AZOP: Advice on Protecting Personal Data During Holidays
The Croatian data protection authority (AZOP) has issued a series of recommendations aimed at raising awareness among individuals about the protection of their personal data during the holiday period.
The authority reminds the distinction between taking photographs for private use, which is not subject to the GDPR, and their publication on public platforms such as social networks. In the latter case, it is necessary to ensure that other people present, especially children, are not identifiable in the foreground. If a person notices that their photograph has been published without their consent, they must first request its removal from the publisher or the platform. In case of failure, a complaint can be filed with AZOP.
Regarding registration in tourist accommodations, hoteliers and owners are legally required to collect specific data for the eVisitor system, based on an identity document. Customers must present their document, but its photocopy or retention by the host is not compliant with the GDPR. Refusal to present the identity document authorizes the provider to refuse service.
AZOP also warns about phishing risks where fraudsters impersonate hosts or booking platforms. It is advised to verify the authenticity of payment or data requests by contacting the provider directly through official channels. Finally, it is recommended to avoid using public Wi-Fi networks for sensitive operations such as banking transactions or online purchases, favoring a secure mobile data connection.
The authority reminds the distinction between taking photographs for private use, which is not subject to the GDPR, and their publication on public platforms such as social networks. In the latter case, it is necessary to ensure that other people present, especially children, are not identifiable in the foreground. If a person notices that their photograph has been published without their consent, they must first request its removal from the publisher or the platform. In case of failure, a complaint can be filed with AZOP.
Regarding registration in tourist accommodations, hoteliers and owners are legally required to collect specific data for the eVisitor system, based on an identity document. Customers must present their document, but its photocopy or retention by the host is not compliant with the GDPR. Refusal to present the identity document authorizes the provider to refuse service.
AZOP also warns about phishing risks where fraudsters impersonate hosts or booking platforms. It is advised to verify the authenticity of payment or data requests by contacting the provider directly through official channels. Finally, it is recommended to avoid using public Wi-Fi networks for sensitive operations such as banking transactions or online purchases, favoring a secure mobile data connection.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire