Zakon o varstvu osebnih podatkov (ZVOP-2), Personal Data Protection Act
Zakon o varstvu osebnih podatkov (ZVOP-2), Uradni list RS, st. 163/22
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 26 January 2023.
A comprehensive regime rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Slovenia, and expect ZVOP-2's own institutional and procedural rules to govern rather than a GDPR restatement alone.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Slovenia adopted ZVOP-2 in December 2022, five years after the General Data Protection Regulation (GDPR) took effect, replacing the original 2004 ZVOP-1.
The Act's full text, hosted by the Information Commissioner, confirms the citation exactly as Uradni list RS, st. 163/22, and shows a later amendment by the Zakon o informacijski varnosti (Information Security Act, ZInfV-1, Uradni list RS, st. 40/25), in force 19 June 2025, whose Article 67 rewrote ZVOP-2 Article 23(1)'s terminology from security requirements to risk management measures as a NIS2-alignment update rather than a substantive privacy change.
Having legislated five years late rather than in the original 2018 rush, ZVOP-2 is noticeably more specific than a hurried transposition, most visibly in its dedicated biometric-data chapter.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
ip-rs.si, ZVOP-2 full text (162,090 chars, not truncated)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.