EnglishSL
Slovenia flag

Slovenia

Slovenia Data Privacy Laws: GDPR, ZVOP-2, and the Information Commissioner (2026)

By Recording Law Editorial TeamReviewed May 20, 202617 min read
Slovenia Data Privacy Laws: GDPR, ZVOP-2, and the Information Commissioner (2026)

Frequently Asked Questions

Why was Slovenia the last EU member state to implement the GDPR?

Slovenia's nearly five-year delay resulted from protracted political and legal debates over the scope of the Information Commissioner's powers, how to structure administrative fines within Slovenian constitutional law, and the balance between data protection and freedom of expression. Multiple draft versions circulated from 2017 onward before the final text was adopted in December 2022. The GDPR applied directly throughout this period, and the older ZVOP-1 (2004) continued to operate where it did not conflict with the GDPR.

What is the constitutional basis for data protection in Slovenia?

Article 38 of the 1991 Slovenian Constitution expressly guarantees the protection of personal data, prohibits using personal data contrary to the purpose for which it was collected, and requires that collection, processing, use, and supervision of personal data be regulated by statute. This makes personal data protection a constitutional right in Slovenia, predating both the EU Charter of Fundamental Rights and the GDPR.

Do organisations need prior approval to process biometric data in Slovenia?

Yes, in the private sector. Processing biometric data for identification or authentication requires prior approval from the Information Commissioner, prior written notice to affected individuals, and cannot be used for marketing purposes. This requirement is stricter than most EU member states, which generally allow biometric processing on standard GDPR legal bases without advance regulatory clearance.

What are the mandatory processing log requirements under ZVOP-2?

ZVOP-2 requires traceability logs for automated systems processing personal data of more than 100,000 individuals, or special-category personal data of more than 10,000 individuals, as well as for systematic monitoring activities and where a DPIA has identified a manageable risk. Logs must record who accessed data, when, and for what purpose. The transition period expired on 26 January 2025.

What fines can the Information Commissioner impose under ZVOP-2?

For GDPR violations, the Commissioner can impose fines up to EUR 10 million or 2% of global annual turnover (Tier 1), or up to EUR 20 million or 4% of global annual turnover (Tier 2), whichever is higher. For violations of ZVOP-2-specific provisions, fines for legal entities range from EUR 100 to EUR 40,000. All fines are processed through Slovenia's misdemeanour framework, compared to the previous maximum of EUR 12,510 under ZVOP-1.

How does Slovenia's AI Act implementation affect data protection compliance?

Slovenia enacted ZIUDHPUI on 21 November 2025, designating the Information Commissioner as the market supervisory authority for the highest-risk AI systems, including biometric identification, social scoring, crime prediction, and emotion detection in workplaces. AI systems processing biometric data face simultaneous ZVOP-2 pre-authorisation requirements and AI Act market supervision, both enforced by the same authority.

What is the age of digital consent in Slovenia?

Slovenia set the age of digital consent at 15 years old. Children aged 15 and older can independently consent to information society services such as social media platforms. Children under 15 require parental or guardian authorisation.

How do cross-border data transfers work under Slovenian law?

Slovenia follows the standard GDPR framework. Transfers outside the EEA require an adequacy decision, Standard Contractual Clauses with a Transfer Impact Assessment, Binding Corporate Rules, or an applicable derogation. A legacy Slovenian adequacy arrangement for transfers to North Macedonia under ZVOP-1 does not carry over to ZVOP-2, so organisations transferring data to North Macedonia must now use SCCs or another GDPR mechanism.

Updates

Full expansion and refresh: added Article 38 constitutional foundation section, detailed late-transposition history and misdemeanour fine framework, 2024 enforcement decisions from GDPRhub, expanded DPO qualification requirements, new EU AI Act and ZIUDHPUI section, processing log thresholds and post-deadline compliance status, cross-border transfer North Macedonia note, and business compliance checklist. Word count increased from approximately 2,300 to approximately 5,500.

Sources and References

  1. Information Commissioner ZVOP-2 Overview(ip-rs.si).gov
  2. Information Commissioner Key Features ZVOP-2(ip-rs.si).gov
  3. Information Commissioner My Rights(ip-rs.si).gov
  4. Schoenherr ZVOP-2 Late Transposition(schoenherr.eu)
  5. Wolf Theiss ZVOP-2 Analysis(wolftheiss.com)
  6. CMS Expert Guide Slovenia(cms.law)
  7. DLA Piper Slovenia Data Protection(dlapiperdataprotection.com)
  8. GDPRhub IP Slovenia Enforcement(gdprhub.eu)
  9. EuroCloud Slovenia Last EU State(eurocloud.org)
  10. Jadek Pensa ZVOP-2 Entry into Force(jadek-pensa.si)
  11. Information Commissioner AI Act Supervision(365trust.me)
  12. EDPB Slovenia(edpb.europa.eu).gov
  13. EU FRA Slovenian Constitution(fra.europa.eu).gov
Share: