Law / Slovenia

Slovenia

European Union law applies in Slovenia Slovenia is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Slovenia, described on this page below, applies here too.

15 of 16 named instruments researched to a stage, across all six areas of law we track: 14 in force and 1 enacted but not yet in force. As of 15 September 2026.

When they take effect12 of 15 carry a date, 3 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 2 instruments (2 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 3 instruments (3 in force) 2023: 4 instruments (4 in force) 2024: 0 instruments 2025: 1 instrument (1 in force) 2026: 1 instrument (1 enacted but not yet in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law 2
  5. Age gating law 2
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (238 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Slovenia and is not restated here as Slovenian law; its Article 50 transparency duties and Article 53 general-purpose-model duties are researched at the EU level.

Slovenia's Zakon o izvajanju uredbe (EU) o umetni inteligenci (ZIUDHPUI) designates the Agency for Communication Networks and Services of the Republic of Slovenia (AKOS) as the country's single point of contact for the AI Act, as the authority responsible for establishing an AI regulatory sandbox, and as the market-surveillance and compliance-oversight authority for the high-risk AI systems the Act assigns to national competence, with power to act against a provider, product manufacturer, deployer, authorised representative, importer, or distributor found in breach.

Separately, Kazenski zakonik (KZ-1) Article 176(3) criminalizes acquiring, producing, distributing, selling, importing, exporting, or otherwise offering pornographic or other sexual material involving a minor or a minor's realistic likeness, reaching a synthetic or computer-generated depiction that need not show an actual child, and criminalizes possessing such material or accessing it by means of information or communication technology.

The National Artificial Intelligence Strategy to 2030 (NsUI 2030), adopted by the government on 5 March 2026, is a non-binding strategic framework document prepared by the Ministry of Digital Transformation; it sets policy goals around sovereign and trustworthy AI, adoption, and protecting the Slovenian language and cultural identity, and imposes no legal obligation on a private actor, crawler operator, or AI system provider or deployer.

AI governance

Zakon o izvajanju uredbe (EU) o umetni inteligenci (ZIUDHPUI), AKOS Designation as AI Act Competent Authority

Zakon o izvajanju uredbe (EU) 2024/1689 o umetni inteligenci (ZIUDHPUI)AKOS (Agency for Communication Networks and Services of the Republic of Slovenia)

In force. Binds public and private bodies.

What this law does

ZIUDHPUI designates the Agency for Communication Networks and Services of the Republic of Slovenia (AKOS) as Slovenia's single point of contact for the AI Act, the body responsible for setting up at least one AI regulatory sandbox, and the market-surveillance and compliance-oversight authority over high-risk AI systems the Act places within national competence, including systems listed in Annex I that are safety components of, or are themselves, products covered by named EU harmonisation legislation, and Annex III systems used in critical infrastructure, employment, public benefits eligibility, and emergency-services triage.

AKOS also monitors the transparency obligations of providers and deployers of certain AI systems and can act against a provider, product manufacturer, deployer, authorised representative, importer, or distributor found, during its supervision, to be in breach of the AI Act, and forwards complaints from Slovenian users against providers established elsewhere to the coordinator in that provider's own country.

What it requires

AI prohibited practices

Kazenski zakonik (KZ-1, Criminal Code), Art. 176(3), Pornographic Material Involving a Minor's Realistic Likeness

KZ-1, Art. 176(3)Kazenski zakonik (KZ-1), official consolidated text (uradno prečiščeno besedilo), Pravno-informacijski sistem (PISRS)

In force. Binds public and private bodies.

What this law does

Article 176(3) punishes, to the same extent as paragraph 2, whoever for themself or another acquires, produces, distributes, sells, imports, exports, or otherwise offers pornographic or other sexual material that involves a minor or a minor's realistic likeness, or whoever possesses such material or gains access to it by means of information or communication technology, or discloses the identity of a minor depicted in it.

Because the provision reaches material involving a minor's realistic likeness (njihove realistične podobe) and not only material depicting an actual child, it extends to a synthetic, computer-generated, or otherwise artificial depiction that realistically portrays what appears to be a minor.

What it requires

Privacy law6 instruments, 6 in force

Research summary (106 words)

Slovenia's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by ZVOP-2, adopted five years after the GDPR took effect and confirmed at ip-rs.si. ZVOP-2 Article 81 imposes a default prohibition on biometric processing, stronger than a bare GDPR Article 9 lawful-basis test, and Article 80 bans automated license-plate and biometric recognition on public surfaces, with fines at Article 105.

Commentary describing Article 80 as carrying a collective-redress mandate is wrong: the primary text shows it is entirely about public video surveillance. A reported data-localization requirement for sensitive-data categories rests on one uncorroborated, no-citation commentary claim and is not folded into the cross-border finding here.

Biometric privacy

ZVOP-2 Chapter 4 (Articles 81-84) and Article 80, Biometric and Genetic Data

ZVOP-2, Arts. 80-84, 105ip-rs.si, ZVOP-2 Arts. 80-84, 105 (verbatim)

In force since 26 January 2023. Binds public and private bodies.

What this law does

ZVOP-2 Part II Chapter 4, Processing of Personal Data Using Biometrics and Genetic Data, imposes a default prohibition rather than a bare General Data Protection Regulation (GDPR) Article 9 lawful-basis test, read verbatim: Article 81(1) states processing of biometric personal data contrary to this chapter's provisions is prohibited; Article 81(2) requires any other law authorizing biometric processing to itself set the conditions of use; Article 81(3) bars linking biometric-data collections with other collections, or enabling their GDPR Article 20 portability, except where another law provides otherwise.

Separately, in Chapter 3 (Video Surveillance), Article 80 bans, on public surfaces, automated license-plate-recognition systems and systems processing biometric personal data, backed by Article 105 fines of EUR 5,000 to 30,000. Article 80 is entirely a public-video-surveillance provision; it does not carry a collective-redress or representative-action mandate, contrary to commentary that describes one. No voiceprint-specific definition has been located; ZVOP-2's own Article 3 definitions section is not reproduced here.

What it requires

Breach notification

GDPR Articles 33-34, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34GDPR Arts. 33-34

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the Information Commissioner within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. Commentary describes a parallel channel under the Information Security Act for special processing; which categories of processing that extends to, and its relationship to the General Data Protection Regulation (GDPR) Article 33 duty, are not verified.

What it requires

Comprehensive regime

Zakon o varstvu osebnih podatkov (ZVOP-2), Personal Data Protection Act

Zakon o varstvu osebnih podatkov (ZVOP-2), Uradni list RS, st. 163/22ip-rs.si, ZVOP-2 full text (162,090 chars, not truncated)

In force since 26 January 2023. Binds public and private bodies.

What this law does

Slovenia adopted ZVOP-2 in December 2022, five years after the General Data Protection Regulation (GDPR) took effect, replacing the original 2004 ZVOP-1.

The Act's full text, hosted by the Information Commissioner, confirms the citation exactly as Uradni list RS, st. 163/22, and shows a later amendment by the Zakon o informacijski varnosti (Information Security Act, ZInfV-1, Uradni list RS, st. 40/25), in force 19 June 2025, whose Article 67 rewrote ZVOP-2 Article 23(1)'s terminology from security requirements to risk management measures as a NIS2-alignment update rather than a substantive privacy change.

Having legislated five years late rather than in the original 2018 rush, ZVOP-2 is noticeably more specific than a hurried transposition, most visibly in its dedicated biometric-data chapter.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c)GDPR Arts. 44-49, 83(5)(c)

In force since 25 May 2018. Binds public and private bodies.

What this law does

A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier.

A single commentary source separately claimed ZVOP-2 requires certain sensitive-data categories to remain within Slovenia's territory; this is flagged as unverified rather than folded into this jurisdiction's cross-border finding, since intra-EEA localization is not what General Data Protection Regulation (GDPR) Chapter V regulates and no article citation or primary text supports the claim.

What it requires

Data subject rights

GDPR Data-Subject Rights and ZVOP-2 Article 11, Judicial Protection

Regulation (EU) 2016/679, Arts. 12-22; ZVOP-2, Art. 11ip-rs.si, ZVOP-2 Art. 11 (verbatim)

In force since 25 May 2018, effective 26 January 2023. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12-22 apply directly. ZVOP-2 Article 11, read verbatim, confirms general judicial protection including damages, available to a data subject in Slovenia without first exhausting an administrative complaint to the Information Commissioner.

A single commentary source separately described an Article 80 representative-action mechanism; primary text shows ZVOP-2's own Article 80 is the public-video-surveillance provision above, not a representative-action provision, so if that commentary claim has any basis it describes GDPR's own Article 80 rather than a ZVOP-2 provision, and the Author should not attribute a representative-action power to "ZVOP-2 Article 80".

What it requires

Enforcement supervision

Informacijski pooblaščenec Enforcement, GDPR Article 82, and ZVOP-2 Articles 114-116

Regulation (EU) 2016/679, Art. 82; ZVOP-2, Arts. 105, 114-116ip-rs.si, ZVOP-2 Arts. 105, 114-116

In force since 25 May 2018, effective 26 January 2023. Binds public and private bodies.

What this law does

Informacijski pooblascenec (the Information Commissioner) is Slovenia's supervisory authority. ZVOP-2 Articles 114-115 require the misdemeanor-law fining authority to weigh proportionality alongside General Data Protection Regulation (GDPR) Article 83(1) factors, and Article 115 allows a fast-track fine above the statutory minimum.

Article 116 requires processing operations under Article 23(1), which names biometric, health, and criminal or misdemeanor-record data as triggering categories, to come into compliance within three years of the law's entry into force. GDPR Article 82 arms an individual with a direct private right of action, exercised through ZVOP-2 Article 11's judicial-protection route.

What it requires

Scraping law1 instrument, 1 in force

Research summary (187 words)

Slovenia has no scraping-specific statute, so general law governs each dimension separately.

Kazenski zakonik (KZ-1) Article 221 criminalizes unauthorized entry into an information system and the unauthorized use, alteration, copying, transfer, or destruction of data within one; because the offense turns on the entry or act being unauthorized (neupravičeno), a plain reading places reading a public, unauthenticated page without defeating an access control outside the provision, though no Slovenian court decision testing that reading has been located.

Personal-data protection over scraped personal data is governed by the General Data Protection Regulation (GDPR) and Zakon o varstvu osebnih podatkov (ZVOP-2), already researched under this jurisdiction's privacy topic. Slovenia's text-and-data-mining exception, Zakon o avtorski in sorodnih pravicah (ZASP) Articles 57.a and 57.b, is filed under this jurisdiction's aggregation topic, since the opt-out mechanism that provision registers is that topic's tdm_optout family.

No Slovenian sui generis database right distinct from the EU Database Directive's own compilation-investment right has been located, no reported Slovenian case addresses the enforceability of a browsewrap or clickwrap terms-of-service against a scraper, and no statute or reported case assigns robots.txt a specific legal weight or imposes an AI-training-specific scraping rule.

Computer misuse

Kazenski zakonik (KZ-1, Criminal Code), Art. 221, Napad na informacijski sistem (Attack on an Information System)

KZ-1, Art. 221Kazenski zakonik (KZ-1), official consolidated text (uradno prečiščeno besedilo), Pravno-informacijski sistem (PISRS)

In force. Binds public and private bodies.

What this law does

Article 221 criminalizes unauthorized entry into, or breaking into, an information system, and unauthorized interception of data during its non-public transmission into or out of the system (paragraph 1); it separately criminalizes the unauthorized use, alteration, copying, transfer, or destruction of data in an information system, unauthorized entry of data into one, or obstructing the transfer of data or the system's operation (paragraph 2), makes an attempt of that second offense punishable (paragraph 3), and raises the penalty where the paragraph 2 act causes significant damage (paragraph 4).

What it requires

Cybersecurity law2 instruments, 1 in force, 1 enacted but not yet in force

Research summary (592 words)

Slovenia transposed the NIS2 Directive through the Zakon o informacijski varnosti (ZInfV-1, Information Security Act), Uradni list RS (Official Gazette of the Republic of Slovenia) št. 40/25, adopted by the National Assembly on 22 May 2025, published 3 June 2025 and in force since 18 June 2025.

Article 69(1) repeals the predecessor Zakon o informacijski varnosti (Uradni list RS, št. 30/18, 95/21, 130/22, 18/23 and 49/23), Slovenia's NIS1-era transposition, along with four implementing regulations and two general acts on essential-service security documentation, security measures and incident notification that governed under it; none of the predecessor regime survives.

Article 10(1) designates the Urad Vlade Republike Slovenije za informacijsko varnost (URSIV, the Government Office for Information Security) as the competent national authority, supervising through its own information-security inspectors under Article 45.

Article 13 provides for one or more CSIRT groups; pending their formal designation, Article 59 assigns SIGOV-CERT (the internal unit of the competent authority) to handle incidents of state and local public-administration bodies and trust-service providers used by state administration, and SI-CERT, the unit hosted by the public research-network institute ARNES, to handle incidents for every other obligated entity and to act as the single point of contact.

Two instruments carry the coded duties: Article 22's cybersecurity risk-management measures, together with Article 20's governance duty and Article 21's security-documentation duty, and Article 29 and 30's significant-incident notification duty with its 24-hour, 72-hour and one-month clock.

Article 6 binds an entity within Annex 1 (Priloga 1, highly critical sectors) or Annex 2 (Priloga 2, other critical sectors) that has at least 50 employees and an annual turnover or balance-sheet total of at least EUR 10 million, the medium-enterprise floor, unless one of Article 6(2)'s no-threshold triggers applies (sole national provider of the service, public electronic-communications or trust-service provider, top-level domain (TLD) registry or DNS provider, or a public-administration body).

Article 29(3) separately names a provider of an online marketplace, an online search engine or a social-networking-services platform, alongside a DNS service, TLD registry, cloud, data-centre, content-delivery-network, managed-service or managed-security-service provider, for special notification treatment, confirming these digital providers sit within the Act's scope on the same NIS2 Annex II model as the rest of the corpus.

Article 52 and 53 set a two-tier misdemeanor (prekršek) fine, not a criminal offence: an essential entity faces 0.5 to 2 percent of worldwide annual turnover or EUR 10,000 to 10,000,000, whichever is higher, and an important entity faces 0.3 to 1.4 percent or EUR 7,000 to 7,000,000, whichever is higher, both triggered by a failure under Articles 21, 22, 24, 29 or 30; a responsible person of the entity, or a sole trader, faces a separate personal fine under the same articles.

The Cyber Resilience Act (Regulation (EU) 2024/2847) is directly applicable EU law and is documented at the European Union level rather than restated here; Slovenia's government adopted an implementing regulation assigning Cyber Resilience Act (CRA) market-surveillance tasks jointly to URSIV and the Market Inspectorate (Tržni inšpektorat), reported in Slovenian legal press, but this filing does not rest a coded claim on that secondary reporting.

Slovenia has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and ZVOP-2's personal-data-breach notification to the Informacijski pooblaščenec (Information Commissioner), both of which sit in the privacy topic rather than here.

Article 50(1) of this Act requires a security inspector who finds that a matter under investigation involves a personal-data breach, or a suspected one, to notify the Informacijski pooblaščenec, the one point where the two regimes cross-refer without either duplicating the other's corpus.

Sector security regimes

Zakon o informacijski varnosti (ZInfV-1), Cybersecurity Risk-Management Measures and Governance

Zakon o informacijski varnosti (ZInfV-1), Uradni list RS, št. 40/25, čl. 20-22Consolidated text

In force in 86 days, effective 18 December 2026. Binds public and private bodies.

What this law does

Article 22(1) requires an essential or important entity to adopt technical, operational and organisational measures to secure the integrity, authenticity, confidentiality and availability of the network and information systems it uses for its work or to provide its services, and to prevent or reduce the impact of an incident on the recipients of its services and other services.

Article 22(2) requires those measures to follow an all-hazards approach covering at minimum management support for information and cybersecurity, personnel integrity checks before, during and after employment (cross-referencing Article 23), basic cyber-hygiene practices and training, human-resources security and access-rights management, backup management, the logging duty of Article 24, supply-chain security with minimum requirements for key suppliers, cryptography and encryption policy, and further items through paragraph 13.

Article 20 assigns responsibility for these measures to the entity's odgovorna oseba (responsible person, the individual who leads, supervises or manages a legal person's business, or is otherwise legally charged with ensuring its lawful operation, or the head of a public-administration body), who must approve the Article 22 measures, oversee their implementation, complete cybersecurity risk-management training at least every four years, and ensure regular staff training.

Article 6(1) binds an entity within Priloga 1 (Annex 1, highly critical sectors) or Priloga 2 (Annex 2, other critical sectors) that has at least 50 employees and an annual turnover or balance-sheet total of at least EUR 10 million; Article 6(2) drops that threshold for, among others, a public electronic-communications or trust-service provider, a top-level domain (TLD) registry or DNS provider, a sole national provider of the service, and a public-administration body.

Article 62(1) phases this duty in over eighteen months from the Act's 18 June 2025 commencement, to 18 December 2026, for the general population of essential and important entities; Article 62(2) held that date to one year (18 June 2026, already past) for an entity already designated as an essential-service operator under Article 6 of the predecessor Zakon o informacijski varnosti or a state-administration body designated under that Act's Article 9, which remained bound by the predecessor Act's own security requirements and penalties until its own one-year deadline passed.

This Act, the ZInfV-1, by its own Article 69(1) repeals the predecessor Zakon o informacijski varnosti (Uradni list RS, št. 30/18, 95/21, 130/22, 18/23 and 49/23), Slovenia's NIS1-era transposition, together with four implementing regulations and two general acts that carried the risk-management and security-documentation duties under it.

Article 29(3) of this Act, in the companion notification row, confirms that a provider of an online marketplace, an online search engine or a social-networking-services platform is among the essential or important entities this Article 6 scope reaches, naming them for variant notification treatment; that same population is bound by this row's Article 22 risk-management duty once it applies to them.

What it requires

Vulnerability and incident reporting

Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification Obligations

Zakon o informacijski varnosti (ZInfV-1), Uradni list RS, št. 40/25, čl. 29-30Consolidated text

In force since 18 June 2025. Binds public and private bodies.

What this law does

Article 29(1) requires an essential or important entity to notify its competent CSIRT group of every incident that has a significant impact on the provision of its services, an incident that is significant (pomemben incident) where it has caused, or could cause, the entity serious operational disruption or financial loss, or has affected, or could affect, another natural or legal person by causing substantial material or non-material damage.

Article 30(1) sets the notification clock: an early warning without delay, at latest within 24 hours of detecting the significant incident, indicating where relevant whether the incident is suspected to result from an unlawful or malicious act and whether it may have a cross-border effect; a full notification without delay, at latest within 72 hours, updating that information with an initial assessment of the incident's severity and impact and, where available, threat indicators; an interim report on the CSIRT group's request; and a final report, at latest one month after the 72-hour notification, describing the incident, its severity and impact, the likely threat or root cause, mitigating measures taken or under way, and any cross-border effect, with a progress report substituting where the incident is still ongoing and the final report then due within one month of resolution.

Article 29(3) applies a variant scope to a DNS service provider, top-level domain (TLD) registry, cloud, data-centre or content-delivery-network provider, a managed-service or managed-security-service provider, and a provider of an online marketplace, an online search engine or a social-networking-services platform, directing them to the European Commission's NIS2 implementing acts for the particular cases in which an incident counts as significant for their service.

Article 29(6)-(7) requires the entity to inform the recipients of its services, without delay, of a significant incident likely to adversely affect them, and to communicate to a recipient potentially affected by a significant cyber threat the measures it can take in response.

No transitional provision reviewed here defers this duty; unlike the companion risk-management-measures row, Article 62 phases in only Articles 21 and 22, so this notification duty binds from the Act's own 18 June 2025 commencement.

What it requires

Age gating law2 instruments, 2 in force

Research summary (173 words)

Slovenia's age-gating framework for audiovisual content and video platforms sits in the Zakon o avdiovizualnih medijskih storitvah (ZAvMS), which transposes the Audiovisual Media Services Directive and split out from the general Zakon o medijih (Media Act) when it was enacted in 2011.

Article 14 requires providers of audiovisual media services to classify content that could harm a child's development into age bands, including an adults-only category, and to gate that category behind a default-locked PIN or equivalent technical control that only an adult can unlock, limiting any personal data collected through that control to age-verification purposes.

Article 38.b, added by the 2021 ZAvMS-B transposition of the 2018 AVMSD amendment, requires video-sharing platform providers under Slovenian jurisdiction to adopt appropriate protective measures for children, naming an age-verification system for platform users and parental-control tools as examples. Both duties carry the same misdemeanor fine tier under Article 43.

Slovenia has no separate app-store or social-media-specific minor-access statute; a distinct social-media minor-access law, an app-store age-verification law, and a standalone age-appropriate design code were not located.

Adult content age verification (AV)

Zakon o avdiovizualnih medijskih storitvah (ZAvMS), Art. 14, Technical Protection of Minors from Adult Audiovisual Content

Zakon o avdiovizualnih medijskih storitvah (ZAvMS), Uradni list RS, st. 87/11, 84/15 in 204/21, Art. 14Consolidated text of the ZAvMS, Pravno-informacijski sistem (PISRS), Slovenian Government Legislation Service

In force since 16 November 2011. Binds public and private bodies.

