Skip to main content
Image coming soon

Croatia GDPR Implementation Act (OG 42/2018) Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
Croatia GDPR Act · Implementation Act OG 42/2018 · Evidence & Implementation Kit
Comply in Croatia, without separating the GDPR from the OG 42/2018 derogations yourself.
Every obligation handed to you as an adopt-ready control, from the GDPR baseline through Croatia's specific provisions, the consent age of 16 and the video surveillance regime, with the evidence AZOP examines.
Compliant in a weekend, not a quarter.

Here is the honest situation. Croatia applies the GDPR through the Act on the Implementation of the General Data Protection Regulation (OG 42/2018), and it adds national rules on top: a consent age of 16 for information society services, restrictions on genetic data affecting insurance and credit, specific biometric processing conditions for the public and private sectors, and a detailed video surveillance regime covering work premises, residential buildings and public areas. Working out which Croatian derogations change the GDPR baseline, and evidencing each to AZOP, is weeks of legal interpretation, and mishandling video surveillance or the consent age is exactly where Croatian controllers fall short.

This Kit removes that interpretation. It is every obligation, GDPR baseline plus the OG 42/2018 derogations, written as an adopt-ready control you personalize in a weekend, with the evidence AZOP examines.

What you get, the moment you buy

35
Obligations as adopt-ready controls. Every obligation, from the GDPR baseline through Croatia's specific provisions, the video surveillance regime, the AZOP role and the data subject rights, written so you personalize and apply it. The OG 42/2018 derogations are built in.
35
Evidence-they-examine checklists. For each obligation, exactly what AZOP examines, plus where Croatian controllers fall short, so you close the gap first.
1
Data Protection Control Matrix, pre-built. Every obligation in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each obligation and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the Croatian Act on the Implementation of the GDPR (OG 42/2018) as a GDPR-implementing law, with the consent age of 16, the genetic-data restriction, the biometric processing conditions and the video surveillance regime (Articles 25 to 32) called out. Editable Word and Excel files.

The video surveillance regime is what catches controllers
Croatia's implementation act devotes Articles 25 to 32 to video surveillance, with distinct rules for work premises, residential buildings and public areas, plus signage, retention and a DPO decision requirement. A controller applying only the GDPR will miss it. This Kit builds the surveillance controls, so the derogation that catches controllers is handled.

What one control looks like

This is the GDPR baseline lawful basis and principles, on which Croatia's specific rules sit. All 35 are built to this depth.

CROGDPR-1 Establish and document lawful basis GDPR BASELINE
Put this control in place

Require [your organization name] to identify and record one specific Article 6 lawful basis for each processing purpose before any personal data is collected, distinguishing consent, contract, legal obligation, vital interests, public task, and legitimate interests, and to reassess the chosen basis whenever the purpose, data categories, or processing context materially changes.

Legal note.

Croatian AZOP expects the lawful basis to be fixed at collection and not retrofitted after a complaint arises.

Evidence AZOP examines
  • Lawful basis register mapping each purpose to its Article 6 ground
  • Legitimate interests assessments where that basis is relied upon
  • Consent capture records with timestamp and version of the notice
  • Change log recording reassessment of basis after purpose changes
Common finding they raise: Organizations often assert legitimate interests generically without a documented balancing test against the data subject's rights.

Why this is not another template pack

  • The evidence is the point. A duty you cannot evidence is exposure to AZOP. This tells you what AZOP examines and where controllers fall short, for every obligation.
  • The Croatian derogations built in. The consent age of 16, the genetic-data restriction, the biometric conditions and the video surveillance regime are written into the controls, the places a GDPR-only approach fails.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. The GDPR baseline maps onto every EU member state, so this work feeds a broader multi-jurisdiction privacy program.

Who buys this

Any organization processing personal data in Croatia, and the privacy, legal and HR leads who own it. Whether it is a first assessment or a market entry, you save weeks and walk in with the Croatian derogations and the GDPR duties handled.

By the end of the weekend you will have
✓  An adopt-ready control for all 35 obligations
✓  A completed data protection control matrix
✓  The evidence AZOP examines
✓  Your video surveillance and consent-age controls in place
✓  A readiness percentage and a fix list
✓  The common gaps closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Is this legal advice? No. It is an implementation toolkit grounded in the OG 42/2018 act and the GDPR. For a specific matter consult Croatian counsel; this gets your controls and records in order fast.

Does it cover video surveillance? Yes. The Articles 25 to 32 regime, work premises, residential buildings and public areas, is its own control group, because Croatia regulates it in detail.

What is the consent age? 16 for information society services. It is built as a control, because it differs from the GDPR default position.

What if it is not for me? A 30-day money-back guarantee.

Do not apply the GDPR and miss the Croatian rules.
Every obligation is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be compliant this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com