In conversations about compliance with the Croatian Cybersecurity Act the figure most often quoted is ten million euro. It is accurate but incomplete, and on its own it rarely moves anything.
What moves things is the provision alongside it: the individuals responsible for managing the measures are liable personally.
The ranges
| Who | Range | Alternative |
|---|---|---|
| Essential entity | EUR 10,000 - 10,000,000 | 0.5 % to 2 % of total annual worldwide turnover |
| Important entity | EUR 5,000 - 7,000,000 | 0.2 % to 1.4 % of total annual worldwide turnover |
| Responsible individual, essential entity | EUR 1,000 - 6,000 | - |
| Responsible individual, important entity | EUR 500 - 3,000 | - |
| Failure to deliver data to NCSC-HR | EUR 2,000 - 20,000 | responsible individual EUR 200 - 1,000 |
For legal persons the higher of the two figures applies - the fixed amount or the percentage of turnover. For an entity with EUR 400 million turnover the ceiling is not 10 million but 8 million by percentage, so the fixed amount governs. Above roughly half a billion, the percentage overtakes it.
Who counts as a "responsible individual"
Article 29 is precise, and broader than expected. Responsible for implementing the measures are:
- members of the management bodies of essential and important entities
- heads of state administration bodies and other state bodies
- executive bodies of local and regional self-government units
Paragraph 4 extends the circle to other individuals who, on the basis of authority to supervise the conduct of business, a power of attorney or another authority to represent, take part in decisions about the measures or in their implementation.
A procurator, a supervisory board member deciding on security investment, or an IT director holding a power of attorney can all fall within the circle of personal liability. That liability cannot be transferred by contract to a supplier or a consultant.
Two duties a board cannot delegate
Article 29(2) requires responsible individuals to approve the measures and to verify their implementation. Paragraph 3 adds a duty that is routinely overlooked:
- responsible individuals must themselves attend appropriate training
- and must enable staff to attend training
A board that has not been trained does not meet a statutory duty, however good the system beneath it. It is one of the few requirements where the evidence has to carry a board member's name.
What affects the amount
Article 85 lists the circumstances the competent authority takes into account:
- the seriousness of the breach and the importance of the provision breached
- its duration
- previous breaches by the same entity
- the damage caused, including financial loss, effects on other services and the number of affected users
- whether the entity acted with intent or through negligence
- measures taken to prevent or mitigate the damage
- adherence to codes of conduct and certification conditions
- the level of cooperation of the responsible individuals with the authorities
Paragraph 2 of the same article lists: repeated breaches, failure to report or to resolve significant incidents, failure to remedy deficiencies when ordered to, and obstructing or impeding an audit.
In other words: a missed incident notification and obstruction of an audit are not technical oversights but aggravating circumstances that raise the penalty in themselves.
You will not be punished twice for the same conduct
A provision rarely mentioned and worth knowing: where the data protection authority has already imposed an administrative fine under the GDPR for a personal data breach arising from the same conduct, no misdemeanour charge or order may be issued under the Act for that same conduct.
This does not merge the obligations - it prevents double punishment for one act. Notification to the competent CSIRT and notification to the data protection authority remain two separate duties with their own deadlines.
How to raise this with a board
- Personal liability. A range of EUR 1,000 to 6,000 is not much money for a company, but it is very concrete for the individual paying it.
- Cooperation is scored. The level of cooperation with the authority expressly affects the penalty. An organisation that reports its own failure with a remediation plan is not in the same position as one that waits for an inspection.
- Board training is a statutory duty, not a recommendation. It is the easiest item to close and the most commonly left open.
This is an informative overview of the penalty provisions, not legal advice. The amount in any given case depends on the circumstances in Article 85 and on the decision of the authority or court. To assess your own exposure, start with the categorisation check - the category determines which range applies.
Sources
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.