AZOP (Croatia) - Cookie Consent Violation
| AZOP - Cookie Consent Violation | |
|---|---|
| Authority: | AZOP (Croatia) |
| Jurisdiction: | Croatia |
| Relevant Law: | Article 5(1)(a) GDPR Article 6(1)(a) GDPR Article 7 GDPR Article 13 GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | |
| Decided: | 26.02.2026 |
| Published: | |
| Fine: | 20.000 EUR |
| Parties: | n/a |
| National Case Number/Name: | Cookie Consent Violation |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Croatian |
| Original Source: | AZOP (in HR) |
| Initial Contributor: | RP |
The DPA fined a website provider €20,000 for unlawfully setting cookies on users’ devices before they interacted with the cookie banner and for failing to provide clear, transparent information to data subjects.
English Summary
Facts
The Croatian DPA (AZOP) initiated an ex officio investigation into a company (controller) regarding its handling of personal data collected via cookies on its website.
The investigation revealed that visitors’ personal data were being stored and processed immediately upon visiting the controller's website, even before they had provided informed consent.
The initial cookie banner informed users that cookies would be used but did not allow granular consent for different purposes, combining marketing, analytics, and functional cookies in a single consent interface.
AZOP reviewed the types of cookies, the data collected, and the information provided to users. The controller documented its cookies, their retention periods, and their purposes. The controller later implemented consent management platforms, however, between July 2013 and November 2022, personal data were processed for marketing and statistical purposes.
Holding
AZOP held that the cotroller violated multiple provisions of the GDPR.
First, the controller processed personal data without valid consent, breaching Article 6(1)(a) and Article 7 GDPR because consent must be freely given, informed, specific, and granular. Consent for multiple purposes must be separate and presented clearly, which the controller failed to do. By preloading cookies before consent, the company misled users and deprived them of meaningful choice, making any consent invalid.
Second, the controller's practices violated the principle of fair and transparent processing under Article 5(1)(a) because data collection was automatic, deceptive, and users were not properly informed or given a genuine opt-in.
Third, the controller failed to provide adequate information to users about personal data processing via cookies, contrary to Article 13(1) and Article 13(2), which require clear disclosure of the controller, purposes, types of data, retention periods, and users’ rights.
Consequently, AZOP imposed a fine of €20,000.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Croatian original. Please refer to the Croatian original for more details.
REPUBLIC OF CROATIA
AGENCY FOR PROTECTION
OF PERSONAL DATA
CLASS:
NUMBER:
Zagreb, 26 February 2024
Personal Data Protection Agency (OIB: 28454963989), pursuant to Article 57, paragraph 1,
Article 58, paragraph 1 and 2, item (i) and Article 83 of Regulation (EU) 2016/679 of the European Parliament and of the
Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the
free movement of such data, and repealing Directive 95/46/EC (General
Data Protection Regulation) OJ EU L119, Articles 44, 45 and 46 of the Act on the Implementation of the General
Data Protection Regulation (Official Gazette No. 42/18) and Article 42, paragraphs 1 and 2 and Article 96 of the Act on General Administrative Procedure (Official Gazette No. 47/09, 110/21) in the proceedings initiated ex officio against the controller of the data processing company X (OIB: X), for the protection of personal data,
issues the following
DECISION
1. It is established that the company X, as the controller, collected and processed the personal data of the data subjects
through cookies without enabling the data subjects to give or withdraw their consent to the processing of personal data through cookies in an informed and voluntary manner, in violation of Article 6
Paragraph 1. Point (a) and, in connection with this, Article 7 of the General Data Protection Regulation.
2. It is established that the company X, as the controller, unfairly processed the personal data of the data subjects
through the collection of cookies, which is contrary to Article 5 Paragraph 1. (a) of the General Data Protection Regulation.
3. It is established that company X, as a data controller, did not adequately inform the respondents about
data processing through cookies, which violates Article 13, paragraph 1 and 2 of the General Regulation on
data protection.
4. For the violations described in points 1 - 3 of the operative part of this decision, in accordance with the provisions of Article 83 of the General Data Protection Regulation, an administrative fine shall be imposed on the controller of the company X in the amount of:
EUR 20,000.00
(in words: twenty thousand euros)
The controller of the company X Radnička cesta 34/a, Zagreb is obliged to pay the imposed administrative
fine to the state budget within 15 days from the date of entry into force of this
decision to the account number: HR1210010051863000160, model HR64 and reference number
1 of the approval:_with the indication - "administrative fines imposed by the AZOP".
5. If the controller of the company X does not pay the imposed administrative fine within 15 days of the entry into force of this decision, the Personal Data Protection Agency shall, in accordance with Article 46, paragraph 2 of the Act on the Implementation of the General Data Protection Regulation, notify the Regional Office of the Tax Administration of the Ministry of Finance in whose territory the seat of the said company is located, in order to collect the administrative fine by force in accordance with the regulations on forced tax collection.
6. The controller of the company X is obliged to submit proof of payment to the Personal Data Protection Agency within 15 days of the payment.
R e a s s i n g
I. DETERMINATION OF VIOLATION
The Personal Data Protection Agency (hereinafter referred to as: the Agency) has carried out supervisory activities
ex officio as part of the plan of supervisory checks on the compliance of the content of the websites of business entities from the service sector with the provisions of the General Data Protection Regulation.
