Law / Slovenia

Informacijski pooblaščenec Enforcement, GDPR Article 82, and ZVOP-2 Articles 114-116

Regulation (EU) 2016/679, Art. 82; ZVOP-2, Arts. 105, 114-116

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018, effective 26 January 2023.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • Expect the Information Commissioner to weigh proportionality alongside the General Data Protection Regulation (GDPR) Article 83(1) factors when setting a fine for processing personal data of a person in Slovenia, per ZVOP-2 Articles 114-115.
  • Expect any person in Slovenia who suffered material or non-material damage from an infringement to have a direct GDPR Article 82 right to compensation, exercisable through ZVOP-2 Article 11's judicial-protection route.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Kazenski zakonik (KZ-1) Article 143, Zloraba osebnih podatkov (Misuse of Personal Data), is a genuine criminal offense distinct from ZVOP-2's misdemeanor fine regime. Unauthorized public disclosure of personal data, or unauthorized access to a computerized personal data collection (paragraphs 1-2), carries a fine or imprisonment up to one year; disclosing sensitive personal data this way (paragraph 5) carries imprisonment up to two years; assuming another person's identity or exploiting their personal data for gain or to injure their dignity (paragraph 4) carries imprisonment from three months to three years; and the aggravated form, committed by an official through abuse of official position or official powers (paragraph 6), carries imprisonment up to five years, the article's maximum penalty.

Penalty structure

ZVOP-2 Article 95(1) incorporates the GDPR's own fine amounts and ranges directly as the misdemeanor (prekrsek) penalty for a legal person, sole proprietor, or individual conducting an independent activity, so the governing ceiling matches GDPR Article 83(5)'s higher tier: up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher (the lower Article 83(4) tier, EUR 10,000,000 or 2 percent, is recorded on the instrument covering GDPR Articles 33-34). ZVOP-2 Article 95(2) separately prescribes its own, smaller fixed-euro fine bands where GDPR's turnover-based formula cannot reach the violator: Article 96 sets EUR 100 to 5,000 for the responsible person of a legal person, sole proprietor, state body, or self-governing local community who violates the lower-tier GDPR Article 83(4) obligations, and Article 97 sets EUR 200 to 8,000 for the same class of responsible person, or EUR 200 to 2,000 for an individual, on the higher-tier GDPR Article 83(5)-(6) obligations. Article 114 requires the misdemeanor authority to weigh proportionality, profit or harm motive, and repeat-violation factors alongside the GDPR Article 83(1) criteria when setting any of these fines, and Article 115 lets the authority impose a fast-track (hitri postopek) fine above the statutory minimum.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Informacijski pooblascenec (Information Commissioner)

Enforcement record

The Information Commissioner (IP-RS) does not publish per-decision fine amounts; it publishes each anonymised decision in full and an aggregate table in its annual report. actions_per_year (91) and fines_per_year (47) are IP-RS's own Annual Report 2024 figures (Letno porocilo za leto 2024), the most recent complete year at the time of this reading; the 2025 annual report had not yet been published. Year-by-year decisions/fines from the CMS report's own table of IP-RS annual-report figures: 2019 65/44, 2020 89/58, 2021 37/18, 2022 116/75, 2023 77/38, 2024 91/47, 2025 (partial-year, as tracked at publication) 70/51. The count fluctuates year to year rather than showing a clean multi-year direction, hence trend is recorded as flat. The highest fine to date, per an 11 December 2025 decision, was EUR 71,474 on an employer for covertly installing employee-monitoring software, with a further EUR 4,000 fine on the responsible individual; IP-RS does not publish a running total or median across all fines.

As of
2 September 2026
Trend
Flat
Currency
EUR
Source link
https://cms.law/en/svk/publication/gdpr-enforcement-tracker-report/slovenia
Fines per year
47
Actions per year
91

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Informacijski pooblascenec (the Information Commissioner) is Slovenia's supervisory authority. ZVOP-2 Articles 114-115 require the misdemeanor-law fining authority to weigh proportionality alongside General Data Protection Regulation (GDPR) Article 83(1) factors, and Article 115 allows a fast-track fine above the statutory minimum.

Article 116 requires processing operations under Article 23(1), which names biometric, health, and criminal or misdemeanor-record data as triggering categories, to come into compliance within three years of the law's entry into force. GDPR Article 82 arms an individual with a direct private right of action, exercised through ZVOP-2 Article 11's judicial-protection route.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

Read the law

ip-rs.si, ZVOP-2 Arts. 105, 114-116
GDPR Art. 82

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app