GDPR for Companies — Complete Guide to Personal Data Protection under EU Regulation 2016/679
Practical GDPR guide for companies: what GDPR is, its relationship to Act No. 18/2018 Coll., 7 principles of processing, legal bases, rights of data subjects, obligations, Data Protection Officer (DPO), breach notification within 72 hours, penalties and Slovak specificities.
What GDPR Is and Why It Applies to Your Business Too
GDPR (General Data Protection Regulation) is the general regulation on the protection of personal data, officially Regulation of the European Parliament and of the Council (EU) 2016/679. It is the most comprehensive personal-data protection framework in EU history. Unlike a directive, which must be transposed into national law, a regulation is directly applicable — it applies in the same way in every member state. It took effect on 25 May 2018.
Many business owners believe GDPR is a problem for large corporations and tech giants. The opposite is true. The regulation applies to everyone who processes personal data in connection with business — from a sole-director LLC through an e-shop, an accounting firm or a medical practice to a manufacturing company. If you maintain a customer database, send a newsletter, operate a CCTV system, record attendance or collect contacts via a form, you are processing personal data and GDPR applies to you.
If you are looking for concrete GDPR implementation services rather than theory, see the GDPR for companies — turnkey page. This guide is educational and goes deep into the legislation.
GDPR versus Act No. 18/2018 Coll. — How They Fit Together
A frequent source of confusion is the relationship between the European regulation and Slovak law. Both apply simultaneously, but each serves a different purpose. Regulation 2016/679 (GDPR) is the superior, directly applicable instrument — it defines the principles, legal bases, rights of data subjects, obligations and the penalty framework. It is not a transposition; there is no 'Slovak version of GDPR'.
Act No. 18/2018 Coll. on the Protection of Personal Data complements GDPR in areas where the regulation leaves member states room for their own rules (so-called opening clauses) — the position of the supervisory authority, special rules for birth identification numbers, the age threshold for a child's consent or journalistic purposes. Act No. 18/2018 Coll. replaced the previous Act No. 122/2013 Coll. (which had itself replaced the older Act No. 428/2002 Coll.); both are no longer in force.
In practice this means: when you need the definition of the right to erasure or the deadline for reporting a breach, you open GDPR. When you are dealing with whether you may request a birth identification number or from what age a teenager's consent is valid, you open Act No. 18/2018 Coll.
Key Terms — Who's Who in Data Protection
To apply GDPR you need to understand four roles.
- Personal data — any information about an identified or identifiable natural person: name, e-mail, phone number, IP address, location data, photograph. Special categories (sensitive data) under Art. 9 GDPR are data concerning health, biometrics, genetics, religion, political opinions or sexual orientation — subject to a stricter regime.
- Data subject — the individual whose data is being processed: your customer, employee, supplier or website visitor.
- Controller — the party that determines the purposes and means of processing, typically your company. It bears the primary responsibility and faces the sanctions.
- Processor — processes data on behalf of the controller (an external accountant, payroll firm, IT provider, mailing service, cloud). The relationship must be governed by a processing agreement under Art. 28 GDPR.
Seven Principles of Personal Data Processing (Art. 5 GDPR)
The whole of GDPR rests on seven principles under Art. 5. They are the guardrails you must observe in every processing activity. Breaching them carries the highest tier of fines.
- Lawfulness, fairness and transparency — you process data only on a lawful basis, fairly and in a way that the person can clearly understand.
- Purpose limitation — you collect data for a specific, explicit and legitimate purpose and do not use it for an incompatible purpose.
- Data minimisation — you collect only the data that is genuinely necessary for the purpose. No 'just in case' collection.
- Accuracy — you keep data up to date and promptly correct or erase inaccurate data.
- Storage limitation — you retain data only for as long as necessary, then delete or anonymise it.
- Integrity and confidentiality — you adequately protect data against unauthorised access, loss or destruction.
- Accountability — you must be able to demonstrate compliance with the preceding six principles. It is not enough to comply; you need evidence.
It is precisely the seventh principle — accountability — that makes GDPR a system where 'we don't have anything written down but we comply' simply does not hold up. During an inspection the authority asks for documentation.
What Legal Basis Allows You to Process Data (Art. 6 GDPR)
No processing is 'just because'. Every processing activity must have one of the six legal bases under Art. 6 GDPR:
- Consent of the data subject — a freely given, specific, informed and unambiguous expression of will; it must be revocable and demonstrable.
- Performance of a contract — when processing is necessary for the conclusion or performance of a contract (fulfilling an order, paying a salary).
- Legal obligation — when another law requires you to process the data (accounting, tax, archiving, BOZP (occupational health and safety) and occupational-health documentation).
- Vital interests — protection of the life and health of a person (rare, for example in healthcare).
- Public interest or exercise of official authority — typical for public authorities.
- Legitimate interests — a flexible basis (direct marketing to existing customers, network security, debt collection); requires a proportionality test (balancing test).
The most common company mistake: asking for consent for everything. In reality, consent is often the weakest and most fragile basis (it can be withdrawn at any time). For fulfilling an order or running payroll, consent is not needed at all.
Rights of the Data Subject (Art. 15 – 22 GDPR)
GDPR gives individuals strong and enforceable rights. A company must respond to their exercise generally within one month (Art. 12 GDPR).
| Right | Article | What it means |
|---|---|---|
| Access | Art. 15 | The person may ask whether and what data you hold about them, and receive a copy. |
| Rectification | Art. 16 | Correction of inaccurate and completion of incomplete data. |
| Erasure ('right to be forgotten') | Art. 17 | Deletion of data when it is no longer necessary or consent has been withdrawn. |
| Restriction of processing | Art. 18 | Temporary 'freeze' of processing in disputed cases. |
| Data portability | Art. 20 | Issuance of data in a structured, machine-readable format. |
| Objection | Art. 21 | Objection to processing based on legitimate interest and to direct marketing. |
| Automated decision-making | Art. 22 | Right not to be subject to a purely automated decision with legal effects. |
The practical consequence: you must have a working process for receiving requests, verifying the identity of the requester, locating the data and responding within the deadline. Ignoring a request is a common reason for a complaint to the authority.
Company Obligations — Documentation You Must Have
In addition to principles and rights, GDPR imposes specific 'paperwork' obligations on a company. These are precisely what ÚOOÚ (Office for Personal Data Protection) checks first.
Duty to Inform (Art. 13 – 14 GDPR)
When collecting data you must inform the person in an understandable way — who you are, for what purpose and on what basis you process the data, to whom you provide it, how long you retain it and what rights the person has. This is done through the document Privacy Policy (Principles for the Protection of Personal Data). Art. 13 concerns data obtained directly from the person; Art. 14 covers data obtained from another source.
Records of Processing Activities (Art. 30 GDPR)
Art. 30 GDPR requires keeping an internal record of processing activities — an overview of what data you process, for what purpose, on what basis, for how long and to whom. There is an exemption for organisations with fewer than 250 employees, but it does not apply if the processing is not occasional, poses a risk to the rights of persons, or involves special categories of data — which applies to almost every real business. In practice, therefore, even a small company needs to keep records.
DPIA and Security (Art. 35 and Art. 32 GDPR)
If processing is likely to result in high risk (extensive CCTV systems, profiling, sensitive data on a large scale), you must carry out a data protection impact assessment (DPIA) under Art. 35 GDPR before you start. At the same time, Art. 32 GDPR requires appropriate technical and organisational measures — encryption, access management, backup, pseudonymisation and employee training.
Data Protection Officer (DPO) — When a Company Must Have One (Art. 37 GDPR)
A Data Protection Officer (DPO) is an internal or external expert who oversees GDPR compliance, advises management and acts as the contact point for both data subjects and the authority. Under Art. 37 GDPR (and § 44 of Act No. 18/2018 Coll.) appointing one is mandatory in three cases:
- you are a public authority or a body governed by public law;
- your core activities consist of large-scale systematic monitoring of data subjects (large-scale tracking of behaviour, profiling);
- your core activities consist of large-scale processing of special categories of data under Art. 9 (for example, healthcare facilities).
Outside these cases a DPO is not mandatory, but many companies appoint one voluntarily because it simplifies demonstrating accountability. The DPO must have professional expertise, an independent position and sufficient resources. The role can be covered by an external provider (DPO outsourcing) — the most common solution for small and medium-sized companies.
Data Breach and Reporting Within 72 Hours (Art. 33 – 34 GDPR)
A personal data breach is any security incident leading to the destruction, loss, alteration, unauthorised disclosure or access to data — from a lost USB drive through a hacked e-shop to an e-mail sent to the wrong recipient.
- Notification to the supervisory authority (Art. 33 GDPR, § 40 of Act No. 18/2018 Coll.) — you report the breach to the Office for Personal Data Protection of the Slovak Republic without undue delay, at the latest within 72 hours of becoming aware of it. The exception is where the breach is unlikely to result in a risk to the rights of persons.
- Notification to the data subject (Art. 34 GDPR) — if the breach is likely to result in high risk, you must without undue delay also inform the individuals concerned.
Every breach — including one that you do not report — must be documented internally. A prepared incident response plan (who decides, who reports, within what deadline) is the difference between a managed incident and a fine for a missed notification.
Penalties for GDPR Violations (Art. 83)
GDPR has one of the strictest penalty frameworks in the EU. Art. 83 GDPR distinguishes two tiers of fines depending on the seriousness of the violation.
| Tier | Maximum fine | Typical violations |
|---|---|---|
| Lower tier (Art. 83 ods. 4) | up to €10 million or 2 % of total worldwide annual turnover (whichever is higher) | missing records (Art. 30), processor obligations, missing DPIA, failure to appoint a DPO |
| Upper tier (Art. 83 ods. 5) | up to €20 million or 4 % of total worldwide annual turnover (whichever is higher) | breach of principles (Art. 5), legal bases (Art. 6), rights of persons (Art. 15–22), transfer rules |
The fine is set at whichever of the two amounts (fixed or percentage-based) is higher. In determining the amount, the authority takes into account the nature, seriousness and duration of the infringement, intent, cooperation and measures taken. Alongside fines it may impose corrective measures including a temporary or permanent ban on processing. In Slovak practice fines have so far been lower than the European maxima, but the number of ÚOOÚ decisions is growing.
Office for Personal Data Protection SR (ÚOOÚ) and Supervision
The supervisory authority in Slovakia is the Office for Personal Data Protection of the Slovak Republic (ÚOOÚ), website dataprotection.gov.sk. Beware of a widespread misconception: GDPR is not enforced by the district office or the labour inspectorate — exclusively by ÚOOÚ.
The authority receives and handles complaints from data subjects, carries out inspections (on its own initiative and on a complaint basis), receives breach notifications and imposes fines. An inspection most commonly starts following a complaint by a customer or an employee. During an inspection the authority requests precisely the documentation — records of processing activities, privacy policies, consents, processing agreements and evidence of measures. A company whose documentation is in order will pass an inspection without major issues.
Slovak Specificities Not Governed by GDPR Itself
Birth identification number (§ 78 of Act No. 18/2018 Coll.)
The birth identification number (rodné číslo) is a universally applicable identifier in Slovakia subject to a special regime under § 78 ods. 4 of Act No. 18/2018 Coll. It may be used to identify a person only where it is necessary for the purpose; where processing is based on consent, the consent must be explicit and publishing the birth identification number is prohibited (unless the person publishes it themselves). Blanket collection of birth identification numbers 'into a form just in case' is a typical violation.
Age of consent for a child = 16 years
For offers of information society services (online services) directly to a child, consent is valid from the age of 16 years under § 15 ods. 1 of Act No. 18/2018 Coll. GDPR allowed member states to lower the threshold to as little as 13 years; Slovakia did not exercise this option. For a younger child you need consent from a legal guardian.
Employee monitoring (§ 13 of the Labour Code)
Monitoring of employees (cameras, GPS, monitoring of mail or performance) is regulated, alongside GDPR, also by § 13 ods. 4 of the Labour Code. An employer may not, without serious reasons arising from the special nature of the activity, intrude into an employee's privacy through monitoring without having previously informed the employee of the scope, manner and duration of the monitoring. A CCTV system therefore requires a legal basis, an information obligation, frequently a DPIA and always notification of employees.
How a Company Implements GDPR from Scratch — Step-by-Step Guide
The following procedure summarises how a company gets from zero to a state of GDPR compliance.
Map your processing activities List what personal data you collect, where it comes from, where it is stored and to whom you send it. This is the data audit and the foundation for everything else.
Determine the legal basis for each purpose Under Art. 6, assign a legal basis to each processing activity (contract, legal obligation, legitimate interest, consent).
Draw up records of processing activities Under Art. 30, compile a register of purposes, data categories, retention periods and recipients.
Prepare information obligations Create a Privacy Policy under Art. 13 – 14 for your website, contracts and HR agenda.
Set up consents where they are required For marketing and cookies, ensure demonstrable and revocable consent — not pre-ticked boxes.
Conclude processing agreements With every supplier that processes data on your behalf (accountant, IT provider, hosting, mailing), sign an agreement under Art. 28.
Implement technical and organisational measures Under Art. 32, set up access rights, backups, encryption and rules for employees.
Assess the need for a DPO and DPIA Verify whether Art. 37 requires you to appoint a DPO and whether any high-risk processing requires a DPIA under Art. 35.
Set up a process for data subject rights Prepare a procedure for handling requests under Art. 15 – 22 within the statutory deadline.
Prepare a breach response plan Define who and how will report an incident to the authority within 72 hours under Art. 33 – 34.
Train employees The weakest link is the human factor — regular training reduces the risk of an incident and of a fine.
Review and update regularly GDPR is not a one-off project; revise your documentation with every change to your processes, systems or suppliers.
Most Common GDPR Myths
- 'We are a small company, GDPR doesn't apply to us.' It applies to everyone who processes personal data. Size affects the scope of obligations, not their existence.
- 'I need consent for everything.' Consent is just one of six legal bases and is often not appropriate. Fulfilling an order or running payroll does not require consent.
- 'GDPR prohibits sending a newsletter to customers.' Direct marketing to existing customers can be based on legitimate interest, with the option to object at any time.
- 'Having a sentence about data protection on the website is enough.' The information obligation is just one of the documents required. Without records, agreements and measures you are not compliant.
- 'GDPR and records management are the same thing.' They are not. Records management is a separate area governed by Act No. 395/2002 Coll. and GDPR does not replace it.
- 'Fines are issued by the district office.' Sanctions under GDPR are imposed exclusively by ÚOOÚ.
- 'If nobody reports us, nothing happens.' The authority can act on its own initiative and you must be able to demonstrate accountability at any time.
GDPR Readiness Checklist
Before a customer approaches you with a request or the authority with an inspection, go through this checklist:
- Do you have up-to-date records of processing activities?
- Are there clear and understandable Privacy Policies on your website and in your contracts?
- Do you have a legal basis identified for each processing activity?
- Are consents (marketing, cookies) demonstrable and revocable?
- Do you have signed processing agreements with all suppliers?
- Do you have technical and organisational measures and access controls in place?
- Do you know whether you need a DPO and whether you have carried out a DPIA for high-risk processing?
- Do you have a process for handling data subject rights within the deadline and a breach response plan within 72 hours?
- Have your employees been trained?
If you hesitated at several of the items above, GDPR is not genuinely implemented at your company. To move from theory to implementation, our GDPR services can help — documentation, DPO outsourcing, audit, training and representation during a ÚOOÚ inspection.
Súvisiace služby a zdroje
GDPR pre firmy na kľúč
Vypracujeme dokumentáciu GDPR, prevezmeme funkciu zodpovednej osoby (DPO), zaškolíme a zastúpime vás pri kontrole ÚOOÚ.
BOZP — bezpečnosť a ochrana zdravia pri práci
Komplexné zabezpečenie BOZP pre vašu firmu — popri GDPR pod jednou strechou.
Pracovná zdravotná služba
PZS pre zamestnancov — zdravotný dohľad a posudky popri ochrane osobných údajov.
Civilná ochrana
Dokumentácia a plán ochrany zamestnancov — ďalšia zákonná agenda pod jednou strechou.
Kurzy a školenia
Školenie zamestnancov v oblasti bezpečnosti a ochrany údajov.
Slovník pojmov
Výkladový slovník kľúčových pojmov z BOZP, OPP, PZS a VTZ.
Stručná odpoveď
GDPR is the EU General Data Protection Regulation, which has applied directly in Slovakia since 25 May 2018 and is complemented by the Slovak Act on the protection of personal data. It applies to every company and every sole trader that processes the data of customers or employees. The key obligations are a legal basis for processing, the information obligation, records of processing activities, adequate security and notification of a breach to the authority within 72 hours.
Časté otázky o GDPR
Yes. GDPR applies to everyone who processes personal data in connection with business, regardless of size. A small company and a sole trader have less extensive obligations than a corporation, but the basic rules apply equally: a legal basis, the information obligation, security and usually also records of processing activities.
GDPR is EU Regulation 2016/679, which applies directly and takes precedence throughout the Union. Act No. 18/2018 Coll. merely complements it in Slovakia where the Regulation leaves room for the member state, for example the birth number, the age of a child's consent or the powers of the authority. Both regulations apply simultaneously.
A data protection officer is mandatory if you are a public authority, if your main activity is large-scale systematic monitoring of individuals, or if you process sensitive data on a large scale. Outside these cases a DPO is not mandatory, but many companies set one up voluntarily, often in the form of external outsourcing.
You must report a data breach to the Office for Personal Data Protection without undue delay, no later than within 72 hours of the moment you became aware of it. If there is a high risk to the data subjects, you must also inform them. Every incident must be documented, even if you do not report it.
GDPR distinguishes two levels. The lower rate is up to 10 million euros or 2 per cent of worldwide annual turnover, the higher rate up to 20 million euros or 4 per cent of turnover, whichever amount is higher. The amount is set by the authority according to the seriousness, duration and cooperation of the company.
The supervisory authority is exclusively the Office for Personal Data Protection of the Slovak Republic, based in Bratislava. Neither the district office nor the labour inspectorate carries out oversight. The Office receives complaints, carries out inspections on its own initiative and on the basis of a complaint, and imposes sanctions.
For cookies and similar technologies that are not strictly necessary for the website to function, you need the visitor's valid consent. The consent must be freely given, demonstrable and as easy to withdraw as to give. A pre-ticked box, or the mere use of the website, is not enough as consent.
Monitoring of employees is possible, but only where there is a serious reason consisting in the nature of the activity and after meeting the conditions under § 13 ods. 4 of the Labour Code. You must inform employees in advance of the extent, manner and duration of the monitoring, determine the legal basis, fulfil the information obligation and, for risky monitoring, carry out an impact assessment.
In Slovakia, for online services offered directly to a child, an age limit of 16 years applies under § 15 ods. 1 of Act No. 18/2018 Coll. Slovakia did not use the option to lower it to 13 years. For a younger child you need the consent or approval of the legal representative.
The birth number has a special regime in Slovakia under § 78 of Act No. 18/2018 Coll. You may process it only where its use is genuinely necessary for the given purpose and this follows from a special law or the person consents to it. Publishing a birth number is prohibited, and collecting it into forms en masse 'just in case' is a breach.
It must clearly state who processes the data, for what purpose and on what legal basis, to whom they are provided, how long they are retained, what rights the data subject has and how to exercise them. The document is usually published on the website and is also used in contracts and HR records.
Only for as long as it is necessary for the original purpose. The periods are often set by other laws, for example accounting and tax regulations or employment-law archiving. Once the purpose has passed, you must erase or anonymise the data. The retention periods should be captured in your records of processing activities.
Yes. Every supplier that processes personal data on your behalf is a processor, and the relationship with them must be governed by a written processor agreement under čl. 28 of GDPR. This applies to an external accountant, a payroll company, IT and hosting, an email platform and cloud tools.
As a rule, yes. The exemption for organisations under 250 employees does not apply if the processing is not merely occasional, poses a risk to the rights of individuals, or includes sensitive data. This applies to almost every real company, so in practice you need to keep records even as a small business.
It is enough for them to request erasure, for example by email. You must verify their identity, assess whether erasure is not prevented by another statutory obligation to retain the data, and, within the statutory period — as a rule within one month — comply with the request or refuse it with reasons. You should have the whole procedure prepared in advance.
Need help with workplace safety?
Contact us today and get a free consultation. Our team of experts will help you find a solution tailored to your needs.