Law note · Slovenia
Zakon o varstvu osebnih podatkov (ZVOP-2), Personal Data Protection Act
Slovenia adopted ZVOP-2 in December 2022, five years after the General Data Protection Regulation (GDPR) took effect, replacing the original 2004 ZVOP-1.
Direct fetch of the Act's full text, hosted by the Information Commissioner, confirms the citation exactly as Uradni list RS, st. 163/22, and shows a later amendment by the Zakon o informacijski varnosti (Information Security Act, ZInfV-1, Uradni list RS, st. 40/25), in force 19 June 2025, whose Article 67 rewrote ZVOP-2 Article 23(1)'s terminology from security requirements to risk management measures as a NIS2-alignment update rather than a substantive privacy change.
Having legislated five years late rather than in the original 2018 rush, ZVOP-2 is noticeably more specific than a hurried transposition, most visibly in its dedicated biometric-data chapter.
What it asks of an app
- Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Slovenia, and expect ZVOP-2's own institutional and procedural rules to govern rather than a GDPR restatement alone.
When LexLint raises it
Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics
Primary source: ip-rs.si, ZVOP-2 full text (direct fetch, 162,090 chars, not truncated)