Skip to content
Case Law · Administrative Court of Zagreb ·Us I-4772/2023-10 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

A utility and municipal services enterprise, Zagrebački Holding d.o.o

(the controller) provided users of its services with the option to request a copy of their bill via email.

Judgment

Holding

The court held that the controller had not transparently provided users with the legal basis for collecting copies of identification documents. It found that this information was neither available in the controller’s published documents nor provided when users requested it directly via email. The court therefore upheld the finding of an infringement of Article 13(1)(c) GDPR. The court further found that the information concerning the retention period could be interpreted in different ways. In response to a specific inquiry, the controller should have provided clear information on the duration of the storage. It ruled that this amounted to an infringement of Article 13(2)(a) GDPR. The court also noted that one user had been told that the requested data could not be provided without an identification document, while the controller later stated before the DPA that users unwilling to send a copy could instead present it in person at the Holding Centre in Zagreb. In light of the lack of clear information as to whether providing the identification document was mandatory and the consequences of not providing it, the court upheld the finding of an infringement of Article 13(2)(e) GDPR. Moreover, the court agreed with the DPA that the controller had not implemented appropriate technical and organisational measures for the identification procedure. It determined that the format or name of an email address did not provide sufficient assurance that a request actually originated from the user concerned, while the procedure effectively required certain users to provide a copy of an identification document in order to communicate remotely. The court pointed out that processing such copies could pose a high risk to individuals’ rights, such as identity theft. The court considered that the controller could instead have established a secure email-verification procedure, allowing users to verify an email address for communications and the delivery of bills, while ensuring that the identification procedure applied consistently regardless of the structure of the email address. It therefore upheld the finding that the controller had failed to implement appropriate safeguards in breach of Article 25(2) GDPR. Furthermore, the court rejected the controller’s reliance on the EDPB’s practice, noting that it concerned a different context, namely the verification of the identity of individuals exercising their rights under the GDPR. It acknowledged that an ID copy may be justified in higher-risk situations, such as certain GDPR rights requests involving sensitive or extensive data, or where the controller has no ongoing relationship with the requester. However, it held that this did not affect the infringements established in relation to the controller’s procedure for issuing copies of bills. The court upheld the DPA’s €25,000 fine.

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Summary

Where the name appearing in the email address differed from the user’s name, the controller requested a copy of an identification document as part of the process of verifying the identity of its users. It treated that discrepancy as an indication of possible identity fraud. According to the controller, users were asked to redact any information on the document that was not necessary for identification. In addition, the copies were deleted once the relevant purpose had been fulfilled and access to them was limited to a small number of authorised employees. The Croatian DPA (AZOP) found that the controller had not adequately informed users of the legal basis for collecting copies of identification documents, the applicable retention period, or whether providing such a copy was mandatory and what the consequences of not providing it would be. It held that the controller had infringed Article 13(1)(c) GDPR, Article 13(2)(a) GDPR and Article 13(2)(e) GDPR. Furthermore, it found that the company had not implemented appropriate technical and organizational measures for the process of verifying the identity of users who requested copies of bills via email, in violation of Article 25(2) GDPR. It fined the controller €25,000. The controller challenged the decision before the Administrative Court of Zagreb. It argued that it had published information on its website regarding the processing of personal data. It claimed that the information had been modelled on guidelines published by the EDPB. The controller further alleged that users had been informed that the data would not be retained for longer than was necessary for the purpose of the processing. It also argued that it did not collect an excessive amount of data, as it asked users to redact unnecessary information and that copies were deleted after verification was completed. The DPA pointed out that the information regarding data retention was contradictory or open to different interpretations, and that the controller’s deficiencies were not corrected even when a user requested clarification directly from the controller. Regarding the identification process, the DPA argued that the controller could have achieved the same objective without requesting copies of identification documents, for example by using previously verified email addresses. It considered that a discrepancy between a user’s name and the name associated with an email address did not constitute a reliable criterion for detecting potential identity fraud. According to the DPA, the procedure was not designed with sufficient consideration of the nature, context, and risks of the specific processing, and the mere instruction to users to redact parts of their identification document did not constitute a sufficient safeguard.

Full text 4 paragraphs

Machine translation of the decision, via GDPRhub — not the official text. Read the original

Paragraphs carrying a topic or an applied provision show those connections inline

REPUBLIC OF CROATIA ADMINISTRATIVE COURT IN

§

ZAGREB Zagreb, Avenija Dubrovnik 6 Case No.: 4772/2023-10 IN THE NAME OF THE REPUBLIC OF CROATIA JUDGMENT Administrative Court in Zagreb, before Judge Ivana Horvat, with the participation of Ankica Zorić, court clerk, in the administrative dispute of the plaintiff ZAGREB HOLDING d.o.o., OIB: 85584865987, Zagreb, Ulica grada Vukovara 41, represented by its attorney, Andrijana Kaštelan, lawyer from Zagreb, Savska cesta 32, against the defendant, the Personal Data Protection Agency, OIB: 28454963989, Zagreb, Metela Ožegovića 16, for the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, July 22, 2026, it was ruled: The lawsuit for the annulment of the decision of the Personal Data Protection Agency, CLASS: UP/1-034-01/23-01/21 REGISTRY NUMBER: 567-12/04-23-01 of August 28, 2023. Rationale

¶1

The defendant's contested decision determined that the plaintiff, as the data controller, did not adequately inform service users about the legal basis for processing personal data and the period for which personal data will be stored when collecting a copy of a personal identification document for the purpose of issuing an invoice via email, and thereby acted in violation of the provisions of Article 13(1)(c) and Article 13(2)(a), (e) of the General Data Protection Regulation (Point I of the judgment). It was further determined that the defendant, as the data controller, did not take appropriate technical and organizational measures when processing personal data for the purpose of identifying service users for the issuance of account statements via email, thereby violating the provisions of Article 25(2) of the General Data Protection Regulation. General Data Protection Regulation (Point II of the Judgment), and by Point III of the Judgment, for the violations described in Points I and II, in accordance with the provisions of Article 83. and the General Data Protection Regulation, an administrative fine in the amount of €25,000.00 was imposed on the plaintiff, all under the conditions and manner detailed in further paragraphs IV and V of the contested decision.2. In the lawsuit and during the dispute, the plaintiff challenges the legality of the defendant's decision, and essentially states that on the plaintiff's website www.zgh.hr, in the "About Us" category, subcategory "Personal Data Protection," a general information notice about the processing of personal data was published, and in the same category, subcategory Protection of Personal Data, the further subcategory Processing of Personal Data of Natural Persons (JUP), published information on the processing of personal data by joint controllers in connection with the unified payment order. It emphasizes that in this specific case, the objective was to identify the data subjects who had requested certain information regarding a transcript of their account (the so-called unified invoice – JUP) for the services provided by the controller to its users. It quotes the content of the relevant publications on the website ww.zgh.hr. It states that the said publications providing information to data subjects were modeled on the publications of the European Data Protection Board (EDPB) – the Central European body that ensures the consistent application of EU law, particularly the General Data Protection Regulation, in all countries it covers, and which provides guidance, issues recommendations, and promotes cooperation and the alignment of the work and practices of national data protection authorities in EU member states. Specifically, in its information to data subjects, the EDPB, when discussing the processing of personal data for identification purposes, does not explicitly elaborate on the legal basis for such processing, nor is this processing for the explicitly stated purpose problematized in any way. Regarding the retention period for such collected data, the EDPB's formulation is stated as: "will not be stored for longer than is necessary for that purpose," which has also been paraphrased in the plaintiff's publications. Therefore, insisting on a different way of formulating the duration of the retention period is, in the plaintiff's view, incorrect and unfounded because such information was provided to the data subjects in the form of the aforementioned statement. It believes that such an interpretation by the defendant would amount to imposing a higher standard on the processing of data subjects in the Republic of Croatia than is required by the EDPB's interpretation and practical application. Regarding the allegations concerning the technical and organizational measures taken by the plaintiff as the data controller, the plaintiff quotes Article 25(2) of the Regulation. The plaintiff believes that in this specific case, it acted in accordance with the aforementioned provision and did not process an excessive set of data for the purpose of identifying data subjects. nor did he exceed the scope of processing or the retention period, nor were the data made available or further processed contrary to their purpose (only necessary personal data were requested, with an instruction to black out, redact, and render other data invisible). It believes that the vague reasoning in the contested decision is that the respondent's actions contrary to Article 25(2) of the Regulation created a feeling of fear and a loss of control over personal data, because the plaintiff acted as described, and the claim of creating a feeling in someone represents an unverifiable category, is not quantifiable, and can be an arbitrary conclusion based solely on someone's claim that may not be true. Especially since an investigation by the defendant, prompted by the complaint in the "JS" case, determined that only the necessary data was requested, that copies of ID cards were deleted after they were no longer needed for processing (for identification purposes), and that all of this was accessible only to a specific employee, whose job this is as part of their daily duties, and who are obligated to maintain the confidentiality of personal data. This applies to 15 authorized employees who submit the lists to the defendant. It considers the defendant's claim to be incorrect that there are no prescribed rules for identifying service users who request account statements, and this can only be true in the sense that such rules are not prescribed in the form of an internal act, but the plaintiff's position is that the instructions of the competent managers, given to employees who are in direct communication with the individuals concerned, and for which it is indisputable that instructions were issued, must be considered rules of procedure, since they were issued by an authorized person with the authority to do so, and these same employees were obligated to comply with them. Regarding the administrative measure imposed, it is stated that the defendant provided a detailed explanation of the individual criteria used in determining the penalty. However, the plaintiff's position is that the penalty in question, in terms of its severity and even the choice of the type of sanction, and this is for the irregularities as stated by the defendant (failure to inform about the legal basis for processing, failure to inform about the storage period, inadequate organizational and technical measures, lack of prescribed rules for identification), and taking into account that, in the plaintiff's view, none of these allegations of shortcomings is accurate; it is inappropriate and completely unfounded. The claim that the only issue open to debate is the scope and strength of the protective measures, and the potential need to enhance them in terms of increased protection of examinees' personal data during identification, which is not the subject of detailed discussion in this lawsuit, and considering that the conditions as they stand may not meet the required standards for protection. It states that imposing an administrative monetary penalty as a sanction for the same is considered inappropriate, as the defendant primarily has an advisory and corrective role that is not realized primarily through repressive measures as the sole deterrent to improper conduct, and the determination of the amount of the administrative fine is directly within the defendant's discretion. Therefore, it is proposed that the Court grant the plaintiff's request and annul the contested decision. The defendant, in its answer to the complaint, points out that in the present administrative matter it acted in accordance with the provisions of Article 57(1) and Article 58(1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016. on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) OJ L 119, and that, based on the collected and submitted evidence, it correctly applied procedural and substantive law and issued the contested decision. With respect to the plaintiff's allegations, it notes that pursuant to Article 13. the General Data Protection Regulation requires the controller to inform the data subject of the processing and its purposes, and should provide the data subject with any additional information necessary to ensure fair and transparent processing. A review of the controller's relevant documentation revealed that it does not contain information about the legal basis, the storage period, nor information on whether providing a copy of one's ID card is a legal or contractual obligation or a requirement necessary to enter into a contract, and as a result, a violation of Article 13(1)(c) and Article 13(2)(a) was determined, (e) of the General Data Protection Regulation. It points out that the obligation to transparently inform data subjects about personal data processing does not end with merely publishing the information from Article 13(1) on websites; rather, the controller is also obligated to provide the additional information from Article 13(2) upon the data subject's request, which the plaintiff failed to do in this case. It also points out that the document the plaintiff refers to, titled "Processing of Personal Data of Natural Persons – Unique Payment Order (JUP)," in the section on retention period, prescribes: "The personal data of the data subjects are processed until the purpose of processing the personal data is fulfilled. After the purpose for which they were collected has ceased, the personal data are no longer used, but remain in the storage system and are kept in accordance with regulations on the protection of archival and registrarial materials," and then, in the table immediately following the description, it is stated that identification data are kept permanently. In the same document, you can also find information stating that "copies of an official identification document…will be used only for the purpose of verifying the identity and protecting the data of the respondent to prevent fraud (e.g., false identity, misuse of personal data, etc.), and such data will not be stored for longer than necessary for this purpose. Given that the information provided could be interpreted in two ways, the data controller should have, upon the data subject's direct request, provided clear and complete information on the legal basis, the storage period, and other matters. A breach of Article 13(1)(c) and paragraph 2. points a. and e., the defendant determined that the plaintiff failed to provide this information to the data subject even after it was requested in direct communication with the data controller, and believes that the plaintiff's arguments concerning only the set of information published in the EDPB's "Data Protection Notice" document are not relevant. Furthermore, regarding the reference to the EDPB's wording, the defendant states that in the present case, it concerns the collection of copies of personal identification documents for the purpose of issuing copies of invoices, whereas in the EDPB's case, it is a notice that relates to processing for the purpose of identity verification when submitting requests concerning the rights of data subjects under the General Data Protection Regulation. It is undisputed that if a controller receives a request for access to a broader set of personal data, or special categories of personal data or other categories of sensitive data, or a request for erasure, and in which case there is a higher risk to the individual's rights and freedoms, may request a copy of an identity document on the basis of a legal obligation or legitimate interest for the prevention of fraud, as well as if the requests are made by data subjects with whom the controller is not in an ongoing relationship. Furthermore, the defendant determined a violation of Article 25 of the General Data Protection Regulation because the data controller could have achieved the purpose of the processing without collecting ID cards, by applying the principle of data minimization, as prescribed by Article 25 of the General Data Protection Regulation. The defendant believes that the plaintiff could have verified an individual's identity based on the personal data it processes in connection with the service, and as an additional security measure for communication with service users via electronic means, use the email address that the service user had previously selected. Supporting the defendant's finding that the plaintiff did not properly design the process for identifying data subjects is the fact that the structure of the email address name was used to decide on collecting an identification document to prevent false representation, and when creating the email address name with the electronic communications service provider, user identification is not conducted, for which reason the said parameter cannot be considered reliable for assessing whether there is false representation, and therefore, prior verification of the email address is a measure that would reduce the possibility of misuse. Additionally, when designing the processing procedures, the data controller relied on the data subjects themselves/users of the service, to whom it provided written instructions on how to cover parts of an ID card to prevent the collection of excessive personal data, and did not provide for additional safeguards for sending high-risk personal data categories, such as copies of documents. It is considered that the established violation of Articles 13 and 25 of the General Data Protection Regulation occurred precisely because the personal data processing procedure for collecting the identifiers of the data subjects was modeled on information provided by other data controllers, without taking into account the nature, scope, context, and purpose of the processing, as well as the risks of varying degrees of reliability and seriousness to the rights and freedoms of the individual arising from the data processing in the specific case, which can be inferred from the reference to the EDPB's practice regarding the collection of identification documents. Accordingly, since the plaintiff failed to provide the data subject with complete information about the processing of personal data at multiple stages, and failed to analyze the risk when creating the new process for processing identification documents, and that since this is the controller's core activity, the defendant believes that a monetary fine is the appropriate corrective measure. In determining its amount, the defendant took into account all mitigating circumstances in the case and ensured that its imposition would not jeopardize the performance of its public service.5. The Court proposes to dismiss the plaintiff's claim as unfounded.6. In assessing the legality of the contested decision, the Court reviewed the case file, as well as the defendant's file, which contains information on the factual state of affairs established in the administrative proceedings, and held an oral and public hearing.7. Based on the consideration of all factual and legal issues, the Court finds that the claim is unfounded.8. Article 13(1) Article 13(2)(c) of the General Data Protection Regulation provides that the controller must provide the data subject at the time of collection of personal data with all information on the purposes of the processing for which the personal data are intended, as well as the legal basis for the processing;9. Article 13(2)(a) and (e) provides that the controller must also provide the data subject with additional information necessary to ensure fair and transparent processing: (a) the period for which the personal data will be stored or, if that is not possible, the criteria used to determine that period;(e) information on whether the provision of personal data is a legal or contractual requirement or a condition necessary to enter into a contract, and whether the data subject has an obligation to provide the personal data and the possible consequences of failing to provide such data;10. In accordance with recital (60) of the General Data Protection Regulation, which relates to Article 13. of the General Data Protection Regulation, the controller is obligated to inform the data subject about the processing and its purposes and should provide the data subject with any additional information necessary to ensure fair and transparent processing.11. Article 25(1) of the General Data Protection Regulation provides that the controller, taking into account the latest developments, the cost of implementation and the nature, scope, context, and purposes of processing, as well as the risks of varying likelihood and severity for individuals' rights and freedoms that arise from the processing, and at the time of the determination of the means of processing and at the time of the processing itself, implements appropriate technical and organizational measures, such as pseudonymization, to enable the effective application of data protection by design principles, such as data minimization, and to incorporate safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.12. Article 25(2) of the General Data Protection Regulation provides that the controller shall implement appropriate technical and organizational measures to ensure that, by default, only personal data that are necessary for each specific purpose of the processing are processed. This obligation applies to the amount of personal data collected, the scope of their processing, the period of storage, and their availability.13. In the proceedings leading up to the contested decision, a review of the e-correspondence between the plaintiff and several data subjects revealed that the data controller failed to transparently inform service users of the legal basis for collecting personal data (a copy of an identity document) for the purpose of identification. Specifically, this information was not available to the data subjects through published documents regarding personal data processing on the controller's official websites, nor after they directly requested information about the processing via email. It was also determined that the data controller collected copies of identification documents in cases of suspected impersonation from users who used an email address that included a different name in its structure/the name and surname of the service user, and that there are no prescribed rules for identifying service users who request the delivery of a copy of an invoice, which contains personal data, via email. However, as the defendant correctly concludes, a naming convention for an email address that uses the user's first and last name is not an adequate security measure that would provide the data controller with sufficient assurance that the request in question was made by the actual service user. Accordingly, it was determined that the data controller in question failed to implement appropriate technical and organizational security measures, or to establish a process for processing personal data for the purpose of identifying service users who requested the delivery of personal data via email. Namely, considering only the structure of the email address name in the form of a first and last name that does not correspond to the user's name, he prevented users from (without presenting a personal identification document, the processing of which can pose a high risk to the rights and freedoms of individuals, e.g. identity theft) communicating remotely.14. In this regard, the defendant should have provided all users with a secure means of communication via email. identity theft) to communicate remotely.14. In this regard, the plaintiff should have enabled all users a secure method of communication via email, e.g. in a way that the controller proactively requests consent from the data subject to use the selected email address for communication, sending invoices, etc., or that the data subjects verify their email address for communication with the controller. Therefore, in this court's opinion, the defendant reasonably concludes that the data controller should have implemented the aforementioned business processes for identification via email to ensure that personal data, such as account information, is not disclosed to unauthorized persons, without the need to collect a personal identification document. The defendant also reasonably concludes that the data controller in question should have developed the email-based identification business processes in a way that would ensure the user identification procedure is the same for all users, regardless of the structure of their email address.15. Similarly, it is evident from the emails sent to JS on April 25 and 26, 2023. it is evident that she was not familiar with the legal basis for processing personal data, and that she was told that without an identification document, the complainant could not provide the requested data, which is in contradiction to the statements of Mr. J, who, in response to an explicit inquiry from an Agency officer as to how the data controller would proceed if the data subject does not wish to provide a copy of their personal identification document in order to obtain a copy of an invoice, stated that in that case, they would make an arrangement with the data subject or suggest that the data subject personally bring a copy of their personal identification document for inspection to the Holding Center branch at 41 Vukovar Street, Zagreb.16. Regarding the plaintiff's objection concerning the retention of personal data and the reference to the EDBP information, it is noted that the proceedings have undisputedly established that in the plaintiff's documents, specifically "Processing of personal data of natural persons - Unique Payment Order" the aforementioned information on the retention of personal data which can be interpreted in two ways, and the plaintiff, upon a specific inquiry from the respondent, should have informed them of the legal basis and the retention period. The plaintiff's reference to the EDBP information is irrelevant, since in this specific case, it concerns obtaining copies of personal identification documents for the purpose of issuing copies of invoices, whereas in the case of the EDBP, it concerns a notice relating to processing for the purpose of identity verification when submitting requests related to the rights of data subjects under the General Data Protection Regulation, where it is undisputed, and as correctly concluded by the defendant, that if the data controller receives a request for access to a broader set of personal data or special categories of personal data or other categories of sensitive data, or a request for erasure, in which case there is a higher risk to the rights and freedoms of the individual, may, on the basis of a legal obligation or legitimate interest for the prevention of fraud, request a copy of an identity document, as well as if the requests are made by data subjects with whom the controller is not in an ongoing relationship.17. With respect to the sanction, taking into account the number and type of violations and the provisions on sanctions that are detailed in the reasoning of the contested decision, since this is a matter of the defendant's discretion, this Court, which is not authorized to assess its correctness but only its legality (Article 4(2) of the Law on Administrative Proceedings), finds that the sanction is adequately justified. Administrative Procedure Act), concludes that it is fully and adequately justified in a manner that this Court fully accepts.18. In view of the foregoing, since the objections raised by the plaintiff in the complaint and during the proceedings did not call into question the legality of the contested decision, it was deemed appropriate, pursuant to Article 116(1) of the Law on Administrative Proceedings (Official Gazette, No: 36/24 and 39/26) it was decided as stated in the judgment. In Zagreb, July 22, 2026. Judge: Ivana Horvat Notice of Appeal: An appeal may be filed against this judgment with the Supreme Administrative Court of the Republic of Croatia. An appeal must be filed through this court in a sufficient number of copies for the court and all parties to the dispute, within 15 days from the date of service of the judgment. Parties: 1 Attorney Andrijana Kaštelan – by electronic communication

¶2

Agency for Personal Data Protection, [address] Zagreb, Metela Ožegovića 16

¶3

On the record

How it connects

3 of 4 paragraphs apply legislation or carry a topic — see them in the full text ↓
Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Jan 28, 2020 Personal Data Privacy by Design & Default Processing
Recommendations 01/2021 adequacy referential under the Law Enforcement Directive 1 vo.1 Adopted Recommendations 01/2021 on the adequacy referential under the Law Enforcement Directive Adopted on 2 February 2021 2 vo.1 Adopted Version history Version 1.1 6 July… Recommendations ·EDPB Feb 2, 2021 Supervision Privacy Shield Legitimate Interest
2022 EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Processing Agreement International Transfer