Law note · Slovenia
GDPR Articles 33-34, Breach Notification
A controller must notify the Information Commissioner within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. Commentary describes a parallel channel under the Information Security Act for special processing; this session did not verify which categories of processing that extends to or its relationship to the General Data Protection Regulation (GDPR) Article 33 duty.
What it asks of an app
- Notify the Slovenian Information Commissioner within 72 hours of becoming aware of a personal-data breach affecting a person in Slovenia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics
Primary source: GDPR Arts. 33-34
DLA Piper commentary (parallel Information Security Act channel, unverified detail)