Croatia Croatia

Gambling operator

2,590,000 €

GDPR enforcement action by Croatian Data Protection Authority (azop) on 2026.

Rank · Sector
#18
of 628 in Industry and Commerce
Rank · Croatia
#4
of 44
Rank · All fines
#120
of 3,170

Case details

Authority
Croatian Data Protection Authority (azop)
Date
2026
Controller / Processor
Gambling operator
Sector
Industry and Commerce
Quoted Articles
Art. 5 (1) a), c) GDPR, Art. 6 (1) GDPR, Art. 7 GDPR, Art. 9 (1) GDPR, Art. 12 (1) GDPR, Art. 13 GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The Croatian DPA has imposed a fine of EUR 2,590,000 on a gambling operator. During an ex officio investigation into the controller's operations, the authority found that, while the controller offered to verify data subjects' eligibility to gamble by checking ID cards, they also offered to verify them via RFID chip or fingerprint. In order to make fingerprint verification possible, the controller scanned four of the data subjects' fingerprints, despite stating that only two were scanned. The consent form, which stated that two fingerprints were to be processed, was signed by 34,933 data subjects. The controller stated that the extra fingerprints were being stored in case of skin damage. However, the authority found that this purpose was not necessary for identification, as other forms of ID could be used. Furthermore, the consent form given to data subjects mixed several different processing activities and purposes for identification and biometric data; therefore, the consent given was neither specific nor free. The stated purposes were also contradictory.

Open original source Links to the regulator's original publication or another source.

Related fines