Information on the Processing of Personal Data by the Human Rights Ombudsman of the Republic of Slovenia
This document provides information to individuals on the processing of personal data by the Human Rights Ombudsman of the Republic of Slovenia in accordance with the General Data Protection Regulation (GDPR).
1. Identity and Contact Details of the Controller
Name: Human Rights Ombudsman of the Republic of Slovenia (hereinafter: the Ombudsman)
Address: Dunajska cesta 56, 1000 Ljubljana, Slovenia
Telephone: +386 1 475 00 50
Email: info@varuh-rs.si
2. Contact Details of the Data Protection Officer (DPO)
Name: Andreja Mrak, Institute for Organisational Solutions
Email: dpo@varuh-rs.si
3. Purposes and Legal Bases for Processing Personal Data
Personal data means any information relating to an identified or identifiable natural person (hereinafter: the individual). All personal data are collected, processed, or otherwise used in accordance with the GDPR, primarily for the performance of our public duties and the handling of your requests, based on one of the legal bases listed below.
3.1 Processing Based on Consent
Where processing is based on your consent, the legal basis is Article 6(1)(a) of the GDPR, e.g., when you subscribe to our e-newsletter or consent to the use of analytical cookies.
3.1.1 E-newsletter
Upon subscribing to our e-newsletter, we will regularly inform you via email about current updates. Your email address is used solely for this purpose.
You may withdraw your consent at any time by clicking the unsubscribe link at the bottom of each e-newsletter. Due to technical reasons, unsubscription may take several hours to process.
3.1.2 Cookies
Cookies are small text files stored on your device by websites you visit. When visiting www.varuh-rs.si, only strictly necessary cookies are installed. Non-essential cookies are activated only with your explicit consent (“Accept all”).
With your consent, cookies may also store your preferred settings (e.g., language, font size), so you do not have to reset them on each visit.
You can revoke your consent by adjusting your browser or device settings to disable or delete cookies.
| Type | Name | Provider | Country | Duration | Purpose |
|---|---|---|---|---|---|
| Necessary | PHPSESSID | Ombudsman RS | EU | Session | Used to identify the user’s session. |
| Analytical | _ga | Google Inc. | USA* | 2 years | Used to distinguish users. |
| Analytical | ga | Google Inc. | USA* | 2 years | Used to maintain session state. |
* Commission Implementing Decision (EU) C(2023) 4747 of 10 July 2023
3.2 Processing Necessary for the Performance of a Contract
Legal basis: Article 6(1)(b) GDPR – for employment or cooperation contracts, and pre-contractual steps (e.g., job applications, tenders).
3.2.1 Employment Contract
We process data obtained directly from you during recruitment, employment, or upon termination, solely as required for fulfilling employment rights and obligations.
Data retention complies with applicable legislation (e.g., accounting and archival rules).
3.2.2 Cooperation Contract
We process data obtained during public tenders and cooperation agreements for the purpose of contractual performance. Data are retained per statutory deadlines.
3.3 Processing Necessary for Compliance with a Legal Obligation
Legal basis: Article 6(1)(c) GDPR – for providing data to competent institutions (e.g., ZZZS, ZPIZ, FURS, banks) as required by law.
3.4 Processing Necessary for the Performance of a Task Carried Out in the Public Interest or Exercise of Official Authority
Legal basis: Article 6(1)(e) GDPR – e.g., when you contact us by phone, email, or via forms on our website, for security monitoring, or for reporting misconduct under the Whistleblower Protection Act.
3.4.1 Contact and Reporting Violations
We process your data only to the extent necessary to handle your inquiry or report. Without your data, we cannot process your request.
3.4.2 Video Surveillance
Video surveillance is conducted to ensure safety and prevent damage. Recordings are kept for 30 days or until legal proceedings are completed.
3.4.3 Reporting Misconduct
The Ombudsman processes personal data in accordance with the Whistleblower Protection Act. Data are retained for five years after the conclusion of the procedure, unless otherwise provided by law.
3.5 Processing Necessary for Legitimate Interests
Legal basis: Article 6(1)(f) GDPR – The Ombudsman does not process personal data on this legal basis.
4. Statutory or Contractual Obligation to Provide Data
Providing personal data is:
-
a contractual obligation under Article 6(1)(b) GDPR, or
-
a statutory obligation under Article 6(1)(c) GDPR.
If you do not provide the required data, we cannot conclude or perform the relevant contract or fulfill legal obligations.
5. Recipients of Personal Data
The Ombudsman does not share personal data with third parties unless required by law. Data are processed only by authorised staff or external service providers (e.g., IT hosting, analytics, public authorities) under confidentiality obligations.
More details are available at info@varuh-rs.si.
6. Transfer to Third Countries or International Organisations
Data are not transferred to international organisations. Transfers to the USA occur only with your consent for analytical cookies and are governed by the EU-U.S. Data Privacy Framework (Commission Decision C(2023) 4747).
7. Automated Decision-Making or Profiling
None is carried out.
8. Data Retention Period
Data are retained only as long as necessary for their processing purpose or as required by law.
-
Consent-based data: until withdrawal of consent.
-
Video recordings: 30 days or until the end of legal proceedings.
-
Other data: in accordance with statutory retention periods.
9. Rights of Data Subjects
You have the right to:
-
access your data,
-
request rectification or erasure,
-
restrict processing,
-
data portability, and
-
lodge a complaint with the Information Commissioner of Slovenia.
Requests are handled per GDPR. Contact: info@varuh-rs.si.
10. Consent and Withdrawal
If processing is based on consent (Article 6(1)(a) GDPR), you may withdraw it at any time without affecting prior lawful processing.
11. Right to Lodge a Complaint
You may file a complaint with the Information Commissioner:
Dunajska cesta 22, 1000 Ljubljana
Tel: +386 1 230 97 30
Email: gp.ip@ip-rs.si
12. Additional Questions
For questions or requests related to personal data protection, contact:
dpo@varuh-rs.si or info@varuh-rs.si