Web2026-09-03 · 12 min

Cookies in Slovakia are not policed by the data protection office. The telecom regulator does it, and the fine reaches 5% of turnover

Cookie supervision in Slovakia does not belong to the data protection office. It belongs to the telecom regulator, which has its own audit tool, a fourteen-page guidance note and a penalty reaching 5% of turnover. Here is what applies to an ordinary site.

by Tair Khamitov
Cookies in Slovakia are not policed by the data protection office. The telecom regulator does it, and the fine reaches 5% of turnover
Contents·12 sections
  1. 01Contents
  2. 021. Hype: the cookie bar came with a plugin, so we are done
  3. 032. This is not GDPR, and the data protection office does not police it
  4. 043. Reality: 105 inspections and over 80,000 euros in fines
  5. 054. What the regulator inspects with: the Cookies Auditor
  6. 065. Must versus recommends: where Slovak coverage overreached
  7. 076. The twelve-month rule almost nobody follows
  8. 087. Not only cookies: fingerprinting, local storage, web beacons
  9. 098. Solution: a checklist, and our own site as the example
  10. 10FAQ
  11. 11About the author
  12. 12External sources

Cookies on Slovak websites are not supervised by the data protection office, as most people assume. They are supervised by the telecom regulator, under section 109(8) of the electronic communications act. The fine reaches 5% of turnover. By August 2025 it had run over 105 inspections and issued more than 80,000 euros in penalties.

I expected a short bit of research and ended up with fourteen pages. The regulator published a standalone guidance note on cookies, jointly with the data protection office, and it contains several rules I have not seen summarised anywhere in Slovak. The twelve-month one below, for instance. Everything that follows comes from that document and from the act it rests on.

Contents

The cookie bar is the one thing on a website nobody decides consciously. It arrives with the theme, with a plugin, with the CMS, or an agency drops it in at launch and nobody touches it again. The whole arrangement rests on an unspoken assumption that the bar is a formality: if one is there, the duty is discharged.

The real problem sits elsewhere and it is mundane. Most operators do not know who actually inspects this, so they ask the wrong people. Companies call a lawyer, or whoever wrote their GDPR paperwork. But the things the regulator objects to are settings in code: what loads before the click, how the buttons are labelled, what colour they are, where the record of consent is stored, and when the bar reappears. None of that is a lawyer’s job.

And no, this is not only about big companies. The regulator also acts on complaints, and it published the address for them in its own press release. A complaint costs nothing and can come from anybody who disliked your site.

Anyone can inspect your cookie bar from outside, in thirty seconds, without telling you.

2. This is not GDPR, and the data protection office does not police it

This is the most widespread misconception, and it is worth unpicking, because everything else follows from it, including who you are actually answering to when an inspection lands.

The duty to obtain cookie consent does not come from the GDPR. It comes from section 109(8) of Act No. 452/2021 Coll. on electronic communications, which reads: anyone storing or gaining access to information stored in a user terminal may do so only where the user has given demonstrable consent meeting the requirements of a special regulation. It transposes Article 5(3) of the ePrivacy directive.

Supervision of that provision belongs to the Regulatory Authority for Electronic Communications and Postal Services, the telecom regulator. Not the data protection office. That office enters at the second step: once you want to process the personal data obtained from cookies, you need a legal basis under the GDPR. Two layers, routinely collapsed into one sentence about GDPR, which is imprecise.

There is an exception and it is narrow. Consent is not needed for cookies whose sole purpose is carrying a message over a network, or which are strictly necessary to deliver a service the user explicitly requested. Those are the necessary or technical cookies. Analytics is not among them.

One more point that surprises people: the guidance proceeds from the assumption that third-party cookies generally cannot be treated as necessary. So if you load something from a foreign domain, the burden of proof sits with you.

3. Reality: 105 inspections and over 80,000 euros in fines

In a press release dated 27 August 2025 the regulator published its running total. Quoting its chairman, Ivan Marták: since the new act took effect they had carried out more than 105 website inspections and imposed fines totalling more than 80,000 euros. The same release states that most Slovak websites still process user data unlawfully.

The rate sits in section 124(3) of the electronic communications act: a fine from 200 euros up to 5% of turnover for the preceding accounting period. Watch this number, because the figure 10% is still circulating. That was the earlier version of the provision. An amendment effective from September 2023 moved the rate for breaching section 109(8) to 5%. If you read ten percent somewhere, you are reading superseded text.

The average across those figures works out at a little over 760 euros per penalty, so ceiling rates clearly are not being handed out. It is not symbolic either, and in an inspection the cost lands more in time and in rebuilding the bar than in the fine itself.

Up to 5% of turnover, not 10%. The number circulating on the Slovak web comes from superseded wording.

4. What the regulator inspects with: the Cookies Auditor

The regulator does not inspect by hand. It uses its own tool, the Cookies Auditor, and the guidance describes it. The tool performs a semi-automated audit and analyses not only cookies but also objects held in local storage and session storage, and it identifies every third party from which the page loads content. Results come back in a structured report.

That matters more than it sounds. It means "we do not use cookies, we keep it in local storage" is not a defence, because the tool sees it identically. And it means the thing being inspected is the one thing that can be measured objectively: whether anything was stored before the visitor clicked.

A public version sits at cookies.teleoff.gov.sk. It works unlike most online testers: it prints no verdict on screen, it asks for an email address and a URL and sends the generated report to you. Which means anybody, a competitor or an unhappy customer, can have a report produced about your site and attach it to a complaint.

Under the bonnet this is not a Slovak invention. The report is generated by Website Evidence Collector, an open-source tool from the European Data Protection Supervisor, published on the EU’s own developer platform under the EUPL. It opens your site in a headless browser, captures screenshots of the top and bottom of the page, checks HTTPS and redirects, and lists first-party and third-party cookies, the contents of local storage, web beacons, and any form sending data unencrypted.

5. Must versus recommends: where Slovak coverage overreached

Several claims about cookie bars circulate as hard law. The guidance puts them more precisely, and the distinction is worth knowing, if only so you do not rebuild the bar over something that is a recommendation.

  • Equal ease is a must. The option to give consent must be as simple and as accessible for the user as the option to withhold it. That is not a recommendation, it is a condition of consent being freely given.
  • A reject-all button in the first layer is what the regulator considers correct. It clearly wants one where the first layer carries an accept-all button, but frames it as the correct solution rather than as statutory text. The practical conclusion is the same: put it there.
  • Colour is a does-not-recommend. Where allow-all, allow-selected and reject-all share one colour, the user is not being steered. Highlighting only the consent button in green is something the regulator advises against.
  • Pre-ticked boxes are unlawful. Here the wording is hard: it is not lawful for consent to any cookie category to be ticked by default. Marketing and analytics must both start unticked.
  • A bar that covers the content with no way past it is forced consent. If a visitor cannot proceed without clicking accept, the consent is not free.

And one point that disappears entirely from most discussions: the burden of proving that consent was freely given rests on the site operator. Not on the regulator, and not on the visitor.

6. The twelve-month rule almost nobody follows

This is the part of the guidance I did not expect, and the most practical thing in the whole document.

The regulator treats twelve months as a reasonable period for which consent is given. Then comes the sentence that inverts common practice: the same applies where the user refused consent, and it should not be requested again for at least twelve months.

Run through the sites you visited this week. How many showed you the bar again on your very next visit after you declined? That is precisely the behaviour at issue, and the guidance adds that re-displaying the bar should not disrupt what the user is doing on the site.

The period can be shorter in two cases the guidance names: where circumstances have changed significantly, such as an entirely new bar configuration, or where the operator cannot track the earlier choice because the user cleared their cookies. Both are substantive, not an excuse for asking weekly.

Tied to this is the demonstrability requirement. The guidance says the server should record a unique browser identifier through which it can be traced back whether consent was or was not given. In other words, the choice living in the visitor's browser is not enough. You need a record on your side too.

If a visitor declined cookies, you should not ask again for a year. Most Slovak sites ask on every visit.

7. Not only cookies: fingerprinting, local storage, web beacons

The guidance widens the scope in its opening pages: the rules cover not just cookies but any tool based on storing, or needing access to, a user's terminal device. It names fingerprinting and web beacons specifically.

In practice that closes three popular workarounds. Moving the identifier from a cookie into local storage and claiming the bar no longer applies. Using fingerprinting instead of cookies and arguing nothing is stored. Loading a script from somebody else's domain and treating it as somebody else's problem, when the regulator's tool names third parties explicitly.

So if you are taking inventory, do not take it from a list of cookies. Take it from whatever loads and stores on first opening the page, while the visitor has clicked nothing.

8. Solution: a checklist, and our own site as the example

This is the list you can forward to a developer without further explanation.

  • Nothing non-essential loads before the click. (law) No analytics, no pixel, no script from a foreign domain until consent exists. Verify it in a browser, not in the plugin settings.
  • Reject-all beside accept-all in the first layer. (regulator recommendation, though equal ease of refusing is law) Matching size and colour is the recommended part.
  • No pre-ticked categories other than the strictly necessary ones. (law, and the regulator calls it outright unlawful)
  • The bar must not lock the content so that consent is the only way forward. (law, otherwise consent is not free)
  • A record of consent on the server, traceable through a browser identifier, kept for as long as you store anything on the strength of it. (demonstrability is law, this particular shape is the regulator’s recommendation)
  • After a refusal, do not ask again for twelve months, except where circumstances changed or the cookies were cleared. (recommendation, but asking on every visit cuts against consent being free)
  • A permanent way to change the choice. (law) Withdrawing consent must be as easy as giving it. A footer button or a control in the cookie policy is enough.

So that this is not just theory, we had devnova.eu checked by the regulator’s own tool. The report dated 3 September 2026 came back with zero first-party cookies, zero third-party cookies, empty local storage, no web beacons and no form sending data unencrypted; HTTPS is enforced by redirect. Traffic measurement starts only after consent is given, and where consent is declined it does not start at all. Closing the bar with the cross counts as a refusal, not as silent agreement.

One thing in that report is worth a warning, because it can scare you for no reason. The tool classifies sources not only by domain but by path: check a URL ending in /sk and your own files sitting outside that path show up in the table under "third parties". In our report the third party listed is devnova.eu, which is us. So read the host names, not the count.

This is not an excessive precaution, it is the cheapest route. When the measurement script loads only after consent, there is nothing left to defend. The details are written up in our cookie policy.

Rebuilding a bar like this for a client is a front-end change and one edit to the template, not a new website. Our website prices are public on the pricing page, the way the work runs is on the process page, and what we build is under services.

When the measurement script loads only after consent, an inspection leaves you nothing to defend.

Run an online shop and just realised there will be more of these? You are right. Since June 2026 the site has to offer a withdrawal function, and the product page needs safety data under GPSR.

FAQ

Who supervises cookies in Slovakia? The Regulatory Authority for Electronic Communications and Postal Services, under section 109(8) of Act No. 452/2021 Coll. The data protection office handles the subsequent processing of personal data under the GDPR.

What is the maximum cookie fine? Under section 124(3) of the electronic communications act, from 200 euros up to 5% of turnover for the preceding accounting period. Older articles cite 10%, which is superseded wording.

Do I have to put a reject button in the first layer? The regulator treats it as the correct solution where the first layer carries an accept-all button. The hard condition is that refusing must be as easy as accepting, which is difficult to satisfy without such a button.

Does this cover local storage and fingerprinting? Yes. The guidance states explicitly that the rules apply to any tool based on storing or accessing a user's terminal device, and it names fingerprinting and web beacons.

How long does consent stay valid? The regulator treats twelve months as a reasonable period. Equally, it should not be requested again for at least twelve months from a visitor who refused.

Is it enough that the visitor's browser remembers the choice? No. The act speaks of demonstrable consent, and the regulator expects a record on the operator's side, traceable through a unique browser identifier.

Is Google Analytics a necessary cookie? No. The exception covers carrying a message over a network and what is strictly necessary for a service the visitor explicitly requested. Traffic measurement is neither.

How do I check my own site? Open it in a private window and, without clicking anything, look in developer tools at what was stored and which foreign domains were requested. The regulator also runs a public tool at cookies.teleoff.gov.sk.

About the author

Author: Tair Khamitov, DevNova, Bratislava. He rebuilds cookie bars often enough to care what that guidance actually says, and this piece came out of its fourteen pages plus our own site opened in developer tools. What you will not find here: a legal analysis. That is what a solicitor is for, and in a real dispute you will need one.

External sources

  • Cookie Check, the regulator's public tool for inspecting a website.
Next step

Interesting read? Real projects cost less than this article suggests. Open pricing + 11-day delivery cycle.