Three bodies of law that together set how you protect systems and data
The Cyber Security Act, the General Data Protection Regulation and the AI Act meet at the same points. This page shows where, and who supervises each of them.
Why these three belong on the same page
They are grouped not by subject matter but because they ask the same people for the same records.
The Cyber Security Act (ZKS) protects the system, the General Data Protection Regulation the data inside it, and the AI Act governs what may be done with that data automatically.
The NIS2 directive has no page of its own here, because for an entity in Croatia it carries no separate obligations. It entered Croatian law through the Cyber Security Act, so it is read through that Act, and supervision follows that Act too.
The three meet at three points. At the inventory, where the list of network and information systems, the record of processing activities and your own list of AI tools describe the same assets from three sides. At risk assessment, where a fundamental rights impact assessment may draw on a data protection impact assessment already carried out and supplement it. And at incidents, where one event can trigger two notifications, each to its own authority and on its own clock.
So there is no reason to run them separately. None has precedence over the others and none displaces another, so the work is done once, and only the forms, the deadlines and the recipient differ.
The three
Each has its own page, with who is covered, the deadlines, the supervision and the fines.
The Cyber Security Act
NN 14/2024The Croatian implementation of the NIS2 directive. It sets who is covered, which measures they run, how they report incidents and who supervises them.- Essential and important entities, categorised by the competent authority
- Thirteen measures and 99 sub-measures, Annex II to Regulation NN 135/2024
- Early warning within 24 hours, incident notification within 72
- Fines up to 10 million euros or 2 per cent of worldwide annual turnover
The General Data Protection Regulation
REGULATION (EU) 2016/679Directly applicable since 25 May 2018, alongside the Croatian implementing Act NN 42/2018. It reaches every processing of personal data, whatever the size of the organisation.- Legal basis, record of processing and the processor contract
- Data subject rights; an answer within one month of receipt
- Breach notification to the supervisory authority within 72 hours
- Fines up to 20 million euros or 4 per cent of worldwide annual turnover
The AI Act
REGULATION (EU) 2024/1689In force since 1 August 2024, applying in steps. The scope of the obligations follows from the role you are in and the risk category of the system.- Four risk categories, from prohibited practice to minimal risk
- The provider role and the deployer role
- Transparency obligations from 2 August 2026
- Fines up to 35 million euros or 7 per cent of worldwide annual turnover
Who supervises what in Croatia
The authorities differ, so the proceedings run separately even when the trigger is the same.
The NIS2 directive has no supervisory authority of its own in Croatia, because it applies through the Cyber Security Act. Providers of general-purpose AI models are supervised not by a national authority but by the European Commission, under Article 101 of the Act.
Frequently asked questions
The questions that only come up once the three are set side by side.
One incident, two notifications. Which deadline falls first?
The early warning to the competent CSIRT falls first, no later than 24 hours from becoming aware, under Article 66 of Regulation NN 135/2024. Two things then fall due at 72 hours: the initial incident notification to the competent CSIRT under Article 67 of the Regulation, and the personal data breach notification to the supervisory authority under Article 33 of the GDPR. The two clocks do not necessarily start at the same moment, because one runs from awareness of the incident and the other from awareness of the personal data breach.Can one risk assessment serve all the obligations?
One foundation yes, one document no. The fundamental rights impact assessment under Article 27 of the AI Act may draw on a data protection impact assessment already carried out under Article 35 of the GDPR and supplement it. The risk assessment under the Cyber Security Act has a different subject, the security of network and information systems, so neither of the other two replaces it, but it draws on the same asset inventory and the same risk register.What if obligations from two of the laws collide?
As a rule they do not collide: one is stricter, and that one governs. The laws themselves provide for it. The AI Act requires a deployer to keep logs for at least six months, but expressly adds that a different period applies where Union or national law provides otherwise, in particular the law on the protection of personal data. Article 8 of the Cyber Security Act states that where sectoral legislation lays down requirements that match its own in substance and purpose, or that are stricter, the provisions of that sectoral legislation apply to those questions.Do these laws reach us if nobody has categorised us?
Two of the three do, regardless. The GDPR applies the moment you process personal data, whatever your size or category. The AI Act binds you by role and risk category, again regardless of size. Obligations under the Cyber Security Act only start once the competent authority categorises you and delivers the notice, under Article 19(4) of the Act; your deadlines run from the day of delivery.Who inside the organisation answers under which law?
Three different addressees, one management. Under the Cyber Security Act the persons responsible for managing the measures, that is the management body, must approve the measures and control their implementation, under Article 29, and the obligation stays even where an external provider runs the systems, under Article 26(4). Under the GDPR the controller answers and must be able to demonstrate compliance, under Article 5(2). Under the AI Act responsibility follows the role, provider under Article 16 or deployer under Article 26.Do we have to appoint a separate person for each law?
No law asks for three people, but two roles are separately regulated. A data protection officer is mandatory for public authorities and in the other cases set out in Article 37 of the GDPR, must be independent and must not decide on the purposes of processing, under Articles 38 and 39. Annex II to Regulation NN 135/2024 calls for segregation of roles and for appointing a person dedicated to cyber security, sub-measures 1.5 and 1.6, which are binding at the medium and advanced levels. The AI Act asks for no named role, but it does ask that human oversight be carried out by trained people, under Article 26.Tell us what you run, and we will tell you which law reaches it.
Half an hour, no obligation. We go through your activity, your systems and your data and tell you where to start.
