Data Protection & GDPR
Processing records, privacy notices, processor contracts and ongoing support on data protection questions.
View the service →Answer 15 questions to assess your GDPR compliance posture. Receive a scored gap analysis with prioritised recommendations based on Croatian supervisory authority (AZOP) enforcement practice.
Questions are weighted by AZOP enforcement severity and based on real Croatian supervisory authority decisions.
A GDPR readiness assessment evaluates how well your organisation meets the requirements of the General Data Protection Regulation (EU 2016/679). It identifies gaps across key areas such as legal basis for processing, consent management, data subject rights, breach notification, and accountability, and helps you prioritise remediation before a supervisory authority inspection.
GDPR applies to any organisation that processes personal data of individuals in the EU, regardless of where the organisation is based. This includes companies, non-profits, and public bodies. If you collect names, emails, IP addresses, or any data that identifies a person in the EU, GDPR applies to you.
GDPR fines can reach up to €20 million or 4% of annual global turnover, whichever is higher. In Croatia, the supervisory authority AZOP has issued fines including €2.2 million to a debt collection company and €380,000 for unlawful video surveillance. Even smaller organisations face enforcement for basic violations like missing privacy notices or invalid consent.
AZOP (Agencija za zaštitu osobnih podataka) is Croatia's data protection authority, responsible for supervising GDPR compliance. AZOP conducts inspections, handles data subject complaints, and issues corrective measures including fines. Their enforcement priorities include consent management, transparency obligations, and data breach notification. This assessment tool covers all of them.
Our GDPR assessment tool asks 15 weighted questions covering all major GDPR obligations, from legal basis and consent to breach notification and accountability. Each question is scored (Yes, Partial, No, or N/A) and weighted by enforcement risk. You receive a percentage score, compliance level rating, and prioritised gap analysis with references to real AZOP enforcement cases.
Under GDPR Article 37, a DPO is mandatory if you are a public authority, if your core activities involve regular and systematic monitoring of individuals on a large scale, or if you process special categories of data (health, biometric, criminal records) on a large scale. Even when not legally required, appointing a DPO demonstrates accountability and can reduce enforcement risk.
A DPIA is required under GDPR Article 35 before processing that is likely to result in a high risk to individuals' rights and freedoms. This includes systematic profiling, large-scale processing of sensitive data, and public area monitoring. AZOP publishes a list of processing operations requiring a DPIA in Croatia. Failing to conduct a required DPIA is itself a GDPR violation subject to fines.
Under GDPR Article 33, you must notify your supervisory authority (AZOP in Croatia) within 72 hours of becoming aware of a personal data breach that poses a risk to individuals. If the breach poses a high risk, you must also notify affected individuals without undue delay (Article 34). Late or missing breach notifications are among the most common reasons for AZOP enforcement actions.
Processing records, privacy notices, processor contracts and ongoing support on data protection questions.
View the service →An evidence-based GDPR checklist covering scope, lawful processing, rights, vendors, security, DPIAs, transfers, and governance.
Read the guide →A practical guide to GDPR scope, principles, lawful bases, rights, governance, security, DPIAs, transfers, and evidence.
Read the guide →