Croatia
Croatia Data Privacy Laws: GDPR, AZOP Enforcement & Compliance Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 22 primary sources cited on this page. How we verify our legal content

Croatia protects personal data through the EU General Data Protection Regulation, supplemented by the Act on Implementation of the GDPR (NN 42/2018) and constitutional guarantees in Articles 35 and 37. The Croatian Personal Data Protection Agency (AZOP) enforces the law and imposed EUR 6.7 million in fines in 2025.
Croatia has built one of the more assertive GDPR enforcement records among newer EU member states. The Croatian Personal Data Protection Agency (AZOP) imposed 13 administrative fines totalling EUR 6,725,500 during 2025, after a quieter 2024 in which 38 fines came to EUR 538,200. The country's constitutional protections, a detailed national implementing act, and a supervisory authority whose director now sits on the European Data Protection Board combine to create a rigorous data protection environment.
This guide covers the full framework: from constitutional foundations and the national implementing act to specific enforcement cases, the OIB identifier regime, EU AI Act interaction, and practical compliance guidance for organizations active in Croatia.
Quick Answer: How Does Croatia Protect Personal Data?
Croatia applies the EU General Data Protection Regulation directly as binding law and supplements it with the Act on Implementation of the General Data Protection Regulation (Official Gazette NN 42/2018). The supervisory authority is AZOP, which holds full investigative, corrective, and advisory powers. Constitutional protections under Articles 35 and 37 of the Croatian Constitution underpin the entire framework. GDPR maximum penalties of up to 4% of global annual turnover or EUR 20 million apply, and AZOP has demonstrated the willingness to impose large fines across multiple sectors.
Internal links: For broader EU context, see our EU data privacy laws guide. For Croatia's recording consent rules, see Croatia recording laws.
Constitutional Foundations
Croatian data protection law is grounded in two constitutional provisions.
Article 35 guarantees everyone respect for and legal protection of their personal and family life, dignity, reputation, and honor. The guarantee runs to everyone in Croatia, not only to Croatian citizens. This general privacy right shapes how Croatian courts interpret data protection obligations.
Article 37 goes further and specifically addresses personal data. It guarantees everyone the safety and secrecy of personal data. Without consent from the person concerned, personal data may be collected, processed, and used only under conditions specified by law. Critically, Article 37 also prohibits use of personal data contrary to the purpose of their collection, embedding a purpose limitation principle at the constitutional level. Protection of data and supervision of information systems are to be regulated by law.
These provisions predate the GDPR and reflect Croatia's own legal tradition of treating personal data as a fundamental right, not merely a regulatory compliance obligation.
The Legal Framework: GDPR Plus National Implementing Act
Croatia joined the EU on 1 July 2013, making it subject to EU data protection law. When the GDPR took effect on 25 May 2018, the Croatian Parliament had already enacted the Act on Implementation of the General Data Protection Regulation (Zakon o provedbi Opce uredbe o zastiti podataka), which entered into force on the same day.
The Act operates as a complement to the directly applicable GDPR. It does not replace the GDPR but fills in areas where the regulation expressly permits member states to adopt additional national rules.
What the National Act Adds
The implementing act addresses several specific areas that the GDPR leaves to national discretion.
Employee data is the common misconception about this Act. The implementing act contains no general employment-data provision. Its Chapter IV runs from Article 19 (children's consent) to Article 33 (statistics), and the only workplace rules inside it are Article 23, on employee biometrics for time recording and building access, and Article 30, on workplace video surveillance. Croatia's general employee-data rules sit in the Labour Act and are covered in their own section below.
Genetic data in life insurance is addressed specifically. The Act prohibits insurers from using genetic data to calculate premiums or make coverage decisions, going beyond the GDPR's general sensitive-data protections.
Biometric data processing receives heightened scrutiny requirements, particularly in the employment and public sector contexts.
Video surveillance is regulated in detail (discussed in its own section below).
The Act also sets Croatia's digital consent age at 16 years for information society services, adopting the GDPR's default rather than exercising the option to lower it to 13.
Legal entities performing public functions receive a modified fining regime under Article 44(2) of the Act: a fine against a legal person with public authority, or one performing a public service, must not jeopardize the performance of that authority or service. That is why the Croatian Insurance Bureau received a EUR 101,000 fine rather than a larger penalty despite a data breach affecting over one million vehicle owners.
Article 47 goes further and is the more consequential rule. In proceedings against a public authority, no administrative fine may be imposed at all for breaches of the Act or the GDPR. Article 3(2) defines a public authority as a state administration body, another state body, or a unit of local or regional self-government. AZOP's other corrective powers under GDPR Article 58 remain fully available, so a ministry or a municipality can be ordered to stop processing, but it cannot be fined.
