Law / Slovakia

Slovakia

privacy

Slovakia gives the General Data Protection Regulation (GDPR) domestic effect through Act No. 18/2018 Coll. on the Protection of Personal Data. This document rests entirely on commentary (CMS, DLA Piper): slov-lex.sk, the official legislative portal, served only a JavaScript navigation shell to every fetch method tried, confirmed twice across this wave and a third time in this author pass, and no other official source of the Act's text was reachable.

No employment-specific biometric provision was found in either commentary source, a genuine gap rather than a confirmed absence. Every substantive claim here should be treated as unverified until a primary-source read becomes possible.

12 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

GDPR Articles 33-34, Breach Notification

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source GDPR Arts. 33-34

A controller must notify the Office for Personal Data Protection of the Slovak Republic within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. CMS's commentary states there are no derogations from the General Data Protection Regulation (GDPR) for this dimension in Slovakia; no primary text was read.

What it asks of an app

Comprehensive regime

Act on the Protection of Personal Data

cite Zakon c. 18/2018 Z. z. o ochrane osobnych udajov a o zmene a doplneni niektorych zakonov stage In effect since 2018-05-25 source CMS and DLA Piper commentary only

Slovakia gives the General Data Protection Regulation (GDPR) domestic effect through Act No. 18/2018 Coll. on the Protection of Personal Data, effective 25 May 2018. This session could not read the Act's own text at all: slov-lex.sk, the official legislative portal, served only a JavaScript navigation shell to both a direct fetch and a crawler-based reader, confirmed on repeated attempts across the wave.

Every finding below rests on two commentary sources (CMS's expert guide and DLA Piper's Data Protection Laws of the World) rather than a primary-source read, and should be treated as unconfirmed until someone reads the Act directly.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c) stage In effect since 2018-05-25 source GDPR Arts. 44-49, 83(5)(c)

A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. DLA Piper's commentary confirms no further Slovak derogation, describing free movement of personal data between Slovakia and other EU member states; no primary text was read.

What it asks of an app

Data subject rights

GDPR Articles 12-22, Data-Subject Rights

cite Regulation (EU) 2016/679, Arts. 12-22 stage In effect since 2018-05-25 source GDPR Arts. 12-22

General Data Protection Regulation (GDPR) Articles 12-22 apply directly. No Slovak-specific derogation was found in either commentary source consulted, but this was not exhaustively checked article by article and no primary text was read.

What it asks of an app

Enforcement supervision

Office for Personal Data Protection Enforcement and GDPR Article 82

cite Regulation (EU) 2016/679, Arts. 82-83 stage In effect since 2018-05-25 source GDPR Arts. 82-83

Urad na ochranu osobnych udajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic) is the supervisory authority, confirmed by both commentary sources; fine amounts and detailed procedure were not independently checked beyond the General Data Protection Regulation (GDPR) baseline.

GDPR Article 82 arms an individual with a direct private right of action; DLA Piper states Slovak private rights of action derive from Article 82 without further elaboration, and no Slovak transposition of the EU Representative Actions Directive was found or ruled out in this pass.

What it asks of an app

Sensitive categories

GDPR Article 9 and Act Section 78, National Birth Number

cite Regulation (EU) 2016/679, Art. 9; Zakon c. 18/2018 Z. z., section 78 stage Enacted source CMS and DLA Piper commentary only

General Data Protection Regulation (GDPR) Article 9(1) treats biometric data processed for unique identification as a special category. Commentary (CMS) quotes the Act as permitting biometric, genetic, and health data processing on the basis of a special regulation or an international agreement, a general enabling clause rather than a substantive biometric-specific carve-out; no employment-biometric consent or works-council rule was found in either commentary source.

A separate, more specific commentary-sourced finding, Section 78, protects the Slovak birth number (rodne cislo): explicit consent is required to process it, and public disclosure is prohibited unless the data subject discloses it themself. None of this was independently verified against the Act's own text this session.

No commencement date is recorded for this instrument: this document rests entirely on commentary with no primary-source text read, and status is downgraded from in_effect to enacted rather than asserting an unconfirmed effective date.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.