Law / Slovakia

Slovakia

European Union law applies in Slovakia Slovakia is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Slovakia, described on this page below, applies here too.

15 of 16 named instruments researched to a stage, across all six areas of law we track: 13 in force, 1 enacted but not yet in force and 1 proposed. As of 15 September 2026.

When they take effect13 of 15 carry a date, 2 do not. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 5 instruments (5 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 4 instruments (4 in force) 2023: 0 instruments 2024: 0 instruments 2025: 2 instruments (2 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 1 in force, 1 proposed

Research summary (149 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Slovakia and is not restated here as Slovak law.

As of this review Slovakia has not enacted the implementing law that would designate the Act's national market-surveillance authority and set national penalties: the Ministry of Investments, Regional Development and Informatization (MIRRI) submitted an integrated draft act for inter-departmental comment at the end of July 2025, which would create an Office for Digital Integrity for that purpose, and as of February 2026 that office had not yet been established.

Slovakia's Trestny zakon (Criminal Code) defines child pornography, at section 132(4), to include a simulated depiction of sexual activity with a child or with a person appearing to be a child, so its production, distribution, and possession offences at sections 368 to 370 reach a computer-generated or otherwise simulated depiction and are not limited to the depiction of a real child.

AI governance

Draft Act on Organisation of Public Administration in the Field of Artificial Intelligence

Integrated draft act (inter-departmental comment stage, submitted by MIRRI, 1 August 2025); would amend Act 575/2001 Coll. and related actsMinistry of Investments, Regional Development and Informatization of the Slovak Republic (MIRRI), press releases on the draft act

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This bill has not been enacted and does not currently bind. The Ministry of Investments, Regional Development and Informatization (MIRRI) submitted the draft for inter-departmental comment on 1 August 2025 to implement the EU AI Act's institutional arrangements in Slovakia. As proposed, it would create a new Office for Digital Integrity under MIRRI to serve as the market-surveillance authority for the EU AI Act.

As of 24 February 2026 the government's own public statements describe the Office for Digital Integrity in future terms, indicating it had not yet been established by that date.

What it requires

AI prohibited practices

Trestný zákon, Child Pornography Including Simulated and Deepfake Depictions

Act 300/2005 Coll. (Trestny zakon), ss. 132(4), 368-370Official consolidated text of the Trestny zakon, Slov-Lex (Ministry of Justice of the Slovak Republic)

In force since 1 January 2006. Binds public and private bodies.

What this law does

Section 132(4) defines child pornography, for the purposes of the Trestny zakon, as a depiction of real or simulated sexual intercourse, another form of sexual contact, or similar sexual activity with a child or a person appearing to be a child, or a depiction of the exposed body parts of a child or a person appearing to be a child for sexual purposes.

Because that definition reaches a simulated depiction and a person merely appearing to be a child, it covers a computer-generated or otherwise AI-produced image regardless of whether any real child was involved. Section 368 punishes producing child pornography or a child-pornographic performance with imprisonment of four to ten years, rising to seven to twelve years, ten to fifteen years, or twelve to twenty years for aggravated forms.

Section 369 punishes reproducing, transporting, procuring, making accessible, or otherwise distributing child pornography with imprisonment of one to five years, rising to three to eight years, four to ten years, or seven to twelve years for aggravated forms. Section 370 punishes possessing child pornography, or acting with intent to access it through an electronic communication service, with imprisonment of up to two years.

What it requires

Privacy law6 instruments, 5 in force, 1 enacted but not yet in force

Research summary (69 words)

Slovakia gives the General Data Protection Regulation (GDPR) domestic effect through Act No. 18/2018 Coll. on the Protection of Personal Data. The Act's own text has not been located at primary source; the account rests on commentary (CMS, DLA Piper). No employment-specific biometric provision was found in either commentary source, a genuine gap rather than a confirmed absence. Every substantive claim here should be treated as unverified until a primary-source read becomes possible.

Breach notification

GDPR Articles 33-34, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34GDPR Arts. 33-34

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the Office for Personal Data Protection of the Slovak Republic within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. CMS's commentary states there are no derogations from the General Data Protection Regulation (GDPR) for this dimension in Slovakia; no primary text was read.

What it requires

Comprehensive regime

Act on the Protection of Personal Data

Zakon c. 18/2018 Z. z. o ochrane osobnych udajov a o zmene a doplneni niektorych zakonovCMS and DLA Piper commentary only

In force since 25 May 2018. Binds public and private bodies.

What this law does

Slovakia gives the General Data Protection Regulation (GDPR) domestic effect through Act No. 18/2018 Coll. on the Protection of Personal Data, effective 25 May 2018. The Act's own text has not been located at primary source. Every finding below rests on two commentary sources (CMS's expert guide and DLA Piper's Data Protection Laws of the World) rather than a primary-source read, and should be treated as unconfirmed until someone reads the Act directly.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c)GDPR Arts. 44-49, 83(5)(c)

In force since 25 May 2018. Binds public and private bodies.

What this law does

A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. DLA Piper's commentary confirms no further Slovak derogation, describing free movement of personal data between Slovakia and other EU member states; no primary text was read.

What it requires

Enforcement supervision

Office for Personal Data Protection Enforcement and GDPR Article 82

Regulation (EU) 2016/679, Arts. 82-83GDPR Arts. 82-83

In force since 25 May 2018. Binds public and private bodies.

What this law does

Urad na ochranu osobnych udajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic) is the supervisory authority, confirmed by both commentary sources; fine amounts and detailed procedure were not independently checked beyond the General Data Protection Regulation (GDPR) baseline.

GDPR Article 82 arms an individual with a direct private right of action; DLA Piper states Slovak private rights of action derive from Article 82 without further elaboration, and no Slovak transposition of the EU Representative Actions Directive was found or ruled out.

What it requires

Sensitive categories

GDPR Article 9 and Act Section 78, National Birth Number

Regulation (EU) 2016/679, Art. 9; Zakon c. 18/2018 Z. z., section 78CMS and DLA Piper commentary

Commencement not set. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) treats biometric data processed for unique identification as a special category. Commentary (CMS) quotes the Act as permitting biometric, genetic, and health data processing on the basis of a special regulation or an international agreement, a general enabling clause rather than a substantive biometric-specific carve-out; no employment-biometric consent or works-council rule was found in either commentary source.

A separate, more specific commentary-sourced finding, Section 78, protects the Slovak birth number (rodne cislo): explicit consent is required to process it, and public disclosure is prohibited unless the data subject discloses it themself. None of this is independently verified against the Act's own text.

No commencement date is recorded for this instrument: no primary-source text was read and this rests entirely on commentary, so the status here is enacted rather than in force, rather than an asserted but unconfirmed effective date.

What it requires

Scraping law2 instruments, 2 in force

Research summary (164 words)

Slovakia's Trestny zakon (Criminal Code), Act No. 300/2005 Coll., criminalises unauthorised access to a computer system at section 247 only where the offender overcomes a security measure, so crawling a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision; related sections 247a to 247d reach unauthorised interference with a system or its data, unauthorised interception, and the production or possession of an access device.

The Autorsky zakon (Copyright Act), Act No. 185/2015 Coll., as amended by Act No. 71/2022 Coll. transposing the EU Digital Single Market Copyright Directive, gives a library, archive, museum, school or statutory depositary an unconditional text-and-data-mining exception for research at section 51b, and a general text-and-data-mining exception for any person at section 51c, defeated by an express rightsholder reservation.

No Slovak court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper, on a sui generis database right's application to scraped content, or on robots.txt's legal weight has been located.

Computer misuse

Trestný zákon, Unauthorized Access to a Computer System and Related Offences

Act 300/2005 Coll. (Trestny zakon), ss. 247-247dOfficial consolidated text of the Trestny zakon, Slov-Lex (Ministry of Justice of the Slovak Republic)

In force since 1 January 2006. Binds public and private bodies.

What this law does

Section 247 punishes a person who overcomes a security measure and thereby obtains unauthorized access to a computer system or part of it with imprisonment of up to two years, rising to six months to three years where the act is committed in a more serious manner or causes significant damage, and to one to five years where it causes large-scale damage or is committed as a member of a dangerous grouping.

Because the offence's trigger is overcoming a security measure, reading a public, unauthenticated page without defeating any access control has not itself been held to violate this section.

Section 247a punishes unauthorized interference with a computer system's operation, section 247b unauthorized interference with computer data, section 247c unauthorized interception of non-public computer-data transmissions, and section 247d the production, import, or sale of a device, password, or access code created for unauthorized access to a computer system, each with its own escalating tiers running from six months up to eight years for the most serious forms.

What it requires

Copyright and text and data mining (TDM)

Autorský zákon, TDM Exception

Act 185/2015 Coll., ss. 51b-51c (as amended by Act 71/2022 Coll.), scrapingOfficial consolidated text of the Autorsky zakon, Slov-Lex (Ministry of Justice of the Slovak Republic)

In force since 25 March 2022. Binds public and private bodies.

What this law does

Section 51b, inserted by Act No. 71/2022 Coll. transposing Article 3 of the EU Digital Single Market Copyright Directive, lets a library, archive, museum, school, or statutory depositary reproduce a lawfully accessible work for text-and-data-mining for research purposes without the author's consent, with no rightsholder opt-out, and lets the reproduction be retained for verifying the research results.

Section 51c, transposing Article 4 of the same Directive, gives any person a general text-and-data-mining exception, defeated where the rightsholder has expressly reserved that use; a reproduction made under it may be kept only as long as needed for the mining. Section 51b(2) defines data mining, for the purposes of the Act, as any automated analytical technique aimed at analysing data in digital form to obtain patterns, trends, correlations, or similar results.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (472 words)

Slovakia transposed the NIS2 Directive (Directive (EU) 2022/2555) on time through Zákon č. 366/2024 Z. z., approved by the National Council on 28 November 2024 and in force since 1 January 2025, amending the existing Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti (Cybersecurity Act) rather than restating it in a fresh instrument; two further amendments (Zákon č. 318/2025 Z. z. and Zákon č.

67/2026 Z. z., effective 1 January 2026 and 30 April 2026 respectively) have since adjusted the same consolidated text, which is the version read here.

The amended Act binds an essential-service operator (prevádzkovateľ základnej služby), a category that reaches a medium or larger enterprise in a named sector and a public-administration body alike, and it expressly names the digital-provider slice this vocabulary can flag: a DNS, domain-registration, cloud computing, data-centre, content-delivery-network, managed-service, security-service, online marketplace, online-search-engine or social-networking-platform provider.

Its Section 19 and Section 20 set a general security-measures duty across 18 named domains, backstopped by a National Security Authority (Národný bezpečnostný úrad, NBÚ) Decree that specifies their manner and scope, and its Section 24 sets NIS2's own graduated notification clock (24-hour early warning, 72-hour notification, one-month final report), extended to a significant threat, a near-miss and an unremediated vulnerability in the operator's own networks.

Rather than adopting NIS2's "essential entity"/"important entity" labels, the Act layers a "critical basic service" (kritická základná služba) designation, broadly a large-enterprise or specially critical subset of essential-service operators under Section 18, onto the same register: an operator without that designation faces an administrative fine of up to the greater of EUR 7,000,000 or 1.4% of worldwide turnover for breaching these duties, one with it up to the greater of EUR 10,000,000 or 2%, mirroring NIS2 Article 34's own two tiers in substance if not in name.

A separate provision gives the Authority's national CSIRT unit, not the manufacturer, the coordinated-vulnerability-disclosure role for a vulnerability reported about an ICT product or service.

No located Slovak instrument sets a product-security or market-placement duty on a manufacturer independent of the directly applicable EU Cyber Resilience Act, which is documented at the European Union level and is not restated here, and no located instrument sets a general reasonable-security or information-security-programme duty with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and the GDPR Article 33-34 breach-notification duty to the Úrad na ochranu osobných údajov (Office for Personal Data Protection) that Zákon č.

18/2018 Z. z. gives effect to, both of which sit in the privacy topic rather than here. The broader sector classes the Act reaches by designation (energy, transport, banking, health, water, digital infrastructure and public administration) are not expressed by any activity in this vocabulary and are recorded here as law the lint does not yet reach, rather than flagged on a guess; only the digital-provider slice is flagged.

Sector security regimes

Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Risk-Management Measures

Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplní niektorých zákonov, v znení zákona č. 366/2024 Z. z., §§ 17 až 20Consolidated text of Zákon č. 69/2018 Z. z., Slov-Lex, version effective from 30 April 2026 (amended by Zákon č. 67/2026 Z. z.)

