Law note · Slovenia
GDPR Chapter V, Cross-Border Transfer Restrictions
A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier.
A single commentary source separately claimed ZVOP-2 requires certain sensitive-data categories to remain within Slovenia's territory; this is flagged as unverified rather than folded into this jurisdiction's cross_border_restriction value, since intra-EEA localization is not what General Data Protection Regulation (GDPR) Chapter V regulates and no article citation or primary text supports the claim.
What it asks of an app
- Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Slovenia outside the EEA.
When LexLint raises it
Declared activities: crawls_web, trains_models
Primary source: GDPR Arts. 44-49, 83(5)(c)
DLA Piper commentary (localization claim flagged, not adopted)