Act on the Implementation of the General Data Protection Regulation (OG 42/2018)
The Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka, OG 42/2018) provides national provisions supplementing the EU GDPR in Croatia. It defines specific conditions for lawful processing, the rights of data subjects, and the powers of the Croatian Personal Data Protection Agency (AZOP). The act has been amended by OG 71/2020 and OG 115/2022 to align with subsequent EU legislative updates.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Part I - General Provisions
| Code | Title |
|---|---|
| HR-GDPR-Art.1 | Subject and Scope of the Act |
| HR-GDPR-Art.3 | Definitions and Public Authority Bodies |
Part II - Special Categories of Data Processing
| Code | Title |
|---|---|
| HR-GDPR-Art.19 | Child's Consent for Information Society Services |
| HR-GDPR-Art.20 | Prohibition on Genetic Data Processing for Insurance |
| HR-GDPR-Art.21 | Biometric Data Processing - Public Sector |
| HR-GDPR-Art.22 | Biometric Data Processing - Private Sector |
| HR-GDPR-Art.23 | Biometric Data of Employees (Time and Access) |
| HR-GDPR-Art.24 | Applicability of Biometric Rules and DPIA |
| HR-GDPR-Art.33 | Processing for Statistical Purposes |
Part III - Video Surveillance
| Code | Title |
|---|---|
| HR-GDPR-Art.25 | Video Surveillance - Definition |
| HR-GDPR-Art.26 | Video Surveillance - Lawful Purpose |
| HR-GDPR-Art.27 | Video Surveillance - Notice Requirements |
| HR-GDPR-Art.28 | Video Surveillance - Access Control and Logging |
| HR-GDPR-Art.29 | Video Surveillance - Retention Limit |
| HR-GDPR-Art.30 | Video Surveillance of Work Premises |
| HR-GDPR-Art.31 | Video Surveillance in Residential Buildings |
| HR-GDPR-Art.32 | Video Surveillance of Public Areas |
Part IV - Supervisory Authority (AZOP)
| Code | Title |
|---|---|
| HR-GDPR-Art.11 | Prohibition on Agency Staff Acting as DPO |
| HR-GDPR-Art.13 | Professional Confidentiality Obligation |
| HR-GDPR-Art.14 | Legislative Consultation with AZOP |
| HR-GDPR-Art.15 | Cooperation with Foreign Supervisory Authorities |
| HR-GDPR-Art.17 | Annual Work Report |
| HR-GDPR-Art.18 | Publication of High-Risk Opinions and Decisions |
| HR-GDPR-Art.4 | Supervisory Authority (AZOP) |
| HR-GDPR-Art.5 | National Accreditation Body for Certification |
| HR-GDPR-Art.6 | Powers and Tasks of the Agency |
Part V - Remedies and Sanctions
| Code | Title |
|---|---|
| HR-GDPR-Art.34 | Right to Request Determination of Breach |
| HR-GDPR-Art.35 | Interim Relief in Deletion Cases |
| HR-GDPR-Art.36 | Conduct of Supervision (Inspections) |
| HR-GDPR-Art.37 | Copying, Sealing and Temporary Seizure |
| HR-GDPR-Art.38 | Suspicion of Criminal Offence |
| HR-GDPR-Art.39 | Handling of Classified Data |
| HR-GDPR-Art.40 | Inspection Report (Zapisnik) |
| HR-GDPR-Art.41 | Representation of Data Subjects |
| HR-GDPR-Art.42 | Provision of Expert Opinions |
| HR-GDPR-Art.43 | Fees for Acting on Requests |
| HR-GDPR-Art.44 | Imposition of Administrative Fines |
| HR-GDPR-Art.45 | Administrative Fine Decision |
| HR-GDPR-Art.46 | Payment and Forced Collection of Fines |
| HR-GDPR-Art.47 | Exclusion of Fines for Public Authority Bodies |
| HR-GDPR-Art.48 | Publication of Final Rulings |
| HR-GDPR-Art.49 | Statute of Limitations for Fine Collection |
| HR-GDPR-Art.50 | Misdemeanour Penalties for Confidentiality Breach |
| HR-GDPR-Art.51 | Administrative Fines for Video-Surveillance Violations |
Your Compliance Coverage
If you comply with Act on the Implementation of the General Data Protection Regulation (OG 42/2018), you already cover:
GDPR
25%
11 controls mapped
Compare →NIST SP 800-53 Rev 5
9%
4 controls mapped
Compare →ISO 19011
2%
1 controls mapped
Compare →+ 2 more: ISO 15189:2022 - Medical Laboratories Requirements for Quality and Competence (2%), ISO 31000:2018 (2%)
See all 5 mapped frameworks ↓Maps to 5 other frameworks
Frequently Asked Questions
What is Act on the Implementation of the General Data Protection Regulation (OG 42/2018)?
Act on the Implementation of the General Data Protection Regulation (OG 42/2018) is a compliance framework from Croatia with 5 domains and 44 controls. The Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka, OG 42/2018) provides national provisions supplementing the EU GDPR in Croatia. It defines specific conditions for lawful processing, the rights of data subjects, and the powers of the Croatian Personal Data Protection Agency (AZOP). The act has been amended by OG 71/2020 and OG 115/2022 to align with subsequent EU legislative updates. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Act on the Implementation of the General Data Protection Regulation (OG 42/2018) have?
Act on the Implementation of the General Data Protection Regulation (OG 42/2018) has 44 controls organised across 5 domains. The largest domains are Part V - Remedies and Sanctions (18 controls), Part IV - Supervisory Authority (AZOP) (9 controls), Part III - Video Surveillance (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Act on the Implementation of the General Data Protection Regulation (OG 42/2018) map to?
Act on the Implementation of the General Data Protection Regulation (OG 42/2018) maps to 5 other compliance frameworks. The top mapping partners are GDPR (25% coverage), NIST SP 800-53 Rev 5 (9% coverage), ISO 19011 (2% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Act on the Implementation of the General Data Protection Regulation (OG 42/2018) compliance?
Start your Act on the Implementation of the General Data Protection Regulation (OG 42/2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Act on the Implementation of the General Data Protection Regulation (OG 42/2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 44 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.
Get Started Free →Free forever — no credit card required