Skip to content
هذه ترجمة للتسهيل فقط. النسخة الإنجليزية هي النسخة الرسمية والملزمة قانونيا. عرض النسخة الإنجليزية
EUMEDIUM coverage

Slovakia — GDPR + EU AI Act + Slovak AI Strategy 2030: AI Compliance Requirements

Slovakia's data protection authority is the Úrad na ochranu osobných údajov Slovenskej republiky (UOOU). Slovakia has adopted the Slovak AI Strategy 2030, aligned with the EU AI Act, focusing on AI in industry, public services, and healthcare. The Ministry of Investment, Regional Development and Informatization (MIRRI) coordinates AI policy. Slovakia is developing National AI Testing and Regulatory Sandbox under EU AI Act Article 57.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

May 25, 2018

Enforcement Begins

August 2, 2026

Maximum Penalty

€20,000,000 or 4% of global turnover (GDPR); EU AI Act: €35M or 7% global turnover

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

GDPR AI Compliance — UOOU Supervision

Critical

Slovak UOOU enforces GDPR for AI systems processing Slovak residents' data. Key obligations: lawful basis for AI training data, automated decision-making rights (Art. 22), DPIA for high-risk AI processing, and DPO appointment for public authorities and large-scale profiling operations.

GDPR Art. 22 (automated decisions); Art. 35 (DPIA); Art. 37 (DPO appointment)

EU AI Act Compliance — High-Risk AI in Public Services

High Priority

Slovakia's AI Strategy prioritises AI in public administration. If your AI systems interact with Slovak government procurement, social benefit decisions, or law enforcement, EU AI Act high-risk classification (Annex III) likely applies. Register high-risk systems in the EU AI Act database when operational. NOTE: the "Digital Omnibus" amendment (Regulation (EU) 2026/1744, in force 2026-07-27) deferred stand-alone high-risk (Annex III) conformity/registration obligations from 2026-08-02 to 2027-12-02.

Deadline: December 2, 2027

EU AI Act Art. 6, Annex III (high-risk classification); Art. 16 (provider obligations); Art. 43 (conformity assessment); Art. 26 (deployer obligations)

Slovak AI Regulatory Sandbox Eligibility

Lower Priority

Slovakia is implementing an EU AI Act regulatory sandbox (Art. 57) for AI companies wanting to test innovative systems in a supervised environment. Sandbox participants receive compliance flexibility during testing. Evaluate sandbox participation if you are developing high-risk AI products for the Slovak market.

EU AI Act Art. 57 (regulatory sandboxes)

Who Does This Apply To?

Applies to: any organisation established in Slovakia, and any organisation outside Slovakia processing the personal data of Slovak residents through AI systems — GDPR applies with extraterritorial reach (Art. 3), obligations attaching to the processing activity rather than company size, with no general small-business exemption. As an EU member state, Slovakia is fully subject to the EU AI Act, with ÚNMZ designated as national conformity-assessment body: high-risk AI interacting with Slovak government procurement, social-benefit decisions or law enforcement (Annex III) requires conformity assessment and EU-database registration. The Úrad na ochranu osobných údajov Slovenskej republiky (UOOU) requires a documented lawful basis for AI training data, Article 22 automated-decision rights, a DPIA for high-risk AI, and DPO appointment for public authorities and large-scale profiling. Penalties reach €20M / 4% of global turnover under GDPR and €35M / 7% under the EU AI Act. Slovakia is implementing an EU AI Act Article 57 regulatory sandbox that offers supervised testing and compliance flexibility for high-risk AI developers targeting the Slovak market.

Recent Regulatory Guidance

guidance2024

MIRRI AI Strategy — EU AI Act Implementation Roadmap for Slovakia

Slovakia's Ministry of Investment published the EU AI Act implementation roadmap: (1) ÚNMZ designated as national conformity assessment body; (2) Slovak AI regulatory sandbox open to applications from 2025; (3) public-sector AI procurement guidance requires documentation of bias testing, human oversight, and GDPR compliance; (4) priority enforcement sectors: public administration AI, financial AI, healthcare diagnostic AI.

Frequently Asked Questions

Does Slovakia — GDPR + EU AI Act + Slovak AI Strategy 2030 apply to my business?

Slovakia's data protection authority is the Úrad na ochranu osobných údajov Slovenskej republiky (UOOU). Slovakia has adopted the Slovak AI Strategy 2030, aligned with the EU AI Act, focusing on AI in industry, public services, and healthcare. The… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Slovakia — GDPR + EU AI Act + Slovak AI Strategy 2030 is: €20,000,000 or 4% of global turnover (GDPR); EU AI Act: €35M or 7% global turnover. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Slovakia — GDPR + EU AI Act + Slovak AI Strategy 2030?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.dataprotection.gov.sk/uoou/en

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan