Public National CERT incident reporting: National CERT states coordinates incidents where at least one party is under the .hr domain or Croatian IP address space. Incident reports must include logs, description, time zone, target/source IP or computer name and other potential files.
Sources: https://www.cert.hr/en/report_incident/
PiXi national platform: The PiXi platform is intended for: Key entities and important entities subject to the Croatian Cybersecurity Act (Zakon o kibernetičkoj sigurnosti, ZKS), which transposes NIS2 into Croatian law. Entities subject to DORA (Regulation (EU) 2022/2554 on digital operational resilience for the financial sector). Competent authorities responsible for implementing cybersecurity requirements. Competent authorities responsible for sector-specific legislation. Competent CSIRTs. Croatia’s Single Point of Contact for cybersecurity matters. To access the Pixi Platform service, it is necessary to obtain access rights from a legally authoriSed person for representing a business entity through e-Authorisations. Access to the e-Authorisation and Pixi platform service requires at least a significant level of security from the List of Accepted Credentials.
Sources: https://pixi.carnet.hr/
https://narodne-novine.nn.hr/clanci/sluzbeni/2024_02_14_254.html
https://www.carnet.hr/usluga/pixi-platforma/
https://e-ovlastnja.gov.hr/
https://gov.hr/hr/lista-prihvacenih-verodajnica/1792
GDPR personal-data breach notification to AZOP: AZOP states that controllers must notify personal-data breaches without undue delay and, where feasible, within 72 hours, unless unlikely to pose risk. Incidents such as ransomware, unauthorised access, data loss or loss of access can be personal-data breaches. The report with the signature of the responsible person and the seal of the controller, if applicable, should be submitted to the Personal Data Protection Agency, Ulica Metela Ožegovića 16, 10000 Zagreb, and scanned to the e-mail address.
Sources: https://azop.hr/izvjescivanje-o-povredi-osobnih-podataka/
https://azop.hr/wp-content/uploads/2025/05/izvjesce_o_povredi_osobnih_podataka.rtfnn