US Rijeka - Us I-2520/2025-14

From GDPRhub
US Rijeka - Us I-2520/2025-14
Court: US Rijeka (Croatia)
Jurisdiction: Croatia
Relevant Law: Article 6(1)(c) GDPR
Article 6(1)(f) GDPR
Article 9(2)(f) GDPR
Article 15 GDPR
Article 26 GDPR
Decided: 07.05.2026
Published: 27.05.2026
Parties: HEP Proizvodnja d.o.o.
AZOP (Croatia)
National Case Number/Name: Us I-2520/2025-14
European Case Law Identifier:
Appeal from: AZOP (Croatia)
UP/I-009-01/25-07/6
Appeal to: Unknown
Original Language(s): Croatian
Original Source: Tražilica odluka sudova RH (in Croatian)
Initial Contributor: ds

A court held that an electricity provider lawfully accessed an employee’s data stored on a device after a security incident affecting a hydroelectric plant led to an internal investigation. The protection of infrastructure justified the processing of sensitive data.

English Summary

Facts

The data subject was employed by HEP Proizvodnja d.o.o., an electricity and heat generation provider (the controller), at one of its hydroelectric plants. Their work involved the maintenance of computer systems. Their employment was later terminated in April 2022.

While the data subject was on sick leave, one of the computers located in their office stopped functioning. The data subject claimed that, because of this malfunction, they came to the workplace, disconnected and rearranged some equipment, and then left. According to the data subject, their office contained both work-related and private computer equipment, including devices and hard drives on which their personal data and the personal data of third parties were stored.

The controller stated that the engineering workstation located in the office used by the data subject had lost its uninterrupted power supply due to equipment failure. It was necessary to turn it on and log in so that business processes could continue uninterrupted. The controller further claimed that the data subject appeared at the workplace despite warnings from their superiors that their presence was not needed, entered their workspace, attempted to tamper with the equipment and prevented other colleagues from accessing the computer data.

The controller launched an internal investigation for the security incident. The controller stated that the processing of the data subject’s data was carried out by its Corporate Security Office and was necessary to maintain operational continuity and security of the facility.

The data subject filed a complaint with the Croatian DPA. They claimed that, during the investigation, the controller unlawfully accessed and processed their personal data, including data stored on several computers and hard drives. They argued that some of the data stored there were private, that special categories of personal data were processed, and that the controller could tell from the names of certain files, before opening them, that they contained personal data.

The controller argued that the equipment had been accessed because of a security incident affecting an engineering workstation forming part of the hydroelectric plant’s system. It claimed that the workstation was company property and that the data subject had, without authorisation, installed and removed hardware and changed passwords. The controller also alleged that the data subject had stored and sent a work project through a public network, which created a security risk. In addition, it alleged that files of a pornographic and erotic nature were found on a disk connected to the workstation during the technical and security review.

The DPA rejected the complaint. It considered that the processing could not be assessed separately from the reason why the equipment had been removed. The equipment had been taken for an internal investigation into possible misconduct following a security incident in the workplace. According to the DPA, any personal data found on the equipment were accessed incidentally, since the controller could not know in advance whether the devices contained the data subject’s personal data, how much data they contained, or what categories of data were involved.

The DPA also referred to Recital 20 in the context of the controller’s use of the data for evidence in legal proceedings. It found no violation of the data subject’s rights, noting that the controller had not forwarded the data to third parties or misused them. The DPA stated that the amount and categories of personal data, as well as the alleged involvement of more than one controller, were irrelevant in this case.

The data subject challenged the DPA’s decision before the Administrative Court of Rijeka.

The data subject argued that they had the right to access their personal data and that the controller could not deny this right based solely on an assumption about what they intended to do with the personal data once received. They also stated that the DPA had misapplied Recital 20, as there was no conflict of jurisdiction involved. They also alleged that, since more than one entity had been involved in the processing, the DPA should have examined whether the relationship between them had to be regulated under Article 26 or Article 28 GDPR. Additionally, the data subject considered that Article 9(2)(b) GDPR had been misinterpreted, as the conditions specified therein could not be met since, under Article 9(1) GDPR, the processing of special categories of personal data is prohibited. Moreover, the data subject claimed that Article 9(2)(f) GDPR did not provide a basis for an internal investigation, because an employer could not process data based on an assumption that it might be needed for legal defence.

