Law / Croatia

Croatia

European Union law applies in Croatia Croatia is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Croatia, described on this page below, applies here too.

13 of 14 named instruments researched to a stage, across all six areas of law we track: 13 in force. As of 16 September 2026.

When they take effect13 of 13 carry a date. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 6 instruments (6 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 3 instruments (3 in force) 2022: 0 instruments 2023: 0 instruments 2024: 2 instruments (2 in force) 2025: 1 instrument (1 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (186 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Croatia and is not restated here as Croatian law. Croatia has added one instrument of its own. Since 24 October 2025, Kazneni zakon (Criminal Code) Article 215a makes it a criminal offence to develop, test, verify, oversee, manage or otherwise use an artificial intelligence system in a way that endangers a person's life or body, or property on a large scale, defining an AI system in the same terms as the EU AI Act.

The Zakon o autorskom pravu i srodnim pravima's Articles 187 and 188 text-and-data-mining exception, which lets AI training over online content in Croatia proceed unless a rightsholder reserves rights through a machine-readable signal, is filed under the scraping topic instead.

As of September 2026 a National Plan for the Development of Artificial Intelligence to 2032 remains at the stage of a ministerial proposal to begin drafting, and an inter-ministerial working group chaired by the Ministry of Justice and Public Administration continues drafting Croatia's own AI Act implementing legislation; neither has produced an enacted statute, so neither is recorded as an instrument here.

AI prohibited practices

Kazneni zakon Article 215a, Endangering Life and Property by an Artificial Intelligence System

Zakon o izmjenama i dopunama Kaznenog zakona, Narodne novine 136/2025, cl. 11, novi Kazneni zakon cl. 215aNarodne novine (Official Gazette) 136/2025, text of the Act amending the Criminal Code

In force 10 months, effective 13 November 2025. Binds public and private bodies.

What this law does

Article 215a of the Kazneni zakon (Criminal Code), inserted by the Act of 24 October 2025 amending the Criminal Code, criminalises developing, testing, verifying, overseeing, managing or otherwise using an artificial intelligence system in a way that creates a danger to a person's life or body, or to property on a large scale, where the conduct does not amount to a more serious offence.

The amending Act defines an artificial intelligence system in the same terms as the EU AI Act: a machine-based system of varying levels of autonomy that, from the input it receives, infers how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.

Intentional commission carries six months to five years' imprisonment and negligent commission up to three years; where the offence causes serious bodily injury or property damage of a large scale the ranges rise to one to ten years and six months to five years respectively, and where it causes one or more deaths they rise to three to fifteen years and one to eight years respectively.

What it requires

Privacy law6 instruments, 6 in force

Research summary (93 words)

Croatia's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by the Act on the Implementation of the General Data Protection Regulation, Narodne novine 42/18, read in full (73,116 characters).

Articles 21 to 23 regulate biometric processing by sector: public-authority biometrics (21), private-sector biometrics requiring explicit consent for service-user identification specifically (22), and employee time-and-access biometrics permitted only where legally required or as an alternative to another method plus explicit consent (23). The gazette text read is the as-enacted 2018 issue, not a maintained consolidation, so currency past 2018 is not confirmed.

Biometric privacy

Croatian Act Articles 21-23, Biometric Data by Sector

Zakon o provedbi Opce uredbe o zastiti podataka, Arts. 21-23narodne-novine.nn.hr, gazette issue 42/2018, Arts. 21-23 (verbatim)

In force since 25 May 2018. Binds public and private bodies.

What this law does

Croatia regulates biometric processing by sector rather than a single undifferentiated rule, read verbatim from the gazette text. Article 21 permits public-authority biometric processing only where provided by law and necessary to protect persons, property, classified data, or business secrets, or to fulfil international border-crossing identification obligations.

Article 22 permits private-sector biometric processing where prescribed by law or necessary for those same protective purposes, or for the individual, secure identification of service users, with the last purpose requiring the data subject's explicit General Data Protection Regulation (GDPR)-compliant consent as its legal basis; the other Article 22(1) grounds do not require consent on this reading.

Article 23 permits employee biometric processing for recording working time or entry to and exit from official premises where prescribed by law, or as an alternative to another solution for the same purpose, on condition the employee has given explicit consent.

What it requires

Breach notification

GDPR Articles 33-34, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34GDPR Arts. 33-34

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify AZOP within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. Two commentary sources confirm no Croatian-specific derogation.

What it requires

Comprehensive regime

Act on the Implementation of the General Data Protection Regulation

Zakon o provedbi Opce uredbe o zastiti podataka, Narodne novine (Official Gazette) br. 42/18narodne-novine.nn.hr, gazette issue 42/2018 (verbatim

In force since 25 May 2018. Binds public and private bodies.

What this law does

Croatia gives the General Data Protection Regulation (GDPR) domestic effect through the Act on the Implementation of the General Data Protection Regulation, Narodne novine 42/18, enacted 27 April 2018 and effective 25 May 2018, read in full (73,116 characters, not truncated). AZOP (Agencija za zastitu osobnih podataka) is the supervisory authority.

The cited text is the as-promulgated 2018 gazette issue rather than a consolidated text; no pročišćeni tekst (consolidated version) has been located, so whether the Act has been amended since 2018 is not established.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c)GDPR Arts. 44-49, 83(5)(c)

In force since 25 May 2018. Binds public and private bodies.

What this law does

A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. Two commentary sources independently confirm no further Croatian addition beyond the General Data Protection Regulation (GDPR) baseline.

What it requires

Data subject rights

GDPR Article 22, Right Against Automated Individual Decision-Making

Regulation (EU) 2016/679, Art. 22GDPR Art. 22

In force since 25 May 2018. Binds public and private bodies.

What this law does

Individuals in Croatia have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. Croatia's implementation act adds no Croatia-specific exemptions or extensions to Article 22 beyond what the General Data Protection Regulation (GDPR) itself provides.

What it requires

Enforcement supervision

AZOP Enforcement and GDPR Article 82

Regulation (EU) 2016/679, Arts. 82-83GDPR Arts. 82-83

In force since 25 May 2018. Binds public and private bodies.

What this law does

Agencija za zastitu osobnih podataka (AZOP) is Croatia's supervisory authority, entitled to impose administrative fines in line with General Data Protection Regulation (GDPR) Article 83, with no Croatian-specific enforcement addition found. GDPR Article 82 arms an individual with a direct private right of action; no distinct Croatian civil remedy or collective-redress addition was found.

What it requires

Scraping law2 instruments, 2 in force

Research summary (198 words)

Kazneni zakon (Criminal Code) Chapter XXV, Articles 266 to 273, is Croatia's computer-misuse framework: unauthorised access to a computer system or data, interference with a system's operation, damage to computer data, unauthorised interception, computer forgery, computer fraud, and misuse of devices are each a separate criminal offence, with enhanced penalties under Article 273 where the target is a government body, the Constitutional Court, an international organisation Croatia belongs to, a local or regional government unit, a public institution, or a company of special public interest, where the offender conceals their real identity, or where the offence is committed by a means intended to attack a larger number of computer systems or that causes significant damage.

The Zakon o autorskom pravu i srodnim pravima's Articles 187 and 188 general text-and-data-mining exception is the mechanism through which a scraper's downstream AI-training use of copyrighted material found online in Croatia proceeds without infringing copyright, subject to a rightsholder's machine-readable reservation. Personal-data protection over scraped public data falls to Croatia's privacy-topic record under the seam rule and is not restated here.

Croatia's position on terms-of-service enforceability, sui generis database rights, and unfair-competition doctrine as they apply to scraping has not been established.

Computer misuse

Kazneni zakon, Computer Crime Chapter (Arts. 266-273)

Kazneni zakon, Narodne novine 125/11, 144/12, 56/15, 61/15, 101/17, 118/18, 126/19, 84/21, Glava XXV., cl. 266-273zakon.hr, consolidated text of the Kazneni zakon (Criminal Code)

In force since 1 January 2013. Binds public and private bodies.

What this law does

Chapter XXV of the Kazneni zakon (Criminal Code) creates the criminal offences against computer systems, programs and data. Article 266 punishes unauthorised access to a computer system, part of one, or computer data, with a higher penalty where the target is a government body, the Constitutional Court, an international organisation Croatia belongs to, a local or regional government unit, a public institution, or a company of special public interest.

Article 267 punishes disabling or hindering a computer system's operation or use, or computer communication. Article 268 punishes unauthorised damage, alteration, deletion, destruction or concealment of another's computer data or programs, or blocking access to them. Article 269 punishes unauthorised interception of a non-public transmission of computer data.

Article 270 punishes computer forgery: unauthorised creation, entry, alteration, deletion or suppression of computer data with legal significance, intending it be used as genuine. Article 271 punishes computer fraud committed to obtain an unlawful material gain by manipulating computer data or a computer system's operation, with a higher penalty where a substantial gain or loss results.

Article 272 punishes making, acquiring, distributing or making available a device, program or data created or adapted to commit any of these offences, or a password or access code for the same purpose.

Article 273 raises the penalty for Articles 267 to 270 where the target is a government body, the Constitutional Court, an international organisation Croatia belongs to, a local or regional government unit, a public institution, or a company of special public interest, and for Articles 266 to 269 where the offender conceals their real identity and causes confusion about the authorised holder of that identity; it raises the penalty further, to one to eight years' imprisonment, for an offence under Articles 267 to 269 committed by a means intended to carry out an attack on a larger number of computer systems, or that causes significant damage.

What it requires

Copyright and text and data mining (TDM)

Zakon o autorskom pravu i srodnim pravima, Text and Data Mining Exceptions (Arts. 187-188)

Rudarenje teksta i podataka, Zakon o autorskom pravu i srodnim pravima, NN 111/2021, cl. 187-188Narodne novine (Official Gazette) 111/2021, text of the Copyright and Related Rights Act

In force since 22 October 2021. Binds public and private bodies.

What this law does

Croatia's Copyright and Related Rights Act creates two text-and-data-mining exceptions transposing the EU Digital Single Market Copyright Directive. Article 187 lets a research organisation or cultural heritage institution reproduce and extract from copyrighted works and databases for scientific-research text-and-data-mining without a rightsholder's authorisation or payment, and a rightsholder cannot override this by contract.

Article 188 extends the same freedom to text-and-data-mining for other purposes, including AI training, but only where the rightsholder has not expressly reserved their rights in an appropriate manner; for a work made available online, the only appropriate reservation is a machine-readable means that includes metadata.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (654 words)

Croatia transposed the NIS2 Directive (Directive (EU) 2022/2555) through the Zakon o kibernetičkoj sigurnosti (Cybersecurity Act), adopted by the Croatian Parliament on 26 January 2024, published as Narodne novine No. 14/2024, and in force from 15 February 2024 (Article 116, eighth day after publication).

The Act's Article 30 sets the risk-management measures every essential and important entity must take (risk-analysis and information-security policies, incident handling, business continuity, supply-chain security, secure development and vulnerability handling, measures-effectiveness review, basic cyber hygiene and training, cryptography, human-resources security and access control, and multi-factor or continuous authentication), and its Article 29 puts approval and oversight of those measures, plus a personal training duty, on the entity's own management body or, for a public entity, the heads of the relevant state administration or local self-government body.

The Act's Article 37 creates a general duty to notify the competent CSIRT of every significant incident and its Article 38 a duty to notify affected service recipients, but a genuine structural departure from the pattern this session confirmed across roughly a dozen other Member States is that neither article states the graduated notification clock itself: Article 44 delegates the type, content and deadlines of every notification under Articles 37 to 40 to an implementing regulation.

That regulation, the Uredba o kibernetičkoj sigurnosti (Narodne novine No. 135/2024, adopted by the Government on 21 November 2024 and in force from 30 November 2024 for the articles documented here), is what actually sets the 24-hour early warning, 72-hour initial notification (24 hours for a trust service provider), on-request interim report, and 30-day final report clock in its Articles 64 to 71, and a parallel 72-hour clock for notifying service recipients in its Article 85.

A second departure from the confirmed pattern sits in enforcement: Chapter Nine of the Act calls an Article 29, 30, 37 or 38 failure a prekršaj (misdemeanor) rather than an administrative offense the regulator sanctions directly, and Article 104 requires the competent authority to report a suspected failure to the competent state attorney, who prosecutes it as a misdemeanor before the misdemeanor court; every other Member State this session has read imposes its NIS2 fine as a direct administrative sanction.

The fine bands themselves are also expressed as two-sided ranges rather than a single ceiling: Article 101 sets an essential entity's fine at EUR 10,000 to EUR 10,000,000 or 0.5 percent to 2 percent of worldwide annual turnover, whichever amount is higher, and Article 102 sets an important entity's fine at EUR 5,000 to EUR 7,000,000 or 0.2 percent to 1.4 percent, with a further personal fine on a responsible individual under Article 29 of EUR 1,000 to 6,000 (essential entity) or EUR 500 to 3,000 (important entity).

Annex II (Prilog II, Other Critical Sectors) lists 'providers of digital services' at item 21 without a size floor of its own, and the Act's own definitions clause names a provider of an online marketplace, an online search engine, or a social networking services platform among the digital service providers it reaches; Article 10 applies the general medium-enterprise-or-larger threshold to Annex II entities to categorize them as important entities.

The wider sector classes Annexes I and II also name (energy, transport, banking, health, drinking water, digital infrastructure, public administration, manufacturing, research, education, and others) are recorded here as law the lint does not yet reach rather than flagged on a guess, since no activity in this vocabulary expresses that designation.

No Croatian instrument found here sets a product-security or market-placement duty on a manufacturer independent of the directly applicable EU Cyber Resilience Act, which is documented at the European Union level and not restated here.

No general reasonable-security or information-security-programme statute with no sector gate was found; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and the Croatian Act on the Implementation of the GDPR's own breach-notification duties to AZOP, both of which sit in this jurisdiction's privacy row rather than here.

Sector security regimes

Zakon o kibernetičkoj sigurnosti, Risk-Management Measures and Governance

Zakon o kibernetičkoj sigurnosti, Narodne novine, broj 14/2024, čl. 29. i 30.Zakon o kibernetičkoj sigurnosti

In force since 15 February 2024. Binds public and private bodies.

What this law does

Article 30 of the Cybersecurity Act requires every essential and important entity to take risk-management measures covering, at minimum, risk-analysis and information-system-security policies, incident-handling procedures including monitoring, logging and reporting, business continuity such as backup management and disaster recovery and cybersecurity-crisis management, supply-chain security including the vulnerabilities and security practices of direct suppliers and service providers, security in the acquisition, development and maintenance of network and information systems including vulnerability handling and disclosure, policies to evaluate the effectiveness of the entity's own risk-management measures, basic cyber-hygiene practices and cybersecurity training, cryptography and, where appropriate, encryption policies, human-resources security and access-control policies and asset management including regular inventory updates, and, where appropriate, multi-factor or continuous authentication, secured voice, video and text communications, and secure emergency communication systems.

Article 29 makes the members of an essential or important entity's management body, or the heads of the relevant state administration body, other state body, or local and regional self-government executive body for a public entity, responsible for implementing these measures: they must approve the risk-management measures the entity applies and control their implementation, and they must themselves attend appropriate training on risk-management issues and its effect on the entity's services, and make the same training available to the entity's staff.

Both articles transpose NIS2 Articles 21 and 20 respectively. Annex II (Prilog II, Other Critical Sectors) lists 'providers of digital services' at item 21. The Act's own definitions clause names a provider of an online marketplace, an online search engine, or a social networking services platform among the digital service providers it reaches.

What it requires

Vulnerability and incident reporting

Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting Obligations

Zakon o kibernetičkoj sigurnosti Narodne novine, broj 14/2024, čl. 37.-44.; Uredba o kibernetičkoj sigurnosti, Narodne novine, broj 135/2024, čl. 64.-71. i 85.Zakon o kibernetičkoj sigurnosti (Narodne novine 14/2024) and Uredba o kibernetičkoj sigurnosti (Narodne novine 135/2024, adopted by the…

In force since 30 November 2024. Binds public and private bodies.

What this law does

Article 37 of the Cybersecurity Act requires every essential and important entity to notify the competent CSIRT of every incident with a significant effect on the availability, integrity, confidentiality or authenticity of data material to the entity's business or on the continuity of the services it provides (a significant incident), and Article 38 requires it to notify the recipients of its services of a significant incident likely to affect them and, on a serious cyber threat, of protective measures or remedies those recipients can take.

Neither article states the notification clock itself: Article 44 delegates the criteria for a significant incident, the type and content of every notification under Articles 37 to 40, and the deadlines for their submission to the implementing regulation Article 24 authorizes. That regulation, the Cybersecurity Regulation (Narodne novine No. 135/2024), sets the clock in its Articles 64 to 71.

An early warning to the competent CSIRT is due without delay and no later than 24 hours after becoming aware of a significant incident (Article 66). An initial notification is due no later than 72 hours (Article 67), or 24 hours instead for a trust service provider (Article 68). An interim report is due on the CSIRT's request, within a period the CSIRT sets of 48 hours to 7 days (Article 69).

A final report is due no later than 30 days after the initial notification (Article 70), or, where the incident is still ongoing at that point, a progress report in its place, repeated every 30 days once the incident has run past 60 days, followed by a final report within 30 days of the last progress report (Article 71).

The Regulation's Article 85 sets a parallel 72-hour clock, running from the entity's own awareness of the incident, for notifying affected service recipients under the Act's Article 38. Article 37(4) and Article 38(3) of the Act each separately give a newly categorized entity 30 days from the date it receives its Article 19(1) categorization notice before these notification duties bind it, a grace period distinct from the per-incident clock the Regulation sets.

The same Chapter Nine penalty structure documented on this jurisdiction's companion risk-management-and-governance row applies to a reporting failure: an essential entity's fine of EUR 10,000 to EUR 10,000,000 or 0.5 to 2 percent of worldwide turnover, an important entity's fine of EUR 5,000 to EUR 7,000,000 or 0.2 to 1.4 percent, whichever is higher in each case, referred by the competent authority to the competent state attorney for misdemeanor prosecution rather than imposed directly.

What it requires

Age gating law1 instrument, 1 in force

Research summary (121 words)

Croatia's Zakon o elektroničkim medijima (Electronic Media Act), Narodne novine 111/2021, in force since 22 October 2021, requires an audiovisual media, radio or electronic-publication service to withhold content likely to harm a minor's physical, mental or moral development from Croatian audiences unless it uses scheduling, age-verification tools or another technical measure to keep minors from ordinarily seeing or hearing it, per Article 24.

A provider of a video-sharing platform under Croatian jurisdiction must additionally establish and apply an age-verification system for platform users regarding content that could harm a minor's psychological, physical or moral development, alongside flagging, reporting and content-rating tools, per Article 96. A minor's digital-consent age for personal-data processing is the subject of Croatia's privacy record, not this one.

Age-appropriate design code

Zakon o elektroničkim medijima, Minor Protection and Video-Sharing-Platform Age Verification (Arts. 24, 96)

Zakon o elektronickim medijima, Narodne novine 111/2021, cl. 24, 96Narodne novine (Official Gazette) 111/2021, text of the Electronic Media Act

In force since 22 October 2021. Binds public and private bodies.

What this law does

Article 24 forbids publishing audiovisual media service, radio programme, or electronic publication content likely to seriously harm a minor's physical, mental or moral development, and forbids publishing content that could harm that development at all unless the provider secures, through scheduling, age-verification tools, or another technical measure, that minors within the transmission's reach will not ordinarily see or hear it.

Article 96 requires a provider of a video-sharing platform under Croatian jurisdiction to take appropriate measures protecting minors from user-generated video and audiovisual commercial communications that could harm their physical, mental or moral development; for content causing the greatest harm, those measures include, among others, establishing and applying an age-verification system for platform users, alongside flagging and reporting mechanisms, functionality for users to declare whether their uploaded videos contain audiovisual commercial communications, and easy-to-use content-rating tools.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (189 words)

Croatia transposed the EU Digital Single Market Copyright Directive's press-publisher neighbouring right through the Zakon o autorskom pravu i srodnim pravima (Copyright and Related Rights Act), Narodne novine 111/2021, in force since 22 October 2021.

Articles 165 and 166 give a press publisher established in the EU an exclusive reproduction, distribution, communication-to-the-public and adaptation right, with a separate right specifically against an information-society service provider's online use of its information publications, exempting an individual's private and non-commercial use, hyperlinking, and the use of individual words or very short extracts that do not affect the right's effectiveness.

The Article 165 right lasts ten years and the Article 166 right two years from the information publication's first lawful publication, per Article 171. The same Act's Articles 187 and 188 general text-and-data-mining exception, recorded under this jurisdiction's scraping-topic record, also lets an aggregator's automated indexing of Croatian online content proceed unless the rightsholder has reserved their rights through a machine-readable signal.

No compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act, and no hot-news or misappropriation doctrine distinct from ordinary unfair-competition law, has been located.

Press publishers' right

Zakon o autorskom pravu i srodnim pravima, Pravo nakladnika informativnih publikacija (Arts. 165-166, 170-172)

Pravo nakladnika informativnih publikacija, Zakon o autorskom pravu i srodnim pravima, NN 111/2021, cl. 165-166, 170-172Narodne novine (Official Gazette) 111/2021, text of the Copyright and Related Rights Act

In force since 22 October 2021. Binds private bodies.

What this law does

A publisher of information publications established in the EU holds exclusive reproduction, distribution, communication-to-the-public and adaptation rights over its information publications against ordinary users, per Article 165, and a separate exclusive reproduction and communication-to-the-public right specifically against an information-society service provider's online use, per Article 166.

Article 166(3) exempts an individual user's private and non-commercial use, hyperlinking, and the use of individual words or very short extracts of no more than a few words that carry no photograph or video and do not affect the effectiveness of the exclusive rights.

The Article 165 right against ordinary users lasts ten years from the information publication's first lawful publication, and the Article 166 right against information-society service providers lasts two years from the same event, per Article 171.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.