Here is the honest situation. Croatia applies the GDPR through the Act on the Implementation of the General Data Protection Regulation (OG 42/2018), and it adds national rules on top: a consent age of 16 for information society services, restrictions on genetic data affecting insurance and credit, specific biometric processing conditions for the public and private sectors, and a detailed video surveillance regime covering work premises, residential buildings and public areas. Working out which Croatian derogations change the GDPR baseline, and evidencing each to AZOP, is weeks of legal interpretation, and mishandling video surveillance or the consent age is exactly where Croatian controllers fall short.
This Kit removes that interpretation. It is every obligation, GDPR baseline plus the OG 42/2018 derogations, written as an adopt-ready control you personalize in a weekend, with the evidence AZOP examines.
What you get, the moment you buy
Grounded in the Croatian Act on the Implementation of the GDPR (OG 42/2018) as a GDPR-implementing law, with the consent age of 16, the genetic-data restriction, the biometric processing conditions and the video surveillance regime (Articles 25 to 32) called out. Editable Word and Excel files.
What one control looks like
This is the GDPR baseline lawful basis and principles, on which Croatia's specific rules sit. All 35 are built to this depth.
Why this is not another template pack
- The evidence is the point. A duty you cannot evidence is exposure to AZOP. This tells you what AZOP examines and where controllers fall short, for every obligation.
- The Croatian derogations built in. The consent age of 16, the genetic-data restriction, the biometric conditions and the video surveillance regime are written into the controls, the places a GDPR-only approach fails.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. The GDPR baseline maps onto every EU member state, so this work feeds a broader multi-jurisdiction privacy program.
Who buys this
Any organization processing personal data in Croatia, and the privacy, legal and HR leads who own it. Whether it is a first assessment or a market entry, you save weeks and walk in with the Croatian derogations and the GDPR duties handled.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is this legal advice? No. It is an implementation toolkit grounded in the OG 42/2018 act and the GDPR. For a specific matter consult Croatian counsel; this gets your controls and records in order fast.
Does it cover video surveillance? Yes. The Articles 25 to 32 regime, work premises, residential buildings and public areas, is its own control group, because Croatia regulates it in detail.
What is the consent age? 16 for information society services. It is built as a control, because it differs from the GDPR default position.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com