Skip to the content
Global Data RulesData governance rules, country by country

Croatia

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

Croatia looks like an ordinary European Union country for privacy: data may leave once you have the right paperwork. But its accounting law is stricter than most people expect. A Croatian company's books and receipts may only be kept in Croatia or another European Union country. Public bodies must keep personal-data registers in Croatian data centres. The privacy regulator fines hard.

Eight questions about Croatia

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Croatia's rules apply to my company?

Yes. Croatia's rules reach a company with no office in the country. The European Union privacy rulebook applies to anyone who offers goods or services to people in Europe, or who watches what they do online. There is no revenue or headcount threshold. Croatia does not demand its own local representative on top of the Europe-wide one, which you may place in any European country.

High confidenceNational rulesBloc rulesControllerProcessorAppoint a local representative

Can I store my users' data outside Croatia?

Mostly yes, but with one nasty exception that catches everybody. Ordinary personal data can go abroad using the standard European transfer tools. Your accounting records cannot: Croatian law allows them to be kept outside Croatia only in another European Union country. Health data, public-sector registers and aerial photographs each have their own separate walls.

High confidenceDepends on your industryAll industriesGovernmentHealth and social careMapping and locationBankingKeep the data in the country

What do I need in place before data leaves Croatia?

For personal data, Croatia uses the European model. Some countries are pre-approved, and everywhere else you need a standard contract or a similar tool plus a risk check. The approved list is real and populated, and includes the United Kingdom, Japan, South Korea and Switzerland. For accounting records the model is different and much blunter: only European Union countries are allowed, and no paperwork buys you more.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentPut a transfer safeguard in place

Who enforces the rules in Croatia, and what can they do?

The main regulator is the Personal Data Protection Agency, known as AZOP. It is fully staffed, it hires more people, and it is one of the busiest fining bodies in central Europe for its size. It issued 13 fines totalling about 6.7 million euros (roughly 7.3 million dollars) in 2025, and 38 fines the year before. The cyber regulator, the National Cyber Security Centre, is also up and running.

High confidenceActiveRegulatorPercentage of global turnoverFixed maximum fineCriminal liability

How long do I have to keep the data?

Croatia has strong minimum keeping periods and a few hard maximums. Ledgers and the documents behind them must be kept at least eleven years; payroll lists six years; the detailed wage and contribution records forever. Medical records run to ten years after the patient dies. Going the other way, camera footage must normally be deleted after six months.

High confidenceKeep data for a minimum periodDelete data after a periodKeep records of processingEmployee dataHealth data

What happens if there is a breach?

There are at least two clocks and they run at different speeds. A personal data breach goes to the privacy regulator within 72 hours. A significant cyber incident goes to the cyber authority within 24 hours as an early warning, with a fuller report at 72 hours and a final report within 30 days. One incident can easily trigger both, and the 24-hour clock is the one that catches people out.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidentsSecure the data

What trips people up in Croatia?

Five things that are not in the summary. Your ledger cannot live on an American cloud. Children count as adults for online consent at 16, not 13. Using someone's personal data unlawfully is a crime, not just a fine. Genetic test results may never be used to price life insurance. And camera footage in an apartment building needs two thirds of the owners to agree.

High confidenceChildren's dataGenetic dataBiometric dataGet a parent's consent for childrenCriminal liabilityKeep the data in the countryInsurance

What is changing soon in Croatia?

Two Croatian dates matter. Fines under the state information infrastructure law switch on 1 January 2027. Mandatory eInvoicing widens to smaller traders on the same day. Across Europe, cloud switching fees must fall to zero by 12 January 2027. The thing to watch is the challenge to the Europe-United States data deal, which is still valid but under real pressure.

Medium confidencePartly in forceMake switching cloud provider possibleKeep the data in the countryOfficial 'this country is safe' decision

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    5 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    4 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules5 rules

Zakon o računovodstvu

Act of parliament · Narodne novine 85/2024, Articles 10(3) and 13(3); consolidated to Narodne novine 59/2026

In forceNo — it stays put

A Croatian company may keep its books and the documents behind them outside Croatia only in another European Union country. There is no contract, consent or approval that permits storage in the United States or any other non-EU country.

In force since 27 July 2024

Enforced by Tax Administration

Transfer model: Allowlist

High confidence

Zakon o provedbi Opće uredbe o zaštiti podataka

Act of parliament · Narodne novine 42/2018, Articles 19, 25-34

In forceYes, with paperwork

Croatia's national privacy statute sits on top of the European rulebook. Its distinctive features are a digital consent age of 16, a detailed statutory video surveillance code, and a flat ban on using genetic data to price life insurance.

In force since 25 May 2018

Enforced by Personal Data Protection Agency

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

High confidence

Zakon o kibernetičkoj sigurnosti (i Uredba o kibernetičkoj sigurnosti)

Act of parliament · Narodne novine 14/2024; Cybersecurity Regulation, Narodne novine 135/2024, Articles 65-71

In forceYes — store it anywhere

Croatia's cybersecurity law implements the European network and information security regime. Significant incidents need an early warning in 24 hours, a full report in 72 hours and a closing report within 30 days. It contains no storage-location requirement.

In force since 15 February 2024But only enforceable from 20 November 2024

Enforced by National Cyber Security Centre

Transfer model: No restriction

High confidence

Industry rules4 rules

Zakon o državnoj informacijskoj infrastrukturi

Act of parliament · Narodne novine 72/2025, Articles 17 and 27; penalty Articles 33-34 apply from 1 January 2027 · Government

Partly in forceNo — it stays put

Croatian state registers that contain personal data must be held in data centres inside Croatia, and public bodies must use the government's own shared cloud. The rule is already in force but no fine can be imposed for breaking it until 1 January 2027.

In force since 1 May 2025But only enforceable from 1 January 2027

Enforced by Ministry of Justice, Public Administration and Digital Transformation

Transfer model: Not allowed

High confidence

Zakon o podacima i informacijama u zdravstvu

Act of parliament · Narodne novine 14/2019, Articles 19(2), 27, 28, 29 · Health and social care

In forceA copy must stay

Health data in Croatia is processed inside the national health information infrastructure and exchanged through the central health system. That keeps it in Croatia in practice, although the law does not spell out an express ban on hosting a copy abroad.

In force since 15 February 2019But only enforceable from 15 February 2021

Transfer model: Approval each time

Medium confidence

Uredba o snimanju iz zraka

Directly binding regulation · Narodne novine 77/2020, Articles 4, 6, 7, 9, 10, 13, 14 · Mapping and location

In forceYes, with paperwork

Photographing Croatia from the air needs one government approval to fly and a second, separate approval before the pictures may be used. The Ministry of Defence screens the images first and can order frames to be excluded.

In force since 11 July 2020

Enforced by State Geodetic Administration

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Who you would hear from

  • Agencija za zaštitu osobnih podataka (AZOP)

    General data protection supervisory authority for Croatia.

    Fully operational and expanding. Published tally: 38 fines in 2024 and 13 fines totalling EUR 6,725,500 in 2025, including EUR 4.5 million against a telecoms operator on 14 November 2025 for unlawful transfers to Serbia. Largest fine to date EUR 5.47 million (EOS Matrix, October 2023). Five recruitment competitions for six posts published 18 May 2026.

  • Nacionalni centar za kibernetičku sigurnost (NCSC-HR)

    Central state body for cybersecurity, national incident response team, single point of contact and cyber crisis manager under the Cybersecurity Act. Operates within the Security and Intelligence Agency.

    Operational. Runs the national threat and incident reporting platform and publishes binding guidance.

  • Nacionalni CERT (CARNET)

    Incident response team for the sectors not covered by NCSC-HR; publishes the significant-incident notification guidance.

    Operational; issued the general guidance on significant incident notification in April 2025.

  • Državna geodetska uprava

    Issues approvals for aerial photography and for the use of aerial imagery; co-chairs the defence review commission.

    Operational; publishes the application procedure and forms for both approvals.

  • Hrvatska narodna banka

    Prudential supervisor for credit institutions; sets the outsourcing and information system rules.

    Operational; amended its outsourcing decision in December 2024.

  • Ministarstvo pravosuđa, uprave i digitalne transformacije

    Runs the state information infrastructure and the Shared Services Centre; competent for the 2025 state information infrastructure Act.

    Operational, but the Act's penalty provisions do not apply until 1 January 2027, so no fines are possible yet.

  • Porezna uprava

    Supervises accounting records, retention and the fiscalisation of eInvoices.

    Operational; ran the first phase of mandatory eInvoice fiscalisation from 1 January 2026.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Croatia's traffic and location data retention regime for telecoms operators - the article number, the retention period, and whether retained data must be held in Croatia.

    The Electronic Communications Act, Official Gazette 76/2022, is published on the official gazette site as a single very long page that could not be read past the early articles in this run, and neither the telecoms regulator nor the ministry publishes a plain summary of the retention chapter. No official source was obtained, so no retention period is asserted. Checked 18 August 2026.

  • The deadline for a telecoms operator to notify the Croatian telecoms regulator of a security incident.

    Same source problem as above. The obligation clearly exists in the Act but the deadline could not be read from an official text.

  • Whether any Croatian court or the Constitutional Court has disapplied or limited the Croatian telecoms data retention provisions following the Court of Justice case law on general and indiscriminate retention.

    No Croatian court decision was found on an official court domain, checked 18 August 2026. Absence of a finding is not evidence that no such decision exists.

  • The exact misdemeanour fine amounts under the Accounting Act for keeping business books or accounting documents outside the European Union.

    The penalty chapter did not appear in the retrievable portion of the official gazette text and no official ministry summary of the amounts was located. The prohibition itself is verified from the official text; only the amount is unverified.

  • Whether the Act on Data and Information in Healthcare bars a private healthcare provider from additionally hosting its own patient records outside Croatia.

    Article 19(2) requires processing within Croatia's health information infrastructure and Article 28(3) makes exchange through the central health system compulsory, but no express prohibition on foreign hosting of a provider's own systems was found. Rated a de facto wall, confidence medium.

  • Whether the Croatian Financial Services Supervisory Agency imposes cloud or outsourcing location conditions on insurers, pension companies and investment firms beyond the European Digital Operational Resilience Act.

    No relevant rulebook was located on the regulator's own site within the search budget, checked 18 August 2026. Recorded as no rule found rather than as no rule existing.

  • Whether the current Act on Archival Material and Archives restricts taking a company's documentary material out of Croatia, and whether doing so is still a criminal offence.

    The 1997 version of the Act, which carried a prison penalty of up to five years for removing original archival material without ministerial approval, was replaced in 2018. The current text could not be verified from the official gazette in this run, so no claim is made.

  • The exact maximum sentence under Article 146 of the Croatian Criminal Code for unlawful use of personal data.

    The offence and live prosecutions under it are verified from the State Attorney's Office's own publication, but the penalty range was not obtained from the official text of the Criminal Code.

  • The content and closing date of the 2026 public consultation on amendments to the Electronic Communications Act.

    The consultation page on the government's consultation portal returned an error when fetched on 18 August 2026.

  • Whether AZOP has issued fines in 2026.

    AZOP's published fines table was last modified in February 2026 and shows figures only up to 2025. Its 2026 activity is evidenced by recruitment notices rather than by a published fine tally.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.