Law / Slovenia

Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification Obligations

Zakon o informacijski varnosti (ZInfV-1), Uradni list RS, št. 40/25, čl. 29-30

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 18 June 2025.

A vulnerability and incident reporting rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This binds an essential or important entity within Priloga 1 or Priloga 2 on the same scope as this jurisdiction's companion risk-management row; Article 29(3) separately names a provider of an online marketplace, an online search engine or a social-networking-services platform, alongside a DNS, top-level domain (TLD), cloud, data-centre, content-delivery-network, managed-service or managed-security-service provider, for a variant significant-incident standard set in the Commission's NIS2 implementing acts.
  • Treat an incident as significant where it has caused, or could cause, your organisation serious operational disruption or financial loss, or has affected, or could affect, another person by causing substantial material or non-material damage.
  • Give your competent CSIRT group an early warning without delay, at latest within 24 hours of detecting a significant incident, stating whether it is suspected to result from an unlawful or malicious act and whether it may have a cross-border effect.
  • Follow with a full notification without delay, at latest within 72 hours, updating the early warning with an initial assessment of the incident's severity and impact and any available threat indicators, then an interim report if the CSIRT group asks for one, and a final report at latest one month after the 72-hour notification, or a progress report and a final report within one month of resolution if the incident is still ongoing at that point.
  • Without delay, inform the recipients of your services of a significant incident likely to adversely affect them, and communicate to a recipient potentially affected by a significant cyber threat the measures it can take in response.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Articles 52 and 53 create a prekršek (misdemeanor, an administrative offence), not a kaznivo dejanje (criminal offence under the Kazenski zakonik). No provision reviewed here makes a late or missing notification a criminal offence.

Penalty structure

Article 52(1): an essential entity's failure to meet the notification obligations of Article 29 (paragraphs 1-7) or Article 30 (paragraphs 1-2) carries a fine of 0.5 to 2 percent of worldwide annual turnover in the preceding business year, but not less than EUR 10,000 and not more than EUR 10,000,000, whichever is higher. Article 53(1), the mirror provision for an important entity, sets 0.3 to 1.4 percent of turnover, not less than EUR 7,000 and not more than EUR 7,000,000, whichever is higher. A sole trader and the entity's responsible person each face a separate, lower personal fine under Article 52(2)-(3) and 53(2)-(3) for the same failure.

Rule
Higher of
As of
15 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Urad Vlade Republike Slovenije za informacijsko varnost (URSIV, the Government Office for Information Security), through its information-security inspectors, with notifications received by the competent CSIRT group: SI-CERT (hosted by ARNES) for most obligated entities, and SIGOV-CERT (URSIV's own internal unit) for state and local public-administration bodies and the trust-service providers they use, pending formal CSIRT-group designation under Article 13.

Settledness

As of
15 September 2026
Guidance link
https://www.gov.si/assets/vladne-sluzbe/URSIV/PR/ZInfV-1_Odgovori-na-vprasanja.pdf
Guidance body
Urad Vlade Republike Slovenije za informacijsko varnost (URSIV)
Open questions
Given that Article 62 phases in only the Article 21-22 risk-management measures and is silent on Article 29-30, does the incident-notification duty bind an essential or important entity from the Act's 18 June 2025 commencement regardless of registration status, or only once that entity completes the Article 8 self-registration mechanism the competent national authority was still building out through late 2025?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 29(1) requires an essential or important entity to notify its competent CSIRT group of every incident that has a significant impact on the provision of its services, an incident that is significant (pomemben incident) where it has caused, or could cause, the entity serious operational disruption or financial loss, or has affected, or could affect, another natural or legal person by causing substantial material or non-material damage.

Article 30(1) sets the notification clock: an early warning without delay, at latest within 24 hours of detecting the significant incident, indicating where relevant whether the incident is suspected to result from an unlawful or malicious act and whether it may have a cross-border effect; a full notification without delay, at latest within 72 hours, updating that information with an initial assessment of the incident's severity and impact and, where available, threat indicators; an interim report on the CSIRT group's request; and a final report, at latest one month after the 72-hour notification, describing the incident, its severity and impact, the likely threat or root cause, mitigating measures taken or under way, and any cross-border effect, with a progress report substituting where the incident is still ongoing and the final report then due within one month of resolution.

Article 29(3) applies a variant scope to a DNS service provider, top-level domain (TLD) registry, cloud, data-centre or content-delivery-network provider, a managed-service or managed-security-service provider, and a provider of an online marketplace, an online search engine or a social-networking-services platform, directing them to the European Commission's NIS2 implementing acts for the particular cases in which an incident counts as significant for their service.

Article 29(6)-(7) requires the entity to inform the recipients of its services, without delay, of a significant incident likely to adversely affect them, and to communicate to a recipient potentially affected by a significant cyber threat the measures it can take in response.

No transitional provision reviewed here defers this duty; unlike the companion risk-management-measures row, Article 62 phases in only Articles 21 and 22, so this notification duty binds from the Act's own 18 June 2025 commencement.

When LexLint raises it

  • operates_social_platform

Read the law

Consolidated text
pisrs.si (Pravno-informacijski sistem Republike Slovenije), Zakon o informacijski varnosti (ZInfV-1), ID ZAKO8934, Uradni list RS, št. 40/25

Back to the example  ·  Lint your app