1. EMPLOYMENT LAW
1.1. Key legislation and regulations
As a general act on personal data processing, the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR) applies from 25th May 2018.
In the Article 6, the GDPR prescribes six legal grounds for personal data processing. The Article 9 of the GDPR prescribes exemption from prohibition of processing of special categories of personal data if processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law in so far as it is authorised by Union or Member State law or a collective agreement pursuant to Member State law providing for appropriate safeguards for the fundamental rights and the interests of the data subject.
The Act on Implementation of the General Data Protection Regulation (“Zakon o provedbi Opće uredbe o zaštiti podataka – Official Gazette, No. 42/18” – available only in Croatian – the Act), prescribes specific provisions regarding biometric data of employees for the purpose of records of working hours and security reasons. Such kind of personal data processing is allowed only upon consent of an employee and alternative technical solution shall be provided for employees who do not provide their consent.
The Act also includes provisions regarding video surveillance and defines that such processing shall be in accordance with the Law on Occupational Health and Safety (“Zakon o zaštiti na radu – Official Gazette, No. 71/14, 118/14, 154/14, 94/18, 96/18” – available only in Croatian – the Safety Law) and only upon prior privacy notice. Video surveillance must not include rooms for rest and hygiene of employees.
The main law regarding employees is the Labour Law (with recent changes from December 2022, only available in Croatian here) (‘the Labour Law’).
The Labour Law has a special provision on the privacy of employees and recommends that any data processing and/or transfers of personal data shall be described in the labour regulation of an employer. An employer which hires at least 20 employees must appoint a person in charge for supervision of processing employees’ personal data.
Recent changes, that will be on force from 1 January 2024, introduce new rules regarding platform workers (e.g., via website or an app). In case using automatic systems for organizing platform work, employer must be transparent and introduce an employee with the organization of the digital platform and decision making via automated system. An authorised person shall be appointed for the security and examination of the decisions.
Digital platform shall not process data on private conversation and on emotional and physiological condition of an employee. Health data also shall not be processed, unless in accordance with data protection laws. Additionally, personal data shall not be collected during the time of inactivity of an employee.
The Labour Law prescribes two modalities of teleworking, work from distance and work from a distant place. In case of work from home, an employer has the right to enter employee’s home for the maintenance of business equipment or to perform anticipated audit, but only if such is agreed between the employer and the employee and only in time agreed with the employee. An employer is obliged to preserve employee’s privacy.
1.2. Official guidelines
Croatian Personal Data Protection Authority, as a national data protection authority in accordance with the GDPR, has issued several guidelines regarding personal data processing of employees (available only in Croatian):
- Guidelines on technical and organisational measures;
- Guidelines on processing data regarding education of employees;
- Guidelines on processing data regarding membership in syndicate;
- Guidelines on data processing via GPS system
- Guidelines on scanning ID and bank card of an employee;
- Guidlelines on publishing personal data of an employee on publishing personal data of an employee on an invoice, business attire, the board inside of business premises;
- Guidelines on consent and personal data processing.
In March 2022, AZOP, as a coordinator, together with Data Protection Commission Ireland and Vrije University Brussels, successfully finished the EU-funded project ARC – Awareness Raising Campaign for SMEs (the ARC I project). The project resulted in free trainings, templates, and guidelines.
Subsequently, after the ARC I project, AZOP started with the EU-funded project ARC II – Awareness Raising Campaign for SMEs (the ARC II project), with the Italian data protection authority, the Vrije University Brussels, and the University of Florence. The project started on September 2, 2022, and is expected to end in October 2024.
Within the project, the web tool Olivia, is being developed and adapted to the specific needs of Croatian and Italian SMEs to help them to comply with the GDPR and data protection legal framework. The tool contains a knowledge base integrating all the education materials, templates, FAQs already developed within ARC I and SMEDATA I project, all at one place and in one digital tool, available to SMEs to use free of charge. Online workshops will be conducted, recorded, and published on the ARC II website and the Olivia dashboard, and in this way will be available to a larger public.
The digital tool Olivia will be released under a license in which the copyright holder grants users the rights to use, study, change, and distribute it, meaning that other data protection authorities could use it free of charge, add new modules, functionalities, adjust it to the needs of their SMEs and national legislation, and can upgrade and improve Olivia. All the project activities will be conducted in Croatia and Italy, and dissemination and communication activities are also going to be conducted in Belgium.
1.3. Supervisory authorities
Alongside the Croatian Personal Data Protection Authority, the Ministry of the Government of the Republic of Croatia is also in charge for compliance for labour law. The Ministry also issues guidelines and performs inspections.
1.4. Applicable case law
Croatian legal system does not recognise case law institute, rather case law can be examined as an argument for certain reasoning. The case law often concerns medical data and absence of an employee from work. There is a certain case law on legality of video footage of an employee.
The Supreme Court of the Republic of Croatia regularly publishes the Selection of Decisions. The Supreme Court of the Republic of Croatia also publishes court practice on its web site (www.vsrh.hr – available only in Croatian) and legally binding conclusions from legal assemblies. The access to the web site is free of charge.
The latest report from AZOP, from 2023, published the statistics and descriptions of 28 enforcement decisions, with fines totalling €8,27 million (only available in Croatian here). The decisions concerned privacy notices, processing of specials categories of personal data, consent of data subjects, video surveillance and improper technical and organizational measures.
AZOP received an anonymous complaint on March 22, 2023, stating that there had been unauthorized processing of a large number of personal data belonging to individuals (debtors) by EOS Matrix d.o.o. A USB stick was attached to the complaint containing 181,641 personal data of natural persons in the structure of first and last name, date of birth, and personal identification number, who had outstanding debts to initial creditors that were purchased by EOS Matrix d.o.o. based on the cession agreement.
Consequently, in October 2023, AZOP published its highest fine of €5.47 million on EOS Matrix d.o.o. as a data controller due to the following violations of the GDPR:
- the controller did not take appropriate technical measures to protect the personal data of the data subjects contained in the storage systems, which is contrary to Article 32(1)(b) and 32(2) of the GDPR;
- the controller processed the personal data of data subjects who are not in a debtor-creditor relationship in their database (application) without determining a legal basis from Article 6(1) of the GDPR;
- the controller processed personal data of a special category (health data) of the data subject in its database (application) without determining a legal basis from Article 6(1) of the GDPR and in connection with Article 9(2) of the GDPR;
- the data controller did not inform the data subject in a transparent and prescribed manner about the processing of their health data in the privacy policies, which is contrary to Article 12(1) of the GDPR and, in this regard, Article 13(1)–(2) of the GDPR;
- for the recording of telephone conversations with the data subjects in the period from May 25, 2018, to January 16, 2019, the data controller did not identify legal basis from Article 6(1) of the GDPR, and in connection with mentioned above there was violation of Article 5(2) of the GDPR; and
- the controller did not inform the data subjects in an understandable and clear way about the recording of telephone conversations, and thus they acted contrary to Article 12(1) of the GDPR.
2. RECRUITMENT AND SELECTION
2.1. General requirements for collection, processing, and disclosure of data
In accordance with the GDPR, personal data shall be processed for performing contract-labour agreement and performing pre-contractual activities. Certain personal data can be processed in accordance with legitimate interest of an employer, provided that the interests or the fundamental rights and freedoms of the data subject are not overridden.
Consent should be appropriate legal basis for keeping personal data after certain recruitment process, and, generally speaking, CVs of applicants should not be kept for a long time, since there are no longer valid after few years.
2.2. Advertising a position and requirements for data collection regarding CVs, tests, evaluations
When advertising a position, employers shall keep in mind that companies that employers engage for advertising, recruitment, and selection purposes are usually considered as data processors or joint controllers. Thus, agreements and checks should be in place, in accordance with Article 26 and 28 of the GDPR.
Regarding psychological test, there is a special Law on Psychological Activities (available only in Croatian), which prescribes that only licenced persons are allowed to performs such tests.
2.3. Requirements and restrictions in relation to background checks
Regarding requirement and restrictions in relation to background checks, employers should be aware on provisions in special laws and comply with those provisions. For example, there are special provisions on recruitment, selection, and background checks activities in special laws regarding public bodies, local municipalities, politicians, and certain professional activities (such as, lawyers, doctors etc.).
Croatian Personal Data Protection Agency published opinion that employers should analyse their legitimate interest in case accessing data about employees/candidates that are publicly available.
2.4. Obligations of the employer to protect candidates’ right to privacy during interview process
Employers should comply with the GDPR and applicable special laws. Each candidate should receive all the necessary information, in accordance with the Article 13 and Article 14 of the GDPR.
Employers should refer from asking prohibited questions and collecting excessive personal data. The processing activities shall have in mind basic principles of personal data protection (minimisation, lawfulness, accuracy, confidentiality).
2.5. Employer’s right to ask questions/request references
Labour Law forbids collection of certain type of data. When concluding a labour agreement, an employer must not request from an employee the information that is not directly related to his or her employment, such as, data about pregnancy, number of children, religion etc.
2.6. Candidate’s obligation to reveal information
The questions not to be asked, in accordance with the Labour Law, need not be answered. A candidate has an obligation to reveal only information that is necessary for the performance of labour agreement. For example, a candidate has to inform employer on any obstacle which is significant for performing labour agreement.
2.7. Retention of recruitment records
Retention of recruitment records is prescribed with special laws. In case of no special law, employers decide to keep the data until completion of recruitment process and until expiration of deadline for filing complaints by the candidates.
3. EMPLOYMENT RECORDS

3.1. General requirements for collection, processing and disclosure of data
Employment records are prescribed by Law and Bylaws as an legal obligation. Employments records consist of records of working hours, records in accordance with Safety Law, and general data about an employee, such as, name, surname, certificates, previous working experience, date of birth, citizenship, ID number, Personal Identification Number. Data can be disclosed to public authorities, in accordance with law.
The employee has the right to inspect personal data from the employee records. Any change to personal data, which the employer enters based on a statement, notification, other documents, papers, etc., must be reported by the employee to the employer immediately, and no later than within eight days from the date the change occurred.
The employer is obligated to protect the data from the employee records from unauthorized access during the retention and storage period, during the processes of data conversion from one form to another, and during the processes of deletion, removal, and handing over of data for safekeeping. The employer is also obligated to ensure the availability of data from the employee records to authorized persons, upon their request, by providing access to a written overview of the basic data for each employee and by allowing access to documents, papers, and acts related to the employment relationship or the exercise of individual rights from or related to the employment relationship.
3.2. Notification to the employee on collection, processing, access and disclosure
Employees should receive necessary information from Article 13 of the GDPR (data controller, data retention periods, purpose of processing, data transfer etc.). Also, if an employer has at least 20 employees, employer needs to publish Labour Regulation, in which all the personal data processing activities and transfers related to employees should be described.
3.3. Retention of employment records
Employment records must be kept in accordance with the new Bylaw and employment records (on force from the beginning of October 2024, only available in Croatian here) for at least the following periods:
- Written review of employee data, until the end of the year in which the employment relationship ended.
- The written employment contract or confirmation of the concluded employment contract, and all amendments and supplements to the employment contract, for six years from the end of the year in which the employment relationship ended, or until the final resolution of the dispute, if the employer is aware that a labor dispute has been initiated regarding the exercise of rights from employment or in connection with employment.
- Agreements between the employer and the employee, consents, and written statements of the employee, termination decisions, for six years from the end of the year in which the employment relationship ended, or until the final resolution of the dispute, if the employer is aware that a labor dispute has been initiated regarding the exercise of rights from employment or in connection with employment.
- Registration forms (start, change, termination) for mandatory pension and health insurance, for six years from the end of the year in which the employment relationship ended, or until the final resolution of the dispute, if the employer is aware that a labor dispute has been initiated regarding the exercise of rights from employment or in connection with employment.
- Public and private documents that provide proof of the accuracy of data on professional education, training, advancement, and other information that determines the realization of rights and obligations from employment, for six years from the end of the year in which the employment relationship ended.
- Public and private documents, decisions, certificates, calculations, etc., related to the obligations of payroll calculation and payment, as well as the payment of taxes and contributions, within the time limits prescribed by specific regulations.
- Decisions, private documents, certificates, records, etc., related to safety and health at work, work-related injuries, and occupational diseases, within the time limits prescribed by specific regulations.
- Decisions, private documents, certificates, and the like related to the exercise of rights from pension insurance, including rights based on insurance periods calculated with extended duration, for 40 years from the end of the year in which the employment relationship ended.
- Decisions, private documents, certificates, records, and the like related to the exercise of rights from mandatory health insurance, for six years from the end of the year in which the documentation was created, or until the final resolution of the dispute, if the employer is aware that a labor dispute has been initiated regarding the exercise of rights from employment or in connection with employment.
- Public and private documents, decisions, certificates, etc., related to the exercise of rights to personal care or another right from general labor regulations, as well as the exercise of maternity and parental rights, for six years from the end of the year in which the documentation was created, or until the final resolution of the dispute, if the employer is aware that a labor dispute has been initiated regarding the exercise of rights from employment or in connection with employment.
- Employee requests for the protection of rights from employment, along with decisions, acts, and writings issued by the employer in the course of such requests, for six years from the end of the year in which the documentation was created, or until the final resolution of the dispute, if the employer is aware that a labor dispute has been initiated regarding the exercise of rights from employment or in connection with employment.
- Collective agreements referred to in the employment contract for employees of that employer, regulating certain issues in place of mandatory data in the employment contract, related to the exercise of rights from employment or in connection with employment, for six years from the expiration of the collective agreement or from the expiration of the extended application of legal rules contained in that collective agreement, or until the final resolution of the dispute, if the employer is aware that a labor dispute has been initiated regarding the exercise of rights from employment or in connection with employment.
- Work regulations that regulate wages, work organization, procedures, and measures for protecting dignity and preventing discrimination, and other important issues referred to in the employment contract of employees of that employer, for six years from the end of the year in which the work regulations ceased to be in effect, or until the final resolution of the dispute, if the employer is aware that a labor dispute has been initiated regarding the exercise of rights from employment or in connection with employment.
- Other documents, papers, and acts related to the exercise of rights from employment or in connection with employment, for six years from the end of the year in which the documentation was created.
- Records of working hours must be kept for at least six years.
If not otherwise specified by the law or other regulation, the employer may determine the retention periods in accordance by means of a general act.
Salary slips should be at least for 11 years and salary analytics permanently in accordance with new Croatian Accounting Law (on force from July 2024, only available in Croatian here).
Other tax and financial records should be kept for 11 years after the end of the business year in which the business event occurred.
3.4. Employee rights to information
Employees, as data subjects, have all the rights in accordance with the GDPR (access data, rectify, delete, object and file comply to data processing authority). Also, in accordance with Labour Law, employees have right to file a request for protection of their rights and to file a complaint to a person appointed by employer, who is in charge for supervision of processing personal data of employees.
3.5. Disclosure to works councils, state authorities, arbitration courts, etc.
In accordance with Labour Law and Safety Law, work council should be consulted in case of constant surveillance of employees, appointment of person appointed by employer, who is in charge for supervision of processing personal data of employees, and in any significant transfer of personal data of employees.
State authorities can receive personal data in accordance with their authorities prescribed by law.
4. INFORMATION ABOUT WORKERS’ HEALTH
4.1. General rules on processing of workers’ health information and exceptions
In accordance with Labour Law and Safety Law, employment records must contain data about injuries at work and professional sickness, sick leave, maternity leave, and data necessary for exercising rights of an employee, such as special conditions of working and special working hours or leaves.
5. DATA TRANSFERS
5.1. Legal grounds
Employees’ data should be transferred in accordance with the GDPR, and certain special conditions should be respected in certain situation. For example, work council should be consulted in case of transfer of data of employees and transfer of data should be described in Labour Regulation.
5.2. Mechanisms for the transfers of data
In case of transferring personal data of employers to third parties/data processor, employers should follow the above-mentioned special requirements from Labor Law and general requirements prescribed in the GDPR prescribed in section on ‘General requirements for collection, processing, and disclosure of data’ above (for example, assess data processor, technical and organizational measures, conclude the agreement in accordance with Articles 26 and 28 of the GDPR).
A group of undertakings, or a group of enterprises engaged in a joint economic activity within the EU, can rely on legitimate interest for necessary personal data transfers.
Transfers of data outside the EU are allowed in accordance with the GDPR, such as based on an adequacy decision, Standard Contractual Clauses (SCCs), codes of conduct, and consent.
Since Privacy Shield was invalidated in C-C-311/18 Data Protection Commissioner v. Facebook Ireland Limited, Maximillian Schrems (the Schrems II Case), many employers examined inevitable data transfers to the USA and, in general, switched to SCCs. For all data transfers of employees, employers should carefully check data transfers, data processors, sub-processors, and, if necessary, perform transfer impact assessment to decide which service provider to choose and which mechanism for the transfers of data should be applicable.
Employers should be able to make use of approved Data Privacy Framework, Binding Corporate Rules (BCRs) for their international transfers from the EU to organizations within the same group of undertakings, or group of enterprises engaged in a joint economic activity, provided that such mechanisms include all essential principles and enforceable rights to ensure appropriate safeguards for transfers, or categories of transfers, of personal data.
5.3. Sensitive data
Employers shall always check if the law requires processing special categories of personal data and refrain from processing and transferring data that is necessary for fulfilling the purpose.
Allowed sensitive data processing can be, for example, data necessary for fulfilment of legal obligation of keeping employment of records, records of working hours, records in accordance with Safety Law (data about injuries at work and professional sickness). This type of data can be transferred in case of legal obligation prescribed by law or based on a data processing agreement with service provider.
In case of using biometric data for entrance to business premises and records of working hours, employers should ask for consent from employees.
5.4. Information provision requirements
Employees should receive necessary information from Article 13 of the GDPR (data controller, data retention periods, information about data protection officer, purpose of processing, data transfer, information on data subject’s rights, etc.).
5.5. Notification requirements
If an employer has at least 20 employees, employer needs to publish Labour Regulation, in which all the data transfer activities related to employees should be described.
In case of existence of work council, employer should consult with the work council regarding processing and transferring the data of employees.
6. SANCTIONS
6.1. Criminal and civil liabilities
In addition to administrative fines prescribed by the GDPR, Labour Law has provisions on violation committed by employers.
A fine in the amount ranging from 4,110.00 to 7,960.00 EUR shall be imposed on an employer:
- for requesting from an employee, on the occasion of concluding a labour agreement, the information which is not directly related to his or her employment;
- for unlawfully collecting, processing, using and sending to third parties personal information about employees;
- for failing to appoint a person who authorised to receive and deal with the complaints related to the protection of workers’ dignity or for disclosing information obtained in the complaint procedure;
- for asking information on a woman’s pregnancy, or ordering another person to ask such information, except when the woman personally requests a specific right envisaged under law or another regulation for the protection of pregnant women.
For any enquiries regarding employment law and GDPR in Croatia, do not hesitate to contact us.
Marija Boskovic Batarelo LL.M. Law and Technology