Further to the above, and in accordance with the given powers, the Agency initiated an ex officio proceeding due to the risk to the rights and freedoms of the data subjects and, in order to establish the exact and complete factual situation, carried out supervisory activities on the website of the controller of the company X (hereinafter referred to as the controller), namely on the processing of personal data of data subjects/visitors of the website via cookies (cookies - small files that the Internet browser stores on a computer, mobile device or other device used by the data subject to visit the website, thereby remembering and tracking their further actions on the website, and which processing also relates to aspects of personal data) and the obligation to provide information to data subjects on the processing of personal data.
The European Data Protection Supervisor (EDPS) has published the Website Evidence Collector tool under the European Union Public License (EUPL-1.2). The tool is intended for collecting evidence of the processing of personal data on websites such as cookies.
On 29 September 2022, the Agency, using the Website Evidence Collector tool published and approved by the EDPS (The European Data Protection Supervisor), conducted monitoring activities on the website of the controller X and found that there was a notice on the use of cookies (banner) containing: "Cookies On this site, we use cookies. The purpose of the cookies is to improve your user experience and the functionality of the service, for more information, click here. We use the following types of cookies: Necessary cookies that ensure the proper functioning of the site. Other cookies [x ] (opt-out consent options) This includes analytical cookies, cookies for sharing site content on social networks and cookies for displaying targeted ads and content. You can control the use of cookies by using the © icon located in the footer of the page. Save and close."
Furthermore, clicking here opens a document called Privacy Policy, which, among other things, states: “…2. From each visitor to the X website, the following data is collected:
time and date of visit to the website, pages viewed by the visitor, type and version of the Internet browser, IP address of the visitor’s computer, 10. X uses cookies in order to provide its players with a service with full functionality and the highest quality content.
2Cookies are small text files transferred to the visitor’s computer for the purpose of
tracking the use of certain pages. X may use cookies to determine how the pages are used and to identify users who return to the pages. If the player’s computer has turned off cookies, the player can still use the pages, but the functionality of the service will be partially limited. 12. By using the X website, the player confirms that he is at all times familiar with and agrees to these terms of use, including
the provisions on data processing related to cookies.”
Also, the Website Evidence Collector tool has determined the existence of cookies, namely: i18next,
cookietest, cookietest, __lc_cst, __lc_cid, __lc_cst, __lc_cid, _ga_9NRX2EFPNN, _ga, _fbp,
_gcl_au, uid, C, _gid, _gat, _gat_UA-106513-12, __oauth_redirect_detector, _fbp, which are
stored on the terminal equipment of the visitor/user upon initial loading of the page
and the visitors/respondents were not previously informed about it, i.e. did not give their consent, but
the personal data of the visitors/respondents are tacitly processed through cookies.
On October 31, 2022, the Agency requested a statement CLASS: X, NUMBER: X from the controller, namely on the processing of personal data of visitors/respondents via cookies and the obligation to provide information to respondents on the processing of personal data, in relation to the results obtained after the supervisory activities carried out since September 29, 2022 on the controller's website X. Specifically, it was requested to state which group/type of cookies each cookie belongs to, what is the function/purpose of each cookie, how long each cookie is kept, what personal data is processed through these cookies, how visitors/respondents are informed about the purpose of each group/type of cookies, how visitors/respondents can give consent to each group/type of cookies processed through the website, which require the prior consent of the visitor/respondent, and to state the legal basis and purpose for storing cookies that process the personal data of visitors/respondents on their terminal equipment, which require the prior consent of the visitor/respondent.
On 14 November 2022, the Agency received a statement and supporting documentation from the controller, namely on the processing of personal data of visitors/respondents via cookies and the obligation to provide information to respondents on the processing of personal data, which, among other things, states that information on the processing of personal data, which the controller is obliged to make available to respondents in accordance with Article 13 of the General Data Protection Regulation, for the processing of personal data via websites carried out by X is available in the Privacy Policy document published on X. X has no information that personal data of respondents is processed via websites for which the company is the controller without a valid legal basis, i.e. without fulfilling all legally established requirements. Furthermore, it is stated that even before receiving the Agency's letter of 31 October 2022 and independently of it, a review procedure for compliance with the General Data Protection Regulation was initiated, with the expected duration of the review being several months. It is also stated that policy X is to ensure full compliance with
positive regulations governing the protection of personal data in the Republic of Croatia and to provide
users with the highest level of privacy.
Also, the controller has provided a list of cookies and an explanation for each of the listed ones, as
follows: i18next - preferential, determines the preferred language and country setting of the visitor, which
enables the website to display content that is most relevant to the language and region, storage period
1 year, personal data processed - location data, method of informing respondents -
Privacy policy (available on the website), consent of the respondent - the visitor
by initial active selection on the pop-up banner agrees to the use of cookies that are not
mandatory for the functioning of the website, the selection can be changed later by selecting
the appropriate menu on the website, purpose of processing - display of content relevant to the language and
region selected by website visitors; cookietest - functional, used
3se to check whether the user's browser supports cookies, retention period 1 day, personal data
that is processed - user preferences, method of informing the respondent - Privacy Policy
(available on the website), consent of the respondent - not required, purpose of processing - used
to check whether the user's browser supports cookies; cookietest - functional, used
to check whether the user's browser supports cookies, retention period 1 day, personal data
that is processed - user preferences, method of informing the respondent - Privacy Policy
(available on the website), consent of the respondent - not required, purpose of processing - used
to check whether the user's browser supports cookies; __lc_cst - preferential, necessary
for the functioning of the chat-box function of the website, retention period 2 years, personal data
that is processed - user preferences, method of informing the respondents - Privacy Policy
(available on the website), consent of the respondents - the visitor, by initial active
selection on the pop-up banner, agrees to the use of cookies that are not mandatory for the functioning of the
page, the selection can be changed later by selecting the appropriate menu on
the page, purpose of processing - enables the functioning of the chat box; __lc_cid - preferential,
necessary
for the functioning of the chat-box function of the website, retention period 2 years,
personal data thatare processed - user preferences, method of informing respondents - Privacy Policy (available on the website), consent of the respondent - the visitor, by initial active selection on the pop-up banner, agrees to the use of cookies that are not mandatory for the functioning of the site, the selection can be changed later by selecting the appropriate menu on the website, the purpose of processing - enables the functioning of the chat box; __lc_cst -
preferential, is necessary for the functioning of the chat box function of the website, retention period 2 years, personal data that are processed - user preferences, method of informing respondents - Privacy Policy (available on the website), consent of the respondent -
the visitor, by initial active selection on the pop-up banner, agrees to the use of cookies that are not mandatory for the functioning of the site, the selection can be changed later by selecting the appropriate menu on the website, the purpose of processing - enables the functioning of the chat box;
__lc_cid - preferential, necessary for the functioning of the website's chat box function,
retention period 2 years, personal data processed - user preferences, method of informing respondents - Privacy Policy (available on the website), consent of the respondent - by initial active selection on the pop-up banner, the visitor agrees to the use of cookies that are not mandatory for the functioning of the website, the selection can be changed later by selecting the appropriate menu on the website, purpose of processing - enables the functioning of the chat box;_ga_9NRX2EFPNN - statistical, used by Google Analytics to determine
how many times the user has visited the website, including the dates of the first visit and the last
visit, retention period 2 years, personal data processed - activity of the respondent, method of informing respondents - Privacy Policy (available on the website), consent of the respondent - by initial active selection on the pop-up banner, the visitor agrees to the use of cookies that are not mandatory for the functioning of the website, the selection can be changed later subsequently change
by selecting the appropriate menu on the pages, purpose of processing - used by Google
Analytics to determine how many times the user has visited the website, including
the dates of the first visit and the last visit; _ga - statistically, registers a unique identifier that
is used to generate statistical data on how the visitor uses the website,
retention period 2 years, personal data processed - activity of the respondent, method of informing the
respondent - Privacy Policy (available on the website), consent of the respondent -
by the initial active selection on the pop-up banner, the visitor agrees to the use of cookies that
are not mandatory for the functioning of the website, the selection can be subsequently changed by selecting the appropriate menu on the pages, purpose of processing - generation of statistical data on
the way the website is used; _fbp - marketing, used by Facebook to deliver a range of advertising products such as real-time bidding from third-party advertisers, retention period 3 months, personal data processed - preferences of respondents, method of informing respondents - Privacy Policy (available on the website), consent of the respondent - by initial active selection on the pop-up banner, the visitor agrees to the use of cookies that are not mandatory for the functioning of the site, the selection can be changed later by selecting the appropriate menu on the site, purpose of processing - Facebook uses it to deliver a range of advertising products such as real-time bidding from third-party advertisers; _gcl_au
- marketing, used by Google AdSense to experiment with the effectiveness of advertising on websites that use their services, retention period 3 months,
personal data processed - preferences of respondents, method of informing respondents - Privacy Policy (available on the website), consent of the respondent - by initial
active selection on the pop-up banner, the visitor agrees to the use of cookies that are not mandatory for the functioning of the site, the selection can be changed later by selecting the appropriate
menu on the site, purpose of processing - determining the effectiveness of advertising on websites that use Google Ads; uid - marketing, registers a unique user identifier that recognizes the user's browser when visiting websites that use the same advertising network, and the purpose is to optimize the display of ads based on the movement of users and offers from different advertising providers for displaying ads to users, retention period 2 months, personal data processed - activity of the respondent, method of informing the respondent - Privacy Policy (available on the website), consent of the respondent - by initial active selection on the pop-up banner, the visitor agrees to the use of cookies that are not mandatory for the functioning of the site, the selection can be changed later by selecting the appropriate menu on the site, purpose of processing - optimization of ad display and optimization of advertising offers; C - marketing, used to check whether the user's browser supports cookies, retention period 29 days, personal data processed - preferences of the respondents, method of informing the respondents - Privacy Policy (available on the website), consent of the respondents - by initial active selection on the pop-up banner, the visitor agrees to the use of cookies that are not mandatory for the functioning of the site, the selection can be changed later by selecting the appropriate menu on the site, purpose of processing - used to check whether the user's browser supports cookies; _gid - statistical, registers a unique identifier used to generate statistical data on how the visitor uses the website, retention period 1 day, personal data processed - activities of the respondent, method of informing the respondent - Privacy Policy (available on the website), consent of the respondent - by initial active selection on the pop-up banner, the visitor agrees to the use of cookies that are not mandatory for the functioning of the website, the selection can be changed later by selecting the appropriate menu on the website, purpose of processing - registers a unique identifier used to generate statistical data on how the visitor uses the website; _gat, - statistical, used to reduce the request rate in Google Analytics, retention period 1 day, personal data processed - activities of the respondent, method of informing the respondent - Privacy Policy (available on the website), consent of the respondent - by initial active selection on the pop-up banner, the visitor agrees to the use of cookies that are not mandatory for the functioning of the site, the selection can be changed later by selecting the appropriate menu on the site, purpose of processing - limitation of data collection on high-traffic Internet locations; _ga_UA-
106513-12 - statistical, used by Google Analytics to determine how many times the user has visited the website, including the dates of the first visit and the last visit, retention period 2 years, personal data processed - activities of the respondent, method of informing the respondent - Privacy Policy (available on the website), consent of the respondent - the visitor, by initial active selection on the pop-up banner, agrees to the use of cookies that are not mandatory for the functioning of the website, the selection can be changed later by selecting the appropriate menu on the website, purpose of processing - is used by Google Analytics to determine how many times the user has visited the website, including the dates of the first visit and the last visit; __oauth_redirect_detector - preferential, allows for
recognition of visitors for the purpose of optimizing the chat-box function, storage period 1 day, personal
data processed - activities of respondents, method of informing respondents - Privacy Policy
(available on the website), consent of respondents - by initial active
5 selection on the pop-up banner, the visitor agrees to the use of cookies that are not mandatory for the functioning of the
page, the selection can be changed later by selecting the appropriate menu on the
page, purpose of processing - optimization of the chat box function; _fbp - marketing, used by
Facebook to deliver a range of advertising products such as real-time advertising, retention period 3 months, personal data processed - preferences of respondents, method of informing respondents - Privacy Policy (available on the website), consent of the respondent - by initial active selection on the pop-up banner, the visitor agrees to the use of cookies that are not mandatory for the functioning of the site, the selection can be changed later by selecting the appropriate menu on the site, purpose of processing - Facebook uses it to deliver a range of advertising products such as real-time advertising.
On February 1, 2023, the Agency sent a letter CLASS: X, NUMBER: X and requested the controller to provide additional statements and relevant documentation regarding the creation of the website X with content that allows visitors to use the gaming service, i.e. when it was created, since when the notice/banner on the collection of personal data via cookies was placed on the website X, and information on the total number of visitors to the website X from the date of the start of the provision of gaming services through the same website until September 29, 2022. On March 6, 2023, the Agency received a statement and accompanying documentation from the controller, i.e. as requested, which states, among other things, that the website X with content that allows visitors to use the gaming service was launched on March 1, 2023.
July 2013, and the notice/banner on the collection of personal data via cookies was placed
01 June 2018. Likewise, the controller states that the total number of visits to the website
from 01 July 2013 to 29 September 2022 is around 10.9 million visitors.
The following documentation was submitted with the statement: Decision issued by the Ministry of Finance,
CLASS: X, NUMBER: X dated 25.05.2013, screenshot of the printout of turnover based on online
betting from 01.04.2013 to 30.06.2013, screenshot of the printout of turnover based on online
betting on 01.07.2013, display of the computer code with the update of the page containing
the notice/banner on the collection of personal data via cookies and display of the number of visitors in the
period from 01.07.2013. to 29.09.2022.
The submitted documentation was reviewed and from the screenshot of the online betting transaction statement from 01.04.2013 to 30.06.2013 it was determined that there were no transactions in the specified period, and that they only started on 01.07.2013, as can be seen from the screenshot of the online betting transaction statement on 01.07.2013. From the display of the computer code with the update of the page containing the notification/banner on the collection of personal data via cookies, it is visible that the updates were carried out on 01.06.2018, and the total number of visitors in the period from 01.07.2013 to 29.09.2022 is 10.9 million.
On October 11, 2023, the Agency sent a letter CLASS: X, NUMBER: X and requested the controller to provide information and relevant documentation regarding the creation of the website X with content that allows visitors to use the gaming service, i.e. who created it, since when a new notice/banner on the collection of personal data via cookies was placed on the website X, and whether the controller is independent in its business, i.e. whether it makes decisions independently or receives them from another company/group. In accordance with the request, on November 6, 2023 and November 14, 2023, the Agency received the controller's statements and accompanying documentation, which, among other things, stated that the website X with content that allows visitors to use the gaming service was created by the company X from X based on the contract that the controller concluded with the said company, and on November 24, 2022. a new notification/banner about the collection has been posted
6 personal data via cookies on Internet site X (eng. Consent Management Platform -
CMP Cookiebot), while 05.05.2023. implemented CMP Didomi. Furthermore, the data controller
states that it operates independently and does not receive decisions from another company/group.
An inspection was made of the submitted documentation, among other things, of the submitted evidence from which
it is clear that on 24.11.2022 new notification/banner Cookiebot placed and given
05.05.2023. CMP Didomi.
The Agency points out that as of 25 May 2018, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation (OJ EU L119)) has been directly and bindingly applied in all Member States of the European Union, including the Republic of Croatia.
According to Article 4(1)(1) of the General Data Protection Regulation, personal data are all data relating to an identified or identifiable natural person, and an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. According to Article 4(1)(2) of the General Data Protection Regulation, processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Recital (30) of the General Data Protection Regulation states that individuals may be associated with network identifiers provided by their devices, applications, tools and protocols, such as Internet Protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular in combination with unique identifiers and other information received by servers, can be used to create profiles of individuals and identify them.
Article 4(1)(11) defines consent as any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her. Furthermore, the General Data Protection Regulation states in recital (32) that consent should be given by a clear affirmative action by which the data subject signifies his or her free, specific, informed and unambiguous agreement to the processing of personal data relating to him or her, such as a written statement, including electronic, or oral statement. This could include ticking a box when visiting a website, choosing the technical settings of information society services or any other statement or conduct which clearly indicates in that context that the data subject agrees to the proposed processing of his or her personal data. Silence, a pre-ticked box or inaction should therefore not be considered consent. Consent should
cover all processing operations carried out for the same purpose or purposes. Where the processing has
multiple purposes, consent should be given for all of them (i.e. for each one individually, i.e. in relation to each one, the data subject has a choice). If the data subject's consent is to be given following a request made electronically, that request must be clear, concise and must not unnecessarily hinder the use of the service for which it is used.
7The General Data Protection Regulation also states in recital (42) that, where processing is based on the data subject's consent, the controller should be able to demonstrate that the data subject has given consent to the
processing operation. Safeguards, in particular in the context of a written statement on another matter,
should ensure that the data subject is aware of the fact that he or she is giving consent and to what extent it is being given. In accordance with Council Directive 93/13/EEC on unfair terms in consumer contracts, a statement of consent drawn up in advance by the controller should be offered in an intelligible and easily accessible form, using clear and plain language and should not contain unfair terms. In order to give informed consent, the data subject should at least be aware of the identity of the controller and the purposes of the processing for which the personal data are used. Consent cannot be considered to be freely given if the data subject does not have a genuine and free choice or if he or she is not able to refuse or withdraw consent without consequences. Similarly, recital (43) states that consent is not freely given if it does not allow for the giving of separate consent for different processing operations, despite being appropriate in the individual case, or if the performance of a contract, including the provision of a service, depends on consent and such consent is not necessary for such performance. Article 6(1) of the General Data Protection Regulation provides that processing is lawful only if and to the extent that at least one of the following is met:
(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
(b) the processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
(c) the processing is necessary for compliance with a legal obligation to which the controller is subject;
(d) the processing is necessary to protect the vital interests of the data subject or of another natural person;
(e) the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
(f) the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child.
Article 7 requires that where processing is based on consent, the controller must be able to demonstrate that the data subject has given his or her consent to the processing of his or her personal data. If the data subject gives consent in a written statement that also covers other matters, the request for consent must be presented in a manner that can be clearly distinguished from other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a statement that constitutes a breach of this Regulation shall not be binding. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. The data subject shall be informed of this before giving consent. Withdrawing consent shall be as simple as giving it. When assessing whether consent was voluntary, the greatest possible consideration shall be given to whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data which is not necessary for the performance of that contract.
Article 13(1) of the GDPR requires the controller to provide the data subject, at the time of collection of personal data, with all of the following information:
(a) the identity and contact details of the controller and, where applicable, of the controller's representative;
(b) the contact details of the data protection officer, where applicable;
(c) the purposes of the processing for which the personal data are used and the legal basis for the processing;
(d) where the processing is based on Article 6(1)(f), the legitimate interests of the controller or of a third party;
(e) the recipients or categories of recipients of the personal data, if any; and
8(f) where applicable, the fact that the controller intends to transfer the personal data to a third
country or an international organisation and the existence or absence of a Commission decision on adequacy, or in the case of transfers referred to in Articles 46 or 47 or the second subparagraph of Article 49(1), a reference to the appropriate or appropriate safeguards and the means of obtaining a copy of them or the place where they are made available.
Paragraph 2 of the same Article stipulates that the controller shall provide the data subject with additional information necessary to ensure fair and transparent processing:
(a) the period for which the personal data will be stored or, where that is not possible, the criteria for determining that period;
(b) the existence of the right to obtain from the controller access to and rectification or erasure of personal data concerning the data subject or restriction of processing, or the right to object to the processing of such data and the right to data portability;
(c) where the processing is based on Article 6(1)(a) or Article 9(2)(a),
the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
(d) the right to lodge a complaint with a supervisory authority;
(e) information on whether the provision of personal data is a legal or contractual obligation or a condition for entering into a contract and whether the data subject is obliged to provide personal data and what the consequences are if such data are not provided;
(f) the existence of automated decision-making, including profiling referred to in Article 22(1) and (4) and, at least in such cases, meaningful information on the logic involved and the significance and envisaged consequences of such processing for the data subject.
In accordance with recital (60) of the General Data Protection Regulation, which refers to Article 13 of the General Data Protection Regulation, the controller is obliged to inform the data subject of the processing operation and its purposes and should provide the data subject with any additional information necessary to ensure fair and transparent processing.
Article 43, paragraph 4 of the Electronic Communications Act (Official Gazette, 76/22)
prescribes the following: "The use of electronic communications networks for storing data or for accessing data already stored in the terminal equipment of the end user or user
shall be permitted only in cases where the end user or user has given his consent, after having received clear and complete information in accordance with the regulations on the protection of personal data, in particular on the purposes of data processing. This shall not prevent the technical storage of data or access to data solely for the purpose of carrying out the transmission of communications via an electronic communications network, or, if necessary, for the purpose of providing information society services at the express request of the end user or user".
During the supervisory activities, it was established that the controller, in the period from 01.07.2013. until
24.11.2022., processed the personal data of the respondents for statistical and marketing purposes, and without
requesting consent for the processing of personal data for purposes that are not necessary for the proper functioning of the website.
In this administrative matter, it was also established (via the EDPS tool mentioned above) that
the controller, even before the respondents gave their consent to the collection of cookies, stored them on the user's terminal equipment at the moment of the initial loading of the page, and thus the personal data of the respondents were
collected. This means that the personal data of the respondents were processed at the very moment of loading the website, while they had not yet given their consent to the collection of individual cookies, which was unfair, since the respondents did not even know
that their personal data, which was collected in a covert manner in the manner just
described, was already being collected at the moment of accessing the website. Therefore, the controller used
9 a misleading web interface that created the illusion among the data subjects that their personal data
would be collected via cookies only after consent to the processing of cookies was given, while the truth was
the opposite. The described method resulted in the unfair processing of the data subjects' personal data, which is
contrary to the fundamental principle of personal data protection, namely the principle of lawful, fair and
transparent processing of personal data from Article 5(1) of the General Data Protection Regulation.
In the described case, consent as the applicable legal basis for the processing of personal data from
Article 6(1)(a) did not meet the legal requirements for validity from Article 7
of the General Data Protection Regulation. Namely, consent in situations where the processing of personal data based on the same has multiple purposes (e.g. marketing, analysis/statistics), then the text of the consent (in this case the so-called cookie banner - the initial cookie notice) must be presented in a way that it can be clearly distinguished from other questions (purposes), in an understandable and easily accessible form using clear and plain language. Any part of the statement that is not presented in such a way is not binding. If the controller has combined several purposes for processing, and has not attempted to request separate consent for each purpose, then the consent is not voluntary. Separating the purposes of the consent achieves its granularity, which ultimately allows the data subjects to control the processing of their personal data and provides them with transparency in terms of reviewing all the purposes for which their personal data will be processed. Failure to comply with the conditions of granularity and informed consent ultimately cannot be voluntary and does not meet the legal prerequisites for validity under Article 7 of the General Data Protection Regulation. Since in the specific
case the controller did not separate the so-called cookie banner and enable the respondents to clearly
give their consent for different purposes (marketing, analytics/statistics), it is clear that the consent did not
satisfy the above-mentioned legal prerequisites and that it is therefore not valid as a legal
basis from Article 6, paragraph 1, item (a) of the General Data Protection Regulation. In the mentioned way
there was a violation of the provisions of Article 6, paragraph 1, item (a) and in connection with this Article 7 of the General Data Protection Regulation.
Furthermore, in the specific case the controller stated that the visitors/respondents were
informed about the processing of personal data via cookies for the aforementioned period in the
Privacy Policy document.
Upon review of the PRIVACY POLICY document, it was determined that it is general and does not contain
information on the legal basis, groups/types of cookies, function/purpose of each cookie,
the storage period of cookies, a violation of Article 13, paragraphs 1 and 2 of the General Data Protection Regulation
was determined.
In conclusion, it was determined that after the letter sent on 11.10.2023 by
the Agency, in its response dated 06.11.2023 and 14.11.2023, the controller stated that on
24.11.2022 a new notice/banner was placed on the page regarding the collection of personal data through cookies
on the website X (CMP Cookiebot), while on 05.05.2023 CMP Didomi was implemented and
evidence was provided showing that on 24.11.2022. new
notice/banner Cookiebot and on 05.05.2023. CMP Didomi.
II. DETERMINATION OF ADMINISTRATIVE FINES
Article 44 of the Act on the Implementation of the General Data Protection Regulation stipulates that the Agency shall impose
administrative fines for violations of the provisions of this Act and the General Data Protection Regulation,
in accordance with Article 83 of the General Data Protection Regulation.
Article 45, paragraph 1 of the aforementioned Act stipulates that administrative fines shall be imposed
by decision. Pursuant to paragraph 2 of the same article, the decision shall determine the amount and manner of payment of the administrative
10fine. The decision may determine that the administrative fine shall be paid in installments.
Pursuant to paragraph 4 of the same article, no appeal is permitted against the decision, but an
administrative dispute may be initiated before the competent administrative court.
Pursuant to Article 46 of the same Act, an administrative fine shall be paid within 15 days from the date of the decision imposing it. If the party fails to pay the administrative fine within the prescribed period, or upon the maturity of the last installment if payment by installments has been approved, the Agency shall notify the Regional Office of the Tax Administration of the Ministry of Finance in whose territory the party to whom the administrative fine was imposed has its residence or registered office, in order to collect the administrative fine by force in accordance with the regulations on forced tax collection. Administrative fines shall be paid to the state budget. By way of exception to paragraph 2 of this Article, no interest shall be calculated on a due but unpaid administrative fine. Given the established circumstances in this specific case, the Agency, in accordance with its powers under Article 58, paragraph 2, item (i) of the General Data Protection Regulation, imposed an administrative fine instead of other corrective measures under the relevant article, all in accordance with the conditions for its imposition under Article 83 of the General Data Protection Regulation and Articles 44, 45 and 46 of the Act Implementing the General Data Protection Regulation. After a detailed examination of the available remedies referred to in Article 58(2) of the General Data Protection Regulation, which the supervisory authority is empowered to impose on the controller and/or processor in the event of an infringement of the provisions of the General Data Protection Regulation, and having assessed all the circumstances of the case, in particular that the chosen remedy must be effective, proportionate and dissuasive in each individual case, the Agency has decided to impose an administrative fine, paying due regard to the criteria laid down in Article 83(2) of the General Data Protection Regulation. Namely, Article 83(1) of the General Data Protection Regulation requires each supervisory authority to ensure that the imposition of administrative fines in accordance with this Article in respect of infringements of paragraphs 4, 5 and 6 of this Regulation is effective, proportionate and dissuasive in each individual case. The Agency considers that the amount of the imposed administrative fine cannot be effective if it does not have a significant impact on the controller's income, the principle of proportionality cannot be maintained if the infringement is considered in the abstract without regard to the impact on the controller or processor, and it should also be a deterrent to future infringements. Therefore, the imposed administrative fine cannot be a deterrent if it does not have a financial impact on the controller in question.
The imposition of an administrative fine is also intended to ensure compliance with the rules on personal data protection by both the controller and all other controllers/processors who process personal data in the same way. The imposition of an administrative fine should have a general deterrent effect (to discourage others from repeating the same infringement in the future) as well as a specific deterrent effect (to discourage the addressee of the administrative fine from repeating the same infringements).
Pursuant to Article 83(2) of the General Data Protection Regulation, administrative fines shall be imposed in addition to or instead of the measures referred to in Article 58(2)(a) to (h) and Article 58(2)(j), depending on the circumstances of each individual case. When deciding whether to impose an administrative fine and when determining the amount of the administrative fine in each case, due regard shall be paid to the following:
(a) the nature, gravity and duration of the infringement, taking into account the nature, scope and purposes of the processing concerned as well as the number of data subjects and the level of damage suffered by them;
(b) whether the infringement was intentional or negligent;
11(c) any action taken by the controller or processor to mitigate the damage suffered by data subjects;
(d) the level of responsibility of the controller or processor, taking into account the technical and organisational measures implemented by them in accordance with Articles 25 and 32;
(e) any relevant previous infringements by the controller or processor;
(f) the degree of cooperation with the supervisory authority to remedy the infringement and mitigate the potential harmful effects of the infringement;
(g) the categories of personal data affected by the infringement;
(h) the manner in which the supervisory authority became aware of the breach, in particular whether and to what extent the controller or processor reported the breach;
(i) where measures referred to in Article 58(2) have previously been imposed on the controller or processor concerned in relation to the same matter, compliance with those measures;
(j) compliance with approved codes of conduct in accordance with Article 40 or approved certification mechanisms in accordance with Article 42; and
(k) any other aggravating or mitigating factors applicable to the circumstances of the case,
such as the financial gain gained from the breach or the losses avoided, directly or indirectly, by the breach.
Article 83(5) of the General Data Protection Regulation provides that administrative fines of up to EUR 20,000,000 or, in the case of an undertaking, up to 4% of the total worldwide annual turnover in the preceding financial year may be imposed for infringements of the obligations of the controller and processor in accordance with Articles 6(1), 7, and 13(1) and (2) of the General Data Protection Regulation.
An inspection of the court register determined that the total annual turnover of the controller X based on the financial report for 2022 is 287,749,207.00 kn = 38,190,882.87 EUR, and 4% of that amount is 1,527,635.31 EUR, or less than 20,000,000.00 EUR, or the amount that represents the upper limit for imposing an administrative fine in this specific case. Due to the violation of Article 6, paragraph 1, Article 7, and Article 13, paragraphs 1 and 2, of the General Data Protection Regulation, the Agency imposed an administrative fine of 20,000.00 EUR on the controller X, which is 0.1% of the maximum amount of the administrative fine that the Agency could or was authorized to impose in this specific case.
Pursuant to Article 83(2) of the General Data Protection Regulation, when deciding on the imposition of an administrative fine and deciding on the amount of the administrative fine, the Agency has paid due attention to the following in this case:
- The nature, gravity and duration of the infringement, taking into account the nature, scope and purpose of the processing in question
as well as the number of data subjects and the level of harm suffered by them (Article 83(2)(a);
In accordance with the Guidelines of the Article 29 Working Party on the application and setting of administrative fines for the purposes of Regulation 2016/679 of 3 October 2017 (WP 253), which the European Data Protection Board endorsed at its first plenary session on 25 May 2018,
the gravity of the infringement may be not only the nature of the infringement, but also the scope, purpose of the processing in question, as well as the number of data subjects and the level of harm suffered by them.
In this administrative matter, it was established that the controller collected and processed personal data of visitors/respondents via cookies without a legal basis from 01.07.2013 to 24.11.2022 via the website X. Since the General Data Protection Regulation has been directly and bindingly applicable since 25 May 2018, the Agency, in accordance with the principle of non-retroactive application of regulations, took the aforementioned date into account as the date of the beginning of the violation, and the incriminated period of the violation was from 25.05.2018 to 24.11.2022. Furthermore, the controller did not inform the respondents about the processing in question in accordance with the principle of transparency, and in this way the respondents were deprived of information about the processing of data, such as the legal basis, the function/purpose of each cookie, and the storage period of cookies. Additionally, when determining the penalty, it was taken into account that the processing in question does not constitute the core activity of the controller.
- Whether the infringement is intentional or negligent (Article 83(2)(b);
The Article 29 Working Party states in its Guidelines on the application and setting of administrative fines for the purposes of Regulation 2016/679 of 3 October 2017 (WP 253), which the European Data Protection Board endorsed at its first plenary session on 25 May 2018, that “intention” generally includes knowledge and intent regarding the characteristics of the infringement, while “unintentional” means that there was no intention to cause the infringement even though the controller/processor breached its duty of care prescribed by law. The same Guidelines therefore highlight the distinction between circumstances that are indicative of or “intentional infringements” and those that are indicative of infringements that are caused “unintentionally” or “negligently”. In this regard, the Guidelines mention “failure to adopt policies” and “human error” as examples of conduct that may indicate negligence.
Given that the controller had posted an incomplete notice on cookies on its website in the Privacy Policy and PRIVACY POLICY documents, which provided general instructions to the data subjects regarding cookies, the Agency considered that the case in question was one of negligence.
- Any action taken by the controller or processor to mitigate the damage suffered by the data subjects (Article 83, paragraph 2, point c);
Given that in the case in question it was not established that the data subjects suffered damage, the same circumstance was not assessed as either mitigating or aggravating.
- The degree of responsibility of the controller or processor, taking into account the technical and
organizational measures implemented in accordance with Articles 25 and 32 (Article 83, paragraph 2, point d);
As a mitigating circumstance, when imposing an administrative fine, the Agency particularly appreciated the degree of responsibility demonstrated by the controller following the supervisory activities carried out by the Agency. After requesting a statement from the Agency, the controller immediately took action to correct the observed situation and, after an additional letter from the Agency dated 11 October 2023, the controller provided a statement on 6 November 2023 and 14 November 2023, providing evidence that a new notice/banner on the collection of personal data via cookies was placed on the website X (CMP Cookiebot) on 24 November 2022, while the CMP Didomi was implemented on 05 May 2023. - Relevant previous violations by the controller or processor (Article 83, paragraph 2, item e); The Agency has not identified any previous relevant violations of data protection provisions by the controller.
- The degree of cooperation with the supervisory authority to remedy the breach and mitigate the possible adverse effects of the breach (Article 83(2)(f);
The controller has responded appropriately to the requests of the supervisory authority during this administrative procedure.
- The categories of personal data affected by the breach (Article 83(2)(g);
The case in question does not concern special categories of personal data referred to in Article 9 or Article 10 of the GDPR, nor sensitive categories of personal data which, by virtue of the context and scope of the processing, are likely to result in a high risk to the rights and freedoms of data subjects.
- The manner in which the supervisory authority became aware of the breach, in particular whether and to what extent the controller or processor reported the breach (Article 83(2)(h);
The supervisory authority became aware of the infringement in question acting ex officio as part of the implementation of a plan of supervisory checks on the compliance of the content of websites of business entities in the service sector with the provisions of the General Data Protection Regulation for the purpose of monitoring the application of the provisions of the General Data Protection Regulation.
- If measures referred to in Article 58(2) have previously been imposed on the controller or processor in relation to the same matter, compliance with those measures (Article 83(2)(i);
The controller has not previously been subject to a measure referred to in Article 58(2) of the General Data Protection Regulation.
- Compliance with approved codes of conduct in accordance with Article 40 or approved certification mechanisms in accordance with Article 42 (Article 83(2)(j);
Not applicable in the present case.
- Any other aggravating or mitigating factors applicable to the circumstances of the case, such as the financial gain gained from the infringement or the losses avoided, directly or indirectly, through that infringement (Article 83(2)(k); When determining the amount of the administrative fine, the Agency has not identified any other relevant circumstances that should be considered aggravating or mitigating. A fine can be considered effective if it achieves the objectives for which it was imposed. This may be to restore compliance, to punish unlawful conduct or both. The Agency considers that imposing it will lead to the controller fulfilling its obligations in the field of personal data protection in a timely and appropriate manner in the future. The Agency conducted the investigation in accordance with Articles 51 and 52 of the General Administrative Procedure Act and in accordance with all principles of administrative procedure prescribed by the General Administrative Procedure Act, correctly established the factual situation and, based on the established factual situation, correctly applied substantive law and drew a correct conclusion on the factual situation in the specific case. It bases its decision on all relevant evidence and facts at its disposal and submitted as evidence by the controller.
Equally, taking into account all of the above, the Agency believes that the corrective measure in the form of an administrative fine is effective, proportionate and dissuasive in this administrative matter and that its amount is fully appropriate to the circumstances of the specific case.
Based on all of the above, it was decided as in the Operative Part of the Decision.
14 INSTRUCTIONS ON LEGAL REMEDY
No appeal is allowed against this decision, but an administrative dispute may be initiated before
the Administrative Court in X within 30 days from the date of delivery of the decision.
SUBMIT:
1. X
2. Filing, here
15




