Slovakia - Public Sector Data Management (2025)
Draft Act on the Management of Selected Categories of Public Sector Data
Návrh zákona o správe vybraných kategórií údajov verejného sektora
Slovakia
RAI-SK-NA-DMSCPXX-2025A proposed Slovak national law to establish rules, institutional roles and technical requirements for the management, controlled re-use and secure provision of selected categories of public sector data (including data protected under sectoral rules). The draft aims to implement EU data-governance objectives at national level, enable safe data reuse for research and AI while preserving data protection and intellectual property rights.
Summary
Read full text ↗Plain English
Overview
The Draft Act on the Management of Selected Categories of Public Sector Data is a national legislative proposal (2025) aiming to create a predictable legal and technical framework for the selective re‑use of public sector datasets that cannot be published as open data without additional safeguards. It focuses on facilitating responsible reuse for scientific research, public interest analytics and AI model development while protecting personal data, trade secrets and third‑party intellectual property. The proposal was prepared in the context of Slovakia's national open data and digitization strategies and in alignment with the European Data Governance Act (Regulation (EU) 2022/868) and related EU instruments; national implementation documents and ministerial project pages discuss the operational components and technical standards expected to underpin the law. Official portals such as the national Open Data information page and legislative registers provide context for the draft's aims and obligations.
Definitions
The Draft Act defines key terms to reduce legal uncertainty: "selected categories of public sector data" (datasets held by public sector bodies whose unrestricted public release is limited by law or sensitivity but which may be reusable under controlled conditions); "public sector body" (aligned with the Freedom of Information Act, Zákon č. 211/2000); "competent body" (entity designated to assist or operate secure access services); "secure processing environment" (technical environment enabling analysis without unrestricted disclosure); "data intermediation service provider" and "data altruism organisation" (recognition/registration regimes modelled on the DGA); "metadata catalogue" (machine‑readable inventory using DCAT‑AP‑SK and national metadata standards). The Draft cross‑references national data and ICT standards used in Slovak public administration and requires clear provenance and licensing metadata for re‑use.
Governance and Institutional Framework
The bill establishes an institutional architecture with assigned roles and cooperation duties. Primary responsibilities remain with the original public sector data holder (the data controller where personal data are implicated), while one or more competent bodies are empowered to provide technical assistance, maintain secure processing infrastructure, certify secure environments, host the national registry of selected categories and operate application/appeal gateways. Ministries with sector competence (e.g. Ministry of Investments, Regional Development and Informatization) and the national Data Office / Data Coordination Unit are vested with policy and technical standard‑setting powers. The Úrad na ochranu osobných údajov (Data Protection Authority) retains supervisory competence for privacy compliance; the Draft requires coordinated procedures and memoranda of understanding between the competent body and supervisory authorities to expedite lawful re‑use requests. Relevant national project implementation documents and digital strategy pages describe operational responsibilities and technical components.
Key Focus Areas
The Draft Act concentrates on (1) dataset classification and registration — public bodies must inventory candidate datasets, classify risk tiers and register metadata in the national catalogue; (2) access modalities — open release where feasible, API access where appropriate, and secure processing environments for restricted datasets; (3) privacy and anonymisation — mandatory DPIAs, pseudonymisation and technical controls; (4) interoperability and standards — mandatory use of machine‑readable formats and metadata (e.g. DCAT‑AP‑SK), to enable discoverability and cross‑border use; (5) certification/recognition — a regime for recognised data intermediaries and altruism organisations meeting governance, transparency and security requirements; (6) liability, fees and redress — standardised access agreements, proportionate fees only where legally authorised, and defined complaint/appeal processes. The approach aims to make data available "as open as possible, as closed as necessary" and to enable safe AI training and research while reducing fragmentation and administrative duplication.
Implementation Framework
Implementation will be phased: immediate obligations focus on metadata registration and publication of non‑sensitive datasets; next phases introduce secure processing environments and certification of intermediaries; final phases expand to sectoral registers and cross‑border interoperability. The Draft empowers the designated competent body to prepare technical guidance (APIs, catalogue schemas, anonymisation best practices) and to run pilot secure environments. It foresees funding lines and IT modernization support via national programs and EU structural funds. Project and implementation templates used by Slovak ministries and the national Open Data portal are referenced to ensure alignment with national ICT governance.
Monitoring and Evaluation
The Draft Act requires annual reporting by the competent body and participating public sector bodies on numbers of registered datasets, access requests, approved secure environment cases, anonymisation outcomes, and any incidents or data breaches. Performance indicators include time to decision on access requests, number of re‑uses for scientific/AI purposes, and user satisfaction metrics. The competent body must publish an annual evaluation and an implementation plan for technical updates, and the legislature will review the law's operation within a multi‑year horizon. Cooperation with the Data Protection Authority and sectoral supervisors is mandated for monitoring privacy and security outcomes.
Penalties, Liability, and Appeals
The Draft provides graduated enforcement measures: administrative corrective orders, mandatory remedial action, and financial penalties for public bodies or intermediaries that negligently disclose protected data or fail to apply required safeguards. It clarifies civil liability rules for harm resulting from inappropriate re‑use and sets out expedited administrative appeal routes for denied re‑use requests. The Draft emphasises non‑criminal, administrative enforcement while preserving existing criminal sanctions under sectoral law where applicable. Coordination of sanctioning powers with the Úrad na ochranu osobných údajov is specified.
Relationship to Other Instruments
The Draft Act explicitly references and complements: the national Freedom of Information Act (Zákon č. 211/2000), national open data practices and portals (data.slovensko.sk), Slovak ICT standards and public sector IT regulations, GDPR and the national data protection act (Zákon č. 18/2018), and sectoral laws (health, transport, environment) that may restrict or regulate reuse. It implements DGA concepts at national level and is careful to state that it does not create a new legal basis for personal data processing beyond existing data protection law. Practical implementation will be coordinated with existing national projects and digital governance templates.
International Alignment
The Draft is built to align with the EU Data Governance Act, the Open Data / Public Sector Information directives, and related EU digital strategy instruments to reduce cross‑border friction in data access for research and AI. The law aims to ensure Slovakia can participate in EU data spaces by adopting interoperable metadata standards and by establishing recognised data intermediaries compatible with DGA registration and labels. Transposition and cooperation clauses support interoperability with EU‑level competent authorities and registries.
Implementation Timeline
| Phase | Action | Target Date |
|---|---|---|
| Phase 1 | Metadata register & initial classification; publish guidance | Within 6 months of entry into force |
| Phase 2 | Pilot secure processing environments; recognition regime | 6–18 months |
| Phase 3 | Full roll‑out; sectoral integration; reviews | 18–36 months |
Compliance Checklist
| Requirement | Who | Action |
|---|---|---|
| Dataset inventory & classification | Public sector bodies | Register metadata to national catalogue |
| Privacy assessment | Public sector bodies | Conduct DPIA / anonymisation prior to access |
| Use secure environments | Reusers / competent body | Access restricted datasets via certified enclave |
Sources and References
This proposed Slovak law aims to create a clear framework for public sector bodies to safely share sensitive government data with researchers and AI developers, enabling innovation while protecting privacy and intellectual property.
The law applies to Slovak public sector bodies holding data restricted from open publication due to sensitivity or legal rules. It also impacts entities seeking to reuse this data, such as scientific researchers, public interest analysts, and AI developers, alongside recognised data intermediation service providers and data altruism organisations. A designated "competent body" will assist with technical and secure access services.
Public sector bodies will face several key obligations, including inventorying and classifying sensitive datasets for a national catalogue, managing access through secure processing environments for restricted information, conducting mandatory Data Protection Impact Assessments (DPIAs) with pseudonymisation, and adhering to national interoperability and metadata standards for discoverability.
While the exact effective date is unknown, the law outlines phased implementation. Initial requirements, like metadata registration, are expected within six months of entry into force. Secure processing environments and intermediary recognition will follow within 6-18 months, with full rollout anticipated within 18-36 months.
Non-compliance can lead to administrative corrective orders, mandatory remedial actions, and financial penalties for public bodies or intermediaries negligently disclosing protected data or failing to implement safeguards. Civil liability rules also apply for harm from inappropriate data reuse. Enforcement is primarily administrative, though existing criminal sanctions under other laws remain.
A crucial point for reusers: this law does not create new legal grounds for processing personal data. All existing data protection regulations, including GDPR and Slovakia's national data protection act, continue to apply fully, meaning privacy compliance remains paramount for any data reuse involving personal information.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 13 marked completePlain-English obligations under Slovakia - Public Sector Data Management (2025). Not legal advice — verify against the official text before relying on it.
- #1CriticalKey Focus Areas⏰ Within 6 months of entry into force
Applies to: Public sector bodies
“public bodies must inventory candidate datasets, classify risk tiers and register metadata in the national catalogue”
- #2CriticalKey Focus Areas⏰ Prior to providing access
Applies to: Public sector bodies providing data
“mandatory DPIAs, pseudonymisation and technical controls”
- #3CriticalKey Focus Areas⏰ Prior to providing access
Applies to: Public sector bodies providing data
“mandatory DPIAs, pseudonymisation and technical controls”
- #4CriticalKey Focus Areas⏰ Before offering services
Applies to: Data intermediation service providers and data altruism organisations
“a regime for recognised data intermediaries and altruism organisations meeting governance, transparency and security requirements”
- #5CriticalPenalties, Liability, and Appeals
Applies to: Public sector bodies or data intermediaries
“financial penalties for public bodies or intermediaries that negligently disclose protected data or fail to apply required safeguards.”
- #6CriticalPenalties, Liability, and Appeals
Applies to: Public sector bodies or data intermediaries
“financial penalties for public bodies or intermediaries that negligently disclose protected data or fail to apply required safeguards.”
- #7ImportantKey Focus Areas
Applies to: Public sector bodies providing data
“mandatory use of machine‑readable formats and metadata (e.g. DCAT‑AP‑SK)”
- #8ImportantDefinitions
Applies to: Public sector bodies providing data for re-use
“The Draft cross‑references national data and ICT standards used in Slovak public administration and requires clear provenance and licensing metadata for re‑use.”
- #9ImportantGovernance and Institutional Framework
Applies to: Competent body
“The Draft requires coordinated procedures and memoranda of understanding between the competent body and supervisory authorities to expedite lawful re‑use requests.”
- #10ImportantKey Focus Areas
Applies to: Public sector bodies providing data
“standardised access agreements, proportionate fees only where legally authorised”
- #11ImportantMonitoring and Evaluation⏰ Annually
Applies to: Competent body and participating public sector bodies
“The Draft Act requires annual reporting by the competent body and participating public sector bodies on numbers of registered datasets, access requests, approved secure environment cases, anonymisation outcomes, and any incidents or data breaches.”
- #12ImportantMonitoring and Evaluation⏰ Annually
Applies to: Competent body
“The competent body must publish an annual evaluation and an implementation plan for technical updates”
- #13ImportantMonitoring and Evaluation
Applies to: Competent body and public sector bodies
“Cooperation with the Data Protection Authority and sectoral supervisors is mandated for monitoring privacy and security outcomes.”
Related Regulations
Draft Act on the Organization of State Administration in the Field of Artificial Intelligence (national bill to establish oversight, notifying authority and regulatory sandbox)
Slovakia93% similar
Draft Act on the Organization of Public Administration in the Field of Artificial Intelligence (government bill submitted to interdepartmental comment procedure)
Slovakia93% similar
Draft Act on Data Management (Projekt ustawy o zarządzaniu danymi)
Poland90% similar
Institutional and Coordination Framework for the Digital Transformation of Slovakia (government resolution UV-46042/2024)
Slovakia89% similar
Draft AI Act presented by political party 'Da, Bulgaria' (project bill for an AI law)
Bulgaria89% similar
© Regulations.AI — created on 13-Jun-2026