Skip to the content
Global Data RulesData governance rules, country by country

Croatia

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Croatia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

Croatia looks like an ordinary European Union country for privacy: data may leave once you have the right paperwork. But its accounting law is stricter than most people expect. A Croatian company's books and receipts may only be kept in Croatia or another European Union country. Public bodies must keep personal-data registers in Croatian data centres. The privacy regulator fines hard.

Data governance in Croatia

The eight things that decide how you handle data about people in Croatia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Croatia's rules reach a company with no office in the country. The European Union privacy rulebook applies to anyone who offers goods or services to people in Europe, or who watches what they do online. There is no revenue or headcount threshold. Croatia does not demand its own local representative on top of the Europe-wide one, which you may place in any European country.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Mostly yes, with one exception that catches everybody. Ordinary personal data can go abroad using the standard European transfer tools. Your accounting records cannot. Croatian law lets you keep them outside Croatia only in another European Union country. Health data, public-sector registers and aerial photographs each have their own separate limits.

What you have to do here:
Keep the data in the country

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

For personal data, Croatia uses the European model. Some countries are pre-approved, and everywhere else you need a standard contract or a similar tool plus a risk check. The approved list is real and populated, and includes the United Kingdom, Japan, South Korea and Switzerland. For accounting records the model is different and much blunter: only European Union countries are allowed, and no paperwork buys you more.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The main regulator is the Personal Data Protection Agency, known as AZOP. It is fully staffed, it hires more people, and it is one of the busiest fining bodies in central Europe for its size. It issued 13 fines totalling about 6.7 million euros (roughly 7.3 million dollars) in 2025, and 38 fines the year before. The cyber regulator, the National Cyber Security Centre, is also up and running.

What it costs if you get it wrong:
Percentage of global turnover · Fixed maximum fine · Criminal liability

How long you must keep it — and when to delete it

Croatia has strong minimum keeping periods and a few hard maximums. Ledgers and the documents behind them must be kept at least eleven years; payroll lists six years; the detailed wage and contribution records forever. Medical records run to ten years after the patient dies. Going the other way, camera footage must normally be deleted after six months.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are at least two deadlines and they run at different speeds. A personal data breach goes to the privacy regulator within 72 hours. A significant cyber incident goes to the cyber authority within 24 hours as an early warning. A fuller report follows at 72 hours, and a final report within 30 days. One incident can easily trigger both. The 24-hour deadline is the one that catches people out.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents · Secure the data

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things. Your ledger cannot live on an American cloud. Children count as adults for online consent at 16, not 13. Using someone's personal data unlawfully is a crime, not just a fine. Genetic test results may never be used to price life insurance. And camera footage in an apartment building needs two thirds of the owners to agree.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability

What's changing next

Two Croatian dates matter. Fines under the state information infrastructure law switch on 1 January 2027. Mandatory eInvoicing widens to smaller traders on the same day. Across Europe, cloud switching fees must fall to zero by 12 January 2027. The thing to watch is the challenge to the Europe-United States data deal, which is still valid but under real pressure.

What you have to do here:
Make switching cloud provider possible
Ways to send data out:
Official 'this country is safe' decision

What to do: Diarise 1 January 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Zakon o državnoj informacijskoj infrastrukturi · Narodne novine 72/2025, Articles 17 and 27; penalty Articles 33-34 apply from 1 January 2027 · Act of parliament

Partly in forceNo — it stays put

Croatian state registers that contain personal data must be held in data centres inside Croatia, and public bodies must use the government's own shared cloud. The rule is already in force but no fine can be imposed for breaking it until 1 January 2027.

In force since 1 May 2025In force now, but not enforced until 1 January 2027

That is a long gap: the duty is real law today, but no penalty can follow until 1 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by Ministry of Justice, Public Administration and Digital Transformation

How this country controls where data goes: Not allowed

Health and social care

Health and social care data needs a copy kept in the country

Official name: Zakon o podacima i informacijama u zdravstvu · Narodne novine 14/2019, Articles 19(2), 27, 28, 29 · Act of parliament

In forceA copy must stay

Health data in Croatia is handled inside the national health information infrastructure and exchanged through the central health system. That keeps it in Croatia for any realistic purpose. The law does not spell out an express ban on hosting a copy abroad.

In force since 15 February 2019Enforced from 15 February 2021

How this country controls where data goes: Approval each time

Not fully verified — see “What we're not sure about” below.
Mapping and location

State and security data rules

Official name: Uredba o snimanju iz zraka · Narodne novine 77/2020, Articles 4, 6, 7, 9, 10, 13, 14 · Directly binding regulation

In forceYes, with paperwork

Photographing Croatia from the air needs one government approval to fly. It needs a second, separate approval before the images may be used. The Ministry of Defence checks the images first and can order frames to be excluded.

In force since 11 July 2020

Enforced by State Geodetic Administration

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

Personal data must stay in the country

Official name: Zakon o računovodstvu · Narodne novine 85/2024, Articles 10(3) and 13(3); consolidated to Narodne novine 59/2026 · Act of parliament

In forceNo — it stays put

A Croatian company may keep its books and the documents behind them outside Croatia only in another European Union country. There is no contract, consent or approval that permits storage in the United States or any other non-EU country.

In force since 27 July 2024

Enforced by Tax Administration

How this country controls where data goes: Only approved countries

Insurance rules

Official name: Zakon o provedbi Opće uredbe o zaštiti podataka · Narodne novine 42/2018, Articles 19, 25-34 · Act of parliament

In forceYes, with paperwork

Croatia's national privacy law sits on top of the European rulebook. It has three distinctive features. The digital consent age is 16. There is a detailed camera surveillance code in the law itself. And there is a flat ban on using genetic data to price life insurance.

In force since 25 May 2018

Enforced by Personal Data Protection Agency

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

Cyber security rules

Official name: Zakon o kibernetičkoj sigurnosti (i Uredba o kibernetičkoj sigurnosti) · Narodne novine 14/2024; Cybersecurity Regulation, Narodne novine 135/2024, Articles 65-71 · Act of parliament

In forceYes — store it anywhere

Croatia's cybersecurity law puts the European network and information security rules into national law. Significant incidents need an early warning in 24 hours, a full report in 72 hours and a closing report within 30 days. It says nothing about where data must be stored.

In force since 15 February 2024Enforced from 20 November 2024

Enforced by National Cyber Security Centre

How this country controls where data goes: No restriction

Who you would hear from

  • Agencija za zaštitu osobnih podataka (AZOP)

    General data protection supervisory authority for Croatia.

    Fully operational and expanding. Published tally: 38 fines in 2024, and 13 fines totalling EUR 6,725,500 in 2025. That includes EUR 4.5 million against a telecoms operator on 14 November 2025 for unlawful transfers to Serbia. Largest fine to date EUR 5.47 million (EOS Matrix, October 2023). Five recruitment competitions for six posts were published on 18 May 2026.

  • Nacionalni centar za kibernetičku sigurnost (NCSC-HR)

    Central state body for cybersecurity, national incident response team, single point of contact and cyber crisis manager under the Cybersecurity Act. Operates within the Security and Intelligence Agency.

    Operational. Runs the national threat and incident reporting platform and publishes binding guidance.

  • Nacionalni CERT (CARNET)

    Incident response team for the sectors not covered by NCSC-HR; publishes the significant-incident notification guidance.

    Operational; issued the general guidance on significant incident notification in April 2025.

  • Državna geodetska uprava

    Issues approvals for aerial photography and for the use of aerial imagery; co-chairs the defence review commission.

    Operational; publishes the application procedure and forms for both approvals.

  • Hrvatska narodna banka

    Prudential supervisor for credit institutions; sets the outsourcing and information system rules.

    Operational; amended its outsourcing decision in December 2024.

  • Ministarstvo pravosuđa, uprave i digitalne transformacije

    Runs the state information infrastructure and the Shared Services Centre; competent for the 2025 state information infrastructure Act.

    Up and running, but the Act's penalty rules do not apply until 1 January 2027. So no fines are possible yet.

  • Porezna uprava

    Supervises accounting records, retention and the fiscalisation of eInvoices.

    Operational; ran the first phase of mandatory eInvoice fiscalisation from 1 January 2026.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Croatia's traffic and location data retention regime for telecoms operators - the article number, the retention period, and whether retained data must be held in Croatia.

    We could not confirm how long telecoms operators must keep traffic and location data, or whether it has to stay in Croatia. Checked 18 August 2026. If you run a telecoms service, ask the regulator before you rely on a period.

  • The deadline for a telecoms operator to notify the Croatian telecoms regulator of a security incident.

    The duty to report clearly exists, but we could not confirm the deadline against an official text. If you run a telecoms service, ask the regulator for the deadline.

  • Whether any Croatian court or the Constitutional Court has disapplied or limited the Croatian telecoms data retention provisions following the Court of Justice case law on general and indiscriminate retention.

    We found no Croatian court ruling on this on an official court website, checked 18 August 2026. That does not mean none exists. Check before you rely on it.

  • The exact misdemeanour fine amounts under the Accounting Act for keeping business books or accounting documents outside the European Union.

    We could not confirm the fine amounts for keeping business books or accounting documents outside the European Union. The ban itself is confirmed from the official text. Only the amount is unconfirmed.

  • Whether the Act on Data and Information in Healthcare bars a private healthcare provider from additionally hosting its own patient records outside Croatia.

    The law makes health data run inside Croatia's health information infrastructure, and makes providers exchange it through the central health system. We found no express ban on a private provider also hosting its own records abroad. Treat this as a limit in fact rather than a stated ban. Confidence is medium.

  • Whether the Croatian Financial Services Supervisory Agency imposes cloud or outsourcing location conditions on insurers, pension companies and investment firms beyond the European Digital Operational Resilience Act.

    We found no rulebook on the regulator's own site setting cloud or location conditions for insurers, pension companies and investment firms. That is a rule we did not find, not proof that none exists. If you are in one of those industries, check with the regulator.

  • Whether the current Act on Archival Material and Archives restricts taking a company's documentary material out of Croatia, and whether doing so is still a criminal offence.

    We could not confirm what the current Act on Archival Material and Archives says. The 1997 version carried up to five years in prison for removing original archival material without ministry approval. It was replaced in 2018. We make no claim about the current text, so check it if you hold archival material.

  • The exact maximum sentence under Article 146 of the Croatian Criminal Code for unlawful use of personal data.

    We could not confirm the maximum sentence for unlawful use of personal data. The offence itself, and live prosecutions under it, are confirmed from the State Attorney's Office. Only the penalty range is unconfirmed.

  • The content and closing date of the 2026 public consultation on amendments to the Electronic Communications Act.

    We could not confirm the content or closing date of the 2026 consultation on changes to the Electronic Communications Act. The government's consultation page returned an error on 18 August 2026.

  • Whether AZOP has issued fines in 2026.

    We could not confirm whether AZOP has issued any fines in 2026. Its published fines table was last changed in February 2026 and stops at 2025. Its 2026 activity shows up in recruitment notices instead.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.