Slovakia flag

Slovakia

Slovakia Data Privacy Laws: GDPR Implementation Guide (2026)

By Recording Law Editorial TeamReviewed May 20, 202621 min read
Slovakia Data Privacy Laws: GDPR Implementation Guide (2026)

Frequently Asked Questions

What is Slovakia's main data protection law?

Slovakia's primary data protection legislation is Act No. 18/2018 Coll. on Protection of Personal Data, adopted 29 November 2017 and in force since 25 May 2018. It supplements the directly applicable EU GDPR by addressing the approximately 50 areas where member states may enact national rules, including birth number protections (s. 78(4)), employee monitoring provisions, and the UOOU's structure. The GDPR and Act 18/2018 operate together; the GDPR governs core rules while the Act fills nationally determined spaces.

What constitutional rights protect data privacy in Slovakia?

Articles 19 and 22 of the Constitution of the Slovak Republic expressly protect data privacy. Article 19 guarantees protection against unwarranted collection, publication, or illicit use of personal data, alongside rights to dignity and private life. Article 22 guarantees privacy of correspondence and protection of personal data. The Slovak Constitutional Court has applied the proportionality principle from these provisions to strike down disproportionate disclosure obligations, including a law requiring NGOs to publicly identify donors. At the EU level, Article 8 of the EU Charter of Fundamental Rights provides an additional layer of protection.

Can organisations in Slovakia use birth numbers (rodne cislo) freely?

No. Section 78(4) of Act No. 18/2018 prohibits making a birth number public; the only exception is when the data subject voluntarily discloses their own. Using the birth number as an identifier is permissible only when no alternative method can achieve the same processing purpose, meaning routine collection for convenience is not permitted. Slovakia is phasing out the birth number in favour of the BIFO code, a ten-digit randomly assigned identifier with no personal information encoded. From 2030, the BIFO replaces the rodne cislo entirely.

What rules govern employee monitoring in Slovakia?

The Slovak Labour Code (Act No. 311/2001 Coll.) permits employee monitoring only where serious reasons relating to the specific character of the employer's activities justify it. Employees must be notified in advance of what is monitored, how, and to what extent. The UOOU requires a data protection impact assessment for any monitoring activity before deployment. The UOOU's municipality email case established that even well-intentioned informal access to a former employee's communications violates GDPR without a documented legal basis and proper transparency procedures.

How large are GDPR fines in Slovakia?

The GDPR's maximum fines of EUR 20 million or 4% of worldwide annual turnover apply in Slovakia, but actual enforcement is modest by EU standards. In 2022, 52 fined decisions totalled EUR 106,448 (average EUR 1,166). In 2024, 38 final fined decisions totalled approximately EUR 84,000 (average EUR 2,226). The largest publicly known single fine is EUR 50,000 (Social Insurance Company, 2019). The UOOU does not publish individual decisions, making Slovakia one of the least transparent EU supervisory authorities for GDPR enforcement.

What are the UOOU's enforcement priorities for 2025?

The UOOU's 2025 control plan has two parts. Part 1 examines data processing in Schengen and European information systems and agencies, relevant to organisations handling border control, immigration, and law enforcement database access. Part 2 investigates processing involving public pharmacy customers, driving school participants, and visitors of restaurants and cafes under CCTV surveillance. Part 2 signals attention to routine commercial data processing in consumer-facing sectors, not only large-scale systemic breaches.

How does Slovakia handle cross-border data transfers?

Cross-border transfers outside the EEA require a GDPR Chapter V mechanism: an adequacy decision, Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or an applicable derogation. In 2021, the UOOU found that Slovakia-US FATCA transfers violated Chapter V because the bilateral agreement lacked minimum safeguards. The UOOU took no enforcement action, but the related CJEU case C-804/25 (registered December 2025) may determine the durability of pre-GDPR bilateral transfer instruments. The UOOU's finding also confirms that statutory authorisation alone does not satisfy GDPR Chapter V requirements.

What is the UOOU's role under the EU AI Act?

The UOOU oversees AI applications that involve personal data processing in Slovakia, applying existing GDPR requirements for automated decision-making (Art. 22), profiling, and DPIAs (Art. 35). Slovakia did not create a separate AI regulator. The Ministry of Investments, Regional Development and Informatization (MIRRI SR) is the Single Contact Point and general market surveillance authority under the AI Act. Slovakia enacted Act No. 318/2025 Z.z. effective 1 January 2026 as its domestic AI Act adaptation. Organisations deploying high-risk AI systems must complete conformity assessments and register with the EU high-risk AI database.

