Back to Feed
GDPRAug 14, 2026

US Zagreb - Us I-4772/2023-10

Croatian court upholds DPA's €25,000 fine against Zagrebački Holding for GDPR violations.

Summary

The Administrative Court of Zagreb upheld a €25,000 fine imposed by the Croatian DPA on Zagrebački Holding. The company was penalized for failing to transparently inform users about the processing of ID copies and for using an inadequate identity verification procedure when sending bills via email. The DPA found violations of GDPR Articles 13(1)(c), 13(2)(a), 13(2)(e), and 25(2).

Full text

Help US Zagreb - Us I-4772/2023-10: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 09:01, 14 August 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators275 edits Tag: Decisions [1.0] (No difference) Latest revision as of 09:01, 14 August 2026 US Zagreb - Us I-4772/2023-10 Court: US Zagreb (Croatia) Jurisdiction: Croatia Relevant Law: Article 13(1)(c) GDPR Article 13(2)(a) GDPR Article 13(2)(e) GDPR Article 25(2) GDPR Decided: 22.07.2026 Published: Parties: Zagrebački Holding d.o.o. National Case Number/Name: Us I-4772/2023-10 European Case Law Identifier: Appeal from: AZOP (Croatia)UP/1-034-01/23-01/21 Appeal to: Unknown Original Language(s): Croatian Original Source: Tražilica odluka sudova RH (in Croatian) Initial Contributor: ds A court upheld the DPA's €25,000 fine against a controller for failing to transparently inform users about ID-copy processing and for using an inadequate identity-verification procedure when sending copies of bills by email. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A utility and municipal services enterprise, Zagrebački Holding d.o.o. (the controller) provided users of its services with the option to request a copy of their bill via email. Where the name appearing in the email address differed from the user’s name, the controller requested a copy of an identification document as part of the process of verifying the identity of its users. It treated that discrepancy as an indication of possible identity fraud. According to the controller, users were asked to redact any information on the document that was not necessary for identification. In addition, the copies were deleted once the relevant purpose had been fulfilled and access to them was limited to a small number of authorised employees. The Croatian DPA (AZOP) found that the controller had not adequately informed users of the legal basis for collecting copies of identification documents, the applicable retention period, or whether providing such a copy was mandatory and what the consequences of not providing it would be. It held that the controller had infringed Article 13(1)(c) GDPR, Article 13(2)(a) GDPR and Article 13(2)(e) GDPR. Furthermore, it found that the company had not implemented appropriate technical and organizational measures for the process of verifying the identity of users who requested copies of bills via email, in violation of Article 25(2) GDPR. It fined the controller €25,000. The controller challenged the decision before the Administrative Court of Zagreb. It argued that it had published information on its website regarding the processing of personal data. It claimed that the information had been modelled on guidelines published by the EDPB. The controller further alleged that users had been informed that the data would not be retained for longer than was necessary for the purpose of the processing. It also argued that it did not collect an excessive amount of data, as it asked users to redact unnecessary information and that copies were deleted after verification was completed. The DPA pointed out that the information regarding data retention was contradictory or open to different interpretations, and that the controller’s deficiencies were not corrected even when a user requested clarification directly from the controller. Regarding the identification process, the DPA argued that the controller could have achieved the same objective without requesting copies of identification documents, for example by using previously verified email addresses. It considered that a discrepancy between a user’s name and the name associated with an email address did not constitute a reliable criterion for detecting potential identity fraud. According to the DPA, the procedure was not designed with sufficient consideration of the nature, context, and risks of the specific processing, and the mere instruction to users to redact parts of their identification document did not constitute a sufficient safeguard. Holding The court held that the controller had not transparently provided users with the legal basis for collecting copies of identification documents. It found that this information was neither available in the controller’s published documents nor provided when users requested it directly via email. The court therefore upheld the finding of an infringement of Article 13(1)(c) GDPR. The court further found that the information concerning the retention period could be interpreted in different ways. In response to a specific inquiry, the controller should have provided clear information on the duration of the storage. It ruled that this amounted to an infringement of Article 13(2)(a) GDPR. The court also noted that one user had been told that the requested data could not be provided without an identification document, while the controller later stated before the DPA that users unwilling to send a copy could instead present it in person at the Holding Centre in Zagreb. In light of the lack of clear information as to whether providing the identification document was mandatory and the consequences of not providing it, the court upheld the finding of an infringement of Article 13(2)(e) GDPR. Moreover, the court agreed with the DPA that the controller had not implemented appropriate technical and organisational measures for the identification procedure. It determined that the format or name of an email address did not provide sufficient assurance that a request actually originated from the user concerned, while the procedure effectively required certain users to provide a copy of an identification document in order to communicate remotely. The court pointed out that processing such copies could pose a high risk to individuals’ rights, such as identity theft. The court considered that the controller could instead have established a secure email-verification procedure, allowing users to verify an email address for communications and the delivery of bills, while ensuring that the identification procedure applied consistently regardless of the structure of the email address. It therefore upheld the finding that the controller had failed to implement appropriate safeguards in breach of Article 25(2) GDPR. Furthermore, the court rejected the controller’s reliance on the EDPB’s practice, noting that it concerned a different context, namely the verification of the identity of individuals exercising their rights under the GDPR. It acknowledged that an ID copy may be justified in higher-risk situations, such as certain GDPR rights requests involving sensitive or extensive data, or where the controller has no ongoing relationship with the requester. However, it held that this did not affect the infringements established in relation to the controller’s procedure for issuing copies of bills. The court upheld the DPA’s €25,000 fine. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Croatian original. Please refer to the Croatian original for more details. REPUBLIC OF CROATIA ADMINISTRATIVE COURT IN ZAGREB Zagreb, Avenija Dubrovnik 6 Case No.: 4772/2023-10 IN THE NAME OF THE REPUBLIC OF CROATIA JUDGMENT Administrative Court in Zagreb, before Judge Ivana Horvat, with the participation of Ankica Zorić, court clerk, in the administrative dispute of the plaintiff ZAGREB HOLDING d.o.o., OIB: 85584865987, Zagreb, Ulica grada Vukovara 41, represented by its attorney, Andrijana Kaštelan, lawyer from Zagreb, Savska cesta 32, against the defendant, the Personal Data Protection Agency, OIB: 28454963989, Zagreb, Metela Ožegovića 16, for the protection of individuals with regard to the processing of personal data and on the free movement of such

Entities

Zagrebački Holding (vendor)GDPR (product)