https://odluke.sudovi.hr/Document/View?id=9ebdf64c-a6d7-4793-8287-9827e3d499a9&q=Op%25c4%2587a+uredba+o+za%25c5%25a1titi+podataka
The Municipal Civil Court in Zagreb (Pn-1378/2023-18, 5 December 2025) awarded €3,500 in non-material damages to a client in a non-final judgment after a bank mistakenly sent a monthly custodial report to a third party (breach of privacy/banking secrecy). The court placed particular emphasis on the uncertainty around “what exactly was sent and to whom”.
Tips & Tricks – what to watch out for, even if you’re not a bank
1. Prove the scope of the incident (don’t “assume”).
Preserve and extract logs, recipient lists, and the exact content of the sent message/attachments. In disputes, the key question is whether you can prove what was disclosed and to whom.
2. “I deleted the email” is not a magic solution.
Courts may take the position that this does not guarantee the content was not further shared. Where possible, use solutions with revocable access (expiring links, secure portals).
3. Do not send sensitive reports as standard email attachments.
For financial or identification data, use secure portals/inboxes, encryption, and controlled access (DLP rules, blocking external sending, recipient verification).
4. “Password = personal ID number” is weak protection.
A personal ID number is often not confidential. Use one-time passwords (OTP), MFA, or access through authenticated user accounts.
5. Reduce client uncertainty – it reduces liability risk.
In notifications, clearly state: what categories of data were affected, the number of recipients, what measures were taken, and what the client can do immediately.
6. Incident response = remediation + evidence package.
In addition to technical fixes, prepare a clear timeline, root cause analysis, measures taken, risk assessment, and decisions regarding notifications (internal and to regulators/data subjects where required).