Telecommunications operator (operator of electronic communications networks and services) – €4,500,000 Fine (Croatia, 2025)

€4,500,000Agencija za zaštitu osobnih podataka24 November 2025Croatia
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer personal data to a processor in the Republic of Serbia (a group company maintaining software). Transfers had been based on Standard Contractual Clauses (SCCs) from 16 April 2020 until at the latest 27 December 2022; after that date, transfers continued without SCCs or equivalent safeguards, despite Serbia lacking an adequacy decision. The Serbian processor had administrator access to the controller’s SAP CRM database covering 847,862 data subjects, with access to extensive customer data (including name, Personal Identification Number, address, service/installation/billing addresses, contact details, email, IBAN for SEPA direct debit users, MSISDN, ICCID, and service information). The controller also failed to conduct a transfer risk assessment before commencing transfers. In addition, the controller did not transparently inform data subjects about third-country transfers, using vague “may” language in privacy policies instead of clearly stating that data are transferred outside the EEA, thereby breaching transparency obligations. Separately, the controller excessively processed employee data by collecting copies of employees’ ID cards and certificates of no criminal proceedings without a valid legal basis and contrary to the data minimisation and purpose limitation principles; notably, it disregarded its DPO’s opinion flagging such collection as excessive. Finally, the controller failed to carry out prior checks of a telesales processor’s security measures and engaged a processor lacking even basic safeguards, in breach of Article 28(1) GDPR.

GDPR Articles Cited

AI-verified

Art. 44 GDPR
Art. 5(1)(b) GDPR
Art. 6(1) GDPR
Art. 12(1) GDPR
Art. 13(1)(f) GDPR
Art. 28(1) GDPR
Art. 46(1) GDPR
View original scraped data
Art. 5(1)(b) GDPR
c)
(2) GDPR
Art. 6(1) GDPR
Art. 12(1) GDPR
Art. 13(1)(f) GDPR
Art. 28(1) GDPR
Art. 44 GDPR
Art. 46(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 5 March 2026
date discrepancy
Full Legal Summary

Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer personal data to a processor in the Republic of Serbia (a group company maintaining software). Transfers had been based on Standard Contractual Clauses (SCCs) from 16 April 2020 until at the latest 27 December 2022; after that date, transfers continued without SCCs or equivalent safeguards, despite Serbia lacking an adequacy decision. The Serbian processor had administrator access to the controller’s SAP CRM database covering 847,862 data subjects, with access to extensive customer data (including name, Personal Identification Number, address, service/installation/billing addresses, contact details, email, IBAN for SEPA direct debit users, MSISDN, ICCID, and service information). The controller also failed to conduct a transfer risk assessment before commencing transfers. In addition, the controller did not transparently inform data subjects about third-country transfers, using vague “may” language in privacy policies instead of clearly stating that data are transferred outside the EEA, thereby breaching transparency obligations. Separately, the controller excessively processed employee data by collecting copies of employees’ ID cards and certificates of no criminal proceedings without a valid legal basis and contrary to the data minimisation and purpose limitation principles; notably, it disregarded its DPO’s opinion flagging such collection as excessive. Finally, the controller failed to carry out prior checks of a telesales processor’s security measures and engaged a processor lacking even basic safeguards, in breach of Article 28(1) GDPR.

Related Enforcement Actions (0)

No other enforcement actions found for Telecommunications operator (operator of electronic communications networks and services) in HR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

24 November 2025

Authority

Agencija za zaštitu osobnih podataka

Fine Amount

€4,500,000

Enforcement Tracker ID

ETid-2937

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Telecommunications operator (operator of electronic communications networks and services) - Croatia (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: