·
All episodes
Mario Mlinar
Episode · #713

ZGRADONAČELNIK Mario Milner

Guest Mario MlinarHosted by Tin BašićMay 3, 2026
About this episode
What you'll hear in this conversation

The data protection agency tasked with enforcing GDPR rules across Croatia has a surprising track record when it comes to residential buildings: zero fines issued to co-owners in six years. This leniency, despite high potential penalties, reveals a deeper understanding of where the real challenges lie for building representatives and residents. Mario Mlinar, who heads the supervision and investigations sector at Croatia's Personal Data Protection Agency (AZOP), explains why. He unpacks the persistent confusion around video surveillance, the public display of personal data on notice boards, and the critical distinction between who "controls" and who "processes" data within a building. This conversation offers clarity on the most common GDPR pitfalls in residential settings, revealing AZOP's approach to compliance and how to navigate the rules without inadvertently breaking them. You'll walk away understanding not just what the rules are, but how the agency actually enforces them, and where the line is between an honest mistake and a serious breach.

Insights from the conversation
What to take from this episode
01
In six years of GDPR enforcement, AZOP has issued zero administrative fines to residential co-owners, consistently opting for softer measures. This leniency stems from the agency's observation that most building-related violations are due to misunderstanding or lack of knowledge, not malicious intent.
02
The most frequent early GDPR violations in buildings involved publicly posting debt lists or court documents on notice boards in common areas. Widespread awareness campaigns have largely curbed these obvious breaches, shifting the focus to more nuanced issues.
03
While public data display issues have decreased, video surveillance remains a persistent and complex GDPR challenge in residential buildings. This is partly because it's not just covered by general regulations, but also by specific national laws that introduce additional compliance layers.
04
A frequent violation isn't about *what* data is collected, but *how* it's protected: data controllers often neglect organizational and technical security measures. They dismiss risks with "it won't happen to me" or avoid costs, making them vulnerable to cyber threats.
05
While much attention focuses on data collection, many data controllers overlook their obligation to honor data subjects' rights for access, modification, or objection. This procedural compliance often remains in the shadow of more visible GDPR requirements, leading to frequent oversight.
06
A common misconception is that the building representative is the "data controller" for shared personal data. Instead, the data controller is the collective body of all co-owners who jointly fund and decide on data processing activities, like installing video surveillance.
07
A company becomes a "data processor" only if it maintains ongoing access to personal data, like remotely viewing or retrieving video surveillance footage. A firm that merely installs equipment without continuous access is not a processor, a distinction that reshapes liability.
08
Posting names on building notice boards for debt or cleaning schedules is forbidden, yet names on mailboxes and intercoms are allowed. The difference is the legal basis: you can display your own name, but for others, it requires a clear, demonstrable legal basis like explicit, documented consent from all co-owners, which is rarely met for public announcements.
09
If co-owners want to publicly display personal data, such as names on a notice board, explicit and demonstrable consent from *all* affected individuals is mandatory. This requires documented proof, like signatures from a meeting, emphasizing that implied consent is insufficient for such public processing.