Legal framework and regulations related to digital identity and privacy

Site: Loomen za stručna usavršavanja
Course: Security and Privacy in the Digital Environment
Book: Legal framework and regulations related to digital identity and privacy
Printed by: Gost (anonimni korisnik)
Date: Tuesday, 28 July 2026, 11:07 PM

1. Introduction

In today’s digital society, where almost all of our activities—from personal communication to financial transactions—take place online, the protection of privacy and the security of digital identities have become critical challenges. Announcements of new technologies such as Web3, in which privacy and security are expected to play a key role, are still in their early stages. To ensure user safety, reduce the risks of malicious attacks and unauthorised access, and provide legal protection within the still-prevailing Web2 environment, it is essential to have an appropriate legal framework and regulatory measures in place. Digital identities, which include personal data, biometric data, passwords, and other sensitive information, must be protected by legal norms that define users’ rights, organisations’ obligations, and liability for potential data breaches.

The legal framework governing digital identities and privacy enables the establishment of clear guidelines regarding data collection, processing, and storage, as well as procedures to follow in the event of security incidents. It is also important to understand the role of regulatory bodies in implementing legislation, safeguarding users’ privacy rights, and addressing transnational challenges arising from the global nature of the internet. Traditional laws dealing with privacy and data protection often fail to meet the needs of the digital age, which makes continuous alignment with new technologies and ongoing changes in the digital environment essential.

In this context, regulations such as the European General Data Protection Regulation (GDPR), the U.S. California Consumer Privacy Act (CCPA), and other laws worldwide provide a legal foundation for the protection of digital identities. All of these regulations aim to ensure transparency in data usage, guarantee users control over their personal information, and take appropriate measures against misuse.

This legal framework is not only a tool for regulating behavior in the digital space, but also an important safeguard of individual rights in an increasingly networked, connected, and digital world. Understanding these legal norms is crucial for every internet user, as it enables safe and responsible participation in the digital economy, while simultaneously protecting fundamental human rights to privacy and personal security.

To learn how the GDPR protects users’ personal data in the EU and how it applies to digital identity management, please refer to this book.

2. How GDPR protects user data in the EU

The GDPR (General Data Protection Regulation) is the legal framework of the European Union that protects the personal data of EU citizens and regulates how organisations collect, store, and process such data.

The GDPR was adopted by the European Parliament on 27 April 2016, and has been applicable in all EU Member States since 25 May 2018.

The GDPR was adopted to strengthen and harmonise data protection regulation across the European Union. Its primary purpose is to ensure the privacy and security of EU citizens’ personal data by granting individuals greater control over their information. The GDPR establishes strict guidelines for the collection, storage, processing, and sharing of personal data, aiming to prevent misuse or unauthorised access.

In addition to granting users greater control, the GDPR also imposes strict requirements on organisations that process personal data, including the obligation to conduct Data Protection Impact Assessments (DPIAs), notify authorities and individuals of data breaches, and implement appropriate technical and organisational security measures.

The following links and documents are available in Croatian only. Participants may use free AI-powered translation tools to access the provided materials.

The GDPR is accompanied by strong sanctions for violations, including administrative fines of up to €20 million or up to 4 % of an organisation’s total annual global turnover, depending on the severity of the infringement. There are numerous examples of organisations being fined for non-compliance with the GDPR:

  1. Google (2019) – The French data protection authority (CNIL) fined Google €50 million for failing to comply with GDPR requirements related to transparency and informing users about their rights. According to the regulator, Google did not clearly explain how users’ data were collected and processed, which violated GDPR rules on user information. Source

  2. British Airways (2018) – The company was fined £183 million by the UK data protection authority (ICO), later reduced to £20 million, following a security incident in which the personal data of more than 500,000 customers was exposed. Individuals were not notified in a timely manner, and several aspects of the GDPR relating to data processing and users’ rights were breached. Source

  3. Marriott International (2020) – Marriott was fined £18.4 million for non-compliance with the GDPR following a 2018 security incident in which the personal data of 339 million customers were compromised. The regulator found that Marriott had failed to implement appropriate data protection measures and had not informed users in a timely manner. Source

  4. A1 (2022) – The Croatian Personal Data Protection Agency (AZOP) fined the telecommunications company A1 HRK 2.15 million following a cyberattack that compromised the personal data of approximately 100,000 users. Source

Link to the Law

3. Key principles of GDPR

Lawfulness, Fairness, and Transparency
This principle requires that personal data be processed lawfully, fairly, and in a transparent manner in relation to the data subject. Data processing must be based on a clearly defined legal basis, such as the user’s consent, the existence of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest, or the legitimate interests of the data controller.

Purpose Limitation
Personal data must be collected for specified, explicit, and legitimate purposes and must not be further processed in a manner incompatible with those purposes. This means that an organisation must clearly define and communicate to users why their data are being collected and processed and must not use them for other purposes.

Example: If an organisation collects data to fill an order (e.g., name, address, telephone number), those data may not be used for sending marketing materials unless the user has explicitly consented to this.

Data Minimisation
This principle means that only personal data that are necessary to achieve the stated purposes should be collected. Organisations must not collect or process data that are irrelevant or unnecessary for fulfilling the purpose of processing.

Example: If an organisation needs to process an order, it should collect only the data relevant to fulfilling that order (e.g., name, address, contact information), and not additional data such as the user’s hobbies.

Accuracy
Personal data must be accurate and, where necessary, kept up-to-date. Organisations must take all reasonable steps to ensure that inaccurate personal data are rectified or erased without delay. This principle ensures that individuals are not adversely affected by incorrect information that could be used against them.

Example: If a user changes their address, the organisation should update the data to avoid sending packages to the old address.

Storage Limitation
Personal data may be stored only for as long as necessary for the purposes for which they were collected. Once the data are no longer needed, they must be erased or anonymised to prevent further processing. This principle ensures that data are not retained longer than necessary, thereby reducing the risk of misuse.

Example: If data are collected for the performance of a contract, they must be deleted after a reasonable period following the completion of the contract, unless the law requires longer retention (e.g., accounting records).

Integrity and Confidentiality
Personal data must be processed in a manner that ensures their security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical and organisational measures. This includes data encryption, authentication, access control, backups, and other security methods.

Example: Using encryption for the transmission of sensitive data (e.g., credit card information or personal identification numbers) ensures that the data will not be disclosed in the event of a cyberattack.

Accountability
Data controllers (organisations that process personal data) must be responsible for compliance with all of the above principles and must be able to demonstrate their compliance with the GDPR. This means that organisations must implement appropriate policies, procedures, and measures to ensure GDPR compliance and be prepared for supervision and audits conducted by the regulatory authority (AZOP in Croatia).

Example: An organisation must maintain records of all data processing activities, conduct regular security audits, and ensure that employees are trained in data protection.

4. How GDPR protects users' personal data

How can you exercise your rights guaranteed under the General Data Protection Regulation (GDPR) and the Act on the Implementation of the General Data Protection Regulation?

More information is available on the AZOP website: Source.

  • Right of access to personal data – Article 15
  • Right to rectification of personal data – Article 16
  • Right to erasure of personal data (“right to be forgotten”) – Article 17
  • Right to restriction of processing of personal data – Article 18
  • Right to object – Article 21
  • Right to data portability – Article 20
  • Right related to automated individual decision-making, including profiling – Article 22
  • Obligation to report a personal data breach – Organisations must report a personal data breach to the supervisory authority and, where applicable, to affected individuals within 72 hours. To exercise your rights, you should contact the company or organisation that processes your personal data, i.e., the data controller or processor.

If the data controller does not comply with your request and you believe that your right to the protection of personal data has been violated, you may contact the Croatian Personal Data Protection Agency (AZOP) and submit a request for the determination of a violation of your rights.

5. Privacy Notice

You need to create a paper "Privacy Notice" for publication on the website.

A suggested structure of the paper can be found at link.

The previous link is available in Croatian only. Participants may use free AI-powered translation tools to access the provided materials.

Accessibility

Background Colour Background Colour

Font Face Font Face

Font Size Font Size

1

Text Colour Text Colour

Font Kerning Font Kerning

Image Visibility Image Visibility

Letter Spacing Letter Spacing

0

Line Height Line Height

1.2

Link Highlight Link Highlight