Zdravko Vukić, director of the Croatian Personal Data Protection Agency
Zdravko Vukić graduated from the Faculty of Law at the University of Osijek and holds a master’s degree in public administration. He further pursued studies in business economy and globalization in Zagreb, earning a master’s degree in economics from Libertas International University. Zdravko also possesses an internationally accredited ISO/IEC 27001:2022 Lead Auditor certificate in information security management systems, specializing in information security, cyber security, and privacy protection. Currently, he is finalizing his postgraduate studies with a thesis on Technical and Organizational Measures and Data Security.
From 2005 to 2016, he served as the Chief Human Resources Officer overseeing the organization’s employees and legal affairs. Additionally, between 2008 and 2016, he held the position of Data Protection Officer.
Between 2016 and 2020, Zdravko held the role of Assistant Minister at the Ministry of Construction and Physical Planning, where he supervised the operations of the Directorates for Inspection Affairs, Supervision, and Information System Development.
In 2020, he was appointed as the Director of the Croatian Personal Data Protection Agency, and in February 2024 he was re-elected for another four-year term as director. On 19 June 2024 the Members of the European Data Protection Board (EDPB) elected Zdravko Vukić as Deputy Chair of the European Data Protection Board.
Zdravko is a guest lecturer on personal data protection at various faculties in Croatia and is a member of the National Cybersecurity Council. He is a guest lecturer on personal data protection at several faculties in Croatia and a member of the National Cybersecurity Council.
He has also been active recently in the European Union instrument for institutional cooperation between Public Administrations of EU Member States and non-EU countries aimed at harmonizing the national legislation with the EU legislation in the field of personal data protection, as well as in EU-funded project ARC implemented successfully in cooperation with the Irish Data Protection Authority.
Under his leadership, in 2022 the Croatian Personal Data Protection Agency organized the Spring Conference of the European Supervisory Authorities, the most important forum for cooperation among European regulatory authorities.
He played a key role in the implementation of the EU-funded project ARC I, implemented with Irish DPA, which aimed to support SMEs in aligning with the GDPR. Currently, he serves as a member of the Steering Committee for the ARC II project. This collaborative venture between the Croatian DPA and Garante Privacy focuses on creating an innovative GDPR compliance tool to aid SMEs and DPOs in complying with data protection regulations effectively.
About the Agency
Tasks of the Agency are to:
- monitor and enforce the application of the GDPR;
- promote public awareness and understanding of the risks, rules, safeguards and rights in relation to processing. Activities addressed specifically to children shall receive specific attention;
- advise the Government of the Republic of Croatia, the Croatian Parliament and other institutions and bodies on legislative and administrative measures relating to the protection of natural persons’ rights and freedoms with regard to processing;
- promote the awareness of controllers and processors of their obligations under the GDPR and Act on the Implementation of the GDPR;
- upon the request, to provide information to any data subject concerning the exercise of their rights under the GDPR and Act on the Implementation of the GDPR, if appropriate, cooperate with the supervisory authorities in other Member States to that end;
- handle complaints lodged by a data subject, or by a body, organisation or association in accordance with Article 80 of the GDPR, and investigate, to the extent appropriate, the subject matter of the complaint and inform the complainant of the progress and the outcome of the investigation within a reasonable period, in particular if further investigation or coordination with another supervisory authority is necessary;
- cooperate with, including sharing information and provide mutual assistance to, other supervisory authorities with a view to ensuring the consistency of application and enforcement of the GDPR;
- conduct investigations on the application of this Regulation, including on the basis of information received from another supervisory authority or other public authority;
- monitor relevant developments, insofar as they have an impact on the protection of personal data, in particular the development of information and communication technologies and commercial practices;
- adopt standard contractual clauses referred to in Article 28(8) and in point (d) of Article 46(2) GDPR;
- establish and maintain a list in relation to the requirement for data protection impact assessment pursuant to Article 35(4) of the GDPR;
- give advice on the processing operations referred to in Article 36(2) of the GDPR;
- encourage the drawing up of codes of conduct pursuant to Article 40(1) and provide an opinion and approve such codes of conduct which provide sufficient safeguards, pursuant to Article 40(5) of the GDPR;
- encourage the establishment of data protection certification mechanisms and of data protection seals and marks pursuant to Article 42(1), and approve the criteria of certification pursuant to Article 42(5) of the GDPR;
- where applicable, carry out a periodic review of certifications issued in accordance with Article 42(7) of the GDPR;
- conduct the accreditation of a body for monitoring codes of conduct pursuant to Article 41 and of a certification body pursuant to Article 43 of the GDPR;
- authorise contractual clauses and provisions referred to in Article 46(3) of the GDPR; • approve binding corporate rules pursuant to Article 47 of the GDPR;
- keep internal records of infringements of this Regulation and of measures taken in accordance with Article 58(2) of the GDPR. The investigative powers of the Agency are to:
- order the controller and the processor, and, where applicable, the controller’s or the processor’s representative to provide any information it requires for the performance of its tasks;
- carry out investigations in the form of data protection audits;
- carry out a review on certifications issued pursuant to Article 42(7) of the GDPR;
- notify the controller or the processor of an alleged infringement of the GDPR and Act on the Implementation of the GDPR;
- obtain, from the controller and the processor, access to all personal data and to all information necessary for the performance of its tasks;
- obtain access to any premises of the controller and the processor, including to any data processing equipment and means. The corrective powers of the Agency are to:
- issue warnings to a controller or processor that intended processing operations are likely to infringe provisions the GDPR and Act on the Implementation of the GDPR;
- issue reprimands to a controller or a processor where processing operations have infringed provisions of the GDPR and Act on the Implementation of the GDPR;
- order the controller or the processor to comply with the data subject’s requests to exercise his or her rights pursuant to the GDPR and Act on the Implementation of the GDPR
- order the controller or processor to bring processing operations into compliance with the provisions of the GDPR and Act on the Implementation of the GDPR, where appropriate, in a specified manner and within a specified period; • order the controller to communicate a personal data breach to the data subject; • impose a temporary or definitive limitation including a ban on processing;
- order the rectification or erasure of personal data or restriction of processing pursuant to Articles 16, 17 and 18 and the notification of such actions to recipients to whom the personal data have been disclosed pursuant to Article 17(2) and Article 19 of the GDPR;
- withdraw a certification or to order the certification body to withdraw a certification issued pursuant to Articles 42 and 43 of the GDPR, or to order the certification body not to issue certification if the requirements for the certification are not or are no longer met;
- impose an administrative fine pursuant to Article 83 of the GDPR, in addition to, or instead of measures, depending on the circumstances of each individual case;
- order the suspension of data flows to a recipient in a third country or to an international organisation. The advisory powers of the Agency are to:
- advise the controller in accordance with the prior consultation procedure referred to in Article 36 of the GDPR;
- issue, on its own initiative or on request, opinions to the Croatian parliament, the Government of the Republic of Croatia and to other institutions and bodies as well as to the public on any issue related to the protection of personal data;
- authorise processing referred to in Article 36(5) of the GDPR, if the law of the MS requires such prior authorisation;
- issue an opinion and approve draft codes of conduct pursuant to Article 40(5) of the GDPR;
- accredit certification bodies pursuant to Article 43 of the GDPR;
- issue certifications and approve criteria of certification in accordance with Article 42(5) of the GDPR;
- adopt standard data protection clauses referred to in Article 28(8) and in point (d) of Article 46(2) of the GDPR;
- authorise contractual clauses referred to in point (a) of Article 46(3) of the GDPR;
- authorise administrative arrangements referred to in point (b) of Article 46(3) of the GDPR;
- approve binding corporate rules pursuant to Article 47 of the GDPR. According to the Article 6 of the Act on the Implementation of the GDPR, in addition to its powers laid down by the GDPR, the Agency shall perform the following duties:
- when laid down by a special law, it may initiate and has the right to participate in criminal, misdemeanour, administrative and other court and out-of-court proceedings for breaches of the GDPR and the Act on the Implementation of the GDPR,
- adopts the Criteria for determination of the amount of the compensation of administrative costs,
- publishes individual decisions on the Agency’s website in accordance with Articles 18 and 48 of Act on the Implementation of the GDPR,
- initiates and conducts appropriate procedures against responsible persons for breaches of the GDPR and Act on the Implementation of the GDPR,
- carries out its duties of the independent supervisory authority for monitoring the implementation of Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA, unless otherwise laid down by special regulations and carries out other duties laid down by law. Cooperation with state administration bodies and other bodies Central state administration bodies and other public authorities shall submit to the Agency the drafts of proposals of laws and proposals of other regulations governing issues related to personal data.