Law note · Slovenia

GDPR Articles 33-34, Breach Notification

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2023-01-26 reviewed 2026-08-24

A controller must notify the Information Commissioner within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. Commentary describes a parallel channel under the Information Security Act for special processing; this session did not verify which categories of processing that extends to or its relationship to the General Data Protection Regulation (GDPR) Article 33 duty.

What it asks of an app

  • Notify the Slovenian Information Commissioner within 72 hours of becoming aware of a personal-data breach affecting a person in Slovenia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics

Primary source: GDPR Arts. 33-34
DLA Piper commentary (parallel Information Security Act channel, unverified detail)

← Back to the example  ·  Lint your app →