🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
HR v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing19 sources retrieved model claude-sonnet-5 · 2026-08-05

Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

Croatia

HR schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 41 claims · 28 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
41Claimsbaseline..claims[]
12Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 8 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Croatia's data-protection authority, AZOP, continued an assertive 2025-2026 enforcement run, imposing an administrative fine of EUR 100,000 on a real estate agency on 19 February 2026 for processing contrary to GDPR provisions. This is a directly confirmed enforcement action, sourced from AZOP's own publication, and it sits within a broader pattern that has AZOP reportedly imposing nearly EUR 7 million in fines during 2025, following a record EUR 10.5 million across 97 decisions in 2024. Reports of the 2025 aggregate figure are not independently corroborated by AZOP's own bulletin this cycle, so the precise 2025 total is understood rather than confirmed, but the direction and scale of the enforcement pattern are consistent across every source consulted.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fully GDPR-aligned omnibus regime with an established, active national implementing act and functioning DPA.

Primary frameworkRegulation (EU) 2016/679 (GDPR) as supplemented by the Act on the Implementation of the General Data Protection Regulation (Narodne novine 42/2018)
Traffic-light rationale — GreenFully GDPR-aligned omnibus regime with an established, active national implementing act and functioning DPA.

Sub-modules (5)

Regulator And AuthorityGreen

AZOP is confirmed as the only independent public supervisory authority in Croatia within the meaning of GDPR Article 51.

Claims (1):

  • AZOP (Agencija za zaštitu osobnih podataka) is the sole independent public supervisory authority in the Republic of Croatia within the meaning of Article 51 of the GDPR.

Act And InstrumentsGreen

The Implementation Act (NN 42/2018) is the principal domestic instrument; it also sets an advisory-fee schedule for AZOP's consultation services to commercial requesters.

Claims (2):

  • The Act on the Implementation of the General Data Protection Regulation (Narodne novine No. 42/2018) is Croatia's principal national instrument supplementing the GDPR.
  • The Implementation Act authorizes AZOP to charge fees for advisory consultations provided to business subjects such as law firms and GDPR consultants, while data subjects, DPOs, journalists and public authorities receive free consultation.

Material ScopeGreen

Material scope follows GDPR directly, with a narrow national carve-out for state statistical bodies.

Claims (1):

  • State bodies performing official state statistics activities are not required to enable data subjects to exercise access, rectification, restriction or objection rights where doing so would threaten or disable performance of statistical activities.

Territorial ScopeGreen

Territorial application of national administrative-fine provisions tracks GDPR's establishment/targeting tests for controllers with business residence or service provision in Croatia.

Claims (1):

  • Controllers bound by the Implementation Act's derogations are those having business residence or providing services in the Republic of Croatia.

Regulator Registration And FilingAmber

No general controller-registration/filing regime beyond GDPR Art 30 ROPA; state/local-government bodies are exempt from administrative fines, though public-service legal entities remain fineable within limits.

Claims (1):

  • State administrative bodies, other state bodies, and units of local and regional self-government are excluded from the charging of administrative fines, while legal entities performing public authority or public-service functions remain fineable in amounts that cannot endanger performance of those services.
Category narrative66 words

Croatia is an EU Member State applying the GDPR directly, supplemented by the national Act on the Implementation of the General Data Protection Regulation (Narodne novine No. 42/2018). The Croatian Personal Data Protection Agency (AZOP) is the sole independent supervisory authority under Article 51 GDPR. The Implementation Act adds Croatia-specific procedural rules (advisory fee schedule, statistics-body carve-outs, court-review route) without displacing GDPR's material or territorial scope.

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. ProbableEuropean Data Protection Board — AZOP (Agencija za zaštitu osobnih podataka) is the sole independent public supervisory authority in the Republic of Croatia within the meaning of Article 51 of the GDPR.observed
  2. ProbableEuropean Data Protection Board — The Act on the Implementation of the General Data Protection Regulation (Narodne novine No. 42/2018) is Croatia's principal national instrument supplementing the GDPR.observed
  3. ProbableInternational Association of Privacy Professionals — The Implementation Act authorizes AZOP to charge fees for advisory consultations provided to business subjects such as law firms and GDPR consultants, while data subjects, DPOs, journalists and public authorities receive free consultation.observed
  4. ProbableInternational Association of Privacy Professionals — State bodies performing official state statistics activities are not required to enable data subjects to exercise access, rectification, restriction or objection rights where doing so would threaten or disable performance of statistical activities.observed
  5. ProbableInternational Association of Privacy Professionals — Controllers bound by the Implementation Act's derogations are those having business residence or providing services in the Republic of Croatia.observed
  6. ProbableInternational Association of Privacy Professionals — State administrative bodies, other state bodies, and units of local and regional self-government are excluded from the charging of administrative fines, while legal entities performing public authority or public-service functions remain fineable in amounts that cannot endanger performance of those services.observed

#

GDPR baseline applies with narrow, well-documented national derogations on special categories; consent and anonymisation rely on unmodified GDPR text.

Primary frameworkGDPR Articles 6-9 as supplemented by the Implementation Act (NN 42/2018)
Supervisory authorityAZOP
Traffic-light rationale — GreenGDPR baseline applies with narrow, well-documented national derogations on special categories; consent and anonymisation rely on unmodified GDPR text.

Sub-modules (4)

Lawful BasesGreen

AZOP guidance during COVID-19 confirmed reliance on Art 6(1)(c)/(d) for employee-data processing; no other national lawful-basis derogation identified.

Claims (2):

  • AZOP confirmed that any collection of personal data during the COVID-19 pandemic requires a legal basis under GDPR Article 6(1), plus an Article 9(2) exception where sensitive data is involved.
  • AZOP concluded that processing of employees' personal data can rely on GDPR Article 6(1)(c) (legal obligation) and Article 6(1)(d) (vital interests) in the pandemic context.

Special CategoriesAmber

Two national derogations were identified: a categorical Art 9(2)(a) genetic-data prohibition for insurance risk-scoring, and a consent-free biometric-processing permission for security purposes.

Claims (2):

  • The Implementation Act derogates from Article 9(2)(a) GDPR by categorically prohibiting processing of genetic data to calculate disease-occurrence probability for life-insurance or pure-endowment contract purposes, even on the basis of explicit consent.
  • Public authorities and private entities may process biometric data without consent where necessary for protection of persons, property, classified data or business secrets, provided no prevalent opposing data-subject interests exist.

Pseudonymisation And AnonymisationAmber

No Croatia-specific statutory definition or safe-harbour beyond GDPR Articles 4(5) and 89 was found in AZOP, IAPP or DataGuidance materials searched for this run.

Category narrative48 words

Croatia applies GDPR Articles 6-9 directly. The Implementation Act adds one notable Article 9(2)(a) derogation (genetic data for life-insurance risk calculation) and a biometric-data permission for security/property-protection purposes. No Croatia-specific derogation to the general consent standard (Art 7) or to pseudonymisation/anonymisation definitions (Art 4(5), Art 89) was found.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ProbableDataGuidance — AZOP confirmed that any collection of personal data during the COVID-19 pandemic requires a legal basis under GDPR Article 6(1), plus an Article 9(2) exception where sensitive data is involved.observed
  2. ProbableDataGuidance — AZOP concluded that processing of employees' personal data can rely on GDPR Article 6(1)(c) (legal obligation) and Article 6(1)(d) (vital interests) in the pandemic context.observed
  3. ProbableEUR-Lex / Publications Office of the EU — Consent in Croatia must meet the unmodified GDPR Article 7 standard (freely given, specific, informed, unambiguous, revocable) as no national derogation to the consent standard was enacted.observed
  4. ProbableInternational Association of Privacy Professionals — The Implementation Act derogates from Article 9(2)(a) GDPR by categorically prohibiting processing of genetic data to calculate disease-occurrence probability for life-insurance or pure-endowment contract purposes, even on the basis of explicit consent.observed
  5. ProbableInternational Association of Privacy Professionals — Public authorities and private entities may process biometric data without consent where necessary for protection of persons, property, classified data or business secrets, provided no prevalent opposing data-subject interests exist.observed

#

Rights framework is GDPR-standard with narrow, documented statistics carve-out and an active regulator issuing rights-exercise guidance after incidents.

Primary frameworkGDPR Articles 13-22 as supplemented by the Implementation Act (NN 42/2018)
Supervisory authorityAZOP
Traffic-light rationale — GreenRights framework is GDPR-standard with narrow, documented statistics carve-out and an active regulator issuing rights-exercise guidance after incidents.

Sub-modules (5)

Access RightGreen

Access-right exercise is GDPR-standard; AZOP issued dedicated FAQs helping data subjects claim access/compensation after the EOS Matrix breach.

Claims (1):

  • Following the 2023 EOS Matrix breach, AZOP released FAQs guiding affected citizens on exercising GDPR rights, including claiming compensation and accessing their personal data held by EOS Matrix.

Rectification And ErasureGreen

No Croatia-specific derogation to rectification/erasure beyond the statistics carve-out was found.

Restriction And ObjectionAmber

State statistical bodies are exempted from enabling restriction/objection rights where this would impair statistical functions.

Claims (1):

  • State bodies performing official state statistics activities are exempted from enabling data subjects to exercise access, rectification, restriction-of-processing or objection rights where this would threaten or disable performance of statistical activities.

Data PortabilityAmber

No Croatia-specific derogation to GDPR Article 20 portability was identified; the unmodified GDPR right applies.

Deadlines And Response WindowsAmber

No Croatia-specific shortened/lengthened response-deadline rule was found; the GDPR one-month (extendable) default applies.

Claims (1):

  • No Croatia-specific derogation from the GDPR default one-month (extendable by two further months for complex requests) subject-access response deadline was identified.
Category narrative53 words

Data-subject rights follow GDPR Articles 13-22 directly. Croatia's principal derogation excuses state statistical bodies from certain rights where compliance would impair statistical functions, and provides a court-review (not administrative-complaint) route against AZOP decisions on rights matters. AZOP has also issued rights-exercise FAQs following major breaches. No Croatia-specific portability or deadline derogation was found.

Periodic update · new data 2026-09-28

Data Subject Rights

AZOP is understood to have fined a bank for breaching Article 15(3) of the GDPR by charging a fee for providing copies of credit documentation to a data subject, an action reported via IAPP's coverage of the regulator's enforcement record rather than confirmed directly from AZOP's own decision text. The framing of this case within IAPP's own reporting places it as one of at least two comparable cases in which AZOP has advocated for the right of access to credit documentation against banks specifically, suggesting a recurring rather than isolated enforcement focus on this particular data-subject right within the financial sector.

The substantive issue in each instance is the same: a controller charging a fee for the provision of copies under Article 15(3), where the GDPR permits a reasonable fee only in defined circumstances such as repeated requests, and treats free provision as the default expectation for a first copy. AZOP's enforcement pattern here indicates a regulator prepared to police fee-charging practices around subject access requests specifically within the banking sector, rather than treating access-right compliance as a lower-priority administrative matter.

No Croatia-specific legislative change to the access-right framework itself was located this cycle; the development here is enforcement-pattern rather than statutory. No primary AZOP decision text for either underlying case was directly retrieved, so both cases are understood at Probable confidence rather than Confirmed.

Outlook

Watch for whether AZOP extends this access-rights enforcement focus beyond banks to other sectors handling comparable documentation-heavy customer relationships, and for whether a primary AZOP decision publication becomes available to confirm the exact facts and penalty amounts in either reported case.

Sources and claims (3)
  1. ProbableDataGuidance — Following the 2023 EOS Matrix breach, AZOP released FAQs guiding affected citizens on exercising GDPR rights, including claiming compensation and accessing their personal data held by EOS Matrix.observed
  2. ProbableInternational Association of Privacy Professionals — State bodies performing official state statistics activities are exempted from enabling data subjects to exercise access, rectification, restriction-of-processing or objection rights where this would threaten or disable performance of statistical activities.observed
  3. ProbableEUR-Lex / Publications Office of the EU — No Croatia-specific derogation from the GDPR default one-month (extendable by two further months for complex requests) subject-access response deadline was identified.observed

#

Strong, evidenced enforcement record across security, breach-notification, retention and DPO duties; standard GDPR framework for ROPA/joint-controller arrangements.

Primary frameworkGDPR Articles 24-39 as supplemented by the Implementation Act (NN 42/2018)
Supervisory authorityAZOP
Traffic-light rationale — GreenStrong, evidenced enforcement record across security, breach-notification, retention and DPO duties; standard GDPR framework for ROPA/joint-controller arrangements.

Sub-modules (7)

Accountability And DpiaGreen

AZOP's 2026 Coordinated Enforcement Framework activity requires controllers, including higher-education institutions, to complete mandatory questionnaires on GDPR compliance, AI systems and transparency obligations.

Claims (1):

  • AZOP's 2026 EDPB Coordinated Enforcement Framework activity requires controllers, including higher-education institutions, to complete a mandatory questionnaire on GDPR compliance, AI systems, and Articles 12-14 transparency obligations, with responses due by 15 July 2026.

Dpo RequirementsAmber

AZOP has fined a company €12,000 for DPO-appointment violations and is running a follow-up study on DPOs to inform new guidelines.

Claims (2):

  • AZOP fined a company €12,000 for violations related to Data Protection Officer appointment obligations.
  • AZOP is conducting a follow-up research study on the role of Data Protection Officers, the findings of which will be used to create new DPO guidelines.

Ropa RequirementsAmber

No Croatia-specific derogation from GDPR Article 30 records-of-processing duties was found; the standard EU baseline applies.

Joint Controller ArrangementsAmber

No Croatia-specific joint-controller derogation was found; GDPR Article 26 applies directly.

Security MeasuresGreen

AZOP actively enforces Article 32 security-of-processing duties, evidenced by the Croatian Insurance Bureau and EOS Matrix fines.

Claims (1):

  • AZOP fined the Croatian Insurance Bureau €101,000 (part of a €350,500 total penalty package) for failing to implement adequate technical and organizational measures, violating GDPR Article 32(2) and (4), following a 2024 data leak affecting one million vehicle owners.

Breach NotificationGreen

AZOP's largest publicized enforcement action (EOS Matrix, €5.47M) arose from an anonymous-petition-triggered breach investigation rather than proactive controller self-notification, illustrating an active breach-response posture.

Claims (1):

  • AZOP fined EOS Matrix d.o.o. €5.47 million in October 2023 after an anonymous petition revealed unauthorized processing of 181,641 individuals' personal data, including lack of a legal basis for processing health data and recorded phone conversations.

Retention And DisposalGreen

Croatia caps video-surveillance data retention at six months absent proceedings-related necessity, and AZOP has fined storage-limitation (Art 5(1)(e)) violations.

Claims (2):

  • Personal data collected via video surveillance in Croatia cannot be kept longer than six months unless necessary for judicial, arbitral or similar proceedings.
  • AZOP's investigation of the Croatian Insurance Bureau found the controller had not set maximum retention periods for personal data, violating GDPR Article 5(1)(e) storage limitation.
Category narrative58 words

Controller/processor duties follow GDPR Chapter IV directly. Enforcement history shows active AZOP supervision of Article 32 security measures and Article 5(1)(e) storage limitation (Croatian Insurance Bureau, EOS Matrix), a national six-month video-surveillance retention cap, and 2026 EDPB Coordinated Enforcement Framework scrutiny of DPIA/transparency/AI-related accountability. DPO-appointment violations have been actively fined. No Croatia-specific ROPA or joint-controller derogation was found.

Periodic update · new data 2026-09-28

Controller/Processor Duties

AZOP's 2025 enforcement record is reported to treat organisational governance failures as aggravating factors in penalty calculation rather than as freestanding violations alone. In a EUR 4.5 million fine against a telecom operator, secondary reporting indicates that AZOP counted the controller's disregard of its own data protection officer's explicit warning about excessive data collection, together with a failure to adequately vet a telemarketing processor's security measures, as factors that increased the severity of the eventual penalty. This is reported via VinciWorks' analysis of the case rather than confirmed directly from AZOP's own decision text, so the finding is understood at Probable confidence.

The structural significance, if the reporting holds, is that AZOP's enforcement approach extends beyond assessing whether a breach occurred to assessing whether internal governance mechanisms, specifically DPO independence and processor due-diligence, functioned as GDPR requires. A controller that received and ignored its own DPO's warning is treated more severely than one that had no such warning at all, and a controller that failed to scrutinise a processor's security posture before engaging it is treated as having failed its own Article 28 due-diligence obligation independently of whatever the processor itself did wrong.

No primary AZOP decision document for this case was directly retrieved this cycle; the quantum, the specific aggravating-factor reasoning, and the full facts rest on CMS Law and VinciWorks secondary analysis. This is a material gap for any controller seeking to calibrate governance practice precisely against AZOP's actual enforcement reasoning.

Outlook

The question to track is whether AZOP's underlying decision becomes publicly available in full, which would allow confirmation of exactly how DPO-disregard and processor-vetting failures were weighted in the final penalty, and whether this reasoning recurs in subsequent AZOP decisions against other controllers.

Sources and claims (7)
  1. ProbableDataGuidance — AZOP's 2026 EDPB Coordinated Enforcement Framework activity requires controllers, including higher-education institutions, to complete a mandatory questionnaire on GDPR compliance, AI systems, and Articles 12-14 transparency obligations, with responses due by 15 July 2026.observed
  2. ProbableDataGuidance — AZOP fined a company €12,000 for violations related to Data Protection Officer appointment obligations.observed
  3. ProbableDataGuidance — AZOP is conducting a follow-up research study on the role of Data Protection Officers, the findings of which will be used to create new DPO guidelines.observed
  4. ProbableDataGuidance — AZOP fined the Croatian Insurance Bureau €101,000 (part of a €350,500 total penalty package) for failing to implement adequate technical and organizational measures, violating GDPR Article 32(2) and (4), following a 2024 data leak affecting one million vehicle owners.observed
  5. ProbableDataGuidance — AZOP fined EOS Matrix d.o.o. €5.47 million in October 2023 after an anonymous petition revealed unauthorized processing of 181,641 individuals' personal data, including lack of a legal basis for processing health data and recorded phone conversations.observed
  6. ProbableInternational Association of Privacy Professionals — Personal data collected via video surveillance in Croatia cannot be kept longer than six months unless necessary for judicial, arbitral or similar proceedings.observed
  7. ProbableDataGuidance — AZOP's investigation of the Croatian Insurance Bureau found the controller had not set maximum retention periods for personal data, violating GDPR Article 5(1)(e) storage limitation.observed

#

Full pass-through of the harmonized EU cross-border transfer regime; no national gaps or derogations found.

Primary frameworkGDPR Chapter V (Articles 44-49)
Supervisory authorityAZOP
Traffic-light rationale — GreenFull pass-through of the harmonized EU cross-border transfer regime; no national gaps or derogations found.

Sub-modules (6)

Transfer MechanismsGreen

Croatia relies directly on GDPR-defined mechanisms (adequacy, SCCs, BCRs, derogations) with no supplementary national instrument.

Claims (1):

  • As an EU Member State, Croatia applies GDPR Chapter V (Articles 44-49) directly for international personal-data transfers, including adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules and statutory derogations, without a separate national transfer-mechanism regime.

Adequacy ReceivedGreen

Adequacy determinations affecting Croatia are adopted at EU level by the European Commission and apply uniformly; no Croatia-specific adequacy inbound arrangement exists outside the EU Commission decisions.

Claims (1):

  • Adequacy decisions under GDPR Article 45 are adopted exclusively at EU level by the European Commission and apply uniformly across all Member States including Croatia; Croatia does not issue independent national adequacy determinations.

Adequacy GrantedGreen

Croatia does not issue independent national adequacy decisions; this is an exclusive EU Commission competence under GDPR Article 45.

Claims (1):

  • Adequacy decisions under GDPR Article 45 are adopted exclusively at EU level by the European Commission and apply uniformly across all Member States including Croatia; Croatia does not issue independent national adequacy determinations.

Sccs And BcrsGreen

Standard Contractual Clauses and Binding Corporate Rules are used under the standard EU Commission-approved forms; no Croatia-specific variant was found.

Transfer Impact AssessmentAmber

TIA practice follows the EDPB/Schrems II-derived EU baseline; no Croatia-specific TIA guidance was located in this run.

Data LocalisationAmber

No Croatia-specific data-localisation mandate was identified in AZOP, IAPP or DataGuidance materials searched for this run.

Category narrative40 words

As an EU Member State, Croatia applies GDPR Chapter V (Articles 44-49) directly and uniformly; there is no separate national adequacy, SCC/BCR or transfer-impact-assessment regime distinct from the EU-level mechanism. No Croatia-specific data-localisation mandate was identified in the sources searched.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ProbableEUR-Lex / Publications Office of the EU — As an EU Member State, Croatia applies GDPR Chapter V (Articles 44-49) directly for international personal-data transfers, including adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules and statutory derogations, without a separate national transfer-mechanism regime.observed
  2. ProbableEUR-Lex / Publications Office of the EU — Adequacy decisions under GDPR Article 45 are adopted exclusively at EU level by the European Commission and apply uniformly across all Member States including Croatia; Croatia does not issue independent national adequacy determinations.observed

#

Telecom and insurance/credit overlays are well evidenced; employment and education sectoral rules rely on unconfirmed GDPR-only baseline.

Primary frameworkGDPR plus sector overlays: Electronic Communications Act (ePrivacy); Implementation Act genetic/insurance derogation
Supervisory authorityAZOP
Traffic-light rationale — AmberTelecom and insurance/credit overlays are well evidenced; employment and education sectoral rules rely on unconfirmed GDPR-only baseline.

Sub-modules (7)

Financial Sector OverlayAmber

No dedicated banking-secrecy-vs-GDPR overlay statute was identified beyond general GDPR application to financial-sector controllers.

Health Sector OverlayAmber

The Implementation Act's genetic-data derogation intersects health data with insurance underwriting.

Claims (1):

  • Croatia prohibits processing genetic data to calculate disease-occurrence probability for life-insurance or pure-endowment contract purposes even with data-subject consent, creating a health/insurance-sector overlay on the general GDPR regime.

Telecoms And EprivacyGreen

The Electronic Communications Act, which entered into force in 2022, implements the EU ePrivacy Directive framework for Croatian telecom/electronic-communications providers, supervised by HAKOM alongside AZOP.

Claims (1):

  • Croatia's Electronic Communications Act, which entered into force in 2022, implements the EU ePrivacy Directive framework, operating alongside GDPR and supervised jointly by HAKOM and AZOP.

Employment DataAmber

No Croatia-specific employment-data code beyond GDPR Article 6(1)(c)/(d) guidance issued during COVID-19 was found.

Credit And ScoringGreen

The EOS Matrix enforcement action against a debt-collection/credit-recovery entity illustrates active AZOP supervision of credit-sector personal-data processing.

Claims (1):

  • AZOP's enforcement action against EOS Matrix, a debt-collection entity, found unlawful processing of health data and recorded phone conversations of 181,641 debtors, evidencing active credit-sector GDPR supervision.

EducationAmber

No dedicated education-sector statute was found; the 2026 CEF questionnaire specifically targets higher-education institutions under general GDPR transparency duties.

InsuranceGreen

AZOP has actively enforced against insurance-sector controllers, including a €101,000 fine on the Croatian Insurance Bureau.

Claims (1):

  • AZOP fined the Croatian Insurance Bureau €101,000 for GDPR breaches connected to a data leak from the Register of Registered Vehicles affecting one million vehicle owners' insurance-linked personal data.
Category narrative51 words

Telecoms/ePrivacy is overlaid by the Electronic Communications Act (transposing Directive 2002/58/EC) supervised jointly by HAKOM and AZOP. Insurance and credit/debt-collection sectors show active AZOP enforcement (Croatian Insurance Bureau, EOS Matrix). A genetic-data/life-insurance derogation links health and insurance sectoral rules. No Croatia-specific employment-data code or education-sector statute distinct from GDPR was found.

Periodic update · new data 2026-09-28

Sectoral Watch

Croatia's financial sector faced continued AZOP scrutiny this cycle. A bank is reported to have been fined EUR 1.5 million for processing personal data belonging to 433,922 users without a valid legal basis, arising from software embedded in the bank's mobile-banking applications. This is reported via a&s Adria Magazine rather than confirmed directly from AZOP's own decision text, placing the finding at Probable confidence, though the scale of both the fine and the affected-user count is specific enough to suggest a substantive underlying case rather than a minor administrative matter.

The legal-basis failure at the centre of this case, embedded software processing personal data absent a valid GDPR Article 6 basis, points to a recurring sectoral risk in financial-services mobile applications: third-party or embedded software components processing customer data in ways the controller bank may not have fully mapped or assessed before deployment. Separately, reporting also references a fine involving the Croatian Insurance Bureau and a sports-betting company, though the facts of that action were not independently detailed in the evidence reaching this cycle beyond its mention.

Taken together, these actions indicate AZOP maintaining active sectoral attention on financial services and gambling-adjacent industries specifically, rather than treating GDPR enforcement as evenly distributed across the economy. No primary AZOP decision text was retrieved for either action this cycle.

Outlook

Watch for confirmation of the facts underlying the Croatian Insurance Bureau and sports-betting company fine, and for whether AZOP's mobile-banking-app scrutiny extends to other banks operating comparable embedded third-party software in Croatia.

Sources and claims (4)
  1. ProbableInternational Association of Privacy Professionals — Croatia prohibits processing genetic data to calculate disease-occurrence probability for life-insurance or pure-endowment contract purposes even with data-subject consent, creating a health/insurance-sector overlay on the general GDPR regime.observed
  2. ProbableDataGuidance — Croatia's Electronic Communications Act, which entered into force in 2022, implements the EU ePrivacy Directive framework, operating alongside GDPR and supervised jointly by HAKOM and AZOP.observed
  3. ProbableDataGuidance — AZOP's enforcement action against EOS Matrix, a debt-collection entity, found unlawful processing of health data and recorded phone conversations of 181,641 debtors, evidencing active credit-sector GDPR supervision.observed
  4. ProbableDataGuidance — AZOP fined the Croatian Insurance Bureau €101,000 for GDPR breaches connected to a data leak from the Register of Registered Vehicles affecting one million vehicle owners' insurance-linked personal data.observed

#

Cookie/direct-marketing baseline is confirmed via ePrivacy transposition, but several sub-modules (dark patterns, opt-out signals, clean rooms, cross-context advertising) have no Croatia-specific instrument identified.

Primary frameworkePrivacy Directive 2002/58/EC as transposed by the Electronic Communications Act; GDPR consent baseline
Supervisory authorityAZOP
Traffic-light rationale — AmberCookie/direct-marketing baseline is confirmed via ePrivacy transposition, but several sub-modules (dark patterns, opt-out signals, clean rooms, cross-context advertising) have no Croatia-specific instrument identified.

Sub-modules (6)

Cookies And TrackersGreen

Cookie/tracker consent is governed by the ePrivacy Directive as transposed via the Electronic Communications Act, alongside GDPR consent standards.

Claims (1):

  • Cookie and tracker consent in Croatia is governed by the ePrivacy Directive (2002/58/EC) as transposed via the Electronic Communications Act, operating alongside GDPR consent standards, pending the EU's stalled ePrivacy Regulation reform.

Dark PatternsRed

No Croatia-specific dark-pattern prohibition distinct from general GDPR fairness/transparency principles was found.

Opt Out SignalsRed

No recognition of Global Privacy Control or equivalent automated opt-out signals under Croatian law was identified.

Clean Rooms And DcrRed

No Croatia-specific clean-room or data-collaboration-room rule was identified.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context-advertising concept exists under Croatian law; general GDPR consent/legitimate-interest analysis applies to any such processing.

Direct MarketingAmber

Direct marketing communications require prior opt-in consent under ePrivacy-derived rules implemented via the Electronic Communications Act, layered on GDPR Article 6 lawful-basis requirements.

Claims (1):

  • Direct-marketing electronic communications in Croatia require prior opt-in consent under ePrivacy-derived rules implemented via the Electronic Communications Act, alongside GDPR lawful-basis requirements for the underlying personal-data processing.
Category narrative71 words

Cookie/tracker and direct-marketing rules derive from the ePrivacy Directive as transposed via the Electronic Communications Act, layered on GDPR consent standards, pending the still-stalled EU ePrivacy Regulation reform (which Croatia itself unsuccessfully attempted to advance during its 2020 Council presidency). No Croatia-specific dark-pattern prohibition, Global-Privacy-Control-style opt-out-signal recognition, clean-room/data-collaboration-room rule, or CPRA-style cross-context-advertising concept was found; these are largely constructs of other jurisdictions (notably US state law) without a Croatian equivalent identified.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ProbableEUR-Lex / Publications Office of the EU — Cookie and tracker consent in Croatia is governed by the ePrivacy Directive (2002/58/EC) as transposed via the Electronic Communications Act, operating alongside GDPR consent standards, pending the EU's stalled ePrivacy Regulation reform.observed
  2. ProbableDataGuidance — Direct-marketing electronic communications in Croatia require prior opt-in consent under ePrivacy-derived rules implemented via the Electronic Communications Act, alongside GDPR lawful-basis requirements for the underlying personal-data processing.observed

#

Biometric and genetic-data rules are well documented; ADM transparency, AI-risk-assessment, and state-surveillance sub-modules rely on thin or GDPR-baseline-only evidence.

Primary frameworkGDPR Articles 9, 22 as supplemented by the Implementation Act (NN 42/2018)
Supervisory authorityAZOP
Traffic-light rationale — AmberBiometric and genetic-data rules are well documented; ADM transparency, AI-risk-assessment, and state-surveillance sub-modules rely on thin or GDPR-baseline-only evidence.

Sub-modules (6)

Profiling RestrictionsAmber

No Croatia-specific derogation from GDPR Article 22 profiling restrictions was identified; the EU baseline applies.

Automated Decision Making TransparencyAmber

AZOP's 2026 CEF questionnaire touches ADM-adjacent AI-system transparency under Articles 12-14, but no dedicated ADM-transparency statute was found.

Claims (1):

  • AZOP's 2026 Coordinated Enforcement Framework questionnaire specifically probes controllers' AI systems and their interaction with GDPR transparency obligations under Articles 12-14, signalling emerging AI-governance scrutiny absent a dedicated Croatian AI statute.

Ai Risk AssessmentsAmber

AZOP has begun probing controllers' AI systems via its 2026 coordinated-enforcement questionnaire; no dedicated Croatian AI risk-assessment statute distinct from the EU AI Act was identified.

Claims (1):

  • AZOP's 2026 Coordinated Enforcement Framework questionnaire specifically probes controllers' AI systems and their interaction with GDPR transparency obligations under Articles 12-14, signalling emerging AI-governance scrutiny absent a dedicated Croatian AI statute.

Biometric RegimeAmber

Croatia permits consent-free biometric-data processing by public authorities and private entities for protection of persons, property, classified data or business secrets, subject to a balancing test.

Claims (1):

  • Croatia permits both public authorities and private entities to process biometric data without consent for protection of persons, property, classified information, or business secrets, subject to a balancing test against data-subject interests.

Genetic DataGreen

Croatia categorically bars genetic-data processing for life-insurance/pure-endowment disease-probability calculations, disallowing even explicit-consent reliance.

Claims (1):

  • Croatia categorically prohibits processing genetic data to assess disease-occurrence probability for life-insurance or pure-endowment purposes, disallowing reliance on data-subject consent as a derogation route under Article 9(2)(a) GDPR.

State Surveillance CarveoutsRed

No Croatia-specific national-security/state-surveillance carve-out beyond the general GDPR/EU baseline was identified in the sources searched.

Category narrative70 words

Croatia applies GDPR Article 22 (profiling/ADM) directly with no national derogation found. A national biometric-processing permission and a categorical genetic-data prohibition supplement the GDPR special-categories regime. AZOP's 2026 Coordinated Enforcement Framework activity is the first documented AZOP touchpoint probing controllers' AI systems, though no dedicated Croatian AI statute (distinct from the EU AI Act) was identified. No Croatia-specific state-surveillance carve-out beyond GDPR/national-security exemptions generally applicable across the EU was found.

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

AZOP is reported to have issued guidelines for AI systems involving personal data, emphasising GDPR compliance and risk assessment as the operative framework for controllers deploying AI. The regulator is also reported to have published FAQs addressing legal bases and individual rights specifically in the AI context. Neither the guidelines nor the FAQ document was independently retrieved from a primary AZOP publication this cycle; the finding rests on DataGuidance's aggregator-level summary, which caps confidence at Uncertain rather than Probable or Confirmed.

If the reporting is accurate, this represents Croatia's first documented move toward AI-specific data-protection guidance at the national level, distinct from the general GDPR framework that already applies to any personal-data processing regardless of whether AI is involved. The content of the guidance, specifically what risk-assessment methodology AZOP recommends and how it maps GDPR legal bases onto AI use cases, is not established in the evidence reaching this cycle beyond the general description that it exists and covers these topics.

This is properly read as an emerging rather than settled governance posture. Reports suggest AZOP may have engaged in international coordination on AI and data protection questions, though the specifics of any such coordination were not corroborated by a primary source this cycle and are not asserted here beyond that caveat.

Outlook

The priority for the next reporting period is direct retrieval of AZOP's actual AI guidance document and FAQ text, which would allow this module to move from an aggregator-sourced Uncertain finding to a properly sourced Confirmed or Probable assessment of Croatia's AI-specific data-protection posture.

Sources and claims (3)
  1. ProbableDataGuidance — AZOP's 2026 Coordinated Enforcement Framework questionnaire specifically probes controllers' AI systems and their interaction with GDPR transparency obligations under Articles 12-14, signalling emerging AI-governance scrutiny absent a dedicated Croatian AI statute.observed
  2. ProbableInternational Association of Privacy Professionals — Croatia permits both public authorities and private entities to process biometric data without consent for protection of persons, property, classified information, or business secrets, subject to a balancing test against data-subject interests.observed
  3. ProbableInternational Association of Privacy Professionals — Croatia categorically prohibits processing genetic data to assess disease-occurrence probability for life-insurance or pure-endowment purposes, disallowing reliance on data-subject consent as a derogation route under Article 9(2)(a) GDPR.observed

#

Age-of-consent rule is clearly documented; parental-consent mechanics, minor-profiling bans, education-settings rules and dependent-adults protections rely on GDPR baseline or incidental enforcement evidence only.

Primary frameworkGDPR Article 8 as implemented by the Act on the Implementation of the GDPR (NN 42/2018)
Supervisory authorityAZOP
Traffic-light rationale — AmberAge-of-consent rule is clearly documented; parental-consent mechanics, minor-profiling bans, education-settings rules and dependent-adults protections rely on GDPR baseline or incidental enforcement evidence only.

Sub-modules (5)

Age VerificationGreen

Croatia sets the digital age of consent at 16 without further derogation or a lower age limit.

Claims (1):

  • Croatia's Implementation Act confirms that processing a child's personal data in relation to information-society services is lawful once the child is at least 16, without adopting a lower national age-of-consent derogation.

Minor Profiling BansAmber

No dedicated minor-profiling-ban statute was found; the 2023 EOS Matrix breach (294 minors affected among 181,641 individuals) illustrates enforcement exposure for controllers processing minors' data unlawfully.

Claims (1):

  • The 2023 EOS Matrix breach investigated by AZOP involved unauthorized processing of personal data belonging to 294 minors among 181,641 affected debtors, prompting one of AZOP's largest known GDPR fines.

Education SettingsAmber

No dedicated education-sector children's-data statute was found; AZOP's 2026 CEF questionnaire touches higher-education institutions' transparency compliance generally.

Claims (1):

  • AZOP's 2026 coordinated-enforcement questionnaire specifically targets higher-education institutions' compliance with GDPR transparency obligations, reflecting active education-sector supervisory attention.

Dependent AdultsRed

No Croatia-specific dependent-adult or vulnerable-elderly data-protection provision distinct from the GDPR baseline was identified in the sources searched for this run.

Category narrative61 words

Croatia sets the digital age of consent at 16 with no lower national derogation, meaning information-society-service processing of a child's data is lawful once the child turns 16. The EOS Matrix breach exposed 294 minors' data among affected debtors, illustrating enforcement relevance to minors even absent a bespoke minors-profiling statute. No Croatia-specific dependent-adults/vulnerable-elderly provision distinct from the GDPR baseline was found.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ProbableInternational Association of Privacy Professionals — Croatia's Implementation Act confirms that processing a child's personal data in relation to information-society services is lawful once the child is at least 16, without adopting a lower national age-of-consent derogation.observed
  2. ProbableDataGuidance — The 2023 EOS Matrix breach investigated by AZOP involved unauthorized processing of personal data belonging to 294 minors among 181,641 affected debtors, prompting one of AZOP's largest known GDPR fines.observed
  3. ProbableDataGuidance — AZOP's 2026 coordinated-enforcement questionnaire specifically targets higher-education institutions' compliance with GDPR transparency obligations, reflecting active education-sector supervisory attention.observed

#

Strong, multi-year enforcement track record and an active 2026 EDPB coordinated activity; redress route is clear via administrative courts, though collective-redress and regulator-capacity sub-modules lack confirmed detail.

Primary frameworkGDPR Articles 77-84 as supplemented by the Implementation Act (NN 42/2018)
Supervisory authorityAZOP
Traffic-light rationale — GreenStrong, multi-year enforcement track record and an active 2026 EDPB coordinated activity; redress route is clear via administrative courts, though collective-redress and regulator-capacity sub-modules lack confirmed detail.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

AZOP wields full GDPR Article 83 fining powers, supplemented by a national fine cap (up to HRK 50,000) for video-surveillance-specific violations.

Claims (1):

  • AZOP holds full GDPR Article 83 administrative-fine powers (up to €20 million or 4% of global annual turnover, whichever is higher), supplemented by a national fine cap of up to HRK 50,000 for video-surveillance-specific violations under the Implementation Act.

Enforcement Activity IndexGreen

Multiple significant fines were issued 2023-2024: €5.47M (EOS Matrix), €350,500 aggregate across eight decisions (including €101,000 against the Croatian Insurance Bureau), €12,000 (DPO violation), and €35,000 (two unnamed controllers).

Claims (3):

  • AZOP's largest publicized GDPR fine to date is the €5.47 million penalty against EOS Matrix d.o.o. in October 2023 for unlawful debt-data processing affecting 181,641 individuals.
  • AZOP imposed a combined €350,500 in fines across eight separate GDPR enforcement decisions, including the €101,000 penalty against the Croatian Insurance Bureau.
  • AZOP imposed fines totaling €35,000 on two unnamed controllers for GDPR violations.

Regulator Funding And CapacityRed

No specific AZOP budget or headcount data was located in AZOP, IAPP or DataGuidance materials searched for this run.

Collective Redress And Class ActionsRed

No Croatia-specific collective-redress or class-action mechanism for data-protection claims distinct from the EU Representative Actions Directive baseline was identified in this run.

Private Right Of ActionAmber

Data subjects have no internal administrative-appeal route against AZOP decisions on their GDPR rights but may bring a lawsuit before the competent administrative court.

Claims (1):

  • There is no internal administrative-complaint route against AZOP's decisions related to data subjects' rights, but data subjects may file a lawsuit before the competent administrative court.

Recent Developments 180DGreen

Within the last 180 days, AZOP commenced the 2026 EDPB Coordinated Enforcement Framework activity on transparency and AI-system compliance, with mandatory controller questionnaires due 15 July 2026.

Claims (1):

  • On 15 June 2026, AZOP announced commencement of the EDPB's 2026 Coordinated Enforcement Framework activity, requiring mandatory controller questionnaires on GDPR transparency (Articles 12-14) and AI-systems compliance, with responses due by 15 July 2026.
Category narrative99 words

AZOP holds full GDPR Article 83 fining powers plus national fine caps for local-law violations (e.g., video-surveillance retention up to HRK 50,000). Enforcement activity is well documented over 2023-2026: the €5.47M EOS Matrix fine (2023), a €350,500 aggregate across eight decisions including the €101,000 Croatian Insurance Bureau fine (2024), a €12,000 DPO-appointment fine, a €35,000 combined fine on two unnamed controllers, and the ongoing 2026 EDPB Coordinated Enforcement Framework activity. Redress against AZOP's rights-related decisions runs through the administrative courts rather than an internal appeal. No Croatia-specific collective-redress/class-action mechanism or granular AZOP funding/headcount data was found in this run.

Periodic update · new data 2026-09-28

Enforcement & Redress

AZOP confirmed directly, via its own website, that it imposed an administrative fine of EUR 100,000 on a real estate agency on 19 February 2026 for processing contrary to GDPR provisions. This is the single most directly evidenced enforcement action reaching this cycle, sourced from AZOP's own publication rather than secondary reporting, and it sits within a considerably larger reported enforcement pattern: AZOP is understood to have imposed nearly EUR 7 million in fines during 2025 as a whole, following what is described as a record EUR 10.5 million across 97 decisions in 2024. Both aggregate figures rest on a T4 aggregator source rather than an AZOP-published enforcement report, so they are treated as Uncertain rather than Confirmed, even though the February 2026 individual fine is itself Confirmed.

Beyond the aggregate volume, AZOP is reported to have launched a 2026 coordinated enforcement action alongside the European Data Protection Board focused on transparency, and to have opened a supervisory procedure over CARNET following a data breach affecting students and teachers. Neither the outcome of the EDPB-coordinated action nor the resolution of the CARNET procedure is established in the evidence reaching this cycle; both are open, active matters rather than concluded enforcement outcomes.

Taken as a whole, the picture is of a data-protection authority maintaining a high enforcement tempo across multiple concurrent tracks, sectoral fines, individual enforcement decisions, and participation in EU-wide coordinated actions, though the precision of the aggregate figures depends on AZOP publishing its own annual enforcement report, which was not directly retrieved this cycle.

Outlook

The outcome of the CARNET supervisory procedure and the EDPB coordinated transparency action are the two concrete developments to track into the next reporting period; either reaching a public resolution would convert an open enforcement track into a documented outcome.

Sources and claims (6)
  1. ProbableInternational Association of Privacy Professionals — AZOP holds full GDPR Article 83 administrative-fine powers (up to €20 million or 4% of global annual turnover, whichever is higher), supplemented by a national fine cap of up to HRK 50,000 for video-surveillance-specific violations under the Implementation Act.observed
  2. ProbableDataGuidance — AZOP's largest publicized GDPR fine to date is the €5.47 million penalty against EOS Matrix d.o.o. in October 2023 for unlawful debt-data processing affecting 181,641 individuals.observed
  3. ProbableDataGuidance — AZOP imposed a combined €350,500 in fines across eight separate GDPR enforcement decisions, including the €101,000 penalty against the Croatian Insurance Bureau.observed
  4. ProbableDataGuidance — AZOP imposed fines totaling €35,000 on two unnamed controllers for GDPR violations.observed
  5. ProbableInternational Association of Privacy Professionals — There is no internal administrative-complaint route against AZOP's decisions related to data subjects' rights, but data subjects may file a lawsuit before the competent administrative court.observed
  6. ProbableDataGuidance — On 15 June 2026, AZOP announced commencement of the EDPB's 2026 Coordinated Enforcement Framework activity, requiring mandatory controller questionnaires on GDPR transparency (Articles 12-14) and AI-systems compliance, with responses due by 15 July 2026.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct31.82
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Croatia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 41 claim(s) (41 category placement(s)), 28 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (21 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 8Children & Vulnerable Groupsparental consent
Art. 9Lawful Processing & Special Dataspecial categories
Art. 15Data Subject Rightsaccess right
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-14Data Subject Rightsdeadlines and response windows
Art. 16-17Data Subject Rightsrectification and erasure
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. regulator_and_framework, lawful_processing_and_special_data (special_categories), data_subject_rights, controller_processor_duties, and enforcement_and_redress achieved strong T1 (GDPR/Implementation Act/EDPB) plus T2 (IAPP, DataGuidance) coverage with multiple corroborated enforcement precedents (EOS Matrix €5.47M, Croatian Insurance Bureau €101,000/€350,500 aggregate, DPO €12,000, two-controller €35,000). cross_border_and_adequacy relies on T1 GDPR baseline reasoning (no Croatia-specific derogation exists to find, consistent with EU-harmonized Chapter V). sectoral_watch (telecoms) and adtech_and_commercial_privacy relied partly on thin T3 snippets (HAKOM/Electronic Communications Act entry-into-force) — confidence marked Probable. algorithmic_biometric_and_surveillance_governance's ai_risk_assessments sub_module rests on a single 2026 CEF news item, not a dedicated AI statute. children_and_vulnerable_groups age-of-consent is T2-confirmed (IAPP); minor_profiling_bans/education_settings rely on incidental enforcement/CEF evidence. Several sub-modules (dark_patterns, opt_out_signals, clean_rooms_and_dcr, cross_context_advertising, data_localisation, dependent_adults, regulator_funding_and_capacity, collective_redress_and_class_actions, ropa_requirements, joint_controller_arrangements, transfer_impact_assessment) carry empty claims[] with absent_field_provenance narrative noting searches run against AZOP, IAPP, and DataGuidance sources with no Croatia-specific finding.

Unresolved questions (5):

  • Does Croatia have any dedicated collective-redress/class-action mechanism for data-protection claims beyond the EU Representative Actions Directive transposition?
  • What is AZOP's current budget and headcount (regulator capacity signal)?
  • Is there a Croatia-specific data-localisation mandate for any sector (e.g., public-sector cloud, health records)?
  • Has the 2022 Electronic Communications Act been amended or supplemented by more recent HAKOM/AZOP joint guidance on cookie consent?
  • What was the exact date and full basis of the €4.5M teleoperator fine referenced only by headline in DataGuidance?

Escalate to primary-source review: yes