Skip to content
Ceci est une traduction de commodite. La version anglaise est la version officielle et juridiquement contraignante. Voir la version anglaise
EUMEDIUM coverage1 enforcement action

Croatia — GDPR + EU AI Act + Croatian AI Strategy 2021: AI Compliance Requirements

Croatia's Agencija za zaštitu osobnih podataka (AZOP) supervises GDPR. Croatia adopted its National AI Development Strategy in 2021, covering AI in tourism (major economic sector), manufacturing, logistics, and public services. Croatia's thriving tech startup scene (Zagreb, Split) and EU membership since 2013 make it an emerging AI market.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

May 25, 2018

Enforcement Begins

August 2, 2026

Maximum Penalty

€20,000,000 or 4% of global turnover (GDPR); EU AI Act: €35M or 7% global turnover

What Your Business Must Do

2 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

GDPR AI Compliance — AZOP Supervision

Critical

AZOP enforces GDPR for AI systems processing Croatian residents' data — a genuinely active regulator, with nearly €7M in fines issued in 2025 alone (following a record €10.5M across 97 decisions in 2024), including the largest Croatian GDPR fine on record (EOS Matrix, €5.47M, 2023-10-05, for unlawful automated debt-collection data processing). AI-driven profiling, pricing, and recommendation systems face DPIA requirements. Automated decision-making rights (GDPR Art. 22) mandatory where AI decisions significantly affect individuals.

GDPR Art. 22 (automated decisions); Art. 35 (DPIA)

EU AI Act — Biometric and High-Risk AI (incl. Tourism & Hospitality)

High Priority

Facial recognition and other biometric AI (including in hospitality, e.g. hotel check-in) is high-risk under EU AI Act Annex III / prohibited under Article 5 depending on use case, requiring explicit consent (or a legal-obligation basis), a DPIA, access controls, and data deletion after the processing purpose ends. AZOP has published a Fundamental Rights Impact Assessment (FRIA) methodology under AI Act Article 27 (2025-03) and Croatian-language translations of the EU Commission's prohibited-practices guidelines (2025-07-29). NOTE: the "Digital Omnibus" amendment (Regulation (EU) 2026/1744, in force 2026-07-27) deferred stand-alone high-risk (Annex III) conformity obligations from 2026-08-02 to 2027-12-02.

Deadline: December 2, 2027

EU AI Act Art. 5 (prohibited practices) / Art. 6, Annex III (high-risk biometric classification); Art. 27 (FRIA, per AZOP's own 2025-03 methodology); GDPR Art. 9 (biometric special category)

Who Does This Apply To?

Applies to: any organisation established in Croatia, and any organisation outside Croatia processing the personal data of Croatian residents through AI systems — GDPR applies with extraterritorial reach (Art. 3), obligations attaching to the processing activity rather than company size, with no general small-business exemption. AZOP is a genuinely active enforcer (nearly €7M in fines in 2025, a record €10.5M across 97 decisions in 2024, including its largest-ever fine — EOS Matrix, €5.47M, for unlawful automated debt-collection data processing). As an EU member state, Croatia is fully subject to the EU AI Act: facial-recognition and other biometric AI is high-risk under Annex III (or prohibited under Article 5 depending on use case), requiring explicit biometric consent (or a legal-obligation basis), a DPIA, access controls and data deletion once the purpose ends — GDPR Article 9 independently treats biometric data as a special category requiring explicit, active consent regardless of AI Act status. AZOP requires Article 22 human-review rights where AI decisions significantly affect individuals, and has published its own Article 27 AI Act Fundamental Rights Impact Assessment (FRIA) methodology. Penalties reach €20M / 4% of global turnover under GDPR and €35M / 7% under the EU AI Act.

Recent Enforcement Actions

2023-10-05Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2025-03

AZOP — AI Act Article 27 Fundamental Rights Impact Assessment (FRIA) Methodology

AZOP published a practical FRIA methodology (2025-03) for AI Act Article 27, developed in collaboration with Professor Alessandro Mantelero (Politecnico di Torino, original FRIA methodology author) and the Catalan data protection authority — required before deploying a high-risk AI system under Article 6(2). AZOP held a public workshop on implementing it 2025-06-13, and recommends combining FRIA with a GDPR DPIA where both apply. AZOP also published a Croatian-language translation of the EU Commission's prohibited-AI-practices guidelines on 2025-07-29.

Frequently Asked Questions

Does Croatia — GDPR + EU AI Act + Croatian AI Strategy 2021 apply to my business?

Croatia's Agencija za zaštitu osobnih podataka (AZOP) supervises GDPR. Croatia adopted its National AI Development Strategy in 2021, covering AI in tourism (major economic sector), manufacturing, logistics, and public services. Croatia's thriving… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Croatia — GDPR + EU AI Act + Croatian AI Strategy 2021 is: €20,000,000 or 4% of global turnover (GDPR); EU AI Act: €35M or 7% global turnover. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Croatia — GDPR + EU AI Act + Croatian AI Strategy 2021?

The 2 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://azop.hr/en

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan