Law note · Croatia
Croatian Act Articles 21-23, Biometric Data by Sector
Croatia regulates biometric processing by sector rather than a single undifferentiated rule, read verbatim from the gazette text. Article 21 permits public-authority biometric processing only where provided by law and necessary to protect persons, property, classified data, or business secrets, or to fulfil international border-crossing identification obligations.
Article 22 permits private-sector biometric processing where prescribed by law or necessary for those same protective purposes, or for the individual, secure identification of service users, with the last purpose requiring the data subject's explicit General Data Protection Regulation (GDPR)-compliant consent as its legal basis; the other Article 22(1) grounds do not require consent on this reading.
Article 23 permits employee biometric processing for recording working time or entry to and exit from official premises where prescribed by law, or as an alternative to another solution for the same purpose, on condition the employee has given explicit consent.
What it asks of an app
- Obtain the data subject's explicit General Data Protection Regulation (GDPR)-compliant consent before processing biometric data of a person in Croatia for the individual, secure identification of a service user, per Act Article 22(2).
- Offer a non-biometric alternative and obtain explicit consent, or rely on a legal prescription, before deploying employee biometric time-and-attendance or access-control processing in Croatia, per Act Article 23.
When LexLint raises it
Declared activities: processes_biometrics, high_risk_decisions
Primary source: narodne-novine.nn.hr, gazette issue 42/2018, Arts. 21-23 (direct fetch, verbatim)