Croatia
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Croatia looks like an ordinary European Union country for privacy: data may leave once you have the right paperwork. But its accounting law is stricter than most people expect. A Croatian company's books and receipts may only be kept in Croatia or another European Union country. Public bodies must keep personal-data registers in Croatian data centres. The privacy regulator fines hard.
Eight questions about Croatia
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Croatia's rules apply to my company?
Yes. Croatia's rules reach a company with no office in the country. The European Union privacy rulebook applies to anyone who offers goods or services to people in Europe, or who watches what they do online. There is no revenue or headcount threshold. Croatia does not demand its own local representative on top of the Europe-wide one, which you may place in any European country.
The operative instrument is Regulation (EU) 2016/679, whose Article 3 sets territorial scope. Croatia's national top-up is the Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka), Official Gazette 42/2018, in force since 25 May 2018. That Act does not extend or narrow territorial reach; it fills the gaps the Regulation leaves to member states. It carves out processing by law enforcement for criminal purposes and processing for national security, which sit under separate Croatian statutes. There is no general registration or licensing step for controllers in Croatia. Note that two Croatian rules do turn on establishment rather than on targeting: the Accounting Act binds every 'poduzetnik' subject to Croatian accounting law, which captures a Croatian subsidiary or branch even if the group is foreign, and the Act on State Information Infrastructure binds Croatian public bodies and their suppliers.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka), Official Gazette 42/2018 - Articles 19, 26-32, 34
narodne-novine.nn.hr
“Kod primjene članka 6. stavka 1. točke (a) Opće uredbe o zaštiti podataka, u vezi s nuđenjem usluga informacijskog društva izravno djetetu, obrada osobnih podataka djeteta zakonita je ako dijete ima najmanje 16 godina.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 33, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
Can I store my users' data outside Croatia?
Mostly yes, but with one nasty exception that catches everybody. Ordinary personal data can go abroad using the standard European transfer tools. Your accounting records cannot: Croatian law allows them to be kept outside Croatia only in another European Union country. Health data, public-sector registers and aerial photographs each have their own separate walls.
Headline rating: restrictions apply only in specific sectors. Sector by sector, checked 18 August 2026. ALL BUSINESSES - ACCOUNTING RECORDS - data must stay in the country as against non-EU countries. The Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024, Article 10(3) for accounting documents and Article 13(3) for business books, permits a company to keep them outside Croatia 'ali samo u drugoj državi članici' - only in another European Union member state. There is no transfer mechanism, consent or contract that unlocks a third country. The company must also give the supervising authority online access on demand where records are held electronically. This is the single most commonly missed Croatian rule, because it is in tax and accounting law rather than in privacy law, and because it bites on the very systems most likely to be hosted on non-EU cloud infrastructure - the finance system, the invoice archive and the payroll archive. GOVERNMENT AND PUBLIC SECTOR - data must stay in the country. The Act on State Information Infrastructure (Zakon o državnoj informacijskoj infrastrukturi), Official Gazette 72/2025, Article 27(1): 'Registri koji sadrže osobne podatke pohranjuju se u podatkovnim centrima koji se nalaze na teritoriju Republike Hrvatske.' Registers containing personal data are stored in data centres located on Croatian territory. Article 27(2) allows registers of non-personal data to sit in Croatia or another member state, and Article 27(3) lets the state require Croatian storage of non-personal data where public security justifies it - which is exactly the carve-out Regulation (EU) 2018/1807 permits. Article 17(1) obliges state administration bodies, other state bodies and public institutions founded solely by the Republic of Croatia to use the hosting services of the Shared Services Centre, the state cloud. HEALTH - a copy must stay in the country in practice. The Act on Data and Information in Healthcare, Official Gazette 14/2019, Article 19(2): health data processing is carried out electronically 'u zdravstvenoj informacijskoj infrastrukturi Republike Hrvatske' - in the health information infrastructure of the Republic of Croatia. Article 28(3) makes exchange through the Central Health Information System of the Republic of Croatia (CEZIH) compulsory for all healthcare providers. The Act does not contain an explicit ban on a private clinic additionally hosting its own records abroad, so this is recorded as a strong de facto wall rather than an express prohibition. MAPPING AND GEOSPATIAL - data can leave with the right paperwork, with a collection permit and a defence screen. The Regulation on Aerial Photography, Official Gazette 77/2020, requires a registered operator to hold an approval for aerial photography (Articles 4 and 9, valid for a survey period of at most three months) and then a SECOND, separate approval before the images may be used (Article 10). Article 13 sets up a joint review commission of the State Geodetic Administration and the Ministry of Defence that inspects imagery showing military locations and defence structures, and Article 14 decides which images may be released and which must be excluded. Article 6(3) obliges news organisations to hand the captured material to the State Geodetic Administration within eight days. BANKING - data can leave with the right paperwork. The Croatian National Bank Decision on Outsourcing, Official Gazette 118/2020 as amended by Official Gazette 150/2024, imposes NO localisation. It requires the bank to document the cloud model and the concrete location of the data, to be told when the provider changes location, to assess country risk, and - before outsourcing to a third country - to show that the law there lets the Croatian National Bank inspect directly and gives it timely and unrestricted access to documents and data. The European Union's Digital Operational Resilience Act is the operative outsourcing regime for financial entities since 17 January 2025 and also imposes no localisation. PAYMENTS, INSURANCE, SECURITIES - data can leave with the right paperwork. No Croatian data-residency rule found, checked 18 August 2026. TELECOMS - data can leave with the right paperwork on the evidence available. No Croatian storage-location rule for telecoms was located, checked 18 August 2026. Croatia does operate a traffic-data retention regime under the Electronic Communications Act, Official Gazette 76/2022, but the article number, the retention period and any location requirement could not be verified from an official source in this run - see the unconfirmed list. ONLINE GAMBLING - data can leave with the right paperwork. Contrary to the pattern in several neighbouring countries, no requirement that the gaming server sit on Croatian soil was found in the Gambling Act (Official Gazette 87/09 to 72/25) or the remote betting rulebook, checked 18 August 2026. The remote betting rulebook does require the operator's system to be directly connected to the Ministry of Finance information system, the equipment location to be declared in the licence application, and player money accounts to be held at a bank registered in Croatia. EDUCATION, E-COMMERCE, SOCIAL MEDIA, DEFENCE - no separate Croatian localisation rule found, checked 18 August 2026. Defence and national security processing is outside the scope of the general privacy statute.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on State Information Infrastructure (Zakon o državnoj informacijskoj infrastrukturi), Official Gazette 72/2025 - Article 17 (mandatory use of the Shared Services Centre) and Article 27 (location of data)
narodne-novine.nn.hr
“Registri koji sadrže osobne podatke pohranjuju se u podatkovnim centrima koji se nalaze na teritoriju Republike Hrvatske.”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on Data and Information in Healthcare (Zakon o podacima i informacijama u zdravstvu), Official Gazette 14/2019 - Articles 19, 27, 28, 29
narodne-novine.nn.hr
“Obrada zdravstvenih podataka provodi se elektroničkim putem u zdravstvenoj informacijskoj infrastrukturi Republike Hrvatske.”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Regulation on Aerial Photography (Uredba o snimanju iz zraka), Official Gazette 77/2020 - Articles 4, 6, 9, 10, 13, 14
narodne-novine.nn.hr
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Croatian National Bank Decision on Outsourcing (Odluka o eksternalizaciji), Official Gazette 118/2020
narodne-novine.nn.hr
“propisi države odnosno država u kojima pružatelj usluga posluje omogućuju Hrvatskoj narodnoj banci ... neposredni nadzor dijela poslovanja ... pravodoban i neograničen pristup dokumentaciji”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union
eur-lex.europa.eu
Link checked 18 August 2026
- Secondary sourceZakon.hr (unofficial consolidation)Rulebook on remote betting games (Pravilnik o priređivanju igara klađenja na daljinu), Official Gazette 8/2010 - consolidated text
zakon.hr
Link checked 18 August 2026
What do I need in place before data leaves Croatia?
For personal data, Croatia uses the European model. Some countries are pre-approved, and everywhere else you need a standard contract or a similar tool plus a risk check. The approved list is real and populated, and includes the United Kingdom, Japan, South Korea and Switzerland. For accounting records the model is different and much blunter: only European Union countries are allowed, and no paperwork buys you more.
For personal data the model is an allowlist of approved destinations plus fallback instruments, exactly as under Regulation (EU) 2016/679 Chapter V. The Commission's adequacy list, verified 18 August 2026, covers Andorra, Argentina, Brazil (new, 26 January 2026), Canada for commercial bodies, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the United States for entities self-certified under the EU-US Data Privacy Framework, and the European Patent Organisation. No decision has been withdrawn or suspended. Where the destination is not approved, the 2021 standard contractual clauses (Decision (EU) 2021/914) remain the operative set, unamended; the promised new clauses for importers already directly caught by the Regulation are still not adopted. Binding corporate rules remain available. Article 49 derogations are narrow and are not a basis for routine or bulk flows. A transfer impact assessment is expected. AZOP treats this seriously rather than as paperwork. Its 14 November 2025 decision fined a telecoms operator EUR 4.5 million (about USD 4.9 million) because a processor in Serbia had administrator-level access to the whole customer relationship database, the operator had not put the 2021 standard clauses in place after the 27 December 2022 cut-off, had not carried out a transfer impact assessment, and had not told its 847,862 affected customers that their data went outside the European Economic Area. For accounting records the model is a hard allowlist consisting of the European Union member states alone, under the Accounting Act. Standard clauses, consent and binding corporate rules are irrelevant to it.
Sources
- Official sourceAgencija za zaštitu osobnih podataka (AZOP)Administrative fine of EUR 4.5 million on a telecoms operator for transferring customer data to Serbia without a valid mechanism, 14 November 2025
azop.hr
“Izvršitelj obrade iz Republike Srbije mogao je pristupati cijeloj SAP CRM bazi i to s administratorskim ovlastima, a što je značilo da je imao neograničene ovlasti pristupu osobnim podacima”
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions - current list
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 on standard contractual clauses for transfers to third countries
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
Who enforces the rules in Croatia, and what can they do?
The main regulator is the Personal Data Protection Agency, known as AZOP. It is fully staffed, it hires more people, and it is one of the busiest fining bodies in central Europe for its size. It issued 13 fines totalling about 6.7 million euros (roughly 7.3 million dollars) in 2025, and 38 fines the year before. The cyber regulator, the National Cyber Security Centre, is also up and running.
AGENCIJA ZA ZASTITU OSOBNIH PODATAKA (AZOP) is the supervisory authority under the Act implementing the General Data Protection Regulation. It is independent and reports to Parliament; its director serves a four-year term, renewable once. It is unambiguously operational. Its own published tally shows 1 fine in 2020, 4 in 2021, 14 in 2022, 28 in 2023, 38 in 2024 and 13 in 2025, the 2025 batch totalling EUR 6,725,500. Its largest fine to date is EUR 5.47 million against the debt collection agency EOS Matrix d.o.o. (5 October 2023); its second largest is the EUR 4.5 million telecoms fine of 14 November 2025. On 18 May 2026 it published five recruitment competitions for six posts, which is the clearest possible evidence that it is staffed and expanding rather than dormant. Enforcement is rated actively enforced rather than aggressive: the fines are large but the annual case count is modest, and much of the docket comes from complaints rather than from own-initiative sweeps. The 2025 fines fell on a telecoms operator, a bank, an energy producer, a betting operator, the Croatian Insurance Bureau and a parking company - a spread that shows AZOP is not confined to any one industry. NACIONALNI CENTAR ZA KIBERNETICKU SIGURNOST (NCSC-HR) sits inside the Security and Intelligence Agency and is the central state body for cybersecurity, the national computer security incident response team, the crisis management body and the single point of contact under the Cybersecurity Act. It runs the national incident reporting platform. The National CERT at CARNET handles the remaining sectors. Both are operational and publishing guidance. Other regulators that bite on data: the Croatian National Bank for credit institutions, the Croatian Financial Services Supervisory Agency for insurance, pensions and markets, the State Geodetic Administration for aerial imagery, the Tax Administration for fiscalisation and accounting records, and the Ministry of Justice, Public Administration and Digital Transformation for the state information infrastructure. Unlawful use of personal data is also a criminal offence under Article 146 of the Criminal Code and is actually prosecuted by the State Attorney's Office.
Sources
- Official sourceAgencija za zaštitu osobnih podataka (AZOP)Administrative fines issued by the Croatian Personal Data Protection Agency, by year (2020-2025)
azop.hr
Link checked 18 August 2026
- Official sourceAgencija za zaštitu osobnih podataka (AZOP)Administrative fine of EUR 4.5 million on a telecoms operator for transferring customer data to Serbia without a valid mechanism, 14 November 2025
azop.hr
“Izvršitelj obrade iz Republike Srbije mogao je pristupati cijeloj SAP CRM bazi i to s administratorskim ovlastima, a što je značilo da je imao neograničene ovlasti pristupu osobnim podacima”
Link checked 18 August 2026
- Official sourceAgencija za zaštitu osobnih podataka (AZOP)Five recruitment competitions for six posts at the Personal Data Protection Agency, published 18 May 2026
azop.hr
Link checked 18 August 2026
- Official sourceAgencija za zaštitu osobnih podataka (AZOP)Administrative fine of EUR 5.47 million on debt collection agency EOS Matrix d.o.o., 5 October 2023
azop.hr
Link checked 18 August 2026
- Official sourceNacionalni centar za kibernetičku sigurnost (NCSC-HR)About the National Cyber Security Centre (NCSC-HR), operating within the Security and Intelligence Agency
ncsc.hr
Link checked 18 August 2026
- Official sourceDržavno odvjetništvo Republike Hrvatske (State Attorney's Office)Indictment for unlawful use of personal data under Article 146 of the Criminal Code and computer fraud, Municipal State Attorney's Office in Rijeka
dorh.hr
Link checked 18 August 2026
How long do I have to keep the data?
Croatia has strong minimum keeping periods and a few hard maximums. Ledgers and the documents behind them must be kept at least eleven years; payroll lists six years; the detailed wage and contribution records forever. Medical records run to ten years after the patient dies. Going the other way, camera footage must normally be deleted after six months.
THE FLOOR. Accounting Act, Official Gazette 85/2024: the journal and general ledger at least 11 years, subsidiary ledgers at least 11 years, documents supporting entries in the journal and general ledger at least 11 years, documents supporting entries in subsidiary ledgers at least 11 years, payroll lists at least 6 years, and analytical records of wages and contributions permanently. The clock runs from the last day of the business year to which they relate. The same Act fixes WHERE they may be kept: Croatia or another European Union member state, nowhere else. Healthcare: medical documentation is kept for ten years after the death of the individual, and data in the statutory health registers is kept permanently. Fiscalisation of eInvoices has applied since 1 January 2026 and produces a further archive that has to live inside the accounting retention framework. THE CEILING. Video surveillance recordings must be deleted after six months at the latest unless a longer period is set by another law or the footage is evidence in proceedings. The general privacy rulebook's storage limitation principle applies on top: personal data must not be kept in identifiable form longer than necessary for the purpose. AZOP's 2025 decisions repeatedly cited the absence of any retention policy as an aggravating factor. CONFLICT. Croatia resolves the clash the ordinary European way: a specific statutory keeping period is a legal obligation and beats a deletion request, so an individual cannot force you to delete an invoice inside the eleven years. The practical trap is that the legal obligation only covers the accounting record itself. Marketing profiles, call recordings and CCTV attached to the same customer are not protected by it and must still be deleted on time.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on Data and Information in Healthcare (Zakon o podacima i informacijama u zdravstvu), Official Gazette 14/2019 - Articles 19, 27, 28, 29
narodne-novine.nn.hr
“Obrada zdravstvenih podataka provodi se elektroničkim putem u zdravstvenoj informacijskoj infrastrukturi Republike Hrvatske.”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka), Official Gazette 42/2018 - Articles 19, 26-32, 34
narodne-novine.nn.hr
“Kod primjene članka 6. stavka 1. točke (a) Opće uredbe o zaštiti podataka, u vezi s nuđenjem usluga informacijskog društva izravno djetetu, obrada osobnih podataka djeteta zakonita je ako dijete ima najmanje 16 godina.”
Link checked 18 August 2026
- Official sourcePorezna uprava (Croatian Tax Administration)Fiscalisation of eInvoices - mandatory from 1 January 2026, second phase from 1 January 2027
porezna-uprava.gov.hr
Link checked 18 August 2026
What happens if there is a breach?
There are at least two clocks and they run at different speeds. A personal data breach goes to the privacy regulator within 72 hours. A significant cyber incident goes to the cyber authority within 24 hours as an early warning, with a fuller report at 72 hours and a final report within 30 days. One incident can easily trigger both, and the 24-hour clock is the one that catches people out.
CLOCK 1 - PERSONAL DATA BREACH. Regulation (EU) 2016/679 Article 33: notify AZOP without undue delay and where feasible within 72 hours of becoming aware, unless the breach is unlikely to result in a risk. Article 34: tell the affected individuals without undue delay where the risk to them is high. There is no Croatian variation on these deadlines. CLOCK 2 - SIGNIFICANT CYBER INCIDENT. Cybersecurity Act, Official Gazette 14/2024, and the Cybersecurity Regulation, Official Gazette 135/2024, implementing the European network and information security directive. Essential and important entities must file an early warning within 24 hours of becoming aware, a fuller incident notification within 72 hours, an intermediate report if the response team asks for one (typically 48 hours to 7 days), and a final report within 30 days of the initial notification. If the incident is still running, progress reports are due every 30 days. Trust service providers are exempt from the early warning but must file the initial notification within 24 hours. Reports go through the national platform for collecting and sharing threat and incident data, or by email to the relevant response team if the platform is down. CLOCK 3 - FINANCIAL ENTITIES. The European Union's Digital Operational Resilience Act has applied since 17 January 2025 and adds its own major-incident reporting timetable for banks, insurers, investment firms and their critical technology providers. CLOCK 4 - TELECOMS. The Electronic Communications Act imposes security incident notification duties towards the telecoms regulator. The exact deadline could not be verified from an official source in this run and is listed as unconfirmed. The operational failure is almost always the same: the security team starts the 72-hour privacy clock and forgets that the cyber early warning was due at hour 24.
Sources
- Official sourceNacionalni CERT / CARNETGeneral guidance on the duty to notify significant incidents (Opce smjernice za provedbu obveze obavjestavanja o znacajnim incidentima) - 24 hour early warning, 72 hour notification, 30 day final report
cert.hr
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Cybersecurity Act (Zakon o kibernetičkoj sigurnosti), Official Gazette 14/2024
narodne-novine.nn.hr
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 33, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
What trips people up in Croatia?
Five things that are not in the summary. Your ledger cannot live on an American cloud. Children count as adults for online consent at 16, not 13. Using someone's personal data unlawfully is a crime, not just a fine. Genetic test results may never be used to price life insurance. And camera footage in an apartment building needs two thirds of the owners to agree.
1. THE ACCOUNTING CLOUD TRAP. The Accounting Act allows business books and accounting documents to be held outside Croatia only in another European Union member state. That is not a privacy rule and no privacy instrument overrides it. A Croatian subsidiary running its finance system, invoice archive or payroll archive on infrastructure in the United States, the United Kingdom, Switzerland or Serbia is in breach regardless of what its data processing agreement says. Since mandatory eInvoice fiscalisation began on 1 January 2026 the volume of records caught by this rule has grown sharply. 2. AGE 16, NOT 13 OR 15. Article 19 of the Act implementing the General Data Protection Regulation sets the age at which a child can consent to an online service at 16. Croatia took the maximum the Regulation allows. Products built to a 13-year threshold are non-compliant in Croatia, and a global 'age of digital consent' switch set to 15 or 16 will still be wrong if it is not set to 16 for Croatia. 3. CRIMINAL LIABILITY. Article 146 of the Criminal Code makes unlawful use of personal data a criminal offence attaching to individuals, not an administrative matter. The State Attorney's Office does bring indictments under it, including in combination with computer fraud. An employee who misuses a customer database is exposed personally, and so potentially is the manager who directed it. 4. GENETIC DATA AND LIFE INSURANCE. The Croatian implementing Act forbids the processing of genetic data for the purpose of calculating the probability of illness or other health aspects of a person insured under a life insurance policy. This is a flat national prohibition, not a consent-based restriction, and it has no equivalent in most other member states. 5. VIDEO SURVEILLANCE HAS ITS OWN CODE. Croatia regulates cameras in the statute itself rather than by guidance: recordings must be deleted within six months unless another law says otherwise or they are evidence; signage must carry the controller's identity and contact details; monitoring of changing rooms, washrooms and rest areas is banned; public areas may generally be filmed only by public authorities and public service providers; and in a residential building you need the agreement of two thirds of the co-owners and may cover only entrances and common areas. Biometric access control and time-and-attendance in the private sector needs the employee's explicit consent and must be an alternative to another solution, which makes 'fingerprint only' clocking systems hard to justify. 6. BONUS - THE PUBLIC PROCUREMENT WALL. If you sell software to the Croatian state, the Act on State Information Infrastructure now forces personal-data registers into Croatian data centres and forces state bodies into the government's Shared Services Centre. A foreign vendor whose architecture assumes a regional hyperscale region outside Croatia cannot bid credibly.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka), Official Gazette 42/2018 - Articles 19, 26-32, 34
narodne-novine.nn.hr
“Kod primjene članka 6. stavka 1. točke (a) Opće uredbe o zaštiti podataka, u vezi s nuđenjem usluga informacijskog društva izravno djetetu, obrada osobnih podataka djeteta zakonita je ako dijete ima najmanje 16 godina.”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
- Official sourceDržavno odvjetništvo Republike Hrvatske (State Attorney's Office)Indictment for unlawful use of personal data under Article 146 of the Criminal Code and computer fraud, Municipal State Attorney's Office in Rijeka
dorh.hr
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on State Information Infrastructure (Zakon o državnoj informacijskoj infrastrukturi), Official Gazette 72/2025 - Article 17 (mandatory use of the Shared Services Centre) and Article 27 (location of data)
narodne-novine.nn.hr
“Registri koji sadrže osobne podatke pohranjuju se u podatkovnim centrima koji se nalaze na teritoriju Republike Hrvatske.”
Link checked 18 August 2026
- Official sourcePorezna uprava (Croatian Tax Administration)Fiscalisation of eInvoices - mandatory from 1 January 2026, second phase from 1 January 2027
porezna-uprava.gov.hr
Link checked 18 August 2026
What is changing soon in Croatia?
Two Croatian dates matter. Fines under the state information infrastructure law switch on 1 January 2027. Mandatory eInvoicing widens to smaller traders on the same day. Across Europe, cloud switching fees must fall to zero by 12 January 2027. The thing to watch is the challenge to the Europe-United States data deal, which is still valid but under real pressure.
CROATIA - DATED. 1 January 2027: the penalty articles of the Act on State Information Infrastructure (Articles 33 and 34, fines of EUR 500 to EUR 6,630, roughly USD 540 to USD 7,200) start to apply. Until then the Croatian data-centre rule for state registers is in force but carries no fine, which is exactly the kind of gap that lulls suppliers into missing it. 1 January 2027: the second phase of eInvoice fiscalisation catches traders who are not registered for value added tax. Phase one, covering value added tax registered businesses, has applied since 1 January 2026. Within 12 months of the state infrastructure regulation: projects must be registered in the state project register and data exchange interfaces must be built. A public consultation on amendments to the Electronic Communications Act was open in 2026; the content could not be verified from an official source in this run. EUROPEAN UNION - DATED. 12 January 2027: under the Data Act, Regulation (EU) 2023/2854, all cloud switching charges and data egress fees must be zero. This is a hard deadline and it changes cloud contract economics. 2 August 2026: the transparency obligations of the Artificial Intelligence Act have already started. Still not adopted: the European cloud certification scheme, deadlocked over sovereignty since 2020, so national arrangements continue to govern. The Digital Omnibus proposal of 19 November 2025 - which would loosen the definition of personal data and stretch breach notification from 72 to 96 hours - has no legal effect and was opposed on its core change in February 2026. DORMANT SWITCHES - the powers already held that could change the picture with no consultation. 1. Article 27(3) of the Act on State Information Infrastructure lets the state require NON-personal data to be stored in Croatia where a public security justification is made out. That is the escape hatch Regulation (EU) 2018/1807 leaves open, and it is written into Croatian law and ready to use. 2. The Ministry of Defence review commission for aerial imagery can exclude any image from release without a published standard. A survey flight can be flown lawfully and the resulting dataset still be unusable. 3. The Europe-United States Data Privacy Framework remains in force and legally valid on 18 August 2026, but the Latombe appeal is pending before the Court of Justice after the General Court dismissed the case on 3 September 2025, the United States oversight bodies that underpin it have been weakened, and on 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether the adequacy decision is still sound. The Commission has neither suspended nor revoked it. Do not build a single-mechanism architecture on it.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on State Information Infrastructure (Zakon o državnoj informacijskoj infrastrukturi), Official Gazette 72/2025 - Article 17 (mandatory use of the Shared Services Centre) and Article 27 (location of data)
narodne-novine.nn.hr
“Registri koji sadrže osobne podatke pohranjuju se u podatkovnim centrima koji se nalaze na teritoriju Republike Hrvatske.”
Link checked 18 August 2026
- Official sourcePorezna uprava (Croatian Tax Administration)Fiscalisation of eInvoices - mandatory from 1 January 2026, second phase from 1 January 2027
porezna-uprava.gov.hr
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) - cloud switching charges must fall to zero from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEuropean Data Protection Board - July 2026 letter to the Commission on the EU-US Data Privacy Framework
edpb.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union
eur-lex.europa.eu
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
5 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
4 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules5 rules
Zakon o računovodstvu
Act of parliament · Narodne novine 85/2024, Articles 10(3) and 13(3); consolidated to Narodne novine 59/2026
A Croatian company may keep its books and the documents behind them outside Croatia only in another European Union country. There is no contract, consent or approval that permits storage in the United States or any other non-EU country.
Enforced by Tax Administration
Transfer model: Allowlist
What it makes you do
- Keep the data in the countryAccounting documents and business books may be kept outside Croatia only in another European Union member state.
- Keep data for a minimum period — 11 yearsJournal, general ledger, subsidiary ledgers and the documents behind them: at least 11 years.
- Keep data for a minimum period — 6 yearsPayroll lists: at least 6 years. Analytical records of wages and contributions: permanently.
- Keep records of processingWhere records are held electronically, the supervising body must be given access on request.
What it costs if you get it wrong
- Fixed maximum fineFailure to keep or produce business books and accounting documents as required. Exact amounts not verified.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
- Secondary sourceZakon.hr (unofficial consolidation)Accounting Act - consolidated text as amended to Official Gazette 59/2026, in force 10 June 2026
zakon.hr
Link checked 18 August 2026
Zakon o provedbi Opće uredbe o zaštiti podataka
Act of parliament · Narodne novine 42/2018, Articles 19, 25-34
Croatia's national privacy statute sits on top of the European rulebook. Its distinctive features are a digital consent age of 16, a detailed statutory video surveillance code, and a flat ban on using genetic data to price life insurance.
Enforced by Personal Data Protection Agency
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest
What it makes you do
- Get a parent's consent for children — applies at: under 16 years oldCroatia set the digital consent age at the maximum the European rulebook allows.
- Delete data after a period — 6 monthsVideo surveillance recordings deleted after six months unless another law or evidential need extends it.
- Tell people what you doCamera signage must name the controller and give contact details.
- Put a transfer safeguard in place
- Appoint a data protection officer
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover — about $22 millionBreach of basic principles, individual rights or the transfer rules.
- Order to stopOrder to stop processing or to suspend flows to a third country.
- Claims by individualsCompensation claims by individuals.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka), Official Gazette 42/2018 - Articles 19, 26-32, 34
narodne-novine.nn.hr
“Kod primjene članka 6. stavka 1. točke (a) Opće uredbe o zaštiti podataka, u vezi s nuđenjem usluga informacijskog društva izravno djetetu, obrada osobnih podataka djeteta zakonita je ako dijete ima najmanje 16 godina.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 33, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
Zakon o kibernetičkoj sigurnosti (i Uredba o kibernetičkoj sigurnosti)
Act of parliament · Narodne novine 14/2024; Cybersecurity Regulation, Narodne novine 135/2024, Articles 65-71
Croatia's cybersecurity law implements the European network and information security regime. Significant incidents need an early warning in 24 hours, a full report in 72 hours and a closing report within 30 days. It contains no storage-location requirement.
Enforced by National Cyber Security Centre
Transfer model: No restriction
What it makes you do
- Report cyber incidents — within 24 hoursEarly warning to the competent incident response team within 24 hours of becoming aware.
- Report cyber incidents — within 72 hoursFull incident notification within 72 hours. Trust service providers file at 24 hours and are exempt from the early warning.
- Report cyber incidents — within 720 hoursFinal report within 30 days of the initial notification; progress reports every 30 days while the incident continues.
- Register or notifyEssential and important entities must be registered and categorised.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fineFailure to report or to implement required security measures. Amounts follow the European network and information security regime.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Cybersecurity Act (Zakon o kibernetičkoj sigurnosti), Official Gazette 14/2024
narodne-novine.nn.hr
Link checked 18 August 2026
- Official sourceNacionalni CERT / CARNETGeneral guidance on the duty to notify significant incidents (Opce smjernice za provedbu obveze obavjestavanja o znacajnim incidentima) - 24 hour early warning, 72 hour notification, 30 day final report
cert.hr
Link checked 18 August 2026
- Official sourceNacionalni centar za kibernetičku sigurnost (NCSC-HR)About the National Cyber Security Centre (NCSC-HR), operating within the Security and Intelligence Agency
ncsc.hr
Link checked 18 August 2026
Zakon o fiskalizaciji
Act of parliament · Zakon o fiskalizaciji; eInvoice obligations phased 1 January 2026 and 1 January 2027
Since 1 January 2026 Croatian businesses registered for value added tax must issue electronic invoices and report them to the Tax Administration. The resulting archive is caught by the accounting rule that keeps records inside the European Union.
Enforced by Tax Administration
Transfer model: No restriction
What it makes you do
- Keep records of processing — from 1 January 2026Businesses registered for value added tax must issue eInvoices to business customers and report them to the Tax Administration; every recipient must receive and report them.
- Keep records of processing — from 1 January 2027Second phase extends the issuing duty to traders not registered for value added tax.
- Keep data for a minimum period — 11 yearsThe resulting eInvoice archive falls inside the Accounting Act retention and storage-location rules.
What it costs if you get it wrong
- Fixed maximum fineFailure to issue, receive or report an eInvoice. Amounts not verified.
Sources
- Official sourcePorezna uprava (Croatian Tax Administration)Fiscalisation of eInvoices - mandatory from 1 January 2026, second phase from 1 January 2027
porezna-uprava.gov.hr
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Accounting Act (Zakon o računovodstvu), Official Gazette 85/2024 - Article 10(3) accounting documents and Article 13(3) business books
narodne-novine.nn.hr
“Poduzetnik može odlučiti čuvati knjigovodstvene isprave izvan područja Republike Hrvatske, ali samo u drugoj državi članici.”
Link checked 18 August 2026
Kazneni zakon, članak 146. – Nedozvoljena uporaba osobnih podataka
Act of parliament · Criminal Code, Article 146 (unlawful use of personal data)
Misusing personal data is a criminal offence in Croatia, not only a regulatory one. Prosecutors do bring charges under it against individuals, typically together with computer fraud.
What it makes you do
- Secure the dataMisuse of personal data by an individual is prosecuted, not merely fined.
What it costs if you get it wrong
- Criminal liabilityCollecting, processing or using personal data contrary to law, including for gain. Prosecuted by the State Attorney's Office, often alongside computer fraud.
Sources
- Official sourceDržavno odvjetništvo Republike Hrvatske (State Attorney's Office)Indictment for unlawful use of personal data under Article 146 of the Criminal Code and computer fraud, Municipal State Attorney's Office in Rijeka
dorh.hr
Link checked 18 August 2026
Industry rules4 rules
Zakon o državnoj informacijskoj infrastrukturi
Act of parliament · Narodne novine 72/2025, Articles 17 and 27; penalty Articles 33-34 apply from 1 January 2027 · Government
Croatian state registers that contain personal data must be held in data centres inside Croatia, and public bodies must use the government's own shared cloud. The rule is already in force but no fine can be imposed for breaking it until 1 January 2027.
Enforced by Ministry of Justice, Public Administration and Digital Transformation
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryRegisters containing personal data must be stored in data centres on Croatian territory. Non-personal registers may sit in Croatia or another member state, or be forced into Croatia on public security grounds.
- Prove the data stays under local controlState administration bodies, other state bodies and public institutions founded solely by the Republic of Croatia must use the state Shared Services Centre for hosting.
What it costs if you get it wrong
- Fixed maximum fine: €6,630 — about $7 thousandBreach of the Act; penalty provisions apply only from 1 January 2027.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on State Information Infrastructure (Zakon o državnoj informacijskoj infrastrukturi), Official Gazette 72/2025 - Article 17 (mandatory use of the Shared Services Centre) and Article 27 (location of data)
narodne-novine.nn.hr
“Registri koji sadrže osobne podatke pohranjuju se u podatkovnim centrima koji se nalaze na teritoriju Republike Hrvatske.”
Link checked 18 August 2026
- Official sourceMinistarstvo pravosuđa, uprave i digitalne transformacijeShared Services Centre (CDU) - the state cloud powering digital Croatia
mpudt.gov.hr
Link checked 18 August 2026
Zakon o podacima i informacijama u zdravstvu
Act of parliament · Narodne novine 14/2019, Articles 19(2), 27, 28, 29 · Health and social care
Health data in Croatia is processed inside the national health information infrastructure and exchanged through the central health system. That keeps it in Croatia in practice, although the law does not spell out an express ban on hosting a copy abroad.
Transfer model: Approval each time
What it makes you do
- Keep the data in the countryHealth data is processed electronically within the health information infrastructure of the Republic of Croatia.
- Keep data for a minimum period — 10 yearsMedical documentation kept for ten years after the person's death; register data kept permanently.
- Secure the dataExchange through the Central Health Information System must use automated means over a protected channel.
What it costs if you get it wrong
- Fixed maximum fine: HRK 100,000 — about $15 thousandUnlawful processing or failure to exchange data through the central health system. Amounts are still expressed in kuna in the 2019 text.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Act on Data and Information in Healthcare (Zakon o podacima i informacijama u zdravstvu), Official Gazette 14/2019 - Articles 19, 27, 28, 29
narodne-novine.nn.hr
“Obrada zdravstvenih podataka provodi se elektroničkim putem u zdravstvenoj informacijskoj infrastrukturi Republike Hrvatske.”
Link checked 18 August 2026
Uredba o snimanju iz zraka
Directly binding regulation · Narodne novine 77/2020, Articles 4, 6, 7, 9, 10, 13, 14 · Mapping and location
Photographing Croatia from the air needs one government approval to fly and a second, separate approval before the pictures may be used. The Ministry of Defence screens the images first and can order frames to be excluded.
Enforced by State Geodetic Administration
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyThe operator must be registered for the activity and hold an approval for aerial photography, valid for a survey window of at most three months.
- Independent auditA joint commission of the State Geodetic Administration and the Ministry of Defence reviews imagery showing military and defence facilities before any use is approved.
- Keep records of processingNews organisations must deliver the captured material to the State Geodetic Administration within eight days.
What it costs if you get it wrong
- Order to stopRefusal of the approval to use the imagery, or exclusion of specific frames.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Regulation on Aerial Photography (Uredba o snimanju iz zraka), Official Gazette 77/2020 - Articles 4, 6, 9, 10, 13, 14
narodne-novine.nn.hr
Link checked 18 August 2026
- Official sourceDržavna geodetska uprava (State Geodetic Administration)Aerial photography - approvals page of the State Geodetic Administration
dgu.gov.hr
Link checked 18 August 2026
Odluka o eksternalizaciji
Regulator directive · Narodne novine 118/2020, amended by Narodne novine 150/2024 · Banking
Croatian banks may use foreign and cloud providers, including outside Europe, but only if the Croatian National Bank can still inspect the provider directly and get unrestricted access to the data. There is no requirement to keep banking data in Croatia.
Enforced by Croatian National Bank
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Written vendor contractThe contract must state the cloud model and the concrete location where data is held, processed and stored, and require the provider to report any change of location.
- Independent auditBefore outsourcing to a country outside the European Union the bank must show that local law lets the Croatian National Bank inspect directly and gives it timely and unrestricted access to documents and data.
- Assess high-risk projectsCountry and region risk, and differences in national data protection law, must be assessed and documented.
What it costs if you get it wrong
- Order to stopSupervisory order to terminate or restructure the outsourcing arrangement.
Sources
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Croatian National Bank Decision on Outsourcing (Odluka o eksternalizaciji), Official Gazette 118/2020
narodne-novine.nn.hr
“propisi države odnosno država u kojima pružatelj usluga posluje omogućuju Hrvatskoj narodnoj banci ... neposredni nadzor dijela poslovanja ... pravodoban i neograničen pristup dokumentaciji”
Link checked 18 August 2026
- Official sourceNarodne novine (Official Gazette of the Republic of Croatia)Decision amending the Decision on Outsourcing (Odluka o izmjenama Odluke o eksternalizaciji), Official Gazette 150/2024
narodne-novine.nn.hr
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Croatia's traffic and location data retention regime for telecoms operators - the article number, the retention period, and whether retained data must be held in Croatia.
The Electronic Communications Act, Official Gazette 76/2022, is published on the official gazette site as a single very long page that could not be read past the early articles in this run, and neither the telecoms regulator nor the ministry publishes a plain summary of the retention chapter. No official source was obtained, so no retention period is asserted. Checked 18 August 2026.
The deadline for a telecoms operator to notify the Croatian telecoms regulator of a security incident.
Same source problem as above. The obligation clearly exists in the Act but the deadline could not be read from an official text.
Whether any Croatian court or the Constitutional Court has disapplied or limited the Croatian telecoms data retention provisions following the Court of Justice case law on general and indiscriminate retention.
No Croatian court decision was found on an official court domain, checked 18 August 2026. Absence of a finding is not evidence that no such decision exists.
The exact misdemeanour fine amounts under the Accounting Act for keeping business books or accounting documents outside the European Union.
The penalty chapter did not appear in the retrievable portion of the official gazette text and no official ministry summary of the amounts was located. The prohibition itself is verified from the official text; only the amount is unverified.
Whether the Act on Data and Information in Healthcare bars a private healthcare provider from additionally hosting its own patient records outside Croatia.
Article 19(2) requires processing within Croatia's health information infrastructure and Article 28(3) makes exchange through the central health system compulsory, but no express prohibition on foreign hosting of a provider's own systems was found. Rated a de facto wall, confidence medium.
Whether the Croatian Financial Services Supervisory Agency imposes cloud or outsourcing location conditions on insurers, pension companies and investment firms beyond the European Digital Operational Resilience Act.
No relevant rulebook was located on the regulator's own site within the search budget, checked 18 August 2026. Recorded as no rule found rather than as no rule existing.
Whether the current Act on Archival Material and Archives restricts taking a company's documentary material out of Croatia, and whether doing so is still a criminal offence.
The 1997 version of the Act, which carried a prison penalty of up to five years for removing original archival material without ministerial approval, was replaced in 2018. The current text could not be verified from the official gazette in this run, so no claim is made.
The exact maximum sentence under Article 146 of the Croatian Criminal Code for unlawful use of personal data.
The offence and live prosecutions under it are verified from the State Attorney's Office's own publication, but the penalty range was not obtained from the official text of the Criminal Code.
The content and closing date of the 2026 public consultation on amendments to the Electronic Communications Act.
The consultation page on the government's consultation portal returned an error when fetched on 18 August 2026.
Whether AZOP has issued fines in 2026.
AZOP's published fines table was last modified in February 2026 and shows figures only up to 2025. Its 2026 activity is evidenced by recruitment notices rather than by a published fine tally.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Compare with
- Croatia versus Argentina
- Croatia versus Armenia
- Croatia versus Australia
- Croatia versus Austria
- Croatia versus Azerbaijan
- Croatia versus Brazil
- Croatia versus Bulgaria
- Croatia versus Cambodia
- Croatia versus Canada
- Croatia versus China
- Croatia versus Cyprus
- Croatia versus Estonia
- Croatia versus France
- Croatia versus Georgia
- Croatia versus Germany
- Croatia versus Greece
- Croatia versus Hong Kong SAR
- Croatia versus Hungary
- Croatia versus Iceland
- Croatia versus India
- Croatia versus Indonesia
- Croatia versus Ireland
- Croatia versus Israel
- Croatia versus Italy
- Croatia versus Japan
- Croatia versus Latvia
- Croatia versus Lithuania
- Croatia versus Luxembourg
- Croatia versus Malta
- Croatia versus Mexico
- Croatia versus Mongolia
- Croatia versus Nepal
- Croatia versus Netherlands
- Croatia versus Poland
- Croatia versus Russia
- Croatia versus Saudi Arabia
- Croatia versus Serbia
- Croatia versus Singapore
- Croatia versus Slovakia
- Croatia versus Slovenia
- Croatia versus South Korea
- Croatia versus Spain
- Croatia versus Sri Lanka
- Croatia versus Sweden
- Croatia versus Switzerland
- Croatia versus Taiwan
- Croatia versus Thailand
- Croatia versus Turkey
- Croatia versus Ukraine
- Croatia versus United Arab Emirates
- Croatia versus United Kingdom
- Croatia versus United States
- Croatia versus Uzbekistan