Telecommunications operator (operator of electronic communications networks and services) – €4,500,000 Fine (Croatia, 2025)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A telecommunications operator in Croatia was fined €4.5 million for serious data protection violations. The company transferred customer data to a processor in Serbia without proper safeguards, putting 847,862 customers at risk. This case shows the importance of protecting customer data when transferring it across borders.
What happened
The telecommunications operator was fined for transferring customer personal data to a Serbian processor without adequate safeguards.
Who was affected
847,862 customers whose personal data was transferred to a processor in Serbia without proper protections.
What the authority found
The authority ruled that the company violated multiple GDPR requirements, including failing to ensure safe data transfers and not informing customers transparently about these transfers.
Why this matters
This ruling emphasizes that companies must take data protection seriously, especially when transferring data internationally. Businesses should ensure they have strong safeguards in place to protect customer information.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer personal data to a processor in the Republic of Serbia (a group company maintaining software). Transfers had been based on Standard Contractual Clauses (SCCs) from 16 April 2020 until at the latest 27 December 2022; after that date, transfers continued without SCCs or equivalent safeguards, despite Serbia lacking an adequacy decision. The Serbian processor had administrator access to the controller’s SAP CRM database covering 847,862 data subjects, with access to extensive customer data (including name, Personal Identification Number, address, service/installation/billing addresses, contact details, email, IBAN for SEPA direct debit users, MSISDN, ICCID, and service information). The controller also failed to conduct a transfer risk assessment before commencing transfers. In addition, the controller did not transparently inform data subjects about third-country transfers, using vague “may” language in privacy policies instead of clearly stating that data are transferred outside the EEA, thereby breaching transparency obligations. Separately, the controller excessively processed employee data by collecting copies of employees’ ID cards and certificates of no criminal proceedings without a valid legal basis and contrary to the data minimisation and purpose limitation principles; notably, it disregarded its DPO’s opinion flagging such collection as excessive. Finally, the controller failed to carry out prior checks of a telesales processor’s security measures and engaged a processor lacking even basic safeguards, in breach of Article 28(1) GDPR.
Related Enforcement Actions (0)
No other enforcement actions found for Telecommunications operator (operator of electronic communications networks and services) in HR
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
24 November 2025
Authority
Agencija za zaštitu osobnih podataka
Fine Amount
€4,500,000
Enforcement Tracker ID
ETid-2937
About this data
Cite as: Cookie Fines. Telecommunications operator (operator of electronic communications networks and services) - Croatia (2025). Retrieved from cookiefines.eu
Last updated: