EnglishHR
Croatia flag

Croatia

Croatia Data Privacy Laws: GDPR, AZOP Enforcement & Compliance Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 22 primary sources cited on this page. How we verify our legal content

Croatia Data Privacy Laws: GDPR, AZOP Enforcement & Compliance Guide (2026)

Frequently Asked Questions

What is Croatia's data protection authority?

Croatia's sole data protection authority is AZOP (Agencija za zastitu osobnih podataka), the Croatian Personal Data Protection Agency, based in Zagreb. AZOP was established in 2004 and holds full GDPR enforcement powers including the ability to conduct audits, issue orders, impose processing bans, and levy administrative fines. AZOP Director Zdravko Vukic was elected Deputy Chair of the European Data Protection Board in June 2024.

What is the largest GDPR fine ever imposed in Croatia?

The largest individual GDPR fine in Croatian history is EUR 5.47 million, imposed by AZOP in October 2023 against debt collection agency EOS Matrix d.o.o. Violations included processing personal data of 181,641 individuals (including non-debtors and minors) without a legal basis, recording health data without satisfying Article 9(2), and failing to implement adequate technical security measures. The largest fine issued in 2025 was EUR 4.5 million against an unnamed telecommunications operator for unlawful data transfers to a Serbian processor, transparency failures, and excessive employee data collection.

What special protections does Croatia give to the OIB personal identification number?

The OIB (Osobni identifikacijski broj) is an 11-digit universal identifier assigned to all Croatian citizens and residents. Because it is used across tax, healthcare, banking, and public administration, AZOP treats unauthorized OIB processing as a heightened risk. AZOP guidance tells prize-game organisers to publish no more than a winner's name and place of residence, never an OIB or a home address, and the agency imposed a EUR 2.26 million fine against B2 Kapital for processing OIB data of 77,317 individuals without authorization. Organizations must have a documented legal basis for any OIB processing.

Does Croatia have a specific age of digital consent?

Yes. Croatia set the digital consent age at 16 years, adopting the GDPR's default threshold. Children under 16 cannot independently consent to information society services and require parental or guardian authorization. Croatia did not exercise the GDPR Article 8 option to lower the threshold to 13.

What transfer mechanisms are valid for sending data from Croatia to third countries?

The standard GDPR transfer mechanisms apply: adequacy decisions from the European Commission, Standard Contractual Clauses (SCCs), Binding Corporate Rules, certification mechanisms, or applicable Article 49 derogations. Serbia, the destination in the 2025 telecom fine, has no EU adequacy decision. Organizations using SCCs must ensure they remain in force, conduct Transfer Risk Assessments before transfers begin, and clearly disclose international transfers in privacy notices.

What does Croatia's national GDPR implementing act add beyond the GDPR itself?

The Act on Implementation of the General Data Protection Regulation (NN 42/2018) sets the digital consent age at 16, bans the use of genetic data in life insurance underwriting, regulates biometric data including employee biometrics for time recording under Article 23, and sets detailed video surveillance rules with a six-month retention cap. Article 44(2) limits fines against a legal person with public authority or performing a public service so they do not jeopardize that service, and Article 47 bars any administrative fine against a public authority. The Act does not contain general employment-data rules: those are in Article 29 of the Labour Act.

How does Croatia's Schengen membership affect data protection?

Croatia joined Schengen on 1 January 2023. Schengen membership means Croatian authorities participate in shared EU data systems including the Schengen Information System (wanted persons), the Visa Information System, and the Entry/Exit System, which started operating on 12 October 2025 and became fully operational on 10 April 2026. Processing of personal data within these systems falls under Directive 2016/680 (the Law Enforcement Directive) rather than the GDPR, with AZOP maintaining oversight of Croatian authorities' compliance.

How does the EU AI Act interact with Croatian data protection law?

The EU AI Act applies directly in Croatia. Prohibited practices have applied since 2 February 2025, general-purpose AI model obligations since 2 August 2025, and the Article 50 transparency duties since the general application date of 2 August 2026. Regulation (EU) 2026/1744 moved the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, and the Article 27 fundamental rights impact assessment moves with them. Croatia designated seven Article 77(2) fundamental-rights authorities including AZOP, but has still not notified a market surveillance authority. AZOP has issued FRIA guidance, took part in the BfDI-initiated European consultation on personal data in AI models, and published a recommendation on the safe use of large language models in May 2026. Organizations using AI systems that process personal data must satisfy both GDPR and AI Act requirements simultaneously.

Updates

Corrected Croatia's enforcement figures to AZOP's published totals (38 fines worth EUR 538,200 in 2024, 13 worth EUR 6,725,500 in 2025, with 2023 the record year by value), re-attributed the employee-data rules to Article 29 of the Labour Act and the 2024 platform-work provisions, removed a prize-game enforcement action that AZOP never brought, de-named the EUR 1.5 million bank fine and noted that the decision is not final, updated the EU AI Act timeline for the 2026 Digital Omnibus and Croatia's seven designated fundamental-rights authorities, fixed the Entry/Exit System dates, and added the Article 47 bar on fining public authorities, the six-month video surveillance retention cap, and Croatia's cookie-consent rule under the Electronic Communications Act.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Accuracy corrections: added EOS Matrix d.o.o. EUR 5.47 million fine (October 2023, Croatia's record individual [GDPR](/world-laws/world-data-privacy-laws) fine); corrected telecom fine ranking to largest 2025 fine rather than all-time largest; corrected FAQ largest-fine answer; corrected AZOP source description; clarified Act 126/2025 implements the Data Governance Act (Regulation 2022/868), a separate instrument from the EU Data Act (Regulation 2023/2854).

Major expansion: added annual enforcement statistics, detail on the mobile banking application fine, an EU AI Act overlay section, EU Data Act implementation status, Schengen and eurozone data implications, and AZOP leadership at the EDPB.

Reviewed and approved by an editor

Initial publication covering AZOP enforcement, 2025 fines, OIB protections, and video surveillance rules.

Sources and References

  1. AZOP - National Legislation(azop.hr).gov
  2. AZOP - About the Agency(azop.hr).gov
  3. AZOP - EUR 4.5M Telecom Fine (November 2025)(azop.hr).gov
  4. AZOP - EUR 2.26M B2 Kapital Fine(azop.hr).gov
  5. AZOP - Zdravko Vukic Elected EDPB Deputy Chair(azop.hr).gov
  6. EDPB - B2 Kapital Fine Announcement(edpb.europa.eu).gov
  7. CMS Expert Guide - Croatia Data Protection(cms.law)
  8. OECD - Croatia OIB Documentation(oecd.org).gov
  9. Croatian Government - Schengen and Eurozone 2023(vlada.gov.hr).gov
  10. IAPP - Croatian GDPR Implementation Law(iapp.org)
  11. GDPRhub - HUO Insurance Bureau Decision(gdprhub.eu)
  12. EDPB - EOS Matrix Fine Announcement(edpb.europa.eu).gov
  13. AZOP - Administrative Fines by Year (2020-2025 totals)(azop.hr).gov
  14. AZOP - EUR 1.5 Million Administrative Fine Imposed on a Bank (18 December 2025, decision not final)(azop.hr).gov
  15. AZOP - EUR 5.47M EOS Matrix Fine(azop.hr).gov
  16. AZOP - Eight Administrative Fines Totalling EUR 350,500 (2 July 2025, incl. Croatian Insurance Bureau)(azop.hr).gov
  17. Zakon o provedbi Opce uredbe o zastiti podataka (NN 42/2018) - consolidated text, incl. Arts. 23, 28-32, 44 and 47(zakon.hr).gov
  18. Zakon o radu - Art. 29 (worker privacy) and Arts. 221.g-221.j (algorithmic management, in force 1 January 2024)(zakon.hr).gov
  19. Zakon o elektronickim komunikacijama (NN 76/22, 14/24, 45/26) - Art. 43(4) terminal-equipment consent, Art. 161 HAKOM inspection, Art. 170 penalties(zakon.hr).gov
  20. Ustav Republike Hrvatske - Arts. 35 and 37(zakon.hr).gov
  21. AZOP - Croatia's List of Competent Authorities under the EU AI Act (seven Article 77(2) authorities)(azop.hr).gov
  22. AZOP - Recommendation on the Safe Use of Large Language Models (7 May 2026)(azop.hr).gov
  23. European Commission - AI Act Market Surveillance Authorities and Single Points of Contact (updated 7 September 2026)(digital-strategy.ec.europa.eu).gov
  24. European Commission - The Entry/Exit System Will Become Fully Operational on 10 April 2026(home-affairs.ec.europa.eu).gov
  25. Regulation (EU) 2026/1744 (Digital Omnibus on AI) - amends the AI Act application dates(eur-lex.europa.eu).gov
Share: