Law note · Slovenia

Zakon o varstvu osebnih podatkov (ZVOP-2), Personal Data Protection Act

cite Zakon o varstvu osebnih podatkov (ZVOP-2), Uradni list RS, st. 163/22 stage In effect since 2023-01-26 reviewed 2026-08-24

Slovenia adopted ZVOP-2 in December 2022, five years after the General Data Protection Regulation (GDPR) took effect, replacing the original 2004 ZVOP-1.

Direct fetch of the Act's full text, hosted by the Information Commissioner, confirms the citation exactly as Uradni list RS, st. 163/22, and shows a later amendment by the Zakon o informacijski varnosti (Information Security Act, ZInfV-1, Uradni list RS, st. 40/25), in force 19 June 2025, whose Article 67 rewrote ZVOP-2 Article 23(1)'s terminology from security requirements to risk management measures as a NIS2-alignment update rather than a substantive privacy change.

Having legislated five years late rather than in the original 2018 rush, ZVOP-2 is noticeably more specific than a hurried transposition, most visibly in its dedicated biometric-data chapter.

What it asks of an app

  • Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Slovenia, and expect ZVOP-2's own institutional and procedural rules to govern rather than a GDPR restatement alone.

When LexLint raises it

Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics

Primary source: ip-rs.si, ZVOP-2 full text (direct fetch, 162,090 chars, not truncated)

← Back to the example  ·  Lint your app →