Skip to content
Dies ist eine Ubersetzung zur Orientierung. Die englische Version ist die massgebliche und rechtsverbindliche Version. Englische Version anzeigen
EUMEDIUM coverage

Slovenia — GDPR + EU AI Act + Slovenian Digital Strategy + AI Sandbox: AI Compliance Requirements

Slovenia's Informacijski pooblaščenec (Information Commissioner, IP) supervises both data protection and freedom of information — an unusually combined mandate that affects AI transparency obligations. Slovenia has published a Digital Slovenia 2030 strategy including AI governance. Slovenia is notable for hosting an EU AI Act regulatory sandbox and for the Information Commissioner's proactive AI auditing stance. CYCLE 19 (2026-08-22) FINDING: Slovenia's national EU AI Act implementing act — the Act on the Implementation of the (EU) Regulation on Harmonised Rules on Artificial Intelligence (ZIUDHPUI) — took effect 2025-11-21 and was previously entirely absent from this entry. It establishes a MULTI-AGENCY market-surveillance structure, not a single AI regulator: AKOS (primary industry/public contact point, manages sandboxes and SME support), the Information Commissioner (data protection/transparency), Banka Slovenije (financial-sector AI), the Insurance Supervision Authority (insurance-sector AI), and the Market Inspectorate (general market surveillance/enforcement) — coordinated overall by the Ministry for Digital Transformation, with the internal-market ministry as notifying authority for most Annex I systems and the health ministry/medicines agency covering medical-device AI. The Information Commissioner is therefore ONE of five designated authorities, not Slovenia's sole AI regulator as the entry's prior framing implied.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

May 25, 2018

Enforcement Begins

August 2, 2026

Maximum Penalty

€20,000,000 or 4% of global turnover (GDPR); EU AI Act: €35M or 7% global turnover

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

GDPR AI Compliance — IP (Information Commissioner) Supervision

Critical

Slovenia's Information Commissioner has one of the most active AI audit programmes in the smaller EU member states. The IP has published AI guidelines covering: automated HR decisions, AI in healthcare, AI-driven surveillance, and algorithmic public administration. DPIA required for any high-risk AI processing Slovenian personal data.

GDPR Art. 22 (automated decisions); Art. 35 (DPIA)

AI Transparency Obligations — Public Sector AI

High Priority

Slovenia's Information Commissioner applies freedom-of-information logic to public AI: citizens have the right to know when AI systems make decisions about them. Public sector AI must maintain audit logs, decision explanations, and appeal mechanisms. Private sector AI interacting with government data via APIs inherits these transparency obligations.

Slovenian Access to Public Information Act (Zakon o dostopu do informacij javnega značaja, ZDIJZ); GDPR Art. 22 where the AI decision also involves personal data

EU AI Act Regulatory Sandbox — Slovenia Participation

Medium Priority

Slovenia operates an EU AI Act regulatory sandbox for innovative AI companies. If you are developing novel AI systems targeting the Slovenian or broader EU market, sandbox participation provides: (1) supervised testing environment, (2) regulatory flexibility during testing, (3) fast-track compliance assessment, (4) direct engagement with GDPR and AI Act authorities.

EU AI Act Art. 57 (regulatory sandboxes); Act on the Implementation of the (EU) Regulation on Harmonised Rules on Artificial Intelligence (ZIUDHPUI), in force 2025-11-21 — AKOS as sandbox-managing authority

Who Does This Apply To?

Applies to: any organisation established in Slovenia, and any organisation outside Slovenia processing the personal data of Slovenian residents through AI systems — GDPR applies with extraterritorial reach (Art. 3), obligations attaching to the processing activity rather than company size, with no general small-business exemption. As an EU member state, Slovenia is fully subject to the EU AI Act and operates an EU AI Act regulatory sandbox offering supervised testing and regulatory flexibility — but a GDPR DPIA must be completed before sandbox testing begins, and individual-rights obligations are not suspended during testing. The Informacijski pooblaščenec (Information Commissioner, IP) holds a combined data-protection and freedom-of-information mandate, so it applies FOI logic to public AI: citizens have a right to know when AI decides about them, and public-sector AI must maintain audit logs, decision explanations and appeal mechanisms — obligations that private-sector AI accessing government APIs inherits. A DPIA is required for any high-risk AI processing Slovenian personal data. Penalties reach €20M / 4% of global turnover under GDPR and €35M / 7% under the EU AI Act.

Recent Regulatory Guidance

guidance2024-06

IP Slovenia EU AI Act Implementation — Sandbox and GDPR Interplay (2024)

Slovenia's Information Commissioner guidance on EU AI Act regulatory sandbox: (1) GDPR DPIAs must be completed before AI Act sandbox testing begins; (2) sandbox participation does not suspend GDPR individual rights obligations; (3) Companies in the sandbox must designate a contact point for data subject rights requests even during testing; (4) Post-sandbox deployment requires full GDPR + EU AI Act compliance documentation.

Frequently Asked Questions

Does Slovenia — GDPR + EU AI Act + Slovenian Digital Strategy + AI Sandbox apply to my business?

Slovenia's Informacijski pooblaščenec (Information Commissioner, IP) supervises both data protection and freedom of information — an unusually combined mandate that affects AI transparency obligations. Slovenia has published a Digital Slovenia 2030… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Slovenia — GDPR + EU AI Act + Slovenian Digital Strategy + AI Sandbox is: €20,000,000 or 4% of global turnover (GDPR); EU AI Act: €35M or 7% global turnover. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Slovenia — GDPR + EU AI Act + Slovenian Digital Strategy + AI Sandbox?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.ip-rs.si/en

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan