Consultant for the General Data Protection Regulation (GDPR) Ana Keglović Horvat presented this Regulation on Monday, which was adopted by the European Union in 2016, and will begin to be applied in all EU countries from May 25, along with its compliance with the Croatian Personal Data Protection Act, which is expected to be adopted soon.
– Regardless of whether Croatia will adopt a law within the deadline that will regulate the issue of personal data protection at the national level, this Regulation will come into effect on May 25, as it is a general regulation, meaning it is uniformly applied in all 28 member states of the European Union, emphasized Keglović Horvat at a press conference.
>>>Lider’s guide to GDPR can be found at Tisak and iNovine
It would be beneficial for Croatia to appoint a personal data protection commissioner
The General Data Protection Regulation (GDPR) brings changes to the way of doing business and in the legislative sector, especially regarding the rights of citizens who have personal data stored or processed by certain organizations, she explained.
– According to the Regulation, from May 25, numerous organizations will have to align and change their operations, and citizens will be given the opportunity to exercise some of their seven rights related to personal data protection. This protection is now elevated to the level of human rights, thus enabling fundamentally different behavior towards data, emphasized Keglović Horvat.
>>>Project Privacy: Fundamental GDPR guidelines for startups
She stated that the Regulation applies to every organization that collects and processes data of respondents, EU citizens, so practically every organization, such as a public authority, company, association, school, hospital – must comply with this Regulation.
From May 25, every organization with more than 250 employees and that collects large amounts of data or particularly protected categories of data, as well as every public authority, will have to appoint a data protection officer. She also advocated for Croatia to appoint a commissioner for personal data protection.
>>>GDPR: From next year, rigorous European obligations in personal data protection
– The protection of personal data has been elevated to the level of human rights, and therefore I think it would be very useful for Croatia to show concern for human rights in the category of personal data by appointing a commissioner for personal data protection, just as we currently have a commissioner for information, she said.
Fines for violations of personal data protection up to 20 million euros
She emphasized that with the application of the Regulation, there will be the possibility for any supervisory body from EU member states to conduct oversight with the consent of the national local agency and in any other EU member state. Thus, it is likely that supervisory bodies from the EU will come to Croatia, but the Croatian Agency for Personal Data Protection (AZOP) will likely also be under oversight in another EU country.
