Slovakia
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Slovakia has no general rule that data must stay in the country. It runs on the European rulebook: send data abroad once you have the right paperwork. Three areas break that rule. Online gambling servers must sit on Slovak soil. The most sensitive government data must stay in a Slovak data centre. And anyone who takes aerial survey pictures of Slovakia must hand a copy to a defence ministry archive.
Eight questions about Slovakia
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Slovakia's rules apply to my company?
Yes. A company with no office in Slovakia is still caught if it offers goods or services to people in Slovakia, or watches what they do online. There is no minimum size, headcount or revenue below which you are safe. If you have no office anywhere in the European Union, you must name a written representative inside the Union, and you can put that person in any member state where your customers are — it does not have to be Slovakia.
Two layers stack. The General Data Protection Regulation applies directly in Slovakia and reaches controllers outside the European Union under Article 3(2) where they offer goods or services to people in the Union or monitor their behaviour; Article 27 then requires a written representative established in a member state where the affected people are. On top of that, section 3(4) of Act 18/2018 Coll. sets out Slovakia's own territorial reach: point (a) catches any controller or processor with a registered office, place of business, branch, establishment or permanent residence in Slovakia 'regardless of whether the processing is carried out inside or outside the territory of the Slovak Republic', and point (c) catches processing of people located in Slovakia by a controller established outside the member states. That last phrase in point (a) is also the clearest textual confirmation that Slovak law does not care where the servers are. There is no Slovak registration or licensing step before you may process personal data — the old notification duty went with the 1998 and 2013 Acts. A data protection officer must be notified to the authority when one is appointed, using the authority's own form. Note that Act 18/2018 is on its way out: the authority has two replacement bills in the legislative pipeline (see question eight), but on 18 August 2026 they are still bills.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 18/2018 Z. z. o ochrane osobných údajov — consolidated version in force from 18 August 2026 (as amended by Act 168/2026 Coll.), sections 3, 15, 48, 104
slov-lex.sk
“Tento zákon sa vzťahuje na spracúvanie osobných údajov v rámci činnosti prevádzkovateľa alebo sprostredkovateľa, ktorého sídlo, miesto podnikania, organizačná zložka, prevádzkareň alebo trvalý pobyt je na území Slovenskej republiky, a to bez ohľadu na to, či sa spracúvanie osobných údajov vykonáva na území Slovenskej republiky alebo mimo územia Slovenskej republiky”
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 27, 44-49 and 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyNational legislation — the Slovak data protection authority's own list of the laws in force, still naming Act 18/2018 Coll. as the national data protection law
dataprotection.gov.sk
“Na úrovni Slovenskej republiky je ochrana osobných údajov fyzických osôb upravená: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov”
Link checked 18 August 2026
Can I store my users' data outside Slovakia?
In general, yes — with the standard European paperwork. Nothing in Slovak law says personal data must be kept in Slovakia, and the law says so almost in as many words: it applies to a Slovak company whether it processes data inside or outside the country. But three specific activities do force data to stay. Online gambling operators must put their server in Slovakia. The top security tier of government data must stay in a Slovak data centre. And aerial survey imagery of Slovakia must be handed to a state archive.
SECTOR BY SECTOR, checked 18 August 2026. GAMING — a hard wall. Section 14(22) of Act 30/2019 Coll. on gambling: 'Server je prevádzkovateľ hazardnej hry povinný umiestniť na území Slovenskej republiky' — the gambling operator must place the server on Slovak territory. The same section requires the server to record every game played, every stake and win, every intervention in the game software and, for online games, every player-account movement. Section 14(21) requires the operator to give the gambling regulator free, online access to that server. This is stricter than Hungary's equivalent, which allows anywhere in the European Economic Area. Rating: closed GOVERNMENT — a hard wall at the top tier only. Section 24a of Act 95/2019 Coll. lets the ministry set standards that force public bodies, when acting on people's rights and duties, to use only cloud services entered in the government cloud catalogue. The binding methodological guidance of 11 April 2025 (ref. 020775/2025/oSBATA, effective 15 April 2025) sets four categories. Category U4, 'special data', is defined as data 'ktoré však vyžadujú uchovávanie a spracovávanie dát na území SR a v dátovom centre, ktoré je v dosahu štátnych orgánov SR, v privátnej časti vládneho cloudu' — requiring storage and processing on Slovak territory, in a data centre within reach of Slovak state authorities, in the private part of the government cloud. Categories U1 to U3 carry no location requirement, but the questionnaire demands a full list of data-centre locations, expressly flagged as important 'pri uchovávaní osobných údajov mimo EÚ'. Only the Ministry of the Interior (with the Ministry of Finance data centre) may supply the private infrastructure-as-a-service and platform-as-a-service layer. Registration lasts two years and lapses automatically if not renewed. Rating: data must stay in the country for U4, data can leave once conditions are met below it. GEOSPATIAL — a copy must stay. Section 8 of Act 215/1995 Coll. on geodesy and cartography requires anyone who acquires primary aerial remote-sensing material or aerial survey photographs to report it within 30 days and, after use, hand it over free of charge to a special archive run by the Ministry of Defence. Publishers of cartographic works must deposit two analogue copies and, if it exists in digital form, one digital copy with the archive of the Geodesy, Cartography and Cadastre Authority within 30 days, plus one more with the Ministry of Defence archive. You keep your own copy and may take it abroad, so this is a mirror duty, not an export ban. Rating: mirror BANKING, PAYMENTS, INSURANCE, SECURITIES — no localisation found. The central bank's own cloud computing page tells institutions that using a public cloud does not relieve them of responsibility for confidentiality, integrity and availability, and points them to the European Banking Authority outsourcing recommendations; it states no location rule. Its insurance outsourcing page says only critical or important operational functions must be notified in advance under section 30(3) of the Insurance Act, and expressly contemplates providers in other member states or third countries meeting Article 274 of Delegated Regulation 2015/35. The Digital Operational Resilience Act has applied to financial entities since 17 January 2025 and requires the processing location to be named in the contract, with audit rights and an exit plan — disclosure, not residency. Rating: conditional HEALTH — no localisation found. Act 153/2013 Coll. on the national health information system contains no territorial storage rule; the national system itself is state-operated and physically in Slovakia, but that is an operating fact about a state system, not a rule binding private controllers. What it does contain is extremely long retention (see question five). TELECOM — no localisation found, and less retention than most people expect (see question five). EDUCATION, E-COMMERCE, SOCIAL MEDIA, ARTIFICIAL INTELLIGENCE — no Slovak storage-location rule found, checked 18 August 2026. DEFENCE AND CLASSIFIED MATERIAL — not researched in depth. Classified information is governed by a separate regime (Act 215/2004 Coll.) which we did not verify; treat anything classified as out of scope of this record.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 30/2019 Z. z. o hazardných hrách, section 14(21) and 14(22) — version in force from 1 January 2026
slov-lex.sk
“Server je prevádzkovateľ hazardnej hry povinný umiestniť na území Slovenskej republiky.”
Link checked 18 August 2026
- Official sourceMinisterstvo investícií, regionálneho rozvoja a informatizácie Slovenskej republiky (Ministry of Investments, Regional Development and Informatisation)Binding methodological guidance no. 020775/2025/oSBATA of 11 April 2025 on entering a cloud service in the government cloud catalogue (effective 15 April 2025), category U4
mirri.gov.sk
“Kategória U4: Špeciálne dáta (Kritická úroveň zabezpečenia) ... dáta úrovne C3I3A3, ktoré však vyžadujú uchovávanie a spracovávanie dát na území SR a v dátovom centre, ktoré je v dosahu štátnych orgánov SR, v privátnej časti vládneho cloudu.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 95/2019 Z. z. o informačných technológiách vo verejnej správe, section 24a (government cloud) — version in force from 30 April 2026
slov-lex.sk
“Štandardy podľa § 24 ods. 1 písm. f) ustanovia úrovne cloudových služieb ... pri ktorých dosiahnutí môže orgán riadenia ... odoberať a využívať len cloudové služby, ktoré sú vládnymi cloudovými službami.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon Národnej rady SR č. 215/1995 Z. z. o geodézii a kartografii, section 8 (duties on aerial survey imagery and published cartographic works) and sections 30-31 (penalties)
slov-lex.sk
“oznamovať nadobudnutie prvotných materiálov leteckého diaľkového prieskumu Zeme a leteckých meračských snímok do 30 dní od ich nadobudnutia a po využití ich bezplatne odovzdať na archívne účely osobitnému archívu zriadenému Ministerstvom obrany Slovenskej republiky”
Link checked 18 August 2026
- Official sourceNárodná banka Slovenska (National Bank of Slovakia)Cloud computing — the Slovak central bank's own guidance page for supervised financial institutions
nbs.sk
“For any use of core banking services in the 'public cloud', an institution is not relieved from its responsibilities with respect to confidentiality, integrity and availability of data.”
Link checked 18 August 2026
- Official sourceNárodná banka Slovenska (National Bank of Slovakia)Outsourcing — the Slovak central bank's own position for insurance undertakings
nbs.sk
“Povinnosť poisťovne oznamovať Národnej banke Slovenska zámer zveriť výkon funkcií alebo činností inej osobe sa v súlade s § 30 ods. 3 zákona o poisťovníctve vzťahuje len na výkon kritických alebo dôležitých operačných funkcií”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 18/2018 Z. z. o ochrane osobných údajov — consolidated version in force from 18 August 2026 (as amended by Act 168/2026 Coll.), sections 3, 15, 48, 104
slov-lex.sk
“Tento zákon sa vzťahuje na spracúvanie osobných údajov v rámci činnosti prevádzkovateľa alebo sprostredkovateľa, ktorého sídlo, miesto podnikania, organizačná zložka, prevádzkareň alebo trvalý pobyt je na území Slovenskej republiky, a to bez ohľadu na to, či sa spracúvanie osobných údajov vykonáva na území Slovenskej republiky alebo mimo územia Slovenskej republiky”
Link checked 18 August 2026
What do I need in place before data leaves Slovakia?
Slovakia uses the European model, and it is an allowlist. Data may go to a country the European Commission has approved, or to anywhere else if you sign the Commission's standard contract, use approved group-wide rules, or fit one of a few narrow exceptions. The approved list is real and populated — it includes the United Kingdom, Switzerland, Japan, South Korea, Canada for commercial bodies, and the United States only for companies signed up to the transatlantic framework. Slovakia adds nothing of its own on top.
Section 48 of Act 18/2018 Coll. mirrors Chapter V of the General Data Protection Regulation: transfer on the basis of a Commission adequacy decision, or failing that on appropriate safeguards, or failing that on a derogation. The Slovak authority runs the notification and approval forms for transfers to third countries, for approving contractual clauses and for approving binding corporate rules, and lists them on its own site. The 2021 standard contractual clauses (Decision (EU) 2021/914) remain the operative set and are unamended; the promised new clauses for importers already directly subject to the Regulation under Article 3(2) are still not adopted as at 18 August 2026. A transfer impact assessment is still expected after Schrems II. The EU-US Data Privacy Framework is still in force and legally valid on 18 August 2026, but it is under pressure: the General Court dismissed the Latombe challenge on 3 September 2025 and an appeal to the Court of Justice was lodged on 31 October 2025 and is pending, and on 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether US institutional changes affect the decision's validity. The Commission has not suspended or revoked it. Practical advice: usable, but never as your only mechanism. Separately, EDPB Guidelines 02/2024 on Article 48 confirm that an order from a third-country authority is not by itself a lawful basis to hand data over. Regulation (EU) 2018/1807 forbids Slovakia from imposing localisation on non-personal data except on public-security grounds — which is exactly the ground the gambling and government-cloud rules would have to rest on.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 18/2018 Z. z. o ochrane osobných údajov — consolidated version in force from 18 August 2026 (as amended by Act 168/2026 Coll.), sections 3, 15, 48, 104
slov-lex.sk
“Tento zákon sa vzťahuje na spracúvanie osobných údajov v rámci činnosti prevádzkovateľa alebo sprostredkovateľa, ktorého sídlo, miesto podnikania, organizačná zložka, prevádzkareň alebo trvalý pobyt je na území Slovenskej republiky, a to bez ohľadu na to, či sa spracúvanie osobných údajov vykonáva na území Slovenskej republiky alebo mimo územia Slovenskej republiky”
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the Commission's own list of countries found to provide adequate protection
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionCommission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEDPB Guidelines 02/2024 on Article 26 GDPR — a third-country authority's order is not by itself a lawful basis to disclose
edpb.europa.eu
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union, Article 4
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyNational legislation — the Slovak data protection authority's own list of the laws in force, still naming Act 18/2018 Coll. as the national data protection law
dataprotection.gov.sk
“Na úrovni Slovenskej republiky je ochrana osobných údajov fyzických osôb upravená: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov”
Link checked 18 August 2026
Who enforces the rules in Slovakia, and what can they do?
The Office for Personal Data Protection of the Slovak Republic. It is real, staffed and busy. In 2025 it issued 542 final fines totalling about 468,000 euros (roughly $510,000) and actually collected about 411,000 euros of that — a very high number of fines but a very small average, about 860 euros each. It has around 60 staff and got 20 extra posts in 2025. Cybersecurity incidents go to a separate body, the National Security Authority.
The authority (Úrad na ochranu osobných údajov Slovenskej republiky) is led by chair Zuzana Valková, with deputy chair Tomáš Danč appointed with effect from 24 October 2024. Its own 2025 annual report gives the numbers used above, plus 10 procedural fines, 177 breach notifications received (a 45% year-on-year rise), 59 internal appeals lodged and 66 decided. Its budget for 2025 was about 4.9 million euros. The enforcement profile is unusual: very high volume, very low value. A large share of 2025's caseload came from a wave of anonymous mass complaints that municipalities were publishing insufficiently redacted contracts in the Central Register of Contracts, which the office is legally obliged to examine one by one. It is also active in the European Data Protection Board and has signed up to the Board's 2026 coordinated enforcement action on transparency. Rating actively enforced rather than aggressive: fines are frequent and routine, but the office is small, the amounts are modest by European standards, and there is no evidence of large proactive investigations of major platforms. Other regulators: the National Security Authority (Národný bezpečnostný úrad) supervises cybersecurity under Act 69/2018 Coll. and can fine up to 10 million euros or 2% of turnover; the National Bank of Slovakia supervises financial firms; the Gambling Regulatory Authority supervises the gambling server rule; the Geodesy, Cartography and Cadastre Authority supervises the mapping deposit duties.
Sources
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyReport on the state of personal data protection for 2025 — the Slovak data protection authority's own annual report (sanctions, staffing, breach statistics)
dataprotection.gov.sk
“V roku 2025 úrad za porušenie právnych predpisov v oblasti ochrany osobných údajov právoplatne uložil 542 pokút v súhrnnej výške 468 000 Eur.”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyAnnual reports index of the Slovak data protection authority, showing the 2025 report published
dataprotection.gov.sk
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 69/2018 Z. z. o kybernetickej bezpečnosti — version in force from 30 April 2026, incident reporting and penalties
slov-lex.sk
“bez zbytočného odkladu, avšak najneskôr do 24 hodín od jeho zistenia sa hlási včasné [varovanie] ... bez zbytočného odkladu, avšak najneskôr do 72 hodín od jeho zistenia sa hlási oznámenie”
Link checked 18 August 2026
- Official sourceNárodný bezpečnostný úrad (National Security Authority)Cybersecurity — the National Security Authority's own cybersecurity pages
nbu.gov.sk
Link checked 18 August 2026
How long do I have to keep the data?
There is no single retention rule. The general privacy rule is to delete when you no longer need the data. Against that sit long minimum-keeping duties: ten years for accounts and financial statements, and up to one hundred years after death for entries in the national health registers. Telecom companies keep far less than most people assume — Slovakia scrapped blanket call-record retention after its Constitutional Court struck it down, so operators only retain what a court order covers.
THE CEILING. Article 5(1)(e) of the General Data Protection Regulation, applied directly, requires storage limitation: keep personal data in identifiable form no longer than necessary. Act 18/2018 Coll. adds no general Slovak retention ceiling. The data protection authority has treated keeping camera-system recordings for longer than 72 hours as a point of concern in its supervision. THE FLOOR. Accounting: section 35 of Act 431/2002 Coll. requires financial statements, the annual report, accounting records, inventory lists and the chart of accounts to be kept for ten years following the year they relate to; audit reports likewise ten years; sustainability reporting five years. Before a company is wound up it must tell the tax office who will hold the accounting documentation. Health: the annexes to Act 153/2013 Coll. set retention for the national health registers at up to one hundred years after the death of the person, and five years after a contact person's role ends. Gambling: section 14(22) of Act 30/2019 Coll. requires the Slovak-based server to record all games, stakes, winnings, software interventions and player-account movements. Mapping: aerial survey imagery must be deposited in a state archive permanently. HOW CONFLICTS RESOLVE. Slovakia does what most European Union states do: a specific statutory keeping duty is a legal obligation under Article 6(1)(c) of the Regulation and beats a deletion request, but only for the data and the period the statute actually names. A ten-year accounting duty does not license keeping an entire customer relationship record for ten years. TELECOMS — the finding most trackers get wrong. On 29 April 2015 the Constitutional Court, in PL. ÚS 10/2014 (published as no. 139/2015 Coll.), held the blanket retention provisions of the old Act 351/2011 Coll., together with the linked Criminal Procedure Code and Police Act powers, incompatible with the Constitution, the Charter of Fundamental Rights and Freedoms and the European Convention. The replacement law, Act 452/2021 Coll., does not restore blanket retention: section 112(2) requires an operator to retain traffic, location and communicating-party data only where those data are covered by a court authorisation, a subsequent court authorisation, or a court order under the Criminal Procedure Code. There is a separate, ordinary rule that traffic data may be kept until the time limit for challenging or enforcing an invoice expires. Anyone still citing a six-month Slovak telecoms retention period is quoting a law that was struck down eleven years ago.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 431/2002 Z. z. o účtovníctve, section 35 — ten-year retention of accounting records
slov-lex.sk
“účtovná závierka, výkazy vybraných údajov z účtovných závierok podľa § 17a a 22 a výročná správa počas desiatich rokov nasledujúcich po roku, ktorého sa týkajú”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 153/2013 Z. z. o národnom zdravotníckom informačnom systéme, Annex — retention periods for the national health registers
slov-lex.sk
“Doba uchovávania osobných údajov dotknutej osoby ... Sto rokov po smrti dotknutej osoby”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 452/2021 Z. z. o elektronických komunikáciách, sections 112 and 117 — targeted retention only under a court order
slov-lex.sk
“Podnik je na účely poskytovania údajov podľa § 117 ods. 6 povinný uchovávať prevádzkové údaje, lokalizačné údaje a údaje komunikujúcich strán, na ktoré sa vzťahuje súhlas súdu alebo dodatočný súhlas súdu podľa § 117 ods. 7 a 8 alebo príkaz súdu podľa Trestného poriadku.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRFinding of the Constitutional Court of the Slovak Republic, file PL. ÚS 10/2014 of 29 April 2015, published as no. 139/2015 Coll. — blanket telecoms data retention held unconstitutional
slov-lex.sk
“Ustanovenia § 58 ods. 5 až 7 a § 63 ods. 6 zákona č. 351/2011 Z. z. o elektronických komunikáciách v znení neskorších predpisov, § 116 zákona č. 301/2005 Z. z. Trestný poriadok v znení neskorších predpisov a § 76a ods. 3 zákona Národnej rady Slovenskej republiky č. 171/1993 Z. z. o Policajnom zbore v znení neskorších predpisov nie sú v súlade s ...”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyReport on the state of personal data protection for 2025 — the Slovak data protection authority's own annual report (sanctions, staffing, breach statistics)
dataprotection.gov.sk
“V roku 2025 úrad za porušenie právnych predpisov v oblasti ochrany osobných údajov právoplatne uložil 542 pokút v súhrnnej výške 468 000 Eur.”
Link checked 18 August 2026
What happens if there is a breach?
There are two clocks and they are different. A personal data breach goes to the privacy authority within 72 hours of you becoming aware of it, and to the affected people without undue delay if the risk to them is high. A cybersecurity incident at a regulated organisation goes to the National Security Authority twice: a first warning within 24 hours, then a fuller report within 72 hours. If you are both, you file both, to two different bodies.
CLOCK ONE — privacy. Article 33 of the General Data Protection Regulation: notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to people's rights. Article 34: tell affected individuals without undue delay where the risk is high. The Slovak authority takes notifications through its own form on the national portal, and its 2025 report complains that controllers often bypass the form and file something too brief to assess. It received 177 notifications in 2025. Processors must tell their controller without undue delay. CLOCK TWO — cybersecurity. Act 69/2018 Coll., as amended to transpose the NIS2 Directive by Act 366/2024 Coll. with effect from 1 January 2025 and further amended in 2026, requires an early warning without undue delay and at the latest within 24 hours of detecting a significant incident, then a notification without undue delay and at the latest within 72 hours. There is also a duty to provide information to the authority within 72 hours of a request. Fines run to 10 million euros or 2% of worldwide turnover for essential entities and 7 million euros or 1.4% for important entities. WHERE PEOPLE COME UNSTUCK. The two regimes cover overlapping but different organisations and go to different regulators, and the 24-hour cybersecurity warning fires a full day before the privacy deadline. A ransomware attack on a Slovak hospital or energy supplier triggers both. Financial entities have a third clock under the Digital Operational Resilience Act. Build one incident process that starts the 24-hour clock by default and de-escalates, rather than deciding which regime applies first.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 69/2018 Z. z. o kybernetickej bezpečnosti — version in force from 30 April 2026, incident reporting and penalties
slov-lex.sk
“bez zbytočného odkladu, avšak najneskôr do 24 hodín od jeho zistenia sa hlási včasné [varovanie] ... bez zbytočného odkladu, avšak najneskôr do 72 hodín od jeho zistenia sa hlási oznámenie”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyReport on the state of personal data protection for 2025 — the Slovak data protection authority's own annual report (sanctions, staffing, breach statistics)
dataprotection.gov.sk
“V roku 2025 úrad za porušenie právnych predpisov v oblasti ochrany osobných údajov právoplatne uložil 542 pokút v súhrnnej výške 468 000 Eur.”
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 27, 44-49 and 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 69/2018 Coll. on cybersecurity — official version history showing the NIS2 transposition by Act 366/2024 Coll. effective 1 January 2025
slov-lex.sk
Link checked 18 August 2026
What trips people up in Slovakia?
Five things that are not in the summary. Public bodies can be fined the full amount, with no discount. Mishandling personal data you got through your job is a crime, not just a fine. The age of consent for online services is 16, not 13. The rule on dead people's data changed today. And the gambling server rule has no European workaround.
1. PUBLIC BODIES GET NO DISCOUNT. Many European Union states cap or waive fines on public authorities. Slovakia does the opposite and says so in the text: section 104(1)(a) of Act 18/2018 Coll. applies the 10-million-euro or 2%-of-turnover ceiling to a controller 'vrátane orgánu verejnej moci a verejnoprávnym inštitúciám' — including public authorities and public-law institutions — and section 104(1)(c) does the same for public bodies acting as processors. Municipalities and state agencies are squarely in scope, and in 2025 they were the largest single source of complaints. 2. IT IS A CRIME. Section 374 of the Criminal Code (Act 300/2005 Coll.) makes it an offence, punishable by up to one year in prison, to disclose, make available or publish someone else's personal data obtained in connection with public authority, the exercise of constitutional rights, or your own profession, employment or office, in breach of a legal duty. Up to two years where it causes serious harm to the person's rights, is done publicly, or is done in a more serious manner. This attaches to individual employees, not just to the company. 3. AGE SIXTEEN. Section 15(1) of Act 18/2018 Coll. sets the age at which a child can consent to an information society service at 16 — Slovakia did not use the option to lower it to 13. Below 16, a legal representative must give or approve the consent, and the controller must make reasonable efforts to verify that, taking available technology into account. A product built for a United States thirteen-year-old threshold is non-compliant in Slovakia. 4. DEAD PEOPLE'S DATA CHANGED ON 18 AUGUST 2026. Until today, Act 18/2018 Coll. contained a genuinely unusual Slovak rule: where the person had died, a close relative could give the consent the law required, and the consent was invalid if even one close relative objected in writing. Act 168/2026 Coll., in force from 18 August 2026, deletes that mechanism and instead excludes deceased persons from the Act altogether. If your Slovak consent process or genealogy, archive or funeral-sector product relied on the relative-consent rule, it is now built on a repealed provision. This is a day-old change and the plain-language guidance has not caught up. 5. THE GAMBLING SERVER RULE HAS NO EUROPEAN WORKAROUND. Slovakia says 'on the territory of the Slovak Republic', not 'in the European Economic Area'. An operator licensed elsewhere in the Union cannot serve Slovak players from a Dutch or Maltese data centre, and the regulator must be given free online access to that Slovak server. 6. BONUS TRAP — CONTRACT PUBLICATION. Slovak public bodies must publish their contracts in the Central Register of Contracts. That means your commercial agreement with a Slovak ministry or municipality becomes public, and any personal data in it has to be redacted first — a failure the privacy authority is now receiving mass complaints about.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 18/2018 Z. z. o ochrane osobných údajov — consolidated version in force from 18 August 2026 (as amended by Act 168/2026 Coll.), sections 3, 15, 48, 104
slov-lex.sk
“Tento zákon sa vzťahuje na spracúvanie osobných údajov v rámci činnosti prevádzkovateľa alebo sprostredkovateľa, ktorého sídlo, miesto podnikania, organizačná zložka, prevádzkareň alebo trvalý pobyt je na území Slovenskej republiky, a to bez ohľadu na to, či sa spracúvanie osobných údajov vykonáva na území Slovenskej republiky alebo mimo územia Slovenskej republiky”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 300/2005 Z. z. Trestný zákon, section 374 — unauthorised handling of personal data
slov-lex.sk
“Kto neoprávnene poskytne, sprístupní alebo zverejní ... osobné údaje o inom získané v súvislosti s výkonom svojho povolania, zamestnania alebo funkcie a tým poruší všeobecne záväzným právnym predpisom ustanovenú povinnosť, potrestá sa odňatím slobody až na jeden rok.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 30/2019 Z. z. o hazardných hrách, section 14(21) and 14(22) — version in force from 1 January 2026
slov-lex.sk
“Server je prevádzkovateľ hazardnej hry povinný umiestniť na území Slovenskej republiky.”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyReport on the state of personal data protection for 2025 — the Slovak data protection authority's own annual report (sanctions, staffing, breach statistics)
dataprotection.gov.sk
“V roku 2025 úrad za porušenie právnych predpisov v oblasti ochrany osobných údajov právoplatne uložil 542 pokút v súhrnnej výške 468 000 Eur.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 18/2018 Coll. — official version history, showing the amendment by Act 168/2026 Coll. taking effect on 18 August 2026
slov-lex.sk
Link checked 18 August 2026
What is changing soon in Slovakia?
The whole national privacy law is being replaced by two new laws — one general, one for police and courts — but they are still bills and have no legal effect. Act 18/2018 was amended today, 18 August 2026, mostly to remove dead people from its scope. Public bodies face a bigger data-registration duty from 1 January 2027, and all cloud switching and data export fees across Europe must drop to zero by 12 January 2027.
ALREADY HAPPENED, TODAY. Act 168/2026 Coll. amended Act 18/2018 Coll. with effect from 18 August 2026: deceased persons are removed from the Act's scope, the Ministry of Justice is added to the list of competent authorities for law-enforcement processing, and a new rule governs onward transfer of data received from a third country, linked to Act 167/2026 Coll. on international judicial cooperation in criminal matters. BILLS, NOT LAW. On 11 March 2025 the data protection authority announced it was replacing Act 18/2018 Coll. with two separate statutes: a general one, and one dedicated to police and justice processing under Directive (EU) 2016/680. Both went to interministerial consultation as files LP/2025/305 and LP/2025/306 with a comment deadline of 1 July 2025. The stated aims are to end the 'dvojkoľajná úprava' — the two-track system that copies the directly applicable Regulation into national law — to cut the burden of impact assessments, and to introduce codes of conduct and certification supervised by the authority. As at 18 August 2026 the authority's own national legislation page still lists only Act 18/2018 Coll., and no replacement act appears in the collection of laws. A great deal of Slovak commentary published in late 2025 and 2026 announces a 'new data protection act from 2026' as though it were settled. It is not. Treat it as a bill. DATED CHANGES. 1 January 2027: Act 95/2019 Coll., as amended by Act 67/2026 Coll., widens what public bodies must publish into the central metadata system — not just technical details of their systems but metadata about the registers they run, the data those registers hold, and the legal basis on which anyone may use that data, with an express instruction that this must not directly or indirectly disclose personal data. 12 January 2027: the European Data Act's hard deadline, after which all cloud switching charges and data egress fees must be zero. 30 April 2026 has already passed: Act 67/2026 Coll. amended both the cybersecurity act and the public administration IT act on that date. DORMANT SWITCHES — powers already held that could change things without warning. First, the government cloud categories are set by ministerial methodological guidance, not by statute. The ministry can redefine which data falls into category U4 — the tier that must stay in Slovakia — and widen the localisation wall by publishing a new document, without parliament and without consultation. Registrations lapse every two years, so a change bites within one renewal cycle. Second, the gambling regulator's power to demand free online access to the operator's Slovak server is open-ended, with the scope set by finance ministry decree. Third, the cybersecurity authority's powers under Act 69/2018 Coll. include mandatory blocking measures. Fourth, the two replacement privacy bills could be reintroduced and passed quickly, since the drafts already exist and the responsible regulator is their author.
Sources
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyInterministerial consultation on the two new data protection bills (files LP/2025/305 and LP/2025/306), comment deadline 1 July 2025
dataprotection.gov.sk
“Úrad na ochranu osobných údajov Slovenskej republiky predložil do medzirezortného pripomienkového konania (MPK): návrh zákona o zabezpečení ochrany fyzických osôb pri spracúvaní osobných údajov ... Termín na pripomienkovanie je 1.7.2025.”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyForthcoming new data protection legislation — announcement by the Slovak data protection authority, 11 March 2025
dataprotection.gov.sk
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyNational legislation — the Slovak data protection authority's own list of the laws in force, still naming Act 18/2018 Coll. as the national data protection law
dataprotection.gov.sk
“Na úrovni Slovenskej republiky je ochrana osobných údajov fyzických osôb upravená: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 18/2018 Coll. — official version history, showing the amendment by Act 168/2026 Coll. taking effect on 18 August 2026
slov-lex.sk
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 95/2019 Coll. — version taking effect on 1 January 2027 (amended by Act 67/2026 Coll.), expanded central metadata register duties
slov-lex.sk
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 (Data Act), Chapters VI and VII
eur-lex.europa.eu
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
3 rules here
Layer 2
National rules
Added by this country on top of any bloc rules.
5 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
7 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules3 rules
Nariadenie Európskeho parlamentu a Rady (EÚ) 2016/679 (všeobecné nariadenie o ochrane údajov)
Directly binding regulation · Regulation (EU) 2016/679
The European baseline that governs almost all personal data in Slovakia. It does not require data to stay in Europe; it sets the conditions under which data may leave.
Enforced by European Data Protection Board
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of processing
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a local representativeRequired where there is no establishment in the European Union.
- Put a transfer safeguard in placePlus a documented transfer impact assessment after the Schrems II judgment.
- Do not hand data to foreign authorities on demandA third-country authority's order is not by itself a lawful basis to disclose (EDPB Guidelines 02/2024).
- Delete data after a period
- Get a parent's consent for children — applies at: 16 in Slovakia — Slovakia did not lower the age below the default
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $11 millionController and processor obligations
- Order to stopThe regulator can order processing to stop or suspend flows to a third country
- Claims by individualsIndividuals can claim compensation
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 27, 44-49 and 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the Commission's own list of countries found to provide adequate protection
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionCommission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyNational legislation — the Slovak data protection authority's own list of the laws in force, still naming Act 18/2018 Coll. as the national data protection law
dataprotection.gov.sk
“Na úrovni Slovenskej republiky je ochrana osobných údajov fyzických osôb upravená: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov”
Link checked 18 August 2026
Nariadenie (EÚ) 2018/1807 o rámci pre voľný tok neosobných údajov v Európskej únii
Directly binding regulation · Regulation (EU) 2018/1807
Slovakia is forbidden from forcing non-personal data to be stored on its territory, except where public security genuinely requires it. This is the rule any Slovak localisation demand has to justify itself against.
Transfer model: No restriction · Accepted routes: Nothing required
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union, Article 4
eur-lex.europa.eu
Link checked 18 August 2026
Nariadenie (EÚ) 2023/2854 o harmonizovaných pravidlách týkajúcich sa spravodlivého prístupu k údajom a ich používania (akt o údajoch)
Directly binding regulation · Regulation (EU) 2023/2854 (Data Act)
The European Data Act has applied since 12 September 2025 and gives customers a right to switch cloud providers. Its hardest deadline is 12 January 2027, when all switching charges and data export fees must fall to zero.
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Make switching cloud provider possible — from 12 January 2027All cloud switching charges and data egress fees must be zero from 12 January 2027.
- Do not hand data to foreign authorities on demandChapter VII restricts third-country government access to non-personal data held in the European Union.
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 (Data Act), Chapters VI and VII
eur-lex.europa.eu
Link checked 18 August 2026
National rules5 rules
Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov
Act of parliament · Act No. 18/2018 Coll., as last amended by Act No. 168/2026 Coll.
Slovakia's national privacy law. It contains no requirement to keep data in Slovakia and expressly applies whether processing happens inside or outside the country. It sets the age of online consent at 16 and applies the full European fine ceilings to public bodies.
Enforced by Office for Personal Data Protection of the Slovak Republic
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest
What it makes you do
- Appoint a data protection officerWhere appointed, the data protection officer must be notified to the authority on its own form.
- Get a parent's consent for children — applies at: 16 years — section 15(1); the controller must make reasonable efforts to verify the parent's consent
- Put a transfer safeguard in place
- Keep records of processing
- Assess high-risk projects
What it costs if you get it wrong
- Percentage of global turnover: €20,000,000 or 4% of total worldwide annual turnover, whichever is higher — about $22 millionBreach of the basic principles, individual rights, transfer rules, or a regulator order — section 104(2)
- Percentage of global turnover: €10,000,000 or 2% of total worldwide annual turnover, whichever is higher — about $11 millionController and processor obligations — section 104(1), which expressly includes public authorities and public-law institutions
- Fixed maximum fine: €2,000 — about $2 thousandProcedural fine for obstructing an inspection — section 105
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 18/2018 Z. z. o ochrane osobných údajov — consolidated version in force from 18 August 2026 (as amended by Act 168/2026 Coll.), sections 3, 15, 48, 104
slov-lex.sk
“Tento zákon sa vzťahuje na spracúvanie osobných údajov v rámci činnosti prevádzkovateľa alebo sprostredkovateľa, ktorého sídlo, miesto podnikania, organizačná zložka, prevádzkareň alebo trvalý pobyt je na území Slovenskej republiky, a to bez ohľadu na to, či sa spracúvanie osobných údajov vykonáva na území Slovenskej republiky alebo mimo územia Slovenskej republiky”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyNational legislation — the Slovak data protection authority's own list of the laws in force, still naming Act 18/2018 Coll. as the national data protection law
dataprotection.gov.sk
“Na úrovni Slovenskej republiky je ochrana osobných údajov fyzických osôb upravená: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 18/2018 Coll. — official version history, showing the amendment by Act 168/2026 Coll. taking effect on 18 August 2026
slov-lex.sk
Link checked 18 August 2026
Návrh zákona o zabezpečení ochrany fyzických osôb pri spracúvaní osobných údajov (LP/2025/305) a návrh zákona o ochrane fyzických osôb pri spracúvaní osobných údajov príslušnými orgánmi (LP/2025/306)
Draft law · Legislative process files LP/2025/305 and LP/2025/306
Two draft laws that would split the current privacy act into a general law and a separate police-and-justice law. They are bills only: as at 18 August 2026 the regulator's own legislation page still lists only the 2018 act. Do not plan around them as binding.
Enforced by Office for Personal Data Protection of the Slovak Republic
Sources
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyInterministerial consultation on the two new data protection bills (files LP/2025/305 and LP/2025/306), comment deadline 1 July 2025
dataprotection.gov.sk
“Úrad na ochranu osobných údajov Slovenskej republiky predložil do medzirezortného pripomienkového konania (MPK): návrh zákona o zabezpečení ochrany fyzických osôb pri spracúvaní osobných údajov ... Termín na pripomienkovanie je 1.7.2025.”
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyForthcoming new data protection legislation — announcement by the Slovak data protection authority, 11 March 2025
dataprotection.gov.sk
Link checked 18 August 2026
- Official sourceÚrad na ochranu osobných údajov Slovenskej republikyNational legislation — the Slovak data protection authority's own list of the laws in force, still naming Act 18/2018 Coll. as the national data protection law
dataprotection.gov.sk
“Na úrovni Slovenskej republiky je ochrana osobných údajov fyzických osôb upravená: Zákon č. 18/2018 Z. z. o ochrane osobných údajov a o zmene a doplnení niektorých zákonov”
Link checked 18 August 2026
Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplnení niektorých zákonov
Act of parliament · Act No. 69/2018 Coll., transposing Directive (EU) 2022/2555 (NIS2) by Act No. 366/2024 Coll., further amended by Acts 318/2025 and 67/2026 Coll.
Slovakia's cybersecurity law, which transposed the European NIS2 rules from 1 January 2025. It imposes no storage-location rule, but it adds a second incident clock: 24 hours for a first warning, 72 hours for the fuller report, to a different regulator from the privacy one.
Enforced by National Security Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 24 hoursEarly warning of a significant incident, without undue delay and at the latest within 24 hours of detection.
- Report cyber incidents — within 72 hoursFuller notification, without undue delay and at the latest within 72 hours of detection.
- Secure the data
- Independent auditCertified cybersecurity auditors verify compliance; the same audit gates the government cloud categories U3 and U4.
- Register or notifyRegistration of essential and important entities with the National Security Authority.
What it costs if you get it wrong
- Percentage of global turnover: €500 to €10,000,000 or up to 2% of total turnover — about $11 millionEssential entity failing cybersecurity duties
- Percentage of global turnover: €300 to €7,000,000 or up to 1.4% of total turnover — about $8 millionImportant entity failing cybersecurity duties
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 69/2018 Z. z. o kybernetickej bezpečnosti — version in force from 30 April 2026, incident reporting and penalties
slov-lex.sk
“bez zbytočného odkladu, avšak najneskôr do 24 hodín od jeho zistenia sa hlási včasné [varovanie] ... bez zbytočného odkladu, avšak najneskôr do 72 hodín od jeho zistenia sa hlási oznámenie”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 69/2018 Coll. on cybersecurity — official version history showing the NIS2 transposition by Act 366/2024 Coll. effective 1 January 2025
slov-lex.sk
Link checked 18 August 2026
- Official sourceNárodný bezpečnostný úrad (National Security Authority)Cybersecurity — the National Security Authority's own cybersecurity pages
nbu.gov.sk
Link checked 18 August 2026
Zákon č. 300/2005 Z. z. Trestný zákon, § 374 Neoprávnené nakladanie s osobnými údajmi
Act of parliament · Act No. 300/2005 Coll. (Criminal Code), section 374
Leaking personal data you obtained through your job is a criminal offence in Slovakia, punishable by up to a year in prison and up to two years in aggravated cases. It bites the individual, not just the company.
What it makes you do
- Secure the dataApplies to the individual who discloses, not only to the employer.
What it costs if you get it wrong
- Criminal liability: Imprisonment up to 1 year; up to 2 years where it causes serious harm to the person's rights, is done publicly, or in a more serious mannerUnlawfully disclosing, making available or publishing personal data obtained through public authority, the exercise of constitutional rights, or one's own profession, employment or office
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 300/2005 Z. z. Trestný zákon, section 374 — unauthorised handling of personal data
slov-lex.sk
“Kto neoprávnene poskytne, sprístupní alebo zverejní ... osobné údaje o inom získané v súvislosti s výkonom svojho povolania, zamestnania alebo funkcie a tým poruší všeobecne záväzným právnym predpisom ustanovenú povinnosť, potrestá sa odňatím slobody až na jeden rok.”
Link checked 18 August 2026
Zákon č. 431/2002 Z. z. o účtovníctve, § 35 Uchovávanie a ochrana účtovnej dokumentácie
Act of parliament · Act No. 431/2002 Coll., section 35
Accounting records must be kept for ten years after the year they relate to. There is no rule saying they must be kept in Slovakia, and electronic storage on a data carrier is expressly allowed.
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 10 yearsFinancial statements, the annual report, accounting records, inventory lists and the chart of accounts: ten years following the year they relate to. Sustainability and income-tax reports: five years.
- Keep records of processingBefore a company is wound up it must tell the tax office who will hold its accounting documentation.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 431/2002 Z. z. o účtovníctve, section 35 — ten-year retention of accounting records
slov-lex.sk
“účtovná závierka, výkazy vybraných údajov z účtovných závierok podľa § 17a a 22 a výročná správa počas desiatich rokov nasledujúcich po roku, ktorého sa týkajú”
Link checked 18 August 2026
Industry rules7 rules
Zákon č. 30/2019 Z. z. o hazardných hrách a o zmene a doplnení niektorých zákonov, § 14 ods. 21 a 22
Act of parliament · Act No. 30/2019 Coll., section 14(21) and 14(22) · Online gaming
An online or terminal-based gambling operator must place its server inside Slovakia and give the regulator free online access to it. This is a genuine hard wall with no European workaround.
Enforced by Gambling Regulatory Authority
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryThe operator's server must be physically located on Slovak territory. Not the European Economic Area — Slovakia.
- Keep logsThe server must record every game played, all stakes and winnings, every intervention in the game data or software, every fault, and for online games every player-account movement.
- Register or notifyThe operator must give the gambling regulator free online access to that server, in a scope set by finance ministry decree.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions under the Gambling Act
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 30/2019 Z. z. o hazardných hrách, section 14(21) and 14(22) — version in force from 1 January 2026
slov-lex.sk
“Server je prevádzkovateľ hazardnej hry povinný umiestniť na území Slovenskej republiky.”
Link checked 18 August 2026
Metodické usmernenie č. 020775/2025/oSBATA z 11. 4. 2025 pre proces zaradenia cloudovej služby do katalógu vládnych cloudových služieb, vydané podľa § 24a zákona č. 95/2019 Z. z.
Government rules · Binding methodological guidance no. 020775/2025/oSBATA, issued under section 24a of Act No. 95/2019 Coll. · Government
Slovak public bodies handling the top security tier of data may only use a cloud service that keeps that data inside Slovakia, in a state-reachable data centre. Lower tiers have no location rule but must disclose every data-centre location.
Enforced by Ministry of Investments, Regional Development and Informatisation
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryCategory U4 'special data' must be stored and processed on Slovak territory, in a data centre within reach of Slovak state authorities, in the private part of the government cloud.
- Register or notifyThe cloud service must be entered in the government cloud catalogue. Entry lasts two years and is deleted automatically if not renewed in time.
- Independent auditCategories U3 and U4 require assessment by a certified cybersecurity auditor under Act 69/2018 Coll.
- Hold a security certificateThe provider must disclose every data-centre location where data is stored, expressly flagged as important where personal data would sit outside the European Union.
- Prove the data stays under local controlOnly the Ministry of the Interior, using the Interior and Finance Ministry data centres, may supply the private infrastructure and platform layers.
Sources
- Official sourceMinisterstvo investícií, regionálneho rozvoja a informatizácie Slovenskej republiky (Ministry of Investments, Regional Development and Informatisation)Binding methodological guidance no. 020775/2025/oSBATA of 11 April 2025 on entering a cloud service in the government cloud catalogue (effective 15 April 2025), category U4
mirri.gov.sk
“Kategória U4: Špeciálne dáta (Kritická úroveň zabezpečenia) ... dáta úrovne C3I3A3, ktoré však vyžadujú uchovávanie a spracovávanie dát na území SR a v dátovom centre, ktoré je v dosahu štátnych orgánov SR, v privátnej časti vládneho cloudu.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 95/2019 Z. z. o informačných technológiách vo verejnej správe, section 24a (government cloud) — version in force from 30 April 2026
slov-lex.sk
“Štandardy podľa § 24 ods. 1 písm. f) ustanovia úrovne cloudových služieb ... pri ktorých dosiahnutí môže orgán riadenia ... odoberať a využívať len cloudové služby, ktoré sú vládnymi cloudovými službami.”
Link checked 18 August 2026
- Official sourceMinisterstvo investícií, regionálneho rozvoja a informatizácie Slovenskej republikyCatalogue of government cloud services
mirri.gov.sk
Link checked 18 August 2026
Zákon č. 95/2019 Z. z. o informačných technológiách vo verejnej správe, § 24a Vládny cloud
Act of parliament · Act No. 95/2019 Coll., section 24a, as amended by Act No. 67/2026 Coll. · Government
The statute behind the government cloud. Most of it is already in force; a further tranche of data-registration duties on public bodies starts on 1 January 2027, so parts of the current text are not yet operative.
Enforced by Ministry of Investments, Regional Development and Informatisation
Transfer model: Allowlist
What it makes you do
- Register or notifyOnly a service in the government cloud catalogue may be used by a public body acting on people's rights and duties, at the service levels the standards specify.
- Keep records of processing — 2 years, from 1 January 2027From 1 January 2027 public bodies must also publish metadata about the registers they run, the data those registers hold, and the legal basis for using that data — without disclosing personal data directly or indirectly.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 95/2019 Z. z. o informačných technológiách vo verejnej správe, section 24a (government cloud) — version in force from 30 April 2026
slov-lex.sk
“Štandardy podľa § 24 ods. 1 písm. f) ustanovia úrovne cloudových služieb ... pri ktorých dosiahnutí môže orgán riadenia ... odoberať a využívať len cloudové služby, ktoré sú vládnymi cloudovými službami.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRAct 95/2019 Coll. — version taking effect on 1 January 2027 (amended by Act 67/2026 Coll.), expanded central metadata register duties
slov-lex.sk
Link checked 18 August 2026
Zákon Národnej rady Slovenskej republiky č. 215/1995 Z. z. o geodézii a kartografii
Act of parliament · Act No. 215/1995 Coll., section 8 · Mapping and location
If you fly a survey over Slovakia or publish a map of it, a copy has to be handed to Slovak state archives, one of which is run by the Ministry of Defence. You keep your own copy and may take it abroad, so this is a mirror duty rather than an export ban. The fines are small.
Enforced by Geodesy, Cartography and Cadastre Authority of the Slovak Republic
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep the data in the countryAcquisition of primary aerial remote-sensing material or aerial survey photographs must be reported within 30 days and the material handed over free of charge, after use, to a special archive run by the Ministry of Defence.
- Keep data for a minimum periodPublishers of cartographic works must deposit two analogue copies and one digital copy with the mapping authority's archive within 30 days, plus one copy with the Ministry of Defence archive.
What it costs if you get it wrong
- Fixed maximum fine: €3,300 for a legal person; €330 for an individual — about $4 thousandFailing to report or deposit aerial survey imagery or published cartographic works
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon Národnej rady SR č. 215/1995 Z. z. o geodézii a kartografii, section 8 (duties on aerial survey imagery and published cartographic works) and sections 30-31 (penalties)
slov-lex.sk
“oznamovať nadobudnutie prvotných materiálov leteckého diaľkového prieskumu Zeme a leteckých meračských snímok do 30 dní od ich nadobudnutia a po využití ich bezplatne odovzdať na archívne účely osobitnému archívu zriadenému Ministerstvom obrany Slovenskej republiky”
Link checked 18 August 2026
Zákon č. 452/2021 Z. z. o elektronických komunikáciách, § 112 a § 117, v nadväznosti na nález Ústavného súdu SR sp. zn. PL. ÚS 10/2014 (139/2015 Z. z.)
Act of parliament · Act No. 452/2021 Coll., sections 112 and 117; Constitutional Court finding PL. ÚS 10/2014 of 29 April 2015, published as No. 139/2015 Coll. · Telecoms
Slovakia has no blanket telecoms data retention. The Constitutional Court struck the old blanket rules down in 2015 and the 2021 replacement law only requires retention of what a court order actually covers. Trackers still reporting a six-month Slovak retention period are quoting a repealed law.
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum periodTargeted only: an operator must retain traffic, location and communicating-party data solely where a court authorisation or a court order under the Criminal Procedure Code covers them.
- Delete data after a periodTraffic data must otherwise be erased or anonymised once no longer needed; it may be kept until the period for challenging or enforcing an invoice expires.
- Secure the dataRetained data must be held to the same quality and security standard as live data and destroyed at the end of the retention period.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 452/2021 Z. z. o elektronických komunikáciách, sections 112 and 117 — targeted retention only under a court order
slov-lex.sk
“Podnik je na účely poskytovania údajov podľa § 117 ods. 6 povinný uchovávať prevádzkové údaje, lokalizačné údaje a údaje komunikujúcich strán, na ktoré sa vzťahuje súhlas súdu alebo dodatočný súhlas súdu podľa § 117 ods. 7 a 8 alebo príkaz súdu podľa Trestného poriadku.”
Link checked 18 August 2026
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRFinding of the Constitutional Court of the Slovak Republic, file PL. ÚS 10/2014 of 29 April 2015, published as no. 139/2015 Coll. — blanket telecoms data retention held unconstitutional
slov-lex.sk
“Ustanovenia § 58 ods. 5 až 7 a § 63 ods. 6 zákona č. 351/2011 Z. z. o elektronických komunikáciách v znení neskorších predpisov, § 116 zákona č. 301/2005 Z. z. Trestný poriadok v znení neskorších predpisov a § 76a ods. 3 zákona Národnej rady Slovenskej republiky č. 171/1993 Z. z. o Policajnom zbore v znení neskorších predpisov nie sú v súlade s ...”
Link checked 18 August 2026
Stanoviská Národnej banky Slovenska ku cloud computingu a k outsourcingu (poisťovníctvo), v nadväznosti na § 30 ods. 3 zákona o poisťovníctve a usmernenia EBA/EIOPA
Regulator guideline · National Bank of Slovakia supervisory positions on cloud computing and on outsourcing by insurance undertakings · Finance
Slovak financial regulation contains no storage-location rule. The central bank requires contracts, monitoring and audit rights for cloud outsourcing, and advance notice for critical insurance functions, but does not tell firms where to keep data.
Enforced by National Bank of Slovakia
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Written vendor contractContracts, monitoring and audit rights as set out in the European Banking Authority outsourcing recommendations; the Digital Operational Resilience Act additionally requires the processing location to be named, with audit rights and an exit plan.
- Register or notifyInsurers must notify the central bank in advance of an intention to outsource a critical or important operational function.
Sources
- Official sourceNárodná banka Slovenska (National Bank of Slovakia)Cloud computing — the Slovak central bank's own guidance page for supervised financial institutions
nbs.sk
“For any use of core banking services in the 'public cloud', an institution is not relieved from its responsibilities with respect to confidentiality, integrity and availability of data.”
Link checked 18 August 2026
- Official sourceNárodná banka Slovenska (National Bank of Slovakia)Outsourcing — the Slovak central bank's own position for insurance undertakings
nbs.sk
“Povinnosť poisťovne oznamovať Národnej banke Slovenska zámer zveriť výkon funkcií alebo činností inej osobe sa v súlade s § 30 ods. 3 zákona o poisťovníctve vzťahuje len na výkon kritických alebo dôležitých operačných funkcií”
Link checked 18 August 2026
Zákon č. 153/2013 Z. z. o národnom zdravotníckom informačnom systéme a o zmene a doplnení niektorých zákonov
Act of parliament · Act No. 153/2013 Coll., annexes on the national health registers · Health and social care
Slovakia's health information law has no rule about where health data must be stored, but it sets extraordinarily long minimum retention: up to one hundred years after death for entries in the national health registers.
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Keep data for a minimum periodEntries in several national health registers are kept for one hundred years after the death of the person concerned; contact-person data for five years after the role ends.
Sources
- Official sourceZbierka zákonov Slovenskej republiky (Slov-Lex), Ministerstvo spravodlivosti SRZákon č. 153/2013 Z. z. o národnom zdravotníckom informačnom systéme, Annex — retention periods for the national health registers
slov-lex.sk
“Doba uchovávania osobných údajov dotknutej osoby ... Sto rokov po smrti dotknutej osoby”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the two replacement data protection bills (LP/2025/305 and LP/2025/306) have not been submitted to or passed by the National Council.
We confirmed from the regulator's own legislation page on 18 August 2026 that Act 18/2018 Coll. is still listed as the law in force, and found no replacement act in the collection of laws. We were not able to load the parliament's own bill tracker or the slov-lex legislative process pages for those file numbers, which time out for automated fetching. The negative is therefore inferred from the absence of a published act rather than confirmed from the parliamentary record.
That no localisation rule exists for banking, payments, insurance or securities data in Slovakia.
We verified the central bank's own cloud computing and insurance outsourcing pages, neither of which imposes a location rule, but we did not read the full text of the Banking Act (483/2001 Coll.), the Payment Services Act (492/2009 Coll.) or the Securities Act (566/2001 Coll.). Banking secrecy provisions in particular were not examined. Confidence medium; checked 18 August 2026.
That Slovak health law imposes no storage-location rule on private healthcare providers.
We searched the National Health Information System Act (153/2013 Coll.) and found no territorial storage rule, but we did not read the Healthcare Act (576/2004 Coll.) in full, which governs medical records held by individual providers. Confidence medium; checked 18 August 2026.
How often, if ever, the gambling server-location rule and the aerial imagery deposit duty are actually enforced.
Both rules are unambiguous in the statute, but we found no published enforcement decisions from either the Gambling Regulatory Authority or the Geodesy, Cartography and Cadastre Authority. The gambling regulator's site could not be fetched reliably through our proxy. A rule on paper with no visible enforcement record is a different risk picture from an actively policed one.
The precise content of Act 67/2026 Coll., which amended both the cybersecurity act and the public administration information technology act with effect from 30 April 2026 and again from 1 January 2027.
We confirmed the amendment and its effective dates from the official version history and read the consolidated texts, and we identified the 2027 changes to the central metadata duties. We did not obtain the explanatory memorandum, so we cannot say what policy problem the amendment was intended to solve or whether further tranches follow.
Whether the defence and classified information regime (Act 215/2004 Coll.) imposes additional storage-location duties.
Not researched. Anything classified under Slovak law should be treated as outside the scope of this record.
The average and maximum size of individual fines issued by the Slovak data protection authority in 2025.
The annual report gives the total (542 fines, about 468,000 euros) but does not publish a decision-by-decision breakdown or name the largest fine. The average of roughly 860 euros is our own arithmetic, not a figure the authority states. Individual decisions are not published in full.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.