Skip to content
Enforcement · Croatian Data Protection Authority (azop) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Retailer: Insufficient fulfilment of information obligations

The Croation DPA (azop) has imposed a fine of EUR 1,991 on a retailer.

€1,991 Fine
Retailer
CROATIA
Art. 27 GDPR

Full text

The Croation DPA (azop) has imposed a fine of EUR 1,991 on a retailer. The controller had installed a video surveillance system in its premises, however the DPA found that the video surveillance notice did not contain all relevant information. The DPA therefore concluded that the controller had violated Art. 27 (2) of the Croatian Act on the Implementation of the GDPR.

Industry: Industry and Commerce

How it connects

10 A 5144/23 VG Hannover: Controller appeals DPA reprimand over unlawful workplace video surveillance The owner of a doner kebab production facility (the controller) had installed video cameras to monitor virtually every room of the business premises. Cameras were placed in the… Administrative Court Hannover Aug 7, 2026 Controllers Supervisory Authorities Legitimate Interest
C-422/24 Case C-422/24 - AB Storstockholms Lokaltrafik. A new page has been created with the following information: "" CJEU Jan 7, 2026 Personal Data Fairness & Transparency Controllers
42 K 51.25 VG Berlin: DPA correctly found residential video surveillance for property protection The property management company of a high-rise building (the controller) had a video surveillance system installed at the entrances of the building in 2021. The installation was… Administrative Court Berlin Apr 20, 2026 Legitimate Interest Supervisory Authorities Retention Period
1713/2026 High Court of Justice of the Basque Country · TSJ PV - 1713/2026 The data subject had worked for Fineco Sociedad de Valores, SA and GIIC Fineco Sociedad Gestora de Instituciones de Inversión Colectiva, SAU, the controller, since 2004. The data… Jul 17, 2026 Personal Data Controllers Monitoring
703/2026 Sibiu Tribunal: rail company liable for refusal of CCTV access request On 5 June 2025, an individual (the data subject) made an access request under Article 15 GDPR to the Romanian National Railways Company, Societatea Națională de Căi Ferate SA (the… Jul 3, 2026 Right of Access Personal Data Legitimate Interest