🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
HR · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 19 sources retrieved model claude-sonnet-5 ·

Croatia

HR schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 41 claims · 19 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
41Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fully GDPR-aligned omnibus regime with an established, active national implementing act and functioning DPA.

Primary frameworkRegulation (EU) 2016/679 (GDPR) as supplemented by the Act on the Implementation of the General Data Protection Regulation (Narodne novine 42/2018)
Traffic-light rationale — GreenFully GDPR-aligned omnibus regime with an established, active national implementing act and functioning DPA.

Sub-modules (5)

Regulator And AuthorityGreen

AZOP is confirmed as the only independent public supervisory authority in Croatia within the meaning of GDPR Article 51.

Claims: CLM-HR-a1b2c3d4

Act And InstrumentsGreen

The Implementation Act (NN 42/2018) is the principal domestic instrument; it also sets an advisory-fee schedule for AZOP's consultation services to commercial requesters.

Claims: CLM-HR-b2c3d4e5, CLM-HR-c3d4e5f6

Material ScopeGreen

Material scope follows GDPR directly, with a narrow national carve-out for state statistical bodies.

Claims: CLM-HR-d4e5f6a7

Territorial ScopeGreen

Territorial application of national administrative-fine provisions tracks GDPR's establishment/targeting tests for controllers with business residence or service provision in Croatia.

Claims: CLM-HR-e5f6a7b8

Regulator Registration And FilingAmber

No general controller-registration/filing regime beyond GDPR Art 30 ROPA; state/local-government bodies are exempt from administrative fines, though public-service legal entities remain fineable within limits.

Claims: CLM-HR-f6a7b8c9

Category narrative66 words

Croatia is an EU Member State applying the GDPR directly, supplemented by the national Act on the Implementation of the General Data Protection Regulation (Narodne novine No. 42/2018). The Croatian Personal Data Protection Agency (AZOP) is the sole independent supervisory authority under Article 51 GDPR. The Implementation Act adds Croatia-specific procedural rules (advisory fee schedule, statistics-body carve-outs, court-review route) without displacing GDPR's material or territorial scope.

Sources and claims (6)
  1. ConfirmedEuropean Data Protection BoardAZOP (Agencija za zaštitu osobnih podataka) is the sole independent public supervisory authority in the Republic of Croatia within the meaning of Article 51 of the GDPR.
  2. ConfirmedEuropean Data Protection BoardThe Act on the Implementation of the General Data Protection Regulation (Narodne novine No. 42/2018) is Croatia's principal national instrument supplementing the GDPR.
  3. ConfirmedInternational Association of Privacy ProfessionalsThe Implementation Act authorizes AZOP to charge fees for advisory consultations provided to business subjects such as law firms and GDPR consultants, while data subjects, DPOs, journalists and public authorities receive free consultation.
  4. ConfirmedInternational Association of Privacy ProfessionalsState bodies performing official state statistics activities are not required to enable data subjects to exercise access, rectification, restriction or objection rights where doing so would threaten or disable performance of statistical activities.
  5. ConfirmedInternational Association of Privacy ProfessionalsControllers bound by the Implementation Act's derogations are those having business residence or providing services in the Republic of Croatia.
  6. ConfirmedInternational Association of Privacy ProfessionalsState administrative bodies, other state bodies, and units of local and regional self-government are excluded from the charging of administrative fines, while legal entities performing public authority or public-service functions remain fineable in amounts that cannot endanger performance of those services.

#

GDPR baseline applies with narrow, well-documented national derogations on special categories; consent and anonymisation rely on unmodified GDPR text.

Primary frameworkGDPR Articles 6-9 as supplemented by the Implementation Act (NN 42/2018)
Supervisory authorityAZOP
Traffic-light rationale — GreenGDPR baseline applies with narrow, well-documented national derogations on special categories; consent and anonymisation rely on unmodified GDPR text.

Sub-modules (4)

Lawful BasesGreen

AZOP guidance during COVID-19 confirmed reliance on Art 6(1)(c)/(d) for employee-data processing; no other national lawful-basis derogation identified.

Claims: CLM-HR-g7h8i9j0, CLM-HR-h8i9j0k1

Special CategoriesAmber

Two national derogations were identified: a categorical Art 9(2)(a) genetic-data prohibition for insurance risk-scoring, and a consent-free biometric-processing permission for security purposes.

Claims: CLM-HR-j0k1l2m3, CLM-HR-k1l2m3n4

Pseudonymisation And AnonymisationAmber

No Croatia-specific statutory definition or safe-harbour beyond GDPR Articles 4(5) and 89 was found in AZOP, IAPP or DataGuidance materials searched for this run.

Category narrative48 words

Croatia applies GDPR Articles 6-9 directly. The Implementation Act adds one notable Article 9(2)(a) derogation (genetic data for life-insurance risk calculation) and a biometric-data permission for security/property-protection purposes. No Croatia-specific derogation to the general consent standard (Art 7) or to pseudonymisation/anonymisation definitions (Art 4(5), Art 89) was found.

Sources and claims (5)
  1. ConfirmedDataGuidanceAZOP confirmed that any collection of personal data during the COVID-19 pandemic requires a legal basis under GDPR Article 6(1), plus an Article 9(2) exception where sensitive data is involved.
  2. ConfirmedDataGuidanceAZOP concluded that processing of employees' personal data can rely on GDPR Article 6(1)(c) (legal obligation) and Article 6(1)(d) (vital interests) in the pandemic context.
  3. ProbableEUR-Lex / Publications Office of the EUConsent in Croatia must meet the unmodified GDPR Article 7 standard (freely given, specific, informed, unambiguous, revocable) as no national derogation to the consent standard was enacted.
  4. ConfirmedInternational Association of Privacy ProfessionalsThe Implementation Act derogates from Article 9(2)(a) GDPR by categorically prohibiting processing of genetic data to calculate disease-occurrence probability for life-insurance or pure-endowment contract purposes, even on the basis of explicit consent.
  5. ConfirmedInternational Association of Privacy ProfessionalsPublic authorities and private entities may process biometric data without consent where necessary for protection of persons, property, classified data or business secrets, provided no prevalent opposing data-subject interests exist.

#

Rights framework is GDPR-standard with narrow, documented statistics carve-out and an active regulator issuing rights-exercise guidance after incidents.

Primary frameworkGDPR Articles 13-22 as supplemented by the Implementation Act (NN 42/2018)
Supervisory authorityAZOP
Traffic-light rationale — GreenRights framework is GDPR-standard with narrow, documented statistics carve-out and an active regulator issuing rights-exercise guidance after incidents.

Sub-modules (5)

Access RightGreen

Access-right exercise is GDPR-standard; AZOP issued dedicated FAQs helping data subjects claim access/compensation after the EOS Matrix breach.

Claims: CLM-HR-l2m3n4o5

Rectification And ErasureGreen

No Croatia-specific derogation to rectification/erasure beyond the statistics carve-out was found.

Restriction And ObjectionAmber

State statistical bodies are exempted from enabling restriction/objection rights where this would impair statistical functions.

Claims: CLM-HR-m3n4o5p6

Data PortabilityAmber

No Croatia-specific derogation to GDPR Article 20 portability was identified; the unmodified GDPR right applies.

Deadlines And Response WindowsAmber

No Croatia-specific shortened/lengthened response-deadline rule was found; the GDPR one-month (extendable) default applies.

Claims: CLM-HR-n4o5p6q7

Category narrative53 words

Data-subject rights follow GDPR Articles 13-22 directly. Croatia's principal derogation excuses state statistical bodies from certain rights where compliance would impair statistical functions, and provides a court-review (not administrative-complaint) route against AZOP decisions on rights matters. AZOP has also issued rights-exercise FAQs following major breaches. No Croatia-specific portability or deadline derogation was found.

Sources and claims (3)
  1. ConfirmedDataGuidanceFollowing the 2023 EOS Matrix breach, AZOP released FAQs guiding affected citizens on exercising GDPR rights, including claiming compensation and accessing their personal data held by EOS Matrix.
  2. ConfirmedInternational Association of Privacy ProfessionalsState bodies performing official state statistics activities are exempted from enabling data subjects to exercise access, rectification, restriction-of-processing or objection rights where this would threaten or disable performance of statistical activities.
  3. ProbableEUR-Lex / Publications Office of the EUNo Croatia-specific derogation from the GDPR default one-month (extendable by two further months for complex requests) subject-access response deadline was identified.

#

Strong, evidenced enforcement record across security, breach-notification, retention and DPO duties; standard GDPR framework for ROPA/joint-controller arrangements.

