Employment law and GDPR in Croatia checklist

  1. Laws

1.1. Laws and regulations

1.1.1. What laws and/or regulations apply to data protection in the employment context?

As a general act on personal data processing, the General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR) became effective on May 25, 2018. Article 6 of the GDPR prescribes six legal grounds for personal data processing. Article 9 of the GDPR provides exemptions from the prohibition on the processing of special categories of personal data.

Therefore, if the processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law, in so far as it is authorized by European Union or Member State law, or a collective agreement pursuant to Member State law providing for appropriate safeguards for the fundamental rights and the interests of the data subject.

The main law regarding employees is the Labor Law (only available in Croatian here) (the Labor Law). The Labor Law has a special provision on the privacy of employees and recommends that any data processing and/or transfers of personal data shall be described in the labor regulation of an employer. An employer that hires at least 20 employees must appoint a person in charge of supervising the processing of employees’ personal data.

Citation

Articles 6 and 9 of the GDPR

Article 23 of the Law on the Implementation of the General Data Protection Regulation 2018 (only available in Croatian here) (the Law)

Article 29 of the Labor Law

1.2. Supervisory authority

1.2.1. Who is responsible for enforcing the law(s) and issuing guidelines?

The Croatian Personal Data Protection Agency (AZOP), as the national data protection authority in accordance with the GDPR, is responsible for issuing guidelines and decisions regarding the personal data processing of employees.

Supervisory authority, alongside AZOP, is the Government of the Republic of Croatia (the Government), in charge of the compliance with the Labor Law. The Government also issues guidelines and performs inspections.

Citation

Article 4 of the Law

1.3. Guidelines

1.3.1. Have any guidelines been released on data protection in the employment context?

AZOP, as the national data protection authority in accordance with the GDPR, has issued several guidelines and decisions regarding the personal data processing of employees on (only available in Croatian here):

  • technical and organizational measures;
  • data processing regarding education of employees;
  • data processing regarding membership in syndicate;
  • data processing via GPS system;
  • scanning ID and bank card of an employee;
  • publishing personal data of an employee on an invoice, business attire, and the board inside of business premises; and
  • consent of employees and processing of personal data of employees.

In 2024, AZOP, as the coordinator, together with the Italian Data Protection Authority (Garante), the Vrije University Brussels, and the University of Florence, FOI University Croatia successfully finished the EU-funded project ARC – Awareness Raising Campaign for SMEs (the ARC II project). The project resulted in free trainings, templates, and guidelines. Within the project, the web tool Olivia, was developed and adapted to the specific needs of Croatian SMEs to help them to comply with the GDPR.

  1. Recruitment and selection

2.1. Hiring documents

2.1.1. Is it permissible to collect hiring documents?

In accordance with the GDPR, personal data shall be processed for performing contract-labor agreements and performing pre-contractual activities. Certain personal data can be processed in accordance with the legitimate interests of an employer, provided that the interests or the fundamental rights and freedoms of the data subject are not overridden.

Citation

Article 6 of the GDPR

2.1.2. Are there any restrictions on collecting hiring documents?

Employers should comply with the GDPR and applicable special laws. Each candidate should receive all the necessary information, in accordance with Articles 13 and Article 14 of the GDPR.

Employers should refrain from asking prohibited questions and collecting excessive and special categories of personal data. The processing activities shall bear in mind the basic principles of personal data protection (minimization, lawfulness, accuracy, and confidentiality).

Citation

Articles 9, 13, and 14 of the GDPR

2.1.3. Which lawful bases can be relied on for the processing of personal information contained in hiring documents?

In accordance with the GDPR, personal data shall be processed for performing contract-labor agreements and performing pre-contractual activities.

Consent should be an appropriate legal basis for keeping personal data after certain recruitment processes, and CVs of applicants should not be kept for a long time, since they are no longer valid after a few years.

Citation

Article 6 of the GDPR

2.1.4. Is it permissible to disclose/share such personal information with third parties?

In accordance with the Labor Law, work councils should be consulted in cases of:

  • constant surveillance of employees;
  • appointment of the person hired by the employer who is in charge of the supervision of the processing of personal data of employees; and
  • any significant transfer of personal data of employees.

State authorities can receive personal data in accordance with their authorities prescribed by the law.

Citation

Article 151 of the Labor Law

2.1.5. Is notice required when collecting such data?

If an employer has at least 20 employees, the employer needs to publish a labor regulation, in which all the data transfer activities related to the employees should be described.

In case of the existence of a work council, the employer should consult with the work council in relation to the processing and transferring of employee data.

Data subjects should receive necessary information in accordance with Articles 13 and 14 of the GDPR.

Citation

Article 26 of the Labor Law

Articles 13 and 14 of the GDPR

2.1.6. What information must be provided with the notice?

Data subjects should receive necessary information in accordance with Articles 13 and 14 of the GDPR (such as information about the data controller, data retention periods, purpose of processing, and data transfers).

Citation

Articles 13 and 14 of the GDPR

2.1.7. In what format must this information be provided?

Data subjects should receive necessary information in written form (such as information about the data controller, data retention periods, the purpose of processing, and data transfers).

Citation

Articles 12, 13, and 14 of the GDPR

2.1.8. When should notice be provided?

The data subject shall receive the notice at the moment of data collection. In the case of Article 14 of the GDPR, the notice shall be provided within a reasonable period after obtaining the personal data, but at the latest within one month, having regard to the specific circumstances in which the personal data are processed.

Citation

Articles 12, 13, and 14 of the GDPR

2.2. Special category data

2.2.1. Is it permissible to collect special category data during recruitment?

In relation to requirements and restrictions for background checks, employers should be aware of provisions in special laws and comply with those provisions. For example, there are special provisions on recruitment, selection, and background check activities in special laws regarding public bodies, local municipalities, politicians, and certain professional activities (such as lawyers, doctors etc.).

Citation

Articles 6 and 9 of the GDPR

2.2.2. Are there any restrictions on collecting special category data during recruitment?

Since, in accordance with the GDPR, diversity data, and background checks are considered as a special category of personal data, it is necessary, on case-by-case basis, to examine special laws whether this type of data is required to follow special legal obligations, such as positive discrimination or special conditions for certain position.

Citation

Articles 6 and 9 of the GDPR

2.2.3. Which lawful bases can be relied on for the processing of special categories of data during recruitment?

Employers must ensure that the processing is generally lawful, fair, and transparent and complies with all the other principles and requirements of the GDPR. To ensure they need to identify an Article 6 basis for processing, and one of the conditions from Article 9.

  • Explicit consent
  • Employment, social security and social protection (if authorized by law)
  • Vital interests
  • Not-for-profit bodies
  • Made public by the data subject
  • Legal claims or judicial acts
  • Reasons of substantial public interest (with a basis in law)
  • Health or social care (with a basis in law)
  • Public health (with a basis in law)
  • Archiving, research and statistics (with a basis in law)

Citation

Articles 6 and 9 of the GDPR

2.2.4. Is it permissible to disclose/share such personal information with third parties?

In accordance with the Labor Law, work councils should be consulted in cases of:

  • constant surveillance of employees;
  • appointment of the person hired by the employer who is in charge of the supervision of the processing of personal data of employees; and
  • any significant transfer of personal data of employees.

State authorities can receive personal data in accordance with their authorities prescribed by the law.

Citation

Article 151 of the Labor Law

2.2.5. Is notice required when collecting such data?

If an employer has at least 20 employees, the employer needs to publish a labor regulation, in which all the data transfer activities related to the employees should be described.

In case of the existence of a work council, the employer should consult with the work council in relation to the processing and transferring of employee data.

A privacy notice is required in accordance with the GDPR.

Citation

Article 26 of the Labor Law

Articles 13 and 14 of the GDPR

2.2.6. What information must be provided within the notice?

Data subjects should receive necessary information in accordance with Articles 13 and 14 of the GDPR (such as information about the data controller, data retention periods, purpose of processing, and data transfers).

Citation

Articles 13 and 14 of the GDPR

2.2.7. In what format must this information be provided?

If an employer has at least 20 employees, the employer needs to publish a labor regulation, in which all the data transfer activities related to the employees should be described. Employees should receive necessary information in written form (such as information about the data controller, data retention periods, the purpose of processing, and data transfers).

Citation

Article 26 of the Labor Law

Articles 13 and 14 of the GDPR

2.2.8. When should notice be provided?

The data subject shall receive the notice at the moment of data collection. In the case of Article 14 of the GDPR, the notice shall be provided within a reasonable period after obtaining the personal data, but at the latest within one month, having regard to the specific circumstances in which the personal data are processed.

Employees should receive necessary information in written form at the moment of signing the labor agreement, prior to data processing activities.

Citation

Article 26 of the Labor Law

Articles 13 and 14 of the GDPR

  1. Employee records

    službenik za zaštitu podataka DPO

3.1. Personnel records

3.1.1. Is it permissible to process personal information contained in personnel records?

Employment records are governed by laws and bylaws and constitute a legal obligation. Employment records consist of the records of working hours, and general data about an employee, such as name, surname, certificates, previous working experience, date of birth, citizenship, ID number, and personal identification number.

The employee has the right to inspect personal data from the employee records. Any change to personal data, which the employer enters based on a statement, notification, other documents, papers, etc., must be reported by the employee to the employer immediately, and no later than within eight days from the date the change occurred.

Citation

Article 3 of the Regulation on the content and method of keeping records of employees employed by the employer (only available in Croatian here) (the Regulation on method of keeping employee records)

3.1.2. Are there any restrictions on processing such data?

The employer is obligated to protect the data from the employee records from unauthorized access during the retention and storage period, during the processes of data conversion from one form to another, and during the processes of deletion, removal, and handing over of data for safekeeping.

The employer is also obligated to ensure the availability of data from the employee records to authorized persons, upon their request, by providing access to a written overview of the basic data for each employee and by allowing access to documents, papers, and acts related to the employment relationship or the exercise of individual rights from or related to the employment relationship.

Citation

Article 5 of the Regulation on method of keeping employee records

3.1.3. Which lawful bases can be relied on for processing personal information contained in personnel records?

Legal obligation in accordance with the GDPR.

Citation

Article 6 of the GDPR

3.1.4. Is it permissible to disclose/share such personal information with third parties?

In accordance with the Labor Law, work councils should be consulted in cases of:

  • constant surveillance of employees;
  • appointment of the person hired by the employer who is in charge of the supervision of the processing of personal data of employees; and
  • any significant transfer of personal data of employees.

State authorities and arbitration courts can receive personal data in accordance with their authorities prescribed by the law.

Citation

Article 151 of the Labor Law

3.2. Performance records

3.2.1. Is it permissible to process personal information contained in performance records?

The processing of such personal data is permitted, for example, when it is necessary for the fulfilment of a legal obligation for keeping records of employment, records of working hours, and records in accordance with internal acts.

In the case of using biometric data to gain access to a business premises and records of working hours, employers should ask for explicit consent from employees.

Citation

Article 3 of the Regulation on the method of keeping records of employees

Article 23 of the Law

3.2.2. Are there any restrictions on processing such data?

If an employer has at least 20 employees, the employer needs to publish a labor regulation, in which all the data processing activities related to the employees should be described.

In case of the existence of a work council, the employer should consult with the work council in relation to the processing and transferring of employee data.

Employees should receive necessary information in accordance with the GDPR (such as information about the data controller, data retention periods, purpose of processing, and data transfers).

Citation

Article 26 Labor Law

Articles 12,13, and 14 of the GDPR

3.2.3. Which lawful bases can be relied on for processing personal information contained in performance records?

Employment records must be processed as a legal obligation in accordance with the Regulation on the content and method of keeping records of employees employed by the employer.

Citation

Article 3 of the Regulation on the method of keeping records of employees

3.2.4. Is it permissible to disclose/share such personal information with third parties?

In accordance with the Labor Law, work councils should be consulted in cases of:

  • constant surveillance of employees;
  • appointment of the person hired by the employer who is in charge of the supervision of the processing of personal data of employees; and
  • any significant transfer of personal data of employees.

State authorities and arbitration courts can receive personal data in accordance with their authorities prescribed by the law.

Citation

Article 151 of the Labor Law

3.3. Activity records

3.3.1. Is it permissible to process personal information contained in activity records?

Employment records must be processed as a legal obligation in accordance with the Regulation on the content and method of keeping records of employees employed by the employer.

Citation

Article 13 of the Regulation on the method of keeping records of employees

3.3.2. Are there any restrictions on processing such data?

Records of working hours must be kept for at least six years.

If not otherwise specified by the law or other regulation, the employer may determine the retention periods in accordance with means of a general act.

Salary slips should be at least for 11 years, and salary analytics permanently in accordance with the Croatian Accounting Law (only available in Croatian here) (the Accounting Law).

Citation

Article 10 of the Accounting Law

Article 8 of the Regulation on the method of keeping records of employees

3.3.3. Which lawful bases can be relied on for processing personal information contained in activity records?

Employment records must be processed as a legal obligation in accordance with the Regulation on the method of keeping records of employees.

Citation

Article 13 of the Regulation on the method of keeping records of employees

3.3.4. Is it permissible to disclose/share such personal information with third parties?

In accordance with the Labor Law, work councils should be consulted in cases of:

  • constant surveillance of employees;
  • appointment of the person hired by the employer who is in charge of the supervision of the processing of personal data of employees; and
  • any significant transfer of personal data of employees.

State authorities and arbitration courts can receive personal data in accordance with their authorities prescribed by the law.

Citation

Article 151 of the Labor Law

3.4. Sensitive records

3.4.1. Is it permissible to process personal information contained in special category records?

Employers should always check if the law requires the processing of special categories of personal data and refrain from processing and transferring data that is unnecessary for fulfilling the purpose.

This type of data can be transferred in case of legal obligation prescribed by law or based on a data processing agreement with the service provider.

Citation

Articles 6 and 9 of the GDPR

3.4.2. Are there any restrictions on processing such data?

In the case of using biometric data to gain access to business premises and records of working hours, employers should ask for explicit consent from employees.

Citation

Article 23 of the Law

3.4.3. Which lawful bases can be relied on for processing personal information contained in sensitive records?

The processing of sensitive data is permitted, for example, when it is necessary for the fulfilment of a legal obligation for keeping records of employment, records of working hours, and records in accordance with the Safety Law (data about injuries at work and professional sickness).

Citation

Article 13 of the Regulation on the method of keeping records of employees

3.4.4. Is it permissible to disclose/share such personal information with third parties?

In accordance with the Labor Law, work councils should be consulted in cases of:

  • constant surveillance of employees;
  • appointment of the person hired by the employer who is in charge of the supervision of the processing of personal data of employees; and
  • any significant transfer of personal data of employees.

State authorities and arbitration courts can receive personal data in accordance with their authorities prescribed by the law.

Citation

Article 151 of the Labor Law

3.5. Payroll and pension records

3.5.1. Is it permissible to process personal information contained in payroll and pension records?

Employment records that contain data on payroll and pension records must be processed as a legal obligation in accordance with the Regulation on the content and method of keeping records of employees employed by the employer.

Citation

Articles 3 and 13 of the Regulation on the method of keeping records of employees

3.5.2. Are there any restrictions on processing such data?

Salary slips should be delivered each month to employees and kept for at least 11 years. Salary analytics should be kept permanently in accordance with the Accounting Law.

Citation

Article 10 of the Accounting Law

3.5.3. Which lawful bases can be relied on for processing personal information contained in payroll and pension records?

The legal basis for processing is as per the GDPR.

Citation

Article 6 of the GDPR

3.5.4. Is it permissible to disclose/share such personal information with third parties?

In accordance with the Labor Law, work councils should be consulted in cases of:

  • constant surveillance of employees;
  • appointment of the person hired by the employer who is in charge of the supervision of the processing of personal data of employees; and
  • any significant transfer of personal data of employees.

State authorities and arbitration courts can receive personal data in accordance with their authorities prescribed by the law.

Citation

Article 151 of the Labor Law

  1. Data subject rights

4.1. Access requests

4.1.1. Are there any specific rules for handling employee access requests?

The employee has the right to inspect personal data from the employee records. Any change to personal data, which the employer enters based on a statement, notification, other documents, papers, etc., must be reported by the employee to the employer immediately, and no later than eight days from the date the change occurred.

Citation

Article 3 of the Regulation on the method of keeping records of employees

4.1.2. Are there any limitations to providing employees access to their personal information?

The employer is obligated to protect the data from the employee records from unauthorized access during the retention and storage period, during the processes of data conversion from one form to another, and during the processes of deletion, removal, and handing over of data for safekeeping.

Citation

Article 3 of the Regulation on the method of keeping records of employees

4.2. Privacy policies

4.2.1. Is there a requirement to provide employees with a privacy policy?

Employees should receive all the necessary information in accordance with the GDPR in relevant internal acts, notices and in labor regulation (data controller, data retention periods, information about the data protection officer, purpose of processing, data transfers, and information on data subject’s rights).

If an employer has at least 20 employees, the employer needs to publish a labor regulation, in which all the data transfer activities related to the employees should be described.

In case of the existence of a work council, the employer should consult with the work council in relation to the processing and transferring of employee data.

Citation

Articles 12,13, and 14 of the GDPR

Articles 26 and 27 of the Labor Law

4.2.2. What information must be provided to employees regarding the processing of their personal information?

Employees should receive necessary information in accordance with the GDPR and Labor Law (such as information about the data controller, data retention periods, purpose of processing, and data transfers).

Citation

Articles 12,13, and 14 of the GDPR

Articles 26 and 27 of the Labor Law

4.2.3. When must this information be provided?

Employees should receive necessary information in the written form in the moment of signing the labor agreement, prior to data processing activities. In case of Article 14 of the GDPR the notice shall be provided within a reasonable period after obtaining the personal data, but at the latest within one month, having regard to the specific circumstances in which the personal data are processed.

Citation

Articles 12,13, and 14 of the GDPR

4.2.4. In what format must this information be provided?

In a written form, as a Privacy Notice document of Labor Bylaw document.

Citation

Articles 12,13, and 14 of the GDPR

Articles 26 and 27 of the Labor Law

  1. Use of AI and automated decision-making

5.1. Recruitment

5.1.1. Are there requirements regarding the use of automated decision-making and/or AI during recruitment?

The use of automated processing for decision-making is authorized only in the following cases:

  • the decision based on the algorithm is necessary (i.e., there must be no other way to achieve the same goal) to enter into or to perform a contract with the individual whose data your company/organization processed via the algorithm;
  • a particular national law allows the use of algorithms and provides for suitable safeguards to protect the individual’s rights, freedoms and legitimate interests; or
  • the individual has explicitly given his consent to a decision based on the algorithm.

Citation

Articles 4 and 22 of the GDPR

5.1.2. What are the requirements regarding the use of automated decision-making and/or AI during recruitment?

The use of automated processing for decision-making is authorized only in the following cases:

  • the decision based on the algorithm is necessary (i.e., there must be no other way to achieve the same goal) to enter into or to perform a contract with the individual whose data your company/organization processed via the algorithm;
  • a particular national law allows the use of algorithms and provides for suitable safeguards to protect the individual’s rights, freedoms and legitimate interests; or
  • the individual has explicitly given his consent to a decision based on the algorithm.

Citation

Articles 4 and 22 of the GDPR

5.2. Employee performance

5.2.1. Are there requirements regarding the use of automated decision-making and/or AI to evaluate employee performance?

The recent amendments to the Labor Law, which entered into force on January 1, 2024, introduced new rules regarding platform workers (e.g., via website or an app).

Citation

Article 221 g of the Labor Law

5.2.2. What are the requirements regarding the use of automated decision-making and/or AI to evaluate employee performance?

The recent amendments to the Labor Law, which entered into force on January 1, 2024, introduced new rules regarding platform workers (e.g., via website or an app). In cases using automatic systems for organizing platform work, employers must be transparent and introduce an employee to the organization of the digital platform and decision-making via an automated system. An authorized person shall be appointed for the security and examination of the decisions.

The digital platform shall not process data on private conversations and on the emotional and psychological condition of an employee. Health data also shall not be processed, unless in accordance with data protection laws. Additionally, personal data shall not be collected during the time of inactivity of an employee.

Citation

Article 221 g of the Labor Law

  1. Teleworking

6.1. Policy, procedures, and guidance

6.1.1. Are there any specific requirements for employers with employees that work remotely?

The Croatian Academic and Research Network – CARNET published certain recommendations and best practices for working from home (only available in Croatian here) (the Teleworking Best Practices).

Citation

The Teleworking Best Practices https://www.cert.hr/ROKCERT

6.1.2. What are the requirements for employers with employees that work remotely?

The Labor Law as amended, prescribes two modalities of teleworking. work from a distance and work from a distant place. In case of work from home, an employer has the right to enter the employee’s home for the maintenance of business equipment or to perform the anticipated audit, but only if such is agreed between the employer and the employee, and only at the time agreed with the employee. An employer is obliged to preserve an employee’s privacy.

Citation

Article 17 of the Labor Law

  1. Training and awareness

7.1. Employee training

7.1.1. Are there any requirements for training employees on data protection compliance?

In accordance with the latest guidance from AZOP, employees should finish introduction training on the GDPR, regular training once year and training in accordance with the compliance risks.

Citation

Olivia Tool

7.1.2. What should employee training programs encompass?

Staff training programs should encompass data breach procedure, data subjects’ requests procedure, legal grounds for data processing, technical and organizational measures, internal acts and procedures on personal data protection.

Citation

Olivia Tool

  1. Enforcement

8.1. Liability

8.1.1. What are the penalties for violation of the applicable laws?

In addition to the administrative fines prescribed by the GDPR, the Labor Law has provisions for violations committed by employers.

A fine in the amount ranging from €4,110 to €7,960 shall be imposed on an employer:

  • for requesting from an employee, on the occasion of concluding a labor agreement, information that is not directly related to their employment;
  • for unlawfully collecting, processing, using, and/or sending to third parties’ personal information about employees;
  • for failing to appoint a person who is authorized to receive and deal with complaints related to the protection of workers’ dignity or for disclosing information obtained during the complaint procedure; and
  • for asking information on a woman’s pregnancy, or ordering another person to ask such information, except when the woman personally requests a specific.

Citation

Articles 226, 227, 228, and 229 of the Labor Law

Article 83 of the GDPR

8.2. Enforcement decisions

8.2.1. Has the supervisory authority issued any enforcement decisions on data protection and employment?

The reports from AZOP (only available in Croatian here) published the statistics and descriptions of the enforcement decisions, with fines in total around €9 million. The decisions concerned privacy notices, processing of specials categories of personal data, consent of data subjects, video surveillance, and improper technical and organizational measures.

In October 2023, AZOP published its highest fine of €5.47 million on EOS Matrix d.o.o. (only available in Croatian here) as a data controller due to the following violations of the GDPR:

  • the controller did not take appropriate technical measures to protect the personal data of the data subjects contained in the storage systems, which is contrary to Article 32(1)(b) and 32(2) of the GDPR;
  • the controller processed the personal data of data subjects who are not in a debtor-creditor relationship in their database (application) without determining a legal basis from Article 6(1) of the GDPR;
  • the controller processed personal data of a special category (health data) of the data subject in its database (application) without determining a legal basis from Article 6(1) of the GDPR and in connection with Article 9(2) of the GDPR;
  • the data controller did not inform the data subject in a transparent and prescribed manner about the processing of their health data in the privacy policies, which is contrary to Article 12(1) of the GDPR and, in this regard, Article 13(1)–(2) of the GDPR;
  • for the recording of telephone conversations with the data subjects in the period from May 25, 2018, to January 16, 2019, the data controller did not identify legal basis from Article 6(1) of the GDPR, and in connection with mentioned above there was violation of Article 5(2) of the GDPR; and
  • the controller did not inform the data subjects in an understandable and clear way about the recording of telephone conversations, and thus they acted contrary to Article 12(1) of the GDPR.

In 2025, following ex officio proceedings, AZOP published administrative fine of EUR 4.5 million imposed on a telecommunications operator. The infringements concerned:

  • the transfer of personal data to third countries without a valid transfer instrument and without transparent information to data subjects,
  • the processing of copies of employees’ identity cards and certificates of no criminal proceedings without a legal basis,
  • as well as the failure to carry out appropriate prior checks of a processor.

From 16 April 2020 to no later than 27 December 2022, the transfer was based on standard contractual clauses. However, after that date, the controller failed to conclude standard contractual clauses with the processor in the Republic of Serbia, which means that, after that date, the transfer of personal data occurred without appropriate safeguards.  A review of the privacy policies showed that the controller did not use clear language indicating that personal data would be transferred outside the EEA. Instead, it used formulations such as personal data “may” be shared with third countries or that data are “as a rule” processed within the European Union and only exceptionally outside it, which is contrary to Article 12(1) GDPR.

Furthermore, the controller excessively processed personal data of its employees by collecting copies of their identity cards, contrary to Article 6(1), and in connection with Article 5(1)(c) and (2) GDPR. An aggravating factor was that the controller disregarded the opinion of its Data Protection Officer, who had advised that collecting copies of identity cards, considering the nature of the data, could be considered excessive in relation to the stated purpose. Similarly, the controller collected certificates of no criminal proceedings for its employees, contrary to Article 6(1), and in connection with Article 5(1)(b) and (2) GDPR.

Citation

https://azop.hr/administrative-fine-of-eur-4-5-million-imposed-on-a-telecommunications-operator-14-november-2025/

Annual reports from AZOP

8.3. Case law

8.3.1. Are there any relevant decisions on data protection and employment from judicial courts?

In the Croatian legal system, case law is examined as an argument for a certain reasoning. The case law often concerns medical data and the absence of an employee from work. There is certain case law on the legality of video footage of an employee. The Supreme Court of the Republic of Croatia (the Supreme Court) regularly publishes a selection of decisions. In addition, the Supreme Court also publishes court practices on its website and legally binding conclusions from legal assemblies.

Citation

https://www.vsrh.hr/en/

For more assistance on your GDPR matters, do not hesitate to contact us on info@parser.hr.

Marija Bošković Batarelo, LLM Law and Technology