
Advokáti Chlipala s.r.o.
INPLP member firm · Bratislava, Slovakia
The BCH Advokáti Chlipala | Law Firm has been providing legal services for its clients since 2003. During this time, we have provided comprehensive legal consultancy work for a number of flagship projects. We provide legal services to leading companies in various sectors of the economy. As Slovak lawyers we possess knowledge regarding our clients’ needs combined with a deep insight into the Slovak legal environment. Svatoplukova 30, 821 08 Bratislava, Slovakia Tel: +421.2.3301.4760 Mobil: +421.948.553.160 Email: office@bch.sk Web: www.bch.sk Miroslav has over 16 years of experience focusing on IP & IT law, software law, cybersecurity law, privacy and personal data protection, innovations and modern technologies. The law firm under its leadership has been repeatedly awarded the Slovak Leading Law Firm - the highly recommended law firm in Intellectual property and Telecommunication & IT Law. Apart from practicing advocacy, he addresses the theoretical and professional aspects of IP/IT law and their impact on the business sphere. He is actively participating in expert conferences and conducting workshops and seminars where he lectures on topical IT issues with an emphasis on the logical link between law & tech. He repeatedly speaks at prestigious conferences and events organised by the Slovak Bar Association, Forbes, Eset, Digital Academy by PwC etc. He participates as Chairman of the Program Committee at the most important Slovak expert conference on IT law. Miroslav has worked as a lecturer at the Faculty of Law of the Comenius University in Bratislava. He is co-founder of the legal studies at the Slovak University of Technology in Bratislava. He is an active author of many articles and several publications on IP/IT law. He has passed several international stays and internships (Hague Academy of International Law, University of Oslo, University of Ljubljana, Jagiellonian University in Kraków).
Representatives

Miroslav Chlipala
partner
Contact
Publications
- GDPR knows no exceptions: Neither cities nor giants are safe!The Office for Personal Data Protection of the Slovak Republic recently ruled in two cases that clearly show neither cities nor large companies are immune to the strict rules of the GDPR. From attendance records in public administration to handling customer requests, even seemingly routine procedures can reveal serious personal data protection violations.11 December 2025
- Unauthorized Processing of Personal Data in Connection with a Traffic AccidentThe Slovak Office for Personal Data Protection (hereinafter referred to as the “Office”) recently imposed a fine of EUR 7,500 on Company CC for repeated and serious violations of data protection rules under the GDPR. Company CC, which focuses on compensating traffic accident participants, unlawfully collected and processed personal data without a proper legal basis and subsequently contacted these individuals with service offers. This case underscores the importance of lawful and transparent processing of personal data.5 November 2024
- Violation of personal data protection by the City of Trnava as the Controller of personal dataIn a recent decision by the Office for Personal Data Protection, we witnessed a case of violation of the Personal Data Protection Act and GDPR. The breach of personal data protection concerned the Controller, who unlawfully disclosed personal data of 47 affected individuals, including the applicant, in a resolution of the City Council of Trnava (“Resolution”).13 February 2024
- Data Protection vs. Anti-Doping Measures - Advocate General Ćapeta PerspectiveThis case highlights the challenging balance between safeguarding data privacy and preserving the integrity of sport through anti-doping measures. In a world where the internet is the primary channel for information dissemination, adapting data protection regulations to meet evolving dynamics while upholding the preventive goals of anti-doping initiatives is a critical consideration. The outcome of this case is expected to set a significant precedent in this ongoing and crucial debate.10 January 2024
- Decision of the Slovak court regarding requested disclosure of personal dataIn today's society, the issue of fulfilling the characteristics of personal data is the subject of many disputes as well as legal discussions. What would not have fulfilled the definition of personal data 5 years ago is possible today, because technological advances are making it increasingly easier. For this reason, it is necessary to exercise a considerable degree of prudence when disclosing personal data. Supreme Court of the Slovak Republic pointed out that "personal data is not only the data by which the natural person is directly identified, but also the data relating to the identifiable person." and pointed out that appealed decision of District Court, based on which District Court did not comply with the request regarding disclosure of personal data, was right.26 August 2022
- The new Slovak Electronic Communication Act shall change opt-out regime to opt-in regime for cookiesThe use of cookies will therefore no longer be linked to the passivity of the users concerned (opt-out). Anyone who stores or obtains access to information stored in the user's endpoint equipment (cookies) will have to have the prior consent of the user concerned (opt-in), and the consent must comply with the requirements of the GDPR.20 January 2022
- Based on the appeal of the controller, the imposed fine for several GDPR violations has been increased almost 15 times!By filing an appeal against the first-instance decision, the controller worsened its situation when the supervisory body increased the amount of the financial sanction almost 15 times! The principle of prohibition of reformatio in peius (prohibition of tightening up of the previous decision) is one of the essential principles of criminal proceedings, but in administrative proceedings, the tightening up of the first instance administrative decision is allowed.19 July 2021
- Slovak country-wide COVID-19 testing from the perspective of personal data protectionSlovakia has recently witnessed a significant increase in the number of confirmed COVID-19 cases. The country exceeded the threshold of one thousand cases per day on Oct. 7. Only about a week later, tests revealed over 2.000 infected people per day.2 November 2020
- Protection of Personal Data vs. Citizen’s HealthAt the time of the fight against the corona virus pandemic, the need to establish an imaginary border between the protection of personal data on the one hand, and the need to protect the lives and health of citizens on the other is much more relevant than was previously the case.16 April 2020
- Slovak list of processing operations which are subject to the requirement for a data protection impact assessmentWhere a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data (hereinafter “DPIA”).6 May 2019
Join the network
Applications from qualified privacy practices are reviewed individually by the INPLP board.