Office for Personal Data Protection Enforcement and GDPR Article 82
Regulation (EU) 2016/679, Arts. 82-83
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
An enforcement supervision rule binding public and private bodies.
As of 2 September 2026.
What it requires
- Expect the Office for Personal Data Protection to have General Data Protection Regulation (GDPR) Article 83 fining power over your processing of personal data of a person in Slovakia.
- Expect any person in Slovakia who suffered material or non-material damage from an infringement to have a direct GDPR Article 82 right to compensation from you as controller or processor.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Slovakia's general Criminal Code (Zakon c. 300/2005 Z. z., Trestny zakon), section 374, Unauthorized Handling of Personal Data (Neopravnene nakladanie s osobnymi udajmi), criminalizes unlawfully providing, granting access to, or publishing another person's personal data that was either collected in connection with the exercise of public authority or the exercise of a person's constitutional rights, or obtained through the offender's own profession, employment, or function, where doing so breaches a duty set by generally binding law. The base offense carries imprisonment of up to one year; an aggravated form, where the act causes serious harm to the affected person's rights, is committed publicly, or is committed in a more serious manner, carries imprisonment of up to two years. This is a separate offence from section 247 (unauthorized access to a computer system, candidate sk-300-2005-coll-247) and from Act No. 18/2018 Coll., whose own sections 104 to 106 set out administrative fines only, with no criminal provision of its own.
Penalty structure
GDPR Article 83(5) sets the higher administrative-fine tier, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher, for infringements of the basic principles for processing (Articles 5, 6, 7 and 9), the data subjects' rights (Articles 12 to 22), cross-border transfer conditions (Articles 44 to 49), Member State law obligations under Chapter IX, and non-compliance with a supervisory authority order under Article 58. Act No. 18/2018 Coll., section 104(2), reproduces this ceiling domestically without alteration: the Office may impose a fine of up to EUR 20,000,000, or for an undertaking up to 4 percent of total worldwide annual turnover for the preceding accounting year, whichever is higher, confirmed by reading the Act's own text (the official slov-lex.sk portal serves only a JavaScript shell and zakonypreludi.sk returned HTTP 403; the Act's consolidated text was read at zakony.judikaty.info instead). Section 104(1) carries the parallel lower EUR 10,000,000 or 2 percent tier matching GDPR Article 83(4), and section 104(3) applies the higher tier again to failure to comply with an Office order. Section 105 adds a national-only poriadkova pokuta (procedural fine) of EUR 2,000 to EUR 10,000 for obstructing a supervisory inspection, with no GDPR analogue.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Urad na ochranu osobnych udajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic)
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Urad na ochranu osobnych udajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic) is the supervisory authority, confirmed by both commentary sources; fine amounts and detailed procedure were not independently checked beyond the General Data Protection Regulation (GDPR) baseline.
GDPR Article 82 arms an individual with a direct private right of action; DLA Piper states Slovak private rights of action derive from Article 82 without further elaboration, and no Slovak transposition of the EU Representative Actions Directive was found or ruled out.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
Read the law
GDPR Arts. 82-83
CMS and DLA Piper commentary (no Slovak Act text read)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.