AZOP Enforcement and GDPR Article 82
Regulation (EU) 2016/679, Arts. 82-83
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
An enforcement supervision rule binding public and private bodies.
As of 2 September 2026.
What it requires
- Expect AZOP to have General Data Protection Regulation (GDPR) Article 83 fining power over your processing of personal data of a person in Croatia.
- Expect any person in Croatia who suffered material or non-material damage from an infringement to have a direct GDPR Article 82 right to compensation from you as controller or processor.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Article 146 of the Croatian Criminal Code (Kazneni zakon), Nedozvoljena uporaba osobnih podataka (unauthorized use of personal data), makes it an offense to collect, process, or use personal data of a natural person contrary to the conditions set by law, punishable by up to one year of imprisonment for the basic offense. The maximum rises to three years where the data is exported from Croatia for further processing, published, or otherwise made accessible, where the offender gains significant material benefit or causes significant damage, where the offense is committed against a child, or where the personal data processed is a special category (racial or ethnic origin, political opinion, religious or other belief, trade union membership, health, sex life or sexual orientation, or data on criminal or misdemeanor proceedings). The maximum rises again, to between six months and five years, where the offense is committed by an official person in the performance of their duty or a responsible person exercising public authority. This offense is separate from AZOP's Article 83 administrative fining power and from an individual's Article 82 civil claim.
Penalty structure
Article 83(5) sets the higher administrative-fine tier, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher, for infringements of the provisions listed in Article 83(5)(a) to (e), including non-compliance with a supervisory-authority order under Article 58. A lower Article 83(4) tier also exists, up to EUR 10,000,000 or 2 percent of turnover, for the controller and processor obligations in Articles 8, 11, 25 to 39, 42 and 43. Croatia's own implementation act, the Act on the Implementation of the General Data Protection Regulation (Narodne novine 42/18), sets no Croatia-specific fine cap of its own for a controller or processor; its own separate misdemeanor provision (Art. 50) penalizes only an AZOP director, deputy director, or official who discloses confidential information learned in the course of duty, a different offense from a controller's or processor's own GDPR breach.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Agencija za zastitu osobnih podataka (AZOP), Croatia's supervisory authority under GDPR Article 51, designated by the Act on the Implementation of the General Data Protection Regulation (Narodne novine 42/18).
Enforcement record
AZOP's own published register of administrative monetary fines states that, as of the page's own to-date count, the Agency has imposed 97 administrative fines totalling approximately EUR 10.5 million since the GDPR became applicable, and that the highest single fine imposed to date was EUR 5.47 million, against a debt-collection agency for serious infringements. actions_per_year is left unrecorded rather than estimated from this cumulative total: the page states that a year-by-year breakdown of fines is available at a separate link ('Na poveznici dostupne su upravne novcane kazne po godinama'), but does not itself give that link's address or a per-year count. Leaving the field blank means base_rate_band derives as unrated (null) rather than a wrong band read off a multi-year cumulative figure; AZOP's own annual activity report (Godisnja izvjesca o radu) or the by-year breakdown page would carry the current year's actions_per_year. fines_per_year, median_fine and p90_fine are likewise not established from AZOP's published register alone. This is the regime's own enforcement record in Croatia as a whole, not specific to this instrument's provisions alone.
- As of
- 2 September 2026
- Currency
- EUR
- Source link
- https://azop.hr/upravne-novcane-kazne
- Total fines
- 10,500,000
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Agencija za zastitu osobnih podataka (AZOP) is Croatia's supervisory authority, entitled to impose administrative fines in line with General Data Protection Regulation (GDPR) Article 83, with no Croatian-specific enforcement addition found. GDPR Article 82 arms an individual with a direct private right of action; no distinct Croatian civil remedy or collective-redress addition was found.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
GDPR Arts. 82-83
CMS and DLA Piper commentary
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.