🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
SK v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing8 sources retrieved model claude-sonnet-5 · 2026-08-05

Slovakia

SK schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 30 claims · 14 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
30Claimsbaseline..claims[]
5Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

The European Commission adopted Implementing Decision (EU) 2025/1225 on 24 June 2025, amending the United Kingdom's adequacy decision under the Law Enforcement Directive, Directive (EU) 2016/680. This is a supranational development with direct bearing on Slovakia's cross-border data-transfer position, since Slovak controllers and processors transferring personal data to the United Kingdom for law-enforcement-adjacent purposes rely on the same EU-wide adequacy finding as every other Member State. Separately, a draft amendment to Act No. 18/2018 Coll. on the protection of personal data has been reported that would remove the Office for Personal Data Protection's (UOOU) discretion not to impose a fine, extend the chair's term of office from five to seven years, remove the existing two-term limit, and introduce a new deepfake-related offence, with a reported target effective date of 1 January 2026. The enactment status of this draft has not been confirmed against an official legislative-process source this cycle, and it rests on a single secondary commentary source, so it is reported here as a proposal under consideration rather than as settled law.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fully GDPR-aligned omnibus regime with an operational, EDPB-participating national DPA and clear implementing statute; no material derogation gaps identified in research.

Primary frameworkRegulation (EU) 2016/679 (GDPR), as implemented nationally by Act No. 18/2018 Coll. on Protection of Personal Data and on Amendments to Certain Acts
Traffic-light rationale — GreenFully GDPR-aligned omnibus regime with an operational, EDPB-participating national DPA and clear implementing statute; no material derogation gaps identified in research.

Sub-modules (5)

Regulator And AuthorityGreen

The ÚOOÚ SR is Slovakia's sole GDPR supervisory authority and EDPB member, with statutory investigative and corrective powers under GDPR Ch. VI-VIII as transposed via Act 18/2018.

Claims (1):

  • The Úrad na ochranu osobných údajov Slovenskej republiky is Slovakia's independent supervisory authority for data protection and is Slovakia's representative on the European Data Protection Board.

Act And InstrumentsGreen

GDPR is the primary directly-applicable instrument; Act No. 18/2018 Coll. is the national supplementing/implementing statute, including provisions on DPIA (Sections 42-43) and ÚOOÚ procedure.

Claims (2):

  • Regulation (EU) 2016/679 (GDPR) applies directly in Slovakia as the primary legal instrument governing personal data processing.
  • Act No. 18/2018 Coll. on Protection of Personal Data and on Amendments to Certain Acts is Slovakia's national implementing statute supplementing the GDPR, including DPIA rules in Sections 42-43.

Material ScopeGreen

Material scope follows GDPR Art. 2 — covers automated and structured manual processing across private-sector and most public-sector activity.

Claims (1):

  • GDPR's material scope in Slovakia covers processing of personal data by the private sector and most of the public sector, whether automated or structured manual processing.

Territorial ScopeGreen

Territorial scope follows GDPR Art. 3, including extraterritorial reach to non-EU controllers offering goods/services to, or monitoring, individuals in Slovakia/the EU.

Claims (1):

  • GDPR applies to non-EU-established controllers/processors that offer goods or services to, or monitor the behaviour of, individuals in Slovakia/the EU, requiring an EU representative in certain circumstances.

Regulator Registration And FilingAmber

GDPR removed general notification-to-regulator duties; residual filing obligations in Slovakia are narrower, chiefly DPO-contact notification to ÚOOÚ SR.

Claims (1):

  • Controllers/processors appointing a DPO in Slovakia are expected to notify DPO contact details to the ÚOOÚ SR via its notification channel, though GDPR abolished general processing-notification duties.
Category narrative219 words

Slovakia is an EU Member State operating under direct application of the GDPR, supplemented by national implementing Act No. 18/2018 Coll. The competent supervisory authority is the Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic, 'ÚOOÚ SR'), based in Bratislava, which participates in the EDPB as Slovakia's representative body. <cite index="6-1">The Úrad na ochranu osobných údajov Slovenskej republiky is located at Galvaniho 7/B, 821 04 Bratislava, Slovakia</cite>. GDPR applies directly as a Regulation and governs both private-sector and most public-sector processing, with the national Act filling in derogations, procedural rules, and the DPO/ROPA administrative regime. <cite index="53-1">The GDPR protects persons where their personal data is processed by the private sector and most of the public sector</cite>. GDPR's territorial scope extends to non-EU-established controllers targeting or monitoring EU data subjects, and its material scope removed most prior general notification duties in favour of accountability. <cite index="45-15">The Regulation requires companies based outside the EU to apply the same rules as companies based in the EU if they are offering goods and services related to the personal data or are monitoring the behaviour of individuals in the Union</cite>. <cite index="1-12,1-13">The GDPR abolished most notification obligations and the associated costs</cite>, shifting the compliance model toward internal accountability and DPO-based registration rather than blanket regulator filing.