Primary frameworkGDPR Articles 24-39 as supplemented by the Implementation Act (NN 42/2018)
Supervisory authorityAZOP
Traffic-light rationale — GreenStrong, evidenced enforcement record across security, breach-notification, retention and DPO duties; standard GDPR framework for ROPA/joint-controller arrangements.

Sub-modules (7)

Accountability And DpiaGreen

AZOP's 2026 Coordinated Enforcement Framework activity requires controllers, including higher-education institutions, to complete mandatory questionnaires on GDPR compliance, AI systems and transparency obligations.

Claims: CLM-HR-o5p6q7r8

Dpo RequirementsAmber

AZOP has fined a company €12,000 for DPO-appointment violations and is running a follow-up study on DPOs to inform new guidelines.

Claims: CLM-HR-p6q7r8s9, CLM-HR-q7r8s9t0

Ropa RequirementsAmber

No Croatia-specific derogation from GDPR Article 30 records-of-processing duties was found; the standard EU baseline applies.

Joint Controller ArrangementsAmber

No Croatia-specific joint-controller derogation was found; GDPR Article 26 applies directly.

Security MeasuresGreen

AZOP actively enforces Article 32 security-of-processing duties, evidenced by the Croatian Insurance Bureau and EOS Matrix fines.

Claims: CLM-HR-r8s9t0u1

Breach NotificationGreen

AZOP's largest publicized enforcement action (EOS Matrix, €5.47M) arose from an anonymous-petition-triggered breach investigation rather than proactive controller self-notification, illustrating an active breach-response posture.

Claims: CLM-HR-s9t0u1v2

Retention And DisposalGreen

Croatia caps video-surveillance data retention at six months absent proceedings-related necessity, and AZOP has fined storage-limitation (Art 5(1)(e)) violations.

Claims: CLM-HR-t0u1v2w3, CLM-HR-u1v2w3x4

Category narrative58 words

Controller/processor duties follow GDPR Chapter IV directly. Enforcement history shows active AZOP supervision of Article 32 security measures and Article 5(1)(e) storage limitation (Croatian Insurance Bureau, EOS Matrix), a national six-month video-surveillance retention cap, and 2026 EDPB Coordinated Enforcement Framework scrutiny of DPIA/transparency/AI-related accountability. DPO-appointment violations have been actively fined. No Croatia-specific ROPA or joint-controller derogation was found.

Sources and claims (7)
  1. ConfirmedDataGuidanceAZOP's 2026 EDPB Coordinated Enforcement Framework activity requires controllers, including higher-education institutions, to complete a mandatory questionnaire on GDPR compliance, AI systems, and Articles 12-14 transparency obligations, with responses due by 15 July 2026.
  2. ProbableDataGuidanceAZOP fined a company €12,000 for violations related to Data Protection Officer appointment obligations.
  3. ConfirmedDataGuidanceAZOP is conducting a follow-up research study on the role of Data Protection Officers, the findings of which will be used to create new DPO guidelines.
  4. ConfirmedDataGuidanceAZOP fined the Croatian Insurance Bureau €101,000 (part of a €350,500 total penalty package) for failing to implement adequate technical and organizational measures, violating GDPR Article 32(2) and (4), following a 2024 data leak affecting one million vehicle owners.
  5. ConfirmedDataGuidanceAZOP fined EOS Matrix d.o.o. €5.47 million in October 2023 after an anonymous petition revealed unauthorized processing of 181,641 individuals' personal data, including lack of a legal basis for processing health data and recorded phone conversations.
  6. ConfirmedInternational Association of Privacy ProfessionalsPersonal data collected via video surveillance in Croatia cannot be kept longer than six months unless necessary for judicial, arbitral or similar proceedings.
  7. ConfirmedDataGuidanceAZOP's investigation of the Croatian Insurance Bureau found the controller had not set maximum retention periods for personal data, violating GDPR Article 5(1)(e) storage limitation.

#

Full pass-through of the harmonized EU cross-border transfer regime; no national gaps or derogations found.

Primary frameworkGDPR Chapter V (Articles 44-49)
Supervisory authorityAZOP
Traffic-light rationale — GreenFull pass-through of the harmonized EU cross-border transfer regime; no national gaps or derogations found.

Sub-modules (6)

Transfer MechanismsGreen

Croatia relies directly on GDPR-defined mechanisms (adequacy, SCCs, BCRs, derogations) with no supplementary national instrument.

Claims: CLM-HR-v2w3x4y5

Adequacy ReceivedGreen

Adequacy determinations affecting Croatia are adopted at EU level by the European Commission and apply uniformly; no Croatia-specific adequacy inbound arrangement exists outside the EU Commission decisions.

Claims: CLM-HR-w3x4y5z6

Adequacy GrantedGreen

Croatia does not issue independent national adequacy decisions; this is an exclusive EU Commission competence under GDPR Article 45.

Claims: CLM-HR-w3x4y5z6

Sccs And BcrsGreen

Standard Contractual Clauses and Binding Corporate Rules are used under the standard EU Commission-approved forms; no Croatia-specific variant was found.

Transfer Impact AssessmentAmber

TIA practice follows the EDPB/Schrems II-derived EU baseline; no Croatia-specific TIA guidance was located in this run.

Data LocalisationAmber

No Croatia-specific data-localisation mandate was identified in AZOP, IAPP or DataGuidance materials searched for this run.

Category narrative40 words

As an EU Member State, Croatia applies GDPR Chapter V (Articles 44-49) directly and uniformly; there is no separate national adequacy, SCC/BCR or transfer-impact-assessment regime distinct from the EU-level mechanism. No Croatia-specific data-localisation mandate was identified in the sources searched.

Sources and claims (2)
  1. ConfirmedEUR-Lex / Publications Office of the EUAs an EU Member State, Croatia applies GDPR Chapter V (Articles 44-49) directly for international personal-data transfers, including adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules and statutory derogations, without a separate national transfer-mechanism regime.
  2. ConfirmedEUR-Lex / Publications Office of the EUAdequacy decisions under GDPR Article 45 are adopted exclusively at EU level by the European Commission and apply uniformly across all Member States including Croatia; Croatia does not issue independent national adequacy determinations.

#

Telecom and insurance/credit overlays are well evidenced; employment and education sectoral rules rely on unconfirmed GDPR-only baseline.

Primary frameworkGDPR plus sector overlays: Electronic Communications Act (ePrivacy); Implementation Act genetic/insurance derogation
Supervisory authorityAZOP
Traffic-light rationale — AmberTelecom and insurance/credit overlays are well evidenced; employment and education sectoral rules rely on unconfirmed GDPR-only baseline.

Sub-modules (7)

Financial Sector OverlayAmber

No dedicated banking-secrecy-vs-GDPR overlay statute was identified beyond general GDPR application to financial-sector controllers.

Health Sector OverlayAmber

The Implementation Act's genetic-data derogation intersects health data with insurance underwriting.

Claims: CLM-HR-x4y5z6a7

Telecoms And EprivacyGreen

The Electronic Communications Act, which entered into force in 2022, implements the EU ePrivacy Directive framework for Croatian telecom/electronic-communications providers, supervised by HAKOM alongside AZOP.

Claims: CLM-HR-y5z6a7b8

Employment DataAmber

No Croatia-specific employment-data code beyond GDPR Article 6(1)(c)/(d) guidance issued during COVID-19 was found.

Credit And ScoringGreen

The EOS Matrix enforcement action against a debt-collection/credit-recovery entity illustrates active AZOP supervision of credit-sector personal-data processing.

Claims: CLM-HR-z6a7b8c9

EducationAmber

No dedicated education-sector statute was found; the 2026 CEF questionnaire specifically targets higher-education institutions under general GDPR transparency duties.

InsuranceGreen

AZOP has actively enforced against insurance-sector controllers, including a €101,000 fine on the Croatian Insurance Bureau.

Claims: CLM-HR-a7b8c9d0

Category narrative51 words

Telecoms/ePrivacy is overlaid by the Electronic Communications Act (transposing Directive 2002/58/EC) supervised jointly by HAKOM and AZOP. Insurance and credit/debt-collection sectors show active AZOP enforcement (Croatian Insurance Bureau, EOS Matrix). A genetic-data/life-insurance derogation links health and insurance sectoral rules. No Croatia-specific employment-data code or education-sector statute distinct from GDPR was found.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsCroatia prohibits processing genetic data to calculate disease-occurrence probability for life-insurance or pure-endowment contract purposes even with data-subject consent, creating a health/insurance-sector overlay on the general GDPR regime.
  2. ProbableDataGuidanceCroatia's Electronic Communications Act, which entered into force in 2022, implements the EU ePrivacy Directive framework, operating alongside GDPR and supervised jointly by HAKOM and AZOP.
  3. ConfirmedDataGuidanceAZOP's enforcement action against EOS Matrix, a debt-collection entity, found unlawful processing of health data and recorded phone conversations of 181,641 debtors, evidencing active credit-sector GDPR supervision.
  4. ConfirmedDataGuidanceAZOP fined the Croatian Insurance Bureau €101,000 for GDPR breaches connected to a data leak from the Register of Registered Vehicles affecting one million vehicle owners' insurance-linked personal data.

#

Cookie/direct-marketing baseline is confirmed via ePrivacy transposition, but several sub-modules (dark patterns, opt-out signals, clean rooms, cross-context advertising) have no Croatia-specific instrument identified.

Primary frameworkePrivacy Directive 2002/58/EC as transposed by the Electronic Communications Act; GDPR consent baseline
Supervisory authorityAZOP
Traffic-light rationale — AmberCookie/direct-marketing baseline is confirmed via ePrivacy transposition, but several sub-modules (dark patterns, opt-out signals, clean rooms, cross-context advertising) have no Croatia-specific instrument identified.

Sub-modules (6)

Cookies And TrackersGreen

Cookie/tracker consent is governed by the ePrivacy Directive as transposed via the Electronic Communications Act, alongside GDPR consent standards.

Claims: CLM-HR-b8c9d0e1

Dark PatternsRed

No Croatia-specific dark-pattern prohibition distinct from general GDPR fairness/transparency principles was found.

Opt Out SignalsRed

No recognition of Global Privacy Control or equivalent automated opt-out signals under Croatian law was identified.

Clean Rooms And DcrRed

No Croatia-specific clean-room or data-collaboration-room rule was identified.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context-advertising concept exists under Croatian law; general GDPR consent/legitimate-interest analysis applies to any such processing.

Direct MarketingAmber

Direct marketing communications require prior opt-in consent under ePrivacy-derived rules implemented via the Electronic Communications Act, layered on GDPR Article 6 lawful-basis requirements.

Claims: CLM-HR-c9d0e1f2

Category narrative71 words

Cookie/tracker and direct-marketing rules derive from the ePrivacy Directive as transposed via the Electronic Communications Act, layered on GDPR consent standards, pending the still-stalled EU ePrivacy Regulation reform (which Croatia itself unsuccessfully attempted to advance during its 2020 Council presidency). No Croatia-specific dark-pattern prohibition, Global-Privacy-Control-style opt-out-signal recognition, clean-room/data-collaboration-room rule, or CPRA-style cross-context-advertising concept was found; these are largely constructs of other jurisdictions (notably US state law) without a Croatian equivalent identified.

Sources and claims (2)
  1. ConfirmedEUR-Lex / Publications Office of the EUCookie and tracker consent in Croatia is governed by the ePrivacy Directive (2002/58/EC) as transposed via the Electronic Communications Act, operating alongside GDPR consent standards, pending the EU's stalled ePrivacy Regulation reform.
  2. ProbableDataGuidanceDirect-marketing electronic communications in Croatia require prior opt-in consent under ePrivacy-derived rules implemented via the Electronic Communications Act, alongside GDPR lawful-basis requirements for the underlying personal-data processing.

#

Biometric and genetic-data rules are well documented; ADM transparency, AI-risk-assessment, and state-surveillance sub-modules rely on thin or GDPR-baseline-only evidence.

Primary frameworkGDPR Articles 9, 22 as supplemented by the Implementation Act (NN 42/2018)
Supervisory authorityAZOP
Traffic-light rationale — AmberBiometric and genetic-data rules are well documented; ADM transparency, AI-risk-assessment, and state-surveillance sub-modules rely on thin or GDPR-baseline-only evidence.

Sub-modules (6)

Profiling RestrictionsAmber

No Croatia-specific derogation from GDPR Article 22 profiling restrictions was identified; the EU baseline applies.

Automated Decision Making TransparencyAmber

AZOP's 2026 CEF questionnaire touches ADM-adjacent AI-system transparency under Articles 12-14, but no dedicated ADM-transparency statute was found.

Claims: CLM-HR-d0e1f2g3

Ai Risk AssessmentsAmber

AZOP has begun probing controllers' AI systems via its 2026 coordinated-enforcement questionnaire; no dedicated Croatian AI risk-assessment statute distinct from the EU AI Act was identified.

Claims: CLM-HR-d0e1f2g3

Biometric RegimeAmber

Croatia permits consent-free biometric-data processing by public authorities and private entities for protection of persons, property, classified data or business secrets, subject to a balancing test.

Claims: CLM-HR-e1f2g3h4

Genetic DataGreen

Croatia categorically bars genetic-data processing for life-insurance/pure-endowment disease-probability calculations, disallowing even explicit-consent reliance.

Claims: CLM-HR-f2g3h4i5

State Surveillance CarveoutsRed

No Croatia-specific national-security/state-surveillance carve-out beyond the general GDPR/EU baseline was identified in the sources searched.

Category narrative70 words

Croatia applies GDPR Article 22 (profiling/ADM) directly with no national derogation found. A national biometric-processing permission and a categorical genetic-data prohibition supplement the GDPR special-categories regime. AZOP's 2026 Coordinated Enforcement Framework activity is the first documented AZOP touchpoint probing controllers' AI systems, though no dedicated Croatian AI statute (distinct from the EU AI Act) was identified. No Croatia-specific state-surveillance carve-out beyond GDPR/national-security exemptions generally applicable across the EU was found.

Sources and claims (3)
  1. ConfirmedDataGuidanceAZOP's 2026 Coordinated Enforcement Framework questionnaire specifically probes controllers' AI systems and their interaction with GDPR transparency obligations under Articles 12-14, signalling emerging AI-governance scrutiny absent a dedicated Croatian AI statute.
  2. ConfirmedInternational Association of Privacy ProfessionalsCroatia permits both public authorities and private entities to process biometric data without consent for protection of persons, property, classified information, or business secrets, subject to a balancing test against data-subject interests.
  3. ConfirmedInternational Association of Privacy ProfessionalsCroatia categorically prohibits processing genetic data to assess disease-occurrence probability for life-insurance or pure-endowment purposes, disallowing reliance on data-subject consent as a derogation route under Article 9(2)(a) GDPR.

#

Age-of-consent rule is clearly documented; parental-consent mechanics, minor-profiling bans, education-settings rules and dependent-adults protections rely on GDPR baseline or incidental enforcement evidence only.

Primary frameworkGDPR Article 8 as implemented by the Act on the Implementation of the GDPR (NN 42/2018)
Supervisory authorityAZOP
Traffic-light rationale — AmberAge-of-consent rule is clearly documented; parental-consent mechanics, minor-profiling bans, education-settings rules and dependent-adults protections rely on GDPR baseline or incidental enforcement evidence only.

Sub-modules (5)

Age VerificationGreen

Croatia sets the digital age of consent at 16 without further derogation or a lower age limit.

Claims: CLM-HR-g3h4i5j6

Minor Profiling BansAmber

No dedicated minor-profiling-ban statute was found; the 2023 EOS Matrix breach (294 minors affected among 181,641 individuals) illustrates enforcement exposure for controllers processing minors' data unlawfully.

Claims: CLM-HR-h4i5j6k7

Education SettingsAmber

No dedicated education-sector children's-data statute was found; AZOP's 2026 CEF questionnaire touches higher-education institutions' transparency compliance generally.

Claims: CLM-HR-i5j6k7l8

Dependent AdultsRed

No Croatia-specific dependent-adult or vulnerable-elderly data-protection provision distinct from the GDPR baseline was identified in the sources searched for this run.

Category narrative61 words

Croatia sets the digital age of consent at 16 with no lower national derogation, meaning information-society-service processing of a child's data is lawful once the child turns 16. The EOS Matrix breach exposed 294 minors' data among affected debtors, illustrating enforcement relevance to minors even absent a bespoke minors-profiling statute. No Croatia-specific dependent-adults/vulnerable-elderly provision distinct from the GDPR baseline was found.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsCroatia's Implementation Act confirms that processing a child's personal data in relation to information-society services is lawful once the child is at least 16, without adopting a lower national age-of-consent derogation.
  2. ConfirmedDataGuidanceThe 2023 EOS Matrix breach investigated by AZOP involved unauthorized processing of personal data belonging to 294 minors among 181,641 affected debtors, prompting one of AZOP's largest known GDPR fines.
  3. ConfirmedDataGuidanceAZOP's 2026 coordinated-enforcement questionnaire specifically targets higher-education institutions' compliance with GDPR transparency obligations, reflecting active education-sector supervisory attention.

#

Strong, multi-year enforcement track record and an active 2026 EDPB coordinated activity; redress route is clear via administrative courts, though collective-redress and regulator-capacity sub-modules lack confirmed detail.

Primary frameworkGDPR Articles 77-84 as supplemented by the Implementation Act (NN 42/2018)
Supervisory authorityAZOP
Traffic-light rationale — GreenStrong, multi-year enforcement track record and an active 2026 EDPB coordinated activity; redress route is clear via administrative courts, though collective-redress and regulator-capacity sub-modules lack confirmed detail.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

AZOP wields full GDPR Article 83 fining powers, supplemented by a national fine cap (up to HRK 50,000) for video-surveillance-specific violations.

Claims: CLM-HR-j6k7l8m9

Enforcement Activity IndexGreen

Multiple significant fines were issued 2023-2024: €5.47M (EOS Matrix), €350,500 aggregate across eight decisions (including €101,000 against the Croatian Insurance Bureau), €12,000 (DPO violation), and €35,000 (two unnamed controllers).

Claims: CLM-HR-k7l8m9n0, CLM-HR-l8m9n0o1, CLM-HR-m9n0o1p2

Regulator Funding And CapacityRed

No specific AZOP budget or headcount data was located in AZOP, IAPP or DataGuidance materials searched for this run.

Collective Redress And Class ActionsRed

No Croatia-specific collective-redress or class-action mechanism for data-protection claims distinct from the EU Representative Actions Directive baseline was identified in this run.

Private Right Of ActionAmber

Data subjects have no internal administrative-appeal route against AZOP decisions on their GDPR rights but may bring a lawsuit before the competent administrative court.

Claims: CLM-HR-n0o1p2q3

Recent Developments 180DGreen

Within the last 180 days, AZOP commenced the 2026 EDPB Coordinated Enforcement Framework activity on transparency and AI-system compliance, with mandatory controller questionnaires due 15 July 2026.

Claims: CLM-HR-o1p2q3r4

Category narrative99 words

AZOP holds full GDPR Article 83 fining powers plus national fine caps for local-law violations (e.g., video-surveillance retention up to HRK 50,000). Enforcement activity is well documented over 2023-2026: the €5.47M EOS Matrix fine (2023), a €350,500 aggregate across eight decisions including the €101,000 Croatian Insurance Bureau fine (2024), a €12,000 DPO-appointment fine, a €35,000 combined fine on two unnamed controllers, and the ongoing 2026 EDPB Coordinated Enforcement Framework activity. Redress against AZOP's rights-related decisions runs through the administrative courts rather than an internal appeal. No Croatia-specific collective-redress/class-action mechanism or granular AZOP funding/headcount data was found in this run.

Sources and claims (6)
  1. ConfirmedInternational Association of Privacy ProfessionalsAZOP holds full GDPR Article 83 administrative-fine powers (up to €20 million or 4% of global annual turnover, whichever is higher), supplemented by a national fine cap of up to HRK 50,000 for video-surveillance-specific violations under the Implementation Act.
  2. ConfirmedDataGuidanceAZOP's largest publicized GDPR fine to date is the €5.47 million penalty against EOS Matrix d.o.o. in October 2023 for unlawful debt-data processing affecting 181,641 individuals.
  3. ConfirmedDataGuidanceAZOP imposed a combined €350,500 in fines across eight separate GDPR enforcement decisions, including the €101,000 penalty against the Croatian Insurance Bureau.
  4. ProbableDataGuidanceAZOP imposed fines totaling €35,000 on two unnamed controllers for GDPR violations.
  5. ConfirmedInternational Association of Privacy ProfessionalsThere is no internal administrative-complaint route against AZOP's decisions related to data subjects' rights, but data subjects may file a lawsuit before the competent administrative court.
  6. ConfirmedDataGuidanceOn 15 June 2026, AZOP announced commencement of the EDPB's 2026 Coordinated Enforcement Framework activity, requiring mandatory controller questionnaires on GDPR transparency (Articles 12-14) and AI-systems compliance, with responses due by 15 July 2026.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Croatia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 41 claim(s), 19 source(s) in the cumulative register.