GDPR Articles 12-21, Data Subject Rights in Croatia
Regulation (EU) 2016/679, Arts. 12-21; Zakon o provedbi Opće uredbe o zaštiti podataka (NN 42/2018)
In force since .
A data subject rights rule binding public and private bodies.
As of .
What it requires
- Honor a person's request to access, rectify, erase, restrict, port, or object to processing of their personal data in Croatia within one month of receipt.
What this law does
Under General Data Protection Regulation (GDPR) Articles 12 to 21, a person in Croatia can ask a controller for access to their personal data and for its rectification, erasure, restriction or portability, or object to its processing, and the controller must answer within one month, a period it may extend by two further months for complex or numerous requests.
The Croatian implementing Act adds no restriction on these requests that reaches a private controller: its statistics exception (Art. 33) covers only bodies producing official statistics, and Articles 34 and 35 govern complaints to the Personal Data Protection Agency and challenges to its decisions.
When LexLint raises it
When your app profile says your app crawls the web, trains models, generates content with AI, deploys a chatbot or sends automated outreach.