When must a data protection officer (DPO) be appointed in Slovakia?

DPO appointment is mandatory under Act No. 18/2018 (following GDPR Art. 37) for: public authorities and bodies (except courts in their judicial capacity); organisations whose main activities involve large-scale systematic monitoring of individuals; and organisations processing special category or criminal data on a large scale. Slovakia enacted no derogations from these thresholds. DPOs must be registered with the UOOU and their contact details published. Both internal and external (contracted) DPOs are permitted.

What are Slovakia's data breach notification requirements?

Controllers must notify the UOOU within 72 hours of becoming aware of a breach likely to create risk to data subjects' rights and freedoms. If the breach creates high risk, the controller must also directly notify affected data subjects without undue delay. Processors must notify the controller without undue delay on becoming aware of a breach. Under NIS 2 (Act No. 366/2024 Coll., in force 1 January 2025), certain entities face parallel incident notification obligations to the NSA: an early warning within 24 hours and a full incident report within 72 hours.

How does the NIS 2 Directive affect Slovak organisations?

Slovakia transposed NIS 2 through Act No. 366/2024 Coll., amending the Cybersecurity Act (Act No. 69/2018 Coll.), in force 1 January 2025. Over 10,000 organisations across critical sectors are now in scope as essential or important entities. Registration with the NSA was required by 1 March 2025. Full technical and governance compliance is required by 31 December 2026. Essential entities must undergo a cybersecurity audit within two years of registration. Incidents affecting personal data require dual notification to both the NSA and the UOOU.

Does Slovak law have special rules for electronic marketing and cookies?

Yes. Act No. 452/2021 Coll. (Electronic Communications) requires prior demonstrable consent before using automated calling systems, fax, email, SMS, or MMS for direct marketing. Section 109 prohibits conditioning service or feature access on consent to cookies, mirroring the GDPR's freely-given consent requirement. Consent withdrawal must be confirmed within 30 days on durable media. These rules apply in parallel with GDPR consent requirements and are enforced by the UOOU.

Updates

Expanded from 2,280 to approximately 5,800 words. Added sections: Constitutional Basis (Art. 19, Art. 22), Legal Bases for Processing (s. 13 Act 18/2018), Data Subject Rights, EU AI Act Overlay (Act No. 318/2025 Z.z.), Cybersecurity/NIS2 (Act No. 366/2024 Coll.), Recent Developments 2024-2026. Added s. 78(4) statutory reference to birth number section; added Labour Code Act No. 311/2001 Coll. reference; added BIFO transition timeline (2020-2030); added 2022 and 2024 enforcement aggregate statistics; added UOOU FATCA finding (2021) and CJEU C-804/25 (December 2025); added Constitutional Court NGO donor ruling; expanded FAQ from 5 to 11 pairs. Fixed disclaimer internal link.

Sources and References

  1. UOOU Official Website(dataprotection.gov.sk).gov
  2. UOOU Frequently Asked Questions(dataprotection.gov.sk).gov
  3. UOOU About the Office(dataprotection.gov.sk).gov
  4. Act No. 18/2018 Coll. on Protection of Personal Data(slov-lex.sk).gov
  5. EU GDPR Regulation (EU) 2016/679(eur-lex.europa.eu).gov
  6. EU AI Act Regulation (EU) 2024/1689(eur-lex.europa.eu).gov
  7. European Data Protection Board(edpb.europa.eu).gov
  8. EC Digital Strategy AI Act Market Surveillance(digital-strategy.ec.europa.eu).gov
  9. CMS GDPR Enforcement Tracker Slovakia(cms.law)
  10. CMS Expert Guide Slovakia Data Protection(cms.law)
  11. CMS AI Regulation Scanner Slovakia(cms.law)
  12. White and Case GDPR Slovakia Implementation(whitecase.com)
  13. DLA Piper Data Protection Laws Slovakia(dlapiperdataprotection.com)
  14. Linklaters Data Protected Slovakia(linklaters.com)
  15. Ius Laboris Employee Email Slovakia(iuslaboris.com)
  16. Noerr Slovak Labour Privacy(noerr.com)
  17. Lansky NIS 2 Transposition Slovakia(lansky.at)
  18. ppc.land UOOU FATCA Finding(ppc.land)
  19. IAPP Mass Disclosure Slovakia(iapp.org)
  20. Slovak Spectator Birth Number BIFO Transition(spectator.sme.sk)
Share: