{
 "jurisdiction_id": "HR",
 "jurisdiction": "Croatia",
 "url": "https://dataprotection.gi/jurisdictions/croatia/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 41,
  "sub_modules": 57,
  "source_register": 19
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/croatia/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Fully GDPR-aligned omnibus regime with an established, active national implementing act and functioning DPA.",
   "claims": [
    {
     "statement": "AZOP (Agencija za zaštitu osobnih podataka) is the sole independent public supervisory authority in the Republic of Croatia within the meaning of Article 51 of the GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://edpb.europa.eu/system/files/2023-04/csc_guide_right_of_access_rectification_and_erasure_20230403_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act on the Implementation of the General Data Protection Regulation (Narodne novine No. 42/2018) is Croatia's principal national instrument supplementing the GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://edpb.europa.eu/system/files/2023-04/csc_guide_right_of_access_rectification_and_erasure_20230403_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Implementation Act authorizes AZOP to charge fees for advisory consultations provided to business subjects such as law firms and GDPR consultants, while data subjects, DPOs, journalists and public authorities receive free consultation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "State bodies performing official state statistics activities are not required to enable data subjects to exercise access, rectification, restriction or objection rights where doing so would threaten or disable performance of statistical activities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Controllers bound by the Implementation Act's derogations are those having business residence or providing services in the Republic of Croatia.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "State administrative bodies, other state bodies, and units of local and regional self-government are excluded from the charging of administrative fines, while legal entities performing public authority or public-service functions remain fineable in amounts that cannot endanger performance of those services.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/croatia/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "GDPR baseline applies with narrow, well-documented national derogations on special categories; consent and anonymisation rely on unmodified GDPR text.",
   "claims": [
    {
     "statement": "AZOP confirmed that any collection of personal data during the COVID-19 pandemic requires a legal basis under GDPR Article 6(1), plus an Article 9(2) exception where sensitive data is involved.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-issues-statement-employees-data-processing-and-coronavirus",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AZOP concluded that processing of employees' personal data can rely on GDPR Article 6(1)(c) (legal obligation) and Article 6(1)(d) (vital interests) in the pandemic context.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-issues-statement-employees-data-processing-and-coronavirus",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Consent in Croatia must meet the unmodified GDPR Article 7 standard (freely given, specific, informed, unambiguous, revocable) as no national derogation to the consent standard was enacted.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex / Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Implementation Act derogates from Article 9(2)(a) GDPR by categorically prohibiting processing of genetic data to calculate disease-occurrence probability for life-insurance or pure-endowment contract purposes, even on the basis of explicit consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Public authorities and private entities may process biometric data without consent where necessary for protection of persons, property, classified data or business secrets, provided no prevalent opposing data-subject interests exist.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/croatia/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights framework is GDPR-standard with narrow, documented statistics carve-out and an active regulator issuing rights-exercise guidance after incidents.",
   "claims": [
    {
     "statement": "Following the 2023 EOS Matrix breach, AZOP released FAQs guiding affected citizens on exercising GDPR rights, including claiming compensation and accessing their personal data held by EOS Matrix.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-fines-eos-matrix-547m-unlawful-processing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "State bodies performing official state statistics activities are exempted from enabling data subjects to exercise access, rectification, restriction-of-processing or objection rights where this would threaten or disable performance of statistical activities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No Croatia-specific derogation from the GDPR default one-month (extendable by two further months for complex requests) subject-access response deadline was identified.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex / Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/croatia/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Strong, evidenced enforcement record across security, breach-notification, retention and DPO duties; standard GDPR framework for ROPA/joint-controller arrangements.",
   "claims": [
    {
     "statement": "AZOP's 2026 EDPB Coordinated Enforcement Framework activity requires controllers, including higher-education institutions, to complete a mandatory questionnaire on GDPR compliance, AI systems, and Articles 12-14 transparency obligations, with responses due by 15 July 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-begins-coordinated-edpb-enforcement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AZOP fined a company €12,000 for violations related to Data Protection Officer appointment obligations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-fines-company-eu12000-dpo-appointment",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AZOP is conducting a follow-up research study on the role of Data Protection Officers, the findings of which will be used to create new DPO guidelines.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-begins-coordinated-edpb-enforcement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AZOP fined the Croatian Insurance Bureau €101,000 (part of a €350,500 total penalty package) for failing to implement adequate technical and organizational measures, violating GDPR Article 32(2) and (4), following a 2024 data leak affecting one million vehicle owners.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-announces-data-leak-affecting-1m-natural",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AZOP fined EOS Matrix d.o.o. €5.47 million in October 2023 after an anonymous petition revealed unauthorized processing of 181,641 individuals' personal data, including lack of a legal basis for processing health data and recorded phone conversations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-fines-eos-matrix-547m-unlawful-processing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Personal data collected via video surveillance in Croatia cannot be kept longer than six months unless necessary for judicial, arbitral or similar proceedings.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AZOP's investigation of the Croatian Insurance Bureau found the controller had not set maximum retention periods for personal data, violating GDPR Article 5(1)(e) storage limitation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-announces-data-leak-affecting-1m-natural",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/croatia/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Full pass-through of the harmonized EU cross-border transfer regime; no national gaps or derogations found.",
   "claims": [
    {
     "statement": "As an EU Member State, Croatia applies GDPR Chapter V (Articles 44-49) directly for international personal-data transfers, including adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules and statutory derogations, without a separate national transfer-mechanism regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex / Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Adequacy decisions under GDPR Article 45 are adopted exclusively at EU level by the European Commission and apply uniformly across all Member States including Croatia; Croatia does not issue independent national adequacy determinations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex / Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/croatia/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Telecom and insurance/credit overlays are well evidenced; employment and education sectoral rules rely on unconfirmed GDPR-only baseline.",
   "claims": [
    {
     "statement": "Croatia prohibits processing genetic data to calculate disease-occurrence probability for life-insurance or pure-endowment contract purposes even with data-subject consent, creating a health/insurance-sector overlay on the general GDPR regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Croatia's Electronic Communications Act, which entered into force in 2022, implements the EU ePrivacy Directive framework, operating alongside GDPR and supervised jointly by HAKOM and AZOP.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-hakom-announces-entry-force-electronic",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AZOP's enforcement action against EOS Matrix, a debt-collection entity, found unlawful processing of health data and recorded phone conversations of 181,641 debtors, evidencing active credit-sector GDPR supervision.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-fines-eos-matrix-547m-unlawful-processing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AZOP fined the Croatian Insurance Bureau €101,000 for GDPR breaches connected to a data leak from the Register of Registered Vehicles affecting one million vehicle owners' insurance-linked personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-announces-data-leak-affecting-1m-natural",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/croatia/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie/direct-marketing baseline is confirmed via ePrivacy transposition, but several sub-modules (dark patterns, opt-out signals, clean rooms, cross-context advertising) have no Croatia-specific instrument identified.",
   "claims": [
    {
     "statement": "Cookie and tracker consent in Croatia is governed by the ePrivacy Directive (2002/58/EC) as transposed via the Electronic Communications Act, operating alongside GDPR consent standards, pending the EU's stalled ePrivacy Regulation reform.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex / Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex:32002L0058",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Direct-marketing electronic communications in Croatia require prior opt-in consent under ePrivacy-derived rules implemented via the Electronic Communications Act, alongside GDPR lawful-basis requirements for the underlying personal-data processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-hakom-announces-entry-force-electronic",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/croatia/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric and genetic-data rules are well documented; ADM transparency, AI-risk-assessment, and state-surveillance sub-modules rely on thin or GDPR-baseline-only evidence.",
   "claims": [
    {
     "statement": "AZOP's 2026 Coordinated Enforcement Framework questionnaire specifically probes controllers' AI systems and their interaction with GDPR transparency obligations under Articles 12-14, signalling emerging AI-governance scrutiny absent a dedicated Croatian AI statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-begins-coordinated-edpb-enforcement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Croatia permits both public authorities and private entities to process biometric data without consent for protection of persons, property, classified information, or business secrets, subject to a balancing test against data-subject interests.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Croatia categorically prohibits processing genetic data to assess disease-occurrence probability for life-insurance or pure-endowment purposes, disallowing reliance on data-subject consent as a derogation route under Article 9(2)(a) GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/croatia/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Age-of-consent rule is clearly documented; parental-consent mechanics, minor-profiling bans, education-settings rules and dependent-adults protections rely on GDPR baseline or incidental enforcement evidence only.",
   "claims": [
    {
     "statement": "Croatia's Implementation Act confirms that processing a child's personal data in relation to information-society services is lawful once the child is at least 16, without adopting a lower national age-of-consent derogation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The 2023 EOS Matrix breach investigated by AZOP involved unauthorized processing of personal data belonging to 294 minors among 181,641 affected debtors, prompting one of AZOP's largest known GDPR fines.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-fines-eos-matrix-547m-unlawful-processing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AZOP's 2026 coordinated-enforcement questionnaire specifically targets higher-education institutions' compliance with GDPR transparency obligations, reflecting active education-sector supervisory attention.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-begins-coordinated-edpb-enforcement",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/croatia/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Strong, multi-year enforcement track record and an active 2026 EDPB coordinated activity; redress route is clear via administrative courts, though collective-redress and regulator-capacity sub-modules lack confirmed detail.",
   "claims": [
    {
     "statement": "AZOP holds full GDPR Article 83 administrative-fine powers (up to €20 million or 4% of global annual turnover, whichever is higher), supplemented by a national fine cap of up to HRK 50,000 for video-surveillance-specific violations under the Implementation Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AZOP's largest publicized GDPR fine to date is the €5.47 million penalty against EOS Matrix d.o.o. in October 2023 for unlawful debt-data processing affecting 181,641 individuals.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-fines-eos-matrix-547m-unlawful-processing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AZOP imposed a combined €350,500 in fines across eight separate GDPR enforcement decisions, including the €101,000 penalty against the Croatian Insurance Bureau.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-issues-eight-fines-totaling-eu350500-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AZOP imposed fines totaling €35,000 on two unnamed controllers for GDPR violations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-imposes-fines-totaling-35000-two-unnamed",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "There is no internal administrative-complaint route against AZOP's decisions related to data subjects' rights, but data subjects may file a lawsuit before the competent administrative court.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/croatian-gdpr-implementation-law-main-features-and-unanswered-questions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 15 June 2026, AZOP announced commencement of the EDPB's 2026 Coordinated Enforcement Framework activity, requiring mandatory controller questionnaires on GDPR transparency (Articles 12-14) and AI-systems compliance, with responses due by 15 July 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/croatia-azop-begins-coordinated-edpb-enforcement",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}