018 Coll. include ordering blocking measures. Fourth, the two replacement privacy bills could be brought back and passed quickly. The drafts already exist and the responsible regulator wrote them.
Sources
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyInterministerial consultation on the two new data protection bills (files LP/2025/305 and LP/2025/306), comment deadline 1 July 2025
dataprotection.gov.sk
“Úrad na ochranu osobných údajov Slovenskej republiky predložil do medzirezortného pripomienkového konania (MPK): návrh zákona o zabezpečení ochrany fyzických osôb pri spracúvaní osobných údajov ... Termín na pripomienkovanie je 1.7.2025.”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyForthcoming new data protection legislation — announcement by the Slovak data protection authority, 11 March 2025
dataprotection.gov.sk
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyNational legislation — the Slovak data protection authority's own list of the laws in force, still naming Act 18/2018 Coll. as the national data protection law
dataprotection.gov.sk
“Na úrovni Slovenskej republiky je ochrana osobných údajov fyzických osôb upravená: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 18/2018 Coll. — official version history, showing the amendment by Act 168/2026 Coll. taking effect on 18 August 2026
slov-lex.sk
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 95/2019 Coll. — version taking effect on 1 January 2027 (amended by Act 67/2026 Coll.), expanded central metadata register duties
slov-lex.sk
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 (Data Act), Chapters VI and VII
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Diarise 1 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries7 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Online gaming data must stay in the country
Official name: Zákon č. 30/2019 Z. z. o hazardných hrách a o zmene a doplnení niektorých zákonov, § 14 ods. 21 a 22 · Act No. 30/2019 Coll., section 14(21) and 14(22) · Act of parliament
If you run online or terminal gambling, your server must be inside Slovakia. You must also give the regulator free online access to it. There is no way around this by using another European country.
Enforced by Gambling Regulatory Authority
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryYour server must be physically located on Slovak territory. Anywhere else in the European Economic Area does not count.
- Keep logsThe server must record every game played, all stakes and all winnings. It must record every change to the game data or software, and every fault. For online games it must record every movement in a player's account.
- Register or notifyYou must give the gambling regulator free online access to that server. The Ministry of Finance sets how much access by decree.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions under the Gambling Act
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 30/2019 Z. z. o hazardných hrách, section 14(21) and 14(22) — version in force from 1 January 2026
slov-lex.sk
“Server je prevádzkovateľ hazardnej hry povinný umiestniť na území Slovenskej republiky.”
Link checked 18 August 2026
Government data must stay in the country
Official name: Metodické usmernenie č. 020775/2025/oSBATA z 11. 4. 2025 pre proces zaradenia cloudovej služby do katalógu vládnych cloudových služieb, vydané podľa § 24a zákona č. 95/2019 Z. z. · Binding methodological guidance no. 020775/2025/oSBATA, issued under section 24a of Act No. 95/2019 Coll. · Government rules
Slovak public bodies handling the top security tier of data have one option. They must use a cloud service that keeps that data inside Slovakia. The data centre must be within reach of the Slovak state. Lower tiers have no location rule. They must still disclose every data centre location.
Enforced by Ministry of Investments, Regional Development and Informatisation
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryCategory U4 'special data' must be stored and used on Slovak territory. It must sit in a data centre within reach of Slovak state authorities, in the private part of the government cloud.
- Register or notifyThe cloud service must be entered in the government cloud catalogue. Entry lasts two years and is deleted automatically if not renewed in time.
- Independent auditCategories U3 and U4 must be checked by a certified cybersecurity auditor under Act 69/2018 Coll.
- Hold a security certificateThe provider must list every data centre where the data is stored. This is flagged as important where personal data would sit outside the European Union.
- Prove the data stays under local controlOnly the Ministry of the Interior, using the Interior and Finance Ministry data centres, may supply the private infrastructure and platform layers.
Sources
- Official sourceMinisterstvo investícií, regionálneho rozvoja a informatizácie Slovenskej republiky (Ministry of Investments, Regional Development and Informatisation)Binding methodological guidance no. 020775/2025/oSBATA of 11 April 2025 on entering a cloud service in the government cloud catalogue (effective 15 April 2025), category U4
mirri.gov.sk
“Kategória U4: Špeciálne dáta (Kritická úroveň zabezpečenia) ... dáta úrovne C3I3A3, ktoré však vyžadujú uchovávanie a spracovávanie dát na území SR a v dátovom centre, ktoré je v dosahu štátnych orgánov SR, v privátnej časti vládneho cloudu.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 95/2019 Z. z. o informačných technológiách vo verejnej správe, section 24a (government cloud) — version in force from 30 April 2026
slov-lex.sk
“Štandardy podľa § 24 ods. 1 písm. f) ustanovia úrovne cloudových služieb ... pri ktorých dosiahnutí môže orgán riadenia ... odoberať a využívať len cloudové služby, ktoré sú vládnymi cloudovými službami.”
Link checked 18 August 2026
- Official sourceMinisterstvo investícií, regionálneho rozvoja a informatizácie Slovenskej republikyCatalogue of government cloud services
mirri.gov.sk
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Zákon č. 95/2019 Z. z. o informačných technológiách vo verejnej správe, § 24a Vládny cloud · Act No. 95/2019 Coll., section 24a, as amended by Act No. 67/2026 Coll. · Act of parliament
The law behind the government cloud. Most of it is already in force. More data-registration duties for public bodies start on 1 January 2027. So parts of the current text do not apply yet.
Enforced by Ministry of Investments, Regional Development and Informatisation
How this country controls where data goes: Only approved countries
What you have to do
- Register or notifyA public body deciding on people's rights and duties may only use a service listed in the government cloud catalogue. It must meet the service levels the standards set.
- Keep records of how you use data — 2 years, from 1 January 2027From 1 January 2027 public bodies must publish more. That means the registers they run, the data those registers hold, and the legal basis for using that data. They must not reveal personal data, directly or indirectly.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 95/2019 Z. z. o informačných technológiách vo verejnej správe, section 24a (government cloud) — version in force from 30 April 2026
slov-lex.sk
“Štandardy podľa § 24 ods. 1 písm. f) ustanovia úrovne cloudových služieb ... pri ktorých dosiahnutí môže orgán riadenia ... odoberať a využívať len cloudové služby, ktoré sú vládnymi cloudovými službami.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 95/2019 Coll. — version taking effect on 1 January 2027 (amended by Act 67/2026 Coll.), expanded central metadata register duties
slov-lex.sk
Link checked 18 August 2026
Mapping and location data needs a copy kept in the country
Official name: Zákon Národnej rady Slovenskej republiky č. 215/1995 Z. z. o geodézii a kartografii · Act No. 215/1995 Coll., section 8 · Act of parliament
If you fly a survey over Slovakia or publish a map of it, you must give a copy to Slovak state archives. One of those archives is run by the Ministry of Defence. You keep your own copy and may take it abroad. So this is a copy duty, not a ban on exporting. The fines are small.
Enforced by Geodesy, Cartography and Cadastre Authority of the Slovak Republic
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep the data in the countryIf you acquire original aerial remote-sensing material or aerial survey photographs, report it within 30 days. After you have used it, hand it over free of charge to a special archive run by the Ministry of Defence.
- Keep data for a minimum periodIf you publish maps, give the mapping authority's archive two paper copies and one digital copy within 30 days. Give one more copy to the Ministry of Defence archive.
What it costs if you get it wrong
- Fixed maximum fine: €3,300 for a legal person; €330 for an individual — about $4 thousandFailing to report or deposit aerial survey imagery or published cartographic works
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon Národnej rady SR č. 215/1995 Z. z. o geodézii a kartografii, section 8 (duties on aerial survey imagery and published cartographic works) and sections 30-31 (penalties)
slov-lex.sk
“oznamovať nadobudnutie prvotných materiálov leteckého diaľkového prieskumu Zeme a leteckých meračských snímok do 30 dní od ich nadobudnutia a po využití ich bezplatne odovzdať na archívne účely osobitnému archívu zriadenému Ministerstvom obrany Slovenskej republiky”
Link checked 18 August 2026
Telecoms rules
Official name: Zákon č. 452/2021 Z. z. o elektronických komunikáciách, § 112 a § 117, v nadväznosti na nález Ústavného súdu SR sp. zn. PL. ÚS 10/2014 (139/2015 Z. z.) · Act No. 452/2021 Coll., sections 112 and 117; Constitutional Court finding PL. ÚS 10/2014 of 29 April 2015, published as No. 139/2015 Coll. · Act of parliament
Slovakia does not make telecoms companies keep everyone's records. The Constitutional Court struck the old blanket rules down in 2015. The 2021 replacement law only requires keeping what a court order actually covers. Sources still reporting a six-month Slovak keeping period are quoting a repealed law.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum periodTargeted only. An operator must keep traffic, location and communicating-party data solely where a court authorisation or a court order under the Criminal Procedure Code covers it.
- Delete data after a periodOtherwise traffic data must be erased or made anonymous once it is no longer needed. You may keep it until the time limit for challenging or enforcing an invoice runs out.
- Secure the dataData you keep must meet the same quality and security standard as live data. Destroy it at the end of the keeping period.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 452/2021 Z. z. o elektronických komunikáciách, sections 112 and 117 — targeted retention only under a court order
slov-lex.sk
“Podnik je na účely poskytovania údajov podľa § 117 ods. 6 povinný uchovávať prevádzkové údaje, lokalizačné údaje a údaje komunikujúcich strán, na ktoré sa vzťahuje súhlas súdu alebo dodatočný súhlas súdu podľa § 117 ods. 7 a 8 alebo príkaz súdu podľa Trestného poriadku.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRFinding of the Constitutional Court of the Slovak Republic, file PL. ÚS 10/2014 of 29 April 2015, published as no. 139/2015 Coll. — blanket telecoms data retention held unconstitutional
slov-lex.sk
“Ustanovenia § 58 ods. 5 až 7 a § 63 ods. 6 zákona č. 351/2011 Z. z. o elektronických komunikáciách v znení neskorších predpisov, § 116 zákona č. 301/2005 Z. z. Trestný poriadok v znení neskorších predpisov a § 76a ods. 3 zákona Národnej rady Slovenskej republiky č. 171/1993 Z. z. o Policajnom zbore v znení neskorších predpisov nie sú v súlade s ...”
Link checked 18 August 2026
Cloud and outsourcing rules (Finance)
Official name: Stanoviská Národnej banky Slovenska ku cloud computingu a k outsourcingu (poisťovníctvo), v nadväznosti na § 30 ods. 3 zákona o poisťovníctve a usmernenia EBA/EIOPA · National Bank of Slovakia supervisory positions on cloud computing and on outsourcing by insurance undertakings · Regulator guideline
Slovak financial rules say nothing about where data must be stored. For cloud outsourcing the central bank requires contracts, monitoring and audit rights. Insurers must give advance notice for critical functions. Neither rule tells firms where to keep data.
Enforced by National Bank of Slovakia
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Written vendor contractYou need contracts, monitoring and audit rights, as set out in the European Banking Authority outsourcing recommendations. The Digital Operational Resilience Act also makes you name in the contract where the data is handled, with audit rights and an exit plan.
- Register or notifyInsurers must tell the central bank in advance before they outsource a critical or important operational function.
Sources
- Official sourceNárodná banka Slovenska (National Bank of Slovakia)Cloud computing — the Slovak central bank's own guidance page for supervised financial institutions
nbs.sk
“For any use of core banking services in the 'public cloud', an institution is not relieved from its responsibilities with respect to confidentiality, integrity and availability of data.”
Link checked 18 August 2026
- Official sourceNárodná banka Slovenska (National Bank of Slovakia)Outsourcing — the Slovak central bank's own position for insurance undertakings
nbs.sk
“Povinnosť poisťovne oznamovať Národnej banke Slovenska zámer zveriť výkon funkcií alebo činností inej osobe sa v súlade s § 30 ods. 3 zákona o poisťovníctve vzťahuje len na výkon kritických alebo dôležitých operačných funkcií”
Link checked 18 August 2026
Health data rules
Official name: Zákon č. 153/2013 Z. z. o národnom zdravotníckom informačnom systéme a o zmene a doplnení niektorých zákonov · Act No. 153/2013 Coll., annexes on the national health registers · Act of parliament
Slovakia's health information law says nothing about where health data must be stored. But it sets extraordinarily long minimum keeping times. Entries in the national health registers are kept up to one hundred years after the person dies.
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Keep data for a minimum periodEntries in several national health registers are kept for one hundred years after the death of the person concerned. Contact-person data is kept for five years after that role ends.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 153/2013 Z. z. o národnom zdravotníckom informačnom systéme, Annex — retention periods for the national health registers
slov-lex.sk
“Doba uchovávania osobných údajov dotknutej osoby ... Sto rokov po smrti dotknutej osoby”
Link checked 18 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law (2018)
Official name: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov · Act No. 18/2018 Coll., as last amended by Act No. 168/2026 Coll. · Act of parliament
Slovakia's national privacy law. It does not require data to be kept in Slovakia. It says so directly: it applies whether you use the data inside or outside the country. It sets the age for online consent at 16. It applies the full European maximum fines to public bodies too.
Enforced by Office for Personal Data Protection of the Slovak Republic
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest
What you have to do
- Appoint a data protection officerIf you appoint a data protection officer, you must tell the authority, using its own form.
- Get a parent's consent for children — applies at: 16 years — section 15(1); the controller must make reasonable efforts to verify the parent's consent
- Put a transfer safeguard in place
- Keep records of how you use data
- Assess high-risk projects
What it costs if you get it wrong
- Percentage of global turnover: €20,000,000 or 4% of total worldwide annual turnover, whichever is higher — about $22 millionBreach of the basic principles, individual rights, transfer rules, or a regulator order — section 104(2)
- Percentage of global turnover: €10,000,000 or 2% of total worldwide annual turnover, whichever is higher — about $11 millionController and processor obligations — section 104(1), which expressly includes public authorities and public-law institutions
- Fixed maximum fine: €2,000 — about $2 thousandProcedural fine for obstructing an inspection — section 105
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 18/2018 Z. z. o ochrane osobných údajov — consolidated version in force from 18 August 2026 (as amended by Act 168/2026 Coll.), sections 3, 15, 48, 104
slov-lex.sk
“Tento zákon sa vzťahuje na spracúvanie osobných údajov v rámci činnosti prevádzkovateľa alebo sprostredkovateľa, ktorého sídlo, miesto podnikania, organizačná zložka, prevádzkareň alebo trvalý pobyt je na území Slovenskej republiky, a to bez ohľadu na to, či sa spracúvanie osobných údajov vykonáva na území Slovenskej republiky alebo mimo územia Slovenskej republiky”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyNational legislation — the Slovak data protection authority's own list of the laws in force, still naming Act 18/2018 Coll. as the national data protection law
dataprotection.gov.sk
“Na úrovni Slovenskej republiky je ochrana osobných údajov fyzických osôb upravená: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 18/2018 Coll. — official version history, showing the amendment by Act 168/2026 Coll. taking effect on 18 August 2026
slov-lex.sk
Link checked 18 August 2026
General data protection law (Legislative process files LP/2025/305 and LP/2025/306)
Official name: Návrh zákona o zabezpečení ochrany fyzických osôb pri spracúvaní osobných údajov (LP/2025/305) a návrh zákona o ochrane fyzických osôb pri spracúvaní osobných údajov príslušnými orgánmi (LP/2025/306) · Legislative process files LP/2025/305 and LP/2025/306 · Draft law
Two draft laws would split the current privacy act in two. One would be general. One would cover police and justice. They are bills only. As at 18 August 2026 the regulator's own legislation page still lists only the 2018 act. Do not plan around them as binding.
Enforced by Office for Personal Data Protection of the Slovak Republic
Sources
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyInterministerial consultation on the two new data protection bills (files LP/2025/305 and LP/2025/306), comment deadline 1 July 2025
dataprotection.gov.sk
“Úrad na ochranu osobných údajov Slovenskej republiky predložil do medzirezortného pripomienkového konania (MPK): návrh zákona o zabezpečení ochrany fyzických osôb pri spracúvaní osobných údajov ... Termín na pripomienkovanie je 1.7.2025.”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyForthcoming new data protection legislation — announcement by the Slovak data protection authority, 11 March 2025
dataprotection.gov.sk
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyNational legislation — the Slovak data protection authority's own list of the laws in force, still naming Act 18/2018 Coll. as the national data protection law
dataprotection.gov.sk
“Na úrovni Slovenskej republiky je ochrana osobných údajov fyzických osôb upravená: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov”
Link checked 18 August 2026
Cyber security rules
Official name: Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplnení niektorých zákonov · Act No. 69/2018 Coll., transposing Directive (EU) 2022/2555 (NIS2) by Act No. 366/2024 Coll., further amended by Acts 318/2025 and 67/2026 Coll. · Act of parliament
Slovakia's cybersecurity law. It brought in the European NIS2 rules from 1 January 2025. It says nothing about where data must be stored. But it adds a second incident deadline: 24 hours for a first warning, then 72 hours for the fuller report. That goes to a different regulator from the privacy one.
Enforced by National Security Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 24 hoursSend an early warning of a significant incident as soon as you can, and within 24 hours of detecting it.
- Report cyber incidents — within 72 hoursSend the fuller report as soon as you can, and within 72 hours of detecting it.
- Secure the data
- Independent auditCertified cybersecurity auditors check that you comply. The same audit is what unlocks government cloud categories U3 and U4.
- Register or notifyEssential and important organisations must register with the National Security Authority.
What it costs if you get it wrong
- Percentage of global turnover: €500 to €10,000,000 or up to 2% of total turnover — about $11 millionEssential entity failing cybersecurity duties
- Percentage of global turnover: €300 to €7,000,000 or up to 1.4% of total turnover — about $8 millionImportant entity failing cybersecurity duties
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 69/2018 Z. z. o kybernetickej bezpečnosti — version in force from 30 April 2026, incident reporting and penalties
slov-lex.sk
“bez zbytočného odkladu, avšak najneskôr do 24 hodín od jeho zistenia sa hlási včasné [varovanie] ... bez zbytočného odkladu, avšak najneskôr do 72 hodín od jeho zistenia sa hlási oznámenie”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 69/2018 Coll. on cybersecurity — official version history showing the NIS2 transposition by Act 366/2024 Coll. effective 1 January 2025
slov-lex.sk
Link checked 18 August 2026
- Official sourceNárodný bezpečnostný úrad (National Security Authority)Cybersecurity — the National Security Authority's own cybersecurity pages
nbu.gov.sk
Link checked 18 August 2026
General data protection law (2006)
Official name: Zákon č. 300/2005 Z. z. Trestný zákon, § 374 Neoprávnené nakladanie s osobnými údajmi · Act No. 300/2005 Coll. (Criminal Code), section 374 · Act of parliament
Leaking personal data you got through your job is a crime in Slovakia. The penalty is up to one year in prison, and up to two years in more serious cases. The person who did it is punished, not only the company.
What you have to do
- Secure the dataThis applies to the person who leaks the data, not only to the employer.
What it costs if you get it wrong
- Criminal liability: Imprisonment up to 1 year; up to 2 years where it causes serious harm to the person's rights, is done publicly, or in a more serious mannerUnlawfully disclosing, making available or publishing personal data obtained through public authority, the exercise of constitutional rights, or one's own profession, employment or office
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 300/2005 Z. z. Trestný zákon, section 374 — unauthorised handling of personal data
slov-lex.sk
“Kto neoprávnene poskytne, sprístupní alebo zverejní ... osobné údaje o inom získané v súvislosti s výkonom svojho povolania, zamestnania alebo funkcie a tým poruší všeobecne záväzným právnym predpisom ustanovenú povinnosť, potrestá sa odňatím slobody až na jeden rok.”
Link checked 18 August 2026
Record-keeping rules for tax and accounts
Official name: Zákon č. 431/2002 Z. z. o účtovníctve, § 35 Uchovávanie a ochrana účtovnej dokumentácie · Act No. 431/2002 Coll., section 35 · Act of parliament
Accounting records must be kept for ten years after the year they relate to. No rule says they must be kept in Slovakia. Storing them electronically on a data carrier is expressly allowed.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 10 yearsFinancial statements, the annual report, accounting records, inventory lists and the chart of accounts: ten years following the year they relate to. Sustainability and income-tax reports: five years.
- Keep records of how you use dataBefore a company is wound up it must tell the tax office who will hold its accounting documentation.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 431/2002 Z. z. o účtovníctve, section 35 — ten-year retention of accounting records
slov-lex.sk
“účtovná závierka, výkazy vybraných údajov z účtovných závierok podľa § 17a a 22 a výročná správa počas desiatich rokov nasledujúcich po roku, ktorého sa týkajú”
Link checked 18 August 2026
Applies across the European Union3 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Nariadenie Európskeho parlamentu a Rady (EÚ) 2016/679 (všeobecné nariadenie o ochrane údajov) · Regulation (EU) 2016/679 · Directly binding regulation
The European rules that cover almost all personal data in Slovakia. They do not require data to stay in Europe. They set the conditions for sending data out.
Enforced by European Data Protection Board
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of how you use data
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a representativeYou need this if you have no office in the European Union.
- Put a transfer safeguard in placeYou must also write down a risk check on the destination country, following the Schrems II judgment.
- Do not hand data to foreign authorities on demandAn order from a foreign authority is not on its own a legal reason to hand data over. See European Data Protection Board Guidelines 02/2024.
- Delete data after a period
- Get a parent's consent for children — applies at: 16 in Slovakia — Slovakia did not lower the age below the default
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $11 millionController and processor obligations
- Order to stopThe regulator can order processing to stop or suspend flows to a third country
- Claims by individualsIndividuals can claim compensation
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 27, 44-49 and 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the Commission's own list of countries found to provide adequate protection
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionCommission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyNational legislation — the Slovak data protection authority's own list of the laws in force, still naming Act 18/2018 Coll. as the national data protection law
dataprotection.gov.sk
“Na úrovni Slovenskej republiky je ochrana osobných údajov fyzických osôb upravená: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov”
Link checked 18 August 2026
General data protection law
Official name: Nariadenie (EÚ) 2018/1807 o rámci pre voľný tok neosobných údajov v Európskej únii · Regulation (EU) 2018/1807 · Directly binding regulation
Slovakia may not force non-personal data to be stored inside the country. The only exception is where public security truly requires it. Any Slovak demand for local storage has to meet that test.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union, Article 4
eur-lex.europa.eu
Link checked 18 August 2026
Cloud and outsourcing rules (2027)
Official name: Nariadenie (EÚ) 2023/2854 o harmonizovaných pravidlách týkajúcich sa spravodlivého prístupu k údajom a ich používania (akt o údajoch) · Regulation (EU) 2023/2854 (Data Act) · Directly binding regulation
The European Data Act has applied since 12 September 2025. It gives customers the right to switch cloud providers. Its firmest deadline is 12 January 2027. From then, all switching charges and data export fees must be zero.
That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Make switching cloud provider possible — from 12 January 2027All cloud switching charges and data egress fees must be zero from 12 January 2027.
- Do not hand data to foreign authorities on demandChapter seven limits foreign government access to non-personal data held in the European Union.
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 (Data Act), Chapters VI and VII
eur-lex.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the two replacement data protection bills (LP/2025/305 and LP/2025/306) have not been submitted to or passed by the National Council.
We could not confirm how far the two replacement bills have got in parliament. The regulator's own legislation page still listed Act 18/2018 Coll. as the law in force on 18 August 2026, and no replacement act appears in the collection of laws. We could not check the parliamentary record itself. Treat the 2018 act as the law and watch for a new one.
That no localisation rule exists for banking, payments, insurance or securities data in Slovakia.
We found no rule about where financial data must be stored. The central bank's own cloud computing and insurance outsourcing pages set no location rule. But we did not read the full text of the Banking Act (483/2001 Coll.), the Payment Services Act (492/2009 Coll.) or the Securities Act (566/2001 Coll.). We did not examine the banking secrecy rules. If you are a bank, payment firm or broker, check those before you rely on this. Checked 18 August 2026.
That Slovak health law imposes no storage-location rule on private healthcare providers.
We found no rule that health data must stay in Slovakia. We searched the National Health Information System Act (153/2013 Coll.) and found no territorial storage rule. But we did not read the Healthcare Act (576/2004 Coll.) in full, and that law covers medical records held by individual providers. If you handle patient records, check it before you rely on this. Checked 18 August 2026.
How often, if ever, the gambling server-location rule and the aerial imagery deposit duty are actually enforced.
We could not confirm whether these two rules are enforced. The wording in the law is clear. But we found no published enforcement decisions from the Gambling Regulatory Authority or the Geodesy, Cartography and Cadastre Authority. A rule that is never enforced carries a different risk from one that is policed. Assume it applies to you and plan for it.
The precise content of Act 67/2026 Coll., which amended both the cybersecurity act and the public administration information technology act with effect from 30 April 2026 and again from 1 January 2027.
We could not confirm why this amendment was made or whether more changes follow. We did confirm the amendment and its start dates from the official version history, and we read the combined texts. We also identified the 2027 changes to the central metadata duties. We did not get the explanatory memorandum that would set out the reasoning.
Whether the defence and classified information regime (Act 215/2004 Coll.) imposes additional storage-location duties.
We did not research classified information. If your data is classified under Slovak law, this record does not cover it. Get specific advice before you rely on anything here.
The average and maximum size of individual fines issued by the Slovak data protection authority in 2025.
We could not confirm the size of the largest fine. The annual report gives only the total: 542 fines worth about 468,000 euros. It gives no breakdown by decision, and full decisions are not published. The average of roughly 860 euros is our own arithmetic, not a figure the authority states.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.