What Is Personal Data Protection Act (ZVOP-2)?
Slovenia’s operative national statute is the Personal Data Protection Act (ZVOP-2), Official Gazette No. 163/2022. It was adopted on 15 December 2022, published on 27 December 2022, and entered into force on 26 January 2023. ZVOP-2 replaced ZVOP-1, which remained valid until that date despite the GDPR’s application from 25 May 2018. The current PISRS consolidated working text is marked NPB2 and incorporates ZVOP-2, ZInfV-1, and the 2026 ZP-1L amendment, but PISRS states that the consolidation is unofficial and informational. GDPR remains the baseline for Chapter III rights, complaints, remedies, and fines, while ZVOP-2 regulates their exercise and adds Slovenian procedures, safeguards, and purpose-specific restrictions. The law contains detailed rules for expression and public information, research, historical archives, statistics, children’s consent, linking signs such as EMŠO, criminal and misdemeanour data, and access to information about deceased persons for 20 years after death. A genuinely current penalty finding is that Articles 95(2), 96, and 97 ceased to apply on 25 February 2026 under the 2026 ZP-1L amendment. Slovenia has no simple data-broker-specific removal route in the reviewed materials: the general routes are GDPR Article 17 against the relevant controller and a complaint to the Information Commissioner, subject to public-book, expression, research, statistical, and archive rules.
At a glance
- Full name
- Personal Data Protection Act (ZVOP-2)
- Short code
- ZVOP-2
- Jurisdiction
- Slovenia
- Enacted
- 2022
- Last major update
- The PISRS NPB2 working text incorporates ZVOP-2, the Information Security Act amendment ZInfV-1, and the 2026 Minor Offences Act amendment ZP-1L; ZVOP-2 Articles 95(2), 96, and 97 ceased to apply on 25 February 2026
- Regulator
- Information Commissioner
- Private right of action
- Limited
- Statutory citation
- Personal Data Protection Act (ZVOP-2), Official Gazette No. 163/2022
Scope, who ZVOP-2 covers
Protected data
Data subject rights
Right to information and transparency, with a one-month response period extendable by two months
Right to appeal a controller refusal to the Information Commissioner within 15 days of service
Right of access, subject to research, archive, and statistical safeguards
Right to rectification, subject to specified archive and state-statistics limitations
Right to erasure subject to GDPR exceptions and expression, archive, and statistical rules
Right to restriction of processing, subject to archive and statistical restrictions
Right to notification of recipients about rectification, erasure, or restriction
Right to data portability, subject to research and archive conditions
Right to object, subject to archive and statistical exclusions and the preserved research rule in Article 21(6)
Right to complain to the Information Commissioner
Notable features
ZVOP-2 provides extensive Slovenian layering around GDPR rights. Distinctive provisions include a child-consent age of 15, restrictions on using EMŠO and other linking signs to acquire data from specified collections, special rules for criminal and misdemeanour data, 20-year post-death access rules, and detailed expression, research, archive, and statistics derogations. The 2026 ZP-1L amendment also caused a partial repeal of Articles 95(2), 96, and 97.
Enforcement & penalties
Regulator: Information Commissioner
Penalties: For GDPR violations, ZVOP-2 uses the GDPR Article 83 fine amounts and ranges: up to €10 million or 2% of worldwide annual turnover for the lower tier, and up to €20 million or 4% of worldwide annual turnover for the upper tier. Narrow ZVOP-2-specific misdemeanour schedules remain active: processing-log, storage-security, and traceability violations carry €4,000-12,000 for legal persons and €8,000-36,000 for medium or large companies; linking-sign violations carry €1,000-8,000 for legal persons and €8,000-36,000 for medium or large companies. Articles 95(2), 96, and 97 ceased to apply on 25 February 2026.
Private right of action: Controller-refusal appeals to the Information Commissioner, special-status procedures, inspection complaints, and corrective powers are the identified mechanisms; a general Slovenia-specific private-action rule was not located in the reviewed materials.
Relevance to data brokers
No Slovenia-specific data-broker complaint, deletion, or opt-out route was located. The general routes are GDPR Article 17 against the relevant controller and an Information Commissioner complaint. ZVOP-2 addresses public-book and official-record access, purpose limitation, and linking restrictions, but no dedicated deletion petition for a data broker or public-record entry was located under ZVOP-2 itself.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
What is Slovenia’s current personal-data protection law?+
The operative national statute is the Personal Data Protection Act (ZVOP-2), Official Gazette No. 163/2022, in force since 26 January 2023. GDPR remains the baseline for Chapter III rights, complaints, remedies, and fines.
Does Slovenia have a dedicated data-broker deletion route?+
No Slovenia-specific data-broker complaint, deletion, or opt-out route was located. The general routes are GDPR Article 17 against the relevant controller and a complaint to the Information Commissioner, subject to applicable public-book, expression, research, archive, and statistics rules.
What changed in Slovenia in February 2026?+
ZVOP-2 Articles 95(2), 96, and 97 ceased to apply on 25 February 2026 under the 2026 ZP-1L amendment. Any source relying on those specific provisions before that amendment may be stale.
Official sources & citations
Other international privacy regimes
ZVOP-2 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
