Act on the Implementation of the General Data Protection Regulation (OG 42/2018)
Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Part I - General Provisions
The Act ensures national implementation of Regulation (EU) 2016/679 (GDPR) in Croatia. It does not apply to processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences or execution of penalties, nor to national security and defence.
- Scoping assessment confirming which processing falls under the Act vs. the law-enforcement / national-security exclusions
- Treating law-enforcement or national-security processing as in-scope, or vice versa, leading to the wrong legal regime
Terms have the same meaning as in the GDPR. 'Public authority bodies' are defined as state administration bodies, other state bodies, and units of local and regional (territorial) self-government.
- Documented determination of whether the organisation qualifies as a 'public authority body' under the Act
- Misclassifying public vs. private status, which changes obligations and fine exposure
Part II - Special Categories of Data Processing
For GDPR Art. 6(1)(a) processing in connection with offering information society services directly to a child, processing is lawful where the child is at least 16 years old (children resident in Croatia). Acting contrary is a breach of GDPR Art. 8 and is sanctioned under GDPR Art. 83.
- Age-verification mechanism
- Parental-consent workflow for under-16s
- Treating under-16 consent as valid without parental authorisation
Processing genetic data to calculate disease probability or other health aspects in the context of concluding or performing life-insurance and survival-clause contracts is prohibited; the data subject's consent cannot lift this prohibition. Applies where the controller is established in or provides services in Croatia. Breach = GDPR Art. 9 violation, sanctioned under Art. 83(5).
- Underwriting controls blocking genetic-data use in life insurance
- Using genetic data in life-insurance underwriting even with consent
In public-authority bodies, biometric data may be processed only where prescribed by law and necessary to protect persons, property, classified data or business secrets, subject to a balancing test against data-subject interests. Processing is deemed lawful where needed to meet international-treaty obligations for identifying individuals crossing the state border.
- Legal basis citation
- Necessity and balancing assessment
- Public-sector biometric processing without statutory basis or balancing test
In the private sector, biometric data may be processed only where prescribed by law or necessary to protect persons, property, classified data, business secrets, or for individual and secure identification of service users, subject to a balancing test. The legal basis for secure identification of service users is the explicit consent of the data subject given under the GDPR.
- Explicit consent records
- Balancing assessment
- Private-sector biometric processing without explicit consent or lawful necessity
Processing employees' biometric data for recording working time and for entry/exit to official premises is permitted where prescribed by law, or as an alternative to another time/access solution, provided the employee gave explicit consent under the GDPR.
- Employee explicit-consent records
- Alternative (non-biometric) option offered
- Mandating employee biometrics without a genuine free-choice alternative
The Act's biometric rules apply to data subjects in Croatia where processing is by a controller established in or serving Croatia, or by a public authority. They do not affect the obligation to carry out a data protection impact assessment under GDPR Art. 35, and do not apply to defence, national security or the security-intelligence system.
- DPIA covering biometric processing
- Skipping the GDPR Art. 35 DPIA for biometric systems
Bodies producing official statistics may derogate from the rights of access, rectification, restriction and objection where necessary to achieve statistical purposes and where such rights would seriously impair them. They must apply technical and organisational protection measures, need not notify data subjects of transfers for statistics, the purpose is deemed compatible with appropriate safeguards, and the data must not permit identification of individuals.
- Technical and organisational safeguards for statistical data
- Anonymisation/de-identification controls
- Statistical outputs that allow re-identification
- Claiming derogation without necessity
Part III - Video Surveillance
Video surveillance means collecting and further processing personal data that includes creating a recording forming, or intended to form, part of a storage system. Unless another law provides otherwise, the Act's provisions apply to processing via video-surveillance systems.
- Inventory of video-surveillance systems and their storage
- Operating cameras outside any documented data-protection regime
Video surveillance may be carried out only for a purpose that is necessary and justified to protect persons and property, where data-subject interests do not override it. It may cover premises, parts of premises, the building's exterior, and interior public-transport space where necessary for that purpose.
- Documented purpose and necessity justification
- Coverage map vs. purpose
- Surveillance beyond the protective purpose (e.g., productivity monitoring)
The controller/processor must mark that the object, premises and exterior are under video surveillance, with the mark visible at the latest upon entering the recording perimeter. The notice must contain all relevant GDPR Art. 13 information, and in particular a simple, easily understandable image plus text informing data subjects that the area is monitored, the controller's identity, and contact details for exercising their rights.
- Photographs of compliant signage at perimeter
- Notice text mapped to GDPR Art. 13 items
- Missing or non-compliant surveillance signage
Access to video-surveillance personal data is limited to the controller/processor's responsible person and those they authorise; footage must not be used contrary to the Art. 26 purpose. The system must be protected from unauthorised access, and the controller/processor must establish an automated logging system recording the time, place and identity of persons who accessed the footage. Competent state bodies may access within their legal remit.
- Access authorisation matrix
- Automated access logs (time, place, identity)
- System hardening evidence
- No access logging on the CCTV system
- Unrestricted or unlogged footage access
Video-surveillance footage may be kept for at most six months, unless a longer retention is prescribed by another law or the footage is evidence in judicial, administrative, arbitration or equivalent proceedings.
- Retention schedule with automatic deletion at six months
- Legal-hold exceptions log
- Indefinite CCTV retention beyond six months without legal basis
Employee video surveillance may be conducted only if occupational-safety regulation conditions are also met, employees were appropriately informed in advance, and the employer informed employees before deciding to install the system. It must not cover rest, personal-hygiene or changing rooms.
- Prior employee notification records
- Camera placement plan excluding rest/hygiene/changing areas
- Cameras in prohibited areas (toilets, changing rooms)
- No prior employee consultation
Installing video surveillance in residential or mixed residential-business buildings requires the consent of co-owners holding at least two-thirds of co-ownership shares. It may cover only entrances/exits and common areas, and must not be used to monitor the work performance of janitors, cleaners or others working in the building.
- Co-owner consent (>=2/3 shares) records
- Coverage limited to entrances and common areas
- Installing building CCTV without the two-thirds consent threshold
Surveillance of public areas is permitted only to public-authority bodies, legal persons with public powers and legal persons performing a public service, only where prescribed by law and necessary to carry out their tasks or to protect life, health and property. This does not exclude the GDPR Art. 35 DPIA obligation for large-scale systematic monitoring of publicly accessible areas.
- Statutory authorisation for public-area surveillance
- DPIA for large-scale monitoring
- Private bodies monitoring public areas
- No DPIA for large-scale public monitoring
Part IV - Supervisory Authority (AZOP)
The Agency's director, deputy and officials must not perform the role of data protection officer for any other controller or processor (conflict-of-interest bar).
- DPO appointment records showing the DPO is not AZOP staff
- Appointing a conflicted person as DPO
The Agency's director, deputy and officials must keep all personal and other confidential data learned in their duties as professional/other secrecy under the data-secrecy law; the obligation persists after leaving office.
- Confidentiality undertakings
- Secrecy-law compliance records
- Disclosure of confidential information learned during supervision
Central state administration and other state bodies must submit draft laws and other regulations governing personal-data processing to AZOP for expert opinion.
- Records of AZOP opinions sought on draft legislation
- Adopting data-processing legislation without AZOP consultation
Representatives of a guest supervisory authority may conduct joint operations (including investigations and enforcement) under an agreement with AZOP per GDPR Art. 62. Controllers, processors and data subjects directly involved must be informed before a joint operation that guest-authority representatives are taking part.
- Joint-operation agreements
- Prior-notification records to involved parties
- Failing to notify involved parties of guest-authority participation
AZOP must submit an annual work report to Parliament by 31 March, with mandatory contents: number of enquiries/complaints, rulings, supervisions, breach notifications received under GDPR Art. 33, prior consultations under Art. 36, code-of-conduct/certification actions (Arts. 40-43), approved clauses (Art. 46(3)), findings/warnings/reprimands/fines/measures (Art. 58(2)), legislative opinions, EDPB activity, cooperation, awareness, and revenue/expenditure and staffing data.
- Published AZOP annual reports
- Not applicable to controllers; institutional obligation on AZOP
AZOP rulings and opinions concerning processing types that, given nature/scope/context/purpose, may create high risk to rights and freedoms are published on AZOP's website, anonymised or pseudonymised; where they concern minors, anonymisation is applied to ensure a high level of privacy.
- Anonymised/pseudonymised published decisions
- Publishing identifying or minor-related data contrary to anonymisation duty
The supervisory authority under GDPR Art. 51 is the Croatian Personal Data Protection Agency (AZOP), an independent state body answerable to the Croatian Parliament, seated in Zagreb.
- Records of AZOP as lead/competent authority
- Correspondence and registration with AZOP
- Engaging the wrong supervisory authority for Croatian establishments
The national accreditation body designated under Regulation (EC) 765/2008 is competent to accredit certification bodies under GDPR Art. 43(1).
- Accreditation status of any certification body relied upon
- Relying on a certification body that is not properly accredited
Beyond GDPR powers, AZOP may initiate and participate in criminal, misdemeanour, administrative and other judicial/extrajudicial proceedings for GDPR/Act breaches, sets administrative-cost fee criteria, publishes decisions, acts as the supervisory authority for the Law Enforcement Directive (EU) 2016/680, and may suspend proceedings and refer questions on Commission adequacy/standard-clause decisions to the High Administrative Court.
- Evidence of cooperation with AZOP investigations and proceedings
- Obstructing or failing to respond to AZOP exercise of statutory powers
Part V - Remedies and Sanctions
Anyone who believes a right guaranteed by the Act or GDPR has been violated may file a request with AZOP for a determination of the breach. AZOP decides by ruling, which is an administrative act; no appeal lies, but an administrative dispute may be initiated before the competent administrative court.
- Complaint-handling procedure referencing AZOP
- Records of requests and AZOP rulings
- No internal route to support data-subject complaints to AZOP
Where a ruling orders deletion or other irreversible removal of personal data, a dissatisfied party may ask the competent administrative court to stay execution if it proves re-collection would require disproportionate effort. If granted, the party must block all processing of the disputed data, except storage, until a final court decision.
- Processing-block (restriction) capability pending court decision
- Inability to block processing while retaining data under a stay
Authorised AZOP officials, sometimes with guest-authority representatives, may conduct announced or unannounced supervision; for unannounced supervision the supervised party is informed at the place and time of supervision. Officials must present their official ID and supervision warrant before starting. Where obstruction is expected, AZOP may request police assistance; the warrant is issued by the AZOP director.
- Inspection-readiness procedures
- Records of cooperation with AZOP supervision
- Obstructing or refusing lawful AZOP inspection
Authorised officials may copy available documents, image all contents of storage systems and collect other relevant information. Where copies cannot be made on site for technical reasons, they may seize the storage systems/equipment for as long as needed to make copies, up to 15 days, and may seal storage systems or equipment during supervision (up to 15 days) where there is a risk of evidence destruction or alteration. A copy of the official note is given to the supervised entity.
- Custody/seizure acknowledgements
- Official notes received from AZOP
- Tampering with sealed or seized systems
If supervision reveals knowledge or items indicating a criminal offence prosecuted ex officio, authorised officials must promptly notify the competent police station or state attorney.
- Records of criminal referrals arising from supervision
- Not applicable to controllers; obligation on AZOP officials
Any access, copying or other processing of data classified with a secrecy level must follow the data-secrecy regulations, and must be carried out by officials holding a valid security clearance for access to classified data.
- Security-clearance records for personnel accessing classified data
- Classified-handling procedures
- Unauthorised handling of classified data without clearance
A report is drawn up on the supervision, stating at least: place and date; whether announced or unannounced; names and signatures of authorised persons and the supervised party's representative; description of each action and statements; list of documents/items used, copied, sealed or seized; and notice of the right to object. The supervised party may object within 15 days; a written response on acceptance follows within 15 days. No objection within the period is treated as no objection.
- Signed inspection reports
- Objection submissions and AZOP responses
- Missing the 15-day objection window to the inspection report
A data subject may authorise a non-profit body, organisation or association established under law, whose statute states public-interest objectives and which is active in protecting data-subject rights, to lodge a complaint on their behalf and exercise rights under GDPR Arts. 77, 78 and 79 and the right to compensation under Art. 82.
- Mandates authorising representative bodies
- Refusing to recognise a validly mandated representative body
On a written request by a natural or legal person, AZOP gives an expert opinion on personal-data protection within 30 days, extendable by a further 30 days where other domestic or foreign bodies must be involved to obtain necessary data.
- Records of AZOP opinion requests and responses
- Not applicable to controllers; service obligation on AZOP
AZOP acts free of charge for data subjects, data protection officers, journalists and public authorities. It may charge a reasonable administrative-cost fee or refuse to act where requests are manifestly unfounded or excessive (especially repetitive), and charges fees for opinions requested by business entities (law firms, consultants) for their regular activity. Fee criteria are published in the Official Gazette and on AZOP's website; fees go to the state budget.
- Published fee criteria
- Records justifying any fee charged or request refused
- Charging data subjects, DPOs or journalists who are entitled to free service
AZOP imposes administrative fines for breaches of the Act and GDPR under GDPR Art. 83. Where imposed on a legal person with public powers or performing a public service, the fine must not jeopardise the exercise of that public power or service.
- Records of AZOP fine decisions and responses
- Not applicable as a control objective; defines enforcement exposure
Administrative fines are imposed by decision setting the amount and payment method, with possible instalments. Where fines accompany Art. 58(2)(a)-(h) and (j) GDPR measures, the fine decision is made once the measure ruling becomes final. No appeal lies, but an administrative dispute may be initiated. AZOP sets instalment criteria, published in the Official Gazette and on its website.
- Fine decisions with payment terms
- Not applicable as a control objective; procedural
Administrative fines are paid within 15 days of the decision becoming final. On non-payment, AZOP notifies the competent regional Tax Administration office for forced collection under tax-enforcement rules. Fines go to the state budget; no interest accrues on due but unpaid fines.
- Payment records
- Not applicable as a control objective; procedural
Without prejudice to AZOP's GDPR Art. 58 powers, in proceedings against public-authority bodies, no administrative fine may be imposed on a public-authority body for breaches of the Act or GDPR.
- Determination of public-authority status for fine-exposure assessment
- Assuming fine immunity without confirming public-authority-body status
A final ruling is published on AZOP's website without anonymising the offender where it establishes a breach involving minors, special categories, automated individual decision-making or profiling, where the offender is a repeat infringer, or where an administrative fine of at least HRK 100,000 has become final.
- Awareness of publication exposure in breach scenarios
- Not applicable as a control objective; reputational consequence
Limitation on the right to collect an administrative fine follows the general tax-procedure law; limitation runs from the date the decision becomes final and is suspended during instalment repayment.
- Records of fine finality dates
- Not applicable as a control objective; procedural
A fine of HRK 5,000 to 50,000 applies to the AZOP director, deputy or official who discloses confidential data learned in their duties to an unauthorised person, contrary to Art. 13. The state attorney is the authorised prosecutor.
- Confidentiality controls for supervisory staff
- Not applicable to controllers; binds AZOP staff
An administrative fine up to HRK 50,000 applies to a controller/processor who fails to mark surveillance under Art. 27, fails to establish the automated access-logging system under Art. 28(4), or whose authorised persons use footage contrary to Art. 28(2).
- Evidence of Art. 27 signage and Art. 28(4) access logging in place
- Missing CCTV signage or access logging exposing the organisation to fines
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.