Skip to content

Evidence request lists

Act on the Implementation of the General Data Protection Regulation (OG 42/2018)

Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Part I - General Provisions

HR-GDPR-Art.1
Subject and Scope of the Act

The Act ensures national implementation of Regulation (EU) 2016/679 (GDPR) in Croatia. It does not apply to processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences or execution of penalties, nor to national security and defence.

Artefacts an auditor will ask for
  • Scoping assessment confirming which processing falls under the Act vs. the law-enforcement / national-security exclusions
Where this commonly fails
  • Treating law-enforcement or national-security processing as in-scope, or vice versa, leading to the wrong legal regime
HR-GDPR-Art.3
Definitions and Public Authority Bodies

Terms have the same meaning as in the GDPR. 'Public authority bodies' are defined as state administration bodies, other state bodies, and units of local and regional (territorial) self-government.

Artefacts an auditor will ask for
  • Documented determination of whether the organisation qualifies as a 'public authority body' under the Act
Where this commonly fails
  • Misclassifying public vs. private status, which changes obligations and fine exposure

Part II - Special Categories of Data Processing

HR-GDPR-Art.19
Child's Consent for Information Society Services

For GDPR Art. 6(1)(a) processing in connection with offering information society services directly to a child, processing is lawful where the child is at least 16 years old (children resident in Croatia). Acting contrary is a breach of GDPR Art. 8 and is sanctioned under GDPR Art. 83.

Artefacts an auditor will ask for
  • Age-verification mechanism
  • Parental-consent workflow for under-16s
Where this commonly fails
  • Treating under-16 consent as valid without parental authorisation
HR-GDPR-Art.20
Prohibition on Genetic Data Processing for Insurance

Processing genetic data to calculate disease probability or other health aspects in the context of concluding or performing life-insurance and survival-clause contracts is prohibited; the data subject's consent cannot lift this prohibition. Applies where the controller is established in or provides services in Croatia. Breach = GDPR Art. 9 violation, sanctioned under Art. 83(5).

Artefacts an auditor will ask for
  • Underwriting controls blocking genetic-data use in life insurance
Where this commonly fails
  • Using genetic data in life-insurance underwriting even with consent
HR-GDPR-Art.21
Biometric Data Processing - Public Sector

In public-authority bodies, biometric data may be processed only where prescribed by law and necessary to protect persons, property, classified data or business secrets, subject to a balancing test against data-subject interests. Processing is deemed lawful where needed to meet international-treaty obligations for identifying individuals crossing the state border.

Artefacts an auditor will ask for
  • Legal basis citation
  • Necessity and balancing assessment
Where this commonly fails
  • Public-sector biometric processing without statutory basis or balancing test
HR-GDPR-Art.22
Biometric Data Processing - Private Sector

In the private sector, biometric data may be processed only where prescribed by law or necessary to protect persons, property, classified data, business secrets, or for individual and secure identification of service users, subject to a balancing test. The legal basis for secure identification of service users is the explicit consent of the data subject given under the GDPR.

Artefacts an auditor will ask for
  • Explicit consent records
  • Balancing assessment
Where this commonly fails
  • Private-sector biometric processing without explicit consent or lawful necessity
HR-GDPR-Art.23
Biometric Data of Employees (Time and Access)

Processing employees' biometric data for recording working time and for entry/exit to official premises is permitted where prescribed by law, or as an alternative to another time/access solution, provided the employee gave explicit consent under the GDPR.

Artefacts an auditor will ask for
  • Employee explicit-consent records
  • Alternative (non-biometric) option offered
Where this commonly fails
  • Mandating employee biometrics without a genuine free-choice alternative
HR-GDPR-Art.24
Applicability of Biometric Rules and DPIA

The Act's biometric rules apply to data subjects in Croatia where processing is by a controller established in or serving Croatia, or by a public authority. They do not affect the obligation to carry out a data protection impact assessment under GDPR Art. 35, and do not apply to defence, national security or the security-intelligence system.

Artefacts an auditor will ask for
  • DPIA covering biometric processing
Where this commonly fails
  • Skipping the GDPR Art. 35 DPIA for biometric systems
HR-GDPR-Art.33
Processing for Statistical Purposes

Bodies producing official statistics may derogate from the rights of access, rectification, restriction and objection where necessary to achieve statistical purposes and where such rights would seriously impair them. They must apply technical and organisational protection measures, need not notify data subjects of transfers for statistics, the purpose is deemed compatible with appropriate safeguards, and the data must not permit identification of individuals.

Artefacts an auditor will ask for
  • Technical and organisational safeguards for statistical data
  • Anonymisation/de-identification controls
Where this commonly fails
  • Statistical outputs that allow re-identification
  • Claiming derogation without necessity

Part III - Video Surveillance

HR-GDPR-Art.25
Video Surveillance - Definition

Video surveillance means collecting and further processing personal data that includes creating a recording forming, or intended to form, part of a storage system. Unless another law provides otherwise, the Act's provisions apply to processing via video-surveillance systems.

Artefacts an auditor will ask for
  • Inventory of video-surveillance systems and their storage
Where this commonly fails
  • Operating cameras outside any documented data-protection regime
HR-GDPR-Art.26
Video Surveillance - Lawful Purpose

Video surveillance may be carried out only for a purpose that is necessary and justified to protect persons and property, where data-subject interests do not override it. It may cover premises, parts of premises, the building's exterior, and interior public-transport space where necessary for that purpose.

Artefacts an auditor will ask for
  • Documented purpose and necessity justification
  • Coverage map vs. purpose
Where this commonly fails
  • Surveillance beyond the protective purpose (e.g., productivity monitoring)
HR-GDPR-Art.27
Video Surveillance - Notice Requirements

The controller/processor must mark that the object, premises and exterior are under video surveillance, with the mark visible at the latest upon entering the recording perimeter. The notice must contain all relevant GDPR Art. 13 information, and in particular a simple, easily understandable image plus text informing data subjects that the area is monitored, the controller's identity, and contact details for exercising their rights.

Artefacts an auditor will ask for
  • Photographs of compliant signage at perimeter
  • Notice text mapped to GDPR Art. 13 items
Where this commonly fails
  • Missing or non-compliant surveillance signage
HR-GDPR-Art.28
Video Surveillance - Access Control and Logging

Access to video-surveillance personal data is limited to the controller/processor's responsible person and those they authorise; footage must not be used contrary to the Art. 26 purpose. The system must be protected from unauthorised access, and the controller/processor must establish an automated logging system recording the time, place and identity of persons who accessed the footage. Competent state bodies may access within their legal remit.

Artefacts an auditor will ask for
  • Access authorisation matrix
  • Automated access logs (time, place, identity)
  • System hardening evidence
Where this commonly fails
  • No access logging on the CCTV system
  • Unrestricted or unlogged footage access
HR-GDPR-Art.29
Video Surveillance - Retention Limit

Video-surveillance footage may be kept for at most six months, unless a longer retention is prescribed by another law or the footage is evidence in judicial, administrative, arbitration or equivalent proceedings.

Artefacts an auditor will ask for
  • Retention schedule with automatic deletion at six months
  • Legal-hold exceptions log
Where this commonly fails
  • Indefinite CCTV retention beyond six months without legal basis
HR-GDPR-Art.30
Video Surveillance of Work Premises

Employee video surveillance may be conducted only if occupational-safety regulation conditions are also met, employees were appropriately informed in advance, and the employer informed employees before deciding to install the system. It must not cover rest, personal-hygiene or changing rooms.

Artefacts an auditor will ask for
  • Prior employee notification records
  • Camera placement plan excluding rest/hygiene/changing areas
Where this commonly fails
  • Cameras in prohibited areas (toilets, changing rooms)
  • No prior employee consultation
HR-GDPR-Art.31
Video Surveillance in Residential Buildings

Installing video surveillance in residential or mixed residential-business buildings requires the consent of co-owners holding at least two-thirds of co-ownership shares. It may cover only entrances/exits and common areas, and must not be used to monitor the work performance of janitors, cleaners or others working in the building.

Artefacts an auditor will ask for
  • Co-owner consent (>=2/3 shares) records
  • Coverage limited to entrances and common areas
Where this commonly fails
  • Installing building CCTV without the two-thirds consent threshold
HR-GDPR-Art.32
Video Surveillance of Public Areas

Surveillance of public areas is permitted only to public-authority bodies, legal persons with public powers and legal persons performing a public service, only where prescribed by law and necessary to carry out their tasks or to protect life, health and property. This does not exclude the GDPR Art. 35 DPIA obligation for large-scale systematic monitoring of publicly accessible areas.

Artefacts an auditor will ask for
  • Statutory authorisation for public-area surveillance
  • DPIA for large-scale monitoring
Where this commonly fails
  • Private bodies monitoring public areas
  • No DPIA for large-scale public monitoring

Part IV - Supervisory Authority (AZOP)

HR-GDPR-Art.11
Prohibition on Agency Staff Acting as DPO

The Agency's director, deputy and officials must not perform the role of data protection officer for any other controller or processor (conflict-of-interest bar).

Artefacts an auditor will ask for
  • DPO appointment records showing the DPO is not AZOP staff
Where this commonly fails
  • Appointing a conflicted person as DPO
HR-GDPR-Art.13
Professional Confidentiality Obligation

The Agency's director, deputy and officials must keep all personal and other confidential data learned in their duties as professional/other secrecy under the data-secrecy law; the obligation persists after leaving office.

Artefacts an auditor will ask for
  • Confidentiality undertakings
  • Secrecy-law compliance records
Where this commonly fails
  • Disclosure of confidential information learned during supervision
HR-GDPR-Art.14
Legislative Consultation with AZOP

Central state administration and other state bodies must submit draft laws and other regulations governing personal-data processing to AZOP for expert opinion.

Artefacts an auditor will ask for
  • Records of AZOP opinions sought on draft legislation
Where this commonly fails
  • Adopting data-processing legislation without AZOP consultation
HR-GDPR-Art.15
Cooperation with Foreign Supervisory Authorities

Representatives of a guest supervisory authority may conduct joint operations (including investigations and enforcement) under an agreement with AZOP per GDPR Art. 62. Controllers, processors and data subjects directly involved must be informed before a joint operation that guest-authority representatives are taking part.

Artefacts an auditor will ask for
  • Joint-operation agreements
  • Prior-notification records to involved parties
Where this commonly fails
  • Failing to notify involved parties of guest-authority participation
HR-GDPR-Art.17
Annual Work Report

AZOP must submit an annual work report to Parliament by 31 March, with mandatory contents: number of enquiries/complaints, rulings, supervisions, breach notifications received under GDPR Art. 33, prior consultations under Art. 36, code-of-conduct/certification actions (Arts. 40-43), approved clauses (Art. 46(3)), findings/warnings/reprimands/fines/measures (Art. 58(2)), legislative opinions, EDPB activity, cooperation, awareness, and revenue/expenditure and staffing data.

Artefacts an auditor will ask for
  • Published AZOP annual reports
Where this commonly fails
  • Not applicable to controllers; institutional obligation on AZOP
HR-GDPR-Art.18
Publication of High-Risk Opinions and Decisions

AZOP rulings and opinions concerning processing types that, given nature/scope/context/purpose, may create high risk to rights and freedoms are published on AZOP's website, anonymised or pseudonymised; where they concern minors, anonymisation is applied to ensure a high level of privacy.

Artefacts an auditor will ask for
  • Anonymised/pseudonymised published decisions
Where this commonly fails
  • Publishing identifying or minor-related data contrary to anonymisation duty
HR-GDPR-Art.4
Supervisory Authority (AZOP)

The supervisory authority under GDPR Art. 51 is the Croatian Personal Data Protection Agency (AZOP), an independent state body answerable to the Croatian Parliament, seated in Zagreb.

Artefacts an auditor will ask for
  • Records of AZOP as lead/competent authority
  • Correspondence and registration with AZOP
Where this commonly fails
  • Engaging the wrong supervisory authority for Croatian establishments
HR-GDPR-Art.5
National Accreditation Body for Certification

The national accreditation body designated under Regulation (EC) 765/2008 is competent to accredit certification bodies under GDPR Art. 43(1).

Artefacts an auditor will ask for
  • Accreditation status of any certification body relied upon
Where this commonly fails
  • Relying on a certification body that is not properly accredited
HR-GDPR-Art.6
Powers and Tasks of the Agency

Beyond GDPR powers, AZOP may initiate and participate in criminal, misdemeanour, administrative and other judicial/extrajudicial proceedings for GDPR/Act breaches, sets administrative-cost fee criteria, publishes decisions, acts as the supervisory authority for the Law Enforcement Directive (EU) 2016/680, and may suspend proceedings and refer questions on Commission adequacy/standard-clause decisions to the High Administrative Court.

Artefacts an auditor will ask for
  • Evidence of cooperation with AZOP investigations and proceedings
Where this commonly fails
  • Obstructing or failing to respond to AZOP exercise of statutory powers

Part V - Remedies and Sanctions

HR-GDPR-Art.34
Right to Request Determination of Breach

Anyone who believes a right guaranteed by the Act or GDPR has been violated may file a request with AZOP for a determination of the breach. AZOP decides by ruling, which is an administrative act; no appeal lies, but an administrative dispute may be initiated before the competent administrative court.

Artefacts an auditor will ask for
  • Complaint-handling procedure referencing AZOP
  • Records of requests and AZOP rulings
Where this commonly fails
  • No internal route to support data-subject complaints to AZOP
HR-GDPR-Art.35
Interim Relief in Deletion Cases

Where a ruling orders deletion or other irreversible removal of personal data, a dissatisfied party may ask the competent administrative court to stay execution if it proves re-collection would require disproportionate effort. If granted, the party must block all processing of the disputed data, except storage, until a final court decision.

Artefacts an auditor will ask for
  • Processing-block (restriction) capability pending court decision
Where this commonly fails
  • Inability to block processing while retaining data under a stay
HR-GDPR-Art.36
Conduct of Supervision (Inspections)

Authorised AZOP officials, sometimes with guest-authority representatives, may conduct announced or unannounced supervision; for unannounced supervision the supervised party is informed at the place and time of supervision. Officials must present their official ID and supervision warrant before starting. Where obstruction is expected, AZOP may request police assistance; the warrant is issued by the AZOP director.

Artefacts an auditor will ask for
  • Inspection-readiness procedures
  • Records of cooperation with AZOP supervision
Where this commonly fails
  • Obstructing or refusing lawful AZOP inspection
HR-GDPR-Art.37
Copying, Sealing and Temporary Seizure

Authorised officials may copy available documents, image all contents of storage systems and collect other relevant information. Where copies cannot be made on site for technical reasons, they may seize the storage systems/equipment for as long as needed to make copies, up to 15 days, and may seal storage systems or equipment during supervision (up to 15 days) where there is a risk of evidence destruction or alteration. A copy of the official note is given to the supervised entity.

Artefacts an auditor will ask for
  • Custody/seizure acknowledgements
  • Official notes received from AZOP
Where this commonly fails
  • Tampering with sealed or seized systems
HR-GDPR-Art.38
Suspicion of Criminal Offence

If supervision reveals knowledge or items indicating a criminal offence prosecuted ex officio, authorised officials must promptly notify the competent police station or state attorney.

Artefacts an auditor will ask for
  • Records of criminal referrals arising from supervision
Where this commonly fails
  • Not applicable to controllers; obligation on AZOP officials
HR-GDPR-Art.39
Handling of Classified Data

Any access, copying or other processing of data classified with a secrecy level must follow the data-secrecy regulations, and must be carried out by officials holding a valid security clearance for access to classified data.

Artefacts an auditor will ask for
  • Security-clearance records for personnel accessing classified data
  • Classified-handling procedures
Where this commonly fails
  • Unauthorised handling of classified data without clearance
HR-GDPR-Art.40
Inspection Report (Zapisnik)

A report is drawn up on the supervision, stating at least: place and date; whether announced or unannounced; names and signatures of authorised persons and the supervised party's representative; description of each action and statements; list of documents/items used, copied, sealed or seized; and notice of the right to object. The supervised party may object within 15 days; a written response on acceptance follows within 15 days. No objection within the period is treated as no objection.

Artefacts an auditor will ask for
  • Signed inspection reports
  • Objection submissions and AZOP responses
Where this commonly fails
  • Missing the 15-day objection window to the inspection report
HR-GDPR-Art.41
Representation of Data Subjects

A data subject may authorise a non-profit body, organisation or association established under law, whose statute states public-interest objectives and which is active in protecting data-subject rights, to lodge a complaint on their behalf and exercise rights under GDPR Arts. 77, 78 and 79 and the right to compensation under Art. 82.

Artefacts an auditor will ask for
  • Mandates authorising representative bodies
Where this commonly fails
  • Refusing to recognise a validly mandated representative body
HR-GDPR-Art.42
Provision of Expert Opinions

On a written request by a natural or legal person, AZOP gives an expert opinion on personal-data protection within 30 days, extendable by a further 30 days where other domestic or foreign bodies must be involved to obtain necessary data.

Artefacts an auditor will ask for
  • Records of AZOP opinion requests and responses
Where this commonly fails
  • Not applicable to controllers; service obligation on AZOP
HR-GDPR-Art.43
Fees for Acting on Requests

AZOP acts free of charge for data subjects, data protection officers, journalists and public authorities. It may charge a reasonable administrative-cost fee or refuse to act where requests are manifestly unfounded or excessive (especially repetitive), and charges fees for opinions requested by business entities (law firms, consultants) for their regular activity. Fee criteria are published in the Official Gazette and on AZOP's website; fees go to the state budget.

Artefacts an auditor will ask for
  • Published fee criteria
  • Records justifying any fee charged or request refused
Where this commonly fails
  • Charging data subjects, DPOs or journalists who are entitled to free service
HR-GDPR-Art.44
Imposition of Administrative Fines

AZOP imposes administrative fines for breaches of the Act and GDPR under GDPR Art. 83. Where imposed on a legal person with public powers or performing a public service, the fine must not jeopardise the exercise of that public power or service.

Artefacts an auditor will ask for
  • Records of AZOP fine decisions and responses
Where this commonly fails
  • Not applicable as a control objective; defines enforcement exposure
HR-GDPR-Art.45
Administrative Fine Decision

Administrative fines are imposed by decision setting the amount and payment method, with possible instalments. Where fines accompany Art. 58(2)(a)-(h) and (j) GDPR measures, the fine decision is made once the measure ruling becomes final. No appeal lies, but an administrative dispute may be initiated. AZOP sets instalment criteria, published in the Official Gazette and on its website.

Artefacts an auditor will ask for
  • Fine decisions with payment terms
Where this commonly fails
  • Not applicable as a control objective; procedural
HR-GDPR-Art.46
Payment and Forced Collection of Fines

Administrative fines are paid within 15 days of the decision becoming final. On non-payment, AZOP notifies the competent regional Tax Administration office for forced collection under tax-enforcement rules. Fines go to the state budget; no interest accrues on due but unpaid fines.

Artefacts an auditor will ask for
  • Payment records
Where this commonly fails
  • Not applicable as a control objective; procedural
HR-GDPR-Art.47
Exclusion of Fines for Public Authority Bodies

Without prejudice to AZOP's GDPR Art. 58 powers, in proceedings against public-authority bodies, no administrative fine may be imposed on a public-authority body for breaches of the Act or GDPR.

Artefacts an auditor will ask for
  • Determination of public-authority status for fine-exposure assessment
Where this commonly fails
  • Assuming fine immunity without confirming public-authority-body status
HR-GDPR-Art.48
Publication of Final Rulings

A final ruling is published on AZOP's website without anonymising the offender where it establishes a breach involving minors, special categories, automated individual decision-making or profiling, where the offender is a repeat infringer, or where an administrative fine of at least HRK 100,000 has become final.

Artefacts an auditor will ask for
  • Awareness of publication exposure in breach scenarios
Where this commonly fails
  • Not applicable as a control objective; reputational consequence
HR-GDPR-Art.49
Statute of Limitations for Fine Collection

Limitation on the right to collect an administrative fine follows the general tax-procedure law; limitation runs from the date the decision becomes final and is suspended during instalment repayment.

Artefacts an auditor will ask for
  • Records of fine finality dates
Where this commonly fails
  • Not applicable as a control objective; procedural
HR-GDPR-Art.50
Misdemeanour Penalties for Confidentiality Breach

A fine of HRK 5,000 to 50,000 applies to the AZOP director, deputy or official who discloses confidential data learned in their duties to an unauthorised person, contrary to Art. 13. The state attorney is the authorised prosecutor.

Artefacts an auditor will ask for
  • Confidentiality controls for supervisory staff
Where this commonly fails
  • Not applicable to controllers; binds AZOP staff
HR-GDPR-Art.51
Administrative Fines for Video-Surveillance Violations

An administrative fine up to HRK 50,000 applies to a controller/processor who fails to mark surveillance under Art. 27, fails to establish the automated access-logging system under Art. 28(4), or whose authorised persons use footage contrary to Art. 28(2).

Artefacts an auditor will ask for
  • Evidence of Art. 27 signage and Art. 28(4) access logging in place
Where this commonly fails
  • Missing CCTV signage or access logging exposing the organisation to fines
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.