Social Insurance Agency – Court Ruling (Slovakia, 2025)

Court Ruling
DPA25 June 2025Slovakia
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Slovak Social Insurance Agency sent sensitive personal data through regular mail instead of using a safer method. This decision put the data at risk and led to a complaint from the affected person. The ruling emphasizes the importance of using secure methods for sending personal information.

What happened

The Social Insurance Agency sent sensitive personal data by ordinary mail instead of registered mail.

Who was affected

The affected person was someone applying for a Danish invalidity pension whose sensitive data was mishandled.

What the authority found

The court ruled that the agency did not ensure adequate security for sensitive personal data, violating GDPR requirements.

Why this matters

This case highlights the need for companies to prioritize data security when handling sensitive information. Businesses should review their mailing practices to ensure they protect personal data appropriately.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 24(1) GDPR
Art. 32(1) GDPR
Art. 32(2) GDPR
Art. 83(4)(a) GDPR
Art. 83(7) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 24(1) GDPR
Art. 32(1) GDPR
Art. 32(2) GDPR
Art. 83(4)(a) GDPR
Art. 83(7) GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

§100(1) ZOOÚ
§100(2) ZOOÚ
§104(1)(a) ZOOÚ
Decision AuthoritySprávny súd v Bratislave
Reviewed AuthorityOffice for Personal Data Protection of the Slovak Republic
Source verified 18 July 2026
articles corrected
amount discrepancy
authority corrected
Full Legal Summary
Detailed

Sociálna poisťovňa, the social insurance agency (the controller), processes applications for foreign invalidity pensions and forwards related documents to the social insurance institutions of other EU Member States. A data subject applied for a Danish invalidity pension. On 22 October 2018, the controller sent the data subject's sensitive personal data (including health data, personal identification number and a Danish personal identifier) to the Danish social insurance institution by ordinary (uninsured, untracked) second-class mail rather than by registered mail. The data subject could not confirm delivery and, in November 2018, filed a request with the Slovak DPA alleging that sending sensitive data by ordinary mail, without any proof of dispatch or protection against loss, violated their data protection rights. The controller resent the documents by the same method in December 2018. The DPA's first-instance decision (13 June 2019) found that the controller had violated Article 24(1) in conjunction with Article 32(1) and (2) GDPR, because sending sensitive personal data by ordinary rather than registered mail did not ensure a level of security appropriate to the risk. The DPA ordered the controller to use registered mail for such dispatches going forward and imposed a fine of €50,000. The controller's appeal was rejected, and the Slovak DPA president upheld the first-instance decision. The controller then brought an action before the Regional Administrative Court Bratislava, arguing among other things that: the parcel had in fact been delivered (as confirmed by the Danish institution by email), registered mail offers no greater protection against loss of confidentiality than ordinary mail, only one data subject was concerned and no damage had occurred and the decision's operative part improperly referred to the data of pension applicants generally, not just the individual data subject who had filed the complaint. The court did not rule on the substance of the s

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Related Cases (0)

No other cases found for Social Insurance Agency in SK

This is the only recorded case for this entity in this jurisdiction.

Details

Ruling Date

25 June 2025

Authority

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Social Insurance Agency - Slovakia (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: