> Slovenia's Reporting Persons Protection Act (ZZPri): the 50-worker rule, the 10-worker sectoral rule, the zaupnik, the 1 March return to the KPK, the fine bands, and the official Slovenian sources.

Source: https://ethicsportal.eu/it/whistleblower-laws/slovenia/
Updated: 2026-09-22

---

# Whistleblower law in Slovenia

Slovenia implemented Directive (EU) 2019/1937 through the **Zakon o zaščiti prijaviteljev (ZZPri)**, Uradni list RS no. 16/23, in force since **22 February 2023**. Slovenia gives a visible role to the **Commission for the Prevention of Corruption (KPK)** for protection and reporting oversight.

Two features make Slovenia unusual. The person who receives internal reports — the *zaupnik* — must be appointed from among the employer's own employees. And every obliged employer files an annual return to the KPK by 1 March.

## Applicable law

- [ZZPri — official text in Uradni list RS no. 16/23](https://www.uradni-list.si/glasilo-uradni-list-rs/vsebina/2023-01-0301/zakon-o-zasciti-prijaviteljev-zzpri)
- [KPK — protection of reporting persons](https://www.kpk-rs.si/en/commissions-activities/protection-of-reporting-persons)

## Who must establish an internal channel

Article 9(2) ZZPri: public and private sector entities with **50 or more employees**.

Article 9(3) lowers the threshold to **10 employees** for entities whose principal registered activity is healthcare, or the collection, treatment and distribution of water, sewerage, or waste collection and management. This is a lower threshold, not an exemption from headcount — the Directive's own Article 8(4) carve-out for regulated financial and AML entities applies separately and does remove the headcount test for those entities.

Article 9(4) covers listed public sector bodies regardless of size.

## The zaupnik

The employer appoints a *zaupnik* (confidential officer) **from among its employees**. The role cannot be outsourced, which is the first structural question for any organization procuring a reporting channel here: the software is the system of record and the audit trail, but the statutory recipient is an internal person.

The zaupnik runs a **7-day preliminary admissibility test** on each report — whether the reporter qualifies, whether the matter is a breach within scope, whether it is manifestly unfounded, and whether the breach is ongoing or ended less than two years ago. Substantive feedback follows within **three months**.

## Annual return to the KPK

Article 9(16): by **1 March** each year, for the preceding year, every obliged employer reports to the KPK via an electronic form — the number of reports received, how many were anonymous, how many were well-founded, the number of retaliation cases handled, and the identity of the zaupnik.

This is a recurring dated obligation most EU transpositions do not impose, and it is the practical reason a mailbox is not enough: the figures have to be countable at year end.

## Retention

Article 7(4): unless another act provides otherwise, data in the register of reports is retained for **five years after the end of the procedure**.

## Penalties

Fine bands turn on the size of the offender as well as the offence.

| Offence | Medium/large companies | Other legal entities | Sole traders | Responsible person |
|---|---|---|---|---|
| No internal channel; channel not described in the internal act; missed 1 March return | €3,000–6,000 | €2,000–4,000 | €1,000–2,000 | €300–2,000 |
| Trying to establish the reporter's identity; threatening or attempting retaliation | €3,000–6,000 | €2,000–4,000 | €1,000–2,000 | €300–2,000 |
| Carrying out a retaliatory measure | €10,000–60,000 | €5,000–20,000 | €3,000–15,000 | €500–2,500 |

Disclosing the identity of a reporter, facilitator or connected person is fined **€300–2,500**. A reporter who deliberately reports or publicly discloses information they know to be untrue is fined **€400–1,200**; that offence is prosecuted by the external reporting authority that handled the report, not the KPK.

## External reporting authority

ZZPri designates around two dozen sectoral external reporting authorities. The [Commission for the Prevention of Corruption (KPK)](https://www.kpk-rs.si/en/commissions-activities/protection-of-reporting-persons) is the catch-all where no specialised regulator has jurisdiction, and it is the body that issues the certificate of eligibility for protection.

## Data protection authority

For GDPR complaints about whistleblower data handling, the relevant authority is the [Information Commissioner of the Republic of Slovenia](https://www.ip-rs.si/en/) and its [complaint filing page](https://www.ip-rs.si/varstvo-osebnih-podatkov/pravice-posameznika/vlo%C5%BEitev-prijave).

## Support measures beyond the Directive

- **Free legal aid** in court proceedings, granted regardless of the applicant's means, once the reporter shows they filed a report before the retaliatory measure or holds a KPK certificate of eligibility.
- **Unemployment benefit** where the employer terminated the contract and the reporter is pursuing judicial protection.
- **State-funded psychological support**, which the KPK can arrange through the public mental-health network.
- **Reversed burden of proof** and exemption from court fees in retaliation proceedings.

## Official sources

- [ZZPri — official law text, Uradni list RS no. 16/23](https://www.uradni-list.si/glasilo-uradni-list-rs/vsebina/2023-01-0301/zakon-o-zasciti-prijaviteljev-zzpri)
- [KPK — official guidance on ZZPri, including the fine bands (PDF)](https://www.kpk-rs.si/storage/uploads/cd75a022-7e97-4497-85e0-fff75c493673/ZZPri.pdf)
- [KPK — protection of reporting persons](https://www.kpk-rs.si/en/commissions-activities/protection-of-reporting-persons)
- [KPK — reporting on whistleblowing](https://www.kpk-rs.si/en/kpk-applications/reporting-on-whistleblowing)
- [Information Commissioner of the Republic of Slovenia](https://www.ip-rs.si/en/)
- [Information Commissioner — complaint filing](https://www.ip-rs.si/varstvo-osebnih-podatkov/pravice-posameznika/vlo%C5%BEitev-prijave)

---

[Deploy your reporting channel →](/pricing/)
