Law / Slovenia

Slovenia

privacy

Slovenia's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by ZVOP-2, adopted five years after the GDPR took effect and read directly at ip-rs.si. ZVOP-2 Article 81 imposes a default prohibition on biometric processing, stronger than a bare GDPR Article 9 lawful-basis test, and Article 80 bans automated license-plate and biometric recognition on public surfaces, with fines at Article 105; a commentary-sourced first pass had speculated Article 80 carried a collective-redress mandate, but the primary text shows it is entirely about public video surveillance.

A reported data-localization requirement for sensitive-data categories rests on one uncorroborated, no-citation commentary claim and is not folded into this document's cross-border finding.

12 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

ZVOP-2 Chapter 4 (Articles 81-84) and Article 80, Biometric and Genetic Data

cite ZVOP-2, Arts. 80-84, 105 stage In effect since 2023-01-26 source ip-rs.si, ZVOP-2 Arts. 80-84, 105 (direct fetch, verbatim)

ZVOP-2 Part II Chapter 4, Processing of Personal Data Using Biometrics and Genetic Data, imposes a default prohibition rather than a bare General Data Protection Regulation (GDPR) Article 9 lawful-basis test, read verbatim: Article 81(1) states processing of biometric personal data contrary to this chapter's provisions is prohibited; Article 81(2) requires any other law authorizing biometric processing to itself set the conditions of use; Article 81(3) bars linking biometric-data collections with other collections, or enabling their GDPR Article 20 portability, except where another law provides otherwise.

Separately, in Chapter 3 (Video Surveillance), Article 80 bans, on public surfaces, automated license-plate-recognition systems and systems processing biometric personal data, backed by Article 105 fines of EUR 5,000 to 30,000. Article 80 is entirely a public-video-surveillance provision; it does not carry a collective-redress or representative-action mandate, correcting a commentary-sourced first pass that speculated it did.

No voiceprint-specific definition was located in the sections read; ZVOP-2's own Article 3 definitions section was not read in this pass.

What it asks of an app

Breach notification

GDPR Articles 33-34, Breach Notification

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2023-01-26 source GDPR Arts. 33-34

A controller must notify the Information Commissioner within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. Commentary describes a parallel channel under the Information Security Act for special processing; this session did not verify which categories of processing that extends to or its relationship to the General Data Protection Regulation (GDPR) Article 33 duty.

What it asks of an app

Comprehensive regime

Zakon o varstvu osebnih podatkov (ZVOP-2), Personal Data Protection Act

cite Zakon o varstvu osebnih podatkov (ZVOP-2), Uradni list RS, st. 163/22 stage In effect since 2023-01-26 source ip-rs.si, ZVOP-2 full text (direct fetch, 162,090 chars, not truncated)

Slovenia adopted ZVOP-2 in December 2022, five years after the General Data Protection Regulation (GDPR) took effect, replacing the original 2004 ZVOP-1.

Direct fetch of the Act's full text, hosted by the Information Commissioner, confirms the citation exactly as Uradni list RS, st. 163/22, and shows a later amendment by the Zakon o informacijski varnosti (Information Security Act, ZInfV-1, Uradni list RS, st. 40/25), in force 19 June 2025, whose Article 67 rewrote ZVOP-2 Article 23(1)'s terminology from security requirements to risk management measures as a NIS2-alignment update rather than a substantive privacy change.

Having legislated five years late rather than in the original 2018 rush, ZVOP-2 is noticeably more specific than a hurried transposition, most visibly in its dedicated biometric-data chapter.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c) stage In effect since 2023-01-26 source GDPR Arts. 44-49, 83(5)(c)

A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier.

A single commentary source separately claimed ZVOP-2 requires certain sensitive-data categories to remain within Slovenia's territory; this is flagged as unverified rather than folded into this jurisdiction's cross_border_restriction value, since intra-EEA localization is not what General Data Protection Regulation (GDPR) Chapter V regulates and no article citation or primary text supports the claim.

What it asks of an app

Data subject rights

GDPR Data-Subject Rights and ZVOP-2 Article 11, Judicial Protection

cite Regulation (EU) 2016/679, Arts. 12-22; ZVOP-2, Art. 11 stage In effect since 2023-01-26 source ip-rs.si, ZVOP-2 Art. 11 (direct fetch, verbatim)

General Data Protection Regulation (GDPR) Articles 12-22 apply directly. ZVOP-2 Article 11, read verbatim, confirms general judicial protection including damages, available to a data subject in Slovenia without first exhausting an administrative complaint to the Information Commissioner.

A single commentary source separately described an Article 80 representative-action mechanism; primary text shows ZVOP-2's own Article 80 is the public-video-surveillance provision above, not a representative-action provision, so if that commentary claim has any basis it describes GDPR's own Article 80 rather than a ZVOP-2 provision, and the Author should not attribute a representative-action power to "ZVOP-2 Article 80".

What it asks of an app

Enforcement supervision

Informacijski Pooblascenec Enforcement, GDPR Article 82, and ZVOP-2 Articles 114-116

cite Regulation (EU) 2016/679, Art. 82; ZVOP-2, Arts. 105, 114-116 stage In effect since 2023-01-26 source ip-rs.si, ZVOP-2 Arts. 105, 114-116 (direct fetch)

Informacijski pooblascenec (the Information Commissioner) is Slovenia's supervisory authority. ZVOP-2 Articles 114-115, read directly, require the misdemeanor-law fining authority to weigh proportionality alongside General Data Protection Regulation (GDPR) Article 83(1) factors, and Article 115 allows a fast-track fine above the statutory minimum.

Article 116 requires processing operations under Article 23(1), which names biometric, health, and criminal or misdemeanor-record data as triggering categories, to come into compliance within three years of the law's entry into force. GDPR Article 82 arms an individual with a direct private right of action, exercised through ZVOP-2 Article 11's judicial-protection route.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.