RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

Three bodies of law that together set how you protect systems and data

The Cyber Security Act, the General Data Protection Regulation and the AI Act meet at the same points. This page shows where, and who supervises each of them.

Why these three belong on the same page

They are grouped not by subject matter but because they ask the same people for the same records.

The Cyber Security Act (ZKS) protects the system, the General Data Protection Regulation the data inside it, and the AI Act governs what may be done with that data automatically.

The NIS2 directive has no page of its own here, because for an entity in Croatia it carries no separate obligations. It entered Croatian law through the Cyber Security Act, so it is read through that Act, and supervision follows that Act too.

The three meet at three points. At the inventory, where the list of network and information systems, the record of processing activities and your own list of AI tools describe the same assets from three sides. At risk assessment, where a fundamental rights impact assessment may draw on a data protection impact assessment already carried out and supplement it. And at incidents, where one event can trigger two notifications, each to its own authority and on its own clock.

So there is no reason to run them separately. None has precedence over the others and none displaces another, so the work is done once, and only the forms, the deadlines and the recipient differ.

The three

Each has its own page, with who is covered, the deadlines, the supervision and the fines.

Who supervises what in Croatia

The authorities differ, so the proceedings run separately even when the trigger is the same.

LAWSUPERVISION IN CROATIANOTE
The Cyber Security ActThe central state authority for cyber security, and for the public sector the central state authority for information securityAnnex III to the Act allocates competence by sector and names the competent CSIRT for each
The General Data Protection RegulationThe Croatian Personal Data Protection AgencyThe supervisory authority under Article 4 of Act NN 42/2018; a data subject complains to it under Article 77 of the GDPR
The AI ActThe national market surveillance authority has not yet been designatedCroatia has notified its fundamental rights authorities, among them AZOP and the ombudswoman; the implementing act is still being prepared

The NIS2 directive has no supervisory authority of its own in Croatia, because it applies through the Cyber Security Act. Providers of general-purpose AI models are supervised not by a national authority but by the European Commission, under Article 101 of the Act.

Frequently asked questions

The questions that only come up once the three are set side by side.

One incident, two notifications. Which deadline falls first?

The early warning to the competent CSIRT falls first, no later than 24 hours from becoming aware, under Article 66 of Regulation NN 135/2024. Two things then fall due at 72 hours: the initial incident notification to the competent CSIRT under Article 67 of the Regulation, and the personal data breach notification to the supervisory authority under Article 33 of the GDPR. The two clocks do not necessarily start at the same moment, because one runs from awareness of the incident and the other from awareness of the personal data breach.

Can one risk assessment serve all the obligations?

One foundation yes, one document no. The fundamental rights impact assessment under Article 27 of the AI Act may draw on a data protection impact assessment already carried out under Article 35 of the GDPR and supplement it. The risk assessment under the Cyber Security Act has a different subject, the security of network and information systems, so neither of the other two replaces it, but it draws on the same asset inventory and the same risk register.

What if obligations from two of the laws collide?

As a rule they do not collide: one is stricter, and that one governs. The laws themselves provide for it. The AI Act requires a deployer to keep logs for at least six months, but expressly adds that a different period applies where Union or national law provides otherwise, in particular the law on the protection of personal data. Article 8 of the Cyber Security Act states that where sectoral legislation lays down requirements that match its own in substance and purpose, or that are stricter, the provisions of that sectoral legislation apply to those questions.

Do these laws reach us if nobody has categorised us?

Two of the three do, regardless. The GDPR applies the moment you process personal data, whatever your size or category. The AI Act binds you by role and risk category, again regardless of size. Obligations under the Cyber Security Act only start once the competent authority categorises you and delivers the notice, under Article 19(4) of the Act; your deadlines run from the day of delivery.

Who inside the organisation answers under which law?

Three different addressees, one management. Under the Cyber Security Act the persons responsible for managing the measures, that is the management body, must approve the measures and control their implementation, under Article 29, and the obligation stays even where an external provider runs the systems, under Article 26(4). Under the GDPR the controller answers and must be able to demonstrate compliance, under Article 5(2). Under the AI Act responsibility follows the role, provider under Article 16 or deployer under Article 26.

Do we have to appoint a separate person for each law?

No law asks for three people, but two roles are separately regulated. A data protection officer is mandatory for public authorities and in the other cases set out in Article 37 of the GDPR, must be independent and must not decide on the purposes of processing, under Articles 38 and 39. Annex II to Regulation NN 135/2024 calls for segregation of roles and for appointing a person dedicated to cyber security, sub-measures 1.5 and 1.6, which are binding at the medium and advanced levels. The AI Act asks for no named role, but it does ask that human oversight be carried out by trained people, under Article 26.

Tell us what you run, and we will tell you which law reaches it.

Half an hour, no obligation. We go through your activity, your systems and your data and tell you where to start.

Book a callINFO@RISKORIA.EU · +385 97 737 1345