Skip to content
Enforcement · Croatian Data Protection Authority (azop) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Sports betting operator: Insufficient legal basis for data processing

The Croatian DPA (AZOP) has imposed a fine of EUR 380,000 on a sports betting operator.

€380,000 Fine
Sports betting operator
CROATIA
Art. 6 GDPR Art. 13 GDPR Art. 25 GDPR Art. 32 GDPR

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Croatian DPA (AZOP) has imposed a fine of EUR 380,000 on a sports betting operator. AZOP had received a complaint from a data subject, stating that the controller had obtained a copy of their bank card. During its investigation, AZOP found that the controller had collected personal data (including copies of bank cards) of data subjects without a valid legal basis. In 2022, players had the option to have their winnings paid out not only via their bank account but also via their Visa card. The controller collected copies of the bank cards with the intention of complying with requirements of the national Money Laundering Act. However, AZOP found that the collection of the copies was not necessary to comply with the requirements of the Money Laundering Act and that the processing of the data was therefore unlawful. In this context, AZOP also found that the controller had not sufficiently informed the data subjects about the processing of their personal data, in particular, it was expressly stated that the data controller does not store bank card numbers and that the numbers are not accessible to the unauthorized persons.

§

Accordingly, the information provided to the data subjects was missing information on the legal basis, purpose of collection and retention period of the personal data. The controller also failed to take sufficient technical and organizational measures to protect personal data relating to the establishment of payment processes via Visa bank cards, as well as for the storage of data contained in the controller's databases. As a result, in 2022 the controller collected copies of a total of 2078 bank cards, of which 655 copies were fully accessible. In assessing the fine amount, AZOP took into account as an aggravating factor that financial data is particularly sensitive data and the controller therefore should have taken special measures to protect it. As a mitigating circumstance, it was taken into account that the controller had announced that it would bring its processing procedures in line with the GDPR and had deleted all secured copies of the bank cards. GDPR Articles: Art. 6 (1) GDPR, Art. 13 (1), (2) GDPR, Art. 25 (1), (2) GDPR, Art. 32 (1) a), d) GDPR Industry: Industry and Commerce

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
Us I-4772/2023-10 A utility and municipal services enterprise, Zagrebački Holding d.o.o (the controller) provided users of its services with the option to request a copy of their bill via email. Where the name appearing in the email address differed from the user’s… US Zagreb - Us I-4772/2023-10 ·Administrative Court of Zagreb Jul 22, 2026 Personal Data Retention Period Controllers
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities
2022 EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Processing Agreement International Transfer
C-231/22 État belge v Autorité de protection des données In Case C-231/22, the Court of Justice of the European Union interpreted Article 4(7) and Article 5(2) of the GDPR in response to a preliminary reference from the Brussels Court… CJEU ·Third Chamber Jan 11, 2024 Controllers Personal Data Public Authority