Overview
The 'Zakon o provedbi Opće uredbe o zaštiti podataka' lays down national regulations to implement the EU General Data Protection Regulation (GDPR) within Croatia. It specifies organizational roles, including the Croatian Data Protection Agency's independence, its powers to issue fines and recommendations, and oversee GDPR compliance. Additional provisions restrict the processing of genetic and biometric data and set the age of consent for processing children's data at 16 years. The law also establishes rules for collaboration with other national and international supervisory bodies, regulates cross-border operations, and stipulates transparency and accountability measures, including mandatory annual reporting to the Croatian Parliament.