Croatia
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Croatia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Croatia looks like an ordinary European Union country for privacy: data may leave once you have the right paperwork. But its accounting law is stricter than most people expect. A Croatian company's books and receipts may only be kept in Croatia or another European Union country. Public bodies must keep personal-data registers in Croatian data centres. The privacy regulator fines hard.
Data governance in Croatia
The eight things that decide how you handle data about people in Croatia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Croatia's rules reach a company with no office in the country. The European Union privacy rulebook applies to anyone who offers goods or services to people in Europe, or who watches what they do online. There is no revenue or headcount threshold. Croatia does not demand its own local representative on top of the Europe-wide one, which you may place in any European country.
- What you have to do here:
- Appoint a representative
The main law is Regulation (EU) 2016/679, the General Data Protection Regulation. It sets out who it applies to. Croatia's own addition is one Act. It is the Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka), Official Gazette 42/2018. It has been in force since 25 May 2018. That Act does not widen or narrow who is caught. It fills the gaps the Regulation leaves to member states. It leaves out police work on crime and work for national security, which sit under separate Croatian laws. There is no general registration or licensing step in Croatia. Two Croatian rules work differently. They apply because you have a presence in Croatia, not because you target people there. The Accounting Act binds every business subject to Croatian accounting law. That captures a Croatian subsidiary or branch even if the group is foreign. The Act on State Information Infrastructure binds Croatian public bodies and their suppliers.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka), Official Gazette 42/2018 - Articles 19, 26-32, 34
narodne-novine.nn.hr
“Kod primjene članka 6. stavka 1. točke (a) Opće uredbe o zaštiti podataka, u vezi s nuđenjem usluga informacijskog društva izravno djetetu, obrada osobnih podataka djeteta zakonita je ako dijete ima najmanje 16 godina.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 33, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
Where the data is allowed to live
Mostly yes, with one exception that catches everybody. Ordinary personal data can go abroad using the standard European transfer tools. Your accounting records cannot. Croatian law lets you keep them outside Croatia only in another European Union country. Health data, public-sector registers and aerial photographs each have their own separate limits.
- What you have to do here:
- Keep the data in the country
The answer depends on your industry. Here is the position for each, checked 18 August 2026. ALL BUSINESSES - ACCOUNTING RECORDS. Closed as against countries outside the European Union. The rule is in the Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024. It lets a company keep its accounting documents and business books outside Croatia only in another European Union member state. No transfer tool, consent or contract unlocks a country outside the Union. Where you hold the records electronically, you must give the supervising authority online access on demand. This is the Croatian rule people miss most often. It sits in tax and accounting law rather than privacy law. And it hits the systems most likely to run on cloud outside the Union: the finance system, the invoice archive and the payroll archive. GOVERNMENT AND PUBLIC SECTOR. Closed. The rule is in the Act on State Information Infrastructure (Zakon o državnoj informacijskoj infrastrukturi), Official Gazette 72/2025. Registers containing personal data must be stored in data centres on Croatian territory. Registers of non-personal data may sit in Croatia or another member state. The state can also require Croatian storage of non-personal data where public security justifies it. That is the opening Regulation (EU) 2018/1807 leaves. Some bodies must use the hosting services of the Shared Services Centre, the state cloud. Those are state administration bodies, other state bodies, and public institutions founded solely by the Republic of Croatia. HEALTH. A copy has to stay in Croatia. The rule is in the Act on Data and Information in Healthcare, Official Gazette 14/2019. Health data is handled electronically inside the health information infrastructure of the Republic of Croatia. All healthcare providers must exchange data through the Central Health Information System of the Republic of Croatia (CEZIH). The Act does not expressly ban a private clinic from also hosting its own records abroad. So we record this as a strong limit in fact rather than an express ban. MAPPING AND GEOSPATIAL. Allowed with conditions: a collection permit plus a defence check. The Regulation on Aerial Photography, Official Gazette 77/2020, requires a registered operator to hold an approval for aerial photography. That approval covers a survey period of at most three months. A second, separate approval is needed before the images may be used. A joint commission of the State Geodetic Administration and the Ministry of Defence inspects imagery showing military locations and defence structures. It decides which images may be released and which must be excluded. News organisations must hand the captured material to the State Geodetic Administration within eight days. BANKING. Allowed with conditions. The Croatian National Bank Decision on Outsourcing, Official Gazette 118/2020 as amended by Official Gazette 150/2024, does NOT require data to stay in Croatia. It requires the bank to record the cloud model and the exact location of the data. The provider must tell the bank when it changes location. The bank must assess country risk. Before using a supplier outside the Union, the bank must show that local law lets the Croatian National Bank inspect directly. Local law must also give the Bank prompt and unrestricted access to documents and data. The European Union's Digital Operational Resilience Act has covered outsourcing by financial firms since 17 January 2025. It does not require data to stay in any country either. PAYMENTS, INSURANCE, SECURITIES. Allowed with conditions. We found no Croatian rule that data must stay in the country, checked 18 August 2026. TELECOMS. Allowed with conditions, on the evidence we have. We found no Croatian rule on where telecoms data must be stored, checked 18 August 2026. Croatia does make operators keep traffic data under the Electronic Communications Act, Official Gazette 76/2022. We could not verify the keeping period or any location requirement from an official source. See the unconfirmed list. ONLINE GAMBLING. Allowed with conditions. Several neighbouring countries make the gaming server sit on their soil. We found no such rule in Croatia's Gambling Act (Official Gazette 87/09 to 72/25) or the remote betting rulebook, checked 18 August 2026. The remote betting rulebook does require the operator's system to connect directly to the Ministry of Finance information system. You must declare the equipment location in the licence application. Player money accounts must be held at a bank registered in Croatia. EDUCATION, E-COMMERCE, SOCIAL MEDIA, DEFENCE. We found no separate Croatian rule that data must stay in the country, checked 18 August 2026. Defence and national security work sits outside the general privacy law.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on State Information Infrastructure (Zakon o državnoj informacijskoj infrastrukturi), Official Gazette 72/2025 - Article 17 (mandatory use of the Shared Services Centre) and Article 27 (location of data)
narodne-novine.nn.hr
“Registri koji sadrže osobne podatke pohranjuju se u podatkovnim centrima koji se nalaze na teritoriju Republike Hrvatske.”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on Data and Information in Healthcare (Zakon o podacima i informacijama u zdravstvu), Official Gazette 14/2019 - Articles 19, 27, 28, 29
narodne-novine.nn.hr
“Obrada zdravstvenih podataka provodi se elektroničkim putem u zdravstvenoj informacijskoj infrastrukturi Republike Hrvatske.”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Regulation on Aerial Photography (Uredba o snimanju iz zraka), Official Gazette 77/2020 - Articles 4, 6, 9, 10, 13, 14
narodne-novine.nn.hr
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Croatian National Bank Decision on Outsourcing (Odluka o eksternalizaciji), Official Gazette 118/2020
narodne-novine.nn.hr
“propisi države odnosno država u kojima pružatelj usluga posluje omogućuju Hrvatskoj narodnoj banci ... neposredni nadzor dijela poslovanja ... pravodoban i neograničen pristup dokumentaciji”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union
eur-lex.europa.eu
Link checked 18 August 2026
- Secondary sourceZakon.hr (unofficial consolidation)Rulebook on remote betting games (Pravilnik o priređivanju igara klađenja na daljinu), Official Gazette 8/2010 - consolidated text
zakon.hr
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
For personal data, Croatia uses the European model. Some countries are pre-approved, and everywhere else you need a standard contract or a similar tool plus a risk check. The approved list is real and populated, and includes the United Kingdom, Japan, South Korea and Switzerland. For accounting records the model is different and much blunter: only European Union countries are allowed, and no paperwork buys you more.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent
For personal data you can send it freely to approved countries, and use standard tools for everywhere else. We verified the European Commission's list of approved countries on 18 August 2026. It covers Andorra, Argentina, Brazil (new, 26 January 2026), Canada for commercial bodies, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan and Jersey. It also covers New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland and Uruguay. It covers the United Kingdom too, renewed on 19 December 2025 and running to 2031. And it covers the European Patent Organisation. The United States is covered only for companies signed up to the EU-US Data Privacy Framework. None has been withdrawn or suspended. Where the destination is not approved, use the 2021 standard contract clauses (Decision (EU) 2021/914). They are still the current set and unchanged. The promised new clauses for recipients already covered by the Regulation have still not been adopted. Company-wide binding rules remain available. The narrow exceptions in the Regulation are not a basis for routine or bulk flows. You are also expected to write down why the destination country is safe. AZOP treats this seriously rather than as paperwork. On 14 November 2025 it fined a telecoms operator EUR 4.5 million (about 4.9 million US dollars). A supplier in Serbia had administrator-level access to the whole customer database. The operator had not put the 2021 standard clauses in place after the 27 December 2022 cut-off. It had not written down why Serbia was safe. And it had not told its 847,862 affected customers that their data went outside the European Economic Area. Accounting records work differently. Under the Accounting Act you may keep them only in European Union member states. Standard clauses, consent and company-wide rules make no difference to that.
Sources
- Official sourceAgencija za zaštitu osobnih podataka (AZOP)Administrative fine of EUR 4.5 million on a telecoms operator for transferring customer data to Serbia without a valid mechanism, 14 November 2025
azop.hr
“Izvršitelj obrade iz Republike Srbije mogao je pristupati cijeloj SAP CRM bazi i to s administratorskim ovlastima, a što je značilo da je imao neograničene ovlasti pristupu osobnim podacima”
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions - current list
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 on standard contractual clauses for transfers to third countries
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The main regulator is the Personal Data Protection Agency, known as AZOP. It is fully staffed, it hires more people, and it is one of the busiest fining bodies in central Europe for its size. It issued 13 fines totalling about 6.7 million euros (roughly 7.3 million dollars) in 2025, and 38 fines the year before. The cyber regulator, the National Cyber Security Centre, is also up and running.
- What it costs if you get it wrong:
- Percentage of global turnover · Fixed maximum fine · Criminal liability
AGENCIJA ZA ZASTITU OSOBNIH PODATAKA (AZOP) is the privacy regulator under the Act implementing the General Data Protection Regulation. It is independent and reports to Parliament. Its director serves a four-year term and can be reappointed once. It is clearly up and running. Its own published tally shows 1 fine in 2020, 4 in 2021, 14 in 2022, 28 in 2023, 38 in 2024 and 13 in 2025. The 2025 fines totalled EUR 6,725,500. Its largest fine so far is EUR 5.47 million against the debt collection agency EOS Matrix d.o.o. on 5 October 2023. Its second largest is the EUR 4.5 million telecoms fine of 14 November 2025. On 18 May 2026 it published five recruitment competitions for six posts, so it is staffed and growing rather than idle. We rate enforcement active rather than aggressive. The fines are large but the number of cases each year is modest. Most cases come from complaints rather than from the regulator's own sweeps. The 2025 fines fell on a telecoms operator, a bank, an energy producer, a betting operator, the Croatian Insurance Bureau and a parking company. That spread shows AZOP is not limited to one industry. NACIONALNI CENTAR ZA KIBERNETICKU SIGURNOST (NCSC-HR) sits inside the Security and Intelligence Agency. It is the central state body for cybersecurity. It is also the national computer security incident response team, the crisis management body and the single point of contact under the Cybersecurity Act. It runs the national incident reporting platform. The National CERT at CARNET covers the remaining industries. Both are up and running and publishing guidance. Other regulators matter for data too. The Croatian National Bank covers banks. The Croatian Financial Services Supervisory Agency covers insurance, pensions and markets. The State Geodetic Administration covers aerial imagery. The Tax Administration covers eInvoice reporting and accounting records. The Ministry of Justice, Public Administration and Digital Transformation covers the state information infrastructure. Unlawful use of personal data is also a crime under the Criminal Code, and the State Attorney's Office does prosecute it.
Sources
- Official sourceAgencija za zaštitu osobnih podataka (AZOP)Administrative fines issued by the Croatian Personal Data Protection Agency, by year (2020-2025)
azop.hr
Link checked 18 August 2026
- Official sourceAgencija za zaštitu osobnih podataka (AZOP)Administrative fine of EUR 4.5 million on a telecoms operator for transferring customer data to Serbia without a valid mechanism, 14 November 2025
azop.hr
“Izvršitelj obrade iz Republike Srbije mogao je pristupati cijeloj SAP CRM bazi i to s administratorskim ovlastima, a što je značilo da je imao neograničene ovlasti pristupu osobnim podacima”
Link checked 18 August 2026
- Official sourceAgencija za zaštitu osobnih podataka (AZOP)Five recruitment competitions for six posts at the Personal Data Protection Agency, published 18 May 2026
azop.hr
Link checked 18 August 2026
- Official sourceAgencija za zaštitu osobnih podataka (AZOP)Administrative fine of EUR 5.47 million on debt collection agency EOS Matrix d.o.o., 5 October 2023
azop.hr
Link checked 18 August 2026
- Official sourceNacionalni centar za kibernetičku sigurnost (NCSC-HR)About the National Cyber Security Centre (NCSC-HR), operating within the Security and Intelligence Agency
ncsc.hr
Link checked 18 August 2026
- Official sourceDržavno odvjetništvo Republike Hrvatske (State Attorney's Office)Indictment for unlawful use of personal data under Article 146 of the Criminal Code and computer fraud, Municipal State Attorney's Office in Rijeka
dorh.hr
Link checked 18 August 2026
How long you must keep it — and when to delete it
Croatia has strong minimum keeping periods and a few hard maximums. Ledgers and the documents behind them must be kept at least eleven years; payroll lists six years; the detailed wage and contribution records forever. Medical records run to ten years after the patient dies. Going the other way, camera footage must normally be deleted after six months.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep records of how you use data
MINIMUMS. Accounting Act, Official Gazette 85/2024: the journal and general ledger at least 11 years. Subsidiary ledgers at least 11 years. Documents supporting entries in the journal and general ledger at least 11 years. Documents supporting entries in subsidiary ledgers at least 11 years. Payroll lists at least 6 years. Analytical records of wages and contributions permanently. The clock runs from the last day of the business year they relate to. The same Act also fixes where you may keep them: Croatia or another European Union member state, nowhere else. Healthcare: medical records are kept for ten years after the person dies, and data in the statutory health registers is kept permanently. eInvoice reporting has applied since 1 January 2026 and creates a further archive that falls under the accounting keeping rules. MAXIMUMS. Camera recordings must be deleted after six months at the latest. That changes only if another law sets a longer period, or the footage is evidence in a case. The general European rule applies on top. Do not keep personal data in a form that identifies someone for longer than you need it. AZOP's 2025 decisions repeatedly counted the lack of any deletion policy against the company. CONFLICT. Croatia settles the clash the normal European way. A keeping period set by another law beats a deletion request. So someone cannot force you to delete an invoice inside the eleven years. The trap is that this covers only the accounting record itself. Marketing profiles, call recordings and camera footage about the same customer are not covered. You must still delete those on time.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on Data and Information in Healthcare (Zakon o podacima i informacijama u zdravstvu), Official Gazette 14/2019 - Articles 19, 27, 28, 29
narodne-novine.nn.hr
“Obrada zdravstvenih podataka provodi se elektroničkim putem u zdravstvenoj informacijskoj infrastrukturi Republike Hrvatske.”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka), Official Gazette 42/2018 - Articles 19, 26-32, 34
narodne-novine.nn.hr
“Kod primjene članka 6. stavka 1. točke (a) Opće uredbe o zaštiti podataka, u vezi s nuđenjem usluga informacijskog društva izravno djetetu, obrada osobnih podataka djeteta zakonita je ako dijete ima najmanje 16 godina.”
Link checked 18 August 2026
- Official sourcePorezna uprava (Croatian Tax Administration)Fiscalisation of eInvoices - mandatory from 1 January 2026, second phase from 1 January 2027
porezna-uprava.gov.hr
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are at least two deadlines and they run at different speeds. A personal data breach goes to the privacy regulator within 72 hours. A significant cyber incident goes to the cyber authority within 24 hours as an early warning. A fuller report follows at 72 hours, and a final report within 30 days. One incident can easily trigger both. The 24-hour deadline is the one that catches people out.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents · Secure the data
CLOCK 1 - PERSONAL DATA BREACH. Under Regulation (EU) 2016/679, tell AZOP without undue delay and, where you can, within 72 hours of finding out. You can skip this if the breach is unlikely to create a risk. Tell the people affected without undue delay where the risk to them is high. Croatia does not change these deadlines. CLOCK 2 - SIGNIFICANT CYBER INCIDENT. This comes from the Cybersecurity Act, Official Gazette 14/2024, and the Cybersecurity Regulation, Official Gazette 135/2024. They put the European network and information security directive into Croatian law. Essential and important entities must send an early warning within 24 hours of finding out. A fuller notice follows within 72 hours. An interim report is due if the response team asks for one, usually within 48 hours to 7 days. A final report is due within 30 days of the first notice. If the incident is still running, send progress reports every 30 days. Trust service providers skip the early warning but must file the first notice within 24 hours. Reports go through the national platform for collecting and sharing threat and incident data. If the platform is down, email the relevant response team. CLOCK 3 - FINANCIAL FIRMS. The European Union's Digital Operational Resilience Act has applied since 17 January 2025. It adds its own reporting timetable for major incidents at banks, insurers, investment firms and their critical technology providers. CLOCK 4 - TELECOMS. The Electronic Communications Act makes operators report security incidents to the telecoms regulator. We could not verify the exact deadline from an official source. It is listed as unconfirmed. The mistake is almost always the same. The security team starts the 72-hour privacy clock and forgets that the cyber early warning was due at hour 24.
Sources
- Official sourceNacionalni CERT / CARNETGeneral guidance on the duty to notify significant incidents (Opce smjernice za provedbu obveze obavjestavanja o znacajnim incidentima) - 24 hour early warning, 72 hour notification, 30 day final report
cert.hr
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Cybersecurity Act (Zakon o kibernetičkoj sigurnosti), Official Gazette 14/2024
narodne-novine.nn.hr
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 33, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things. Your ledger cannot live on an American cloud. Children count as adults for online consent at 16, not 13. Using someone's personal data unlawfully is a crime, not just a fine. Genetic test results may never be used to price life insurance. And camera footage in an apartment building needs two thirds of the owners to agree.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
1. THE ACCOUNTING CLOUD TRAP. The Accounting Act lets you hold business books and accounting documents outside Croatia only in another European Union member state. That is not a privacy rule, and no privacy paperwork overrides it. Say a Croatian subsidiary runs its finance system, invoice archive or payroll archive abroad. If that infrastructure is in the United States, the United Kingdom, Switzerland or Serbia, it is breaking the rule. What its data protection contract says makes no difference. Compulsory eInvoice reporting began on 1 January 2026, so the volume of records caught by this rule has grown sharply. 2. AGE 16, NOT 13 OR 15. The Act implementing the General Data Protection Regulation sets 16 as the age at which a child can agree to an online service. Croatia took the highest age the Regulation allows. A product built to a 13-year cut-off breaks the rules in Croatia. A single global setting of 15 or 16 will still be wrong unless it is 16 for Croatia. 3. CRIMINAL LIABILITY. The Criminal Code makes unlawful use of personal data a crime. It attaches to people, not just to companies. The State Attorney's Office does bring charges under it, sometimes alongside computer fraud. An employee who misuses a customer database is personally at risk. So is the manager who told them to do it. 4. GENETIC DATA AND LIFE INSURANCE. The Croatian implementing Act bans one use of genetic data. You may not use it to price a life insurance policy. That covers working out how likely someone is to fall ill, and other health facts about them. This is a flat national ban. Consent does not unlock it. Most other member states have nothing like it. 5. CAMERAS HAVE THEIR OWN RULES. Croatia puts the camera rules in the law itself rather than in guidance. Delete recordings within six months, unless another law says otherwise or they are evidence. Signs must name the company responsible and give its contact details. You may not film changing rooms, washrooms or rest areas. Public areas may generally be filmed only by public authorities and public service providers. In a residential building you need two thirds of the co-owners to agree, and you may cover only entrances and common areas. Fingerprint or face-based door entry and clocking-in systems in the private sector need each employee's explicit consent. They must also be offered as an alternative to another option. That makes fingerprint-only clocking systems hard to justify. 6. BONUS - PUBLIC PROCUREMENT. If you sell software to the Croatian state, the Act on State Information Infrastructure now forces personal-data registers into Croatian data centres. It also forces state bodies into the government's Shared Services Centre. A foreign vendor whose systems assume a big cloud region outside Croatia cannot bid credibly.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka), Official Gazette 42/2018 - Articles 19, 26-32, 34
narodne-novine.nn.hr
“Kod primjene članka 6. stavka 1. točke (a) Opće uredbe o zaštiti podataka, u vezi s nuđenjem usluga informacijskog društva izravno djetetu, obrada osobnih podataka djeteta zakonita je ako dijete ima najmanje 16 godina.”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
- Official sourceDržavno odvjetništvo Republike Hrvatske (State Attorney's Office)Indictment for unlawful use of personal data under Article 146 of the Criminal Code and computer fraud, Municipal State Attorney's Office in Rijeka
dorh.hr
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on State Information Infrastructure (Zakon o državnoj informacijskoj infrastrukturi), Official Gazette 72/2025 - Article 17 (mandatory use of the Shared Services Centre) and Article 27 (location of data)
narodne-novine.nn.hr
“Registri koji sadrže osobne podatke pohranjuju se u podatkovnim centrima koji se nalaze na teritoriju Republike Hrvatske.”
Link checked 18 August 2026
- Official sourcePorezna uprava (Croatian Tax Administration)Fiscalisation of eInvoices - mandatory from 1 January 2026, second phase from 1 January 2027
porezna-uprava.gov.hr
Link checked 18 August 2026
What's changing next
Two Croatian dates matter. Fines under the state information infrastructure law switch on 1 January 2027. Mandatory eInvoicing widens to smaller traders on the same day. Across Europe, cloud switching fees must fall to zero by 12 January 2027. The thing to watch is the challenge to the Europe-United States data deal, which is still valid but under real pressure.
- What you have to do here:
- Make switching cloud provider possible
- Ways to send data out:
- Official 'this country is safe' decision
CROATIA - WITH DATES. 1 January 2027: the penalty parts of the Act on State Information Infrastructure start to apply. Fines run from EUR 500 to EUR 6,630, roughly 540 to 7,200 US dollars. Until then the Croatian data-centre rule for state registers is in force but carries no fine. That gap is exactly what makes suppliers miss it. 1 January 2027: the second phase of eInvoice reporting catches traders who are not registered for value added tax. Phase one, covering businesses registered for value added tax, has applied since 1 January 2026. Within 12 months of the state infrastructure regulation: projects must be registered in the state project register, and data exchange interfaces must be built. A public consultation on changes to the Electronic Communications Act was open in 2026. We could not verify its content from an official source. EUROPEAN UNION - WITH DATES. 12 January 2027: under the Data Act, Regulation (EU) 2023/2854, all cloud switching charges and data export fees must be zero. This is a firm deadline and it changes what cloud contracts cost. 2 August 2026: the openness duties of the Artificial Intelligence Act have already started. Still not adopted: the European cloud certification scheme, stuck over sovereignty since 2020. So national arrangements continue to apply. The Digital Omnibus proposal of 19 November 2025 would loosen the definition of personal data and stretch breach reporting from 72 to 96 hours. It has no legal effect, and its core change was opposed in February 2026. POWERS ALREADY HELD, which could change the answer with no consultation. 1. The Act on State Information Infrastructure lets the state require NON-personal data to be stored in Croatia where public security justifies it. Regulation (EU) 2018/1807 leaves that opening. Croatia has written it into its law, ready to use. 2. The Ministry of Defence commission for aerial imagery can block any image from release, with no published standard. You can fly a survey lawfully and still be unable to use the results. 3. The Europe-United States Data Privacy Framework is still in force and legally valid on 18 August 2026. But the Latombe appeal is pending before the Court of Justice, after the General Court dismissed the case on 3 September 2025. The United States oversight bodies behind it have been weakened. On 31 July 2026 the European Data Protection Board wrote to the Commission. It asked the Commission to check whether the decision that the United States is safe enough still holds. The Commission has not suspended or revoked it. Do not build on it as your only route.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on State Information Infrastructure (Zakon o državnoj informacijskoj infrastrukturi), Official Gazette 72/2025 - Article 17 (mandatory use of the Shared Services Centre) and Article 27 (location of data)
narodne-novine.nn.hr
“Registri koji sadrže osobne podatke pohranjuju se u podatkovnim centrima koji se nalaze na teritoriju Republike Hrvatske.”
Link checked 18 August 2026
- Official sourcePorezna uprava (Croatian Tax Administration)Fiscalisation of eInvoices - mandatory from 1 January 2026, second phase from 1 January 2027
porezna-uprava.gov.hr
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) - cloud switching charges must fall to zero from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEuropean Data Protection Board - July 2026 letter to the Commission on the EU-US Data Privacy Framework
edpb.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Diarise 1 January 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: Zakon o državnoj informacijskoj infrastrukturi · Narodne novine 72/2025, Articles 17 and 27; penalty Articles 33-34 apply from 1 January 2027 · Act of parliament
Croatian state registers that contain personal data must be held in data centres inside Croatia, and public bodies must use the government's own shared cloud. The rule is already in force but no fine can be imposed for breaking it until 1 January 2027.
That is a long gap: the duty is real law today, but no penalty can follow until 1 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by Ministry of Justice, Public Administration and Digital Transformation
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryRegisters containing personal data must be stored in data centres on Croatian territory. Non-personal registers may sit in Croatia or another member state, or be forced into Croatia on public security grounds.
- Prove the data stays under local controlState administration bodies, other state bodies and public institutions founded solely by the Republic of Croatia must use the state Shared Services Centre for hosting.
What it costs if you get it wrong
- Fixed maximum fine: €6,630 — about $7 thousandBreach of the Act; penalty provisions apply only from 1 January 2027.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on State Information Infrastructure (Zakon o državnoj informacijskoj infrastrukturi), Official Gazette 72/2025 - Article 17 (mandatory use of the Shared Services Centre) and Article 27 (location of data)
narodne-novine.nn.hr
“Registri koji sadrže osobne podatke pohranjuju se u podatkovnim centrima koji se nalaze na teritoriju Republike Hrvatske.”
Link checked 18 August 2026
- Official sourceMinistarstvo pravosuđa, uprave i digitalne transformacijeShared Services Centre (CDU) - the state cloud powering digital Croatia
mpudt.gov.hr
Link checked 18 August 2026
Health and social care data needs a copy kept in the country
Official name: Zakon o podacima i informacijama u zdravstvu · Narodne novine 14/2019, Articles 19(2), 27, 28, 29 · Act of parliament
Health data in Croatia is handled inside the national health information infrastructure and exchanged through the central health system. That keeps it in Croatia for any realistic purpose. The law does not spell out an express ban on hosting a copy abroad.
How this country controls where data goes: Approval each time
What you have to do
- Keep the data in the countryHealth data is handled electronically within the health information infrastructure of the Republic of Croatia.
- Keep data for a minimum period — 10 yearsMedical documentation kept for ten years after the person's death; register data kept permanently.
- Secure the dataExchange through the Central Health Information System must use automated means over a protected channel.
What it costs if you get it wrong
- Fixed maximum fine: HRK 100,000 — about $15 thousandUnlawful processing or failure to exchange data through the central health system. Amounts are still expressed in kuna in the 2019 text.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on Data and Information in Healthcare (Zakon o podacima i informacijama u zdravstvu), Official Gazette 14/2019 - Articles 19, 27, 28, 29
narodne-novine.nn.hr
“Obrada zdravstvenih podataka provodi se elektroničkim putem u zdravstvenoj informacijskoj infrastrukturi Republike Hrvatske.”
Link checked 18 August 2026
State and security data rules
Official name: Uredba o snimanju iz zraka · Narodne novine 77/2020, Articles 4, 6, 7, 9, 10, 13, 14 · Directly binding regulation
Photographing Croatia from the air needs one government approval to fly. It needs a second, separate approval before the images may be used. The Ministry of Defence checks the images first and can order frames to be excluded.
Enforced by State Geodetic Administration
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyThe operator must be registered for the activity and hold an approval for aerial photography, valid for a survey window of at most three months.
- Independent auditA joint commission of the State Geodetic Administration and the Ministry of Defence reviews imagery showing military and defence facilities before any use is approved.
- Keep records of how you use dataNews organisations must deliver the captured material to the State Geodetic Administration within eight days.
What it costs if you get it wrong
- Order to stopRefusal of the approval to use the imagery, or exclusion of specific frames.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Regulation on Aerial Photography (Uredba o snimanju iz zraka), Official Gazette 77/2020 - Articles 4, 6, 9, 10, 13, 14
narodne-novine.nn.hr
Link checked 18 August 2026
- Official sourceDržavna geodetska uprava (State Geodetic Administration)Aerial photography - approvals page of the State Geodetic Administration
dgu.gov.hr
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Odluka o eksternalizaciji · Narodne novine 118/2020, amended by Narodne novine 150/2024 · Regulator directive
Croatian banks may use foreign and cloud providers, including outside Europe. But the Croatian National Bank must still be able to inspect the provider directly and get unrestricted access to the data. There is no requirement to keep banking data in Croatia.
Enforced by Croatian National Bank
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Written vendor contractThe contract must state the cloud model and the exact location where data is held, used and stored. It must also make the provider report any change of location.
- Independent auditBefore using a supplier outside the European Union, the bank must show two things. Local law lets the Croatian National Bank inspect the supplier directly. And local law gives the Bank timely, unrestricted access to documents and data.
- Assess high-risk projectsCountry and region risk, and differences in national data protection law, must be assessed and documented.
What it costs if you get it wrong
- Order to stopSupervisory order to terminate or restructure the outsourcing arrangement.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Croatian National Bank Decision on Outsourcing (Odluka o eksternalizaciji), Official Gazette 118/2020
narodne-novine.nn.hr
“propisi države odnosno država u kojima pružatelj usluga posluje omogućuju Hrvatskoj narodnoj banci ... neposredni nadzor dijela poslovanja ... pravodoban i neograničen pristup dokumentaciji”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Decision amending the Decision on Outsourcing (Odluka o izmjenama Odluke o eksternalizaciji), Official Gazette 150/2024
narodne-novine.nn.hr
Link checked 18 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
Personal data must stay in the country
Official name: Zakon o računovodstvu · Narodne novine 85/2024, Articles 10(3) and 13(3); consolidated to Narodne novine 59/2026 · Act of parliament
A Croatian company may keep its books and the documents behind them outside Croatia only in another European Union country. There is no contract, consent or approval that permits storage in the United States or any other non-EU country.
Enforced by Tax Administration
How this country controls where data goes: Only approved countries
What you have to do
- Keep the data in the countryAccounting documents and business books may be kept outside Croatia only in another European Union member state.
- Keep data for a minimum period — 11 yearsJournal, general ledger, subsidiary ledgers and the documents behind them: at least 11 years.
- Keep data for a minimum period — 6 yearsPayroll lists: at least 6 years. Analytical records of wages and contributions: permanently.
- Keep records of how you use dataWhere records are held electronically, the supervising body must be given access on request.
What it costs if you get it wrong
- Fixed maximum fineFailure to keep or produce business books and accounting documents as required. Exact amounts not verified.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
- Secondary sourceZakon.hr (unofficial consolidation)Accounting Act - consolidated text as amended to Official Gazette 59/2026, in force 10 June 2026
zakon.hr
Link checked 18 August 2026
Insurance rules
Official name: Zakon o provedbi Opće uredbe o zaštiti podataka · Narodne novine 42/2018, Articles 19, 25-34 · Act of parliament
Croatia's national privacy law sits on top of the European rulebook. It has three distinctive features. The digital consent age is 16. There is a detailed camera surveillance code in the law itself. And there is a flat ban on using genetic data to price life insurance.
Enforced by Personal Data Protection Agency
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest
What you have to do
- Get a parent's consent for children — applies at: under 16 years oldCroatia set the digital consent age at the maximum the European rulebook allows.
- Delete data after a period — 6 monthsVideo surveillance recordings deleted after six months unless another law or evidential need extends it.
- Tell people what you doCamera signs must name the company responsible and give its contact details.
- Put a transfer safeguard in place
- Appoint a data protection officer
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover — about $22 millionBreach of basic principles, individual rights or the transfer rules.
- Order to stopOrder to stop processing or to suspend flows to a third country.
- Claims by individualsCompensation claims by individuals.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka), Official Gazette 42/2018 - Articles 19, 26-32, 34
narodne-novine.nn.hr
“Kod primjene članka 6. stavka 1. točke (a) Opće uredbe o zaštiti podataka, u vezi s nuđenjem usluga informacijskog društva izravno djetetu, obrada osobnih podataka djeteta zakonita je ako dijete ima najmanje 16 godina.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 33, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
Cyber security rules
Official name: Zakon o kibernetičkoj sigurnosti (i Uredba o kibernetičkoj sigurnosti) · Narodne novine 14/2024; Cybersecurity Regulation, Narodne novine 135/2024, Articles 65-71 · Act of parliament
Croatia's cybersecurity law puts the European network and information security rules into national law. Significant incidents need an early warning in 24 hours, a full report in 72 hours and a closing report within 30 days. It says nothing about where data must be stored.
Enforced by National Cyber Security Centre
How this country controls where data goes: No restriction
What you have to do
- Report cyber incidents — within 24 hoursEarly warning to the competent incident response team within 24 hours of becoming aware.
- Report cyber incidents — within 72 hoursFull incident notification within 72 hours. Trust service providers file at 24 hours and are exempt from the early warning.
- Report cyber incidents — within 720 hoursFinal report within 30 days of the initial notification; progress reports every 30 days while the incident continues.
- Register or notifyEssential and important entities must be registered and categorised.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fineFailure to report or to implement required security measures. Amounts follow the European network and information security regime.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Cybersecurity Act (Zakon o kibernetičkoj sigurnosti), Official Gazette 14/2024
narodne-novine.nn.hr
Link checked 18 August 2026
- Official sourceNacionalni CERT / CARNETGeneral guidance on the duty to notify significant incidents (Opce smjernice za provedbu obveze obavjestavanja o znacajnim incidentima) - 24 hour early warning, 72 hour notification, 30 day final report
cert.hr
Link checked 18 August 2026
- Official sourceNacionalni centar za kibernetičku sigurnost (NCSC-HR)About the National Cyber Security Centre (NCSC-HR), operating within the Security and Intelligence Agency
ncsc.hr
Link checked 18 August 2026
Record-keeping rules for tax and accounts
Official name: Zakon o fiskalizaciji · Zakon o fiskalizaciji; eInvoice obligations phased 1 January 2026 and 1 January 2027 · Act of parliament
Since 1 January 2026 Croatian businesses registered for value added tax must issue electronic invoices and report them to the Tax Administration. The resulting archive is caught by the accounting rule that keeps records inside the European Union.
Enforced by Tax Administration
How this country controls where data goes: No restriction
What you have to do
- Keep records of how you use data — from 1 January 2026Businesses registered for value added tax must issue eInvoices to business customers. They must report them to the Tax Administration. Every recipient must receive and report them too.
- Keep records of how you use data — from 1 January 2027Second phase extends the issuing duty to traders not registered for value added tax.
- Keep data for a minimum period — 11 yearsThe resulting eInvoice archive falls inside the Accounting Act retention and storage-location rules.
What it costs if you get it wrong
- Fixed maximum fineFailure to issue, receive or report an eInvoice. Amounts not verified.
Sources
- Official sourcePorezna uprava (Croatian Tax Administration)Fiscalisation of eInvoices - mandatory from 1 January 2026, second phase from 1 January 2027
porezna-uprava.gov.hr
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
General data protection law
Official name: Kazneni zakon, članak 146. – Nedozvoljena uporaba osobnih podataka · Criminal Code, Article 146 (unlawful use of personal data) · Act of parliament
Misusing personal data is a criminal offence in Croatia, not only a regulatory one. Prosecutors do bring charges under it against individuals, typically together with computer fraud.
What you have to do
- Secure the dataMisuse of personal data by an individual is prosecuted, not merely fined.
What it costs if you get it wrong
- Criminal liabilityCollecting, processing or using personal data contrary to law, including for gain. Prosecuted by the State Attorney's Office, often alongside computer fraud.
Sources
- Official sourceDržavno odvjetništvo Republike Hrvatske (State Attorney's Office)Indictment for unlawful use of personal data under Article 146 of the Criminal Code and computer fraud, Municipal State Attorney's Office in Rijeka
dorh.hr
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Croatia's traffic and location data retention regime for telecoms operators - the article number, the retention period, and whether retained data must be held in Croatia.
We could not confirm how long telecoms operators must keep traffic and location data, or whether it has to stay in Croatia. Checked 18 August 2026. If you run a telecoms service, ask the regulator before you rely on a period.
The deadline for a telecoms operator to notify the Croatian telecoms regulator of a security incident.
The duty to report clearly exists, but we could not confirm the deadline against an official text. If you run a telecoms service, ask the regulator for the deadline.
Whether any Croatian court or the Constitutional Court has disapplied or limited the Croatian telecoms data retention provisions following the Court of Justice case law on general and indiscriminate retention.
We found no Croatian court ruling on this on an official court website, checked 18 August 2026. That does not mean none exists. Check before you rely on it.
The exact misdemeanour fine amounts under the Accounting Act for keeping business books or accounting documents outside the European Union.
We could not confirm the fine amounts for keeping business books or accounting documents outside the European Union. The ban itself is confirmed from the official text. Only the amount is unconfirmed.
Whether the Act on Data and Information in Healthcare bars a private healthcare provider from additionally hosting its own patient records outside Croatia.
The law makes health data run inside Croatia's health information infrastructure, and makes providers exchange it through the central health system. We found no express ban on a private provider also hosting its own records abroad. Treat this as a limit in fact rather than a stated ban. Confidence is medium.
Whether the Croatian Financial Services Supervisory Agency imposes cloud or outsourcing location conditions on insurers, pension companies and investment firms beyond the European Digital Operational Resilience Act.
We found no rulebook on the regulator's own site setting cloud or location conditions for insurers, pension companies and investment firms. That is a rule we did not find, not proof that none exists. If you are in one of those industries, check with the regulator.
Whether the current Act on Archival Material and Archives restricts taking a company's documentary material out of Croatia, and whether doing so is still a criminal offence.
We could not confirm what the current Act on Archival Material and Archives says. The 1997 version carried up to five years in prison for removing original archival material without ministry approval. It was replaced in 2018. We make no claim about the current text, so check it if you hold archival material.
The exact maximum sentence under Article 146 of the Croatian Criminal Code for unlawful use of personal data.
We could not confirm the maximum sentence for unlawful use of personal data. The offence itself, and live prosecutions under it, are confirmed from the State Attorney's Office. Only the penalty range is unconfirmed.
The content and closing date of the 2026 public consultation on amendments to the Electronic Communications Act.
We could not confirm the content or closing date of the 2026 consultation on changes to the Electronic Communications Act. The government's consultation page returned an error on 18 August 2026.
Whether AZOP has issued fines in 2026.
We could not confirm whether AZOP has issued any fines in 2026. Its published fines table was last changed in February 2026 and stops at 2025. Its 2026 activity shows up in recruitment notices instead.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.