Law / Croatia

Croatia

privacy

Croatia's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by the Act on the Implementation of the General Data Protection Regulation, Narodne novine 42/18, read directly at 73,116 characters.

Articles 21 to 23 regulate biometric processing by sector: public-authority biometrics (21), private-sector biometrics requiring explicit consent for service-user identification specifically (22), and employee time-and-access biometrics permitted only where legally required or as an alternative to another method plus explicit consent (23). The gazette text read is the as-enacted 2018 issue, not a maintained consolidation, so currency past 2018 is not confirmed.

16 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

Croatian Act Articles 21-23, Biometric Data by Sector

cite Zakon o provedbi Opce uredbe o zastiti podataka, Arts. 21-23 stage In effect since 2018-05-25 source narodne-novine.nn.hr, gazette issue 42/2018, Arts. 21-23 (direct fetch, verbatim)

Croatia regulates biometric processing by sector rather than a single undifferentiated rule, read verbatim from the gazette text. Article 21 permits public-authority biometric processing only where provided by law and necessary to protect persons, property, classified data, or business secrets, or to fulfil international border-crossing identification obligations.

Article 22 permits private-sector biometric processing where prescribed by law or necessary for those same protective purposes, or for the individual, secure identification of service users, with the last purpose requiring the data subject's explicit General Data Protection Regulation (GDPR)-compliant consent as its legal basis; the other Article 22(1) grounds do not require consent on this reading.

Article 23 permits employee biometric processing for recording working time or entry to and exit from official premises where prescribed by law, or as an alternative to another solution for the same purpose, on condition the employee has given explicit consent.

What it asks of an app

Breach notification

GDPR Articles 33-34, Breach Notification

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source GDPR Arts. 33-34

A controller must notify AZOP within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. Two commentary sources confirm no Croatian-specific derogation.

What it asks of an app

Comprehensive regime

Act on the Implementation of the General Data Protection Regulation

cite Zakon o provedbi Opce uredbe o zastiti podataka, Narodne novine (Official Gazette) br. 42/18 stage In effect since 2018-05-25 source narodne-novine.nn.hr, gazette issue 42/2018 (direct fetch, verbatim

Croatia gives the General Data Protection Regulation (GDPR) domestic effect through the Act on the Implementation of the General Data Protection Regulation, Narodne novine 42/18, enacted 27 April 2018 and effective 25 May 2018, read directly at 73,116 characters, not truncated. AZOP (Agencija za zastitu osobnih podataka) is the supervisory authority.

The url read here is the as-promulgated 2018 gazette issue rather than a maintained consolidated text; this session did not find or read a procisceni tekst (consolidated version) and does not know whether the Act has been amended since 2018.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c) stage In effect since 2018-05-25 source GDPR Arts. 44-49, 83(5)(c)

A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. Two commentary sources independently confirm no further Croatian addition beyond the General Data Protection Regulation (GDPR) baseline.

What it asks of an app

Data subject rights

GDPR Article 22, Right Against Automated Individual Decision-Making

cite Regulation (EU) 2016/679, Art. 22 stage In effect since 2018-05-25 source GDPR Art. 22

Individuals in Croatia have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. Croatia's implementation act adds no Croatia-specific exemptions or extensions to Article 22 beyond what the General Data Protection Regulation (GDPR) itself provides.

What it asks of an app

Enforcement supervision

AZOP Enforcement and GDPR Article 82

cite Regulation (EU) 2016/679, Arts. 82-83 stage In effect since 2018-05-25 source GDPR Arts. 82-83

Agencija za zastitu osobnih podataka (AZOP) is Croatia's supervisory authority, entitled to impose administrative fines in line with General Data Protection Regulation (GDPR) Article 83, with no Croatian-specific enforcement addition found in this pass. GDPR Article 82 arms an individual with a direct private right of action; no distinct Croatian civil remedy or collective-redress addition was found.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.