Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›Regulations
Regulations

Four instruments that together set how you protect systems and data

In practice they keep overlapping at the same points: the same asset inventory, the same risk register, the same incident records. Here they are side by side - what each requires, who supervises it, and what non-compliance costs.

OG 14/2024

Cybersecurity Act

Protects systems
What it requires
  • Categorisation into essential and important entities
  • The 13 measures of Annex II at the prescribed level
  • Significant incident notification within 24 h, 72 h and 30 days
  • Independent audit or self-assessment
  • Data delivery to NCSC-HR, including IP ranges
Penalties

Up to EUR 10m or 2 % of global turnover (essential)
Up to EUR 7m or 1.4 % (important)
Responsible individuals personally: EUR 500 to 6,000

Supervision

SOA and sectoral authorities · incidents to NCSC-HR and the National CERT

Full text →
EU 2016/679

General Data Protection Regulation

Protects personal data
What it requires
  • Records of processing and a lawful basis for each
  • Impact assessment where risk is high
  • Processor contracts and transfers outside the EU
  • Data subject requests within statutory deadlines
  • Breach notification to the authority within 72 hours
Penalties

Up to EUR 20m or 4 % of global turnover,
whichever is higher

Supervision

Croatian Personal Data Protection Agency (AZOP)

Full text →
EU 2024/1689

AI Act

Governs automated decision-making
What it requires
  • Inventory of AI systems by use case
  • Classification into four risk levels
  • Prohibited practices must not be used
  • AI literacy for staff operating the systems
  • Transparency duties towards users
Penalties

Up to EUR 35m or 7 % of global turnover
for prohibited practices; lower ranges for other breaches

Supervision

Authorities designated by national implementation

Full text →
EU 2022/2554

DORA - digital operational resilience

A specific regime for financial services
What it requires
  • ICT risk management framework
  • Register of information on ICT provider contracts
  • Reporting of major ICT-related incidents
  • Resilience testing programme
  • Exit strategies for critical providers
Penalties

Under the Croatian DORA implementation act (OG 136/2024)
and sectoral legislation

Supervision

Croatian National Bank and HANFA

Full text →

Where they overlap

Three points where all four rely on the same material. An organisation that keeps them as one source reports; one that keeps them apart transcribes.

Asset inventory
The information asset register, the AI system inventory and the DORA register of information are three views of the same assets. One source, three reports.
Risk assessment
All four require a documented risk assessment with an owner and a treatment plan. Two methodologies mean two registers that diverge.
Incident reporting
Deadlines and recipients differ, but the incident record is the same. Where a personal data breach is involved, two notifications run in parallel.
You will not be penalised twice for the same conduct

Where the data protection authority has already imposed an administrative fine under the GDPR for a personal data breach arising from the same conduct, no misdemeanour charge or order may be issued under the Cybersecurity Act for that same conduct. The obligations remain separate, but the same act is not punished twice.

The penalty figures are the upper limits set by each instrument. The actual amount depends on the circumstances each instrument lists - the seriousness and duration of the breach, intent or negligence, measures taken, and the level of cooperation with the authority. This is an informative overview, not legal advice.

Not sure where you stand?

Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.