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. ConfirmedEuropean Data Protection Board — The Úrad na ochranu osobných údajov Slovenskej republiky is Slovakia's independent supervisory authority for data protection and is Slovakia's representative on the European Data Protection Board.observed
  2. ConfirmedEUR-Lex — Regulation (EU) 2016/679 (GDPR) applies directly in Slovakia as the primary legal instrument governing personal data processing.observed
  3. ConfirmedDataGuidance — Act No. 18/2018 Coll. on Protection of Personal Data and on Amendments to Certain Acts is Slovakia's national implementing statute supplementing the GDPR, including DPIA rules in Sections 42-43.observed
  4. ConfirmedEUR-Lex — GDPR's material scope in Slovakia covers processing of personal data by the private sector and most of the public sector, whether automated or structured manual processing.observed
  5. ConfirmedEuropean Commission / EUR-Lex — GDPR applies to non-EU-established controllers/processors that offer goods or services to, or monitor the behaviour of, individuals in Slovakia/the EU, requiring an EU representative in certain circumstances.observed
  6. ProbableDataGuidance — Controllers/processors appointing a DPO in Slovakia are expected to notify DPO contact details to the ÚOOÚ SR via its notification channel, though GDPR abolished general processing-notification duties.observed

#

GDPR lawful bases and special-category rules apply without material derogation identified; children's digital-consent age threshold not independently confirmed for Slovakia.

Primary frameworkGDPR Arts. 6-9; Act No. 18/2018 Coll.
Traffic-light rationale — GreenGDPR lawful bases and special-category rules apply without material derogation identified; children's digital-consent age threshold not independently confirmed for Slovakia.

Sub-modules (4)

Lawful BasesGreen

The six GDPR Art. 6 lawful bases (consent, contract, legal obligation, vital interests, public interest/official authority, legitimate interests) apply directly in Slovakia; the legitimate-interest basis does not extend to public-authority processing carried out in performance of their tasks.

Claims (1):

  • Processing of personal data in Slovakia is lawful only where at least one of the GDPR Art. 6(1) conditions is satisfied, and the legitimate-interest basis does not apply to processing carried out by public authorities in the performance of their tasks.

Special CategoriesAmber

Special-category data (health, biometric, genetic, ethnic origin, political opinion, sexual orientation, criminal data) are subject to the heightened Art. 9 regime; no Slovakia-specific broadening located in research.

Pseudonymisation And AnonymisationGreen

GDPR's pseudonymisation safe-harbour concept applies directly; pseudonymised data remain personal data.

Claims (1):

  • GDPR promotes pseudonymisation as a risk-mitigation technique, replacing identifying fields with artificial identifiers, but pseudonymised data remain personal data subject to GDPR.
Category narrative163 words

Slovakia applies the GDPR Art. 6 lawful-basis enumeration and Art. 9 special-category regime directly, with Act 18/2018 providing localized procedural detail. Consent must be an unambiguous, freely-given, specific and informed indication of wishes, revocable at any time. <cite index="56-14,56-15">If processing is based on consent, the controller must be able to demonstrate that the data subject has given consent to the processing of their personal data</cite>, and <cite index="56-19,56-20,56-21">the data subject has the right to withdraw consent at any time, and withdrawal does not affect the lawfulness of processing based on consent before its withdrawal</cite>. For children, Slovakia follows the GDPR default digital-consent age unless a national derogation is legislated. <cite index="56-27,56-28,56-29">Where a child is at least 16 years old, consent to information-society-service offers is lawful directly; below that age, national law may lower this threshold, but not below 13</cite>. No evidence was found of a Slovak-specific derogation lowering this age below the 16-year default; this is treated as an open question in self_audit.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedEUR-Lex — Processing of personal data in Slovakia is lawful only where at least one of the GDPR Art. 6(1) conditions is satisfied, and the legitimate-interest basis does not apply to processing carried out by public authorities in the performance of their tasks.observed
  2. ConfirmedEUR-Lex — Where processing is based on consent, the controller must be able to demonstrate that the data subject gave consent, and consent embedded in a broader written declaration must be clearly distinguishable, intelligible and easily accessible.observed
  3. ConfirmedEUR-Lex — Data subjects in Slovakia have the right to withdraw consent at any time, with withdrawal being as easy as giving consent and not affecting the lawfulness of prior processing.observed
  4. ConfirmedEUR-Lex — GDPR promotes pseudonymisation as a risk-mitigation technique, replacing identifying fields with artificial identifiers, but pseudonymised data remain personal data subject to GDPR.observed

#

Full GDPR rights catalogue and standard one-month response deadline apply without identified Slovak derogation.

Primary frameworkGDPR Arts. 12-23; Act No. 18/2018 Coll.
Traffic-light rationale — GreenFull GDPR rights catalogue and standard one-month response deadline apply without identified Slovak derogation.

Sub-modules (5)

Access RightGreen

Data subjects may obtain confirmation of processing and access to their personal data and processing metadata under GDPR Art. 15.

Claims (1):

  • Data subjects in Slovakia have the right to obtain confirmation from the controller as to whether their personal data are being processed and, if so, to access such data and related processing details.

Rectification And ErasureGreen

Rectification (Art. 16) and erasure/'right to be forgotten' (Art. 17) apply, including onward-notification duties to other controllers when data was made public.

Claims (1):

  • Where a controller has made personal data public and is obliged to erase it, the controller must take reasonable steps, including technical measures, to inform other controllers processing the data that the data subject has requested erasure of links, copies or replications.

Restriction And ObjectionGreen

Restriction (Art. 18) and objection, including objection to processing for scientific/historical/statistical research absent overriding public-interest necessity (Art. 21(6)), apply directly.

Claims (1):

  • A data subject may obtain restriction of processing in specified circumstances, and, where processing is for scientific, historical research or statistical purposes, may object on grounds relating to their particular situation unless processing is necessary for a public-interest task.

Data PortabilityGreen

The Art. 20 portability right facilitates transfer of personal data between service providers where processing is consent- or contract-based and automated.

Claims (1):

  • GDPR's data-portability right facilitates the transfer of personal data between service providers for consent- or contract-based, automated processing.

Deadlines And Response WindowsAmber

GDPR's standard one-month response window (extendable by two further months for complex/numerous requests) applies; no Slovak-specific shortening identified.

Category narrative150 words

GDPR's full data-subject rights catalogue (access, rectification, erasure, restriction, objection, portability) applies directly in Slovakia via Act 18/2018 procedural transposition. <cite index="9-2">Companies and organisations will have to promptly inform individuals of serious data breaches, and the clearer right to erasure ('right to be forgotten') allows deletion of data where there is no legitimate ground for retaining it</cite>. <cite index="10-5,10-6">A data subject has the right to obtain restriction of processing from the controller in specified cases, and where processing has been restricted such data may only be processed with the data subject's consent or for establishing, exercising or defending legal claims, protecting another's rights, or for important EU/Member State public-interest reasons</cite>. <cite index="10-23,10-26">A data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects them, subject to safeguards including the right to obtain human intervention</cite>.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedEUR-Lex — Data subjects in Slovakia have the right to obtain confirmation from the controller as to whether their personal data are being processed and, if so, to access such data and related processing details.observed
  2. ConfirmedEUR-Lex — Where a controller has made personal data public and is obliged to erase it, the controller must take reasonable steps, including technical measures, to inform other controllers processing the data that the data subject has requested erasure of links, copies or replications.observed
  3. ConfirmedEUR-Lex — A data subject may obtain restriction of processing in specified circumstances, and, where processing is for scientific, historical research or statistical purposes, may object on grounds relating to their particular situation unless processing is necessary for a public-interest task.observed
  4. ConfirmedEUR-Lex — GDPR's data-portability right facilitates the transfer of personal data between service providers for consent- or contract-based, automated processing.observed

#

Full GDPR controller/processor obligations regime in force with national DPIA procedural supplementation; no Slovak-specific weakening identified.

Primary frameworkGDPR Arts. 5, 24-39; Act No. 18/2018 Coll. Sections 42-43
Traffic-light rationale — GreenFull GDPR controller/processor obligations regime in force with national DPIA procedural supplementation; no Slovak-specific weakening identified.

Sub-modules (7)

Accountability And DpiaGreen

Accountability principle (Art. 5(2)/24) and DPIA triggers (Art. 35) apply directly, with Slovak procedural detail in Act 18/2018 §§42-43.

Claims (2):

  • Controllers in Slovakia are responsible for, and must demonstrate, compliance with GDPR's data-protection principles under the accountability principle.
  • Where a type of processing, especially using new technologies, is likely to result in high risk to individuals' rights and freedoms, the controller must carry out a DPIA before processing, with Slovak procedural mechanics specified in Act No. 18/2018 Coll. Sections 42-43.

Dpo RequirementsGreen

GDPR Art. 37 DPO-appointment thresholds (public authorities; large-scale regular/systematic monitoring; large-scale special-category/criminal-data processing) apply; Slovak Act 18/2018 supplies notification procedure to ÚOOÚ SR.

Claims (1):

  • Controllers and processors in Slovakia must designate a DPO where required by GDPR Art. 37 (public authority status, large-scale systematic monitoring, or large-scale special-category/criminal-data processing).

Ropa RequirementsGreen

Records-of-processing obligations under Art. 30 apply, with an SME exemption unless processing is regular, risk-bearing, or involves special categories/criminal data.

Claims (1):

  • GDPR Art. 30 records-of-processing obligations apply in Slovakia; SMEs are exempt unless processing is regular, likely to result in risk to data subjects, or involves special-category or criminal-conviction data.

Joint Controller ArrangementsGreen

Art. 26 joint-controller and Art. 28 processor-contract rules apply directly; processor sub-engagement requires controller authorisation.

Claims (1):

  • A processor in Slovakia may not engage a sub-processor without the controller's prior specific or general written authorisation, and processing must be governed by a binding contract or legal act specifying subject-matter, duration, nature and purpose of processing.

Security MeasuresGreen

Art. 32 security-of-processing obligations (pseudonymisation, encryption, resilience, testing) apply directly with no Slovak derogation identified.

Breach NotificationGreen

Breach notification to the regulator within 72 hours of awareness (where risk exists), and to data subjects without undue delay for high-risk breaches, applies directly.

Claims (1):

  • Controllers must notify the ÚOOÚ SR of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

Retention And DisposalAmber

Storage-limitation principle (Art. 5(1)(e)) applies; no Slovakia-specific statutory retention schedule for general personal data was located beyond sector-specific archival laws.

Category narrative206 words

GDPR's accountability regime (Art. 5(2), 24), DPIA regime (Art. 35, with Act 18/2018 Sections 42-43 providing national procedural detail), DPO regime (Art. 37-39), processor rules (Art. 28), security (Art. 32) and breach notification (Art. 33-34) all apply directly. <cite index="56-8">The controller is responsible for, and must be able to demonstrate, compliance with the accountability principle</cite>. <cite index="55-4,55-5">Where processing, particularly using new technologies, is likely to result in high risk to individuals' rights and freedoms, the controller must carry out a data protection impact assessment prior to processing, and a single assessment may cover a set of similar high-risk operations</cite>, and <cite index="55-6">the controller must consult the data protection officer, where one has been designated, during the DPIA</cite>. Slovak DPIA procedure is further specified in <cite index="27-3,27-4">Sections 42 and 43 of Act No. 18/2018 Coll. on Protection of Personal Data and on Amendments to certain Acts</cite>. On processors, <cite index="58-12,58-13">where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures so that processing meets GDPR requirements and protects data subject rights</cite>, and <cite index="58-14,58-15">a processor shall not engage another processor without prior specific or general written authorisation of the controller</cite>.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedEUR-Lex — Controllers in Slovakia are responsible for, and must demonstrate, compliance with GDPR's data-protection principles under the accountability principle.observed
  2. ConfirmedDataGuidance — Where a type of processing, especially using new technologies, is likely to result in high risk to individuals' rights and freedoms, the controller must carry out a DPIA before processing, with Slovak procedural mechanics specified in Act No. 18/2018 Coll. Sections 42-43.observed
  3. ConfirmedEUR-Lex — Controllers and processors in Slovakia must designate a DPO where required by GDPR Art. 37 (public authority status, large-scale systematic monitoring, or large-scale special-category/criminal-data processing).observed
  4. ConfirmedEuropean Commission / EUR-Lex — GDPR Art. 30 records-of-processing obligations apply in Slovakia; SMEs are exempt unless processing is regular, likely to result in risk to data subjects, or involves special-category or criminal-conviction data.observed
  5. ConfirmedEUR-Lex — A processor in Slovakia may not engage a sub-processor without the controller's prior specific or general written authorisation, and processing must be governed by a binding contract or legal act specifying subject-matter, duration, nature and purpose of processing.observed
  6. ConfirmedEUR-Lex — Controllers must notify the ÚOOÚ SR of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.observed

#

Core EU adequacy/SCC/BCR framework applies uniformly, but Slovakia-specific TIA guidance, localisation rules, and national case examples were not independently located in this research pass.

Primary frameworkGDPR Arts. 44-50
Traffic-light rationale — AmberCore EU adequacy/SCC/BCR framework applies uniformly, but Slovakia-specific TIA guidance, localisation rules, and national case examples were not independently located in this research pass.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Ch. V mechanisms (adequacy, SCCs, BCRs, codes of conduct/certification, Art. 49 derogations) apply uniformly in Slovakia as in all EU Member States.

Claims (1):

  • Slovak controllers and processors may transfer personal data to third countries using European Commission adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, approved codes of conduct/certification, or Art. 49 derogations, per the uniformly-applicable GDPR Chapter V regime.

Adequacy ReceivedGreen

Slovakia does not independently receive adequacy findings; as an EU Member State it benefits from reciprocal EU adequacy arrangements (e.g., with the UK) negotiated at Union level.

Adequacy GrantedGreen

Adequacy decisions covering transfers from Slovakia to third countries are issued exclusively by the European Commission and apply EU-wide; Slovakia has no independent national adequacy-granting power.

Claims (1):

  • Adequacy decisions determining whether third countries provide an adequate level of data protection for transfers originating in Slovakia are adopted exclusively by the European Commission under GDPR Art. 45 and apply uniformly across all EU Member States.

Sccs And BcrsGreen

Standard Contractual Clauses and Binding Corporate Rules approved under the EU consistency mechanism are directly usable by Slovak controllers/processors.

Transfer Impact AssessmentAmber

TIA expectations (post-Schrems II) apply per EDPB guidance uniformly; no Slovakia-specific TIA guidance located.

Absence provenance: unavailable. Searched: Ú, O, O, Ú, , S, R, , t, r, a, n, s, f, e, r, , i, m, p, a, c, t, , a, s, s, e, s, s, m, e, n, t, , g, u, i, d, a, n, c, e, , S, c, h, r, e, m, s, , I, I.

Data LocalisationAmber

No general personal-data localisation mandate for Slovakia was identified in research beyond standard EU public-sector/national-security carve-outs.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , d, a, t, a, , l, o, c, a, l, i, s, a, t, i, o, n, , r, e, q, u, i, r, e, m, e, n, t, , p, e, r, s, o, n, a, l, , d, a, t, a, , 2, 0, 2, 5, , 2, 0, 2, 6.

Category narrative89 words

As an EU Member State, Slovakia relies on the GDPR Chapter V transfer regime: adequacy decisions issued by the European Commission apply uniformly across the EU/EEA (Slovakia does not issue independent national adequacy decisions), alongside SCCs, BCRs, and Art. 49 derogations. No Slovakia-specific data-localisation mandate for general personal data was identified in research; sector-specific localisation (e.g., certain public-sector or defence data) may exist but was not independently confirmed. This module is populated primarily from the general EU/GDPR baseline given the absence of Slovakia-specific transfer guidance in the sources retrieved.

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

The European Commission adopted Implementing Decision (EU) 2025/1225 on 24 June 2025, amending the United Kingdom's adequacy decision under the Law Enforcement Directive, Directive (EU) 2016/680. This is a supranational, EU-wide development rather than a Slovakia-specific one, but it applies directly to Slovakia as a Member State: Slovak controllers and processors engaged in law-enforcement-adjacent personal-data transfers to the United Kingdom rely on this same adequacy finding as the legal basis for those transfers, and the amendment updates the terms of that basis for every Member State simultaneously.

No Slovakia-specific cross-border transfer mechanism, standard contractual clause practice, or binding corporate rules development was located this cycle beyond this EU-level adequacy amendment. The practical effect for Slovak organisations transferring personal data to the UK for law-enforcement-related purposes is that they should review the amended adequacy decision's terms to confirm their transfers remain within its scope, though no evidence this cycle indicates the amendment narrows or expands Slovakia's own transfer practices beyond the EU-wide baseline.

Outlook

No Slovakia-specific cross-border or adequacy development beyond the EU-wide UK LED adequacy amendment was located this cycle. Future cycles should watch for any Slovak-specific guidance from UOOU interpreting the amended UK adequacy decision's practical application to Slovak controllers and processors.

Sources and claims (2)
  1. ConfirmedEUR-Lex — Slovak controllers and processors may transfer personal data to third countries using European Commission adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, approved codes of conduct/certification, or Art. 49 derogations, per the uniformly-applicable GDPR Chapter V regime.observed
  2. ConfirmedEUR-Lex — Adequacy decisions determining whether third countries provide an adequate level of data protection for transfers originating in Slovakia are adopted exclusively by the European Commission under GDPR Art. 45 and apply uniformly across all EU Member States.observed

#

No comprehensive Slovakia-specific sectoral overlay evidence was located in this research pass; only the general EU ePrivacy baseline is confirmed.

Traffic-light rationale — RedNo comprehensive Slovakia-specific sectoral overlay evidence was located in this research pass; only the general EU ePrivacy baseline is confirmed.

Sub-modules (7)

Financial Sector OverlayRed

No Slovakia-specific banking-secrecy/GDPR interaction guidance was located in this pass.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , b, a, n, k, i, n, g, , s, e, c, r, e, c, y, , G, D, P, R, , f, i, n, a, n, c, i, a, l, , s, e, c, t, o, r, , p, e, r, s, o, n, a, l, , d, a, t, a, , o, v, e, r, l, a, y.

Health Sector OverlayRed

No Slovakia-specific health-data overlay statute (e.g., health records act interaction with GDPR) was independently retrieved.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , h, e, a, l, t, h, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , a, c, t, , G, D, P, R, , o, v, e, r, l, a, y.

Telecoms And EprivacyAmber

The EU ePrivacy Directive 2002/58/EC applies as the baseline electronic-communications privacy instrument across the EU including Slovakia, pending the still-unadopted ePrivacy Regulation.

Claims (1):

  • Directive 2002/58/EC (ePrivacy Directive) governs processing of personal data and privacy in the electronic-communications sector across the EU, including Slovakia, pending the proposed ePrivacy Regulation.

Employment DataRed

No Slovakia-specific employment-data code was independently retrieved in this pass.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , L, a, b, o, u, r, , C, o, d, e, , e, m, p, l, o, y, e, e, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , G, D, P, R.

Credit And ScoringRed

No Slovakia-specific credit-scoring statute was independently retrieved.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , c, r, e, d, i, t, , s, c, o, r, i, n, g, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , r, e, g, u, l, a, t, i, o, n.

EducationRed

No Slovakia-specific education-sector data rule was independently retrieved beyond general GDPR applicability.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , e, d, u, c, a, t, i, o, n, , s, e, c, t, o, r, , s, t, u, d, e, n, t, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , G, D, P, R.

InsuranceRed

No Slovakia-specific insurance-sector data rule was independently retrieved.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , i, n, s, u, r, a, n, c, e, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , G, D, P, R, , o, v, e, r, l, a, y.

Category narrative62 words

No Slovakia-specific sectoral overlay documentation (banking-secrecy interaction, health-sector rules, telecoms/ePrivacy transposition specifics, employment-code provisions, credit-scoring rules, education or insurance-sector data rules) was independently retrieved in this research pass beyond the general EU ePrivacy Directive (2002/58/EC) baseline, which is referenced as applicable across the EU including Slovakia. This module is therefore populated conservatively with an explicit gap declaration rather than fabricated sector detail.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. ProbableEUR-Lex — Directive 2002/58/EC (ePrivacy Directive) governs processing of personal data and privacy in the electronic-communications sector across the EU, including Slovakia, pending the proposed ePrivacy Regulation.observed

#

Only the general EU cookie-consent baseline is confirmed; Slovakia-specific adtech instruments (dark patterns, GPC recognition, clean rooms, marketing suppression) were not independently located.

Primary frameworkDirective 2002/58/EC (ePrivacy); GDPR (where personal data involved)
Traffic-light rationale — RedOnly the general EU cookie-consent baseline is confirmed; Slovakia-specific adtech instruments (dark patterns, GPC recognition, clean rooms, marketing suppression) were not independently located.

Sub-modules (6)

Cookies And TrackersAmber

Cookie/tracker placement requires prior informed consent under the ePrivacy Directive's transposition, layered with GDPR consent standards where personal data are processed.

Claims (1):

  • Placement of cookies or similar trackers on end-user devices in Slovakia requires prior informed consent under the EU ePrivacy Directive framework, layered with GDPR consent standards where personal data are processed.

Dark PatternsRed

No Slovakia-specific dark-pattern prohibition statute was independently retrieved.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , d, a, r, k, , p, a, t, t, e, r, n, s, , c, o, n, s, e, n, t, , G, D, P, R, , Ú, O, O, Ú, , g, u, i, d, a, n, c, e.

Opt Out SignalsRed

No Slovakia-specific Global Privacy Control or DAA-equivalent opt-out-signal recognition was independently retrieved.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , G, l, o, b, a, l, , P, r, i, v, a, c, y, , C, o, n, t, r, o, l, , r, e, c, o, g, n, i, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n.

Clean Rooms And DcrRed

No Slovakia-specific clean-room/data-collaboration-room guidance was independently retrieved.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , d, a, t, a, , c, l, e, a, n, , r, o, o, m, , G, D, P, R, , g, u, i, d, a, n, c, e.

Cross Context AdvertisingAmber

No CPRA-style 'sale'/'share' concept exists in Slovakia; cross-context advertising is governed generically by GDPR consent/legitimate-interest analysis.

Direct MarketingAmber

Direct marketing requires a lawful basis (typically consent or legitimate interest with opt-out) under GDPR; no Slovakia-specific suppression-list mechanism was independently retrieved.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , d, i, r, e, c, t, , m, a, r, k, e, t, i, n, g, , c, o, n, s, e, n, t, , s, u, p, p, r, e, s, s, i, o, n, , l, i, s, t, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n.

Category narrative54 words

Cookie/tracker consent in Slovakia follows the EU ePrivacy Directive's consent requirement as implemented nationally, overlaid by GDPR consent standards where personal data are involved. No Slovakia-specific dark-pattern prohibition statute, Global-Privacy-Control recognition, clean-room framework, or direct-marketing suppression-list mechanism was independently retrieved in this research pass; this is flagged as a gap rather than assumed absent.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ProbableEUR-Lex — Placement of cookies or similar trackers on end-user devices in Slovakia requires prior informed consent under the EU ePrivacy Directive framework, layered with GDPR consent standards where personal data are processed.observed

#

GDPR Art. 22/9 baseline is confirmed; Slovakia-specific AI Act national competent authority designation and state-surveillance carve-out detail were not independently located.

Primary frameworkGDPR Art. 9, Art. 22; EU AI Act (Regulation (EU) 2024/1689) interface
Traffic-light rationale — AmberGDPR Art. 22/9 baseline is confirmed; Slovakia-specific AI Act national competent authority designation and state-surveillance carve-out detail were not independently located.

Sub-modules (6)

Profiling RestrictionsGreen

Art. 22 restricts solely-automated decisions with legal or similarly significant effects, subject to enumerated exceptions and safeguards.

Claims (1):

  • Data subjects in Slovakia have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them, subject to enumerated exceptions and safeguards including human intervention.

Automated Decision Making TransparencyGreen

Controllers must provide meaningful information about the logic involved in automated decision-making under Arts. 13-15, alongside Art. 22 safeguards.

Ai Risk AssessmentsAmber

The EU AI Act layers risk-based obligations (including interaction with GDPR DPIAs) atop GDPR for high-risk AI systems; Slovak national AI Act implementation/competent-authority detail was not independently confirmed in this pass.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , A, I, , A, c, t, , n, a, t, i, o, n, a, l, , c, o, m, p, e, t, e, n, t, , a, u, t, h, o, r, i, t, y, , d, e, s, i, g, n, a, t, i, o, n, , 2, 0, 2, 5, , 2, 0, 2, 6.

Biometric RegimeGreen

Biometric data used for unique identification purposes is a GDPR Art. 9 special category, requiring an Art. 9(2) condition for lawful processing.

Claims (1):

  • Biometric data processed for the purpose of uniquely identifying a natural person is treated as a special category of personal data in Slovakia under GDPR Art. 9, requiring a specific lawful condition beyond Art. 6.

Genetic DataGreen

Genetic data is likewise a GDPR Art. 9 special category subject to heightened protection.

State Surveillance CarveoutsAmber

No Slovakia-specific state-surveillance/national-security carve-out statute was independently retrieved in this pass; GDPR Art. 23 permits Member State restrictions for national security, defence and public security subject to necessity/proportionality.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , n, a, t, i, o, n, a, l, , s, e, c, u, r, i, t, y, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , c, a, r, v, e, -, o, u, t, , G, D, P, R, , A, r, t, i, c, l, e, , 2, 3.

Category narrative129 words

GDPR Art. 22 profiling/ADM restrictions apply directly in Slovakia. <cite index="10-23,10-26">A data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, and the controller must implement suitable measures including the right to obtain human intervention, to express one's point of view and to contest the decision</cite>. Biometric and genetic data are treated as special categories under Art. 9. As an EU Member State, Slovakia is also subject to the EU AI Act's risk-based governance layer, and its national data protection authority interfaces with AI Act obligations per EDPB/EDPS statements on the intersecting roles of DPAs in AI oversight. No Slovakia-specific state-surveillance carve-out statute was independently retrieved in this pass.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ConfirmedEUR-Lex — Data subjects in Slovakia have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them, subject to enumerated exceptions and safeguards including human intervention.observed
  2. ConfirmedEUR-Lex — Biometric data processed for the purpose of uniquely identifying a natural person is treated as a special category of personal data in Slovakia under GDPR Art. 9, requiring a specific lawful condition beyond Art. 6.observed

#

GDPR Art. 8 default is confirmed; Slovakia's specific national digital-consent age (if derogated) and minor-profiling/education/dependent-adults specifics were not independently verified in this pass.

Primary frameworkGDPR Art. 8
Traffic-light rationale — AmberGDPR Art. 8 default is confirmed; Slovakia's specific national digital-consent age (if derogated) and minor-profiling/education/dependent-adults specifics were not independently verified in this pass.

Sub-modules (5)

Age VerificationAmber

The default GDPR digital-consent age is 16, absent a national derogation (permitted down to a floor of 13); Slovakia's specific national figure was not independently confirmed.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , G, D, P, R, , A, r, t, i, c, l, e, , 8, , a, g, e, , o, f, , c, o, n, s, e, n, t, , c, h, i, l, d, r, e, n, , d, e, r, o, g, a, t, i, o, n.

Claims (1):

  • In Slovakia, where an information-society service is offered directly to a child under the applicable digital age of consent (16 by GDPR default, absent a confirmed national derogation not below 13), processing of the child's personal data is lawful only where consent is given or authorised by the holder of parental responsibility.

Minor Profiling BansRed

No Slovakia-specific statutory ban on profiling of minors beyond GDPR's general Art. 22/recital 71 caution was independently retrieved.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , m, i, n, o, r, , p, r, o, f, i, l, i, n, g, , b, a, n, , c, h, i, l, d, r, e, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n.

Education SettingsRed

No Slovakia-specific education-sector children's-data statute was independently retrieved.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , s, c, h, o, o, l, , s, t, u, d, e, n, t, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, t, a, t, u, t, e.

Dependent AdultsRed

No Slovakia-specific dependent-adults data-protection statute beyond general capacity/guardianship civil law was independently retrieved.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, s, , i, n, c, a, p, a, c, i, t, a, t, e, d, , p, e, r, s, o, n, s, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n.

Category narrative115 words

GDPR Art. 8's digital-consent age threshold applies as the default in Slovakia. <cite index="56-27,56-28,56-29">Where GDPR Art. 6(1)(a) applies to an offer of information-society services directly to a child, processing is lawful only if the child is at least 16 years old; where the child is younger, consent must be given or authorised by the holder of parental responsibility, and Member States may set a lower age by law provided it is not below 13</cite>. Research did not independently confirm whether Slovakia has legislated a national derogation lowering this threshold below 16; this is flagged as an open question. No Slovakia-specific minor-profiling ban, education-settings-specific statute, or dependent-adults protection regime beyond general capacity/guardianship law was independently retrieved.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ProbableEUR-Lex — In Slovakia, where an information-society service is offered directly to a child under the applicable digital age of consent (16 by GDPR default, absent a confirmed national derogation not below 13), processing of the child's personal data is lawful only where consent is given or authorised by the holder of parental responsibility.observed

#

Core GDPR enforcement powers and fining ceiling are confirmed, and a significant Constitutional Court privacy ruling was located; however, no recent (12-month) ÚOOÚ SR enforcement-decision data or granular funding/headcount figures were independently retrieved.

Primary frameworkGDPR Arts. 58, 77-84
Traffic-light rationale — AmberCore GDPR enforcement powers and fining ceiling are confirmed, and a significant Constitutional Court privacy ruling was located; however, no recent (12-month) ÚOOÚ SR enforcement-decision data or granular funding/headcount figures were independently retrieved.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

ÚOOÚ SR holds GDPR Art. 58 investigative/corrective powers and may impose administrative fines up to the higher of €20 million or 4% of global annual turnover under Art. 83, calculated per EDPB fine-calculation guidelines.

Claims (1):

  • The ÚOOÚ SR may impose administrative fines calculated in accordance with EDPB harmonisation guidelines, which require that fines be effective, proportionate and dissuasive in each individual case, up to the maximum GDPR Art. 83 ceilings.

Enforcement Activity IndexRed

No specific ÚOOÚ SR fine/decision data from the past 12 months was independently retrieved in this research pass.

Absence provenance: unavailable. Searched: Ú, r, a, d, , n, a, , o, c, h, r, a, n, u, , o, s, o, b, n, ý, c, h, , ú, d, a, j, o, v, , S, R, , p, o, k, u, t, a, , 2, 0, 2, 5, , 2, 0, 2, 6, ;, , S, l, o, v, a, k, i, a, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , a, u, t, h, o, r, i, t, y, , f, i, n, e, , d, e, c, i, s, i, o, n.

Regulator Funding And CapacityRed

No specific ÚOOÚ SR budget/headcount figures were independently retrieved in this research pass.

Absence provenance: unavailable. Searched: Ú, O, O, Ú, , S, R, , r, o, z, p, o, č, e, t, , z, a, m, e, s, t, n, a, n, c, i, , k, a, p, a, c, i, t, a.

Collective Redress And Class ActionsAmber

EU-level collective-redress mechanisms (Representative Actions Directive) apply as the baseline; Slovakia-specific transposition detail was not independently confirmed.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , R, e, p, r, e, s, e, n, t, a, t, i, v, e, , A, c, t, i, o, n, s, , D, i, r, e, c, t, i, v, e, , t, r, a, n, s, p, o, s, i, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , c, o, l, l, e, c, t, i, v, e, , r, e, d, r, e, s, s.

Private Right Of ActionGreen

GDPR Arts. 79 and 82 grant data subjects a direct judicial remedy and compensation right against controllers/processors, applicable in Slovak courts.

Claims (1):

  • Data subjects in Slovakia have a direct right under GDPR Arts. 79 and 82 to an effective judicial remedy and to compensation for material or non-material damage resulting from GDPR infringement, enforceable before Slovak courts.

Recent Developments 180DAmber

The most significant recent Slovak privacy-adjacent development located in research is the Constitutional Court's ruling striking down a mandatory NGO-donor-disclosure amendment as disproportionate to privacy rights; exact ruling date and 180-day currency relative to the 2026-08-05 run date were not independently pinned down.

Absence provenance: unavailable. Searched: S, l, o, v, a, k, i, a, , C, o, n, s, t, i, t, u, t, i, o, n, a, l, , C, o, u, r, t, , N, G, O, , d, o, n, o, r, , d, i, s, c, l, o, s, u, r, e, , r, u, l, i, n, g, , d, a, t, e, ;, , S, l, o, v, a, k, i, a, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , n, e, w, s, , 2, 0, 2, 6.

Claims (1):

  • The Constitutional Court of the Slovak Republic struck down a legislative amendment requiring NGOs to publish identifying data of individual donors contributing over €5,000 per year, holding the blanket disclosure obligation disproportionate to privacy and data-protection rights.
Category narrative195 words

GDPR Arts. 58 and 83 grant the ÚOOÚ SR investigative, corrective and administrative-fining powers (up to the higher of €20 million or 4% of global annual turnover for the most serious infringements), consistent with the EU-wide fining framework. <cite index="31-13,31-14">The calculation of the fine amount is within the competence of the supervisory authority and is governed by rules set out in the GDPR, which requires that in each individual case the fine be effective, proportionate and dissuasive</cite>. A notable Slovak constitutional-law development relevant to enforcement/redress is the Constitutional Court's intervention in a data-transparency dispute: <cite index="25-7,25-8">the Constitutional Court of the Slovak Republic struck down an NGO donor-disclosure amendment, ruling that the blanket and broad obligation to disclose all donor data was disproportionate and unbalanced</cite>, and <cite index="25-9">the court emphasized that even a strong public interest in transparency cannot automatically outweigh the right to privacy and personal data protection</cite>. No specific ÚOOÚ SR fine decisions from the last 12 months were independently retrieved in this research pass; this is flagged as a gap. Collective-redress mechanisms follow the EU Representative Actions Directive baseline; a Slovakia-specific private-right-of-action statute beyond GDPR Art. 79/82 court-access rights was not independently confirmed.

Periodic update · new data 2026-09-28

Enforcement & Redress

UOOU's confirmed procedural framework requires the authority to decide a data-protection proceeding within 90 days of initiation, extendable by up to a further 180 days in justified cases, with written notice given to the parties. This is standing national procedure under Act No. 18/2018 Coll. and was not reported as changed this cycle.

A draft amendment to Act No. 18/2018 has been reported that would materially alter UOOU's enforcement posture: it would remove the authority's discretion not to impose a fine where a violation is found, extend the chair's term of office from five to seven years, remove the existing two-term limit on the chair's tenure, and introduce a new offence addressing deepfake-related conduct. A target effective date of 1 January 2026 has been reported. However, the enactment status of this draft has not been confirmed against an official Slovak legislative-process source this cycle, and the reporting rests on a single secondary commentary source rather than a primary legislative record, so this should be read as a proposal under consideration rather than as an enacted change to UOOU's enforcement framework.

If enacted as reported, the removal of UOOU's discretion not to impose a fine would represent a meaningful shift toward mandatory financial sanctions for confirmed violations, moving away from the current framework in which the authority retains discretion over whether a fine is the appropriate response to a given finding.

Outlook

Confirmation of the draft Act 18/2018 amendment's legislative status is the single most consequential item to track in this domain. Given the reported 1 January 2026 target date, the coming period should clarify whether the amendment has been enacted, remains pending, or has lapsed; each outcome carries materially different implications for UOOU's enforcement discretion and institutional continuity.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ConfirmedEuropean Data Protection Board — The ÚOOÚ SR may impose administrative fines calculated in accordance with EDPB harmonisation guidelines, which require that fines be effective, proportionate and dissuasive in each individual case, up to the maximum GDPR Art. 83 ceilings.observed
  2. ConfirmedEUR-Lex — Data subjects in Slovakia have a direct right under GDPR Arts. 79 and 82 to an effective judicial remedy and to compensation for material or non-material damage resulting from GDPR infringement, enforceable before Slovak courts.observed
  3. ProbableIAPP — The Constitutional Court of the Slovak Republic struck down a legislative amendment requiring NGOs to publish identifying data of individual donors contributing over €5,000 per year, holding the blanket disclosure obligation disproportionate to privacy and data-protection rights.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct45.45
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Slovakia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 30 claim(s) (30 category placement(s)), 14 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy granted
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, algorithmic_biometric_and_surveillance_governance, and enforcement_and_redress modules are grounded in T1/T2 sources (GDPR text, EUR-Lex summaries, EDPB fine guidelines) with reasonable confidence. cross_border_and_adequacy is grounded in the EU-wide GDPR Ch. V baseline but lacks Slovakia-specific TIA/localisation detail (T3/absent). sectoral_watch and adtech_and_commercial_privacy modules rely mostly on the general EU ePrivacy baseline (T2) with explicit absent_field_provenance for financial/health/employment/credit/education/insurance overlays and for dark-patterns/GPC/clean-room/marketing specifics, as no Slovakia-specific T1/T2 sources were retrieved in this pass. children_and_vulnerable_groups is grounded in the GDPR Art. 8 default but the Slovak national digital-consent-age derogation (if any) was not independently confirmed. enforcement_and_redress.enforcement_activity_index and regulator_funding_and_capacity carry explicit absent_field_provenance given no recent (12-month) ÚOOÚ SR decision or budget data surfaced.

Unresolved questions (6):

  • Has Slovakia legislated a national derogation under GDPR Art. 8(1) lowering the digital age of consent below the 16-year EU default, and if so to what age (floor 13)?
  • What are the current name and tenure details of the ÚOOÚ SR's chairperson/statutory head?
  • Has ÚOOÚ SR issued any significant administrative fines or enforcement decisions in the 12 months preceding 2026-08-05?
  • Does Slovakia impose any sector-specific data-localisation requirement (e.g., public-sector cloud, defence, or critical-infrastructure data)?
  • Is there a Slovakia-specific transposition of the EU Representative Actions Directive enabling collective redress for data-protection claims?
  • What is the exact date of the Slovak Constitutional Court's ruling striking down the NGO donor-disclosure amendment, and does it fall within the 180-day recent-developments window as of 2026-08-05?

Escalate to primary-source review: yes