AZOP (Croatia) - 05/01/2026
| AZOP - 05/01/2026 | |
|---|---|
| Authority: | AZOP (Croatia) |
| Jurisdiction: | Croatia |
| Relevant Law: | Article 5(1) GDPR Article 13 GDPR Article 27 ZPOUZP |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | |
| Decided: | 05.01.2026 |
| Published: | |
| Fine: | 6,636.14 EUR |
| Parties: | n/a |
| National Case Number/Name: | 05/01/2026 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Croatian |
| Original Source: | AZOP (in HR) |
| Initial Contributor: | RP |
The DPA fined a retailer €6,636.14 for operating a video surveillance system in its shop without informing its customers by displaying a notice in the shop.
English Summary
Facts
On 20 August 2025, the Croatian Data Protection Authority (AZOP) carried out an unannounced inspection in a context of an ex oficio investigation at a retail branch inside a shopping centre (the controller). The inspection examined the processing of personal data through a video surveillance system installed in the shop.
During the inspection, AZOP found seven surveillance cameras installed inside the store. A store employee informed the authority that the system had been installed when the branch opened in 2016. The controller used the cameras to protect employees, property and goods in the shop. Employees could access the recordings through a computer using an application. The authority checked the system and confirmed that recordings were stored and that the oldest available recording dated from 18 August 2025.
AZOP inspected the premises and found that the controller had not displayed any notice informing visitors that the space was under video surveillance. The authority did not find a sign at the entrance of the shop, on the storefront window or inside the premises.
Holding
AZOP held that the controller violated Article 27(1) of the Croatian Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka). Article 27(1) of the Act requires controllers to mark the premises and surrounding areas under video surveillance.
AZOP clarified that this obligation ensures transparency when controllers process personal data through video surveillance. Video recordings that show identifiable individuals constitute personal data processing. Therefore, individuals must be informed about the monitoring before they enter the recorded area.
The authority further explained that Article 27(2) of the Act requires the information provided under Article 27(1) to comply with the information requirements of Article 13 GDPR.
When determining the sanction under Article 83(2) GDPR, AZOP considered the duration and seriousness of the infringement. The controller processed personal data through video surveillance without notice for more than seven years after the GDPR became applicable. The authority also noted that the shop was located in a busy shopping centre, meaning that a large number of individuals were affected. AZOP further concluded that the infringement was intentional because the controller had already been fined on 5 December 2022 for the same violation at another location.
In light of the long duration of the infringement, the large number of affected individuals and the repeated nature of the violation, AZOP imposed the maximum administrative fine of €6,636.14 under Article 51(1) of the Croatian Act on the Implementation of the General Data Protection Regulation. The authority considered this amount effective, proportionate and dissuasive, particularly because the earlier fine had not prevented the controller from repeating the same violation.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Croatian original. Please refer to the Croatian original for more details.
REPUBLIC OF CROATIA AGENCY FOR THE PROTECTION OF PERSONAL DATA CLASS: REGISTRATION NUMBER: Zagreb, 5.1.2026. Personal Data Protection Agency (OIB: 28454963989) pursuant to Article 57, paragraph 1, Article 58, paragraph 1 and 2, point (i) and Article 83, paragraph 2 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) OJ EU L119, Articles 44, 45 and 51, paragraph 1, indent 1 of the Act on the Implementation of the General Data Protection Regulation (Official Gazette No. 42/18) and Article 42, paragraphs 1 and 2 and Article 96 of the Act on General Administrative Procedure (Official Gazette No. 47/09 and 110/21) ex officio issues the following DECISION 1. It is established that the personal data controller X, (OIB:X), contrary to Article 27. paragraph 1 of the Act on the Implementation of the General Data Protection Regulation, failed to indicate that the branch office at the location of shopping mall X, or rather an individual room therein, and the external area of the facility is under video surveillance. 2. For the violation described in point 1 of the operative part of this decision, in accordance with the provision of Article 51, paragraph 1, indent 1 of the Act on the Implementation of the General Data Protection Regulation, an administrative fine in the amount of: EUR 6,636.14 (in words: six thousand six hundred thirty-six euros and fourteen cents) 3. The personal data processor X is obliged to pay the imposed administrative fine to the state budget within 15 days from the date of entry into force of this decision into the account number: HR1210010051863000160, model HR64 and reference to the approval number with the indication — "administrative fines imposed by the AZOP". 4. If the personal data processor X fails to pay the imposed administrative fine within 15 days from the date of entry into force of this decision, The Personal Data Protection Agency shall, in accordance with Article 46, paragraph 2 of the Act on the Implementation of the General Data Protection Regulation notify the Regional Office of the Tax Administration of the Ministry of Finance in whose territory the registered office of the said company is located in order to collect the administrative fine by force in accordance with the regulations on forced tax collection. 1 5. The personal data processor X is obliged to submit proof of payment to this Agency within 15 days of the payment. R e a s s u p t i o n 1. DETERMINATION OF VIOLATION The Personal Data Protection Agency (hereinafter: the Agency) carried out, ex officio on 20 August 2025, without prior notice, direct supervision of the processing and implementation of personal data protection regarding the collection and processing of personal data made by a video surveillance system installed in the office of the personal data processor X within the shopping mall X, and for which a Report on the conducted supervision was drawn up (CLASS: X, NUMBER: X of 20 August 2025). During the supervisory activities on 20 August 2025, it was established that seven video surveillance cameras were installed within the branch office of the personal data processor X within the shopping center X. During the supervision, an employee of the branch office contacted the sales director Mr. X by telephone and the same employee stated to the Personal Data Protection Agency that the video surveillance was installed when the branch office was opened in 2016. During the supervisory proceedings, an employee of the branch office stated that the purpose of establishing the video surveillance system was to protect employees and property and goods in the branch office. The branch office employees have access to the recordings on their computers, and during the supervision, the computer was inspected and the current camera footage as well as the camera footage was inspected in the Smart PSS application, where the oldest stored footage from 18.08.2025 was determined. During the supervisory proceedings, by inspecting the business premises, it was established that the business office in question the entity does not have a notice of video surveillance displayed either at the entrance to the business premises, on the glass wall (shop window) or in the branch office itself. During the surveillance procedure, photographs were taken of the cameras in the premises, the Smart PSS application, the camera angle, the angle of the oldest recording, the premises at the entrance to the branch office and the glass wall (shop window). The Agency points out that since 25 May 2018, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) OJ EU L119. In accordance with Article 4, paragraph 1, point 1 of the General Data Protection Regulation, personal data are all data relating to an identified or identifiable natural person, and an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. 2According to Article 4(1)(2) of the General Data Protection Regulation, processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. According to Article 5 of the General Data Protection Regulation, personal data must be processed lawfully, fairly and transparently in relation to the data subject, collected for specified, explicit and legitimate purposes, adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed and processed in a manner that ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage by applying appropriate technical or organisational measures (principle of integrity and confidentiality). Article 25(1) of the Act implementing the General Data Protection Regulation stipulates that video surveillance refers to the collection and further processing of personal data which includes the creation of a recording which constitutes or is intended to constitute part of a storage system. In accordance with Article 27(1) of the Act implementing the General Data Protection Regulation, the controller or processor is obliged to mark that the facility or individual room in it and the external surface of the facility is under video surveillance, and the mark must be visible at the latest when entering the recording perimeter. In accordance with Article 27, paragraph 2 of the Act Implementing the General Data Protection Regulation, the notification referred to in paragraph 1 of this Article must contain all relevant information in accordance with the provisions of Article 13 of the General Data Protection Regulation, and in particular a simple and easily understandable image with text which provides the data subjects with the following information: - that the premises are under video surveillance; - information about the controller; - contact details through which the data subject can exercise his or her rights. Recital 39 of the General Data Protection Regulation further clarifies, inter alia, that any processing of personal data should be lawful and fair. Individuals should be transparent about how personal data relating to them are collected, used, disclosed or otherwise processed, as well as the extent to which such personal data are or will be processed. The principle of transparency requires that any information and communication relating to the processing of such data be easily accessible and understandable and that clear and plain language. This principle refers in particular to information to the data subject on the identity of the controller and the purposes of the processing and further information to ensure the fairness and transparency of the processing in relation to the individuals concerned and their right to obtain confirmation and information about the personal data which are being processed and which relate to them. Also, recital 58 of the GDPR clarifies, inter alia, that the principle of transparency requires that any information intended for the public or the data subject be concise, easily accessible and intelligible, that clear and plain language is used and, where appropriate, that visualisation is used. Furthermore, recital 60 of the GDPR states, inter alia, that the principle of fair and transparent processing requires that the data subject be informed of the processing operation 3 and its purposes. The controller should provide the data subject with all additional information necessary to ensure fair and transparent processing taking into account the specific circumstances and the context of the processing personal data. Similarly, Recital 148 of the GDPR states that in order to improve the enforcement of the rules of this Regulation, sanctions, including administrative fines, should be provided for for any infringement of this Regulation, in addition to or instead of appropriate measures imposed by the supervisory authority in accordance with this Regulation. In the case of a minor infringement or where a possible fine would impose a disproportionate burden on the natural person, a warning may be issued instead of a fine. However, particular attention should be paid to the nature, seriousness and duration of the infringement, the intention of the infringement, the measures taken to mitigate the damage suffered, the degree of responsibility or any previous relevant infringements, the manner in which the supervisory authority became aware of the infringement, compliance with measures ordered against the controller or processor, compliance with a code of conduct and any other aggravating or mitigating factors. The imposition of sanctions, including administrative fines, should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter, including effective judicial protection and due process. After accurately and completely establishing the facts, it is clear that the controller of the processing X failed to mark the business premises within the shopping mall X before entering the recording perimeter, i.e. in the manner required by the provisions of Article 27 of the Act on the Implementation of the General Data Protection Regulation. II. DETERMINATION OF ADMINISTRATIVE FINES Article 44 of the Act on the Implementation of the General Data Protection Regulation stipulates that the Agency shall impose administrative fines for violations of the provisions of this Act and the General Data Protection Regulation, in accordance with Article 83 of the General Data Protection Regulation. Article 45, paragraph 1 of the aforementioned Act stipulates that administrative fines shall be imposed by decision. Pursuant to paragraph 2 of the same article, the decision shall determine the amount and manner of payment of the administrative fine. The decision may determine that the administrative fine shall be paid in installments. Pursuant to paragraph 4 of the same article, no appeal is allowed against the decision, but an administrative dispute may be initiated before the competent administrative court. Pursuant to Article 46 of the same Act, the administrative fine shall be paid within 15 days from the date of the finality of the decision imposing it. If the party fails to pay the administrative fine within the prescribed period, or upon the maturity of the last installment if payment by installments has been approved, the Agency shall notify the Regional Office of the Tax Administration of the Ministry of Finance in whose territory the party to whom the administrative fine was imposed has its residence or registered office, for the purpose of collecting the administrative fine by force in accordance with the regulations on the forced collection of taxes. Administrative fines shall be paid to the benefit of the state budget. By way of exception to paragraph 2 of this article, no interest shall be calculated on the due but unpaid administrative fine. Given the established circumstances in this case, the Agency, in accordance with its powers under Article 58, paragraph 2, item (i) of the General Data Protection Regulation, imposed an administrative fine instead of other corrective measures under the relevant Article, all in accordance with the conditions for its imposition under Articles 44, 45 and 46 of the Act Implementing the General Data Protection Regulation. After a detailed examination of the available corrective measures referred to in Article 58(2) of the General Data Protection Regulation, which the supervisory authority is authorised to impose on the controller and/or processor, in the event of a breach of the provisions of the Act on the Implementation of the General Data Protection Regulation, and having assessed all the circumstances of the case in question, in particular that the chosen corrective measure must be effective, proportionate and dissuasive in each individual case, the Agency has decided to impose an administrative fine, paying due attention to the criteria laid down in Article 83(2) of the General Data Protection Regulation. By imposing an administrative fine, the aim is also to ensure that the controller itself, who processes the personal data of the data subjects in connection with the video surveillance system, complies with the rules on the protection of personal data. By imposing an administrative fine, it should be achieved in general deterrence (to discourage others from repeating the same violation in the future), as well as in particular deterrence (to discourage the addressee of this administrative fine from repeating the same violation). In Article 51, paragraph l. indents l. of the Act on the Implementation of the General Regulation on Data Protection prescribed is that the controller will be fined up to HRK 50,000.00 and processor that does not mark the object, premises, parts of the premises and the external surface facility in the manner prescribed by Article 27 of this Law. Furthermore, Article 3, paragraph 1, item 11 of the Act on the Introduction of the Euro as the Official Currency of the Republic of Croatia (Official Gazette Nos. 57/22 and 88/22) stipulates that the fixed conversion rate is an irrevocably fixed conversion rate between the euro and the kuna with five decimal places, established by a regulation of the EU Council in accordance with Article 140, paragraph 3 of the Treaty on the Functioning of the European Union. Article 1, paragraph 1 of Council Regulation 2022/1208 of 12 July 2022 amending Regulation (EC) No 2866/98 as regards the euro conversion rate for Croatia stipulates that the fixed conversion rate for one euro is 7.53450 Croatian kuna. Accordingly, the maximum amount of the fine that may be imposed pursuant to Article 51, paragraph 1, indent 1 of the Act Implementing the General Data Protection Regulation is 6,636.14 Euros. Pursuant to the provision of Article 83, paragraph 2 of the General Data Protection Regulation, when deciding on the imposition of an administrative fine and deciding on the amount of that administrative fine, the Agency in this case paid due attention to the following: - The nature, gravity and duration of the infringement, taking into account the nature, scope and purpose of the processing in question, as well as the number of data subjects and the level of damage suffered by them (Article 83, paragraph 2, point a): In the case at hand, as set out in point l. of the operative part of this decision, there was a breach of the obligations of the controller X in that the controller did not indicate that the business premises (or individual rooms therein and the external surfaces of the facility) were under video surveillance in accordance with the provisions of Article 27 of the Act on the Implementation of the General Data Protection Regulation. In accordance with the Guidelines of the Working Party under Article 29 on the application and setting of administrative fines for the purposes of Regulation 2016/679 of 3 October 2017 (WP 253), which the European Data Protection Board endorsed at its first plenary session on 25 May 2018, an indicator of the seriousness of the breach may be not only the nature of the breach, but also the scope, purpose of the processing concerned, as well as the number of data subjects and the level of harm suffered by them. In this administrative matter, it was established that the controller X collected and processed personal data of visitors/respondents via video surveillance in the period from 13 January 2016 to 20 August 2025. Since the General Data Protection Regulation has been directly applicable since 25 May 2018, the Agency, in accordance with the principle of non-retroactivity, took into account the specified date as the date of commencement of the violation, and the incriminated period of the violation was from 25 May 2018 to 20 August 2025. When determining the penalty, it was taken into account that the processing in question did not represent the core activity of the controller. Furthermore, the controller did not inform the data subjects about the processing in question in accordance with the principle of transparency, and thus the data subjects were deprived of information about the processing of their data, i.e. the controller in question X acted contrary to Article 27 of the Act on the Implementation of the General Data Protection Regulation for almost seven years and three months from 25 May 2018 to 20 August 2025. Given that the branch office of company X within shopping mall X regularly experiences a large fluctuation of data subjects, and consequently and inevitably their personal data is processed via a video surveillance system, of which the data subjects were not informed, contrary to the obligation under Article 27 of the Act on the Implementation of the General Data Protection Regulation. - Whether the infringement is intentional or negligent (Article 83(2)(b): The Article 29 Working Party states in its Guidelines on the application and setting of administrative fines for the purposes of Regulation 2016/679 of 3 October 2017 (WP 253), which the European Data Protection Board endorsed at its first plenary session on 25 May 2018, that “intention” generally includes knowledge and intent as to the characteristics of the infringement, while “unintentional” means that there was no intention to cause the infringement even though the controller/processor breached his/her duty of care prescribed by law. The same Guidelines therefore highlight the distinction between circumstances indicative of an “intentional infringement” and those indicative of infringements caused “unintentionally” or “negligently”. In this regard, the Guidelines cite “failure to adopt policies” and “human error” as examples of conduct that may indicate negligence. In relation to the above, in the case in question it was established that there was an intention to violate the provisions of the General Data Protection Regulation and the Act on the Implementation of the General Data Protection Regulation by the personal data controller X. Namely, on 5 December 2022, the Agency issued a Decision (CLASS: X, NUMBER:X) to the controller X in question, establishing that the same company, contrary to Art. 27. Paragraph 1 of the Act on the Implementation of the General Data Protection Regulation did not indicate that the Optika X facility at address X, or rather, individual rooms therein and the external surfaces of the facility were under video surveillance, and an administrative fine was imposed, which indicates that the controller knew that by not indicating in the manner prescribed by Article 27 of the Act on the Implementation of the General Data Protection Regulation, he was violating the aforementioned article, and despite the aforementioned, he continued, at another location, with an identical violation of the personal data protection regulations and, by doing so, he clearly willingly consented to it, which clearly supports the existence of intentional action by the controller. - Any action taken by the controller or processor to mitigate the damage suffered by the data subjects (Article 83(2)(c): The controller failed to inform the Agency of any subsequent actions taken and the posting of appropriate notices on the video surveillance system, or to correct his unlawful conduct contrary to the provisions of Article 27 of the Act Implementing the General Data Protection Regulation. - The degree of responsibility of the controller or processor taking into account the technical and organisational measures implemented in accordance with Articles 25 and 32 (Article 83(2)(d): 6Not applicable in the present case. - Relevant previous violations by the controller or processor (Article 83, paragraph 2, item e): According to the records of violations kept by this Agency, the controller of personal data X committed an identical violation in the past in an identical manner and on 5 December 2022, the Agency issued a Decision (CLASS: X, NUMBER: X) to the controller of personal data X in question, establishing that the company, in violation of Article 27, paragraph 1 of the Act on the Implementation of the General Data Protection Regulation, did not indicate that the Optika X facility at address X, or rather individual rooms therein and external surfaces of the facility, was under video surveillance and an administrative fine was imposed, which Decision is final. The repetition of the identical violation or recidivism indicates a systematic disregard for the rules on the protection of personal data, which was assessed as a significant aggravating circumstance for the controller. - The degree of cooperation with the supervisory authority to remedy the breach and mitigate the possible adverse effects of the breach (Article 83(2)(f): The controller has responded appropriately to the requests of the supervisory authority during this administrative procedure. - Categories of personal data affected by the breach (Article 83(2)(g): The video surveillance system in question processes the personal data of the data subject (video recording of the data subject's face and movements). - The manner in which the supervisory authority became aware of the infringement, in particular whether and to what extent the controller or processor reported the infringement (Article 83(2)(h): The supervisory authority became aware of the infringement in question on 20 August 2025 through direct supervision or inspection of the premises of company X within shopping centre X. - If measures referred to in Article 58(2) have previously been imposed on the controller or processor in relation to the same matter , compliance with those measures (Article 83(2)(i): In this part, the Agency did not repeatedly assess the above-mentioned Decision of 5 December 2022 as an aggravating circumstance, due to the prohibition of double assessment of aggravating circumstances. As such, it was omitted as irrelevant. - Compliance with approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42 (Article 83(2)(j): Not applicable in the case at hand. - Any other aggravating or mitigating factors applicable to the circumstances of the case, such as the financial gain gained from the infringement or the losses avoided, directly or indirectly, by the infringement (Article 83(2)(k): 7It has not been established that controller X has gained a financial gain from the infringement or avoided losses, directly or indirectly. In conclusion, it follows from all of the above that the controller of personal data X failed to indicate the branch office within the shopping mall X, or rather, individual premises therein, which are under video surveillance, as prescribed by the provisions of Article 27, paragraphs 1 and 2 of the Act on the Implementation of the General Data Protection Regulation, and for which the violation is punishable by an administrative fine of up to 50,000.00 kn, or 6,636.14 euros, in accordance with Article 51, paragraph 1, indent 1 of the same Act. Since this is a recidivist, the Agency decided to impose the maximum administrative fine, and in that regard took into account that almost three years had passed since the imposition of the first administrative fine, which indicates that the previously imposed amount of the administrative fine did not satisfy the purpose of punishment (special prevention), and as a result, the Agency was forced to apply the maximum amount of the fine. In this part, the Agency also reviewed the financial report of the controller and determined that its total revenue amounted to EUR 7,759,558.98 (Independent Auditor's Report with the Annual Financial Statements for the year ended 31 December 2024). Likewise, taking into account all of the above, the Agency believes that the corrective measure in the form of an administrative fine is effective, proportionate and dissuasive in this administrative matter, and that its amount is fully appropriate to the circumstances of the specific case. Based on all of the above, it was decided as in the operative part of the Decision. INSTRUCTION ON LEGAL REMEDY: No appeal is allowed against this Decision, but an administrative dispute may be initiated before the Administrative Court in Zagreb within 30 days from the date of delivery of the Decision. DIRECTOR Zdravko Vukić, univ. mag. oec. TO BE SUBMITTED: l . X 2. Scripture, here 8




