Data Protection in Slovenia

Breach notification in Slovenia

In relation to data breaches, in Article 23 ZVOP-2 regulates data security in the field of special processing, which also involves reporting breaches. This article specifies that for certain information systems, the provisions on risk management measures and reporting incidents from the Information Security Act (Zakon o informacijski varnosti) apply mutatis mutandis. These provisions concern essential entities if the controller is not obliged to implement measures under the Information Security Act for these processing activities.

Localization rules apply exist in case of special processing of personal information within information systems in which processing of the following categories of personal data is carried out:

  • personal data specified in the laws governing administrative internal affairs,
  • financial administration,
  • citizenship,
  • the Slovenian Intelligence and Security Agency,
  • defence,
  • healthcare,
  • mandatory health insurance,
  • the exercise of rights deriving from public funds, and
  • criminal and minor offence records.

Such data records must be kept within the territory of the Republic of Slovenia.

Continue reading

  • no results

Previous topic
Back to top