CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

In force now

GDPR / ZVOP-2

The oldest regime on this page and still the one most likely to be enforced against you. ZVOP-2 has been the Slovenian implementing act since January 2023, supervised by the Informacijski pooblaščenec.

Why it belongs on a cyber-security page

Because it is the regime under which a breach actually gets punished. NIS2 is new and its enforcement is only starting; the GDPR has a decade of decisions behind it and a supervisory authority that already knows how to run a case. In an incident involving personal data both clocks run at once: seventy-two hours to the Informacijski pooblaščenec under Article 33, twenty-four hours to URSIV under ZInfV-1, and the two reports go to different people asking different questions. Organisations that have not rehearsed that miss one of them.

The security half of the GDPR, in practice

  • Article 32 — security appropriate to the risk, which a regulator reads after the fact
  • Article 33 — breach notification within 72 hours of becoming aware
  • Article 34 — telling the individuals, when the risk to them is high
  • Article 28 — processor contracts, which is supply-chain security by another name
  • Article 35 — a DPIA before high-risk processing, including new surveillance
  • ZVOP-2 — Slovenian rules on video surveillance, biometrics and the workplace

THE DATES

Where this stands today

  1. GDPR applies

  2. ZVOP-2 in force in Slovenia

What we are usually asked to do

  • Rehearse the double clock: one incident, two reports, two regulators, one narrative
  • Establish what was actually taken — forensics is what turns a guess into a notification
  • Show that Article 32 was met before the incident, not improvised after it
  • Review processor contracts against what the suppliers can actually do
  • Handle the video surveillance and access-control questions ZVOP-2 asks specifically

What it costs to get wrong

Up to €20 million or 4% of worldwide annual turnover. The more common cost is smaller and slower: a supervisory inquiry that runs for a year, an obligation to notify every affected individual, and the reputational damage of doing so. In tenders, a live enforcement action is increasingly a disqualifying answer on the questionnaire.

Not sure whether GDPR / ZVOP-2 applies to you?

Tell us your sector, your headcount and what you sell. We will tell you which regimes catch you and what the first three things to do are — in writing, at no charge, because half the organisations that ask turn out not to be in scope and we would rather say so.

Ask us to check Compare all four