Slovakia - Public Sector Data Management (2025)

Draft Act on the Management of Selected Categories of Public Sector Data

Návrh zákona o správe vybraných kategórií údajov verejného sektora

Slovakia

RAI-SK-NA-DMSCPXX-2025
Draft(Being written or scoped)
BillGovernance and OversightData Protection and PrivacyConformity Assessment and Registration
Export PDF

A proposed Slovak national law to establish rules, institutional roles and technical requirements for the management, controlled re-use and secure provision of selected categories of public sector data (including data protected under sectoral rules). The draft aims to implement EU data-governance objectives at national level, enable safe data reuse for research and AI while preserving data protection and intellectual property rights.

Overview

The Draft Act on the Management of Selected Categories of Public Sector Data is a national legislative proposal (2025) aiming to create a predictable legal and technical framework for the selective re‑use of public sector datasets that cannot be published as open data without additional safeguards. It focuses on facilitating responsible reuse for scientific research, public interest analytics and AI model development while protecting personal data, trade secrets and third‑party intellectual property. The proposal was prepared in the context of Slovakia's national open data and digitization strategies and in alignment with the European Data Governance Act (Regulation (EU) 2022/868) and related EU instruments; national implementation documents and ministerial project pages discuss the operational components and technical standards expected to underpin the law. Official portals such as the national Open Data information page and legislative registers provide context for the draft's aims and obligations.

Definitions

The Draft Act defines key terms to reduce legal uncertainty: "selected categories of public sector data" (datasets held by public sector bodies whose unrestricted public release is limited by law or sensitivity but which may be reusable under controlled conditions); "public sector body" (aligned with the Freedom of Information Act, Zákon č. 211/2000); "competent body" (entity designated to assist or operate secure access services); "secure processing environment" (technical environment enabling analysis without unrestricted disclosure); "data intermediation service provider" and "data altruism organisation" (recognition/registration regimes modelled on the DGA); "metadata catalogue" (machine‑readable inventory using DCAT‑AP‑SK and national metadata standards). The Draft cross‑references national data and ICT standards used in Slovak public administration and requires clear provenance and licensing metadata for re‑use.

Governance and Institutional Framework

The bill establishes an institutional architecture with assigned roles and cooperation duties. Primary responsibilities remain with the original public sector data holder (the data controller where personal data are implicated), while one or more competent bodies are empowered to provide technical assistance, maintain secure processing infrastructure, certify secure environments, host the national registry of selected categories and operate application/appeal gateways. Ministries with sector competence (e.g. Ministry of Investments, Regional Development and Informatization) and the national Data Office / Data Coordination Unit are vested with policy and technical standard‑setting powers. The Úrad na ochranu osobných údajov (Data Protection Authority) retains supervisory competence for privacy compliance; the Draft requires coordinated procedures and memoranda of understanding between the competent body and supervisory authorities to expedite lawful re‑use requests. Relevant national project implementation documents and digital strategy pages describe operational responsibilities and technical components.

Key Focus Areas

The Draft Act concentrates on (1) dataset classification and registration — public bodies must inventory candidate datasets, classify risk tiers and register metadata in the national catalogue; (2) access modalities — open release where feasible, API access where appropriate, and secure processing environments for restricted datasets; (3) privacy and anonymisation — mandatory DPIAs, pseudonymisation and technical controls; (4) interoperability and standards — mandatory use of machine‑readable formats and metadata (e.g. DCAT‑AP‑SK), to enable discoverability and cross‑border use; (5) certification/recognition — a regime for recognised data intermediaries and altruism organisations meeting governance, transparency and security requirements; (6) liability, fees and redress — standardised access agreements, proportionate fees only where legally authorised, and defined complaint/appeal processes. The approach aims to make data available "as open as possible, as closed as necessary" and to enable safe AI training and research while reducing fragmentation and administrative duplication.

Implementation Framework

Implementation will be phased: immediate obligations focus on metadata registration and publication of non‑sensitive datasets; next phases introduce secure processing environments and certification of intermediaries; final phases expand to sectoral registers and cross‑border interoperability. The Draft empowers the designated competent body to prepare technical guidance (APIs, catalogue schemas, anonymisation best practices) and to run pilot secure environments. It foresees funding lines and IT modernization support via national programs and EU structural funds. Project and implementation templates used by Slovak ministries and the national Open Data portal are referenced to ensure alignment with national ICT governance.

Monitoring and Evaluation

The Draft Act requires annual reporting by the competent body and participating public sector bodies on numbers of registered datasets, access requests, approved secure environment cases, anonymisation outcomes, and any incidents or data breaches. Performance indicators include time to decision on access requests, number of re‑uses for scientific/AI purposes, and user satisfaction metrics. The competent body must publish an annual evaluation and an implementation plan for technical updates, and the legislature will review the law's operation within a multi‑year horizon. Cooperation with the Data Protection Authority and sectoral supervisors is mandated for monitoring privacy and security outcomes.

Penalties, Liability, and Appeals

The Draft provides graduated enforcement measures: administrative corrective orders, mandatory remedial action, and financial penalties for public bodies or intermediaries that negligently disclose protected data or fail to apply required safeguards. It clarifies civil liability rules for harm resulting from inappropriate re‑use and sets out expedited administrative appeal routes for denied re‑use requests. The Draft emphasises non‑criminal, administrative enforcement while preserving existing criminal sanctions under sectoral law where applicable. Coordination of sanctioning powers with the Úrad na ochranu osobných údajov is specified.

Relationship to Other Instruments

The Draft Act explicitly references and complements: the national Freedom of Information Act (Zákon č. 211/2000), national open data practices and portals (data.slovensko.sk), Slovak ICT standards and public sector IT regulations, GDPR and the national data protection act (Zákon č. 18/2018), and sectoral laws (health, transport, environment) that may restrict or regulate reuse. It implements DGA concepts at national level and is careful to state that it does not create a new legal basis for personal data processing beyond existing data protection law. Practical implementation will be coordinated with existing national projects and digital governance templates.

International Alignment

The Draft is built to align with the EU Data Governance Act, the Open Data / Public Sector Information directives, and related EU digital strategy instruments to reduce cross‑border friction in data access for research and AI. The law aims to ensure Slovakia can participate in EU data spaces by adopting interoperable metadata standards and by establishing recognised data intermediaries compatible with DGA registration and labels. Transposition and cooperation clauses support interoperability with EU‑level competent authorities and registries.

Implementation Timeline

PhaseActionTarget Date
Phase 1Metadata register & initial classification; publish guidanceWithin 6 months of entry into force
Phase 2Pilot secure processing environments; recognition regime6–18 months
Phase 3Full roll‑out; sectoral integration; reviews18–36 months

Compliance Checklist

RequirementWhoAction
Dataset inventory & classificationPublic sector bodiesRegister metadata to national catalogue
Privacy assessmentPublic sector bodiesConduct DPIA / anonymisation prior to access
Use secure environmentsReusers / competent bodyAccess restricted datasets via certified enclave

Sources and References

SourceType
Regulation (EU) 2022/868 (European Data Governance Act)Primary Source
Open Data – otvorené dáta (National portal guidance)Primary Source
Government / MIRRI project and implementation pages (ministerial project templates and data governance projects)Primary Source
Národná rada Slovenskej republiky - Document Preview (sample legislative materials)Primary Source
Plain English

This proposed Slovak law aims to create a clear framework for public sector bodies to safely share sensitive government data with researchers and AI developers, enabling innovation while protecting privacy and intellectual property.

The law applies to Slovak public sector bodies holding data restricted from open publication due to sensitivity or legal rules. It also impacts entities seeking to reuse this data, such as scientific researchers, public interest analysts, and AI developers, alongside recognised data intermediation service providers and data altruism organisations. A designated "competent body" will assist with technical and secure access services.

Public sector bodies will face several key obligations, including inventorying and classifying sensitive datasets for a national catalogue, managing access through secure processing environments for restricted information, conducting mandatory Data Protection Impact Assessments (DPIAs) with pseudonymisation, and adhering to national interoperability and metadata standards for discoverability.

While the exact effective date is unknown, the law outlines phased implementation. Initial requirements, like metadata registration, are expected within six months of entry into force. Secure processing environments and intermediary recognition will follow within 6-18 months, with full rollout anticipated within 18-36 months.

Non-compliance can lead to administrative corrective orders, mandatory remedial actions, and financial penalties for public bodies or intermediaries negligently disclosing protected data or failing to implement safeguards. Civil liability rules also apply for harm from inappropriate data reuse. Enforcement is primarily administrative, though existing criminal sanctions under other laws remain.

A crucial point for reusers: this law does not create new legal grounds for processing personal data. All existing data protection regulations, including GDPR and Slovakia's national data protection act, continue to apply fully, meaning privacy compliance remains paramount for any data reuse involving personal information.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under Slovakia - Public Sector Data Management (2025). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalKey Focus AreasWithin 6 months of entry into force

    Applies to: Public sector bodies

    public bodies must inventory candidate datasets, classify risk tiers and register metadata in the national catalogue
  2. #2CriticalKey Focus AreasPrior to providing access

    Applies to: Public sector bodies providing data

    mandatory DPIAs, pseudonymisation and technical controls
  3. #3CriticalKey Focus AreasPrior to providing access

    Applies to: Public sector bodies providing data

    mandatory DPIAs, pseudonymisation and technical controls
  4. #4CriticalKey Focus AreasBefore offering services

    Applies to: Data intermediation service providers and data altruism organisations

    a regime for recognised data intermediaries and altruism organisations meeting governance, transparency and security requirements
  5. #5CriticalPenalties, Liability, and Appeals

    Applies to: Public sector bodies or data intermediaries

    financial penalties for public bodies or intermediaries that negligently disclose protected data or fail to apply required safeguards.
  6. #6CriticalPenalties, Liability, and Appeals

    Applies to: Public sector bodies or data intermediaries

    financial penalties for public bodies or intermediaries that negligently disclose protected data or fail to apply required safeguards.
  7. #7ImportantKey Focus Areas

    Applies to: Public sector bodies providing data

    mandatory use of machine‑readable formats and metadata (e.g. DCAT‑AP‑SK)
  8. #8ImportantDefinitions

    Applies to: Public sector bodies providing data for re-use

    The Draft cross‑references national data and ICT standards used in Slovak public administration and requires clear provenance and licensing metadata for re‑use.
  9. #9ImportantGovernance and Institutional Framework

    Applies to: Competent body

    The Draft requires coordinated procedures and memoranda of understanding between the competent body and supervisory authorities to expedite lawful re‑use requests.
  10. #10ImportantKey Focus Areas

    Applies to: Public sector bodies providing data

    standardised access agreements, proportionate fees only where legally authorised
  11. #11ImportantMonitoring and EvaluationAnnually

    Applies to: Competent body and participating public sector bodies

    The Draft Act requires annual reporting by the competent body and participating public sector bodies on numbers of registered datasets, access requests, approved secure environment cases, anonymisation outcomes, and any incidents or data breaches.
  12. #12ImportantMonitoring and EvaluationAnnually

    Applies to: Competent body

    The competent body must publish an annual evaluation and an implementation plan for technical updates
  13. #13ImportantMonitoring and Evaluation

    Applies to: Competent body and public sector bodies

    Cooperation with the Data Protection Authority and sectoral supervisors is mandated for monitoring privacy and security outcomes.

© Regulations.AI — created on 13-Jun-2026