Repeal of Prior Law
The Act repealed the former Personal Data Protection Act (Official Gazette NN 103/03 and subsequent amendments), which had governed Croatian data protection since 2003, along with associated subordinate regulations.
AZOP: Croatia's Supervisory Authority
AZOP (Agencija za zastitu osobnih podataka), the Croatian Personal Data Protection Agency, is the sole independent public supervisory authority under GDPR Article 51. AZOP has operated since 2004, making it one of the older data protection authorities in the region.
AZOP is accountable to the Croatian Parliament rather than to the executive branch, preserving its operational independence from government.
Leadership and European Role
Zdravko Vukic has served as AZOP Director since 2020 and was re-elected for a further four-year term in February 2024. In June 2024, the members of the European Data Protection Board elected Vukic as Deputy Chair of the EDPB, giving Croatia a significant role in shaping pan-European data protection policy.
Anamarija Mladinic, Head of AZOP's Sector for EU and International Cooperation, was simultaneously elected Vice-Chair of the Convention 108 Committee in 2024, reinforcing Croatia's profile in international data protection governance.
AZOP's Powers
AZOP holds the full set of GDPR supervisory authority powers.
Investigative powers include: demanding information from controllers and processors, conducting data protection audits, accessing premises and processing equipment, and reviewing certifications and approved codes of conduct.
Corrective powers include: issuing warnings and reprimands, ordering controllers to comply with data subject requests, imposing temporary or permanent processing limitations or bans, ordering data rectification or erasure, withdrawing certifications and approvals, and imposing administrative fines under GDPR Article 83.
Advisory powers include: providing opinions to the Croatian Parliament and government on proposed legislation, issuing guidance and guidelines for organizations, approving codes of conduct, authorizing standard contractual clauses for international data transfers, and handling prior consultation requests for high-risk processing.
AZOP investigates both on the basis of formal complaints and on its own initiative. The agency has demonstrated that anonymous complaints can trigger full investigations resulting in multi-million-euro fines.
Legal Bases and Consent
All six GDPR legal bases apply in Croatia: consent (Article 6(1)(a)), contract performance (Article 6(1)(b)), legal obligation (Article 6(1)(c)), vital interests (Article 6(1)(d)), public task (Article 6(1)(e)), and legitimate interests (Article 6(1)(f)).
Consent must be freely given, specific, informed, and unambiguous. AZOP has scrutinized consent practices closely, particularly in digital contexts. The 2025 mobile banking case demonstrated that embedding data collection within an app, without a transparent and app-specific privacy notice, does not constitute a valid legal basis for processing.
The legitimate interests basis requires a balancing test. AZOP expects documented assessments showing that legitimate interests are not overridden by the data subject's rights and freedoms.
Special categories of data (health, genetic, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation) require an Article 9 condition in addition to an Article 6 legal basis.
Data Subject Rights
Croatian residents hold all GDPR data subject rights: access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), objection (Article 21), and rights related to automated decision-making (Article 22).

Controllers must respond to rights requests within one month, with a possible two-month extension for complex or numerous requests. AZOP enforces response obligations actively. Failure to respond appropriately to a data subject's request for access to video surveillance footage was the basis for a fine against an energy company in a documented 2022 case.
AZOP provides accessible information on data subject rights on its official website, and residents can file complaints with AZOP directly if a controller fails to honor their rights.
Data Breach Notification
The standard GDPR breach notification regime applies. Controllers must notify AZOP within 72 hours of becoming aware of a personal data breach likely to result in risk to individuals' rights and freedoms. Where the risk is high, affected data subjects must also be notified without undue delay.
The notice to AZOP must describe the nature of the breach, the approximate number of individuals and records affected, likely consequences, and measures taken or proposed to address the breach.
AZOP has confirmed it investigates data leaks thoroughly even when notified through indirect channels such as anonymous reports. The Croatian Insurance Bureau case, where a USB stick containing data on over one million vehicle owners was submitted anonymously, resulted in a EUR 101,000 fine focused on inadequate organizational and technical security measures and the absence of defined retention periods.
Processors must notify controllers without undue delay upon becoming aware of a breach.
Data Protection Officers
Most mid-to-large organizations operating in Croatia will require a Data Protection Officer under GDPR Article 37. The mandatory DPO categories are public authorities and bodies (excluding courts acting in a judicial capacity), controllers or processors whose core activities require large-scale systematic monitoring of individuals, and controllers or processors whose core activities involve large-scale processing of special category data.
There is no DPO register in Croatian law. The obligation is the GDPR's own, under Article 37(7): publish the DPO's contact details and communicate them to AZOP, which provides a web form for that notification. The DPO must have expert knowledge of data protection law and practice, and the role must not create a conflict of interest.
The telecom operator enforcement case illustrates the importance of genuinely heeding DPO advice. AZOP's investigation found that the operator had disregarded its own DPO's recommendation that collecting copies of employee identity documents was excessive, which contributed to the severity of the penalty.
OIB: Croatia's Personal Identification Number

Croatia's Personal Identification Number (Osobni identifikacijski broj, OIB) is an 11-digit unique identifier permanently assigned to all natural persons who are Croatian citizens or who establish residence or other legal connections in Croatia. The OIB is used across public administration, taxation, healthcare, notarial records, banking, and most official transactions.
Because the OIB functions as a universal identifier, its exposure creates significant risk. If an OIB is combined with even basic personal information (name, date of birth), the combined profile becomes highly useful for identity fraud or unauthorized profiling.
AZOP treats unauthorized processing or publication of OIB numbers as a serious violation. Enforcement has been consistent:
In the B2 Kapital case, the debt collection agency processed OIB numbers of 77,317 individuals without authorization. The anonymous complaint included a USB stick containing the data. AZOP found violations of transparency obligations (Article 13), processor agreement requirements (Article 28), and security obligations (Article 32), resulting in a EUR 2.26 million fine. The company had not updated its privacy policy since the date the GDPR entered into force in 2018.
AZOP has also published guidance for prize-game organisers that want to name winners publicly. The guidance is that publication still needs an Article 6 legal basis and that data minimisation limits what may be shown, giving name and place of residence as the example of a proportionate scope. An OIB or a home address goes well beyond that.
Organizations that collect OIB numbers for one purpose (such as tax reporting) must not use them for other purposes, must store them securely, and must not disclose them without a valid legal basis.
Video Surveillance Rules
Croatia's implementing act establishes specific rules for video surveillance that supplement the GDPR's general framework.
Surveillance must serve a clearly defined, legitimate purpose. The most commonly accepted purposes are protection of property and personal safety. General monitoring without a specific purpose is not lawful.
Organizations must display clear, prominent signage before any surveilled area. The signage must indicate who operates the surveillance, for what purpose, and how individuals can exercise their rights.
Retention is capped. Article 29 of the implementing act allows footage to be kept for a maximum of six months, unless another law prescribes a longer period or the footage is evidence in judicial, administrative, arbitration or equivalent proceedings.
Three further Croatian rules catch organizations out. Article 28(4) requires an automated access log recording the time and place of each access to footage and the identity of the person who made it. Article 31 allows video surveillance in residential or mixed residential and commercial buildings only with the consent of co-owners holding at least two thirds of the co-ownership shares, limits it to entrances, exits and common areas, and bans using it to monitor the work performance of caretakers, cleaners and other building staff. Article 32 reserves surveillance of public areas to public authorities, legal persons with public authority and legal persons performing a public service, and only where a law prescribes it, where it is necessary for the performance of the body's tasks, or to protect life, health and property (Article 32(1)).
Data protection impact assessments (DPIAs) are required before deploying large-scale video surveillance systems, particularly in public or semi-public spaces.
Footage may only be accessed by authorized personnel for defined purposes. The energy company case, where AZOP fined an organization for failing to provide surveillance footage to a data subject who requested it under Article 15, illustrates that access controls must not prevent legitimate rights requests from being honored.
Employment Data Processing
Croatia's employee-data rules come from the Labour Act (Zakon o radu, NN 93/14 with later amendments), not from the GDPR implementing act. Article 29 is the operative provision.
Worker personal data may be collected, processed, used and disclosed to third parties only where that Act or another Act so provides, or where it is necessary for exercising rights and obligations arising from the employment relationship (Article 29(1)).
The employer must specify in advance, in its works rules (pravilnik o radu), which data it will process for that purpose (Article 29(2)). Only the employer, or a person the employer specifically authorises, may process it (Article 29(3)).
Incorrectly recorded data must be corrected immediately, and data for which no legal or factual reason to keep it remains must be deleted (Article 29(4) and (5)).
An employer with at least twenty workers must appoint a person who enjoys the workers' trust to supervise whether worker data is handled lawfully (Article 29(6)). This is a Croatian-specific role, separate from the GDPR data protection officer. Anyone who learns worker data in the course of their duties must keep it confidential permanently (Article 29(7)).
Two rules from the implementing act also apply at work. Article 23 permits processing employee biometrics for time recording and for entry to and exit from business premises only where a law prescribes it, or where it is offered as an alternative to another solution, and only with the employee's explicit consent. Article 30(2) bars workplace video surveillance from covering rest rooms, personal hygiene rooms and changing rooms.
Since 1 January 2024, Articles 221.g to 221.j of the Labour Act add algorithmic-management duties for work performed through digital labour platforms. The platform must explain how its automated management system allocates work and reaches decisions, appoint a person to monitor workload and safety, and appoint a person who reviews automated decisions at a worker's request. Article 221.j bars the platform from processing data on private conversations, on a worker's emotional or psychological state, or on a worker's health beyond what data protection law allows, and from collecting personal data during periods when the worker is neither working nor offering to work.
The telecom operator case demonstrated the risks of over-collection in employment contexts. AZOP found that the operator collected copies of employee identity documents and criminal background certificates without a valid legal basis and without proper proportionality assessment. The DPO had flagged these practices as excessive, but the company continued them. This specific violation contributed materially to the total EUR 4.5 million penalty.
Employers intending to monitor employees, collect health or background data, or share employee information with service providers outside Croatia must conduct careful legal basis analysis and, where required, DPIAs.
International Data Transfers
Croatia's most consequential enforcement development was the November 2025 telecom fine, which put cross-border data transfers at the center of GDPR compliance.
The standard GDPR transfer framework applies. Data may only be transferred outside the European Economic Area if one of the following applies: the destination country has received an EU adequacy decision, the parties have executed Standard Contractual Clauses (SCCs) approved by the European Commission, the organization operates under Binding Corporate Rules, or an applicable derogation under GDPR Article 49 applies.
The telecom case involved a specific failure mode: the company had contracted with a processor in Serbia (not an EEA member and without an EU adequacy decision) and initially relied on SCCs, but after 27 December 2022, it continued transferring data after the SCC arrangement expired without executing new clauses. The processor had access to 847,862 user records with unrestricted administrative privileges. AZOP found violations of Articles 44, 46(1), 12(1), and 13(1)(f).

Key lessons from this case: organizations must conduct Transfer Risk Assessments before initiating transfers to third countries; SCC arrangements must be maintained and renewed when they expire; privacy notices must clearly and specifically describe international transfers rather than using vague permissive language; and processor due diligence must include verification of actual security measures before data sharing begins.
Serbia remains a third country for EU data transfer purposes as of 10 September 2026. The EU has not issued an adequacy decision for Serbia. Organizations routing Croatian personal data through Serbian processors must maintain valid SCCs and conduct periodic transfer risk assessments.
For EEA-to-EEA transfers (including to other EU member states), no transfer mechanism is required. Croatia's eurozone and Schengen membership facilitates cross-border commerce, but GDPR obligations remain fully applicable to personal data wherever it travels within the EEA.
Schengen and Eurozone Membership: Data Implications
Croatia joined both the Schengen Area and the eurozone on 1 January 2023, completing its integration into the EU's core frameworks after joining the Union in 2013.
Schengen Data Systems
Schengen membership brings Croatia into several shared EU law enforcement data systems:
The Schengen Information System (SIS) is a shared database of wanted persons, missing persons, stolen property, and entry bans accessible to Croatian police, border control, and law enforcement officers. The renewed SIS replaced the former SIS II in March 2023 and runs under three regulations: Regulation (EU) 2018/1861 for border checks, Regulation (EU) 2018/1862 for police and judicial cooperation in criminal matters, and Regulation (EU) 2018/1860 for returns.
EURODAC, the biometric fingerprint database for asylum applications, and the Visa Information System (VIS) are long-standing systems that Croatia joined on accession to Schengen. The Entry/Exit System (EES) is far newer. It started operating on 12 October 2025 with a progressive roll-out across 29 European countries and became fully operational at all external border crossing points on 10 April 2026, replacing passport stamping for non-EU short-stay travellers with a biometric record of entries and exits.
Processing of personal data within these systems is governed by Directive 2016/680 (the Law Enforcement Directive) rather than the GDPR, with AZOP maintaining oversight responsibilities for Croatian national authorities' use of these systems.
Eurozone and Financial Data
Adoption of the euro eliminated the kuna as legal tender and brought Croatia fully within the ECB's monetary framework. Financial institutions operating in Croatia process payment data subject to both GDPR requirements and applicable EU financial regulations including PSD2, which has its own data sharing provisions.
EU AI Act Overlay
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies progressively across EU member states. As an EU member state, Croatia is subject to its provisions on the same timeline as all other members.
The AI Act introduces risk categories for AI systems. Prohibited AI practices, such as real-time remote biometric identification in public spaces without specified exceptions, became applicable from 2 February 2025. General-purpose AI model obligations have applied since 2 August 2025.
The Act's general application date of 2 August 2026 has now passed. That date carried the Article 50 transparency duties: disclosing that a person is interacting with an AI system, marking synthetic audio, image, video and text in machine-readable form, giving notice of emotion recognition and biometric categorisation, and labelling deepfakes. Providers whose synthetic-content systems were already on the market before 2 August 2026 have until 2 December 2026 to meet Article 50(2), under a grace period added by Regulation (EU) 2026/1744.
That same regulation, the Digital Omnibus on AI, in force since 27 July 2026, postponed the high-risk regime. Chapter III Sections 1 to 3, which carry the design requirements and the provider and deployer obligations, now apply from 2 December 2027 for Annex III high-risk systems (employment, credit scoring, education, essential services, law enforcement) and from 2 August 2028 for Annex I systems that are safety components of regulated products. The Article 27 fundamental rights impact assessment rides the Annex III date. The Commission's Article 6(5) classification guidelines were expressly carved out of the delay. Two new prohibitions, on non-consensual intimate imagery and on systems generating child sexual abuse material, apply from 2 December 2026.
Under Article 77(2) Croatia designated seven public authorities to supervise fundamental rights in relation to high-risk AI: AZOP, the Ombudswoman, the Ombudswoman for Children, the Ombudswoman for Gender Equality, the Ombudswoman for Persons with Disabilities, the State Election Commission and the Agency for Electronic Media. AZOP has issued guidance on conducting Fundamental Rights Impact Assessments (FRIAs).
Market surveillance is the open gap. The Commission's list of AI Act market surveillance authorities and single points of contact, last updated 7 September 2026, still shows no entry for Croatia, although the Article 70 deadline was 2 August 2025.
AZOP's generative AI work is well documented. It joined the European consultation on personal data in AI models initiated by Germany's Federal Commissioner for Data Protection and Freedom of Information, running its own call for input in August 2025 with a focus on large language models. Its head of the EU and international cooperation sector presented the EDPB Support Pool of Experts methodology on identifying and managing risk in large language models at the Board's session of 9 April 2025. On 7 May 2026 AZOP published a recommendation on the safe use of large language models, warning organizations not to feed personal data, internal documents or case files into public chatbots without a prior assessment and a legal basis.
Organizations using AI systems in Croatia that process personal data must ensure GDPR compliance and AI Act conformity simultaneously. Where an AI system performs profiling, automated decision-making, or large-scale processing of special category data, both frameworks apply.
EU Data Act and Data Governance
The EU Data Act (Regulation (EU) 2023/2854) became applicable on 12 September 2025. It creates new rights and obligations around data generated by connected devices and data-sharing obligations for data holders.
Separately, Croatia enacted the Act on Implementation of the Data Governance Act (NN 126/2025, in force October 2025) to implement the EU Data Governance Act (Regulation (EU) 2022/868). These are two distinct EU instruments: the Data Governance Act governs data intermediation services and data altruism organizations, while the Data Act addresses data sharing from connected products and related services.
Both instruments interact with GDPR where data sharing involves personal data: neither overrides GDPR requirements, and organizations sharing data under Data Act or Data Governance Act obligations must satisfy applicable GDPR legal bases.
Cookies and Electronic Communications
Cookie consent is not in the GDPR implementing act. It sits in the Electronic Communications Act (Zakon o elektronickim komunikacijama, NN 76/22, 14/24 and 45/26).
Article 43(4) permits the use of electronic communications networks to store information in, or gain access to information already stored in, an end user's terminal equipment only where that user has consented after receiving clear and complete information under data protection law, in particular about the purposes of processing. The exceptions are narrow: technical storage or access needed solely to carry out the transmission, or where strictly necessary to provide an information society service the user has expressly requested. Analytics and advertising cookies fall outside both.
Breach is a serious offence under Article 170 of that Act, punishable by a fine of EUR 13,270 to EUR 132,720 for a legal person, with lower bands for the responsible person within it and for individuals. Inspection supervision belongs to HAKOM, the Croatian Regulatory Authority for Network Industries, while AZOP remains competent for the personal data aspects of the same processing.
Penalties and Enforcement History
The GDPR's two-tier fine structure applies in Croatia. The lower tier (up to EUR 10 million or 2% of global annual turnover, whichever is higher) covers violations of obligations such as data security, breach notification, DPO requirements, and processor contracts. The upper tier (up to EUR 20 million or 4% of global turnover, whichever is higher) covers violations of processing principles, legal bases, data subject rights, and international transfer rules.
2025 Enforcement
AZOP imposed 13 administrative fines totalling EUR 6,725,500 in 2025, targeting telecommunications, banking, debt collection, insurance, and other sectors.
The telecom operator (EUR 4.5 million, November 2025) received the largest single GDPR fine issued in Croatia in 2025 for unlawful data transfers to Serbia, transparency failures, excessive employee data collection, and failure to verify processor security. The Serbian processor had unlimited administrative access to 847,862 user records.
A bank (EUR 1.5 million, announced 18 December 2025) was fined for processing personal data of 433,922 users through a program embedded in its Android and Huawei mobile banking applications without a valid legal basis. The program scanned the device and transmitted the list of every installed application to a centralised bank database. AZOP found breaches of Articles 6(1) and 5(1)(a), of the transparency duties in Articles 12 and 13 because the bank's notices did not address the app processing at all, and of Article 25(2) because a far less intrusive design was available.
AZOP did not name the bank. Under Article 48 of the implementing act it publishes a decision without anonymising the offender only once that decision is final, and it stated that this decision is not final and that the controller may bring an administrative dispute before the competent administrative court within 30 days. Croatian media identified the bank; AZOP has not.
The Croatian Insurance Bureau (EUR 101,000, announced 2 July 2025 as part of a batch of eight fines totalling EUR 350,500) was fined after a USB stick containing data on over one million vehicle owners from the national Register of Registered Vehicles was submitted in an anonymous complaint. AZOP confirmed the data matched HUO's database and found failures in organizational and technical security measures and absence of defined data retention periods. The reduced fine reflects the statutory protection for a legal person with public authority under Article 44(2) of the national implementing act.
2024 Enforcement
AZOP imposed 38 administrative fines in 2024, totalling EUR 538,200. That is the largest number of fines the agency has issued in a single year, but a low total by value, because 2024 produced no case on the scale of EOS Matrix or B2 Kapital.
The record year by value remains 2023, when 28 fines came to EUR 8,266,350. For comparison, AZOP's published table records 14 fines totalling EUR 528,369.49 in 2022, 4 fines totalling EUR 103,191.99 in 2021, and a single fine of EUR 145,995.09 in 2020.
Croatian enforcement totals therefore swing year to year with one or two large decisions rather than climbing steadily.
Earlier Significant Fines
EOS Matrix d.o.o. (EUR 5.47 million, October 2023) is the largest individual GDPR fine AZOP has imposed to date, surpassing all subsequent 2025 fines including the telecom case. The debt collection agency processed personal data of 181,641 debtors, along with non-debtors and 294 minors held in the same database, without a legal basis under Article 6(1), recorded health data (including terminal illness notations) of debtors without satisfying Article 9(2), and failed to implement adequate technical security measures under Article 32. The investigation was triggered by an anonymous complaint accompanied by a USB stick. AZOP found violations of Articles 5, 6, 9, 12, 13 and 32 of the GDPR. The company indicated it would challenge the penalty.
B2 Kapital (EUR 2.26 million, May 2023) was the first Croatian GDPR fine to exceed seven figures at the time of its imposition. The debt collector processed OIB numbers and personal data of 77,317 individuals without authorization, lacked a data processing agreement with its processor, and had an outdated privacy policy unchanged since the GDPR's effective date in 2018.
An energy company received approximately EUR 120,000 for failing to honor a data subject's Article 15 request for access to video surveillance recordings.
Sector-Specific Observations
Telecommunications: The EUR 4.5 million fine demonstrates that telecom operators face heightened scrutiny on international data transfers and processor oversight.
Banking and financial services: The 2025 mobile banking application case shows AZOP's willingness to investigate consumer-facing digital products in detail. Third-party software components embedded in banking apps will be examined against GDPR transparency and legal basis requirements.
Debt collection: B2 Kapital established that debt collectors processing OIB numbers and financial data of large populations face material GDPR exposure. Anonymous complaints can be the trigger.
Insurance: HUO's fine demonstrates that even public-function entities face enforcement, though the special fining regime limits the maximum penalty to avoid disrupting essential services.
Energy: Video surveillance and data subject rights are documented enforcement areas in the energy sector.
Business Compliance: Practical Steps
Organizations active in Croatia should treat AZOP's recent enforcement record as direct evidence of its priorities and capabilities.
Audit international data transfers immediately. The telecom fine showed that expired SCCs, absent Transfer Risk Assessments, and vague privacy notice language around international transfers will each attract separate findings. Map all data flows outside the EEA, confirm valid transfer mechanisms are in place, and verify they have not lapsed.
Examine embedded software components. The 2025 mobile banking case focused on a program inside a banking app that scanned the device and reported every installed application. Any mobile application, website plugin, or integrated service that may collect user data needs its own legal basis analysis and must be disclosed in app-specific privacy notices.
Protect OIB numbers as sensitive identifiers. Treat OIB numbers with the same controls you would apply to financial account numbers. Do not publish them, do not share them without legal basis, and review whether your processing of OIB numbers has a documented lawful purpose.
Establish and document data retention schedules. Both the HUO insurance case and the B2 Kapital case involved failures to define maximum retention periods. A documented retention schedule with enforcement mechanisms is a baseline GDPR obligation.
Take DPO recommendations seriously. The telecom fine explicitly noted that the company ignored its DPO's advice. Documented DPO recommendations that go unheeded will be treated as an aggravating factor in enforcement proceedings.
Fix cookie consent. Consent for storing or reading information on a user's device comes from Article 43(4) of the Electronic Communications Act, not from the GDPR implementing act, and HAKOM inspects it. Non-essential cookies and similar trackers need prior consent, and the fine band for a legal person runs from EUR 13,270 to EUR 132,720.
Prepare for AI Act compliance. Organizations deploying AI systems that use personal data in Croatia must assess whether those systems are high-risk under the AI Act and conduct fundamental rights impact assessments where required. The Article 50 transparency duties already apply; the Annex III high-risk obligations apply from 2 December 2027. AZOP has signaled engagement with AI governance as a priority.
Update privacy notices comprehensively. Multiple 2025 enforcement cases involved privacy notices that were generic, outdated, or failed to address specific processing activities. App-specific notices, workforce processing notices, and international transfer disclosures all require regular review.
Anonymous complaints are a real enforcement trigger. AZOP has imposed some of its largest fines based on anonymous reports, including USB sticks submitted by anonymous parties. Organizations should not rely on the absence of identified complainants as protection from investigation.
Disclaimer: This article provides general legal information about Croatia's data protection framework and is not legal advice. Data protection laws and enforcement practices change frequently. Consult a qualified attorney licensed in Croatia for guidance specific to your situation.
Frequently Asked Questions
What is Croatia's data protection authority?
Croatia's sole data protection authority is AZOP (Agencija za zastitu osobnih podataka), the Croatian Personal Data Protection Agency, based in Zagreb. AZOP was established in 2004 and holds full GDPR enforcement powers including the ability to conduct audits, issue orders, impose processing bans, and levy administrative fines. AZOP Director Zdravko Vukic was elected Deputy Chair of the European Data Protection Board in June 2024.
What is the largest GDPR fine ever imposed in Croatia?
The largest individual GDPR fine in Croatian history is EUR 5.47 million, imposed by AZOP in October 2023 against debt collection agency EOS Matrix d.o.o. Violations included processing personal data of 181,641 individuals (including non-debtors and minors) without a legal basis, recording health data without satisfying Article 9(2), and failing to implement adequate technical security measures. The largest fine issued in 2025 was EUR 4.5 million against an unnamed telecommunications operator for unlawful data transfers to a Serbian processor, transparency failures, and excessive employee data collection.
What special protections does Croatia give to the OIB personal identification number?
The OIB (Osobni identifikacijski broj) is an 11-digit universal identifier assigned to all Croatian citizens and residents. Because it is used across tax, healthcare, banking, and public administration, AZOP treats unauthorized OIB processing as a heightened risk. AZOP guidance tells prize-game organisers to publish no more than a winner's name and place of residence, never an OIB or a home address, and the agency imposed a EUR 2.26 million fine against B2 Kapital for processing OIB data of 77,317 individuals without authorization. Organizations must have a documented legal basis for any OIB processing.
Does Croatia have a specific age of digital consent?
Yes. Croatia set the digital consent age at 16 years, adopting the GDPR's default threshold. Children under 16 cannot independently consent to information society services and require parental or guardian authorization. Croatia did not exercise the GDPR Article 8 option to lower the threshold to 13.
What transfer mechanisms are valid for sending data from Croatia to third countries?
The standard GDPR transfer mechanisms apply: adequacy decisions from the European Commission, Standard Contractual Clauses (SCCs), Binding Corporate Rules, certification mechanisms, or applicable Article 49 derogations. Serbia, the destination in the 2025 telecom fine, has no EU adequacy decision. Organizations using SCCs must ensure they remain in force, conduct Transfer Risk Assessments before transfers begin, and clearly disclose international transfers in privacy notices.
What does Croatia's national GDPR implementing act add beyond the GDPR itself?
The Act on Implementation of the General Data Protection Regulation (NN 42/2018) sets the digital consent age at 16, bans the use of genetic data in life insurance underwriting, regulates biometric data including employee biometrics for time recording under Article 23, and sets detailed video surveillance rules with a six-month retention cap. Article 44(2) limits fines against a legal person with public authority or performing a public service so they do not jeopardize that service, and Article 47 bars any administrative fine against a public authority. The Act does not contain general employment-data rules: those are in Article 29 of the Labour Act.
How does Croatia's Schengen membership affect data protection?
Croatia joined Schengen on 1 January 2023. Schengen membership means Croatian authorities participate in shared EU data systems including the Schengen Information System (wanted persons), the Visa Information System, and the Entry/Exit System, which started operating on 12 October 2025 and became fully operational on 10 April 2026. Processing of personal data within these systems falls under Directive 2016/680 (the Law Enforcement Directive) rather than the GDPR, with AZOP maintaining oversight of Croatian authorities' compliance.
How does the EU AI Act interact with Croatian data protection law?
The EU AI Act applies directly in Croatia. Prohibited practices have applied since 2 February 2025, general-purpose AI model obligations since 2 August 2025, and the Article 50 transparency duties since the general application date of 2 August 2026. Regulation (EU) 2026/1744 moved the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, and the Article 27 fundamental rights impact assessment moves with them. Croatia designated seven Article 77(2) fundamental-rights authorities including AZOP, but has still not notified a market surveillance authority. AZOP has issued FRIA guidance, took part in the BfDI-initiated European consultation on personal data in AI models, and published a recommendation on the safe use of large language models in May 2026. Organizations using AI systems that process personal data must satisfy both GDPR and AI Act requirements simultaneously.
Updates
Corrected Croatia's enforcement figures to AZOP's published totals (38 fines worth EUR 538,200 in 2024, 13 worth EUR 6,725,500 in 2025, with 2023 the record year by value), re-attributed the employee-data rules to Article 29 of the Labour Act and the 2024 platform-work provisions, removed a prize-game enforcement action that AZOP never brought, de-named the EUR 1.5 million bank fine and noted that the decision is not final, updated the EU AI Act timeline for the 2026 Digital Omnibus and Croatia's seven designated fundamental-rights authorities, fixed the Entry/Exit System dates, and added the Article 47 bar on fining public authorities, the six-month video surveillance retention cap, and Croatia's cookie-consent rule under the Electronic Communications Act.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Accuracy corrections: added EOS Matrix d.o.o. EUR 5.47 million fine (October 2023, Croatia's record individual [GDPR](/world-laws/world-data-privacy-laws) fine); corrected telecom fine ranking to largest 2025 fine rather than all-time largest; corrected FAQ largest-fine answer; corrected AZOP source description; clarified Act 126/2025 implements the Data Governance Act (Regulation 2022/868), a separate instrument from the EU Data Act (Regulation 2023/2854).
Major expansion: added annual enforcement statistics, detail on the mobile banking application fine, an EU AI Act overlay section, EU Data Act implementation status, Schengen and eurozone data implications, and AZOP leadership at the EDPB.
Reviewed and approved by an editor
Initial publication covering AZOP enforcement, 2025 fines, OIB protections, and video surveillance rules.
Sources and References
- AZOP - National Legislation(azop.hr).gov
- AZOP - About the Agency(azop.hr).gov
- AZOP - EUR 4.5M Telecom Fine (November 2025)(azop.hr).gov
- AZOP - EUR 2.26M B2 Kapital Fine(azop.hr).gov
- AZOP - Zdravko Vukic Elected EDPB Deputy Chair(azop.hr).gov
- EDPB - B2 Kapital Fine Announcement(edpb.europa.eu).gov
- CMS Expert Guide - Croatia Data Protection(cms.law)
- OECD - Croatia OIB Documentation(oecd.org).gov
- Croatian Government - Schengen and Eurozone 2023(vlada.gov.hr).gov
- IAPP - Croatian GDPR Implementation Law(iapp.org)
- GDPRhub - HUO Insurance Bureau Decision(gdprhub.eu)
- EDPB - EOS Matrix Fine Announcement(edpb.europa.eu).gov
- AZOP - Administrative Fines by Year (2020-2025 totals)(azop.hr).gov
- AZOP - EUR 1.5 Million Administrative Fine Imposed on a Bank (18 December 2025, decision not final)(azop.hr).gov
- AZOP - EUR 5.47M EOS Matrix Fine(azop.hr).gov
- AZOP - Eight Administrative Fines Totalling EUR 350,500 (2 July 2025, incl. Croatian Insurance Bureau)(azop.hr).gov
- Zakon o provedbi Opce uredbe o zastiti podataka (NN 42/2018) - consolidated text, incl. Arts. 23, 28-32, 44 and 47(zakon.hr).gov
- Zakon o radu - Art. 29 (worker privacy) and Arts. 221.g-221.j (algorithmic management, in force 1 January 2024)(zakon.hr).gov
- Zakon o elektronickim komunikacijama (NN 76/22, 14/24, 45/26) - Art. 43(4) terminal-equipment consent, Art. 161 HAKOM inspection, Art. 170 penalties(zakon.hr).gov
- Ustav Republike Hrvatske - Arts. 35 and 37(zakon.hr).gov
- AZOP - Croatia's List of Competent Authorities under the EU AI Act (seven Article 77(2) authorities)(azop.hr).gov
- AZOP - Recommendation on the Safe Use of Large Language Models (7 May 2026)(azop.hr).gov
- European Commission - AI Act Market Surveillance Authorities and Single Points of Contact (updated 7 September 2026)(digital-strategy.ec.europa.eu).gov
- European Commission - The Entry/Exit System Will Become Fully Operational on 10 April 2026(home-affairs.ec.europa.eu).gov
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) - amends the AI Act application dates(eur-lex.europa.eu).gov