e-Invoicing vs. GDPR and Professional Secrecy: What the State Didn’t Tell Half a Million Businesses

e-Invoicing vs. GDPR and Professional Secrecy: What the State Didn’t Tell Half a Million Businesses

Summary

From 1 January 2027, every invoice between Slovak businesses must travel as structured XML through a certified private company — a “digital postman” — and the data extracted from it, including the name of every invoiced line item and the customer’s name, reaches the Financial Administration in near real time. We examined Act No. 385/2025 Coll., the technical specification of the reporting document, the entire legislative file including all 255 comments from the inter-ministerial consultation, the case law of the CJEU and the ECtHR, and the experience of eight countries. The findings fit into six points:

  1. The act does not contain a single mention of personal data protection. The only occurrence of the string “personal” in Act No. 385/2025 Coll. is “personal motor vehicle”. Zero mentions of the GDPR also in the explanatory memorandum, the impact assessment clause, the consultation evaluation, and the Financial Administration’s 47-page FAQ. The Data Protection Impact Assessment (DPIA) that the GDPR requires for large-scale systematic processing is not publicly documented anywhere.
  2. Slovakia reports names to the state that the harmonised European standard does not know — and the technical specification goes beyond even the Slovak act itself: the customer’s name is transmitted always, although the act requires it only for customers without a VAT ID.
  3. The act fails the requirements that Article 23 GDPR imposes on such an intrusion: no retention period, no purpose limitation, no allocation of controller/processor roles, no safeguards against abuse. Automated accesses to the data are not even logged in the taxpayer’s file.
  4. Digital postmen have no statutory confidentiality obligation, no ban on using the data for their own purposes, and no retention limit. Even the National Security Authority asked for security standards for them in the consultation — unsuccessfully.
  5. Attorney-client privilege got no exemption — the secret service did. In the very same consultation, the Slovak Bar Association asked for protection of client identities (rejected), while the Slovak Information Service asked that data about its own purchases not be fed into the system because the system is a “disproportionate security risk” (accepted).
  6. It can be done differently. Germany and Belgium introduced the same European e-invoice without mandatory intermediaries and without state collection; Italy was forced by its data protection authority to stop storing service descriptions and has permanently banned healthcare invoices from the state system; France excluded service descriptions for professions bound by secrecy directly in statute.

There is no final ruling yet that the scheme violates the GDPR — no European court has struck down an e-invoicing system so far. But the Slovak framework does precisely what supervisory authorities elsewhere have called disproportionate, and what the Court of Justice of the EU has repeatedly held against indiscriminate data collection. The full chain of evidence follows.

1. What Exactly the System Collects

The VAT Act amendment (Act No. 385/2025 Coll.) introduces mandatory e-invoicing for domestic B2B transactions from 1 January 2027 in a five-corner Peppol model: supplier → supplier’s postman → customer’s postman → customer, with the Financial Administration as the fifth corner. The entire invoice passes through the postman — the complete XML with all statutory particulars, plus attachments of up to ~100 MB.

The postman automatically sends the Financial Administration a so-called Slovak Republic Tax Data Document (SK TDD, version 1.0.0). We verified its contents field by field:

  • Invoice lines are mandatory, and each line must carry the item name (field BT-153). The Financial Administration thus receives the textual name of everything Slovak businesses invoice each other for. The legal basis is § 74(1)(f) — “quantity and nature of the goods supplied or the extent and nature of the services rendered”.
  • The customer’s name is always mandatory (field BT-044) — even when the customer has a VAT ID. The act (§ 85o(9)) requires the name only for customers without one. The specification therefore transmits more than the statute it was built on.
  • Optionally, the specification also allows transmission of the IBAN, payment card number and cardholder name — data the act does not require to be reported at all.

Retention: the taxpayer must archive invoices for 10 years. The postman has no statutory obligation or restriction whatsoever — the Financial Administration’s FAQ states outright that “the delivery service provider has no legal obligation to retain the transmitted XML files”; what it does with the data is a matter of its commercial contract. And for the data held by the Financial Administration, the act sets no retention period and no processing rules — only the general tax secrecy regime applies (§ 11 of the Tax Procedure Code), which opens the data to any authority that “demonstrates entitlement” under special laws, and whose automated disclosures through the information system are not recorded in the taxpayer’s file (§ 11(6)).

2. Why This Is a Problem Under the GDPR

Invoices of sole traders, attorneys, physicians or landlords — natural persons — are personal data; the CJEU has confirmed this repeatedly (C-92/09 Schecke, C-398/15 Manni) and, in C-175/20 SS SIA, specifically for collection by a tax administration. The European Data Protection Supervisor (EDPS) wrote in Opinion 7/2023 on the EU VAT reform that invoice data “may reveal sensitive information about specific individuals, such as information on goods purchased, travel plans or legal services”, and that its collection at scale “would provide the means to create a detailed profile of the persons concerned”.

Against that backdrop, the Slovak act has four measurable deficits:

Data minimisation (Article 5 GDPR). The harmonised European dataset for cross-border reporting (Directive 2025/516, “ViDA”) identifies the parties solely by VAT ID — names and addresses are not part of it, which the EDPS highlighted as a key safeguard. The Slovak system transmits names. For domestic transactions, ViDA moreover leaves the data scope entirely to the member state (Article 271b(4)) — minimisation was a purely Slovak policy choice that nobody made. The state even holds the proof that less invasive works, in its own legislation: the VAT control statement has operated since 2014 without service descriptions and without names, and it sufficed for cross-matching deductions — incidentally, it keeps running in parallel with the new system until 30 June 2030, so for three and a half years the same transactions are collected twice.

Missing safeguards (Article 23 GDPR). In C-175/20 the CJEU confirmed that bulk collection by a tax administration must satisfy the requirements of Article 23: defined purposes, categories of data, retention periods, safeguards against abuse. Act No. 385/2025 Coll. contains none of them.

Undefined roles (Article 28 GDPR) and security (Article 32). The act does not determine who in the supplier → postman → Financial Administration chain is the controller and who the processor — precisely what the EDPS warned against. The postman certification (§ 76a) requires no demonstration of GDPR security measures; ISO 27001 becomes mandatory only from 1 July 2027, so the first half-year of mandatory operation runs without a certified security management system.

No DPIA (Article 35 GDPR). For large-scale systematic processing, a data protection impact assessment is mandatory. We searched the entire public file — the impact clause, the explanatory memorandum, the consultation evaluation, the Value for Money Unit’s review — and found not a single mention. The only trace: the Financial Directorate’s project brief of August 2025 lists the DPIA decree as a future obligation. The impact clause moreover states verbatim: “No other alternative solutions were identified.” The Spanish supervisory authority AEPD, in an analogous situation (report 015/2024), concluded that a state repository of a “faithful copy of every invoice” without a DPIA lacks a legal basis. (We have asked the Ministry of Finance and the Financial Directorate to disclose the DPIA under the Freedom of Information Act; we will publish the answers.)

And the supervisory authority? The Slovak Data Protection Office is listed in the consultation evaluation as subject No. 57 with zero comments. In a year in which it commented on 54 other legislative drafts with 151 comments, it said nothing about the largest new collection of business data in the country; its annual report does not contain the word “invoice”.

3. Attorneys, Physicians and Secrecy: Only the Secret Service Got an Exemption

An attorney’s invoice carries the client’s name and a description of the service. The sum of an attorney’s invoices is their client list — in the hands of a private postman and in the Financial Administration’s database. The duty of confidentiality under § 23 of the Advocacy Act knows only five exceptions (AML, written waiver by the client, a dispute with the client, disciplinary proceedings, prevention of a crime) — handing an invoice to a commercial Peppol operator falls under none of them. Notaries, tax advisors, bailiffs, mediators and healthcare workers carry analogous duties; none of those statutes knows an e-invoicing exemption either.

The case law is unambiguous and recent:

  • ECtHR, Sommer v. Germany (2017): obtaining the movements on an attorney’s professional bank account from a third party (the bank) violated Article 8 of the Convention — the safeguards of legal privilege cannot be circumvented by requesting the data from an intermediary.
  • CJEU, C-694/20 Orde van Vlaamse Balies (2022): the mere disclosure of the existence of an attorney-client relationship to third parties interferes with Article 7 of the Charter.
  • CJEU, C-432/23 Ordre des avocats du barreau de Luxembourg (26 September 2024): an order requiring an attorney to hand the tax administration “all documentation and information relating to his relations with his client” interferes with Article 7 of the Charter — and a member state may not carve tax-law advice out of the enhanced protection.

What happened in the public consultation. We pulled the complete dataset of 255 comments on the draft act (LP/2025/396) together with the official evaluation containing the ministry’s responses. Five comments touched privacy or secrecy. Three deserve a verbatim read:

The Slovak Bar Association (19 August 2025) proposed that an attorney should not be obliged to state “the client’s identification data or a specific description of the legal service where stating them could lead to a breach of the duty of confidentiality”, with anonymisation “in a manner that excludes any possibility of re-identifying the client” — invoking the Charter, the Convention, the Slovak Constitution and the case law above. Outcome: rejected. The Ministry of Finance replied that identification data are a mandatory invoice particular under the EU directive, adding: “for the description of the service it suffices to state a generic designation that legal services were provided.” A remarkable concession — except it is a sentence in a consultation evaluation, not a legal norm; and it does not address the client’s identity at all: that keeps flowing through the postman and, via the TDD’s mandatory field, to the Financial Administration.

The Slovak Information Service (18 August 2025) asked that data about the nature of goods and services supplied to itself not be fed into the system. Its reasoning deserves quoting: “even the provision of seemingly insignificant data may, directly or in combination with other data, jeopardise the performance of its tasks”; compared to the control statement this is “a disproportionate increase of the security risk”; “it is currently impossible to determine unambiguously the range of entities, or the number of persons, who could potentially have access to the provided data”; and “it is impossible to determine the level of protection of the data … that this system is capable of ensuring.” Outcome: accepted. The act today bans e-invoices for the SIS, Military Intelligence and classified matters.

Read those two decisions side by side. The state’s own secret service officially concluded that the system is a security risk with an uncontrollable circle of access — and received an exemption. Attorneys, with the same logic and stronger case law, did not. The clients of attorneys and the patients of physicians enjoy less protection than the secret service’s shopping lists.

The National Security Authority additionally demanded that postmen meet the security standards for qualified electronic registered delivery services under the eIDAS Regulation (ETSI EN 319 5xx). A fundamental objection: rejected. The national cybersecurity authority asked for concrete security norms for the channel that will carry every invoice in the country — and the finance ministry declined.

4. How Others Handle It

Concentrated tax data, meanwhile, leaks again and again: Bulgaria’s revenue agency lost the data of 5+ million citizens in 2019, an IRS contractor exfiltrated the tax returns of the wealthiest Americans, and Tungsten, an e-invoicing network operator, suffered a breach in 2025. Slovakia’s certification-without-security-norms (Section 3) has yet to present its bill — and the eKasa experience, where the “tamper-proof” certified module could be emulated, shows how much a state certification stamp really weighs.

5. The Domestic Precedent: eKasa Already Fell at the Constitutional Court Once

Slovakia has its own template for how such disputes end. In ruling PL. ÚS 25/2019 (eKasa), the Constitutional Court declared the “unique buyer identifier” unconstitutional and stressed that a statute must define and justify the specific purpose of collection before collecting — not afterwards. The controller (the Financial Administration) and the architecture (real-time transfer into a central database) are identical for e-invoicing. Earlier still, in PL. ÚS 10/2014 (139/2015 Coll.), the court struck down blanket retention of telecom metadata. The CJEU has held the same line from Digital Rights Ireland to La Quadrature du Net: indiscriminate preventive collection covering an entire population, untethered from suspicion, fails even for fighting serious crime — let alone for collecting VAT.

6. What Follows

For the legislator — three fixes that do not impair the system’s declared purpose:

  1. Minimise the dataset: the state should receive the fields needed to compute and match VAT — not item names and personal names. Italy proves it can be done retroactively; doing it before launch is cheaper.
  2. Elevate the professional-secrecy exemption from a sentence in a consultation document to a legal norm — the French model exists, and the Bar Association’s draft was on the table. The protection granted to the SIS belongs to attorneys’ clients and patients too.
  3. Security standards for the postmen — accept what the National Security Authority asked for: eIDAS/ETSI norms, statutory confidentiality, a ban on secondary use of data, retention limits, and independent audits instead of a certification stamp.

For attorneys, physicians and other professions — until 30 June 2030 there is a lawful way to give the client list neither to a postman nor to the state: the e-invoice must be issued, but with the recipient’s consent it may be delivered by e-mail outside the delivery service — and then nothing is reported to the Financial Administration (confirmed directly in the Financial Administration’s FAQ, examples 61 and 66: “neither the supplier nor the customer has the obligation to report data to the financial administration”). You must still keep a contracted postman for receiving (§ 71(5)), and corrective invoices must follow the original channel — but as a client, do ask every supplier bound by secrecy whether they invoice outside the postman. Incidentally: if the statute itself tolerates three and a half years of operation without reporting, it is hard to argue the reporting is necessary.

For the professional chambers — the Slovak Bar Association never publicly communicated its rejected comment; its members are learning about it from this analysis. The medical chambers did not act at all, and the Ministry of Health filed not a single comment. The C-694/20 and C-432/23 case law is ammunition the state cannot wave away as ideology — and the SIS precedent is domestic proof of a double standard that reads effortlessly in a courtroom.

Under the Slovak Freedom of Information Act (No. 211/2000 Coll.), we have asked the Ministry of Finance and the Financial Directorate to disclose the Data Protection Impact Assessment (DPIA) for the eFaktúra system. We will report on the answers.


This analysis draws on the following primary sources: Act No. 385/2025 Coll. and the consolidated VAT Act as of 1 January 2027; the SK Tax Data Document specification v1.0.0; the Financial Administration FAQ 9/DPH/2025/IM; the complete dataset of 255 comments on LP/2025/396 (Slov-Lex portal API) and the consultation evaluation; Directive (EU) 2025/516 and Regulation (EU) 2025/517; EDPS Opinion 7/2023; and the CJEU and ECtHR judgments cited in the text.

more insights