AZOP (Croatia) - 14-11-2025
| AZOP - 14-11-2025 | |
|---|---|
| Authority: | AZOP (Croatia) |
| Jurisdiction: | Croatia |
| Relevant Law: | Article 5(1)(c) GDPR Article 5(1)(a) GDPR Article 6(1) GDPR Article 28 GDPR Article 28(1) GDPR Article 44 GDPR Article 46(1) GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | |
| Decided: | 14.11.2025 |
| Published: | |
| Fine: | 4,500,000 EUR |
| Parties: | n/a |
| National Case Number/Name: | 14-11-2025 |
| European Case Law Identifier: | n/a |
| Appeal: | n/a |
| Original Language(s): | Croatian |
| Original Source: | AZOP (in HR) |
| Initial Contributor: | RP |
The DPA fined a communication network provider €4,500,000 for several GDPR breaches including unlawful data transfers to Serbia and for misleading users with vague information that hid regular third-country processing.
English Summary
Facts
On 14 November 2025, the DPA completed an ex officio investigation into a communication network provider that acted as a controller. The DPA found that the controller transferred the personal data of its users to a processor in the Republic of Serbia (third country outside the EEA).
Until 27 December 2022, the controller relied on standard contractual clauses to legitimise this transfer. After that date, no valid transfer instrument existed, even though the processor in Serbia still had administrator-level access to the controller’s entire database. This database contained the personal data of 847,862 users, including names, national identification numbers, addresses, contact details, and bank account numbers. The controller had not carried out a transfer risk assessment before sending personal data to Serbia.
The DPA also established that the controller did not give clear information to data subjects about these third-country transfers. The privacy policy used vague language, such as stating that data “may” be transferred to third countries or that processing happened “generally” in the EU, with only exceptional processing outside it. The policy did not state that Serbia was in fact used as a regular destination for data transfers.
The investigation further showed that the controller collected copies of employees’ identity cards without identifying a lawful basis and beyond what was necessary for its purposes. The controller did this despite the data protection officer advising that collecting full copies of identity cards was excessive. The controller also required employees to provide certificates confirming that no criminal proceedings were pending against them.
Finally, the controller hired a processor to provide telephone support services. The DPA found that this processor had not implemented basic security measures. The controller had not checked whether the processor complied with data protection requirements before allowing them to process personal data.
Holding
The DPA held that the controller breached Article 44 GDPR together with Article 46 GDPR because it transferred personal data to Serbia without an appropriate safeguard after 27 December 2022 and without a transfer risk assessment. The DPA held that the controller also violated Article 12 GDPR and Article 13(1)(f) GDPR because it did not give data subjects clear and transparent information about transfers to a third country.
The DPA found breaches of Article 5(1)(a) and (c) GDPR and Article 6(1) GDPR because the controller collected copies of employees’ identity cards and certificates of non-criminal proceedings without a lawful basis and in a way that exceeded what was necessary. The DPA treated the controller’s decision to ignore the data protection officer’s warning as an aggravating factor. The DPA also held that the controller violated Article 28(1) GDPR because it engaged a processor without checking whether the processor had adequate technical and organisational measures in place.
For these infringements, the DPA imposed an administrative fine of €4,500,000.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Croatian original. Please refer to the Croatian original for more details.
Teleoperator fined in the total amount of 4.5 million euros November 14, 2025 Following the procedure conducted ex officio, the Personal Data Protection Agency imposed an administrative fine of 4,500,000.00 euros* on a teleoperator (operator of electronic communications networks and services), as a controller, for violating the provisions of the General Data Protection Regulation, namely with regard to the transfer of personal data to third countries without a valid instrument and without transparent information to the data subjects, and the processing of copies of employee ID cards and certificates of non-criminal proceedings without a legal basis, as well as the failure to undertake appropriate prior control of the processor. The controller transferred the personal data of its users to a data importer (processor) in the Republic of Serbia (a company within the group that maintained the software) and based the transfer on standard contractual clauses from 16.04.2020 until 27.12.2022 at the latest. However, after the said date, the controller failed to conclude standard contractual clauses** with the processor in the Republic of Serbia, which means that after the said date, the transfer of personal data of the data subjects took place without appropriate safeguards. The processor from the Republic of Serbia could access the entire SAP CRM database with administrative authority, which meant that it had unlimited authority to access personal data (a total of 847,862) of the data subjects/users of the controller's services, i.e. that it could access the following personal data of the users: name and surname, OIB, address from the ID card, connection address, billing address, contact number, email address, IBAN (for users with a contracted SEP direct debit order), MSISDN (telephone number associated with one SIM card), ICCID (serial number identifying each SIM or eSIM card) and data on the contracted services of the users. In addition, the controller did not conduct a Risk Assessment for the transfer of personal data to the Republic of Serbia, which it was obliged to do before the transfer of personal data to a third country began. The above-mentioned actions are contrary to the provisions of Article 44 in conjunction with Article 46(1) of the General Data Protection Regulation. The controller did not even inform the data subjects about the aforementioned transfer to the Republic of Serbia, a country outside the European Economic Area, in accordance with the obligation under Article 13(1)(f) of the General Data Protection Regulation. A review of the privacy policies revealed that the controller did not use clear language to state that the personal data of the data subjects would be transferred outside the EEA, but rather used formulations such as “maybe” that the personal data would be shared with third countries or that personal data would generally be processed within the European Union and only exceptionally outside the European Union, which is contrary to the provisions of Article 12(1) of the General Data Protection Regulation. Furthermore, the controller excessively processed the personal data of its employees, i.e. collected copies of their identity cards, contrary to the provisions of Article 6(1) and in connection with Article 5(1)(c) and (2) of the General Data Protection Regulation. An additional aggravating circumstance is that the controller ignored the opinion of its data protection officer, who issued an opinion that the collection of copies of identity cards, given the content of the data, could be considered excessive processing of personal data (regarding the stated purpose). Similarly, the controller also collected certificates of non-criminal proceedings against its employees, contrary to the provisions of Article 6, paragraph 1, and in connection with this, Article 5, paragraph 1, item (b) and paragraph 2 of the General Data Protection Regulation. Finally, the processor engaged by the controller for the purposes of the telephone sales service did not have even basic protection measures implemented, which the controller was obliged to check before the start of the processing of personal data in accordance with Article 28, paragraph 1 of the General Data Protection Regulation, i.e. the controller did not conduct a prior check of compliance with the protection measures of the processor before its engagement. * The decision imposing the administrative fine is not final. The controller may initiate an administrative dispute before the competent administrative court within 30 days from the date of delivery of the decision. **Since the European Commission has not issued an adequacy decision for the Republic of Serbia within the meaning of Article 45(3) of the General Data Protection Regulation, the controller had to base regular transfers of personal data of the data subjects on one of the transfer instruments referred to in Article 46 (legally binding instruments between public authorities, binding corporate rules, standard contractual clauses, codes of conduct, approved certification mechanism, contractual clauses and provisions from administrative arrangements).




