Skip to the content
Global Data RulesData governance rules, country by country

Slovakia

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

Slovakia has no general rule that data must stay in the country. It runs on the European rulebook: send data abroad once you have the right paperwork. Three areas break that rule. Online gambling servers must sit on Slovak soil. The most sensitive government data must stay in a Slovak data centre. And anyone who takes aerial survey pictures of Slovakia must hand a copy to a defence ministry archive.

Eight questions about Slovakia

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Slovakia's rules apply to my company?

Yes. A company with no office in Slovakia is still caught if it offers goods or services to people in Slovakia, or watches what they do online. There is no minimum size, headcount or revenue below which you are safe. If you have no office anywhere in the European Union, you must name a written representative inside the Union, and you can put that person in any member state where your customers are — it does not have to be Slovakia.

High confidenceNational rulesBloc rulesAppoint a local representative

Can I store my users' data outside Slovakia?

In general, yes — with the standard European paperwork. Nothing in Slovak law says personal data must be kept in Slovakia, and the law says so almost in as many words: it applies to a Slovak company whether it processes data inside or outside the country. But three specific activities do force data to stay. Online gambling operators must put their server in Slovakia. The top security tier of government data must stay in a Slovak data centre. And aerial survey imagery of Slovakia must be handed to a state archive.

High confidenceDepends on your industryNo — it stays putA copy must stayYes, with paperwork

What do I need in place before data leaves Slovakia?

Slovakia uses the European model, and it is an allowlist. Data may go to a country the European Commission has approved, or to anywhere else if you sign the Commission's standard contract, use approved group-wide rules, or fit one of a few narrow exceptions. The approved list is real and populated — it includes the United Kingdom, Switzerland, Japan, South Korea, Canada for commercial bodies, and the United States only for companies signed up to the transatlantic framework. Slovakia adds nothing of its own on top.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentNeeded for a contractLegal claims

Who enforces the rules in Slovakia, and what can they do?

The Office for Personal Data Protection of the Slovak Republic. It is real, staffed and busy. In 2025 it issued 542 final fines totalling about 468,000 euros (roughly $510,000) and actually collected about 411,000 euros of that — a very high number of fines but a very small average, about 860 euros each. It has around 60 staff and got 20 extra posts in 2025. Cybersecurity incidents go to a separate body, the National Security Authority.

High confidenceActiveRegulator

How long do I have to keep the data?

There is no single retention rule. The general privacy rule is to delete when you no longer need the data. Against that sit long minimum-keeping duties: ten years for accounts and financial statements, and up to one hundred years after death for entries in the national health registers. Telecom companies keep far less than most people assume — Slovakia scrapped blanket call-record retention after its Constitutional Court struck it down, so operators only retain what a court order covers.

High confidenceKeep data for a minimum periodDelete data after a periodRepealed

What happens if there is a breach?

There are two clocks and they are different. A personal data breach goes to the privacy authority within 72 hours of you becoming aware of it, and to the affected people without undue delay if the risk to them is high. A cybersecurity incident at a regulated organisation goes to the National Security Authority twice: a first warning within 24 hours, then a fuller report within 72 hours. If you are both, you file both, to two different bodies.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Slovakia?

Five things that are not in the summary. Public bodies can be fined the full amount, with no discount. Mishandling personal data you got through your job is a crime, not just a fine. The age of consent for online services is 16, not 13. The rule on dead people's data changed today. And the gambling server rule has no European workaround.

High confidenceCriminal liabilityGet a parent's consent for childrenNo — it stays put

What is changing soon in Slovakia?

The whole national privacy law is being replaced by two new laws — one general, one for police and courts — but they are still bills and have no legal effect. Act 18/2018 was amended today, 18 August 2026, mostly to remove dead people from its scope. Public bodies face a bigger data-registration duty from 1 January 2027, and all cloud switching and data export fees across Europe must drop to zero by 12 January 2027.

High confidenceProposedPartly in forceDraft law

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    3 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    5 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    7 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules3 rules

Nariadenie Európskeho parlamentu a Rady (EÚ) 2016/679 (všeobecné nariadenie o ochrane údajov)

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European baseline that governs almost all personal data in Slovakia. It does not require data to stay in Europe; it sets the conditions under which data may leave.

In force since 25 May 2018

Enforced by European Data Protection Board

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Nariadenie (EÚ) 2018/1807 o rámci pre voľný tok neosobných údajov v Európskej únii

Directly binding regulation · Regulation (EU) 2018/1807

In forceYes — store it anywhere

Slovakia is forbidden from forcing non-personal data to be stored on its territory, except where public security genuinely requires it. This is the rule any Slovak localisation demand has to justify itself against.

In force since 28 May 2019

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Nariadenie (EÚ) 2023/2854 o harmonizovaných pravidlách týkajúcich sa spravodlivého prístupu k údajom a ich používania (akt o údajoch)

Directly binding regulation · Regulation (EU) 2023/2854 (Data Act)

Partly in forceYes — store it anywhere

The European Data Act has applied since 12 September 2025 and gives customers a right to switch cloud providers. Its hardest deadline is 12 January 2027, when all switching charges and data export fees must fall to zero.

In force since 12 September 2025But only enforceable from 12 January 2027

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

National rules5 rules

Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov

Act of parliament · Act No. 18/2018 Coll., as last amended by Act No. 168/2026 Coll.

In forceYes — store it anywhere

Slovakia's national privacy law. It contains no requirement to keep data in Slovakia and expressly applies whether processing happens inside or outside the country. It sets the age of online consent at 16 and applies the full European fine ceilings to public bodies.

In force since 25 May 2018

Enforced by Office for Personal Data Protection of the Slovak Republic

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

High confidence

Návrh zákona o zabezpečení ochrany fyzických osôb pri spracúvaní osobných údajov (LP/2025/305) a návrh zákona o ochrane fyzických osôb pri spracúvaní osobných údajov príslušnými orgánmi (LP/2025/306)

Draft law · Legislative process files LP/2025/305 and LP/2025/306

ProposedNot yet established

Two draft laws that would split the current privacy act into a general law and a separate police-and-justice law. They are bills only: as at 18 August 2026 the regulator's own legislation page still lists only the 2018 act. Do not plan around them as binding.

Enforced by Office for Personal Data Protection of the Slovak Republic

High confidence

Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplnení niektorých zákonov

Act of parliament · Act No. 69/2018 Coll., transposing Directive (EU) 2022/2555 (NIS2) by Act No. 366/2024 Coll., further amended by Acts 318/2025 and 67/2026 Coll.

In forceYes — store it anywhere

Slovakia's cybersecurity law, which transposed the European NIS2 rules from 1 January 2025. It imposes no storage-location rule, but it adds a second incident clock: 24 hours for a first warning, 72 hours for the fuller report, to a different regulator from the privacy one.

In force since 1 April 2018But only enforceable from 1 January 2025

Enforced by National Security Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules7 rules

Zákon č. 30/2019 Z. z. o hazardných hrách a o zmene a doplnení niektorých zákonov, § 14 ods. 21 a 22

Act of parliament · Act No. 30/2019 Coll., section 14(21) and 14(22) · Online gaming

In forceNo — it stays put

An online or terminal-based gambling operator must place its server inside Slovakia and give the regulator free online access to it. This is a genuine hard wall with no European workaround.

In force since 1 March 2019

Enforced by Gambling Regulatory Authority

Transfer model: Not allowed

High confidence

Metodické usmernenie č. 020775/2025/oSBATA z 11. 4. 2025 pre proces zaradenia cloudovej služby do katalógu vládnych cloudových služieb, vydané podľa § 24a zákona č. 95/2019 Z. z.

Government rules · Binding methodological guidance no. 020775/2025/oSBATA, issued under section 24a of Act No. 95/2019 Coll. · Government

In forceNo — it stays put

Slovak public bodies handling the top security tier of data may only use a cloud service that keeps that data inside Slovakia, in a state-reachable data centre. Lower tiers have no location rule but must disclose every data-centre location.

In force since 15 April 2025

Enforced by Ministry of Investments, Regional Development and Informatisation

Transfer model: Not allowed

High confidence

Zákon č. 95/2019 Z. z. o informačných technológiách vo verejnej správe, § 24a Vládny cloud

Act of parliament · Act No. 95/2019 Coll., section 24a, as amended by Act No. 67/2026 Coll. · Government

Partly in forceYes, with paperwork

The statute behind the government cloud. Most of it is already in force; a further tranche of data-registration duties on public bodies starts on 1 January 2027, so parts of the current text are not yet operative.

In force since 1 May 2019But only enforceable from 30 April 2026

Enforced by Ministry of Investments, Regional Development and Informatisation

Transfer model: Allowlist

High confidence

Who you would hear from

  • Úrad na ochranu osobných údajov Slovenskej republiky

    General data protection supervision under the General Data Protection Regulation and Act 18/2018 Coll.

    Fully operational. Chair Zuzana Valková; deputy chair Tomáš Danč from 24 October 2024. Around 60 staff, with 20 additional posts granted in 2025 and a 2025 budget of about 4.9 million euros. In 2025 it issued 542 final fines totalling about 468,000 euros, collected about 411,000 euros, imposed 10 procedural fines and received 177 breach notifications. It is actively recruiting: four internal vacancy notices were published in August 2026 alone.

  • Národný bezpečnostný úrad

    Cybersecurity supervision under Act 69/2018 Coll., incident reporting, cybersecurity auditor certification

    Operational. It runs the national cybersecurity incident reporting scheme and certifies the auditors whose sign-off is required for the higher government cloud categories.

  • Ministerstvo investícií, regionálneho rozvoja a informatizácie Slovenskej republiky

    Government cloud catalogue and public administration information technology standards under Act 95/2019 Coll.

    Operational. It maintains the government cloud catalogue and issued the binding methodological guidance of 11 April 2025 that creates the category U4 localisation requirement.

  • Národná banka Slovenska

    Supervision of banks, payment institutions, insurers and securities firms, including outsourcing and cloud arrangements

    Operational. It publishes its own cloud computing and outsourcing positions and issues methodological guidance in its official bulletin.

  • Úrad pre reguláciu hazardných hier

    Licensing and supervision of gambling operators, including the requirement that the operator's server sits in Slovakia

    Operational as licensing regulator. We did not verify how often it has enforced the server-location requirement specifically.

  • Úrad geodézie, kartografie a katastra Slovenskej republiky

    Geodesy and cartography, the state documentation archive and the aerial imagery deposit duties under Act 215/1995 Coll.

    Operational. Penalties under the geodesy act are very small (up to 3,300 euros for a legal person), and we found no evidence of active enforcement of the aerial imagery deposit duty.

  • Európsky výbor pre ochranu údajov

    Consistency and guidance across the European Union; the Slovak authority is a member

    Operational. The Slovak authority joined its 2026 coordinated enforcement action on transparency.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the two replacement data protection bills (LP/2025/305 and LP/2025/306) have not been submitted to or passed by the National Council.

    We confirmed from the regulator's own legislation page on 18 August 2026 that Act 18/2018 Coll. is still listed as the law in force, and found no replacement act in the collection of laws. We were not able to load the parliament's own bill tracker or the slov-lex legislative process pages for those file numbers, which time out for automated fetching. The negative is therefore inferred from the absence of a published act rather than confirmed from the parliamentary record.

  • That no localisation rule exists for banking, payments, insurance or securities data in Slovakia.

    We verified the central bank's own cloud computing and insurance outsourcing pages, neither of which imposes a location rule, but we did not read the full text of the Banking Act (483/2001 Coll.), the Payment Services Act (492/2009 Coll.) or the Securities Act (566/2001 Coll.). Banking secrecy provisions in particular were not examined. Confidence medium; checked 18 August 2026.

  • That Slovak health law imposes no storage-location rule on private healthcare providers.

    We searched the National Health Information System Act (153/2013 Coll.) and found no territorial storage rule, but we did not read the Healthcare Act (576/2004 Coll.) in full, which governs medical records held by individual providers. Confidence medium; checked 18 August 2026.

  • How often, if ever, the gambling server-location rule and the aerial imagery deposit duty are actually enforced.

    Both rules are unambiguous in the statute, but we found no published enforcement decisions from either the Gambling Regulatory Authority or the Geodesy, Cartography and Cadastre Authority. The gambling regulator's site could not be fetched reliably through our proxy. A rule on paper with no visible enforcement record is a different risk picture from an actively policed one.

  • The precise content of Act 67/2026 Coll., which amended both the cybersecurity act and the public administration information technology act with effect from 30 April 2026 and again from 1 January 2027.

    We confirmed the amendment and its effective dates from the official version history and read the consolidated texts, and we identified the 2027 changes to the central metadata duties. We did not obtain the explanatory memorandum, so we cannot say what policy problem the amendment was intended to solve or whether further tranches follow.

  • Whether the defence and classified information regime (Act 215/2004 Coll.) imposes additional storage-location duties.

    Not researched. Anything classified under Slovak law should be treated as outside the scope of this record.

  • The average and maximum size of individual fines issued by the Slovak data protection authority in 2025.

    The annual report gives the total (542 fines, about 468,000 euros) but does not publish a decision-by-decision breakdown or name the largest fine. The average of roughly 860 euros is our own arithmetic, not a figure the authority states. Individual decisions are not published in full.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.