2. How GDPR protects user data in the EU

The GDPR (General Data Protection Regulation) is the legal framework of the European Union that protects the personal data of EU citizens and regulates how organisations collect, store, and process such data.

The GDPR was adopted by the European Parliament on 27 April 2016, and has been applicable in all EU Member States since 25 May 2018.

The GDPR was adopted to strengthen and harmonise data protection regulation across the European Union. Its primary purpose is to ensure the privacy and security of EU citizens’ personal data by granting individuals greater control over their information. The GDPR establishes strict guidelines for the collection, storage, processing, and sharing of personal data, aiming to prevent misuse or unauthorised access.

In addition to granting users greater control, the GDPR also imposes strict requirements on organisations that process personal data, including the obligation to conduct Data Protection Impact Assessments (DPIAs), notify authorities and individuals of data breaches, and implement appropriate technical and organisational security measures.

The following links and documents are available in Croatian only. Participants may use free AI-powered translation tools to access the provided materials.

The GDPR is accompanied by strong sanctions for violations, including administrative fines of up to €20 million or up to 4 % of an organisation’s total annual global turnover, depending on the severity of the infringement. There are numerous examples of organisations being fined for non-compliance with the GDPR:

  1. Google (2019) – The French data protection authority (CNIL) fined Google €50 million for failing to comply with GDPR requirements related to transparency and informing users about their rights. According to the regulator, Google did not clearly explain how users’ data were collected and processed, which violated GDPR rules on user information. Source

  2. British Airways (2018) – The company was fined £183 million by the UK data protection authority (ICO), later reduced to £20 million, following a security incident in which the personal data of more than 500,000 customers was exposed. Individuals were not notified in a timely manner, and several aspects of the GDPR relating to data processing and users’ rights were breached. Source

  3. Marriott International (2020) – Marriott was fined £18.4 million for non-compliance with the GDPR following a 2018 security incident in which the personal data of 339 million customers were compromised. The regulator found that Marriott had failed to implement appropriate data protection measures and had not informed users in a timely manner. Source

  4. A1 (2022) – The Croatian Personal Data Protection Agency (AZOP) fined the telecommunications company A1 HRK 2.15 million following a cyberattack that compromised the personal data of approximately 100,000 users. Source

Link to the Law

Accessibility

Background Colour Background Colour

Font Face Font Face

Font Size Font Size

1

Text Colour Text Colour

Font Kerning Font Kerning

Image Visibility Image Visibility

Letter Spacing Letter Spacing

0

Line Height Line Height

1.2

Link Highlight Link Highlight