In force now
GDPR / ZVOP-2
The oldest regime on this page and still the one most likely to be enforced against you. ZVOP-2 has been the Slovenian implementing act since January 2023, supervised by the Informacijski pooblaščenec.
Why it belongs on a cyber-security page
Because it is the regime under which a breach actually gets punished. NIS2 is new and its enforcement is only starting; the GDPR has a decade of decisions behind it and a supervisory authority that already knows how to run a case. In an incident involving personal data both clocks run at once: seventy-two hours to the Informacijski pooblaščenec under Article 33, twenty-four hours to URSIV under ZInfV-1, and the two reports go to different people asking different questions. Organisations that have not rehearsed that miss one of them.
The security half of the GDPR, in practice
- Article 32 — security appropriate to the risk, which a regulator reads after the fact
- Article 33 — breach notification within 72 hours of becoming aware
- Article 34 — telling the individuals, when the risk to them is high
- Article 28 — processor contracts, which is supply-chain security by another name
- Article 35 — a DPIA before high-risk processing, including new surveillance
- ZVOP-2 — Slovenian rules on video surveillance, biometrics and the workplace
THE DATES
Where this stands today
-
GDPR applies
-
ZVOP-2 in force in Slovenia
What we are usually asked to do
- Rehearse the double clock: one incident, two reports, two regulators, one narrative
- Establish what was actually taken — forensics is what turns a guess into a notification
- Show that Article 32 was met before the incident, not improvised after it
- Review processor contracts against what the suppliers can actually do
- Handle the video surveillance and access-control questions ZVOP-2 asks specifically
What it costs to get wrong
Up to €20 million or 4% of worldwide annual turnover. The more common cost is smaller and slower: a supervisory inquiry that runs for a year, an obligation to notify every affected individual, and the reputational damage of doing so. In tenders, a live enforcement action is increasingly a disqualifying answer on the questionnaire.
WHAT WE DO ABOUT IT
The services that close this gap
Not the whole catalogue — these are the ones that map onto the obligations above. If something here is already covered internally, say so and we will scope around it.
Chief Information Security Officer
A security executive on subscription: policy, risk register, board reporting and the evidence an auditor asks for — without a six-figure hire.
Read more IRIncident response
Containment, eradication and recovery, on site if it needs to be. The 24-hour clock in the law starts the moment you notice, not the moment you call.
Read more DFIRDigital forensics
Evidence handled so it survives a courtroom and an insurer: what was taken, when, by whom, and what has to be disclosed to whom.
Read moreNot sure whether GDPR / ZVOP-2 applies to you?
Tell us your sector, your headcount and what you sell. We will tell you which regimes catch you and what the first three things to do are — in writing, at no charge, because half the organisations that ask turn out not to be in scope and we would rather say so.