{
 "jurisdiction_id": "SK",
 "jurisdiction": "Slovakia",
 "url": "https://dataprotection.gi/jurisdictions/slovakia/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 30,
  "sub_modules": 57,
  "source_register": 8
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/slovakia/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Fully GDPR-aligned omnibus regime with an operational, EDPB-participating national DPA and clear implementing statute; no material derogation gaps identified in research.",
   "claims": [
    {
     "statement": "The Úrad na ochranu osobných údajov Slovenskej republiky is Slovakia's independent supervisory authority for data protection and is Slovakia's representative on the European Data Protection Board.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/contact/contact-dpas_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Regulation (EU) 2016/679 (GDPR) applies directly in Slovakia as the primary legal instrument governing personal data processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Act No. 18/2018 Coll. on Protection of Personal Data and on Amendments to Certain Acts is Slovakia's national implementing statute supplementing the GDPR, including DPIA rules in Sections 42-43.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/slovakia-data-protection-impact-assessment",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR's material scope in Slovakia covers processing of personal data by the private sector and most of the public sector, whether automated or structured manual processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/SK/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR applies to non-EU-established controllers/processors that offer goods or services to, or monitor the behaviour of, individuals in Slovakia/the EU, requiring an EU representative in certain circumstances.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Commission / EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52018DC0043",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Controllers/processors appointing a DPO in Slovakia are expected to notify DPO contact details to the ÚOOÚ SR via its notification channel, though GDPR abolished general processing-notification duties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/slovakia-uoou-launches-online-dpo-notification-system",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/slovakia/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "GDPR lawful bases and special-category rules apply without material derogation identified; children's digital-consent age threshold not independently confirmed for Slovakia.",
   "claims": [
    {
     "statement": "Processing of personal data in Slovakia is lawful only where at least one of the GDPR Art. 6(1) conditions is satisfied, and the legitimate-interest basis does not apply to processing carried out by public authorities in the performance of their tasks.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where processing is based on consent, the controller must be able to demonstrate that the data subject gave consent, and consent embedded in a broader written declaration must be clearly distinguishable, intelligible and easily accessible.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data subjects in Slovakia have the right to withdraw consent at any time, with withdrawal being as easy as giving consent and not affecting the lawfulness of prior processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR promotes pseudonymisation as a risk-mitigation technique, replacing identifying fields with artificial identifiers, but pseudonymised data remain personal data subject to GDPR.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/SK/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/slovakia/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Full GDPR rights catalogue and standard one-month response deadline apply without identified Slovak derogation.",
   "claims": [
    {
     "statement": "Data subjects in Slovakia have the right to obtain confirmation from the controller as to whether their personal data are being processed and, if so, to access such data and related processing details.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where a controller has made personal data public and is obliged to erase it, the controller must take reasonable steps, including technical measures, to inform other controllers processing the data that the data subject has requested erasure of links, copies or replications.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A data subject may obtain restriction of processing in specified circumstances, and, where processing is for scientific, historical research or statistical purposes, may object on grounds relating to their particular situation unless processing is necessary for a public-interest task.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR's data-portability right facilitates the transfer of personal data between service providers for consent- or contract-based, automated processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/SK/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/slovakia/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Full GDPR controller/processor obligations regime in force with national DPIA procedural supplementation; no Slovak-specific weakening identified.",
   "claims": [
    {