Holding

The Court noted that the controller’s actions were not aimed at processing the data subject’s personal data, but at resolving a technical malfunction. It emphasised that the computer and hard drives were located in the controller’s business premises and were connected to a workstation used by the data subject. Accordingly, it pointed out that there was no reason to assume in advance that the devices would contain the data subject’s personal data. The Court held that the processing was carried out in order to prevent damage to the controller’s computers and electronic communication systems, in accordance with Recital 49.

The Court further held that the proportionality test was satisfied. The processing was limited to data contained in equipment located in the data subject’s workplace and relevant to the production process and the security incident.

The Court also took into account that pornographic, erotic and entertainment files were found on a hard drive connected to the workstation. It considered that such content could reasonably be viewed as posing a risk to the functioning of the controller’s systems.

The Court held that the processing was lawful under Article 6(1)(f) GDPR, since it was necessary for the controller’s legitimate interest in ensuring the functioning of the hydroelectric plant. Additionally, the Court referred to Article 6(1)(c) GDPR, considering the controller’s legal obligations regarding the security and operation of energy infrastructure in the Republic of Croatia.

The court further held that the internal investigation was necessary for the exercise or defence of legal claims and in accordance with the controller’s public-interest duties to protect the network and infrastructure. Therefore, it ruled that the controller could rely on Article 9(2)(f) GDPR regarding the processing of special categories of personal data.

The Court also rejected the data subject’s argument that several controllers or processors were involved. It accepted that the Corporate Security Office was an internal division within the controller’s corporate group and had conducted the investigation on behalf of the controller. Therefore, there was no need for a separate arrangement between controllers under Article 26 GDPR.

The Court noted that a controller is generally required to provide a data subject with access to their personal data so that the data subject can be aware of the processing and verify its lawfulness, pursuant to Article 15 GDPR. However, it agreed that the request had to be assessed in light of the controller’s rights and obligations to protect its information and business systems. The court held that the granting of access to the data subject would jeopardize its legitimate interests.

The Court dismissed the data subject’s appeal and upheld the DPA’s decision.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Croatian original. Please refer to the Croatian original for more details.

REPUBLIC OF CROATIAADMINISTRATIVE COURT IN RIJEKA[address] Ć 5Registration number: Us I-2520/2025-14IN THE REPUBLIC OF CROATIAJUDGMENTThe Administrative Court in Rijeka, presided over by Judge Marija Renner Jakovljević, with the participation of the recorder Mirjana Jakić, in the administrative dispute of the plaintiff ĆN from [address], OIB: [personal identification number], represented by the authorized representative Danijel Jurić, lawyer in Rijeka, Andrije Medulića 4, against the defendant Agency for the Protection of Personal Data, Zagreb, Ulica Metela Ožegovića 16, OIB: 28454963989, with the participation of the interested person HEP-Proizvodnja d.o.o., Zagreb, Ulica grada Vukovara 37, OIB: 09518585073, represented by the official AN, for the protection of personal data, May 7, 2026, judgment I. The claim is rejected to annul the decision of the Personal Data Protection Agency CLASS: UP/I-009-01/25-07/6, REGULATION NUMBER: 567-04-02/05-01 of September 30, 2025 and to return the case to the defendant for retrial. II. The plaintiff's request for reimbursement of the costs of this dispute is rejected. III. The interested party's request for reimbursement of the costs of the administrative dispute in the form of court fees is rejected. Reasoning 1. The contested decision of the defendant CLASS: UP/I-009-01/25-07/6, REGULATION NUMBER: 567-04-02/05-01 of September 30, 2025, rejected as unfounded the request for establishing a violation of the plaintiff's right to protection of personal data. 2. The plaintiff disputes the legality of the defendant's decision and claims, in essence, the following. The defendant has incompletely established the factual situation because it has not examined the evidence submitted by the plaintiff in its request and subsequent amendments to the request. Furthermore, it believes that the contested decision incorrectly applied substantive law and that the defendant, despite the submitted documentation and well-founded arguments, made the wrong decision on the request in question and the plaintiff's complaints. The plaintiff sees formal shortcomings in the failure to act according to the formal procedure that the defendant had to carry out on the basis of the request in question. The plaintiff points out that he filed his claim against the defendant in accordance with Article 77(1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter: the Regulation) due to a series of unlawful processing of the plaintiff's personal data carried out by his former employer HEP-Proizvodnja d.o.o., and third parties engaged by the former employer. He also states that the subject of the processing is personal data belonging to the plaintiff, which were located on 15 hard drives (from 3 computers and 12 separate hard drives). The plaintiff believes that the defendant, despite repeatedly pointing out the illegalities committed in the processing of data, has not taken the necessary measures to protect his rights available to him in accordance with the Regulation. In relation to the factual substratum, the plaintiff states that he was a long-time employee of HEP-Proizvodnja d.o.o., that he worked at the GHE Vinodol location in Tribalj, and his job (and private activity outside the workplace) included, among other things, maintaining the process system computers. Because of this, he points out, his workplace contained a large amount of official and private computer equipment on which his personal data and the personal data of third parties not related to the employer were located. He states that during his sick leave, one of the computers in his workplace, which the employer calls the "engineering workstation" (hereinafter: IRS), stopped working without his influence, which is why the plaintiff came to his workplace, noticed the malfunction, disconnected and turned off the computers that were not working or should not be working, rearranged the equipment and left his workplace. After that, the plaintiff alleges, his employer established an IRS at another location that was completely independent of the plaintiff's equipment, after which the plaintiff was accused of sabotaging the IRS and an internal investigation was initiated, based on which all computer equipment (both private and official) was removed from his workplace and his personal data and the personal data of third parties were processed without his knowledge, of which he was unaware, nor the amount of equipment and personal data removed, nor who and when transferred that equipment and personal data, nor to which controller or what types of personal data processing were carried out. Furthermore, he alleges that in April 2022 he was served with a termination of his employment contract, referring to the unlawful processing of the plaintiff's personal data, and that he only later learned about the processing carried out and the perpetrators of that processing in court proceedings. Therefore, he filed a complaint (and a request for a declaration of violation of rights) with the knowledge he had at that time. Furthermore, he states that he submitted three additional statements, two new requests for the determination of a violation of rights, an amendment to one request, an objection to the defendant's conduct and a request for the separation of the case. The plaintiff believes that none of the three computers processed is an IRS, that it is not prohibited to keep personal data on official computers, that special categories of personal data were processed (the processing of which is strictly prohibited in accordance with Article 9, paragraph 1 of the Regulation). He also states that the name of the file, the name of which is explicitly stated, makes it clear that it is personal data and that the controller knew from the file name before processing that he was reviewing personal data and that he nevertheless processed them. Therefore, he believes that the personal data processing carried out is unlawful because the data was not collected lawfully, fairly and transparently, that it was not limited to what is necessary, that it was not collected for a purpose, and the sole purpose of the controller is to investigate the misuse of the IRS by which the processing was carried out. Therefore, complaints were sent to the defendant based on Article 77, paragraph 1 of the Regulation - requests for establishing a violation of rights, that is, requests for initiating administrative misdemeanor proceedings by establishing a violation of the right to protection of personal data. He also considers it disputable that a statement was requested on the processing of only one computer, despite the fact that the request stated that three computers and various private and official media with personal data for which his data was unlawfully processed were removed from his office. Given that the defendant received a request for establishing a violation of rights due to unlawful processing of personal data involving two data controllers, the plaintiff believes that the defendant was obliged to establish their mutual contractual relationship regulating the processing in accordance with Article 26 or 28 of the Regulation in order to establish the material truth, which he failed to do. Furthermore, the plaintiff considers it questionable to establish the inadmissibility of the entire case on the basis of the assumption of what the plaintiff intends to do with his personal data once he receives them and considers that he has the right to access his personal data, and the defendant is not entitled to deny him that right on the basis of a mere assumption of what the plaintiff could do with those data. Furthermore, the plaintiff considers that in the contested decision the defendant has incorrectly applied recital (20) of the Regulation because it does not create an obstacle to the independent conduct of this case and the proceedings in court because there is no conflict of jurisdiction. Furthermore, he considers that I have misinterpreted Article 9(2)(b) of the Regulation because the conditions prescribed therein, specifically the third condition, cannot be met because, in accordance with Article 9(1) of the Regulation, the processing of special categories of personal data is prohibited. Furthermore, he considers that Article 9(2)(f) of the Regulation is not a basis for an internal investigation, since an employer may not process data in the hope that it may need it and then, when a dispute arises, claim that it was necessary to defend a legal claim. In light of the above, the plaintiff proposes that the Court annul the contested decision of the defendant and return the case to the defendant for retrial. The plaintiff claims compensation for the costs of this dispute.3. The defendant states in its response to the lawsuit that the allegations in the lawsuit are unfounded for the following reasons. The defendant acted in this matter in accordance with the principles of the General Administrative Procedure Act ("Official Gazette", No. 47/09. and 110/21., hereinafter: the ZUP) including respect for the principle of establishing the material truth and the principle of independence and free assessment of evidence. It emphasizes that the principle of free assessment of evidence as stated in Article 9 of the ZUP requires that an official independently assess the facts in the proceedings based on a conscientious assessment of individual evidence and the evidence as a whole. Furthermore, it states that the factual situation in this administrative matter was established on the basis of the parties' statements and evidence, whereby the scope of the submitted documentation and the detailed and exhaustively described chronology of events in the case in question were sufficient to establish all relevant facts, which is why the defendant removes the allegation of failure to supervise the data processors, which suggests that the defendant did not collect evidence that would support the illegality of the processing and the violation of the plaintiff's right to the protection of personal data. It also considers that in this case it is an undeniable fact that between the plaintiff (as a former employee) and the data processor (former employer) there is a whole series of disputes, mutual accusations and proceedings in relation to violations of rights and obligations arising from the employment relationship, including the commission of criminal offences. In this regard, it states that the disposal of personal data by the data processor (employer) located on computers (employer's equipment) cannot be viewed in isolation and separately from the purpose for which the computer was seized, so that the employee would have the right to the protection of personal data. Namely, it states that in this case the computer was seized from the employee for the purpose of conducting an internal investigation and collecting evidence that may indicate his wrongful conduct within the framework of the employment relationship, and that the purpose and intention of the employer is not to process his personal data. Therefore, if in such circumstances the collection/processing of personal data occurs as a result of the seizure of the computer from the employee, such processing is essentially accidental and incidental because the employer does not know and cannot know in advance whether the employee's personal data is on the computer in question and what quantity and category of personal data it is.Therefore, the defendant believes that it is important to note that in the case of the exclusion/further use of the “found” personal data of employees by the employer, this is a legitimate use, and for the purpose of proving it in a specific (judicial) procedure. In this regard, the defendant referred to provision (20) of the General Data Protection Regulation (the introductory part of the Regulation). He further states that in this case there could be no question of a violation of the right to protection of the employees’ personal data guaranteed by the Regulation, because he did not forward them or make them available to third parties or misuse them, which is why the defendant assessed that there was no unlawful conduct or violation of the right to protection of personal data to the detriment of the plaintiff. Therefore, he believes, and bearing in mind the above, that in this administrative matter the quantity and categories of personal data, to which the plaintiff refers on several occasions, are irrelevant, as is the number of data controllers. In conclusion, it states that the substantive law was correctly applied in this matter and that the relevant provisions of the Regulation according to which the processing of personal data is lawful, as well as the exemption from the processing of personal data by the competent judicial authorities, have been clarified, all in the context of the specific case. Accordingly, it proposes that the Court reject the claim as unfounded.4. In its response to the claim regarding the factual substratum of this administrative matter, the interested party states that on December 2, 2021, a security incident occurred at the Vinodol Hydroelectric Power Plant (GHE Vinodol), in the part of the interested party. Namely, the engineering workstation (IRS) located in the office used by the plaintiff was left without continuous power supply due to an equipment failure and it was necessary to turn it on and log in so that business processes could proceed smoothly. At that moment, it states, the plaintiff was on sick leave and despite warnings from his superiors that he did not need to come to the work location, he nevertheless appeared and entered the workspace used (office) where the IRS was located. He further states that during that entry into the workplace, the plaintiff attempted to manipulate the equipment and did not allow other colleagues to access the computer data on the IRS. Incidentally, he states that it is not true that the hard drive from the IRS is the plaintiff's private property, since the IRS was entirely owned by the interested party, acquired as part of the hydroelectric power plant management system. Moreover, the plaintiff arbitrarily, without authorization, inserted and removed hardware from the IRS, as well as changed the access password. In addition, he stored and sent the entire official project over a public network, which posed a significant security risk. Also, he stored pornographic and erotic content in the files located on the IRS disk at the workplace. Furthermore, the interested party states that the processing of the plaintiff's data was carried out by the Corporate Security Office of HEP d.d., as part of an internal investigation of a security incident. In addition, this processing was necessary to ensure the continued operation and safety of the GHE Vinodol facility, in accordance with the Energy Act ("Official Gazette", No. 120/12., 14/14., 95/15., 102/15., 68/18.) and the previously valid Critical Infrastructure Act ("Official Gazette", No. 56/13. and 114/22.). In addition, that the processing was necessary to ensure the safety of the entire electricity system of the Republic of Croatia, within which the hydroelectric power plant in question represents part of the national critical infrastructure. Furthermore, it considers that under Article 6(1)(c) of the Regulation, the interested party has a legal basis for data processing and that the processing was necessary for compliance with the legal obligations of the controller. According to Article 6(1)(f) of the Regulation, that the interested party also has a legitimate interest in protecting its information system from possible malware, viruses and other cyber attacks. Also that there is a legitimate interest in protecting national critical infrastructure because the hydroelectric power plant is part of the electricity system of the Republic of Croatia, as well as an interest in protecting its employees from the risks that breaches of security procedures create. It also considers that there is an interest in preventing the leakage of confidential technological knowledge that is the property of HEP Group. Furthermore, it considers that the proportionality test is satisfied, because the processing was limited only to data on the equipment from the plaintiff's workplace, only to data relevant to the security incident and only to data that could be manipulated by the plaintiff. Furthermore, the interested party considers that the defendant correctly concluded in its analysis that the processing was proportionate, that the visual inspection of the data on the disks was not an end in itself because the aim was to remediate the IRS and check the security of the process network. In addition, it states that the erotic and pornographic data were not intentionally collected, but were found during the technical inspection, because the disks were inspected to check whether there were malware or viruses on the disks and to bring the IRS into a functional state. He also believes that according to Article 9(2)(f) of the Regulation, the processing of special categories is legal when it is necessary for the establishment, realization or defense of legal claims. Furthermore, he states that in the case in question, the Office for Corporate Security conducted an investigation, because the plaintiff worked at GHE Vinodol (which is part of HEP-Proizvodnja d.o.o., which is a subsidiary of HEP d.d.), and the incident was related to a security threat to the process network of the hydroelectric plant. Furthermore, he notes that the Office for Corporate Security and HEP-Proizvodnja d.o.o. were not separate data controllers in the sense of Article 4(7) of the Regulation. This is because the Office for Corporate Security, as a service within HEP d.d., conducted the investigation as an authorized person on behalf of the interested person, so there was no need for a contract between two data controllers according to Article 26 of the Regulation, because only one data controller is HEP-Proizvodnja d.o.o. as the plaintiff's employer. The interested party also states that the plaintiff in his submission requests access to the data not for the purpose of monitoring the processing of the data, but in order to prove the alleged unlawful conduct of the employer in separate court disputes with the interested party, which is not the aim of Article 15 of the Regulation. Accordingly, the interested party proposes that the Court reject the claim as unfounded and confirm the contested decision of the defendant of 30 September 2025.5. During the dispute, a hearing was held on 30 April 2026 in order to enable the parties to the dispute to orally explain their allegations in the complaint and the response to the complaint, in accordance with the provisions of Article 6 of the Administrative Disputes Act (Official Gazette, No. 36/24 and 39/26, hereinafter: ZUS). The plaintiff's attorney, the plaintiff himself, the defendant's official and the interested party attended the hearing. At the same hearing, the parties fully maintained the allegations made during the administrative dispute, and after the parties' presentations, the Court presented evidence by examining the documentation contained in the file of the administrative procedure in which the contested decision was made and in the file of this dispute, while it did not present other evidence because the decisive facts could have been established by examining the aforementioned documentation.6. It is undisputed that the plaintiff was an employee of the interested party, or rather of its part of the GHE Vinodol. It is also undisputed that the interested party seized from the plaintiff's office the computer used by the plaintiff and several portable memories, which contained, in addition to official, personal data of the plaintiff. It is also undisputed that after that seizure, the plaintiff, taking actions that he considered necessary, and for the purpose of the security incident and security investigation, obtained the plaintiff's personal data on the plaintiff's business computer owned by the interested party, thereby undertaking the processing of such data.7. It is disputed between the parties to the dispute whether the defendant correctly and lawfully decided on the plaintiff's request for a declaration of a violation of the right to the protection of his personal data.8. Based on the consideration of the undisputed facts and the disputed legal issue, the Court found that the plaintiff's claim was unfounded.9. The provision of Article 4, paragraph 1 of the Regulation defines "personal data" as all data relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.10. The provision of Article 5, paragraph 1 of the Regulation stipulates that personal data must be: (a) processed lawfully, fairly and transparently in relation to the data subject ("lawfulness, fairness and transparency"); (b) collected for specific, explicit and lawful purposes and may not be further processed in a manner inconsistent with these purposes; further processing for the purposes of archiving in the public interest, for the purposes of scientific or historical research or for statistical purposes, in accordance with Article 89, paragraph 1, is not considered inconsistent with the original purposes ("purpose limitation"); (c) appropriate, relevant and limited to what is necessary in relation to the purposes for which they are processed ("data reduction"); (d) accurate and as necessary up-to-date; every reasonable measure must be taken to ensure that personal data that is inaccurate, taking into account the purposes for which it is processed, is deleted or corrected without delay ("accuracy"); (e) kept in a form that enables the identification of the subjects only for as long as is necessary for the purposes for which the personal data is processed; personal data may be stored for longer periods if the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), subject to the implementation of appropriate technical and organisational measures required by this Regulation to safeguard the rights and freedoms of data subjects (‘storage limitation’); (f) processed in a manner which ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage by applying appropriate technical or organisational measures (‘integrity and confidentiality’).11.The provision of Article 6, paragraph 1, items (c) and (f) of the Regulation stipulates that processing is lawful only if and to the extent that at least one of the following is met: the processing is necessary for compliance with the legal obligations of the controller; and the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child.12. The provision of Article 9, paragraph 1 of the Regulation stipulates that the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership is prohibited, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying an individual, data concerning health or data concerning an individual's sex life or sexual orientation. Paragraph 2 of the same article, point (f), stipulates that paragraph 1 shall not apply if the following is met: the processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in a judicial capacity.13. Article 49 of the introductory part of the Regulation stipulates that the processing of personal data to the extent necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or information system to resist, at a given level of confidentiality, accidental events or unlawful or malicious acts that jeopardise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data and the security of related services offered by or accessible through those networks and systems, carried out by public authorities, computer emergency response teams (CERTs), computer security incident response teams (CSIRTs), providers of electronic communications networks and services and providers of security technologies and services, shall be considered to be a legitimate interest of the data controller concerned. This could, for example, include preventing unauthorised access to electronic communications networks and the spread of malicious code, stopping "denial of service" attacks and preventing damage to computer and electronic communications systems.14. According to the Court, the defendant, in the explanation of the contested decision and the response to the complaint, and the interested party, in the response to the complaint, correctly and lawfully responded to all the allegations of the plaintiff, which is why the Court, in order to avoid repetition, refers the plaintiff to these allegations. This is because the proceedings in question that preceded this administrative dispute were conducted correctly, in which the factual situation was correctly and completely established, and to which the substantive law was lawfully applied, which is why, ultimately, the defendant's decision was lawful.15. Namely, it was correctly established that the employees of the interested party had to enter the plaintiff's office at a time when he was on sick leave, due to a malfunction in the IRS, which was necessary for business processes to proceed smoothly. It is clear from this that the official computer of the interested party was accessed, in the official premises of the same person, which is used by the plaintiff. In addition, it is also clear that the said computer was not accessed for the purpose of processing the plaintiff's (personal) data, but for the purpose of eliminating a malfunction on the said computer, which is necessary for the functioning of the interested party's system, and on which occasion inappropriate pornographic, erotic and entertainment content was detected on the hard drive connected to the said official computer, which is reasonable to assume to pose a danger and threat to the functioning of the computer, and thus the entire production system, of the interested party. Therefore, it is necessary to emphasize that the actions of the interested party were not undertaken with the aim of processing the plaintiff's personal data, but for the purpose of eliminating a technical malfunction and putting the computer in the office used by the plaintiff back into operation. Given that the interested party acted on the official computer and external memory, which were undoubtedly located in its business premises and in the office used by the plaintiff, for the aforementioned reasons, there was no basis for assuming before the action itself that the plaintiff's personal data would be found on the said computer and memory. In this regard, it is not decisive whether they were allowed to be there or not, as the plaintiff refers to in the lawsuit, but rather that they were found on the official computer, whereby the plaintiff himself enabled their processing, and that the interested party, given the reasons for the action, the nature of the personal data found and his obligations in terms of the maintenance and functioning of the hydroelectric power plant, was authorized to examine the security of the computer and memory in question as a whole. Furthermore, given that the processing of the plaintiff's personal data was carried out by the Corporate Security Office, as part of the umbrella company (HEP d.d.) of the group in which the interested party also operates, as the plaintiff's former employer, and that the processing itself was carried out in order to prevent damage to computers and electronic communication systems owned by that employer, it was correctly established that the above was carried out in accordance with the cited Article 49 of the introductory part of the Regulation. In addition, and given the processing carried out on data contained in the equipment located in the workplace of the interested party, which was used by the plaintiff, the Court also considers that the proportionality test is satisfied, because the processing of the data is limited only to the data contained in the said equipment, which are relevant to the said production process and security incident and to the data managed by the plaintiff.16. The basis established for the processing of personal data in question, based on Article 6.1.(f) of the Regulation, namely the determination that the processing was necessary for the purposes of the legitimate interests of the controller, is also assessed as lawful. This is because the processed data were located on disks found in the official premises, in the official computer of the interested party, within the IRS, which is a key part of the processing system of the interested party, which is of particular importance not only for the interested party, but for the entire energy system of the Republic of Croatia, from which the legitimate interest for the processing in question is evident (whereby the interested party referred to the provisions of the Energy Act and the Critical Infrastructure Act), as well as the necessity of complying with the legal obligations of the controller (basis for processing pursuant to Article 6(1)(c) of the Regulation). Further to the above, and with regard to the established security incident for which the IRS managed by the plaintiff was accessed, the Court considers that, in accordance with the cited Article 9(2)(f) of the Regulation, the processing of special categories undertaken was lawful, given that it was necessary for the establishment, exercise or defence of legal claims, for the reason that an internal investigation into security incidents is a legal claim of the interested party, and the public interest is the protection of the network and infrastructure, whereby such action by the said person was undertaken for the purpose of investigating the said incident, and not with with the intention of processing the plaintiff's personal data.17. Furthermore, in relation to the claims that dispute the existence of one or more controllers and the existence of a contractual relationship between them, the interested party correctly stated that this person and the Corporate Security Office were not separate controllers within the meaning of Article 4(7) of the Regulation, and given that the Corporate Security Office is a department within the umbrella company HEP d.d., and that it was conducting the investigation on behalf of the interested party. Therefore, there was no need for a contractual relationship between these entities as controllers under Article 26 of the Regulation.18. Furthermore, in relation to the access to the plaintiff's personal data, it should be noted that the defendant correctly pointed out that, in accordance with Article 15 of the Regulation, every employer as a controller is obliged to provide the employee as a data subject with the right to access personal data, so that the employee or data subject is aware of the processing of personal data and can monitor the lawfulness of the processing of such data. However, he also correctly established that the plaintiff's intention to exercise this right is not to control the lawfulness of the processing of his personal data itself, but to exercise some other rights that he considers to be violated and which are being decided in another court proceeding (not this dispute). Therefore, it is necessary to bring the said right of access into connection with the rights and obligations of other subjects, which are in a certain connection. Therefore, the exercise of the said right should be assessed in the context of the right and obligation of the interested party to protect the information and business system and infrastructure and, in that context, the right to conduct an internal investigation due to the identified threat, which would justify the termination of access to the official e-mail, the business system of the employer (interested party) and the exclusion of the plaintiff's personal data in order to protect the aforementioned legitimate interests, as well as enabling access to personal data that could not jeopardize the protection of the aforementioned legitimate interests.19. The Court points to the practice of the Constitutional Court of the Republic of Croatia adopted in Decision, No.: U-III-1916/2020, of 20 April 2022, in which it is stated that: "... The Constitutional Court emphasizes that the principles of adversarial proceedings and equality of arms as fundamental procedural guarantees of the fairness of the procedure imply the right of the parties in the proceedings to present allegations, to be heard and to personally questions to witnesses, even when they are represented by qualified attorneys. These principles also imply the right of parties to propose evidence, and although courts are not obliged to present every piece of evidence proposed by a party, they are nevertheless obliged to state sufficient and relevant reasons for rejecting evidentiary proposals..."20. Therefore, bearing in mind the aforementioned position of the Constitutional Court of the Republic of Croatia, this Court points out that for a complete and proper determination of the factual situation, it was not necessary to unconditionally accept all evidentiary proposals of the plaintiff, because such action would lead to a violation of the principles of economy and efficiency of the procedure, but in that context it was necessary to consider whether the rejected evidentiary proposal could have influenced a different resolution of the administrative matter.In addition, in administrative proceedings, the official is responsible for the quality of all evidentiary proceedings, and thus, among other things, must determine which essential facts should be established in the proceedings and which means of evidence are appropriate for their proof, thereby directly influencing the course of the evidentiary proceedings. However, it is his duty to enable the parties in the evidentiary proceedings to exercise and protect their rights, i.e. to express their views on the facts and legal issues important for resolving the administrative matter. Since the defendant acted in accordance with the above, the allegations that dispute the non-acceptance of all evidentiary proposals of the plaintiff are considered indecisive for a decision in the dispute. Also, given that the subject matter and circumstances of the processing of the plaintiff's personal data are clear, i.e. that each new request by the plaintiff to the defendant, in essence and content, does not have to be a new request, but a repetition of previous requests, and taking into account all of the above, the Court's assessment is that the plaintiff's allegation that the defendant had to decide separately on each confiscated item (computer, external memory) on the basis of which the plaintiff's personal data was processed is not well-founded, given that the same procedure was followed in relation to all of them.21. Following the above, the defendant's contested decision was assessed as lawful, and the Court decided as in point I. of the operative part of this judgment, based on the provision of Article 116. paragraph 1. ZUS. 22. Point II. of the operative part of this judgment is based on the provision of Article 147. paragraph 1. ZUS, according to which the party that loses the dispute bears all the costs of the dispute in full.23. Point III. The operative part of this judgment is based on the provision of Article 144, paragraph 1 of the ZUS, according to which the costs of the dispute consist of justified expenses incurred during or in connection with the dispute, and which expense in the form of the requested court fee requested in the response to the claim of the interested person was not incurred by the interested person, because court fees in an administrative dispute, in accordance with Article 22 of the Court Fees Act ("Official Gazette" 118/18 and 53/91), are paid only (upon filing of the claim and the decision made) if the Court dismisses the claim or rejects the claim, while the interested person in the administrative dispute is not the claimant, but the plaintiff and is therefore not obliged to pay the court fee. In Rijeka, 7 May 2026. Judge Marija Renner Jakovljević INSTRUCTIONS ON LEGAL REMEDY: An appeal against this judgment may be lodged with the High Administrative Court of the Republic of Croatia. The appeal shall be filed through this Court in triplicate, within 15 days from the date of delivery of the judgment. DNA: - to the plaintiff's attorney-at-law, Danijel Jurić, Rijeka, Andrija Medulića 4, - to the defendant, the Personal Data Protection Agency, Zagreb, Ulica Metela Ožegovića 16, - to the interested party, HEP-Proizvodnja d.o.o., Zagreb, Ulica grada Vukovara 37