World Watch/Croatia/Data & Privacy

Data & Privacy · Croatia

Data protection & privacy laws in Croatia (2026)

Comprehensive lawEU General Data Protection Regulation (GDPR, Regulation 2016/679) directly applicable; national implementation via Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka, Official Gazette No. 42/2018); supervisory authority: Agencija za zaštitu osobnih podataka (AZOP)Country index 96 · A+

Croatia shaded by its data & privacy status

Croatia applies GDPR directly as an EU member state, supplemented by its 2018 national implementation act that establishes AZOP as the sole independent supervisory authority and sets out procedural rules, sector-specific carve-outs, and administrative-fine procedures. AZOP is an active enforcer — by 2025 it had issued 58 administrative fines totalling €9.1 million, placing Croatia among the EU's top-ten sanctioning authorities in 2023, and it imposed a record €4.5 million fine on a telecom operator in November 2025. The agency is also designated to supervise compliance with the EU AI Act under Article 70 thereof.

Key points

Legal Basis

GDPR (Regulation 2016/679) has direct effect across Croatia; the national Act on the Implementation of the GDPR (Official Gazette No. 42/2018, in force 25 May 2018) fills Member-State derogations, regulates AZOP's composition and powers, and sets procedural rules for administrative-fine proceedings before AZOP and administrative courts.

Supervisory Authority — AZOP

AZOP (Agencija za zaštitu osobnih podataka) is Croatia's sole independent supervisory authority under Article 51 GDPR. Its Director Zdravko Vukić was elected Vice-Chair of the European Data Protection Board in 2024. AZOP is also designated as the national market-surveillance authority for the EU AI Act.

Enforcement Record

As of 2025 AZOP had issued 58 administrative fines totalling €9.1 million. A landmark €4.5 million fine was imposed on a telecommunications operator in November 2025 for unlawful cross-border data transfers, processing identity-document copies without legal basis, and inadequate processor oversight.

National Specificities

The 2018 implementation act includes tailored rules for biometric data of employees (permitted only with consent and with a non-biometric alternative), video surveillance, children's data, and statistical processing. These national derogations operate within the GDPR's Article 9 and 88 flexibilities.

Data Subject Rights

All GDPR Chapter III rights (access, rectification, erasure, restriction, portability, objection, rights regarding automated decisions) are enforceable against Croatian controllers. AZOP publishes guidance and handles individual complaints as the competent supervisory authority.

NIS2 & AI Act Alignment

Croatia transposed the NIS2 Directive via the Cybersecurity Act (Zakon o kibernetičkoj sigurnosti, Official Gazette No. 14/2024, February 2024). AZOP is actively preparing to supervise EU AI Act obligations, having run FRIA workshops and AI-risk webinars in mid-2025.

Croatia - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →