Propiedad intelectual Formación en PI Respeto por la PI Divulgación de la PI La PI para... La PI y… La PI en… Información sobre patentes y tecnología Información sobre marcas Información sobre los diseños Información sobre las indicaciones geográficas Información sobre las variedades vegetales (UPOV) Leyes, tratados y sentencias de PI Recursos de PI Informes sobre PI Protección por patente Protección de las marcas Protección de los diseños Protección de las indicaciones geográficas Protección de las variedades vegetales (UPOV) Solución de controversias en materia de PI Soluciones operativas para las oficinas de PI Pagar por servicios de PI Negociación y toma de decisiones Cooperación en materia de PI Apoyo a la innovación Colaboraciones público-privadas Herramientas y servicios de IA La Organización Trabajar en la OMPI Rendición de cuentas Patentes Marcas Diseños Indicaciones geográficas Derecho de autor Secretos comerciales Futuro de la PI Academia de la OMPI Talleres y seminarios Observancia de la PI WIPO ALERT Sensibilizar Día Mundial de la PI Revista de la OMPI Casos prácticos y casos de éxito Novedades sobre la PI Premios de la OMPI Empresas Mujeres Universidades Pueblos indígenas Judicatura Juventud Examinadores Ecosistemas de innovación Economía Financiación Activos intangibles Salud mundial Cambio climático Política de competencia Objetivos de Desarrollo Sostenible Recursos genéticos, conocimientos tradicionales y expresiones culturales tradicionales Tecnologías de vanguardia Aplicaciones móviles Deportes Turismo Música Moda PATENTSCOPE Análisis de patentes Clasificación Internacional de Patentes ARDI - Investigación para la innovación ASPI - Información especializada sobre patentes Base Mundial de Datos sobre Marcas Madrid Monitor Base de datos Artículo 6ter Express Clasificación de Niza Clasificación de Viena Base Mundial de Datos sobre Dibujos y Modelos Boletín de Dibujos y Modelos Internacionales Base de datos Hague Express Clasificación de Locarno Base de datos Lisbon Express Base Mundial de Datos sobre Marcas para indicaciones geográficas Base de datos de variedades vegetales PLUTO Base de datos GENIE Tratados administrados por la OMPI WIPO Lex: leyes, tratados y sentencias de PI Normas técnicas de la OMPI Estadísticas de PI WIPO Pearl (terminología) Publicaciones de la OMPI Perfiles nacionales sobre PI Centro de Conocimiento de la OMPI Aspectos destacados de la inversión mundial en activos intangibles Informes de la OMPI sobre tendencias tecnológicas Índice Mundial de Innovación Informe mundial sobre la propiedad intelectual PCT - El sistema internacional de patentes ePCT Budapest - El Sistema internacional de depósito de microorganismos Madrid - El sistema internacional de marcas eMadrid Artículo 6ter (escudos de armas, banderas, emblemas de Estado) La Haya - Sistema internacional de diseños eHague Lisboa - Sistema internacional de indicaciones geográficas eLisbon UPOV PRISMA Mediación Arbitraje Determinación de expertos Disputas sobre nombres de dominio Acceso centralizado a la búsqueda y el examen (CASE) Servicio de acceso digital (DAS) WIPO Pay Cuenta corriente en la OMPI Asambleas de la OMPI Comités permanentes Calendario de reuniones WIPO Webcast Documentos oficiales de la OMPI Agenda para el Desarrollo Iniciativas y proyectos a medida Foros y diálogos de colaboración Programa de Aceleración de la Innovación, la Creatividad y el Desarrollo Historias sobre el impacto de la PI Estrategias nacionales de PI Centro de cooperación Centros de apoyo a la tecnología y la innovación (CATI) Transferencia de tecnología Programa de Asistencia a los Inventores (PAI) WIPO GREEN PAT-INFORMED de la OMPI Consorcio de Libros Accesibles Consorcio de la OMPI para los Creadores WIPO Translate Conversión de voz a texto Asistente de clasificación Estados miembros Observadores Director general Actividades por unidad Oficinas en el exterior Puestos de plantilla Puestos de personal afiliado Adquisiciones Resultados y presupuesto Información financiera Supervisión
Arabic English Spanish French Russian Chinese
Leyes Tratados Sentencias Consultar por jurisdicción

Ley relativa a la información confidencial y ley por la que se modifica la ley relativa a la información confidencial (promulgadas por los Decretos Nº 71-05-03/1-07-2 de 18 de julio de 2007 y Nº 71-05-03/1-12-2 de 18 de julio de 2012, BO N° 79/07 y N°86/2012), Croacia

Atrás
Versión más reciente en WIPO Lex
Detalles Detalles Año de versión 2012 Fechas Adoptado/a: 13 de julio de 2007 Entrada en vigor: 1 de enero de 2007 Tipo de texto Otras textos Materia Patentes (Invenciones), Información no divulgada (Secretos Comerciales), Organismo regulador de PI Notas En la notificación de Croacia a la OMC de conformidad con el artículo 63.2 del Acuerdo sobre los ADPIC se establece lo siguiente:
'La Ley contiene disposiciones relativas a la protección de los documentos abarcados por el secreto profesional o comercial.'

Para las disposiciones sobre propiedad intelectual, véanse los artículos 6, 13, 16.

Fecha de entrada en vigor: véase el artículo 35 para más detalles.

Documentos disponibles

Textos principales Textos relacionados
Textos principales Textos principales Croata Zakon o Tajnosti Podataka         Inglés No se dispone del texto actual en este idioma. Se facilita la versión anterior a título de referencia (2007).      
 
Abrir PDF open_in_new
Zakon o Tajnosti Podataka
 Zakon o Tajnosti Podataka

HRVATSKI SABOR 2483

Na temelju članka 88. Ustava Republike Hrvatske, donosim

ODLUKU

O PROGLAŠENJU ZAKONA O TAJNOSTI PODATAKA

Proglašavam Zakon o tajnosti podataka, koji je Hrvatski sabor donio na sjednici 13. srpnja 2007. godine.

Klasa: 011-01/07-01/97 Urbroj: 71-05-03/1-07-2 Zagreb, 18. srpnja 2007.

Predsjednik Republike Hrvatske Stjepan Mesić, v. r.

ZAKON

O TAJNOSTI PODATAKA

I. OSNOVNE ODREDBE

Članak 1.

(1) Ovim se Zakonom utvrđuju pojam klasificiranih i neklasificiranih podataka, stupnjevi tajnosti, postupak klasifikacije i deklasifikacije, pristup klasificiranim i neklasificiranim podacima, njihova zaštita i nadzor nad provedbom ovoga Zakona. (2) Ovaj Zakon se primjenjuje na državna tijela, tijela jedinica lokalne i područne (regionalne) samouprave, pravne osobe s javnim ovlastima te pravne i fizičke osobe koje, u skladu sa ovim Zakonom, ostvare pristup ili postupaju s klasificiranim i neklasificiranim podacima.

Članak 2.

Pojedini pojmovi u smislu ovoga Zakona imaju sljedeće značenje: – podatak je dokument, odnosno svaki napisani, umnoženi, nacrtani, slikovni, tiskani, snimljeni, fotografirani, magnetni, optički, elektronički ili bilo koji drugi zapis podatka, saznanje, mjera, postupak, predmet, usmeno priopćenje ili informacija, koja s obzirom na svoj sadržaj ima važnost povjerljivosti i cjelovitosti za svoga vlasnika, – klasificirani podatak je onaj koji je nadležno tijelo, u propisanom postupku, takvim označilo i za koji je utvrđen stupanj tajnosti, kao i podatak kojeg je Republici Hrvatskoj tako označenog predala druga država, međunarodna organizacija ili institucija s kojom Republika Hrvatska surađuje, – neklasificirani podatak je podatak bez utvrđenog stupnja tajnosti, koji se koristi u službene

svrhe, kao i podatak koji je Republici Hrvatskoj tako označenog predala druga država, međunarodna organizacija ili institucija s kojom Republika Hrvatska surađuje, – klasifikacija podatka je postupak utvrđivanja jednog od stupnjeva tajnosti podatka s obzirom na stupanj ugroze i područje ovim Zakonom zaštićenih vrijednosti, – deklasifikacija podatka je postupak kojim se utvrđuje prestanak postojanja razloga zbog kojih je određeni podatak klasificiran odgovarajućim stupnjem tajnosti, nakon čega podatak postaje neklasificirani s ograničenom uporabom samo u službene svrhe, – vlasnik podatka je nadležno tijelo u okviru čijeg djelovanja je klasificirani ili neklasificirani podatak nastao, – certifikat je uvjerenje o sigurnosnoj provjeri koje omogućava pristup klasificiranim podacima.

Članak 3.

Klasificiranim podatkom ne može se proglasiti podatak radi prikrivanja kaznenog djela, prekoračenja ili zlouporabe ovlasti te drugih oblika nezakonitog postupanja u državnim tijelima.

II. STUPNJEVI TAJNOSTI

Članak 4.

Stupnjevi tajnosti klasificiranih podataka su: - VRLO TAJNO, - TAJNO, - POVJERLJIVO, - OGRANIČENO.

Članak 5.

S obzirom na stupanj ugroze zaštićenih vrijednosti stupnjevima tajnosti iz članka 4. ovoga Zakona mogu se klasificirati podaci iz djelokruga državnih tijela u području obrane, sigurnosno-obavještajnog sustava, vanjskih poslova, javne sigurnosti, kaznenog postupka te znanosti, tehnologije, javnih financija i gospodarstva ukoliko su podaci od sigurnosnog interesa za Republiku Hrvatsku.

Članak 6.

Stupnjem tajnosti »VRLO TAJNO« klasificiraju se podaci čije bi neovlašteno otkrivanje nanijelo nepopravljivu štetu nacionalnoj sigurnosti i vitalnim interesima Republike Hrvatske, a osobito sljedećim vrijednostima: – temelji Ustavom utvrđenog ustrojstva Republike Hrvatske, – neovisnost, cjelovitost i sigurnost Republike Hrvatske, – međunarodni odnosi Republike Hrvatske, – obrambena sposobnost i sigurnosno-obavještajni sustav, – sigurnost građana, – osnove gospodarskog i financijskog sustava Republike Hrvatske, – znanstvena otkrića, pronalasci i tehnologije od važnosti za nacionalnu sigurnost Republike Hrvatske.

Članak 7.

Stupnjem tajnosti »TAJNO« klasificiraju se podaci čije bi neovlašteno otkrivanje teško naštetilo vrijednostima iz članka 6. ovoga Zakona.

Članak 8.

Stupnjem tajnosti »POVJERLJIVO« klasificiraju se podaci čije bi neovlašteno otkrivanje naštetilo vrijednostima iz članka 6. ovoga Zakona.

Članak 9.

Stupnjem tajnosti »OGRANIČENO« klasificiraju se podaci čije bi neovlašteno otkrivanje naštetilo djelovanju i izvršavanju zadaća državnih tijela u obavljanju poslova iz članka 5. ovoga Zakona.

Članak 10.

Državna tijela koja provode postupak klasificikacije podataka pravilnikom će pobliže razraditi kriterije za određivanje stupnjeva tajnosti za podatke iz svog djelokruga.

III. POSTUPAK KLASIFICIRANJA I DEKLASIFICIRANJA PODATAKA

Članak 11.

Klasifikacija podataka se obavlja pri nastanku klasificiranih podataka ili prilikom periodične procjene iz članka 14. ovoga Zakona.

Članak 12.

(1) U postupku klasifikacije podatka vlasnik podatka dužan je odrediti najniži stupanj tajnosti koji će osigurati zaštitu interesa koji bi neovlaštenim otkrivanjem tog podatka mogli biti ugroženi. (2) Ukoliko klasificirani podatak sadrži određene dijelove ili priloge, čije neovlašteno otkrivanje ne ugrožava vrijednosti zaštićene ovim Zakonom, takvi dijelovi podatka neće biti označeni stupnjem tajnosti.

Članak 13.

(1) Klasificiranje podataka stupnjevima tajnosti »VRLO TAJNO« i »TAJNO« mogu provoditi: Predsjednik Republike Hrvatske, predsjednik Hrvatskog sabora, predsjednik Vlade Republike Hrvatske, ministri, Glavni državni odvjetnik, načelnik Glavnog stožera Oružanih snaga RH i čelnici tijela sigurnosno-obavještajnog sustava RH te osobe koje oni za tu svrhu ovlaste. (2) Osobe iz stavka 1. ovoga članka ovlast prenose pisanim putem na druge osobe isključivo u okviru njihovog djelokruga. (3) Klasificiranje podataka stupnjevima tajnosti »POVJERLJIVO« i »OGRANIČENO«, pored osoba iz stavka 1. i 2. ovoga članka, mogu provoditi i čelnici ostalih državnih tijela. (4) Osobe iz stavka 1., 2. i 3., ovoga članka klasificiraju podatke i za znanstvene ustanove,

zavode i druge pravne osobe, kada rade na projektima, pronalascima, tehnologijama i drugim poslovima od sigurnosnog interesa za Republiku Hrvatsku.

Članak 14.

(1) Za vrijeme važenja stupnja tajnosti podatka, vlasnik podatka obvezan je trajno procjenjivati stupanj tajnosti klasificiranog podatka i izraditi perodičnu procjenu, na temelju koje se može promijeniti stupanj tajnosti ili izvršiti deklasifikacija podatka. (2) Periodična procjena provodi se: – za stupanj tajnosti »VRLO TAJNO« najmanje jednom u 5 godina, – za stupanj tajnosti »TAJNO« najmanje jednom u 4 godine, – za stupanj tajnosti »POVJERLJIVO« najmanje jednom u 3 godine, – za stupanj tajnosti »OGRANIČENO« najmanje jednom u 2 godine. (3) O promjeni stupnja tajnosti ili o deklasifikaciji podatka vlasnik podatka će pisanim putem izvijestiti sva tijela kojima je podatak bio dostavljen.

Članak 15.

(1) Periodična procjena izrađuje se u pisanom obliku za svaki stupanj tajnosti. (2) Vlasnik podatka periodičnu procjenu može provesti i skupno za određene grupe podataka. (3) Periodična procjena označava se stupnjem tajnosti podatka na koji se odnosi i prilaže se uz izvornik u arhivu vlasnika podatka.

Članak 16.

(1) Kad postoji interes javnosti, vlasnik podatka dužan je ocijeniti razmjernost između prava na pristup informacijama i zaštite vrijednosti propisanih u člancima 6., 7., 8. i 9. ovoga Zakona te odlučiti o zadržavanju stupnja tajnosti, promjeni stupnja tajnosti, deklasifikaciji ili oslobađanju od obveze čuvanja tajnosti podatka. (2) Prije donošenja odluke iz stavka 1. ovoga članka vlasnik podatka je dužan zatražiti mišljenje Ureda Vijeća za nacionalnu sigurnost. (3) Vlasnik podatka dužan je o postupku iz stavka 1. ovoga članka izvijestiti i druga nadležna tijela propisana zakonom.

Članak 17.

Način označavanja stupnjeva tajnosti klasificiranih podataka, propisat će se uredbom koju donosi Vlada Republike Hrvatske.

IV. PRISTUP PODACIMA

Članak 18.

(1) Pristup klasificiranim podacima imaju osobe kojima je to nužno za obavljanje poslova iz njihovog djelokruga te koje imaju izdano Uvjerenje o obavljenoj sigurnosnoj provjeri (u daljnjem tekstu: certifikat). (2) Državna tijela, tijela jedinica lokalne i područne (regionalne) samouprave, pravne osobe s javnim ovlastima te pravne i fizičke osobe (u daljnjem tekstu: podnositelji zahtjeva) ovlašteni su za podnošenje zahtjeva za izdavanje certifikata za zaposlenike, koji u okviru svog djelokruga bi trebali imati pravo pristupa klasificiranim podacima.

(3) Zahtjev za izdavanje certifikata podnosi se, u pisanom obliku, Uredu Vijeća za nacionalnu sigurnost. Zahtjev sadrži: ime i prezime osobe, dužnost ili poslove u okviru kojih pristupa klasificiranim podacima i stupanj tajnosti za koji se traži certifikat. (4) Certifikat se izdaje za stupnjeve tajnosti »VRLO TAJNO«, »TAJNO« i »POVJERLJIVO« na rok od pet godina. Certifikat se ne označava stupnjem tajnosti već predstavlja neklasificirani podatak. (5) Certifikat izdaje Ured Vijeća za nacionalnu sigurnost na temelju ocjene o nepostojanju sigurnosnih zapreka za pristup klasificiranim podacima. Postojanje sigurnosnih zapreka utvrđuje se na temelju sigurnosne provjere koju obavlja nadležna sigurnosno-obavještajna agencija. (6) Sigurnosne zapreke u smislu ovoga Zakona su: neistinito navođenje podataka u upitniku za sigurnosnu provjeru, činjenice koje su posebnim zakonom propisane kao zapreke za prijam u državnu službu, te izrečene stegovne sankcije i druge činjenice koje predstavljaju osnovu za sumnju u povjerljivosti ili pouzdanosti osobe za postupanje s klasificiranim podacima.

Članak 19.

(1) Ako tijelo iz članka 18. stavka 5. ovoga Zakona, na temelju izvješća o rezultatima sigurnosne provjere ocijeni da postoje sigurnosne zapreke, rješenjem će odbiti izdavanje certifikata. (2) Osoba kojoj je rješenjem odbijeno izdavanje certifikata nema pravo podnijeti žalbu ali ima pravo pokrenuti upravni spor u roku od 30 dana od primitka rješenja. (3) U postupku pred Upravnim sudom, sud će, prilikom utvrđivanja činjenica i izvođenja dokaza kojima bi mogla nastati šteta za rad sigurnosno-obavještajnih agencija i nacionalnu sigurnost, poduzeti mjere i radnje iz svoje nadležnosti kojima će spriječiti nastanak štete.

Članak 20.

(1) Pristup klasificiranim podacima bez certifikata imat će u okviru obavljanja poslova iz njihovog djelokruga saborski zastupnik, ministar, državni tajnik središnjega državnog ureda, sudac i Glavni državni odvjetnik. (2) Osobe iz stavka 1. ovoga članka dužne su, prije pristupanja klasificiranim podacima, potpisati izjavu Uredu Vijeća za nacionalnu sigurnost kojom potvrđuju da su upoznati s odredbama ovoga Zakona i drugih propisa kojima se uređuje zaštita klasificiranih podataka te se obvezuju raspolagati klasificiranim podacima sukladno navedenim propisima.

Članak 21.

Sadržaj i izgled certifikata iz članka 18. ovoga Zakona te izjave iz članka 20. stavak 2. ovoga Zakona, propisat će se uredbom koju donosi Vlada Republike Hrvatske.

Članak 22.

(1) Pristup klasificiranim podacima druge države i međunarodne organizacije, imaju osobe kojima je to nužno za obavljanje poslova iz njihovog djelokruga te kojima je izdan certifikat propisan međunarodnim ugovorom ili sigurnosnim sporazumom. (2) Certifikat iz stavka 1. ovoga članka izdaje Ured Vijeća za nacionalnu sigurnost na temelju zahtjeva nadležnog tijela. (3) Zahtjev iz stavka 2. ovoga članka može se podnijeti samo za osobe kojima je prethodno izdan odgovarajući certifikat u postupku iz članka 18. ovoga Zakona.

Članak 23.

(1) Pristup neklasificiranim podacima imaju osobe kojima je to nužno u službene svrhe radi obavljanje poslova iz njihovog djelokruga. (2) Pristup neklasificiranim podacima imaju i zainteresirani ovlaštenici prava na informaciju na temelju podnesenog zahtjeva za ostvarivanje prava na pristup informacijama sukladno zakonu.

Članak 24.

Predsjednik Republike Hrvatske, predsjednik Hrvatskoga sabora i predsjednik Vlade Republike Hrvatske, izuzeti su od postupka propisanog za izdavanje certifikata.

V. ZAŠTITA PODATAKA

Članak 25.

Način i provedba zaštite klasificiranih i neklasificiranih podataka propisat će se zakonom koji regulira područje informacijske sigurnosti.

Članak 26.

Dužnosnici i zaposlenici državnih tijela, tijela jedinica lokalne i područne (regionalne) samouprave, pravnih osoba s javnim ovlastima, kao i pravne i fizičke osobe koje ostvare pristup ili postupaju s klasificiranim i neklasificiranim podacima, dužni su čuvati tajnost klasificiranog podatka za vrijeme i nakon prestanka obavljanja dužnosti ili službe, sve dok je podatak utvrđen jednim od stupnjeva tajnosti ili dok se odlukom vlasnika podatka ne oslobode obveze čuvanja tajnosti.

Članak 27.

(1) Ako se klasificirani podatak uništi, otuđi ili učini dostupnim neovlaštenim osobama, vlasnik podatka poduzima sve potrebne mjere za otklanjanje nastajanja mogućih štetnih posljedica, pokreće postupak za utvrđivanje odgovornosti i istodobno izvještava Ured Vijeća za nacionalnu sigurnost. (2) Ako se klasificirani podatak uništi, otuđi ili učini dostupnim neovlaštenim osobama u tijelu koje nije vlasnik podatka, odgovorna osoba tog tijela dužna je odmah o tome izvijestiti vlasnika podatka koji pokreće postupak iz stavka 1. ovoga članka.

Članak 28.

(1) Ured Vijeća za nacionalnu sigurnost će prilikom izdavanja certifikata ili potpisivanja izjave iz članka 20. stavka 2. ovoga Zakona upoznati osobe sa standardima postupanja s klasificiranim podacima te s pravnim i drugim posljedicama neovlaštenog raspolaganja istim. (2) Postupak iz stavka 1. ovoga članka, provodi se najmanje jednom godišnje za vrijeme važenja certifikata.

VI. NADZOR NAD PROVEDBOM ZAKONA

Članak 29.

Državna tijela, tijela jedinica lokalne i područne (regionalne) samouprave i pravne osobe s javnim ovlastima, vode evidenciju o izvršenim uvidima i postupanju s klasificiranim podacima.

Članak 30.

(1) Ured Vijeća za nacionalnu sigurnost provodi nadzor nad postupcima klasifikacije i deklasifikacije podataka, načinom ostvarivanja pristupa klasificiranim i neklasificiranim podacima, provedbi mjera za zaštitu pristupa klasificiranim podacima te izvršavanja obveza proizašlih iz međunarodnih ugovora i sporazuma o zaštiti klasificiranih podataka. (2) U provođenju nadzora predstojnik Ureda Vijeća za nacionalnu sigurnost ovlašten je: – utvrditi činjenično stanje, – dati upute u svrhu otklanjanja utvrđenih nedostataka i nepravilnosti koje su nadzirana tijela dužna u određenom roku ukloniti, – pokrenuti postupak utvrđivanja odgovornosti vlasnika podatka, – poduzeti druge mjere i radnje, za koje je posebnim propisima ovlašten. (3) U Uredu Vijeća za nacionalnu sigurnost ustrojavaju se registri izdanih certifikata, rješenja o odbijanju izdavanja certifikata, potpisanih izjava iz članka 20. stavka 2. ovoga Zakona te obavljenih upoznavanja sa standardima iz članka 28. ovoga Zakona.

VII. PRIJELAZNE I ZAVRŠNE ODREDBE

Članak 31.

(1) Uredba Vlade Republike Hrvatske iz članka 17. i 21. ovoga Zakona donijet će se u roku od 30 dana od dana stupanja na snagu ovoga Zakona. (2) Pravilnik iz članka 10. ovoga Zakona čelnici nadležnih tijela donijet će u roku od 60 dana od dana stupanja na snagu ovoga Zakona. (3) Čelnici nadležnih tijela dužni su utvrditi popis dužnosti i poslova iz njihova djelokruga za koje je potreban certifikat, u roku od 90 dana.

Članak 32.

Stupnjevi tajnosti određeni međunarodnim ugovorima koje je Republika Hrvatska potvrdila prije dana stupanja na snagu ovoga Zakona, stupnjevi tajnosti podataka dobivenih međunarodnom razmjenom prije stupanja na snagu ovoga Zakona, kao i stupnjevi tajnosti podataka koji su utvrđeni prije stupanja na snagu ovoga Zakona, prevode se na način: – »DRŽAVNA TAJNA« u »VRLO TAJNO«, – »SLUŽBENA TAJNA – VRLO TAJNO« i »VOJNA TAJNA – VRLO TAJNO« u »TAJNO«, – »SLUŽBENA TAJNA – TAJNO« i »VOJNA TAJNA – TAJNO« u »POVJERLJIVO«, – »SLUŽBENA TAJNA – POVJERLJIVO« i »VOJNA TAJNA – POVJERLJIVO« u »OGRANIČENO«.

Članak 33.

(1) Certifikati koje je Ured Vijeća za nacionalnu sigurnost izdao do stupanja na snagu ovoga Zakona vrijede do isteka roka označenog na certifikatu. (2) Interna dopuštenja za pristup tajnim podacima koja su izdana na temelju Zakona o zaštiti tajnosti podataka (»Narodne novine«, br. 108/96.), vrijede do izdavanja certifikata po ovom

Zakonu. (3) Podzakonski propisi doneseni na temelju Zakona o zaštiti tajnosti podataka (»Narodne novine«, br. 108/96.) primjenjuju se do stupanja na snagu odgovarajućih podzakonskih propisa na temelju ovoga Zakona.

Članak 34.

Stupanjem na snagu ovoga Zakona prestaju važiti odredbe Zakona o zaštiti tajnosti podataka (»Narodne novine«, br. 108/96.) osim odredbi navedenih u glavi 8. i 9. istog Zakona.

Članak 35.

Ovaj Zakon stupa na snagu osmoga dana od dana objave u »Narodnim novinama«.

Klasa: 804-04/07-01/01 Zagreb, 13. srpnja 2007.

HRVATSKI SABOR Predsjednik

Hrvatskoga sabora Vladimir Šeks, v. r.

HRVATSKI SABOR 1969

Na temelju članka 89. Ustava Republike Hrvatske, donosim

ODLUKU

O PROGLAŠENJU ZAKONA O IZMJENI ZAKONA O TAJNOSTI PODATAKA

Proglašavam Zakon o i zmjeni Zakona o t ajnosti podataka, koji je Hrvatski sabor donio na sjednici 13. srpnja 2012. godine.

Klasa: 011-01/12-01/99

Urbroj: 71-05-03/1-12-2

Zagreb, 18. srpnja 2012.

Predsjednik Republike Hrvatske

Ivo Josipović, v. r.

ZAKON

O IZMJENI ZAKONA O TAJNOSTI PODATAKA

Članak 1.

U Zakonu o tajnosti podataka (»Narodne novine«, br. 79/07.) u članku 20. stavak 1. mijenja se i glasi:

»Pristup klasificiranim podacima bez certifikata imat će u okviru obavljanja poslova iz njihovog djelokruga državni dužnosnici određeni odredbama Zakona o sustavu državne uprave, zastupnici u Hrvatskome saboru, pučki pravobranitelj, suci, Glavni državni odvjetnik, zamjenici Glavnog državnog odvjetnika, ravnatelj Ureda za suzbijanje korupcije i organiziranog kriminaliteta te zamjenici ravnatelja Ureda za suzbijanje korupcije i organiziranog kriminaliteta.«.

Članak 2.

Ovaj Zakon stupa na snagu osmoga dana od dana objave u »Narodnim novinama.«

Klasa: 804-04/12-01/01

Zagreb, 13. srpnja 2012.

HRVATSKI SABOR

Potpredsjednik Hrvatskoga sabora

Josip Leko, v. r.

 
Abrir PDF open_in_new
Data Secrecy Act (promulgated by Decree No. 71-05-03/1-07-2 of July 18, 2007, OG No. 79/07)
 Data Secrecy Protection Law

Official Gazette 79/2007

1

THE CROATIAN PARLIAMENT

Pursuant to Article 88 of the Constitution of the Republic of Croatia, I hereby issue the

DECISION ON PROMULGATING THE DATA SECRECY ACT

I hereby promulgate the Data Secrecy Act, passed by the Croatian Parliament at its session on 13

July 2007.

Class: 011-01/07-01/97

Reg. No.: 71-05-03/1-07-2

Zagreb, 18 July 2007

The President of the Republic of Croatia

Stjepan Mesić, m.p.

DATA SECRECY ACT

I BASIC PROVISIONS

Article 1

(1) This Act establishes the notion of classified and unclassified data, degrees of secrecy, the

procedure of data classification and declassification, classified and unclassified data access,

classified and unclassified data protection and oversight over the implementation of this Act.

(2) This Act applies to state authorities, local and regional self-government bodies, legal

persons with public authority and legal and natural persons that, in accordance with this Act,

gain access to or handle classified and unclassified data.