What this law does

A provider of an audiovisual media service in Slovenia must classify content that could harm a child's physical, mental or moral development into one of five bands, the most restrictive being adult content covering unjustified violence and pornography. Adult content on a non-linear service must sit behind a default-locked, PIN-code-equivalent technical control that only an adult who understands its purpose can unlock. Any personal data of a child collected through that control may be processed only to verify the user's age.

Note and primary source

Age-appropriate design code

Zakon o avdiovizualnih medijskih storitvah (ZAvMS), Art. 38.b, Video-Sharing Platform Protective Measures for Minors

Zakon o avdiovizualnih medijskih storitvah (ZAvMS), Uradni list RS, st. 87/11, 84/15 in 204/21, Art. 38.bConsolidated text of the ZAvMS, Pravno-informacijski sistem (PISRS), Slovenian Government Legislation Service

In force since 12 January 2022. Binds public and private bodies.

What this law does

A video-sharing platform provider within Slovenian jurisdiction must adopt appropriate measures to protect children from content that could harm their physical, mental or moral development. The statute names an age-verification system for platform users and a user-managed parental-control system as example measures, alongside a published complaint-handling process for users. Data collected under these measures may be processed only to verify a user's age.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (173 words)

Slovenia transposed the EU Digital Single Market Copyright Directive (2019/790) through Zakon o spremembah in dopolnitvah Zakona o avtorski in sorodnih pravicah, ZASP-I (Uradni list RS, št. 130/22, published 11 October 2022), which added Article 139.a's press-publisher right and Articles 57.a and 57.b's text-and-data-mining exception to the Zakon o avtorski in sorodnih pravicah (ZASP).

Article 139.a gives a media publisher established in the European Union an exclusive right to reproduce and make available its media publications for online use by an information-society-service provider, running two years from first lawful publication and excluding private or non-commercial use, hyperlinking, and use of individual words or very short extracts.

Articles 57.a and 57.b permit reproduction, for text-and-data-mining purposes, of works lawfully accessed, subject to an express, machine-readable rights reservation for general use and a separate, unconditional exception for research organizations and cultural-heritage institutions.

Slovenia has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act, and no hot-news or misappropriation doctrine distinct from the general law has been located.

Press publishers' right

Zakon o avtorski in sorodnih pravicah (ZASP), Art. 139.a, Media Publications

ZASP-I, Uradni list RS, št. 130/22, čl. 139.aZakon o avtorski in sorodnih pravicah (ZASP), official consolidated text (neuradno prečiščeno besedilo), Pravno-informacijski sistem (PISRS)

In force since 26 October 2022. Binds private bodies.

What this law does

A media publisher established in the European Union holds an exclusive right to reproduce its media publication and to make it available to the public for use by an information-society-service provider.

The right excludes private or non-commercial use by individual users, the act of inserting a hyperlink, and use of individual words or very short extracts from the publication, and it does not affect the rights of the authors or related-rights holders whose works or subject matter the publication incorporates. It runs two years from the publication's first lawful publication.

An author is separately entitled to an appropriate share of the revenue the publisher receives from an information-society-service provider under this right, a share the author cannot waive.

Note and primary source

Text and data mining (TDM) opt-out

Zakon o avtorski in sorodnih pravicah (ZASP), Arts. 57.a-57.b, Text and Data Mining

ZASP-I, Uradni list RS, št. 130/22, čl. 57.a-57.bZakon o avtorski in sorodnih pravicah (ZASP), official consolidated text (neuradno prečiščeno besedilo), Pravno-informacijski sistem (PISRS)

In force since 26 October 2022. Binds public and private bodies.

What this law does

Article 57.a permits, without authorization, reproduction of works lawfully accessed for text-and-data-mining purposes, defined as any automated analytical technique for analyzing text and data in electronic form to generate information such as patterns, trends, and correlations.

That general exception does not apply where the author has expressly and appropriately reserved use of the work, in particular through internationally recognized, standardized, machine-readable means carrying metadata and terms of use for a work publicly available online. Any contractual provision contrary to this article is void.

Article 57.b creates a separate, unconditional exception, without that reservation mechanism, for research organizations, public archives, libraries, museums, film or audio heritage institutions, and public broadcasters carrying out text and data mining for scientific research on works they lawfully access.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.