Skip to content
Enforcement · Croatian Data Protection Authority (azop) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Betting company: Insufficient legal basis for data processing

The Croatian DPA (AZOP) has imposed a fine of EUR 15,000 on a data controller operating in the gambling and betting sector.

€15,000 Fine
Betting company
CROATIA
Art. 6 GDPR Art. 7 GDPR Art. 13 GDPR

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Croatian DPA (AZOP) has imposed a fine of EUR 15,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal data of data subjects through cookies without providing them the opportunity to give or withdraw consent for such processing in an informed and voluntary manner, violating Art. 6 (1) a) GDPR and Art. 7 GDPR. In cases where personal data processing relies on consent and serves multiple purposes, the consent mechanism, such as the cookie banner, must be clearly distinguishable, easily accessible, and use language that is clear and simple to understand. However, in this specific case, the data controller failed to separate the cookie banner, preventing data subjects from giving clear consent for different purposes like marketing or analytics. Furthermore, an examination of the privacy policy of the data controller revealed deficiencies.

§

This document lacked information regarding the legal basis for data processing, types of cookies used, the purpose of each cookie, and the duration of cookie storage. Consequently, data subjects were not adequately informed about the processing of their personal data, breaching Art. 13 (1) and (2) GDPR. This failure to inform data subjects about cookie processing violated the transparency principle, depriving website visitors of crucial information about how their data was handled. GDPR Articles: Art. 6 (1) a) GDPR, Art. 7 GDPR, Art. 13 (1), (2) GDPR Industry: Industry and Commerce

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) Jan 12, 2023 Supervisory Authorities IP Address Supervision
HvJ EU 9 januari 2025, C‑394/23 (Mousse) Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20… HvJ EU 9 januari 2025, C‑394/23 (Mousse). Jan 9, 2025 IP Address Retention Period Identification
C-154/21 RW v Österreichische Post AG The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article… First Chamber Jan 12, 2023 Right of Access Personal Data Recipient
C-422/24 Case C-422/24 - AB Storstockholms Lokaltrafik. A new page has been created with the following information: "" Jan 7, 2026 Personal Data Fairness & Transparency Controllers
C-17/22 HTB Neunte Immobilien Portfolio geschlossene Investment UG & Co. KG and Ökorenta Neue Energien Ökostabil IV geschlossene Investment GmbH & Co. KG v Müller Rechtsanwaltsgesellschaft mbH and Others The Court of Justice of the European Union (Fourth Chamber) issued a preliminary ruling in joined cases C-17/22 and C-18/22, originating from the Amtsgericht München, concerning… Fourth Chamber Sep 12, 2024 Legitimate Interest Personal Data Fairness & Transparency