🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
SK · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 8 sources retrieved model claude-sonnet-5 ·

Slovakia

SK schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 30 claims · 8 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
30Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Lead Signal

The Úrad na ochranu osobných údajov Slovenskej republiky (ÚOOÚ SR) is confirmed as Slovakia's independent GDPR supervisory authority and its representative on the European Data Protection Board. Regulation (EU) 2016/679 applies directly in Slovakia as the primary legal instrument governing personal data processing. Act No. 18/2018 Coll. on Protection of Personal Data supplements GDPR as Slovakia's national implementing statute, including DPIA procedural rules in Sections 42-43. Taken together, these three anchor points establish Slovakia as a fully harmonised EU Member State operating the standard GDPR omnibus architecture, with no material derogation weakening the GDPR floor identified this cycle.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fully GDPR-aligned omnibus regime with an operational, EDPB-participating national DPA and clear implementing statute; no material derogation gaps identified in research.

Primary frameworkRegulation (EU) 2016/679 (GDPR), as implemented nationally by Act No. 18/2018 Coll. on Protection of Personal Data and on Amendments to Certain Acts
Traffic-light rationale — GreenFully GDPR-aligned omnibus regime with an operational, EDPB-participating national DPA and clear implementing statute; no material derogation gaps identified in research.

Sub-modules (5)

Regulator And AuthorityGreen

The ÚOOÚ SR is Slovakia's sole GDPR supervisory authority and EDPB member, with statutory investigative and corrective powers under GDPR Ch. VI-VIII as transposed via Act 18/2018.

Claims: CLM-SK-a1b2c3d4

Act And InstrumentsGreen

GDPR is the primary directly-applicable instrument; Act No. 18/2018 Coll. is the national supplementing/implementing statute, including provisions on DPIA (Sections 42-43) and ÚOOÚ procedure.

Claims: CLM-SK-b2c3d4e5, CLM-SK-c3d4e5f6

Material ScopeGreen

Material scope follows GDPR Art. 2 — covers automated and structured manual processing across private-sector and most public-sector activity.

Claims: CLM-SK-d4e5f6a7

Territorial ScopeGreen

Territorial scope follows GDPR Art. 3, including extraterritorial reach to non-EU controllers offering goods/services to, or monitoring, individuals in Slovakia/the EU.

Claims: CLM-SK-e5f6a7b8

Regulator Registration And FilingAmber

GDPR removed general notification-to-regulator duties; residual filing obligations in Slovakia are narrower, chiefly DPO-contact notification to ÚOOÚ SR.

Claims: CLM-SK-f6a7b8c9

Category narrative219 words

Slovakia is an EU Member State operating under direct application of the GDPR, supplemented by national implementing Act No. 18/2018 Coll. The competent supervisory authority is the Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic, 'ÚOOÚ SR'), based in Bratislava, which participates in the EDPB as Slovakia's representative body. <cite index="6-1">The Úrad na ochranu osobných údajov Slovenskej republiky is located at Galvaniho 7/B, 821 04 Bratislava, Slovakia</cite>. GDPR applies directly as a Regulation and governs both private-sector and most public-sector processing, with the national Act filling in derogations, procedural rules, and the DPO/ROPA administrative regime. <cite index="53-1">The GDPR protects persons where their personal data is processed by the private sector and most of the public sector</cite>. GDPR's territorial scope extends to non-EU-established controllers targeting or monitoring EU data subjects, and its material scope removed most prior general notification duties in favour of accountability. <cite index="45-15">The Regulation requires companies based outside the EU to apply the same rules as companies based in the EU if they are offering goods and services related to the personal data or are monitoring the behaviour of individuals in the Union</cite>. <cite index="1-12,1-13">The GDPR abolished most notification obligations and the associated costs</cite>, shifting the compliance model toward internal accountability and DPO-based registration rather than blanket regulator filing.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedEuropean Data Protection BoardThe Úrad na ochranu osobných údajov Slovenskej republiky is Slovakia's independent supervisory authority for data protection and is Slovakia's representative on the European Data Protection Board.
  2. ConfirmedEUR-LexRegulation (EU) 2016/679 (GDPR) applies directly in Slovakia as the primary legal instrument governing personal data processing.
  3. ConfirmedDataGuidanceAct No. 18/2018 Coll. on Protection of Personal Data and on Amendments to Certain Acts is Slovakia's national implementing statute supplementing the GDPR, including DPIA rules in Sections 42-43.
  4. ConfirmedEUR-LexGDPR's material scope in Slovakia covers processing of personal data by the private sector and most of the public sector, whether automated or structured manual processing.
  5. ConfirmedEuropean Commission / EUR-LexGDPR applies to non-EU-established controllers/processors that offer goods or services to, or monitor the behaviour of, individuals in Slovakia/the EU, requiring an EU representative in certain circumstances.
  6. ProbableDataGuidanceControllers/processors appointing a DPO in Slovakia are expected to notify DPO contact details to the ÚOOÚ SR via its notification channel, though GDPR abolished general processing-notification duties.

#

GDPR lawful bases and special-category rules apply without material derogation identified; children's digital-consent age threshold not independently confirmed for Slovakia.

Primary frameworkGDPR Arts. 6-9; Act No. 18/2018 Coll.
Traffic-light rationale — GreenGDPR lawful bases and special-category rules apply without material derogation identified; children's digital-consent age threshold not independently confirmed for Slovakia.

Sub-modules (4)

Lawful BasesGreen

The six GDPR Art. 6 lawful bases (consent, contract, legal obligation, vital interests, public interest/official authority, legitimate interests) apply directly in Slovakia; the legitimate-interest basis does not extend to public-authority processing carried out in performance of their tasks.

Claims: CLM-SK-a7b8c9d0

Special CategoriesAmber

Special-category data (health, biometric, genetic, ethnic origin, political opinion, sexual orientation, criminal data) are subject to the heightened Art. 9 regime; no Slovakia-specific broadening located in research.

Pseudonymisation And AnonymisationGreen

GDPR's pseudonymisation safe-harbour concept applies directly; pseudonymised data remain personal data.

Claims: CLM-SK-d0e1f2a3

Category narrative163 words

Slovakia applies the GDPR Art. 6 lawful-basis enumeration and Art. 9 special-category regime directly, with Act 18/2018 providing localized procedural detail. Consent must be an unambiguous, freely-given, specific and informed indication of wishes, revocable at any time. <cite index="56-14,56-15">If processing is based on consent, the controller must be able to demonstrate that the data subject has given consent to the processing of their personal data</cite>, and <cite index="56-19,56-20,56-21">the data subject has the right to withdraw consent at any time, and withdrawal does not affect the lawfulness of processing based on consent before its withdrawal</cite>. For children, Slovakia follows the GDPR default digital-consent age unless a national derogation is legislated. <cite index="56-27,56-28,56-29">Where a child is at least 16 years old, consent to information-society-service offers is lawful directly; below that age, national law may lower this threshold, but not below 13</cite>. No evidence was found of a Slovak-specific derogation lowering this age below the 16-year default; this is treated as an open question in self_audit.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedEUR-LexProcessing of personal data in Slovakia is lawful only where at least one of the GDPR Art. 6(1) conditions is satisfied, and the legitimate-interest basis does not apply to processing carried out by public authorities in the performance of their tasks.
  2. ConfirmedEUR-LexWhere processing is based on consent, the controller must be able to demonstrate that the data subject gave consent, and consent embedded in a broader written declaration must be clearly distinguishable, intelligible and easily accessible.
  3. ConfirmedEUR-LexData subjects in Slovakia have the right to withdraw consent at any time, with withdrawal being as easy as giving consent and not affecting the lawfulness of prior processing.
  4. ConfirmedEUR-LexGDPR promotes pseudonymisation as a risk-mitigation technique, replacing identifying fields with artificial identifiers, but pseudonymised data remain personal data subject to GDPR.

#

Full GDPR rights catalogue and standard one-month response deadline apply without identified Slovak derogation.

Primary frameworkGDPR Arts. 12-23; Act No. 18/2018 Coll.
Traffic-light rationale — GreenFull GDPR rights catalogue and standard one-month response deadline apply without identified Slovak derogation.

Sub-modules (5)

Access RightGreen

Data subjects may obtain confirmation of processing and access to their personal data and processing metadata under GDPR Art. 15.

Claims: CLM-SK-e1f2a3b4

Rectification And ErasureGreen

Rectification (Art. 16) and erasure/'right to be forgotten' (Art. 17) apply, including onward-notification duties to other controllers when data was made public.

Claims: CLM-SK-f2a3b4c5

Restriction And ObjectionGreen

Restriction (Art. 18) and objection, including objection to processing for scientific/historical/statistical research absent overriding public-interest necessity (Art. 21(6)), apply directly.

Claims: CLM-SK-a3b4c5d6

Data PortabilityGreen

The Art. 20 portability right facilitates transfer of personal data between service providers where processing is consent- or contract-based and automated.

Claims: CLM-SK-b4c5d6e7

Deadlines And Response WindowsAmber

GDPR's standard one-month response window (extendable by two further months for complex/numerous requests) applies; no Slovak-specific shortening identified.

Category narrative150 words

GDPR's full data-subject rights catalogue (access, rectification, erasure, restriction, objection, portability) applies directly in Slovakia via Act 18/2018 procedural transposition. <cite index="9-2">Companies and organisations will have to promptly inform individuals of serious data breaches, and the clearer right to erasure ('right to be forgotten') allows deletion of data where there is no legitimate ground for retaining it</cite>. <cite index="10-5,10-6">A data subject has the right to obtain restriction of processing from the controller in specified cases, and where processing has been restricted such data may only be processed with the data subject's consent or for establishing, exercising or defending legal claims, protecting another's rights, or for important EU/Member State public-interest reasons</cite>. <cite index="10-23,10-26">A data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects them, subject to safeguards including the right to obtain human intervention</cite>.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedEUR-LexData subjects in Slovakia have the right to obtain confirmation from the controller as to whether their personal data are being processed and, if so, to access such data and related processing details.
  2. ConfirmedEUR-LexWhere a controller has made personal data public and is obliged to erase it, the controller must take reasonable steps, including technical measures, to inform other controllers processing the data that the data subject has requested erasure of links, copies or replications.
  3. ConfirmedEUR-LexA data subject may obtain restriction of processing in specified circumstances, and, where processing is for scientific, historical research or statistical purposes, may object on grounds relating to their particular situation unless processing is necessary for a public-interest task.
  4. ConfirmedEUR-LexGDPR's data-portability right facilitates the transfer of personal data between service providers for consent- or contract-based, automated processing.

#

Full GDPR controller/processor obligations regime in force with national DPIA procedural supplementation; no Slovak-specific weakening identified.

Primary frameworkGDPR Arts. 5, 24-39; Act No. 18/2018 Coll. Sections 42-43
Traffic-light rationale — GreenFull GDPR controller/processor obligations regime in force with national DPIA procedural supplementation; no Slovak-specific weakening identified.

Sub-modules (7)

Accountability And DpiaGreen

Accountability principle (Art. 5(2)/24) and DPIA triggers (Art. 35) apply directly, with Slovak procedural detail in Act 18/2018 §§42-43.

Claims: CLM-SK-c5d6e7f8, CLM-SK-d6e7f8a9

Dpo RequirementsGreen

GDPR Art. 37 DPO-appointment thresholds (public authorities; large-scale regular/systematic monitoring; large-scale special-category/criminal-data processing) apply; Slovak Act 18/2018 supplies notification procedure to ÚOOÚ SR.

Claims: CLM-SK-e7f8a9b0

Ropa RequirementsGreen

Records-of-processing obligations under Art. 30 apply, with an SME exemption unless processing is regular, risk-bearing, or involves special categories/criminal data.

Claims: CLM-SK-f8a9b0c1

Joint Controller ArrangementsGreen

Art. 26 joint-controller and Art. 28 processor-contract rules apply directly; processor sub-engagement requires controller authorisation.

Claims: CLM-SK-a9b0c1d2

Security MeasuresGreen

Art. 32 security-of-processing obligations (pseudonymisation, encryption, resilience, testing) apply directly with no Slovak derogation identified.

Breach NotificationGreen

Breach notification to the regulator within 72 hours of awareness (where risk exists), and to data subjects without undue delay for high-risk breaches, applies directly.

Claims: CLM-SK-b0c1d2e3

Retention And DisposalAmber

Storage-limitation principle (Art. 5(1)(e)) applies; no Slovakia-specific statutory retention schedule for general personal data was located beyond sector-specific archival laws.

Category narrative206 words

GDPR's accountability regime (Art. 5(2), 24), DPIA regime (Art. 35, with Act 18/2018 Sections 42-43 providing national procedural detail), DPO regime (Art. 37-39), processor rules (Art. 28), security (Art. 32) and breach notification (Art. 33-34) all apply directly. <cite index="56-8">The controller is responsible for, and must be able to demonstrate, compliance with the accountability principle</cite>. <cite index="55-4,55-5">Where processing, particularly using new technologies, is likely to result in high risk to individuals' rights and freedoms, the controller must carry out a data protection impact assessment prior to processing, and a single assessment may cover a set of similar high-risk operations</cite>, and <cite index="55-6">the controller must consult the data protection officer, where one has been designated, during the DPIA</cite>. Slovak DPIA procedure is further specified in <cite index="27-3,27-4">Sections 42 and 43 of Act No. 18/2018 Coll. on Protection of Personal Data and on Amendments to certain Acts</cite>. On processors, <cite index="58-12,58-13">where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures so that processing meets GDPR requirements and protects data subject rights</cite>, and <cite index="58-14,58-15">a processor shall not engage another processor without prior specific or general written authorisation of the controller</cite>.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedEUR-LexControllers in Slovakia are responsible for, and must demonstrate, compliance with GDPR's data-protection principles under the accountability principle.
  2. ConfirmedDataGuidanceWhere a type of processing, especially using new technologies, is likely to result in high risk to individuals' rights and freedoms, the controller must carry out a DPIA before processing, with Slovak procedural mechanics specified in Act No. 18/2018 Coll. Sections 42-43.
  3. ConfirmedEUR-LexControllers and processors in Slovakia must designate a DPO where required by GDPR Art. 37 (public authority status, large-scale systematic monitoring, or large-scale special-category/criminal-data processing).
  4. ConfirmedEuropean Commission / EUR-LexGDPR Art. 30 records-of-processing obligations apply in Slovakia; SMEs are exempt unless processing is regular, likely to result in risk to data subjects, or involves special-category or criminal-conviction data.
  5. ConfirmedEUR-LexA processor in Slovakia may not engage a sub-processor without the controller's prior specific or general written authorisation, and processing must be governed by a binding contract or legal act specifying subject-matter, duration, nature and purpose of processing.
  6. ConfirmedEUR-LexControllers must notify the ÚOOÚ SR of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

#

Core EU adequacy/SCC/BCR framework applies uniformly, but Slovakia-specific TIA guidance, localisation rules, and national case examples were not independently located in this research pass.

Primary frameworkGDPR Arts. 44-50
Traffic-light rationale — AmberCore EU adequacy/SCC/BCR framework applies uniformly, but Slovakia-specific TIA guidance, localisation rules, and national case examples were not independently located in this research pass.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Ch. V mechanisms (adequacy, SCCs, BCRs, codes of conduct/certification, Art. 49 derogations) apply uniformly in Slovakia as in all EU Member States.

Claims: CLM-SK-c1d2e3f4

Adequacy ReceivedGreen

Slovakia does not independently receive adequacy findings; as an EU Member State it benefits from reciprocal EU adequacy arrangements (e.g., with the UK) negotiated at Union level.

Adequacy GrantedGreen

Adequacy decisions covering transfers from Slovakia to third countries are issued exclusively by the European Commission and apply EU-wide; Slovakia has no independent national adequacy-granting power.

Claims: CLM-SK-d2e3f4a5

Sccs And BcrsGreen

Standard Contractual Clauses and Binding Corporate Rules approved under the EU consistency mechanism are directly usable by Slovak controllers/processors.

Transfer Impact AssessmentAmber

TIA expectations (post-Schrems II) apply per EDPB guidance uniformly; no Slovakia-specific TIA guidance located.

Absence provenance: not recorded. Searched: Ú, O, O, Ú, , S, R, , t, r, a, n, s, f, e, r, , i, m, p, a, c, t, , a, s, s, e, s, s, m, e, n, t, , g, u, i, d, a, n, c, e, , S, c, h, r, e, m, s, , I, I.

Data LocalisationAmber

No general personal-data localisation mandate for Slovakia was identified in research beyond standard EU public-sector/national-security carve-outs.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , d, a, t, a, , l, o, c, a, l, i, s, a, t, i, o, n, , r, e, q, u, i, r, e, m, e, n, t, , p, e, r, s, o, n, a, l, , d, a, t, a, , 2, 0, 2, 5, , 2, 0, 2, 6.

Category narrative89 words

As an EU Member State, Slovakia relies on the GDPR Chapter V transfer regime: adequacy decisions issued by the European Commission apply uniformly across the EU/EEA (Slovakia does not issue independent national adequacy decisions), alongside SCCs, BCRs, and Art. 49 derogations. No Slovakia-specific data-localisation mandate for general personal data was identified in research; sector-specific localisation (e.g., certain public-sector or defence data) may exist but was not independently confirmed. This module is populated primarily from the general EU/GDPR baseline given the absence of Slovakia-specific transfer guidance in the sources retrieved.

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. ConfirmedEUR-LexSlovak controllers and processors may transfer personal data to third countries using European Commission adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, approved codes of conduct/certification, or Art. 49 derogations, per the uniformly-applicable GDPR Chapter V regime.
  2. ConfirmedEUR-LexAdequacy decisions determining whether third countries provide an adequate level of data protection for transfers originating in Slovakia are adopted exclusively by the European Commission under GDPR Art. 45 and apply uniformly across all EU Member States.

#

No comprehensive Slovakia-specific sectoral overlay evidence was located in this research pass; only the general EU ePrivacy baseline is confirmed.

Traffic-light rationale — RedNo comprehensive Slovakia-specific sectoral overlay evidence was located in this research pass; only the general EU ePrivacy baseline is confirmed.

Sub-modules (7)

Financial Sector OverlayRed

No Slovakia-specific banking-secrecy/GDPR interaction guidance was located in this pass.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , b, a, n, k, i, n, g, , s, e, c, r, e, c, y, , G, D, P, R, , f, i, n, a, n, c, i, a, l, , s, e, c, t, o, r, , p, e, r, s, o, n, a, l, , d, a, t, a, , o, v, e, r, l, a, y.

Health Sector OverlayRed

No Slovakia-specific health-data overlay statute (e.g., health records act interaction with GDPR) was independently retrieved.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , h, e, a, l, t, h, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , a, c, t, , G, D, P, R, , o, v, e, r, l, a, y.

Telecoms And EprivacyAmber

The EU ePrivacy Directive 2002/58/EC applies as the baseline electronic-communications privacy instrument across the EU including Slovakia, pending the still-unadopted ePrivacy Regulation.

Claims: CLM-SK-e3f4a5b6

Employment DataRed

No Slovakia-specific employment-data code was independently retrieved in this pass.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , L, a, b, o, u, r, , C, o, d, e, , e, m, p, l, o, y, e, e, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , G, D, P, R.

Credit And ScoringRed

No Slovakia-specific credit-scoring statute was independently retrieved.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , c, r, e, d, i, t, , s, c, o, r, i, n, g, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , r, e, g, u, l, a, t, i, o, n.

EducationRed

No Slovakia-specific education-sector data rule was independently retrieved beyond general GDPR applicability.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , e, d, u, c, a, t, i, o, n, , s, e, c, t, o, r, , s, t, u, d, e, n, t, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , G, D, P, R.

InsuranceRed

No Slovakia-specific insurance-sector data rule was independently retrieved.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , i, n, s, u, r, a, n, c, e, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , G, D, P, R, , o, v, e, r, l, a, y.

Category narrative62 words

No Slovakia-specific sectoral overlay documentation (banking-secrecy interaction, health-sector rules, telecoms/ePrivacy transposition specifics, employment-code provisions, credit-scoring rules, education or insurance-sector data rules) was independently retrieved in this research pass beyond the general EU ePrivacy Directive (2002/58/EC) baseline, which is referenced as applicable across the EU including Slovakia. This module is therefore populated conservatively with an explicit gap declaration rather than fabricated sector detail.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ProbableEUR-LexDirective 2002/58/EC (ePrivacy Directive) governs processing of personal data and privacy in the electronic-communications sector across the EU, including Slovakia, pending the proposed ePrivacy Regulation.

#

Only the general EU cookie-consent baseline is confirmed; Slovakia-specific adtech instruments (dark patterns, GPC recognition, clean rooms, marketing suppression) were not independently located.

Primary frameworkDirective 2002/58/EC (ePrivacy); GDPR (where personal data involved)
Traffic-light rationale — RedOnly the general EU cookie-consent baseline is confirmed; Slovakia-specific adtech instruments (dark patterns, GPC recognition, clean rooms, marketing suppression) were not independently located.

Sub-modules (6)

Cookies And TrackersAmber

Cookie/tracker placement requires prior informed consent under the ePrivacy Directive's transposition, layered with GDPR consent standards where personal data are processed.

Claims: CLM-SK-f4a5b6c7

Dark PatternsRed

No Slovakia-specific dark-pattern prohibition statute was independently retrieved.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , d, a, r, k, , p, a, t, t, e, r, n, s, , c, o, n, s, e, n, t, , G, D, P, R, , Ú, O, O, Ú, , g, u, i, d, a, n, c, e.

Opt Out SignalsRed

No Slovakia-specific Global Privacy Control or DAA-equivalent opt-out-signal recognition was independently retrieved.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , G, l, o, b, a, l, , P, r, i, v, a, c, y, , C, o, n, t, r, o, l, , r, e, c, o, g, n, i, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n.

Clean Rooms And DcrRed

No Slovakia-specific clean-room/data-collaboration-room guidance was independently retrieved.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , d, a, t, a, , c, l, e, a, n, , r, o, o, m, , G, D, P, R, , g, u, i, d, a, n, c, e.

Cross Context AdvertisingAmber

No CPRA-style 'sale'/'share' concept exists in Slovakia; cross-context advertising is governed generically by GDPR consent/legitimate-interest analysis.

Direct MarketingAmber

Direct marketing requires a lawful basis (typically consent or legitimate interest with opt-out) under GDPR; no Slovakia-specific suppression-list mechanism was independently retrieved.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , d, i, r, e, c, t, , m, a, r, k, e, t, i, n, g, , c, o, n, s, e, n, t, , s, u, p, p, r, e, s, s, i, o, n, , l, i, s, t, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n.

Category narrative54 words

Cookie/tracker consent in Slovakia follows the EU ePrivacy Directive's consent requirement as implemented nationally, overlaid by GDPR consent standards where personal data are involved. No Slovakia-specific dark-pattern prohibition statute, Global-Privacy-Control recognition, clean-room framework, or direct-marketing suppression-list mechanism was independently retrieved in this research pass; this is flagged as a gap rather than assumed absent.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ProbableEUR-LexPlacement of cookies or similar trackers on end-user devices in Slovakia requires prior informed consent under the EU ePrivacy Directive framework, layered with GDPR consent standards where personal data are processed.

#

GDPR Art. 22/9 baseline is confirmed; Slovakia-specific AI Act national competent authority designation and state-surveillance carve-out detail were not independently located.

Primary frameworkGDPR Art. 9, Art. 22; EU AI Act (Regulation (EU) 2024/1689) interface
Traffic-light rationale — AmberGDPR Art. 22/9 baseline is confirmed; Slovakia-specific AI Act national competent authority designation and state-surveillance carve-out detail were not independently located.

Sub-modules (6)

Profiling RestrictionsGreen

Art. 22 restricts solely-automated decisions with legal or similarly significant effects, subject to enumerated exceptions and safeguards.

Claims: CLM-SK-a5b6c7d8

Automated Decision Making TransparencyGreen

Controllers must provide meaningful information about the logic involved in automated decision-making under Arts. 13-15, alongside Art. 22 safeguards.

Ai Risk AssessmentsAmber

The EU AI Act layers risk-based obligations (including interaction with GDPR DPIAs) atop GDPR for high-risk AI systems; Slovak national AI Act implementation/competent-authority detail was not independently confirmed in this pass.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , A, I, , A, c, t, , n, a, t, i, o, n, a, l, , c, o, m, p, e, t, e, n, t, , a, u, t, h, o, r, i, t, y, , d, e, s, i, g, n, a, t, i, o, n, , 2, 0, 2, 5, , 2, 0, 2, 6.

Biometric RegimeGreen

Biometric data used for unique identification purposes is a GDPR Art. 9 special category, requiring an Art. 9(2) condition for lawful processing.

Claims: CLM-SK-b6c7d8e9

Genetic DataGreen

Genetic data is likewise a GDPR Art. 9 special category subject to heightened protection.

State Surveillance CarveoutsAmber

No Slovakia-specific state-surveillance/national-security carve-out statute was independently retrieved in this pass; GDPR Art. 23 permits Member State restrictions for national security, defence and public security subject to necessity/proportionality.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , n, a, t, i, o, n, a, l, , s, e, c, u, r, i, t, y, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , c, a, r, v, e, -, o, u, t, , G, D, P, R, , A, r, t, i, c, l, e, , 2, 3.

Category narrative129 words

GDPR Art. 22 profiling/ADM restrictions apply directly in Slovakia. <cite index="10-23,10-26">A data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, and the controller must implement suitable measures including the right to obtain human intervention, to express one's point of view and to contest the decision</cite>. Biometric and genetic data are treated as special categories under Art. 9. As an EU Member State, Slovakia is also subject to the EU AI Act's risk-based governance layer, and its national data protection authority interfaces with AI Act obligations per EDPB/EDPS statements on the intersecting roles of DPAs in AI oversight. No Slovakia-specific state-surveillance carve-out statute was independently retrieved in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. ConfirmedEUR-LexData subjects in Slovakia have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them, subject to enumerated exceptions and safeguards including human intervention.
  2. ConfirmedEUR-LexBiometric data processed for the purpose of uniquely identifying a natural person is treated as a special category of personal data in Slovakia under GDPR Art. 9, requiring a specific lawful condition beyond Art. 6.

#

GDPR Art. 8 default is confirmed; Slovakia's specific national digital-consent age (if derogated) and minor-profiling/education/dependent-adults specifics were not independently verified in this pass.

Primary frameworkGDPR Art. 8
Traffic-light rationale — AmberGDPR Art. 8 default is confirmed; Slovakia's specific national digital-consent age (if derogated) and minor-profiling/education/dependent-adults specifics were not independently verified in this pass.

Sub-modules (5)

Age VerificationAmber

The default GDPR digital-consent age is 16, absent a national derogation (permitted down to a floor of 13); Slovakia's specific national figure was not independently confirmed.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , G, D, P, R, , A, r, t, i, c, l, e, , 8, , a, g, e, , o, f, , c, o, n, s, e, n, t, , c, h, i, l, d, r, e, n, , d, e, r, o, g, a, t, i, o, n.

Claims: CLM-SK-c7d8e9f0

Minor Profiling BansRed

No Slovakia-specific statutory ban on profiling of minors beyond GDPR's general Art. 22/recital 71 caution was independently retrieved.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , m, i, n, o, r, , p, r, o, f, i, l, i, n, g, , b, a, n, , c, h, i, l, d, r, e, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n.

Education SettingsRed

No Slovakia-specific education-sector children's-data statute was independently retrieved.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , s, c, h, o, o, l, , s, t, u, d, e, n, t, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, t, a, t, u, t, e.

Dependent AdultsRed

No Slovakia-specific dependent-adults data-protection statute beyond general capacity/guardianship civil law was independently retrieved.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, s, , i, n, c, a, p, a, c, i, t, a, t, e, d, , p, e, r, s, o, n, s, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n.

Category narrative115 words

GDPR Art. 8's digital-consent age threshold applies as the default in Slovakia. <cite index="56-27,56-28,56-29">Where GDPR Art. 6(1)(a) applies to an offer of information-society services directly to a child, processing is lawful only if the child is at least 16 years old; where the child is younger, consent must be given or authorised by the holder of parental responsibility, and Member States may set a lower age by law provided it is not below 13</cite>. Research did not independently confirm whether Slovakia has legislated a national derogation lowering this threshold below 16; this is flagged as an open question. No Slovakia-specific minor-profiling ban, education-settings-specific statute, or dependent-adults protection regime beyond general capacity/guardianship law was independently retrieved.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ProbableEUR-LexIn Slovakia, where an information-society service is offered directly to a child under the applicable digital age of consent (16 by GDPR default, absent a confirmed national derogation not below 13), processing of the child's personal data is lawful only where consent is given or authorised by the holder of parental responsibility.

#

Core GDPR enforcement powers and fining ceiling are confirmed, and a significant Constitutional Court privacy ruling was located; however, no recent (12-month) ÚOOÚ SR enforcement-decision data or granular funding/headcount figures were independently retrieved.

Primary frameworkGDPR Arts. 58, 77-84
Traffic-light rationale — AmberCore GDPR enforcement powers and fining ceiling are confirmed, and a significant Constitutional Court privacy ruling was located; however, no recent (12-month) ÚOOÚ SR enforcement-decision data or granular funding/headcount figures were independently retrieved.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

ÚOOÚ SR holds GDPR Art. 58 investigative/corrective powers and may impose administrative fines up to the higher of €20 million or 4% of global annual turnover under Art. 83, calculated per EDPB fine-calculation guidelines.

Claims: CLM-SK-d8e9f0a1

Enforcement Activity IndexRed

No specific ÚOOÚ SR fine/decision data from the past 12 months was independently retrieved in this research pass.

Absence provenance: not recorded. Searched: Ú, r, a, d, , n, a, , o, c, h, r, a, n, u, , o, s, o, b, n, ý, c, h, , ú, d, a, j, o, v, , S, R, , p, o, k, u, t, a, , 2, 0, 2, 5, , 2, 0, 2, 6, ;, , S, l, o, v, a, k, i, a, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , a, u, t, h, o, r, i, t, y, , f, i, n, e, , d, e, c, i, s, i, o, n.

Regulator Funding And CapacityRed

No specific ÚOOÚ SR budget/headcount figures were independently retrieved in this research pass.

Absence provenance: not recorded. Searched: Ú, O, O, Ú, , S, R, , r, o, z, p, o, č, e, t, , z, a, m, e, s, t, n, a, n, c, i, , k, a, p, a, c, i, t, a.

Collective Redress And Class ActionsAmber

EU-level collective-redress mechanisms (Representative Actions Directive) apply as the baseline; Slovakia-specific transposition detail was not independently confirmed.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , R, e, p, r, e, s, e, n, t, a, t, i, v, e, , A, c, t, i, o, n, s, , D, i, r, e, c, t, i, v, e, , t, r, a, n, s, p, o, s, i, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , c, o, l, l, e, c, t, i, v, e, , r, e, d, r, e, s, s.

Private Right Of ActionGreen

GDPR Arts. 79 and 82 grant data subjects a direct judicial remedy and compensation right against controllers/processors, applicable in Slovak courts.

Claims: CLM-SK-e9f0a1b2

Recent Developments 180DAmber

The most significant recent Slovak privacy-adjacent development located in research is the Constitutional Court's ruling striking down a mandatory NGO-donor-disclosure amendment as disproportionate to privacy rights; exact ruling date and 180-day currency relative to the 2026-08-05 run date were not independently pinned down.

Absence provenance: not recorded. Searched: S, l, o, v, a, k, i, a, , C, o, n, s, t, i, t, u, t, i, o, n, a, l, , C, o, u, r, t, , N, G, O, , d, o, n, o, r, , d, i, s, c, l, o, s, u, r, e, , r, u, l, i, n, g, , d, a, t, e, ;, , S, l, o, v, a, k, i, a, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , n, e, w, s, , 2, 0, 2, 6.

Claims: CLM-SK-f0a1b2c3

Category narrative195 words

GDPR Arts. 58 and 83 grant the ÚOOÚ SR investigative, corrective and administrative-fining powers (up to the higher of €20 million or 4% of global annual turnover for the most serious infringements), consistent with the EU-wide fining framework. <cite index="31-13,31-14">The calculation of the fine amount is within the competence of the supervisory authority and is governed by rules set out in the GDPR, which requires that in each individual case the fine be effective, proportionate and dissuasive</cite>. A notable Slovak constitutional-law development relevant to enforcement/redress is the Constitutional Court's intervention in a data-transparency dispute: <cite index="25-7,25-8">the Constitutional Court of the Slovak Republic struck down an NGO donor-disclosure amendment, ruling that the blanket and broad obligation to disclose all donor data was disproportionate and unbalanced</cite>, and <cite index="25-9">the court emphasized that even a strong public interest in transparency cannot automatically outweigh the right to privacy and personal data protection</cite>. No specific ÚOOÚ SR fine decisions from the last 12 months were independently retrieved in this research pass; this is flagged as a gap. Collective-redress mechanisms follow the EU Representative Actions Directive baseline; a Slovakia-specific private-right-of-action statute beyond GDPR Art. 79/82 court-access rights was not independently confirmed.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedEuropean Data Protection BoardThe ÚOOÚ SR may impose administrative fines calculated in accordance with EDPB harmonisation guidelines, which require that fines be effective, proportionate and dissuasive in each individual case, up to the maximum GDPR Art. 83 ceilings.
  2. ConfirmedEUR-LexData subjects in Slovakia have a direct right under GDPR Arts. 79 and 82 to an effective judicial remedy and to compensation for material or non-material damage resulting from GDPR infringement, enforceable before Slovak courts.
  3. ProbableIAPPThe Constitutional Court of the Slovak Republic struck down a legislative amendment requiring NGOs to publish identifying data of individual donors contributing over €5,000 per year, holding the blanket disclosure obligation disproportionate to privacy and data-protection rights.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Slovakia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 30 claim(s), 8 source(s) in the cumulative register.