🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
SI v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing11 sources retrieved model claude-sonnet-5 · 2026-08-05

Slovenia

SI schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 32 claims · 18 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
32Claimsbaseline..claims[]
8Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 12 sub-modules are flagged red.

Jurisdiction brief

Standing brief, as of 6 September 2026.

Lead Signal

Slovenia's data protection framework is understood to set the national age threshold for a child's own valid consent to information-society services at 15 years under ZVOP-2 Article 8, below the GDPR default of 16, following a correction applied during this cycle's review. The European Commission renewed its adequacy decisions for the United Kingdom under the GDPR and the Law Enforcement Directive on 19 December 2025 as full six-year decisions valid until 27 December 2031, superseding the earlier transitional extension, meaning personal data continues to flow from the UK to Slovenia without additional transfer safeguards.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus regime fully in force with an operational, EDPB-member supervisory authority and confirmed national implementing statute.

Primary frameworkGDPR (Regulation (EU) 2016/679) as implemented and supplemented by ZVOP-2 (Personal Data Protection Act, Official Gazette of the Republic of Slovenia)
Traffic-light rationale — GreenComprehensive omnibus regime fully in force with an operational, EDPB-member supervisory authority and confirmed national implementing statute.

Sub-modules (5)

Regulator And AuthorityGreen

The Information Commissioner is confirmed as Slovenia's GDPR supervisory authority and EDPB member.

Claims (1):

  • The Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec) is the national supervisory authority responsible for enforcing GDPR and ZVOP-2 in Slovenia and is a full voting member of the European Data Protection Board.

Act And InstrumentsGreen

ZVOP-2, adopted 15 December 2022, transposes GDPR into Slovenian law.

Claims (1):

  • Slovenia's Personal Data Protection Act (ZVOP-2), adopted by the National Assembly on 15 December 2022, transposes the GDPR into Slovenian national law.

Material ScopeGreen

ZVOP-2 covers confidentiality of processing, public-area video surveillance, special categories, biometrics, and research/archival/statistical processing.

Claims (2):

  • ZVOP-2 contains specific national provisions on the confidentiality of personal data processing, video surveillance in public areas, and the processing of special categories of personal data.
  • ZVOP-2 additionally regulates transmission of personal data in the public and private sectors, biometric data processing, and personal data processing for research, archival, and statistical purposes.

Territorial ScopeGreen

GDPR Article 3 establishment- and targeting-based territorial scope applies directly in Slovenia as EU law.

Claims (1):

  • As GDPR applies directly in Slovenia as an EU Member State, GDPR Article 3's establishment-based and targeting-based extraterritorial application rules govern controllers/processors operating in or targeting data subjects in Slovenia.

Regulator Registration And FilingAmber

GDPR's abolition of general prior-notification/registration duties applies; no confirmed Slovenia-specific residual general filing regime was located in this pass beyond narrow sectoral possibilities.

Claims (1):

  • GDPR's abolition of general prior notification/registration duties applies in Slovenia; ZVOP-2 does not reinstate a general filing regime, though narrower national filing/registration duties may apply to specific processing operations under national law.
Category narrative78 words

Slovenia is an EU Member State operating under the GDPR as directly-applicable EU law, implemented and supplemented nationally by the Personal Data Protection Act (ZVOP-2), adopted 15 December 2022 and in force since 2023. The Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec) is the single national supervisory authority for both general data protection and, separately, access-to-information matters. ZVOP-2 supplements GDPR with national rules on confidentiality of personal data, public-area video surveillance, biometric data, and research/archival/statistical processing.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedEuropean Data Protection Board — The Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec) is the national supervisory authority responsible for enforcing GDPR and ZVOP-2 in Slovenia and is a full voting member of the European Data Protection Board.observed
  2. ConfirmedDataGuidance — Slovenia's Personal Data Protection Act (ZVOP-2), adopted by the National Assembly on 15 December 2022, transposes the GDPR into Slovenian national law.observed
  3. ConfirmedDataGuidance — ZVOP-2 contains specific national provisions on the confidentiality of personal data processing, video surveillance in public areas, and the processing of special categories of personal data.observed
  4. ConfirmedIAPP — ZVOP-2 additionally regulates transmission of personal data in the public and private sectors, biometric data processing, and personal data processing for research, archival, and statistical purposes.observed
  5. ConfirmedEUR-Lex / European Union — As GDPR applies directly in Slovenia as an EU Member State, GDPR Article 3's establishment-based and targeting-based extraterritorial application rules govern controllers/processors operating in or targeting data subjects in Slovenia.observed
  6. UncertainDataGuidance — GDPR's abolition of general prior notification/registration duties applies in Slovenia; ZVOP-2 does not reinstate a general filing regime, though narrower national filing/registration duties may apply to specific processing operations under national law.observed

#

Core lawful-basis and special-category framework is GDPR-aligned and confirmed in force; one sub-module (consent thresholds) has an unresolved gap.

Primary frameworkGDPR Articles 6-11, supplemented by ZVOP-2
Traffic-light rationale — GreenCore lawful-basis and special-category framework is GDPR-aligned and confirmed in force; one sub-module (consent thresholds) has an unresolved gap.

Sub-modules (4)

Lawful BasesGreen

GDPR Article 6's six lawful bases apply directly; ZVOP-2 adds public-sector derogations rather than replacing them.

Claims (1):

  • The six lawful bases for processing under GDPR Article 6 (consent, contract, legal obligation, vital interests, public task, legitimate interests) apply directly in Slovenia, with ZVOP-2 adding national derogations for certain public-sector processing.

Special CategoriesGreen

ZVOP-2 contains dedicated national rules on special categories and biometric data, supplementing GDPR Article 9.

Claims (1):

  • ZVOP-2 includes dedicated national rules on the processing of special categories of personal data and on biometric data processing, supplementing the GDPR Article 9 regime.

Pseudonymisation And AnonymisationRed

No Slovenia-specific pseudonymisation/anonymisation safe-harbour provisions were identified in this research pass beyond the GDPR baseline definitions.

Absence provenance: No SI-specific secondary source located distinguishing national pseudonymisation/anonymisation rules from the GDPR Article 4(5)/Recital 26 baseline.. Searched: S, l, o, v, e, n, i, a, , Z, V, O, P, -, 2, , p, s, e, u, d, o, n, y, m, i, s, a, t, i, o, n, , a, n, o, n, y, m, i, s, a, t, i, o, n, , s, a, f, e, , h, a, r, b, o, u, r.

Category narrative40 words

GDPR Articles 6-11 apply directly in Slovenia. ZVOP-2 supplements the GDPR special-categories regime (Article 9) with dedicated national rules on biometric data processing. The specific national age-of-consent derogation under GDPR Article 8 could not be confirmed in this research pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedEUR-Lex / European Union — The six lawful bases for processing under GDPR Article 6 (consent, contract, legal obligation, vital interests, public task, legitimate interests) apply directly in Slovenia, with ZVOP-2 adding national derogations for certain public-sector processing.observed
  2. UncertainEUR-Lex / European Union — The precise national age threshold Slovenia has set for a child's own consent to information-society services under the GDPR Article 8 derogation could not be confirmed from available secondary sources in this research pass; the GDPR default of 16 applies absent a confirmed lower national threshold.observed
  3. ConfirmedIAPP — ZVOP-2 includes dedicated national rules on the processing of special categories of personal data and on biometric data processing, supplementing the GDPR Article 9 regime.observed

#

Full GDPR rights suite in force with confirmed active regulator engagement on a specific right (erasure) in the current cycle.

Primary frameworkGDPR Articles 12-22, procedurally supplemented by ZVOP-2
Traffic-light rationale — GreenFull GDPR rights suite in force with confirmed active regulator engagement on a specific right (erasure) in the current cycle.

Sub-modules (5)

Access RightGreen

GDPR Article 15 access right applies directly; no SI-specific derogation identified.

Claims (1):

  • GDPR Articles 13-22 data subject rights, including the right of access under Article 15, apply directly and are enforced by the Slovenian Information Commissioner, supplemented procedurally by ZVOP-2.

Rectification And ErasureGreen

The Slovenian SA is participating in the EDPB's 2025 coordinated enforcement action on the right to erasure.

Claims (1):

  • In 2025, the Slovenian Information Commissioner is participating, alongside 29 other DPAs and the EDPS, in the EDPB's Coordinated Enforcement Framework action focused on controllers' implementation of the right to erasure (Article 17 GDPR).

Restriction And ObjectionAmber

GDPR Articles 18/21 apply directly; no SI-specific case identified in this pass.

Absence provenance: No SI-specific enforcement or guidance item located distinct from the GDPR baseline.. Searched: S, l, o, v, e, n, i, a, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , r, e, s, t, r, i, c, t, i, o, n, , o, b, j, e, c, t, i, o, n, , p, r, o, f, i, l, i, n, g, , o, p, t, -, o, u, t, , e, n, f, o, r, c, e, m, e, n, t.

Data PortabilityAmber

GDPR Article 20 portability right applies directly; no SI-specific implementation guidance identified in this pass.

Absence provenance: No SI-specific secondary source located beyond the GDPR baseline text.. Searched: S, l, o, v, e, n, i, a, , d, a, t, a, , p, o, r, t, a, b, i, l, i, t, y, , G, D, P, R, , A, r, t, i, c, l, e, , 2, 0, , g, u, i, d, a, n, c, e.

Deadlines And Response WindowsGreen

The standard one-month (extendable to three-month) response deadline under GDPR Article 12(3) applies to controller responses in Slovenia.

Claims (1):

  • The one-month standard response deadline (extendable up to three months for complex requests) under GDPR Article 12(3) applies to controller responses to data subject rights requests in Slovenia.
Category narrative35 words

GDPR Articles 13-22 data subject rights apply directly and are enforced by the Information Commissioner. The Slovenian SA is an active participant in the EDPB's 2025 Coordinated Enforcement Framework focused on the right to erasure.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedEUR-Lex / European Union — GDPR Articles 13-22 data subject rights, including the right of access under Article 15, apply directly and are enforced by the Slovenian Information Commissioner, supplemented procedurally by ZVOP-2.observed
  2. ConfirmedEuropean Data Protection Board — In 2025, the Slovenian Information Commissioner is participating, alongside 29 other DPAs and the EDPS, in the EDPB's Coordinated Enforcement Framework action focused on controllers' implementation of the right to erasure (Article 17 GDPR).observed
  3. ConfirmedEUR-Lex / European Union — The one-month standard response deadline (extendable up to three months for complex requests) under GDPR Article 12(3) applies to controller responses to data subject rights requests in Slovenia.observed

#

Core controller/processor duties confirmed in force with recent, concrete enforcement precedent; several sub-modules (ROPA, joint-controller, retention specifics) lack SI-specific secondary sourcing.

Primary frameworkGDPR Articles 5, 24-32, 35, 37-39, supplemented by ZVOP-2
Traffic-light rationale — GreenCore controller/processor duties confirmed in force with recent, concrete enforcement precedent; several sub-modules (ROPA, joint-controller, retention specifics) lack SI-specific secondary sourcing.

Sub-modules (7)

Accountability And DpiaGreen

The 2025 school case confirms active enforcement of GDPR Article 25 privacy-by-design/default duties.

Claims (1):

  • In a 2025 enforcement action, the Slovenian SA reprimanded a school and its principal after finding a failure to implement data protection by design and by default under GDPR Article 25, having granted an external school-meal-service provider unrestricted access to the entire student database, including sensitive subsidy and account-balance data, when only names and surnames were necessary.

Dpo RequirementsAmber

GDPR Articles 37-39 DPO thresholds apply directly; ZVOP-2 does not materially narrow them per available sources.

Claims (1):

  • GDPR Articles 37-39 DPO appointment thresholds (public authorities, large-scale systematic monitoring, large-scale special-category processing) apply directly in Slovenia; no confirmed material narrowing or widening by ZVOP-2 was identified in this pass.

Ropa RequirementsAmber

No Slovenia-specific ROPA guidance beyond the GDPR Article 30 baseline was identified in this pass.

Absence provenance: No SI-specific secondary source located beyond general GDPR Article 30 applicability.. Searched: S, l, o, v, e, n, i, a, , R, O, P, A, , r, e, c, o, r, d, s, , o, f, , p, r, o, c, e, s, s, i, n, g, , A, r, t, i, c, l, e, , 3, 0, , g, u, i, d, a, n, c, e, , I, n, f, o, r, m, a, t, i, o, n, , C, o, m, m, i, s, s, i, o, n, e, r.

Joint Controller ArrangementsAmber

No Slovenia-specific joint-controller guidance was identified in this pass beyond the GDPR Article 26 baseline.

Absence provenance: No SI-specific secondary source located.. Searched: S, l, o, v, e, n, i, a, , j, o, i, n, t, , c, o, n, t, r, o, l, l, e, r, , a, r, r, a, n, g, e, m, e, n, t, s, , A, r, t, i, c, l, e, , 2, 6, , G, D, P, R, , g, u, i, d, a, n, c, e.

Security MeasuresGreen

The 2024 FOVELLA/DODO PIZZA CCTV enforcement action illustrates active supervision of security/lawful-basis compliance under national employment-monitoring rules.

Claims (1):

  • In a 2024 enforcement action, the Slovenian SA fined FOVELLA d.o.o. (operator of the DODO PIZZA franchise) €25,000 for unlawful CCTV monitoring of employees inside a restaurant kitchen and for unlawfully live-broadcasting that footage on the company's website without a valid Article 6 GDPR legal basis, together with a reprimand for failing to inform data subjects under Article 13 GDPR and Article 76 of ZVOP-2.

Breach NotificationGreen

GDPR Article 33's 72-hour breach-notification standard applies; the Information Commissioner maintains and periodically updates national breach-notification guidance/forms.

Claims (1):

  • Controllers in Slovenia must notify the Information Commissioner of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, per GDPR Article 33.

Retention And DisposalAmber

No Slovenia-specific retention/disposal guidance was identified in this pass beyond the GDPR Article 5(1)(e) storage-limitation baseline.

Absence provenance: No SI-specific secondary source located distinguishing national retention rules from the GDPR baseline.. Searched: S, l, o, v, e, n, i, a, , d, a, t, a, , r, e, t, e, n, t, i, o, n, , d, i, s, p, o, s, a, l, , Z, V, O, P, -, 2, , s, t, o, r, a, g, e, , l, i, m, i, t, a, t, i, o, n.

Category narrative37 words

GDPR accountability, DPIA, DPO, ROPA, security, and breach-notification duties apply directly in Slovenia, supplemented by ZVOP-2's stricter national employment-CCTV standard. Recent enforcement (FOVELLA/DODO PIZZA CCTV case, 2024; school data-protection-by-design case, 2025) confirms these duties are actively supervised.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ConfirmedEuropean Data Protection Board (national news, published on behalf of SI SA) — In a 2025 enforcement action, the Slovenian SA reprimanded a school and its principal after finding a failure to implement data protection by design and by default under GDPR Article 25, having granted an external school-meal-service provider unrestricted access to the entire student database, including sensitive subsidy and account-balance data, when only names and surnames were necessary.observed
  2. ProbableEUR-Lex / European Union — GDPR Articles 37-39 DPO appointment thresholds (public authorities, large-scale systematic monitoring, large-scale special-category processing) apply directly in Slovenia; no confirmed material narrowing or widening by ZVOP-2 was identified in this pass.observed
  3. ConfirmedEuropean Data Protection Board (national news, published on behalf of SI SA) — In a 2024 enforcement action, the Slovenian SA fined FOVELLA d.o.o. (operator of the DODO PIZZA franchise) €25,000 for unlawful CCTV monitoring of employees inside a restaurant kitchen and for unlawfully live-broadcasting that footage on the company's website without a valid Article 6 GDPR legal basis, together with a reprimand for failing to inform data subjects under Article 13 GDPR and Article 76 of ZVOP-2.observed
  4. ConfirmedEUR-Lex / European Union — Controllers in Slovenia must notify the Information Commissioner of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, per GDPR Article 33.observed

#

Standard GDPR transfer regime confirmed applicable, with concrete evidence of national SA engagement in the EU consistency mechanism on SCCs.

Primary frameworkGDPR Chapter V (Articles 44-49)
Traffic-light rationale — GreenStandard GDPR transfer regime confirmed applicable, with concrete evidence of national SA engagement in the EU consistency mechanism on SCCs.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Chapter V transfer mechanisms (adequacy, SCCs, BCRs, derogations) apply directly.

Claims (1):

  • GDPR Chapter V transfer mechanisms (adequacy decisions, SCCs, BCRs, derogations) apply directly to Slovenian controllers and processors as EU law.

Adequacy ReceivedGreen

Slovenia is covered by the UK's transitional EU-adequacy regulations, enabling UK-to-Slovenia transfers without additional safeguards.

Claims (1):

  • Slovenia, as an EU Member State, is covered by the UK's transitional EU-adequacy regulations, meaning personal data can flow from the UK to Slovenia without additional transfer safeguards.

Adequacy GrantedGreen

As an EU Member State, Slovenia does not independently grant adequacy; this is an EU Commission competence exercised at Union level.

Absence provenance: Adequacy-granting is an EU-level (European Commission) competence for GDPR Member States; no separate Slovenia-level adequacy determinations exist to report.. Searched: S, l, o, v, e, n, i, a, , n, a, t, i, o, n, a, l, , a, d, e, q, u, a, c, y, , d, e, c, i, s, i, o, n, s, , g, r, a, n, t, e, d.

Sccs And BcrsGreen

The Slovenian SA submitted draft national SCCs (Article 28(8) GDPR) to the EDPB for a consistency opinion (Opinion 17/2020).

Claims (1):

  • The Slovenian supervisory authority submitted draft national standard contractual clauses under Article 28(8) GDPR to the EDPB for a consistency opinion (Opinion 17/2020), indicating national-level SCC engagement alongside the EU-wide SCC toolkit.

Transfer Impact AssessmentAmber

The EU-wide Schrems II transfer-impact-assessment obligation applies directly to Slovenian exporters; no SI-specific TIA guidance beyond EDPB recommendations was identified.

Absence provenance: No SI-specific TIA guidance distinct from EDPB-wide recommendations was located in this pass.. Searched: S, l, o, v, e, n, i, a, , t, r, a, n, s, f, e, r, , i, m, p, a, c, t, , a, s, s, e, s, s, m, e, n, t, , S, c, h, r, e, m, s, , I, I, , g, u, i, d, a, n, c, e, , I, n, f, o, r, m, a, t, i, o, n, , C, o, m, m, i, s, s, i, o, n, e, r.

Data LocalisationGreen

No Slovenia-specific data-localisation mandate beyond the EU-wide GDPR transfer regime was identified in this research pass.

Absence provenance: No evidence of a partial or absolute data-localisation requirement distinct from the GDPR baseline was located.. Searched: S, l, o, v, e, n, i, a, , d, a, t, a, , l, o, c, a, l, i, s, a, t, i, o, n, , m, a, n, d, a, t, e, , p, e, r, s, o, n, a, l, , d, a, t, a.

Category narrative42 words

GDPR Chapter V transfer mechanisms apply directly in Slovenia. Slovenia (as an EU Member State) is covered by the UK's transitional EU-adequacy regulations, and the Slovenian SA has engaged with the EDPB Article 64 consistency mechanism on national SCCs for controller-processor relationships.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedEUR-Lex / European Union — GDPR Chapter V transfer mechanisms (adequacy decisions, SCCs, BCRs, derogations) apply directly to Slovenian controllers and processors as EU law.observed
  2. ConfirmedUK Information Commissioner's Office — Slovenia, as an EU Member State, is covered by the UK's transitional EU-adequacy regulations, meaning personal data can flow from the UK to Slovenia without additional transfer safeguards.observed
  3. ConfirmedEuropean Data Protection Board — The Slovenian supervisory authority submitted draft national standard contractual clauses under Article 28(8) GDPR to the EDPB for a consistency opinion (Opinion 17/2020), indicating national-level SCC engagement alongside the EU-wide SCC toolkit.observed

#

Two of seven sub-modules (employment, education) have confirmed findings; five carry absent_field_provenance gaps requiring primary-source escalation.

Primary frameworkZVOP-2 sector-specific provisions supplementing GDPR
Traffic-light rationale — AmberTwo of seven sub-modules (employment, education) have confirmed findings; five carry absent_field_provenance gaps requiring primary-source escalation.

Sub-modules (7)

Financial Sector OverlayRed

No Slovenia-specific financial-sector DP overlay was identified in this research pass.

Absence provenance: No SI-specific secondary source located on banking-secrecy/financial-sector DP overlay in this pass.. Searched: S, l, o, v, e, n, i, a, , f, i, n, a, n, c, i, a, l, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , o, v, e, r, l, a, y, , b, a, n, k, i, n, g, , s, e, c, r, e, c, y, , G, D, P, R.

Health Sector OverlayRed

No Slovenia-specific health-sector DP overlay was identified in this research pass.

Absence provenance: No SI-specific secondary source located on health-sector DP overlay in this pass.. Searched: S, l, o, v, e, n, i, a, , h, e, a, l, t, h, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , o, v, e, r, l, a, y, , p, a, t, i, e, n, t, , d, a, t, a, , G, D, P, R.

Telecoms And EprivacyRed

No Slovenia-specific ePrivacy/telecoms enforcement or transposition detail was confirmed in this research pass.

Absence provenance: No SI-specific secondary source located confirming the national ePrivacy transposition instrument name or recent enforcement.. Searched: S, l, o, v, e, n, i, a, , e, P, r, i, v, a, c, y, , D, i, r, e, c, t, i, v, e, , t, r, a, n, s, p, o, s, i, t, i, o, n, , t, e, l, e, c, o, m, s, , c, o, o, k, i, e, s, , e, n, f, o, r, c, e, m, e, n, t.

Employment DataGreen

ZVOP-2 Article 78 imposes an ultima ratio standard restricting employee video surveillance, confirmed via the 2024 FOVELLA enforcement action.

Claims (1):

  • ZVOP-2 Article 78 imposes an ultima ratio (last-resort) standard restricting employee video surveillance to circumstances absolutely necessary for the safety of people or property, a national employment-data overlay stricter than default GDPR Article 6 balancing.

Credit And ScoringRed

No Slovenia-specific credit-scoring DP overlay was identified in this research pass.

Absence provenance: No SI-specific secondary source located.. Searched: S, l, o, v, e, n, i, a, , c, r, e, d, i, t, , s, c, o, r, i, n, g, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , o, v, e, r, l, a, y.

EducationGreen

The 2025 school case confirms an operative education-sector DP overlay concerning minors' data and third-party processor access.

Claims (1):

  • The Slovenian SA's 2025 enforcement action against a school over unauthorized meal-service-provider access to student data confirms an operative education-sector overlay of GDPR Article 25 data-protection-by-design duties.

InsuranceRed

No Slovenia-specific insurance-sector DP overlay was identified in this research pass.

Absence provenance: No SI-specific secondary source located.. Searched: S, l, o, v, e, n, i, a, , i, n, s, u, r, a, n, c, e, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , o, v, e, r, l, a, y.

Category narrative47 words

Direct sectoral-overlay evidence was limited in this research pass to the employment/education sectors. ZVOP-2 imposes a stricter-than-GDPR-default ultima ratio standard for employee video surveillance, and the 2025 school case demonstrates operative education-sector enforcement. Financial, health, telecoms/ePrivacy, credit-scoring, and insurance overlays were not independently confirmed in this pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ConfirmedEuropean Data Protection Board (national news, published on behalf of SI SA) — ZVOP-2 Article 78 imposes an ultima ratio (last-resort) standard restricting employee video surveillance to circumstances absolutely necessary for the safety of people or property, a national employment-data overlay stricter than default GDPR Article 6 balancing.observed
  2. ConfirmedEuropean Data Protection Board (national news, published on behalf of SI SA) — The Slovenian SA's 2025 enforcement action against a school over unauthorized meal-service-provider access to student data confirms an operative education-sector overlay of GDPR Article 25 data-protection-by-design duties.observed

#

General EU ePrivacy framework presumed applicable, but no SI-specific enforcement or guidance located across any of the six sub-modules in this pass.

Primary frameworkePrivacy Directive (2002/58/EC) national transposition, operating alongside GDPR
Traffic-light rationale — AmberGeneral EU ePrivacy framework presumed applicable, but no SI-specific enforcement or guidance located across any of the six sub-modules in this pass.

Sub-modules (6)

Cookies And TrackersAmber

Cookie/tracker consent is presumed governed by the national ePrivacy transposition alongside GDPR consent standards; the specific national instrument name was not independently verified in this pass.

Claims (1):

  • Cookie and tracker consent in Slovenia is presumed governed by the national transposition of the ePrivacy Directive (2002/58/EC) operating alongside GDPR consent standards and enforced by the Information Commissioner; no Slovenia-specific adtech enforcement action was identified in this research pass.

Dark PatternsRed

No SI-specific dark-pattern enforcement was identified in this research pass.

Absence provenance: No SI-specific secondary source located.. Searched: S, l, o, v, e, n, i, a, , d, a, r, k, , p, a, t, t, e, r, n, s, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , e, n, f, o, r, c, e, m, e, n, t.

Opt Out SignalsRed

No SI-specific Global Privacy Control/DAA opt-out signal guidance was identified in this research pass.

Absence provenance: No SI-specific secondary source located.. Searched: S, l, o, v, e, n, i, a, , G, l, o, b, a, l, , P, r, i, v, a, c, y, , C, o, n, t, r, o, l, , o, p, t, -, o, u, t, , s, i, g, n, a, l, , g, u, i, d, a, n, c, e.

Clean Rooms And DcrRed

No SI-specific data clean-room/collaboration-room guidance was identified in this research pass.

Absence provenance: No SI-specific secondary source located.. Searched: S, l, o, v, e, n, i, a, , d, a, t, a, , c, l, e, a, n, , r, o, o, m, , d, a, t, a, , c, o, l, l, a, b, o, r, a, t, i, o, n, , r, o, o, m, , g, u, i, d, a, n, c, e.

Cross Context AdvertisingRed

No SI-specific cross-context advertising enforcement or guidance was identified in this research pass.

Absence provenance: No SI-specific secondary source located.. Searched: S, l, o, v, e, n, i, a, , c, r, o, s, s, -, c, o, n, t, e, x, t, , a, d, v, e, r, t, i, s, i, n, g, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , e, n, f, o, r, c, e, m, e, n, t.

Direct MarketingAmber

No SI-specific direct-marketing consent/suppression guidance was identified in this research pass beyond the GDPR/ePrivacy baseline.

Absence provenance: No SI-specific secondary source located distinct from the GDPR/ePrivacy baseline.. Searched: S, l, o, v, e, n, i, a, , d, i, r, e, c, t, , m, a, r, k, e, t, i, n, g, , c, o, n, s, e, n, t, , s, u, p, p, r, e, s, s, i, o, n, , l, i, s, t, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n.

Category narrative41 words

No Slovenia-specific adtech enforcement action (cookies/dark patterns/cross-context advertising) was identified in this research pass. Cookie and tracker consent is presumed governed by the national ePrivacy Directive transposition operating alongside GDPR consent standards, but the specific national instrument was not independently verified.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. UncertainEuropean Data Protection Board — Cookie and tracker consent in Slovenia is presumed governed by the national transposition of the ePrivacy Directive (2002/58/EC) operating alongside GDPR consent standards and enforced by the Information Commissioner; no Slovenia-specific adtech enforcement action was identified in this research pass.observed

#

Confirmed national biometric and surveillance provisions plus active AI-privacy engagement, but three of six sub-modules lack SI-specific sourcing.

Primary frameworkGDPR Article 22 and ZVOP-2 national biometric/surveillance provisions
Traffic-light rationale — AmberConfirmed national biometric and surveillance provisions plus active AI-privacy engagement, but three of six sub-modules lack SI-specific sourcing.

Sub-modules (6)

Profiling RestrictionsAmber

GDPR Article 22 profiling restrictions apply directly; no SI-specific elaboration identified in this pass.

Absence provenance: No SI-specific secondary source located beyond the GDPR baseline.. Searched: S, l, o, v, e, n, i, a, , p, r, o, f, i, l, i, n, g, , r, e, s, t, r, i, c, t, i, o, n, s, , A, r, t, i, c, l, e, , 2, 2, , G, D, P, R, , g, u, i, d, a, n, c, e.

Automated Decision Making TransparencyAmber

GDPR Article 22 ADM transparency/explanation rights apply directly; no SI-specific elaboration identified in this pass.

Absence provenance: No SI-specific secondary source located beyond the GDPR baseline.. Searched: S, l, o, v, e, n, i, a, , a, u, t, o, m, a, t, e, d, , d, e, c, i, s, i, o, n, , m, a, k, i, n, g, , t, r, a, n, s, p, a, r, e, n, c, y, , g, u, i, d, a, n, c, e.

Ai Risk AssessmentsGreen

The Information Commissioner co-signed a February 2026 international joint statement on AI-generated imagery and privacy risk.

Claims (1):

  • The Information Commissioner of the Republic of Slovenia is a signatory to a February 2026 multi-regulator Joint Statement on AI-Generated Imagery and the Protection of Privacy, alongside other global data protection and privacy authorities.

Biometric RegimeGreen

ZVOP-2 contains a dedicated national legal framework regulating biometric data processing.

Claims (1):

  • ZVOP-2 contains a dedicated national legal framework regulating biometric data processing, operating as a national specification permitted under GDPR Article 9(4).

Genetic DataAmber

No SI-specific genetic-data regime elaboration was identified in this research pass beyond the GDPR Article 9 baseline.

Absence provenance: No SI-specific secondary source located beyond the GDPR Article 9 baseline.. Searched: S, l, o, v, e, n, i, a, , g, e, n, e, t, i, c, , d, a, t, a, , Z, V, O, P, -, 2, , s, p, e, c, i, a, l, , c, a, t, e, g, o, r, y, , r, e, g, i, m, e.

State Surveillance CarveoutsGreen

ZVOP-2 separately regulates video surveillance in public areas as a national carve-out area addressed alongside GDPR's general processing rules.

Claims (1):

  • ZVOP-2 separately regulates video surveillance in public areas, addressed alongside (not superseding) GDPR's general processing rules.
Category narrative50 words

ZVOP-2 contains a dedicated national biometric-data regime and separately addresses public-area video surveillance. The Slovenian Information Commissioner has also co-signed a February 2026 international joint statement on AI-generated imagery and privacy. Profiling restrictions, ADM transparency, and genetic-data specifics rely on the GDPR baseline without confirmed SI-specific elaboration in this pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedEuropean Data Protection Supervisor (co-signatories) — The Information Commissioner of the Republic of Slovenia is a signatory to a February 2026 multi-regulator Joint Statement on AI-Generated Imagery and the Protection of Privacy, alongside other global data protection and privacy authorities.observed
  2. ConfirmedIAPP — ZVOP-2 contains a dedicated national legal framework regulating biometric data processing, operating as a national specification permitted under GDPR Article 9(4).observed
  3. ConfirmedDataGuidance — ZVOP-2 separately regulates video surveillance in public areas, addressed alongside (not superseding) GDPR's general processing rules.observed

#

One sub-module (education settings) is well-evidenced; age verification/parental consent, minor profiling bans, and dependent adults carry unresolved gaps.

Primary frameworkGDPR Article 8, supplemented by ZVOP-2 and education-sector enforcement precedent
Traffic-light rationale — AmberOne sub-module (education settings) is well-evidenced; age verification/parental consent, minor profiling bans, and dependent adults carry unresolved gaps.

Sub-modules (5)

Age VerificationAmber

Slovenia's specific national age-of-consent threshold was not confirmed in this research pass.

Claims (1):

  • Slovenia's specific national age-of-consent threshold under the GDPR Article 8 derogation for children's consent to information-society services was not confirmed in this research pass; absent a confirmed derogation, the GDPR default age of 16 would presumptively apply.

Minor Profiling BansRed

No Slovenia-specific minor-profiling ban was identified in this research pass beyond the GDPR Recital 38 baseline caution on profiling minors.

Absence provenance: No SI-specific secondary source located.. Searched: S, l, o, v, e, n, i, a, , m, i, n, o, r, , p, r, o, f, i, l, i, n, g, , b, a, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n.

Education SettingsGreen

The 2025 school case is direct evidence of operative enforcement protecting minors' data in the education setting.

Claims (1):

  • The 2025 Slovenian SA decision addressing unauthorized third-party access to a school's student database (including minors' subsidy and financial data) demonstrates operative enforcement of data-protection-by-design duties in the education setting for minors' data.

Dependent AdultsRed

No Slovenia-specific dependent-adult data-protection provisions were identified in this research pass.

Absence provenance: No SI-specific secondary source located.. Searched: S, l, o, v, e, n, i, a, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, s, , e, l, d, e, r, l, y, , i, n, c, a, p, a, c, i, t, a, t, e, d, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , p, r, o, v, i, s, i, o, n, s.

Category narrative39 words

The 2025 school enforcement case confirms operative protection of minors' data in the education setting. The specific national age-of-consent threshold under GDPR Article 8 was not confirmed in this pass, and minor-profiling-ban and dependent-adult specifics were not independently identified.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. UncertainEUR-Lex / European Union — Slovenia's specific national age-of-consent threshold under the GDPR Article 8 derogation for children's consent to information-society services was not confirmed in this research pass; absent a confirmed derogation, the GDPR default age of 16 would presumptively apply.observed
  2. ConfirmedEuropean Data Protection Board (national news, published on behalf of SI SA) — The 2025 Slovenian SA decision addressing unauthorized third-party access to a school's student database (including minors' subsidy and financial data) demonstrates operative enforcement of data-protection-by-design duties in the education setting for minors' data.observed

#

Regulator powers, penalty ceilings, and recent enforcement activity are well-evidenced; regulator funding/capacity specifics remain unconfirmed.

Primary frameworkGDPR Articles 58, 77-84, supplemented by ZVOP-2 procedural provisions
Traffic-light rationale — GreenRegulator powers, penalty ceilings, and recent enforcement activity are well-evidenced; regulator funding/capacity specifics remain unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Information Commissioner may impose GDPR Article 83 maximum fines and other corrective measures (reprimands, processing bans).

Claims (1):

  • The Information Commissioner may impose administrative fines up to the GDPR Article 83 maxima (up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements), alongside corrective powers such as reprimands and processing bans.

Enforcement Activity IndexGreen

2023 annual report figures and the 2024 FOVELLA fine evidence active enforcement.

Claims (2):

  • During 2023, Slovenia's Information Commissioner received, handled, and advised on 1,146 requests to open investigation procedures, including 7 cases of unauthorized processing, as reported in its annual report submitted to the National Assembly on 21 May 2024.
  • In 2024, the Slovenian SA imposed a €25,000 administrative fine on FOVELLA d.o.o. for unlawful employee CCTV monitoring and unlawful live broadcast of that footage, together with a reprimand for transparency failures.

Regulator Funding And CapacityAmber

No specific headcount/budget figures for the Information Commissioner were identified in this research pass.

Absence provenance: No SI-specific secondary source with funding/headcount figures was located in this pass.. Searched: S, l, o, v, e, n, i, a, , I, n, f, o, r, m, a, t, i, o, n, , C, o, m, m, i, s, s, i, o, n, e, r, , b, u, d, g, e, t, , h, e, a, d, c, o, u, n, t, , c, a, p, a, c, i, t, y, , 2, 0, 2, 5, , 2, 0, 2, 6.

Collective Redress And Class ActionsAmber

GDPR Article 80 representative-action mechanics apply directly; no SI-specific collective-redress expansion was confirmed.

Claims (1):

  • GDPR Articles 79-80 provide data subjects in Slovenia with a direct judicial remedy against controllers/processors and the right to mandate a not-for-profit body to lodge complaints or seek judicial remedy on their behalf; no SI-specific expansion of collective redress beyond the GDPR baseline was confirmed in this pass.

Private Right Of ActionGreen

GDPR Article 79 provides a direct judicial remedy for data subjects against controllers/processors in Slovenia.

Claims (1):

  • GDPR Articles 79-80 provide data subjects in Slovenia with a direct judicial remedy against controllers/processors and the right to mandate a not-for-profit body to lodge complaints or seek judicial remedy on their behalf; no SI-specific expansion of collective redress beyond the GDPR baseline was confirmed in this pass.

Recent Developments 180DGreen

Within the recent reporting window, the Slovenian SA is running the 2025 EDPB right-to-erasure coordinated enforcement action and co-signed a February 2026 joint statement on AI-generated imagery privacy risk.

Claims (1):

  • The Slovenian SA is running its 2025 EDPB Coordinated Enforcement Framework action on the right to erasure and issued a May 2025 decision on school data-protection-by-design failures; a February 2026 joint international statement on AI-generated imagery privacy risks was also co-signed by the Slovenian Information Commissioner.
Category narrative58 words

The Information Commissioner holds full GDPR Article 58/83 investigative and corrective powers, including fines up to the GDPR maxima. Enforcement activity in the reporting window includes the 2024 FOVELLA/DODO PIZZA fine, the 2025 school data-protection-by-design reprimand, and ongoing participation in the EDPB's 2025 right-to-erasure coordinated enforcement action. GDPR Articles 79-80 provide direct judicial remedy and representative-body complaint mechanisms.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedEUR-Lex / European Union — The Information Commissioner may impose administrative fines up to the GDPR Article 83 maxima (up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements), alongside corrective powers such as reprimands and processing bans.observed
  2. ConfirmedDataGuidance — During 2023, Slovenia's Information Commissioner received, handled, and advised on 1,146 requests to open investigation procedures, including 7 cases of unauthorized processing, as reported in its annual report submitted to the National Assembly on 21 May 2024.observed
  3. ConfirmedEuropean Data Protection Board (national news, published on behalf of SI SA) — In 2024, the Slovenian SA imposed a €25,000 administrative fine on FOVELLA d.o.o. for unlawful employee CCTV monitoring and unlawful live broadcast of that footage, together with a reprimand for transparency failures.observed
  4. ProbableEUR-Lex / European Union — GDPR Articles 79-80 provide data subjects in Slovenia with a direct judicial remedy against controllers/processors and the right to mandate a not-for-profit body to lodge complaints or seek judicial remedy on their behalf; no SI-specific expansion of collective redress beyond the GDPR baseline was confirmed in this pass.observed
  5. ConfirmedEuropean Data Protection Board — The Slovenian SA is running its 2025 EDPB Coordinated Enforcement Framework action on the right to erasure and issued a May 2025 decision on school data-protection-by-design failures; a February 2026 joint international statement on AI-generated imagery privacy risks was also co-signed by the Slovenian Information Commissioner.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct72.22
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Slovenia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 32 claim(s) (32 category placement(s)), 18 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 8Children & Vulnerable Groupsparental consent
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator identity, act adoption, biometric/video-surveillance material scope, and enforcement precedent (FOVELLA/DODO PIZZA 2024; school DPbD case 2025) are grounded in T2 (EDPB national-news) and T1 (GDPR text, EDPB Art.64 Opinion 17/2020, UK ICO adequacy page) sources. Act-adoption dates, annual-report statistics, and general ZVOP-2 scope descriptions rely on T3 secondary sources (DataGuidance, IAPP) because primary Official Gazette ZVOP-2 full text was not directly retrieved in this pass. Sub-modules for ROPA, joint-controller arrangements, retention/disposal, most sectoral overlays (financial, health, telecoms/ePrivacy, credit-scoring, insurance), most adtech sub-modules, profiling/ADM/genetic-data specifics, age-of-consent threshold, minor-profiling bans, dependent adults, and regulator funding/capacity carry no SI-specific secondary sourcing and are flagged with absent_field_provenance rather than fabricated.

Unresolved questions (7):

  • What specific national age-of-consent threshold (if any, under GDPR Article 8) has Slovenia set for a child's own consent to information-society services?
  • Does ZVOP-2 set DPO-appointment thresholds materially different from the GDPR Articles 37-39 baseline?
  • Are there Slovenia-specific ROPA (Article 30), joint-controller (Article 26), or retention/disposal (Article 5(1)(e)) elaborations beyond the GDPR baseline?
  • What are the operative financial-sector, health-sector, telecoms/ePrivacy, credit-scoring, and insurance-sector DP overlays in Slovenia, and what is the specific national ePrivacy transposition instrument?
  • Has the Slovenian SA taken any dark-pattern, cross-context-advertising, or Global Privacy Control/opt-out-signal enforcement or guidance actions?
  • What is the current headcount/budget of the Information Commissioner's office, relevant to regulator_funding_and_capacity?
  • Has ZVOP-2 or subsequent Slovenian legislation expanded collective redress/class-action mechanisms beyond the GDPR Article 80 baseline?

Escalate to primary-source review: yes