TerraLex Guide to Data Protection

Welcome to the Terralex cross-border guide to data protection

Data protection continues to be a top issue for companies around the globe. With the ever-changing technology and responding legislation, it is important that businesses be prepared to handle a patchwork of data protection regulations. This guide, prepared by TerraLex members from around the globe, provides initial guidance on some of the key aspects to consider.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Slovak Republic TerraLex Guide to Data Protection Guide

Date posted:
08/04/2025
Last update:
25/04/2025

Legislation and regulations

What national laws regulate the processing of personal data in your jurisdiction?

The main laws on personal data processing in the Slovak Republic are:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (the “GDPR”) and

  • Act No. 18/2018 Coll. on the Protection of Personal Data and on Amending and Supplementing Certain Acts, as amended (“Act No. 18/2018 on Personal Data Protection”). This Act was adopted to bring Slovak data protection rules in line with the GDPR. It was enacted partly on the basis of the GDPR’s opening clauses which authorize or require EU member states to define their own rules for specific types of data processing. In addition, the Act covers the processing of personal data in situations that fall outside the scope of EU law (e.g. national security) and transposes the EU Law Enforcement Directive 2016/680 (the “Law Enforcement Directive”).

To whom do the laws apply?

The GDPR applies to:

  • Controllers or processors based in the European Union regardless of where the processing takes place;
  • Non-EU controllers or processors who:
    • Offer goods or services to individuals in the EU (even if free), or
    • Monitor the behaviour of individuals in the EU (cookies, profiling, etc.).

Act No. 18/2018 on Personal Data Protection (the “Act”) applies to:

  • Controllers or processors who have their presence:
    • In the territory of the Slovak Republic, regardless of where the actual data processing takes place; or
    • In a location where Slovak law applies under international public law principles;
  • The processing of personal data of individuals located in the Slovak Republic by controllers or processors established outside the EU, where the processing is related to:
    • The offering of goods or services to individuals in Slovakia, or
    • The monitoring of their behaviour within Slovak territory.

From a material perspective, the Act governs the following areas:

  • The processing of personal data that falls outside the scope of the GDPR;
  • The processing of personal data by competent authorities (police, criminal justice authorities) for the purposes of criminal proceedings, in accordance with the transposition of the Law Enforcement Directive;
  • The processing of personal data within the scope of the GDPR, insofar as the Act provides for specific national provisions under the GDPR’s opening clauses. These include rules applicable to the processing of personal data for purposes such as employment, academic, artistic, or literary activities, as well as the processing of national identification numbers, genetic and biometric data, data processed for scientific, historical research, or statistical purposes, etc.

In addition, the Act establishes the competence and responsibilities of the national data protection authority – the Office for Personal Data Protection of the Slovak Republic.

For most private and public sector controllers / processors, the Act does not apply at all, with the exceptions such as national provisions that complement the GDPR and the provisions on proceedings before the Office for Personal Data Protection of the Slovak Republic.

Scope of protection

What type of data is covered by the law?

Personal data of individuals (data subjects) as defined in the GDPR, i.e. any information relating to an identified or identifiable natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

What are the main exemptions (if any)?

The GDPR does not apply to processing of personal data:

  • By a natural person for purely personal or household activities;
  • In the course of activities outside the scope of EU law, such as national security or defence;
  • In connection with the EU Common Security and Defence Policy;
  • By law enforcement authorities where such processing is governed by the Law Enforcement Directive rather than the GDPR and
  • By EU institutions, which are covered by a separate regulation.

Act No. 18/2018 on Personal Data Protection (the “Act”) does not apply to the processing of personal data:

  • By a natural person for personal or household activities,
  • By the Slovak Information Service, Military Intelligence Service and the National Security Office for specified purposes, and
  • Of deceased persons.

The Act does not apply to data processing activities subject to the GDPR, except where it provides specific national rules in certain areas based on the GDPR’s opening clauses.

What rights do the laws grant to the data owners?

The personal data belong to the individuals they concern (data subjects).

Under the GDPR, data subjects are granted the following rights:

  • the right to be informed on data processing,
  • the right of access to data,
  • the right to rectification of data,
  • the right to erasure of data (the right to be forgotten),
  • the right to restrict processing of data,
  • the right to data portability,
  • the right to object to data processing,
  • the right to withdraw consent to data processing,
  • rights related to automated decision-making and profiling and
  • the right to lodge a complaint with a data protection authority.

The rights granted to data subjects under Act No. 18/2018 on Personal Data Protection largely mirror those set out in the GDPR.

Processing requirement and main obligations

What are the lawful grounds for processing personal data or sensitive personal data (if different)?

Under the GDPR, personal data can be processed lawfully if one of the following legal bases applies:

  • The data subject's explicit consent,
  • The necessity for the performance of a contract,
  • Compliance with a legal obligation,
  • Protection of vital interests,
  • Performance of a public task, or
  • Pursuit of legitimate interests by the data controller or a third party.

For processing sensitive personal data (special categories of data), stricter conditions apply. Sensitive personal data covers personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic and biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation. The processing of sensitive personal data under the GDPR is lawful only if one of the legal grounds mentioned above applies, and at the same time, one of the following conditions is met:

  • If explicit consent is obtained,
  • If necessary for:
    • Employment and social security law,
    • Protecting vital interests,
    • Defending legal claims,
    • Reasons of substantial public interest,
    • Health/social care purposes or
    • Fulfilling public health obligations.
  • If processing is carried out by non-profit organizations with political, philosophical, religious, or trade union aims.

Processing of personal data relating to criminal convictions and offenses is only permitted where authorized by EU or EU member state law.

The legal bases for processing personal data under Act No. 18/2018 on Personal Data Protection are generally in line with those set out in the GDPR. However, there are specific national provisions based on the GDPR’s opening clauses which regulate special situations of lawful processing of personal data and that apply to:

  • The processing of personal data for academic, artistic, or literary purposes,
  • The processing of personal data for the purpose of informing the public through mass media,
  • The sharing or publication of certain employee personal data by employers,
  • The processing of a generally applicable identifier (such as a birth identification number),
  • The processing of genetic, biometric, and health-related data,
  • The processing of personal data about a data subject obtained from another natural person,
  • The processing of personal data for archival, scientific, historical research, or statistical purposes.

What are the main obligations imposed by the law?

The GDPR imposes a range of obligations on data controllers and processors to ensure the lawful and responsible handling of personal data. The key duties include:

  • Processing personal data in accordance with the fundamental principles - Controllers and processors must ensure that data is processed lawfully, fairly, and transparently; collected for specific and legitimate purposes; limited to what is necessary; kept accurate and up to date; stored only as long as needed; and protected through appropriate security measures. They must also be able to demonstrate compliance with these obligations;
  • Maintaining detailed records of processing activities;
  • Conducting data protection impact assessments (DPIAs) where processing is likely to result in a high risk to individuals’ rights and freedoms;
  • Appointing a Data Protection Officer (DPO) in certain circumstances;
  • Implementing appropriate safeguards and security measures;
  • Ensuring data subjects´ rights are respected;
  • Notifying personal data breaches to the data protection authority within 72 hours, and to affected data subjects where there is a high risk.

The main obligations under Act No. 18/2018 on Personal Data Protection largely mirror those set out in the GDPR.

Do the laws establish a data retention period to be observed?

The GDPR does not prescribe exact retention periods. Instead, it requires that personal data be retained only for as long as necessary to fulfill the purposes for which it was collected, in line with the principle of storage limitation.

Act No.18/2018 on Personal Data Protection also does not include any data retention periods and is fully in line with the retention minimalization principle.

Various retention periods are specified in some Slovak laws, for instance:

  • Tax and accounting documents 10 years;
  • Employee´s personnel file 70 years after the employee´s birth;
  • AML documents 5 years;
  • Internal records on ultimate beneficial owners 5 years, etc.

If no specific retention periods are set by special laws, data controllers must determine an appropriate retention period themselves based on the purpose of the processing and the necessity of keeping the data, while always aligning with the storage limitation principle.

Must the data processing activities be recorded under the law?

Under the GDPR, most data controllers and processors are required to maintain a record of their processing activities.

Recording under Act No. 18/2018 on Personal Data Protection largely mirrors the provisions for recording set out in the GDPR.

National authority and DPO

Is there a Data Protection National Authority? If so, what is the National Authority main role?

Yes, the Personal Data Protection Office of the Slovak Republic (the “Office”).

The Office serves as the state administration body with nationwide competence. It supervises the protection of personal data, including the protection of personal data processed by competent authorities in the performance of tasks for the purposes of criminal proceedings and carries out inspections, which are also associated with sanctions. The Office also provides methodological guidelines and explanatory opinions; cooperates with the EDPB and supervisory authorities of other EU member states; approves codes of conduct, etc.

Does the law impose the obligation of designating a data protection officer (DPO)? If so, what is the role of the DPO under the law?

The GDPR imposes the obligation to designate a data protection officer (DPO) in certain circumstances. These include situations

  • where processing is carried out by a public authority or body,
  • where the core activities of an organization involve large-scale, regular, and systematic monitoring of individuals, or
  • where there is large-scale processing of sensitive personal data or data relating to criminal convictions.

The DPO is responsible for overseeing data protection strategy and compliance within an organization. Their key tasks include monitoring adherence to data protection laws, advising on legal obligations, guiding data protection impact assessments, and serving as a contact point for data protection authorities and data subjects.

The conditions under which the controller or processor is obliged to designate a DPO and the role of the DPO under Act No. 18/2018 on Personal Data Protection largely mirrors the role set out in the GDPR.

Cross-border transfers

What rules regulate the transfer of data outside your jurisdiction?

Transfers of personal data from Slovakia to EU or EEA countries are not restricted, because all these countries are bound by the same data protection rules under the GDPR.

Transfers of personal data from Slovakia to countries outside the EU/EEA (third countries) are only allowed if the destination ensures an adequate level of data protection. This can be confirmed through an adequacy decision by the European Commission, or, if no such decision exists, by implementing appropriate safeguards such as standard contractual clauses (SCCs), binding corporate rules (BCRs), or approved codes of conduct or certification mechanisms. In exceptional cases, transfers may also be based on specific derogations, such as the data subject’s explicit consent or necessity for contractual or legal purposes.

Act No. 18/2018 on Personal Data Protection follows the GDPR rules for international data transfers, and does not impose additional conditions beyond those provided by the GDPR.

Is it necessary to notify the National Authority prior to the international transfer?

No, it is not necessary to notify the Slovak Data Protection Office in advance of an international data transfer as long as the transfer complies with the GDPR. In very limited cases, if data transfer is based on specific derogations under Article 49 GDPR, and none of the safeguards apply, the Slovak Data Protection Office may require notification.

Act No. 18/2018 on Personal Data Protection mirror the rules in the GDPR.

Security standards, data breaches, and sanctions

Do the laws impose any information security standards and/or requirements?

Neither the GDPR nor Act No. 18/2018 on Personal Data Protection set specific technical standards. Instead, they require a risk-based approach and that data controllers and processors implement appropriate technical and organizational measures to ensure the security of personal data.

Special Slovak laws may impose such standards or requirements for specific purposes, e.g., cybersecurity legislation.

Do the laws establish any kind of mandatory notification duty?

Yes, both the GDPR and Act No. 18/2018 on Personal Data Protection establish mandatory notification duties in the event of a personal data breach, in particular notification to the data protection authority and, as the case may be, to data subjects.

Depending on the type of breach and affected data, additional authorities may also need to be notified, e.g., the National Security Authority and its CSIRT.SK team (Computer Security Incident Response Team Slovakia), for cybersecurity incidents in information technologies in public administrations and systems or other relevant systems.

What are the sanctions for noncompliance with data protection laws?

The GDPR empowers data protection authorities (like the Slovak Personal Data Protection Office) to impose administrative fines and execute other corrective powers, for instance to:

  • Issue of warnings or reprimands,
  • Impose temporary or permanent bans on processing,
  • Order to erase or rectify data,
  • Suspense data transfers
  • Impose other obligations, etc.

In certain cases, criminal liability may also arise if personal data protection rules are intentionally violated.

Other comments

Other comments

For most data controllers and processors, the processing of personal data must be carried out primarily in accordance with the GDPR. Only certain parts of Slovak Act No. 18/2018 on Personal Data Protection are relevant to them in particular those that supplement the GDPR based on its opening clauses and regulate data processing in some areas or regulate administrative proceedings before the Slovak Personal Data Protection Office.

The remaining provisions of Slovak Act No. 18/2018 on Personal Data Protection apply only in situations where the GDPR does not apply; however, those provisions largely mirror the GDPR, with only a few exceptions.

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.