     "statement": "Controllers in Slovakia are responsible for, and must demonstrate, compliance with GDPR's data-protection principles under the accountability principle.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where a type of processing, especially using new technologies, is likely to result in high risk to individuals' rights and freedoms, the controller must carry out a DPIA before processing, with Slovak procedural mechanics specified in Act No. 18/2018 Coll. Sections 42-43.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/slovakia-data-protection-impact-assessment",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Controllers and processors in Slovakia must designate a DPO where required by GDPR Art. 37 (public authority status, large-scale systematic monitoring, or large-scale special-category/criminal-data processing).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Art. 30 records-of-processing obligations apply in Slovakia; SMEs are exempt unless processing is regular, likely to result in risk to data subjects, or involves special-category or criminal-conviction data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Commission / EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52018DC0043",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A processor in Slovakia may not engage a sub-processor without the controller's prior specific or general written authorisation, and processing must be governed by a binding contract or legal act specifying subject-matter, duration, nature and purpose of processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Controllers must notify the ÚOOÚ SR of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/slovakia/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Core EU adequacy/SCC/BCR framework applies uniformly, but Slovakia-specific TIA guidance, localisation rules, and national case examples were not independently located in this research pass.",
   "claims": [
    {
     "statement": "Slovak controllers and processors may transfer personal data to third countries using European Commission adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, approved codes of conduct/certification, or Art. 49 derogations, per the uniformly-applicable GDPR Chapter V regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Adequacy decisions determining whether third countries provide an adequate level of data protection for transfers originating in Slovakia are adopted exclusively by the European Commission under GDPR Art. 45 and apply uniformly across all EU Member States.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "red",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/slovakia/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "No comprehensive Slovakia-specific sectoral overlay evidence was located in this research pass; only the general EU ePrivacy baseline is confirmed.",
   "claims": [
    {
     "statement": "Directive 2002/58/EC (ePrivacy Directive) governs processing of personal data and privacy in the electronic-communications sector across the EU, including Slovakia, pending the proposed ePrivacy Regulation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/SK/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/slovakia/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Only the general EU cookie-consent baseline is confirmed; Slovakia-specific adtech instruments (dark patterns, GPC recognition, clean rooms, marketing suppression) were not independently located.",
   "claims": [
    {
     "statement": "Placement of cookies or similar trackers on end-user devices in Slovakia requires prior informed consent under the EU ePrivacy Directive framework, layered with GDPR consent standards where personal data are processed.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/SK/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/slovakia/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "GDPR Art. 22/9 baseline is confirmed; Slovakia-specific AI Act national competent authority designation and state-surveillance carve-out detail were not independently located.",
   "claims": [
    {
     "statement": "Data subjects in Slovakia have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them, subject to enumerated exceptions and safeguards including human intervention.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Biometric data processed for the purpose of uniquely identifying a natural person is treated as a special category of personal data in Slovakia under GDPR Art. 9, requiring a specific lawful condition beyond Art. 6.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/slovakia/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "GDPR Art. 8 default is confirmed; Slovakia's specific national digital-consent age (if derogated) and minor-profiling/education/dependent-adults specifics were not independently verified in this pass.",
   "claims": [
    {
     "statement": "In Slovakia, where an information-society service is offered directly to a child under the applicable digital age of consent (16 by GDPR default, absent a confirmed national derogation not below 13), processing of the child's personal data is lawful only where consent is given or authorised by the holder of parental responsibility.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/slovakia/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Core GDPR enforcement powers and fining ceiling are confirmed, and a significant Constitutional Court privacy ruling was located; however, no recent (12-month) ÚOOÚ SR enforcement-decision data or granular funding/headcount figures were independently retrieved.",
   "claims": [
    {
     "statement": "The ÚOOÚ SR may impose administrative fines calculated in accordance with EDPB harmonisation guidelines, which require that fines be effective, proportionate and dissuasive in each individual case, up to the maximum GDPR Art. 83 ceilings.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/system/files/2024-01/edpb_guidelines_042022_calculationofadministrativefines_sk_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data subjects in Slovakia have a direct right under GDPR Arts. 79 and 82 to an effective judicial remedy and to compensation for material or non-material damage resulting from GDPR infringement, enforceable before Slovak courts.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/SK/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Constitutional Court of the Slovak Republic struck down a legislative amendment requiring NGOs to publish identifying data of individual donors contributing over €5,000 per year, holding the blanket disclosure obligation disproportionate to privacy and data-protection rights.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/mass-disclosure-of-personal-data-and-privacy-lessons-from-slovakia-and-the-eu",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}