[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fyLvUA7ghl_lqFteY0j4mRfG7BXnOQkIqK2WKyhr3eVQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"3669f0ab-6bb8-4a66-bba2-3f52312f8dc4","croatian-dpa-fines-zagrebaki-holding-25000-for-gdpr-transparency-and-identity-verification-failures","e175e805-4656-484d-bfe0-0e53c2b173de","Croatian DPA Fines Zagrebački Holding €25,000 for GDPR Transparency and Identity Verification Failures","Zagrebački Holding violated GDPR by failing to clearly inform users how their ID copies were being processed and by using an inadequate identity verification method when delivering bills via email. These failures breached core GDPR transparency obligations (Articles 13(1)(c) and 13(2)(a\u002Fe)) and the data protection by design and by default principle (Article 25(2)). The case highlights that organizations must not only collect data lawfully but must also communicate processing activities clearly and implement proportionate, fit-for-purpose verification mechanisms. Regulators are increasingly scrutinizing everyday operational processes — such as billing and customer onboarding — not just large-scale data breaches. A €25,000 fine and adverse court ruling serve as a reminder that procedural GDPR compliance is enforceable and costly to ignore.","**Immediate actions:**\n- Audit all customer-facing data collection points (forms, emails, portals) to ensure GDPR-compliant privacy notices are present and cover all processing purposes.\n- Replace or strengthen identity verification procedures for email-based document delivery to meet minimum adequacy standards under GDPR Article 25(2).\n\n**Long-term improvements:**\n- Embed a Data Protection by Design review into the development and procurement lifecycle for any process that handles personal data or identity documents.\n- Establish a periodic GDPR compliance review programme covering Articles 13\u002F14 notices across all business units and customer touchpoints.\n- Train operational and customer-service staff on transparency obligations and the lawful handling of identity documents under GDPR.\n\n**Detection & governance measures:**\n- Appoint or empower a Data Protection Officer (DPO) to conduct regular internal audits of data processing disclosures and verification workflows.\n- Implement a compliance monitoring dashboard to track open GDPR obligations, outstanding privacy notice updates, and DPA correspondence.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 13(1)(c) — information on purposes and legal basis of processing","GDPR Article 13(2)(a) — retention period information","GDPR Article 13(2)(e) — right to lodge a complaint with a supervisory authority","GDPR Article 25(2) — Data Protection by Default","NIST SP 800-53 PT-2 (Authority to Process Personally Identifiable Information)","NIST SP 800-53 PT-5 (Privacy Notice)","NIST Privacy Framework PR.PO-P1 (Policies and procedures for data processing transparency)","CIS Control 3 — Data Protection","ISO\u002FIEC 29100:2011 — Privacy Framework (Principle 6: Openness, Transparency and Notice)","ITIL — Service Design: Information Security and Compliance Management","published","2026-08-14T10:21:01.499082+00:00","2026-08-14T10:21:01.387+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=US_Zagreb_-_Us_I-4772\u002F2023-10&diff=52693&oldid=0","us-zagreb-us-i-4772-2023-10-ef8bbf","US Zagreb - Us I-4772\u002F2023-10",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]