In force since 1 January 2025. Binds public and private bodies.

What this law does

Section 17 requires a person the sector annexes reach, including a central state-administration body and a digital provider named at Section 2(2) (DNS, domain-name registration, cloud computing, data centre, content delivery network, managed service, security service, online marketplace, online search engine or social-networking-services platform), to register as an essential-service operator (prevádzkovateľ základnej služby); a person meeting at least the medium-enterprise size threshold in an Annex 1 or Annex 2 sector registers under Section 17(1)(e).

Section 19(1) then requires the operator to adopt, maintain and carry out general security measures, within 12 months of registration and graded by its own risk analysis, covering at minimum the 18 domains Section 20(2) lists (security governance, vulnerability and threat management, asset and risk management, incident handling, business continuity and backup, secure development and acquisition, compliance monitoring, cryptography, human-resources security, identity and access management, network operations security, malware and unwanted-content protection, system, network and communications security, event logging and monitoring, physical and endpoint security, records and privacy protection, supply-chain security, and the use of certified ICT products, services and processes), and Section 19(6)(h) requires the operator to build an effective mechanism for promptly informing its statutory body and responsible senior staff about cyber threats, incidents, near-misses and risk-treatment status.

Section 18 defines a "critical basic service" (kritická základná služba) to include the exercise of a central state-administration body's functions.

It also includes, broadly, a large enterprise (above the medium-enterprise threshold) active in an Annex 1 sector other than public administration, and separately a qualified trust service, a top-level domain (TLD) registry, a DNS service, or an at-least-medium-sized public electronic communications network or service; an operator with this status must itself report it to the Authority, and it draws a higher administrative-penalty tier for the same duties.

The Act transposes NIS2 Article 21 without adopting NIS2's own "essential entity"/"important entity" labels; the National Security Authority's implementing Vyhláška (Decree) on security measures, referenced at Section 20(3), specifies the manner and scope in which these measures are carried out.

What it requires

Vulnerability and incident reporting

Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification

Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplní niektorých zákonov v znení zákona č. 366/2024 Z. z., § 24 a § 5 ods. 5Consolidated text of Zákon č. 69/2018 Z. z., Slov-Lex, version effective from 30 April 2026 (amended by Zákon č. 67/2026 Z. z.)

In force since 1 January 2025. Binds public and private bodies.

What this law does

Section 24(1) requires an essential-service operator to report every significant cyber security incident (závažný kybernetický bezpečnostný incident), defined at (2) as a large-scale incident, or one that has caused or may cause serious disruption to the operator or large-scale damage or lost profit, or that has affected or may affect others with significant harm.

Section 24(3) sets the graduated clock NIS2 Article 23 requires, beginning with an early warning reported without undue delay and no later than 24 hours from detection. No later than 72 hours from detection, the operator must report a notification updating that early warning with an initial severity and impact assessment, and must report further updates on the CSIRT unit's request.

A final report is due no later than one month after that 72-hour notification, and, where a cross-border-impact incident is still ongoing at that point, an updated final report is due within 30 days of restoring normal network operation or, if it is still unresolved then, within 30 days of its eventual resolution.

Section 24(5) extends the same reporting channel to a significant cyber threat the operator becomes aware of, a near-miss event that could have caused a significant incident, and a vulnerability in the operator's own publicly available networks or systems that it could not remediate or mitigate in reasonable time.

Section 24(8) lets an operator that is a financial entity under the EU Digital Operational Resilience Regulation (Regulation (EU) 2022/2554) satisfy this duty instead by reporting a major ICT-related incident through DORA's own competent-authority channel.

Separately, Section 5(5) gives the Authority, acting through its national CSIRT unit, a coordinator role for communication about a discovered or reported vulnerability among the essential-service operator, the manufacturer or supplier of the affected ICT product or ICT service, and other affected persons, a duty the Act places on the Authority rather than on the manufacturer directly.

What it requires

Age gating law1 instrument, 1 in force

Research summary (104 words)

Slovakia transposed the EU Audiovisual Media Services Directive's video-sharing platform protections through sections 48 to 50 of the zakon o medialnych sluzbach (Media Services Act), Act No. 264/2022 Coll., which took effect 1 August 2022.

A video-sharing platform provider must adopt appropriate measures to protect minors from content that may impair their physical, psychological, or moral development, and the measures a regulator may find suitable include a user-controlled parental-control system and an age-verification system tied to that content, alongside complaint-handling, content-flagging, and media-literacy measures.

No dedicated adult-content age-verification statute, social-media minor-access statute, or app-store age-verification statute distinct from this platform-protection regime has been located.

Age-appropriate design code

Media Services Act, Video-Sharing Platform Public-Protection Measures

Act 264/2022 Coll. (zakon o medialnych sluzbach), ss. 48-50Official consolidated text of the zakon o medialnych sluzbach, Slov-Lex (Ministry of Justice of the Slovak Republic)

In force since 1 August 2022. Binds public and private bodies.

What this law does

Section 48(1)(a) requires a video-sharing platform provider to adopt appropriate measures to protect minors from programmes, user-created videos, and audiovisual commercial communications that may impair their physical, psychological, or moral development.

Section 49 lists measures the provider may take depending on the case, including embedding the protective rules in the platform's terms of use, a reporting and flagging mechanism for content covered by section 48, a complaints procedure, and media-literacy tools. Among those listed measures is a parental-control system controlled by the user. Section 49 also lists an age-verification system for users in relation to content that may impair minors' development.

Section 50 lets the regulator request data from the provider to assess whether its measures are suitable, and to request further information where the data supplied does not let the regulator make that assessment. Personal data collected under the parental-control or age-verification measures may not be processed for commercial purposes.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (143 words)

Slovakia transposed the EU Digital Single Market Copyright Directive's press-publisher neighbouring right through sections 129a to 129h of the Autorsky zakon (Copyright Act), Act No. 185/2015 Coll., inserted by Act No. 71/2022 Coll. and running for two years from a periodical's publication.

The right exempts hyperlinking and the use of a headline, individual words, or a very short extract incapable of substituting for the periodical, and does not apply to a periodical first published before 6 June 2019.

The same amendment inserted a general text-and-data-mining exception at section 51c, defeated by an express rightsholder reservation, alongside an unconditional exception for libraries, archives, museums, schools, and statutory depositaries at section 51b. Slovakia has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act, and no hot-news or misappropriation doctrine distinct from ordinary unfair-competition law has been located.

Press publishers' right

Autorský zákon, Press Publisher Right

Act 185/2015 Coll., ss. 129a-129h (as amended by Act 71/2022 Coll.)Official consolidated text of the Autorsky zakon, Slov-Lex (Ministry of Justice of the Slovak Republic)

In force since 25 March 2022. Binds private bodies.

What this law does

Section 129c(1) to (2), inserted by Act No. 71/2022 Coll. transposing Article 15 of the EU Digital Single Market Copyright Directive, gives a periodical's publisher the exclusive right to use the periodical and to authorise its use, so an information-society service provider may reproduce or make the periodical available online only with the publisher's consent unless the Act provides otherwise.

Section 129c(4) exempts an individual user's private, non-commercial use, hyperlinking, and the use of a headline, individual words, or a very short extract incapable of substituting for the whole periodical. Section 129d limits the right's duration to two years from the periodical's publication, ending on the last day of the calendar year in which that term lapses.

A transitional provision excludes any periodical first published before 6 June 2019 from section 129c. Section 129h requires the publisher to pay rightsholders whose works are included in the periodical an appropriate share of the remuneration it receives from licensing an information-society service provider, within six months of the right's expiry.

Note and primary source

Text and data mining (TDM) opt-out

Autorský zákon, TDM Exception (Aggregation)

Act 185/2015 Coll., s. 51c (as amended by Act 71/2022 Coll.), aggregationOfficial consolidated text of the Autorsky zakon, Slov-Lex (Ministry of Justice of the Slovak Republic)

In force since 25 March 2022. Binds public and private bodies.

What this law does

Section 51c, inserted by Act No. 71/2022 Coll. transposing Article 4 of the EU Digital Single Market Copyright Directive, does not require an author's consent to reproduce a work for text-and-data-mining, unless the rightsholder has expressly reserved that use. A reproduction made under the exception may be retained only for as long as the mining requires it.

Section 51b gives a library, archive, museum, school, or statutory depositary a separate, unconditional exception for text-and-data-mining carried out for research.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.