Inspection Plan for 2026

I. Schengen and European information systems and agencies

The first part of the inspection plan is aimed at identifying the state of processing of personal data in information systems, which are used to ensure the practical implementation of the Schengen acquis on the territory of the Slovak Republic and in the premises of representative offices of the Slovak Republic, as well as in other European systems and agencies. Inspections mainly consist of ongoing, continuous monitoring of the ability of state administration bodies to ensure safe and legal processing of personal data in specific information systems used primarily for the internal protection of the Schengen area (e.g. N.SIS).

Ministry of Foreign and European Affairs of the Slovak Republic

1. National part of the Visa Information System

Processing activities of the consular section of the selected representative office of the Slovak Republic in the national section of the Visa Information System (N.VIS) and processing activities of the visa center- an external service provider for the Ministry of Foreign and European Affairs of the Slovak Republic- related to the issuance of Schengen visas pursuant to Regulation (EC) No 767/2008 of the European Parliament and of the Council of July 9, 2008 concerning the Visa Information System (VIS) and the exchange of data between Member States on short-stay visas (VIS regulation), as well as pursuant to Regulation (EC) No 810/2009 of the European Parliament and of the Council  of 13 July 2009 establishing a Community Code on Visas (Visa Code). Compliance of the processing of data subject´s personal data with the principles of personal data processing and the conditions of lawful processing with an emphasis on the rights of the data subjects and the security of personal data.

Ministry of Interior of the Slovak Republic

2. National part of the Schengen Information System

2.1. Processing activities at a selected border crossing point in the national section of the Schengen Information System (N.SIS) as part of the performance and of the duties of the Police Force of the Slovak Republic for the purposes of Regulation (EU) 2018/1861 of the European Parliament and the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System in the field of border checks, and amending the Convention implementing the Schengen Agreement, and amending and repealing Regulation (EC) No 1987/2006, as well as pursuant to Regulation (EU) 2018/1862 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of police cooperation and judicial cooperation in criminal matters, amending and repealing Council Decision 2007/533/JHA, and repealing Regulation (EC) No 1986/2006 of the European Parliament and of the Council and Commission Decision 2010/261/EU. The inspection will also cover data processing activities of a selected border crossing point in the national section of the Visa Information System (N VIS) as part of the Slovak Republic Police Force’s performance of its duties for the purposes set forth in Regulation (EC) No. 767/2008 of the European Parliament and of the Council of July 9, 2008, concerning the Visa Information System (VIS) and the exchange of data between Member States on short-stay visas (VIS Regulation), pursuant to Council Decision 2008/633/JHA of June 23, 2008, on making the Visa Information System (VIS) available for consultation by designated authorities of the Member States and Europol for the purpose of prevention, detection and investigation of terrorist offenses and other serious criminal offences, as well as Regulation (EC) No 810/2009 of the European Parliament and of the Council of 13 July 2009 establishing a Community Code on Visas (Visa Code). Compliance of the processing of the data subjects´ personal data with the principles of personal data processing and the conditions for lawful processing, with an emphasis on the rights of data subjects and the securtiy of personal data.

2.2 Processing activities carried out by the selected unit of the Police Force of the Slovak Republic in the national component of the Schengen Information System (N.SIS) in the performance of the tasks of the Police Force of the Slovak Republic for the purposes of Regulation (EU) 2018/1861 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of border checks, amending the Convention implementing the Schengen Agreement and amending and repealing Regulation (EC) No 1987/2006, as well as Regulation (EU) 2018/1862 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of police cooperation and judicial cooperation in criminal matters, amending and repealing Council Decision 2007/533/JHA and repealing Regulation (EC) No 1986/2006 of the European Parliament and of the Council and Commission Decision 2010/261/EU. Compliance of the processing of personal data of data subjects with the principles governing the processing of personal data and the conditions for lawful processing, with particular emphasis on the rights of data subjects and the security of personal data.

3. Automated European fingerprint identification system (Eurodac)

Processing activities carried out by the national access point of the Eurodac information system pursuant to Regulation (EU) 2024/1358 of the European Parliament and of the Council of 14 May 2024 on the establishment of Eurodac for the comparison of biometric data in order to effectively apply Regulations (EU) 2024/1351 and (EU) 2024/1350 of the European Parliament and of the Council and Council Directive 2001/55/EC and to identify illegally staying third-country nationals and stateless persons, on requests by the law enforcement authorities of the Member States and Europol for comparison with Eurodac data for law enforcement purposes, amending Regulations (EU) 2018/1240 and (EU) 2019/818 of the European Parliament and of the Council and repealing Regulation (EU) No 603/2013 of the European Parliament and of the Council. Compliance of the processing of personal data of data subjects with the principles governing the processing of personal data and the conditions for lawful processing, with particular emphasis on the rights of data subjects and the security of personal data.

4. National Passenger Information Center

Processing activities carried out by the National Passenger Information Unit established as part of the transposition of Directive (EU) 2016/681 of the European Parliament and of the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime. Compliance of the processing of personal data of data subjects with the principles governing the processing of personal data and the conditions for lawful processing, with particular emphasis on the rights of data subjects and the security of personal data.

Processing activities

The second part of the inspection plan, focusing on compliance of the processing of personal data with the requirements of the General Data Protection Regulation, reflects the risks associated with specific processing activities or the use of new technologies and procedures, in particular processes that may significantly interfere with the rights and legally protected interests of a significant number of data subjects.

 

5. Processing of personal data by gambling operators.

6. Processing of personal data in connection with the conclusion and/or performance of distance contracts.

7. Processing of biometric personal data in the context of employment relationships.

8. Collection and further processing of personal data for statistical purposes.

9. Processing of personal data where the controller has engaged a processor in the processing activities.

The inspections referred to in points 5 to 9 will focus on the compliance of the processing of personal data of data subjects with the requirements of the General Data Protection Regulation.