Summary
As of 20 August 2026. The story is developing and we will update this text.
On 17 August 2026, Act No. 29/2026 Coll. on the Commercial Register took effect in Slovakia. Two days later it was clear that anyone in the world can download — with no login, no electronic ID card and without paying a single cent — the birth number, permanent residence address, ID card number and certified specimen signature of any Slovak company director or shareholder.
The media described it as an embarrassment, an implementation bug, a state IT failure. It is none of those. It is exactly what a senseless, privacy-destroying statute says in black and white — and it lands on every entrepreneur, director and shareholder in the country. Below we show the section that orders it.
That it has a basis in law is not a defence — it is an aggravating circumstance. The statute is substantively defective and passing it was a very bad decision. It protects the birth number in one subsection and two subsections later orders the publication of a document containing it. A bug in code you fix with a patch; this someone deliberately wrote into a statute and parliament voted for it. The published data can be trivially abused, the abuse cannot be traced, and no one will ever take the damage back — a birth number is for life. We take this apart point by point in chapter 4.
Over eleven years on this blog we have described how citizens’ privacy is threatened by the intelligence service, how it is threatened by KYC, and how we were able to download the COVID certificate of any Slovak citizen purely because we knew their birth number — the very data point the state has now published wholesale.
And we are adding a new finding: on 18 August 2026 the Ministry of Finance confirmed to us in writing that when drafting the e-invoicing act it never carried out a data protection impact assessment, never consulted the Data Protection Authority, and never performed a proportionality test. The system through which every invoice of every Slovak company will flow from 2027 was therefore assessed for privacy by nobody — except the intelligence service, which secured an exemption for itself.
We are convinced that the greatest threat to citizens’ privacy in Slovakia today is the state itself. Not hackers, not corporations, not foreign intelligence services — the state, which regulates privacy, exempts itself from its own rules, and bears no consequences for breaking them. What follows is eleven years of evidence.
Contents
- 2015: the intelligence service
- 2019: KYC as a honeypot
- 2021: the birth number as a universal key
- 2026: the state published the birth numbers itself. To everyone.
- New evidence: the state never once measured the risk
- And that is only one brick: the regulatory perimeter 2025–2029
- We described this back in 2019
- The paradox: the author of the GDPR is the biggest privacy violator
- What to do: do not rely on the state — including concrete steps for company directors
1. 2015: the intelligence service
In July 2015 we published an article titled “Afraid for your privacy? Fear the SIS.” It was written after the hacked servers of the Italian company Hacking Team spilled out email correspondence with the Slovak intelligence service about buying spyware.
The facts from that article are worth repeating:
- The SIS repeatedly submitted a proposal to intercept any encrypted communication of all citizens. It withdrew it only after public resistance and a formal objection procedure.
- On 15 September 2014 WikiLeaks revealed that Slovakia had bought 39 licences of FinFisher for more than EUR 5 million. FinFisher is built on 0-day vulnerabilities and is used by dictatorships to track dissidents. The Government Office dismissed it with the line that WikiLeaks is “hearsay quality”.
- The leaked emails showed that intermediaries for the SIS invited representatives of Hacking Team and Gamma to Bratislava. The service was therefore genuinely shopping for spyware — comparing offers from two companies that both supplied dictatorial regimes.
- The SIS has direct access to communications at every mobile operator. It does need a court order, but in practice it almost always gets one.
The lesson from 2015: the state acquires offensive capabilities against its own citizens, denies it, and when someone proves it, attacks the source.
2. 2019: KYC as a honeypot
Four years later we wrote about another layer of the same problem — KYC/AML regulation, which forces millions of people to hand a photo of their passport, a proof of address and a selfie holding their ID to private companies of wildly varying security maturity.
In that article we described a specific offer from the darknet marketplace Dread. A vendor going by ExploitDOT was selling KYC documents of users of major crypto exchanges. Our colleague contacted him and received a price list: USD 15 per document, USD 45 for a complete identity (passport or ID, proof of address, selfie with the document), minimum order 100 identities for USD 4,500. The seller was willing to use escrow.
The conclusion was simple and still holds: if you have ever gone through the KYC process of an exchange that was later breached, your privacy is compromised. You cannot take it back. An identity document cannot be “changed like a password”.
KYC does not even work for its stated purpose. Ronald Pol’s peer-reviewed analysis “Anti-money laundering: The world’s least effective policy experiment?” (Policy Design and Practice, 2020) found that the anti-money-laundering regime affects less than 0.1 % of criminal finances, while compliance costs exceed the criminal funds recovered more than a hundredfold. The cost is certain; the benefit is a rounding error. We covered this in detail in Why we are losing privacy and freedom despite the GDPR (in Slovak).
3. 2021: the birth number as a universal key
In August 2021 we published an analysis in which we comprehensively broke the EU COVID-19 vaccination certificates. This is the part to keep in mind while reading the rest of this article.
The chain was this:
- The eHranica application let anyone who knew a vaccinated person’s birth number set a new contact email and phone number for that person.
- The attacker then had that person’s EU vaccination certificate sent to those new contacts.
- The birth number did not have to be stolen anywhere. A Slovak birth number has the form YYMMDD/XXXX and must be divisible by eleven, which leaves roughly 910 valid candidates for a known date of birth. We generated them with a script — about 30 million in total — and verified them through the public portal portaludzs.sk, whose “health insurance verification” service was protected by a bypassable CAPTCHA.
- Politicians’ dates of birth are on Wikipedia. Ordinary people’s dates of birth are on social media. And the dates of birth of every property owner in Slovakia are in the land registry.
The birth number therefore worked as a universal authentication key to a citizen’s health data. Not as an identifier — as a password. We reported the vulnerability to the national CSIRT on 30 July 2021 at 18:23, acknowledgement came on 2 August and the fix on 9 August. The full technical report is public.
The reward was a criminal complaint filed by the National Health Information Center and a series of statements we had to rebut point by point (in Slovak). It was not the first time — a year earlier we had found a leak of the database of patients tested for COVID-19 in the My eHealth application.
So let us remember the sentence the state knew in 2021, because we wrote it down for them in black and white: whoever knows a citizen’s birth number gets to their sensitive data.
And now the most important part. Everything so far was a prelude — individual systems, individual failures, individual years. What happened in August 2026 belongs to a different category. Nobody had to hack the state, nothing leaked anywhere, no attacker exerted any effort. The state published the data itself, voluntarily, on the basis of a statute it wrote for that purpose.
4. 2026: the state published the birth numbers itself. To everyone.
4.1 What happened
Since 17 August 2026 the new commercial register has been running under Act No. 29/2026 Coll. The portal Živé.sk was first to report that through the publicly available documents in the collection of deeds you can reach the birth numbers, full permanent residence addresses, handwritten signatures, specimen signatures and ID card numbers of natural persons.
No electronic ID card. No demonstration of legal interest. No fee. No record whatsoever of who downloaded what. The only obstacle is a four-character verification code you simply retype. Any current AI reads such a code instantly and essentially flawlessly — recognising four characters in an image is a task at which machines overtook humans years ago and which today a commodity multimodal model handles for a fraction of a cent. It is therefore a protection that stops humans, not machines. It inconveniences a person who wants to look at a few documents. It does not inconvenience a script that wants to download all of them.
No attacker, no vulnerability and not a single line of exploit code was needed for this data to get out — an amendment was enough. Until now, some documents had to be requested and arrived in your electronic mailbox after identity verification. Now they are out. For everyone at once.
4.2 It is not a portal bug. It is a bug in the statute.
This is the core of the matter and we have not seen it anywhere in the media coverage. Let us open the statute.
Section 6(1) — formal publicity:
“Registered data and documents stored in the collection of documents shall be made available to everyone without the need to demonstrate a legal interest. Registered data and documents stored in the collection of documents are published on the website of the specialised portal (…) free of charge.”
Section 100(2) — what is not published:
“The following shall not be published under paragraph 1: a) the birth number, b) the place of residence, c) another identifier of a foreign natural person (…), d) data on the ultimate beneficial owner, e) data on the seizure of an ownership interest.”
Section 107(1) — exemptions from disclosure:
“Where the registry court issues documents under Section 105(1)(a) and (b), the birth number (…) shall not be disclosed.”
So the legislator did protect the birth number and the place of residence. Twice, in two places, explicitly. And then wrote a third provision:
Section 100(3):
“A document shall be published without delay after being filed into the collection of documents in the manner under Section 6(1) (…) A document under the first sentence shall be published even if it contains data that is otherwise not published; rights under a special regulation are not affected.”
Read that sentence again. A document shall be published even if it contains data that is otherwise not published.
The protection of the birth number under Sections 100(2) and 107(1) applies to the register extract. For a document in the collection of deeds it is expressly cancelled. And because Section 34(1)(g) requires the collection to contain, among other things, a director’s specimen signature signed by hand in the presence of a notary, the state is not publishing only the birth number — it is publishing a certified sample of the same person’s signature.
This is not a bug. This is not a misconfigured portal. This is a deliberately drafted carve-out from the statute’s own protective clause, which passed through the entire legislative process, the inter-ministerial consultation, the government and parliament. Members of parliament approved a text that says “the birth number shall not be published” and, one subsection later, “and it shall be published even when it is not published”.
The difference between a bug and intent matters. A bug you fix with a patch. This can only be fixed by amending the statute.
Why the Data Protection Authority says the opposite — and why both are right
Here we have to be precise, because the supervisory authority is saying something different from us. The Authority says the statute does not permit publishing birth numbers and that the documents should have been anonymised. We say the statute expressly orders it in one provision. It looks like a contradiction. It is not.
Both statements are correct; they are simply about two different things:
- Section 100(2) is about registered data — the entry in the register itself. There the birth number genuinely must not appear, and the Authority is right.
- Section 100(3) is about documents filed in the collection. There everything is published, “even if it contains data that is otherwise not published” — and the Ministry is right when it says it publishes on the basis of the statute.
The result is that the same data point is protected by the statute in one place and ordered published in another. This is not a dispute about interpretation — it is a contradiction in the text itself. And that is precisely the defect: a norm under which two state bodies reach opposite conclusions about the same birth number is not strict or bold. It is badly drafted.
That is why both the minister and the supervisory authority can invoke the same statute — and why nobody will be held responsible. The statute dissolved that responsibility inside itself. A contradiction in the text is not a detail for lawyers; it is the reason the data leaked and the reason nobody is at fault so far.
And let us immediately add what does not follow from any of this. It does not follow that everything is fine. The finding “it complies with the law” is not a defence — it is a description of who is responsible. When data leaks because of a bug in code, the vendor failed. When it leaks because someone wrote it into a statute and parliament voted for it, the legislator failed. Legality here is an aggravating, not a mitigating circumstance.
That something was adopted through a proper legislative process says nothing about whether it is good. Legal philosophy learned that lesson expensively in the twentieth century, and Gustav Radbruch summed it up: a statute that reaches an intolerable conflict with justice loses its claim to obedience precisely because it is a statute. The next chapter is therefore about something other than what the sections say. It is about why they are badly written.
4.3 Why the statute is bad
This is not about style or clumsy wording. This provision fails every test an interference with privacy ought to pass.
1. The register serves its purpose without any of it. A commercial register exists for legal certainty in commerce — so that a third party knows who is entitled to act for a company and since when. That is exactly what Section 7 on material publicity says. For that purpose, a name, a role, the date the role began and at most a date of birth to distinguish namesakes are enough. The birth number, ID card number, home address and an image of a signature add nothing to legal certainty. A specimen signature moreover exists so that the registry court and a notary can verify the authenticity of a signature — not so that anyone on the internet can. Published to the whole world, it offers orders of magnitude more opportunities to forge a signature than to verify one. What is being published therefore does not serve the declared purpose — and that is the definition of a disproportionate interference, not a borderline case.
On the question of scope this is not merely our reading — it is exactly what the Data Protection Authority says:
“The public nature of the commercial register has its place; commerce needs verifiable data about companies and their representatives. The scope of published data must, however, correspond to what is necessary for that purpose, and the birth number at the very least does not belong among it.”
2. A cheaper and less invasive solution existed and the state did not choose it. The Data Protection Authority asked for the documents to be anonymised before publication. A birth number has a fixed ten-digit format with a known checksum condition — redacting it automatically is a single regular expression. A proportionality test works like this: if you can achieve the same aim by a milder means, the stricter one is impermissible. Here the milder means was technically trivial and expressly proposed by the supervisory authority — and it was not used.
3. The statute removed both brakes at once. Under Section 6(1), documents are made available without demonstrating a legal interest and free of charge. Previously there were two points of friction: you needed a reason and you had to pay. Both disappeared in the same subsection. The cost of downloading the entire database fell to zero. Even if publishing a single document were defensible, bulk and free access changes the nature of the processing — which is precisely why the Court of Justice ruled as it did in Schecke.
4. There is no record of who downloaded what. No authentication means no audit log. When the whole database shows up on a darknet market a year from now, it will be impossible to establish even when it was downloaded, let alone by whom. The system is designed so that abuse is unenforceable in principle.
5. The order of operations is reversed. In Slovak practice the birth number is used not merely as an identifier but as an authenticator — we set out where exactly below. What matters is what comes first: if the state decides the birth number is to be public, it must first decommission every system that treats it as a secret, and only then publish it. It did the opposite. And we had already demonstrated to the state, in 2021 on eHranica, exactly what happens when an attacker knows a birth number. Publishing an authentication factor before it stops being an authentication factor is not bold transparency — it is an operational error.
6. The damage is irreversible and the statute does not account for it. There is no deferred effect, no remedy mechanism, no way to retract what has already flowed out. A norm whose consequences cannot be undone must pass a considerably stricter test than one that can be corrected. This one passed none.
7. The affected person has no way to avoid it. Without an entry in the register you cannot run a limited company. There is no consent, no opt-out, no alternative. Telling people “if you want to do business, you must put up with it” is therefore not an argument about voluntariness — it is a description of coercion. And recall the side finding from the e-invoicing chapter: when the intelligence service asked for an exemption from the state’s own data collection, it got one. A rule whose own author exempts himself from it is an admission that it is harmful.
8. Nobody bears any consequences. The sanction for the ministry is a fine paid from public money by one state body to another. The official who drafted the subsection, the MP who voted for it and the minister who defends it risk nothing. The damage stays with the directors and shareholders, who never asked for it and cannot revoke it. Where the decision-maker faces no risk at all, there is also no reason to be careful.
4.4 What follows from it
The impact does not stop with the individuals concerned. It hits the entire business environment:
- The rational response of an entrepreneur is to leave. If registering in the Slovak register costs you your birth number, home address and specimen signature, and in neighbouring countries it does not, the economically correct answer is to incorporate elsewhere or use a nominee structure. The statute therefore damages precisely the environment the register is meant to serve.
- Slovakia has become a soft target. A verified, state-guaranteed, machine-readable list of economically active people together with their home addresses now exists. For a foreign intelligence service and for organised crime alike it is a ready-made basis for target selection — without a single attack, without a single exploit.
- The birth number has stopped working as a verification factor for the entire private sector. Every bank, insurer, telecom operator and e-shop that used it to verify identity now has a broken control and must rebuild it. The private sector bears the cost, the state made the decision, and the losses from the fraud that gets through in the meantime will be paid by companies and their clients.
- The victim’s bargaining position gets worse. In disputes over an unauthorised transfer or a forged signature, the other side will argue that the data was public and the injured party should have guarded it better. By publishing the data, the state shifted the burden of proof onto the person it took the data from.
- Trust in e-government as a whole declines. Every further state system — the digital euro, e-invoicing, the EUDI wallet — now starts with a history in which the state published its own citizens’ birth numbers and told them to put up with it. That is not a mood to be overcome with communication. It is a rational conclusion from evidence.
In short: the register was supposed to protect legal certainty in commerce. Instead it seriously endangered the privacy and security of every company director and shareholder in Slovakia, in a way an attacker need not earn and need not hide. That it has a basis in a statute the state passed for itself changes none of that — except that it is now clear who should be asked.
4.5 How it can be abused
Let us get concrete. What exactly does an attacker obtain, and what can they do with it?
The package for one person: full name, title, date of birth, birth number, permanent residence address, ID card number, certified specimen of a handwritten signature, ownership interest and its value, the history of changes in the company, financial statements. On the darknet in 2019, a far poorer bundle cost USD 45. Now it is free, legal, and comes with the state’s guarantee of authenticity.
1. Identity theft and company takeover. The combination of a certified specimen signature, a birth number and a document number is exactly what you need to produce a convincing forgery. Minutes of a general meeting, a share transfer agreement, a power of attorney — these are all documents where the authenticity of a signature is compared against the very specimen that is now public. The legislator was partly aware of this problem and tightened the requirements for notarial deeds for certain decisions, while publishing the specimen signatures.
2. The birth number as a key to the rest of your life. This is the point for which chapter 3 of this article matters. We demonstrated in practice to the state that whoever knows a birth number gets to a citizen’s health data. The birth number is at the same time a routine “verification” data point in the phone call centres of banks and insurers, at the Social Insurance Agency, at health insurers, at telecom operators and on dozens of state portals. It is a data point that Slovak practice treats as a secret, although it was never meant to be one. The state has just published it for every director and shareholder at once.
3. Social engineering with perfect cover. An attacker who, on a phone call, knows your birth number, ID card number, address and the exact structure of your company is indistinguishable from a legitimate caller. Add a voice deepfake — a technology that today needs thirty seconds of recording — and you have an attack that even a trained victim will not detect. This is not hypothetical; it is the standard scenario in payment fraud.
4. Physical safety. The collection contains the permanent residence address together with the value of the ownership interest. In other words: a list of people sorted by wealth, with their home addresses. For an entrepreneur holding cryptocurrency this is literally a target list for the so-called wrench attack — a robbery in which access to the wallet is extracted by force. For a journalist, an activist or a lawyer with their own company it is an instrument of intimidation.
5. Bulk download and correlation. The register has no protection against systematic scraping. Anyone — including foreign intelligence services, competitors or organised crime — can download the entire collection of deeds and join it with what is already circulating: the health-authority breach, the land registry, the register of public sector partners, exchange breaches. Large language models today handle data extraction from scanned documents at industrial scale for a few tens of euros. What five years ago was a project for a team of analysts is now a weekend script.
6. Competitive intelligence. Financial statements, ownership structure, historical changes and specimen signatures in one place — plus, from January 2027, e-invoicing with the name of every invoiced line item. The combination of these two data flows is the best industrial espionage tool the Slovak state has ever built.
7. A birth number cannot be changed. This is probably the most important thing about the whole case. You change a password. You block a card. You replace an ID card. Your birth number is for life. Even if the ministry switched the portal off tomorrow and amended the statute, the data downloaded in the meantime stays in circulation forever. This is an irreversible leak. It cannot be taken back; it can only be documented.
4.6 How the state responded
Justice Minister Boris Susko told entrepreneurs they must put up with it and that the data had been available before as well — through a personal visit to the registry court or European systems. Only the form of access supposedly changed.
That argument is technically wrong, and we have known it in security for decades. The difference between “available after a trip to the court and a fee” and “available to the entire internet for free and in bulk” is not formal. It is the difference between obscurity and exposure, between units of requests per year and millions. That difference is precisely why the Court of Justice of the EU annulled the blanket publication of agricultural subsidy recipients as disproportionate in C-92/09 Schecke — even though there too it was “only” data the state already held. And why in C-398/15 Manni, a case directly about a commercial register, it held that the public nature of the register is not unbounded and member states must be able to restrict access.
The Ministry of Justice relied on Article 6(1)(c) GDPR — processing necessary for compliance with a legal obligation. This is a circular argument in its purest form: it is legal because we wrote ourselves a law saying so. Yet Article 6(3) GDPR requires such a law to pursue an objective in the public interest and to be proportionate to the aim pursued. No answer was given to the question of what public interest requires that anyone on the other side of the world — or your competitor one street away — be able to download the birth number and specimen signature of a Slovak sole trader.
The Data Protection Authority has meanwhile opened proceedings against the ministry. Its position — that the statute does not permit publishing birth numbers and that documents should have been anonymised before publication — we analysed above: it holds for registered data, while Section 100(3) speaks about documents and orders the opposite. That is exactly why the ministry and the supervisory authority can both invoke the same statute.
The timing matters. The statute took effect on Monday 17 August. On Tuesday 18 August Živé.sk reported the scope of the published data and, by its own account, the Authority looked into the situation on Tuesday evening — that is, only once journalists approached it. It announced proceedings on Wednesday. A supervisory authority that learns the scope of published data from the newspapers the day after a statute takes effect clearly had no idea what was coming — even though the statute went through the entire legislative process, including the consultation procedure. And with an irreversible leak, starting to act only afterwards is by definition too late.
In short: the ministry says it is following the law. The supervisory authority says the law does not allow it. And the minister has said nothing will change. Until those two agree, the documents stay online — and every day this drags on is another day during which anyone can download them.
That is the whole difference between a dispute about interpretation and a dispute about data. A dispute about interpretation can be decided at any time — in a year, in three, when a court has its say. A dispute about data only makes sense while the data has not yet been copied. After that, any decision is merely an official record of something that already happened.
5. New evidence: the state never once measured the risk
So far we have argued from what the statutes say. Now we also have what they do not say — and we have it in black and white, signed.
On 4 August 2026 we filed a freedom-of-information request with the Slovak Ministry of Finance under Act No. 211/2000 Coll. We asked three questions about Act No. 385/2025 Coll. on e-invoicing. On 18 August 2026 the reply No. INF/000270/2026-11 arrived, signed by the director of the minister’s office.
The questions and answers were these:
- Was a data protection impact assessment (DPIA) under Article 35 GDPR carried out?
Answer: “no data protection impact assessment (DPIA) under Article 35 of Regulation (EU) 2016/679 (GDPR) was carried out, including the assessment under Article 35(10) GDPR as part of the adoption of the legal basis. No implementing measures were adopted.” - Did the ministry consult the draft with the Slovak Data Protection Authority beyond the consultation procedure?
Answer: “the Ministry of Finance did not consult the draft with the Data Protection Authority of the Slovak Republic.” - Was a proportionality test of the interference with the right to data protection under Articles 6(3) and 23(2) GDPR performed — in particular with regard to the scope of reported data under Section 85o(9) and (10), i.e. the customer’s name and the type of goods and services?
Answer: “a proportionality test of the interference with the right to the protection of personal data (…) was not performed.”
Three questions, three answers, one conclusion: none of it was done.
Let us recall what system we are talking about. From 1 January 2027, every invoice of every Slovak company must flow through it — the customer’s name, the type of goods, the amount, the time. Half a million entities. Dozens of private intermediaries with no statutory duty of confidentiality. Data reaching the Financial Administration in near real time, with no statutory retention period and with automated accesses that are not even logged in the taxpayer’s file.
And through the entire legislative process, nobody at the ministry ever sat down and worked out what risk this poses for companies and their clients. No analysis. No consultation with the supervisory authority. No test of whether the state needs to know what you sold to whom in the first place.
Yet Article 35(10) GDPR exists precisely for this situation: where processing has a legal basis in law, the impact assessment is to be carried out as part of adopting that law. Not afterwards. And Article 6(3) requires such a law to be proportionate to the aim pursued — which nobody can establish without a proportionality test, because a proportionality test is the way you establish it.
This is not an oversight by one official. This is a systemic stance: when building a state surveillance system, the privacy of citizens and companies is not treated as a quantity worth measuring at all. We saw the same stance with the online cash register system, which began sending the Financial Administration GPS coordinates and the names of items from citizens’ purchases without any public impact analysis. The same with the commercial register, where the ministry published documents without anonymisation despite the supervisory authority regarding anonymisation as mandatory — and nowhere documented that it had assessed the impact on data subjects in advance. The same with e-invoicing, where nobody asked the Authority even once.
And now the best part. In the consultation procedure on that same act, the Slovak Bar Association asked for protection of client identities — rejected. The intelligence service asked that data about its own purchases not be sent into the system, because in its view the system is an “disproportionate security risk” — approved.
So the state understands the risk perfectly. It can name it in its own words and it knows how to protect itself from it. It simply did not consider it necessary to work out what it will do to you.
6. And that is only one brick: the regulatory perimeter 2025–2029
The commercial register and e-invoicing are not isolated incidents. They are two bricks in a wall that, between 2025 and 2029, is closing around money, communication and access to information itself. An overview of this regulatory perimeter forms the basis of my talk Technologies of Freedom 2026:
- Age Control (2025–2026). The UK Online Safety Act and the related EU rules condition access to content on age verification. The EU age verification app is to be deployed by the end of 2026 and connected to the EUDI Wallet. The marketing talks about zero-knowledge proofs. The reality, as EDRi points out, is the normalisation of needing a state-issued identity to access the internet.
- Chat Control. The temporary derogation allowing blanket scanning of private messages passed on 9 July 2026 — despite a majority of voting MEPs being against it (314 to 276), which merely fell short of the 361-vote absolute majority required. It applies until 2028. The permanent CSA Regulation is still being negotiated. Remember that mechanism: surveillance did not pass because someone wanted it, but because a majority was not enough to stop it.
- The digital euro. The ECB pilot starts in the second half of 2027 with 36 payment service providers; first issuance no earlier than 2029. Slovakia is in the first phase. The ECB has tested holding scenarios up to EUR 3,000 per person. Officially it is not to be programmable. Technically it is — and a holding limit reviewable every two years is programmability in plain sight.
- AMLR (effective 10 July 2027). A EUR 10,000 cap on cash payments, mandatory identification from EUR 3,000, and a ban on privacy coins and anonymous accounts on regulated platforms. The right to pay anonymously in the EU is ending by statute, not by technology.
- DAC-8. Automatic reporting of crypto balances to tax authorities. In force since 2026.
- Mandatory SIM card registration. Under Act No. 452/2021 Coll. you cannot activate even a prepaid card in Slovakia without an ID card or passport. The operator — and indirectly the state — therefore knows who calls whom and from where, because a phone’s location can be determined by triangulation even without GPS. Both the GSMA study and Privacy International’s overview conclude that no link between SIM registration and crime clearance rates has been demonstrated. In the Czech Republic you can still buy an anonymous SIM today and it works in Slovakia too — so the measure stops nobody except the ordinary citizen.
- eKasa (online cash registers). The Slovak implementation sends the Financial Administration the GPS coordinates of the register and every purchased item including its description — that is, exactly what you bought, when and where. In the Czech Republic only aggregate data was sent. Meanwhile the “Verify receipt” app returns the entire contents of a purchase to anyone who knows the receipt ID. We analysed it in e-Kasa — another small step towards a great financial dictatorship in Slovakia (in Slovak). And when we looked at its security, we emulated the protected data module, because communication with it was not encrypted. The citizen is tracked down to the last item; the fraudster has a free hand.
- e-Invoicing. From 1 January 2027 every invoice between Slovak companies must travel as structured XML through a certified private company, and the Financial Administration receives the name of every invoiced line item and the customer’s name in near real time. It affects 530,726 entities. Act No. 385/2025 Coll. contains not a single mention of personal data protection — the only occurrence of the string “personal” is “personal motor vehicle”. The “digital postmen” have no statutory duty of confidentiality and no retention limit. How the bar association fared in that same consultation procedure and how the intelligence service fared, and what the Ministry of Finance confirmed to us in writing, is in the previous chapter. Details in Against e-invoicing: Corporate Stockholm Syndrome and e-Invoicing vs. GDPR and Professional Secrecy.
- The central register of bank accounts (Act No. 123/2022 Coll.) gives the police, the Financial Administration, the intelligence service and military intelligence an overview of where you hold accounts. Banking secrecy as it was once taught in economics has ceased to exist.
- Internet censorship. The Financial Administration has for years maintained a list of prohibited websites that every internet provider must block, and the list keeps growing. Technically it is a DNS blacklist — infrastructure to which a new entry is added with a single line.
7. We described this back in 2019
Together with Juraj Bednár we warned about this pattern in a series of articles titled How Slovakia is preparing to introduce a Chinese-style dictatorship. The first part came out in November 2019 and already described internet censorship, online cash registers, tracking and blocking of financial flows, location tracking via mobile phones, the ban on anonymous SIM and payment cards, and cash restrictions:
- Part I — the technological pillars of a digital dictatorship (November 2019)
- Part II — how the pandemic strengthened state authoritarianism (April 2020)
- Part III — the EU Council’s attack on encryption (November 2020)
- Part IV — the arrival of the Ministry of Truth and the expansion of censorship (November 2020)
I presented the same topic at the ITAPA conference. After almost seven years, the key sentence from part one reads like this:
“By connecting these technologies, if the ‘wrong’ party wins a democratic election, it is possible not only to introduce a Chinese-style dictatorship within a few months — such a government will already have the historical data collected and can start using it immediately.”
This is the most important lens on the whole article. The question is never “do I trust this government?”. The question is: what happens to this database two election cycles from now? A database that today serves business transparency is tomorrow a list. A list cannot be un-collected.
8. The paradox: the author of the GDPR is the biggest privacy violator
Let us sum up what we have just been through.
The European Union wrote the GDPR — the most ambitious data protection regulation in the world. It forced every e-shop, blog and civic association to deal with consents, records of processing activities, impact assessments and data protection officers. Fines for non-compliance reach 4 % of global turnover.
That same European Union, in the same period, introduced blanket scanning of private messages, preparations for a central digital currency with holding limits, mandatory age verification for access to content, a ban on anonymous means of payment, and automatic reporting of financial balances.
And that same Slovak state, which fines companies for an inadequately secured mailing list, has just published the birth numbers, addresses and specimen signatures of its own citizens — and its minister needed only one sentence: they must put up with it.
The GDPR is not protection of the citizen against the state. The GDPR is a regulation by which the state regulates the private sector and exempts itself from surveillance — through carve-outs for tax, statistical and security purposes. That is why we were writing about why we are losing privacy despite the GDPR already in 2021. Nothing has changed since; only the volume of data has grown.
The paradox is not a coincidence, nor the hypocrisy of individuals. It is a structural property: the entity that writes the rules of privacy protection is at the same time the largest collector of data, and it is the only one that can exempt itself from its own rules by statute. Expecting it to protect your privacy is like expecting a player to referee his own match.
9. What to do: do not rely on the state
If we have learned one thing in almost twenty years in this industry, it is this: privacy that depends on the goodwill of the state is not privacy. It is a temporary permission. It is revoked by amendment.
The only privacy that lasts is the kind that depends on nobody’s permission — mathematical, decentralised, without an intermediary who can be forced to report or be switched off. That is exactly what my talk Technologies of Freedom 2026, given at Lunarpunk in Bratislava, is about. Its thesis is simple:
Regulation is a perimeter. Freedom is designed outside it. Disruptive technologies do not fight the perimeter — they are built so that they fall outside it. Non-custodial, decentralised, without an intermediary, self-hosted, open-weight. There is nobody to license, nobody to compel to report, nobody to shut down.
If you are a company director or shareholder: what to do this week
This is triage for those personally affected. The strategy follows right after it.
- Find out what is out there about you. On the new commercial register portal, look up your own company and go through the documents you have ever filed into the collection. Until you know what exactly is published — whether just the birth number, or also the document number and the specimen signature — you do not know what you are dealing with.
- Withdraw your trust from the birth number — and tell those who use it. The birth number can no longer be a verification data point. Contact your bank, your health and commercial insurers, your telecom operator, your accountant and everyone else who verifies your identity with it over the phone or by email, and ask them to replace it with a different authentication factor — an account password, a callback to a verified number, confirmation in an app. If someone tells you “but nobody else knows your birth number”, send them this article.
- File a complaint with the Data Protection Authority. The instrument is a petition to initiate proceedings on personal data protection, for which the Authority also publishes a template form. Proceedings against the ministry are already running, but a complaint from a data subject carries different weight than media criticism — it is the exercise of your right and it widens the file.
- Distinguish your company’s registered seat from your own residence. These are two different data points and each is handled differently. The registered seat you can change to a virtual address practically at any time, and it is the cheapest measure available here — if you currently run your business from your home address, that is the first thing to change. A director’s residence is required by the register and cannot be removed by filing; changing your permanent residence is a serious step with tax and mail-delivery consequences, and it is not something to do because of one article — but if you were considering it anyway, you now have one more reason.
- Expect to be contacted. A fraudster who knows your birth number, address and company structure sounds credible. Agree with your accountant, your bank and the colleagues who approve payments on a verification procedure outside phone and email — and agree on it now, not when the first “urgent” transfer request arrives.
That was the triage. Now the more substantial part — tools that stop tying your privacy to whatever the state has just decided. Ordered by how much they return for the effort invested:
Money
- Privacy coins — Monero, Zcash, and atomic swaps between them and Bitcoin. The AMLR will ban them on regulated platforms from July 2027. That is precisely why it is worth knowing how to use them outside those platforms.
- Non-KYC tools — non-custodial P2P markets such as Peer.xyz (fiat ↔ crypto via Revolut, Wise or PayPal with a zkTLS proof, no exchange), Bitblik (bitcoin to cash from an ATM), RoboSats, Bisq, Vexl. No KYC means no honeypot that can leak.
- Your own payment gateway — CashuPayServer runs on the cheapest PHP hosting and makes you your own unregulated intermediary. Chaumian e-cash with blind signatures means not even the mint knows who is paying.
- Self-custody stablecoins and cash instead of the digital euro. Cash is the only means of payment that sends nothing anywhere.
Communication
- Signal (the successor to Whisper Systems) as the minimum for ordinary communication, SimpleX where even the metadata trail of a phone number bothers you. End-to-end encryption is the one thing Chat Control has not managed to break — which is exactly why the EU keeps pushing against it.
- Nostr as a communication and publishing layer with no central operator; Meshtastic and Reticulum where you do not want to depend even on a telecom operator.
- GrapheneOS instead of stock Android; Tor and a VPN as basic hygiene. A VPN is incidentally also the simplest answer to Age Control.
- Local LLMs and open-weight models instead of cloud ones. What you ask a model is more sensitive than your browser history.
Doing business
And now the uncomfortable conclusion for Slovak entrepreneurs, which after 17 August 2026 there is no point in avoiding:
Doing business in Slovakia is a security risk to the entrepreneur’s privacy. Not metaphorically. Literally. By registering in the Slovak commercial register you today hand over your birth number, home address, document number and certified specimen signature into a publicly and freely downloadable database — and you get nothing in return that you would not get elsewhere without it.
- Foreign jurisdictions with a higher degree of privacy. There are countries where the register contains neither birth numbers nor specimen signatures and where access to documents is conditional on a demonstrated legal interest. The difference in protection is an order of magnitude.
- Nominee directors and nominee shareholders. If a nominee is listed in the public register, then a hacked, leaked or accidentally state-published commercial register cannot endanger your privacy, because your data was never in it. This is not an escape from accountability — tax and AML obligations continue to apply and the beneficial owner is known to those who need to know. It is the separation of the duty to be identified to the authorities from the duty to be identified to the entire internet. That is precisely the line the Slovak legislator has just erased.
- Avoid state surveillance technologies wherever you can. The digital euro is not compulsory — cash and self-custody are still legal. A business model that needs neither online cash registers nor e-invoicing is today a competitive advantage in data protection, not an eccentricity.
- Do not work for the state. At Nethemba we have maintained the “We do not work for the state” initiative for years. The systems described above were built by someone. They were built by companies that decided the contract mattered more than what that contract does to people.
Above all: disruptive technologies
Petitions, consultation procedures and constitutional complaints have their place and should be pursued. But judge their success rate over the past decade for yourself: the online cash register system is deployed, e-invoicing is coming, Chat Control passed against a majority, the register is out, and the minister says you must put up with it.
What does work reliably is technology that makes regulation moot. Encryption cannot be banned — that was proven in the 1990s, when the USA classified the export of cryptography as the export of weapons and PGP reached Europe printed in a book, scanned and recompiled. A non-custodial exchange with no operator has no licence to revoke. A peer-to-peer payment with no intermediary has nobody to compel to report. An open-weight model running on your laptop has nobody to switch off.
This is not an escape from reality. It is the only strategy that has empirically worked for the past thirty years.
Conclusion
In 2015 we wrote that the greatest threat to citizens’ privacy in Slovakia was the intelligence service. That was true — but nowhere near the whole truth.
An intelligence service at least needs a court order and tries not to be seen. In August 2026 the Ministry of Justice needed nothing — it published the birth numbers, addresses and specimen signatures of company directors and shareholders on the basis of a statute it had prepared for that purpose, with a legal basis borrowed from the GDPR, and when criticism came, it told those affected that if they want to do business, they must put up with it.
In 2021 we proved to the state that whoever knows a birth number gets to a citizen’s health data. The state responded by reporting us to the police. Five years later it published those birth numbers itself.
And when we asked the Ministry of Finance whether anyone had assessed the privacy impact of the system through which every invoice of every Slovak company is to flow from 2027, it answered in writing and without embarrassment: not carried out, did not consult, not performed. This is not negligence at one authority. It is a finding about the weight given to citizens’ privacy when state infrastructure is built — none, unless it is the privacy of the intelligence service.
The greatest threat to your privacy is not a hacker. It is an institution that writes the rules of privacy protection, exempts itself from them by statute, and bears no personal consequences for breaking them.
That is why the state cannot be relied on in matters of privacy — not even the one with the best regulation in the world. We have to build privacy ourselves: from cryptography, from decentralised protocols, from non-KYC tools, from jurisdictions that do not publish birth numbers, and from technologies that have no intermediary anyone can lean on.
If you are a company director or shareholder, start with what can be done this week: look up what is out there about you in the register, and tell your bank, your insurer and your operator that the birth number is no longer a verification data point. The rest is a long game — but that first step needs nothing beyond an hour of your time.
Because you cannot change your birth number. A government you can — but the database it leaves behind will still be there.


