As digital privacy takes center stage, understanding cookie regulations is vital for fostering transparency and customer trust. Therefore, whether you are a business owner, website operator or digital marketer, you must be aware of these legal requirements. Let us bring you up to speed on the Croatian cookie consent requirements and compliance strategies.
What is the cookie law of Croatia?
Croatia adheres to the GDPR guidelines in its digital data protection and privacy approach. The Croatian Personal Data Protection Agency has also published recommendations on using cookies to assist businesses to comply with the requirements.
What is the scope of the Croatian cookie guidelines?
The Croatian cookie guidelines apply to all websites and online services that deploy cookies or tracking technologies on devices and collect information from Croatian users.
What are the Croatian cookie consent requirements?
As per the Croatian legal standards, explicit user consent is the gateway to deploying cookies on devices. The consent for processing personal data obtained through cookies must be given in harmony with the GDPR consent requirements.
Do all cookies require consent?
Though consent is a prerequisite for cookies, this can be bypassed under the following specific scenarios:
• If they are solely used for transmitting communication via an electronic communication network;
• If they are necessary to provide the information society service requested by the user.
The following cookies do not require user consent if they are not used for other purposes:
• User input cookies like session IDs that last for the session or permanent cookies that sometimes last for a few hours.
• Authentication cookies that authenticate services during the session.
• User-oriented security cookies that detect authentication abuse for a limited persistent duration.
• Multimedia content session cookies like flash players during the session.
• Load balancing cookies for the duration of a session.
• Cookies that are used for customizing the user interface for the duration of a session or a little more.
• Cookies that are used for sharing the content of social networks/third parties for the login of their members.
Note that user consent is mandatory for using social media cookies, except those necessary to provide the service requested by the user. This is particularly important for tracking cookies.
What are the Croatian DPA cookie guidelines?
Websites must adhere to the following cookie consent guidelines before deploying cookies or other trackers on devices:
• User consent for non-essential cookies must be voluntary, unambiguous, specific and informed.
• Allow users to choose whether to accept or reject cookies without adverse consequences.
• Do not combine consent with other conditions (bundle consent) and must be separable.
• Provide convenient mechanisms to withdraw consent without any consequences.
• Allow users to give separate consent for each purpose rather than consenting to a set of purposes.
• Provide information regarding the data processing to the users.
• Avoid using a broad purpose for unrelated processing activities.
• Consent must be an affirmative action. Therefore, continuous scrolling or other forms of inaction do not constitute consent.
• Consent through internet browser settings must adhere to the GDPR consent requirements, such as granular consent and contain the controllers’ names.
• Renew consent at appropriate intervals depending upon the scope of the purpose and user’s expectation.
The Croatian cookie guidelines are designed to ensure that businesses honour user privacy and maintain transparency in data processing.
The following are the essential information requirements under the law:
• Identity and contact information of the controller
• Specific purposes for processing
• Categories of personal data collected and processed
• Information about the right to withdraw consent
• Recipients or categories of recipients of the collected information
• Data retention period
• Whether the users will be subjected to automated decision-making
• Possible risks if there is a transfer of data due to the absence of suitability decisions and appropriate safeguards
This information should be available to the users in an easily accessible and understandable format. Mostly they are included in the privacy policy
Checklist for Croatian cookie consent compliance
How can CookieYes help achieve Croatian cookie compliance?
The best solution to achieve cookie compliance is to implement a robust consent management platform like CookieYes.
FAQ on Croatian cookie consent