Back to Frameworks

Act on the Implementation of the General Data Protection Regulation (OG 42/2018)

Croatia
vOG 42/2018 as amended by OG 71/2020 and OG 115/2022
5 domains
44 controls

The Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka, OG 42/2018) provides national provisions supplementing the EU GDPR in Croatia. It defines specific conditions for lawful processing, the rights of data subjects, and the powers of the Croatian Personal Data Protection Agency (AZOP). The act has been amended by OG 71/2020 and OG 115/2022 to align with subsequent EU legislative updates.

Verified

Act on the Implementation of the General Data Protection Regulation (OG 42/2018) is a compliance framework from Croatia with 5 domains and 44 controls that map to 2 other frameworks. The largest domains are Part V - Remedies and Sanctions (18 controls), Part IV - Supervisory Authority (AZOP) (9 controls), Part III - Video Surveillance (8 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Part I - General Provisions

2 controls
Controls in the Part I - General Provisions domain of Act on the Implementation of the General Data Protection Regulation (OG 42/2018)2 controls
CodeTitle
HR-GDPR-Art.1Subject and Scope of the Act
HR-GDPR-Art.3Definitions and Public Authority Bodies

Part II - Special Categories of Data Processing

7 controls
Controls in the Part II - Special Categories of Data Processing domain of Act on the Implementation of the General Data Protection Regulation (OG 42/2018)7 controls
CodeTitle
HR-GDPR-Art.19Child's Consent for Information Society Services
HR-GDPR-Art.20Prohibition on Genetic Data Processing for Insurance
HR-GDPR-Art.21Biometric Data Processing - Public Sector
HR-GDPR-Art.22Biometric Data Processing - Private Sector
HR-GDPR-Art.23Biometric Data of Employees (Time and Access)
HR-GDPR-Art.24Applicability of Biometric Rules and DPIA
HR-GDPR-Art.33Processing for Statistical Purposes

Part III - Video Surveillance

8 controls
Controls in the Part III - Video Surveillance domain of Act on the Implementation of the General Data Protection Regulation (OG 42/2018)8 controls
CodeTitle
HR-GDPR-Art.25Video Surveillance - Definition
HR-GDPR-Art.26Video Surveillance - Lawful Purpose
HR-GDPR-Art.27Video Surveillance - Notice Requirements
HR-GDPR-Art.28Video Surveillance - Access Control and Logging
HR-GDPR-Art.29Video Surveillance - Retention Limit
HR-GDPR-Art.30Video Surveillance of Work Premises
HR-GDPR-Art.31Video Surveillance in Residential Buildings
HR-GDPR-Art.32Video Surveillance of Public Areas

Part IV - Supervisory Authority (AZOP)

9 controls
Controls in the Part IV - Supervisory Authority (AZOP) domain of Act on the Implementation of the General Data Protection Regulation (OG 42/2018)9 controls
CodeTitle
HR-GDPR-Art.11Prohibition on Agency Staff Acting as DPO
HR-GDPR-Art.13Professional Confidentiality Obligation
HR-GDPR-Art.14Legislative Consultation with AZOP
HR-GDPR-Art.15Cooperation with Foreign Supervisory Authorities
HR-GDPR-Art.17Annual Work Report
HR-GDPR-Art.18Publication of High-Risk Opinions and Decisions
HR-GDPR-Art.4Supervisory Authority (AZOP)
HR-GDPR-Art.5National Accreditation Body for Certification
HR-GDPR-Art.6Powers and Tasks of the Agency

Part V - Remedies and Sanctions

18 controls
Controls in the Part V - Remedies and Sanctions domain of Act on the Implementation of the General Data Protection Regulation (OG 42/2018)18 controls
CodeTitle
HR-GDPR-Art.34Right to Request Determination of Breach
HR-GDPR-Art.35Interim Relief in Deletion Cases
HR-GDPR-Art.36Conduct of Supervision (Inspections)
HR-GDPR-Art.37Copying, Sealing and Temporary Seizure
HR-GDPR-Art.38Suspicion of Criminal Offence
HR-GDPR-Art.39Handling of Classified Data
HR-GDPR-Art.40Inspection Report (Zapisnik)
HR-GDPR-Art.41Representation of Data Subjects
HR-GDPR-Art.42Provision of Expert Opinions
HR-GDPR-Art.43Fees for Acting on Requests
HR-GDPR-Art.44Imposition of Administrative Fines
HR-GDPR-Art.45Administrative Fine Decision
HR-GDPR-Art.46Payment and Forced Collection of Fines
HR-GDPR-Art.47Exclusion of Fines for Public Authority Bodies
HR-GDPR-Art.48Publication of Final Rulings
HR-GDPR-Art.49Statute of Limitations for Fine Collection
HR-GDPR-Art.50Misdemeanour Penalties for Confidentiality Breach
HR-GDPR-Art.51Administrative Fines for Video-Surveillance Violations

Maps to 2 other frameworks

44 total controls
GDPR
15 source controls mapped|13 target controls covered
34%
NIST SP 800-53 Rev 5
4 source controls mapped|5 target controls covered
9%

Coverage is not the same as your position

This page shows what Act on the Implementation of the General Data Protection Regulation (OG 42/2018) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is Act on the Implementation of the General Data Protection Regulation (OG 42/2018) and who does it apply to?

Act on the Implementation of the General Data Protection Regulation (OG 42/2018) is a compliance framework from Croatia with 5 domains and 44 controls. The Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka, OG 42/2018) provides national provisions supplementing the EU GDPR in Croatia. It defines specific conditions for lawful processing, the rights of data subjects, and the powers of the Croatian Personal Data Protection Agency (AZOP). The act has been amended by OG 71/2020 and OG 115/2022 to align with subsequent EU legislative updates. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Act on the Implementation of the General Data Protection Regulation (OG 42/2018) actually require?

Act on the Implementation of the General Data Protection Regulation (OG 42/2018) has 44 controls organised across 5 domains. The largest domains are Part V - Remedies and Sanctions (18 controls), Part IV - Supervisory Authority (AZOP) (9 controls), Part III - Video Surveillance (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Act on the Implementation of the General Data Protection Regulation (OG 42/2018) do I already cover?

Act on the Implementation of the General Data Protection Regulation (OG 42/2018) maps to 2 other compliance frameworks. The top mapping partners are GDPR (34% coverage), NIST SP 800-53 Rev 5 (9% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Act on the Implementation of the General Data Protection Regulation (OG 42/2018)?

Start your Act on the Implementation of the General Data Protection Regulation (OG 42/2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Act on the Implementation of the General Data Protection Regulation (OG 42/2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 44 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required