Back to Frameworks

Act on the Implementation of the General Data Protection Regulation (OG 42/2018)

Croatia
vOG 42/2018 as amended by OG 71/2020 and OG 115/2022
5 domains
44 controls

The Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka, OG 42/2018) provides national provisions supplementing the EU GDPR in Croatia. It defines specific conditions for lawful processing, the rights of data subjects, and the powers of the Croatian Personal Data Protection Agency (AZOP). The act has been amended by OG 71/2020 and OG 115/2022 to align with subsequent EU legislative updates.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Part I - General Provisions

2 controls
Controls in the Part I - General Provisions domain of Act on the Implementation of the General Data Protection Regulation (OG 42/2018)2 controls
CodeTitle
HR-GDPR-Art.1Subject and Scope of the Act
HR-GDPR-Art.3Definitions and Public Authority Bodies

Part II - Special Categories of Data Processing

7 controls
Controls in the Part II - Special Categories of Data Processing domain of Act on the Implementation of the General Data Protection Regulation (OG 42/2018)7 controls
CodeTitle
HR-GDPR-Art.19Child's Consent for Information Society Services
HR-GDPR-Art.20Prohibition on Genetic Data Processing for Insurance
HR-GDPR-Art.21Biometric Data Processing - Public Sector
HR-GDPR-Art.22Biometric Data Processing - Private Sector
HR-GDPR-Art.23Biometric Data of Employees (Time and Access)
HR-GDPR-Art.24Applicability of Biometric Rules and DPIA
HR-GDPR-Art.33Processing for Statistical Purposes

Part III - Video Surveillance

8 controls
Controls in the Part III - Video Surveillance domain of Act on the Implementation of the General Data Protection Regulation (OG 42/2018)8 controls
CodeTitle
HR-GDPR-Art.25Video Surveillance - Definition
HR-GDPR-Art.26Video Surveillance - Lawful Purpose
HR-GDPR-Art.27Video Surveillance - Notice Requirements
HR-GDPR-Art.28Video Surveillance - Access Control and Logging
HR-GDPR-Art.29Video Surveillance - Retention Limit
HR-GDPR-Art.30Video Surveillance of Work Premises
HR-GDPR-Art.31Video Surveillance in Residential Buildings
HR-GDPR-Art.32Video Surveillance of Public Areas

Part IV - Supervisory Authority (AZOP)

9 controls
Controls in the Part IV - Supervisory Authority (AZOP) domain of Act on the Implementation of the General Data Protection Regulation (OG 42/2018)9 controls
CodeTitle
HR-GDPR-Art.11Prohibition on Agency Staff Acting as DPO
HR-GDPR-Art.13Professional Confidentiality Obligation
HR-GDPR-Art.14Legislative Consultation with AZOP
HR-GDPR-Art.15Cooperation with Foreign Supervisory Authorities
HR-GDPR-Art.17Annual Work Report
HR-GDPR-Art.18Publication of High-Risk Opinions and Decisions
HR-GDPR-Art.4Supervisory Authority (AZOP)
HR-GDPR-Art.5National Accreditation Body for Certification
HR-GDPR-Art.6Powers and Tasks of the Agency

Part V - Remedies and Sanctions

18 controls
Controls in the Part V - Remedies and Sanctions domain of Act on the Implementation of the General Data Protection Regulation (OG 42/2018)18 controls
CodeTitle
HR-GDPR-Art.34Right to Request Determination of Breach
HR-GDPR-Art.35Interim Relief in Deletion Cases
HR-GDPR-Art.36Conduct of Supervision (Inspections)
HR-GDPR-Art.37Copying, Sealing and Temporary Seizure
HR-GDPR-Art.38Suspicion of Criminal Offence
HR-GDPR-Art.39Handling of Classified Data
HR-GDPR-Art.40Inspection Report (Zapisnik)
HR-GDPR-Art.41Representation of Data Subjects
HR-GDPR-Art.42Provision of Expert Opinions
HR-GDPR-Art.43Fees for Acting on Requests
HR-GDPR-Art.44Imposition of Administrative Fines
HR-GDPR-Art.45Administrative Fine Decision
HR-GDPR-Art.46Payment and Forced Collection of Fines
HR-GDPR-Art.47Exclusion of Fines for Public Authority Bodies
HR-GDPR-Art.48Publication of Final Rulings
HR-GDPR-Art.49Statute of Limitations for Fine Collection
HR-GDPR-Art.50Misdemeanour Penalties for Confidentiality Breach
HR-GDPR-Art.51Administrative Fines for Video-Surveillance Violations

Your Compliance Coverage

If you comply with Act on the Implementation of the General Data Protection Regulation (OG 42/2018), you already cover:

+ 2 more: ISO 15189:2022 - Medical Laboratories Requirements for Quality and Competence (2%), ISO 31000:2018 (2%)

See all 5 mapped frameworks ↓

Maps to 5 other frameworks

44 total controls
GDPR
11 source controls mapped|8 target controls covered
25%
NIST SP 800-53 Rev 5
4 source controls mapped|5 target controls covered
9%
ISO 19011
1 source controls mapped|1 target controls covered
2%
2%
ISO 31000:2018
1 source controls mapped|1 target controls covered
2%

Frequently Asked Questions

What is Act on the Implementation of the General Data Protection Regulation (OG 42/2018)?

Act on the Implementation of the General Data Protection Regulation (OG 42/2018) is a compliance framework from Croatia with 5 domains and 44 controls. The Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka, OG 42/2018) provides national provisions supplementing the EU GDPR in Croatia. It defines specific conditions for lawful processing, the rights of data subjects, and the powers of the Croatian Personal Data Protection Agency (AZOP). The act has been amended by OG 71/2020 and OG 115/2022 to align with subsequent EU legislative updates. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Act on the Implementation of the General Data Protection Regulation (OG 42/2018) have?

Act on the Implementation of the General Data Protection Regulation (OG 42/2018) has 44 controls organised across 5 domains. The largest domains are Part V - Remedies and Sanctions (18 controls), Part IV - Supervisory Authority (AZOP) (9 controls), Part III - Video Surveillance (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Act on the Implementation of the General Data Protection Regulation (OG 42/2018) map to?

Act on the Implementation of the General Data Protection Regulation (OG 42/2018) maps to 5 other compliance frameworks. The top mapping partners are GDPR (25% coverage), NIST SP 800-53 Rev 5 (9% coverage), ISO 19011 (2% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Act on the Implementation of the General Data Protection Regulation (OG 42/2018) compliance?

Start your Act on the Implementation of the General Data Protection Regulation (OG 42/2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Act on the Implementation of the General Data Protection Regulation (OG 42/2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 44 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.

Get Started Free →

Free forever — no credit card required