Skip to content

GDPR / ZVOP-2

Regulation (EU) 2016/679 (GDPR) and the Personal Data Protection Act (ZVOP-2)

The GDPR governs the processing of personal data in the EU and applies to any organization processing personal data, regardless of size. In Slovenia it is supplemented by ZVOP-2, in force since 26 January 2023.

Who it applies to

  • Any organization processing personal data — there is no size threshold.
  • Also organizations outside the EU offering goods or services to, or monitoring, people in the EU.
  • Both controllers and processors of personal data.

Key obligations

  • A lawful basis for processing and rules on consent (Articles 5–7).
  • Transparency and data subject rights (Articles 12–22).
  • Records of processing activities (Article 30) and security of processing (Article 32).
  • Notification of a personal data breach to the supervisory authority without undue delay and no later than 72 hours (Article 33).
  • Communication to data subjects where the risk is high (Article 34).
  • Data protection impact assessments (Article 35) and designation of a data protection officer where required (Article 37).
  • Under ZVOP-2, a data protection officer is mandatory for all public-sector entities.

Penalties

Up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher, for controller and processor obligations; and up to EUR 20 million or 4% of turnover for infringements of processing principles, data subject rights and transfer rules (Article 83).

Status in Slovenia

ZVOP-2 was published in Official Gazette RS No. 163/22. National specifics include a 15-year age threshold for children's consent to information society services, protection of deceased persons' data, restrictions on linking databases via identification numbers, and a mandatory data protection officer in the public sector. The supervisory authority is the Information Commissioner.

Important notice

This is general information, not legal advice. The content is verified against primary sources (EUR-Lex, Official Gazette RS), but regulations change and their application depends on each organization's circumstances. Consult a legal professional for a binding assessment.

Sources and standards

  1. 01Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex, 2016
  2. 02Slovenian Personal Data Protection Act (ZVOP-2), Official Gazette RS No. 163/22Uradni list RS, 2022
  3. 03Information Commissioner of the Republic of SloveniaInformacijski pooblaščenec RS

Ready to strengthen security across your organization?

Contact us to see how our turnkey solutions can build a safer, more resilient organization.