Article 2

Particular notions within the meaning of this Act shall have the following meaning:

- data are documents, or any written, copied, drawn, painted, printed, filmed,

photographed, magnetic, optical, electronic or any other type of data recording, insight,

measure, procedure, object, verbal announcement or information that, considering its

content, is significant for its owner in terms of trustworthiness and integrity,

- classified data are documents that were, within the stipulated procedure, classified as

such by the competent authority and for which the degree of secrecy has been determined,

and data that were thus classified and delivered to the Republic of Croatia by another

country, international organization or institution that the Republic of Croatia cooperates

with,

- unclassified data are documents without the determined degree of secrecy, that are used

for official purposes, and data that were thus marked and delivered to the Republic of

Croatia by another country, international organization or institution that the Republic of

Croatia cooperates with,

- data classification is the process of determining the degree of data secrecy regarding the

security threat degree and area of values protected by this Act,

Official Gazette 79/2007

2

- data declassification is the process of determining the cease of reasons for which the data

were classified with the appropriate degree of secrecy, after which data shall become

unclassified with restricted use only for official purposes,

- data owner is the competent authority within whose scope of work the classified or

unclassified data were created,

- certificate is Personnel Security Clearance that enables classified data access

Article 3

Data shall not be classified in order to conceal crime, exceeding or abuse of authority and

other types of illegal proceedings within state authorities.

II DEGREES OF SECRECY

Article 4

Classified data degrees of secrecy are as follows:

- TOP SECRET

- SECRET

- CONFIDENTIAL

- RESTRICTED

Article 5

Taking into consideration the degree of security threat to values protected with degrees of

secrecy referred to in Article 4 of this Act, data from the scope of activity of state authorities

in the field of defence, security intelligence system, foreign affairs, public security, criminal

proceedings and science, technology, public finances and economy may be classified in case

those data are of security interest for the Republic of Croatia.

Article 6

Secrecy degree TOP SECRET shall be used to classify data whose unauthorised disclosure

would result in exceptionally grave damage to national security and vital interests of the

Republic of Croatia, and especially to the following values:

- basis of the structure of the Republic of Croatia as laid down by the Constitution

- independence, integrity and security of the Republic of Croatia

- international relations of the Republic of Croatia

- defence capability and security intelligence system

- public security

- basis of the economic and financial system of the Republic of Croatia

- scientific discoveries, inventions and technologies that are of great significance for the

national security of the Republic of Croatia

Article 7

Secrecy degree SECRET shall be used to classify data whose unauthorised disclosure would

result in grave damage to values referred to in Article 6 of this Act.

Article 8

Secrecy degree CONFIDENTIAL shall be used to classify data whose unauthorised

disclosure would be damaging to the values referred to in Article 6 of this Act.

Official Gazette 79/2007

3

Article 9

Secrecy degree RESTRICTED shall be used to classify data whose unauthorised disclosure

would be damaging to the functioning of state authorities and enforcing tasks referred to in

Article 5 of this Act.

Article 10

State authorities that implement the data classification process shall, by Ordinance, establish

the criteria for determining degrees of secrecy in detail within their scope of work.

III DATA CLASSIFICATION AND DECLASSIFICATION PROCESS

Article 11

Data classification shall be done during the making of classified data or during periodical

assessments referred to in Article 14 of this Act.

Article 12

(1) During the data classification process the data owner shall determine the lowest degree of

secrecy that will secure the protection of interests that could be threatened by unauthorised

disclosure of the said data.

(2) In case the classified data contain certain parts or enclosures whose unauthorised

disclosure does not threaten the values protected by this Act, such parts of the data shall not

be classified with the degree of secrecy.

Article 13

(1) Data classification with TOP SECRET and SECRET degrees of secrecy may be done by:

the President of the Republic of Croatia, the President of the Parliament of the Republic of

Croatia, the President of the Government of the Republic of Croatia, ministers, Chief State

Attorney, Head of the General Staff of the Armed Forces of the Republic of Croatia and

Heads of authorities of the security intelligence system of the Republic of Croatia and those

that are authorised to do so by the said persons.

(2) Persons referred to in paragraph 1 of this Article shall transfer their authority to other

persons in written and solely within their respective scope of work.

(3) Data classification with CONFIDENTIAL and RESTRICTED degrees of secrecy may be

done, apart from the persons referred to in paragraphs 1 and 2 of this Article, by Heads of

other state authorities.

(4) Persons referred to in paragraphs 1, 2 and 3 of this Article shall classify data for scientific

institutions, bureaus and other legal persons when working on projects, discoveries,

technologies and other jobs of security interest for the Republic of Croatia.

Official Gazette 79/2007

4

Article 14

(1) During the time when the degree of secrecy is valid the data owner shall continuously

assess the degree of secrecy of the classified data and shall make periodical assessments based

on which the degree of secrecy can be changed or declassification can be done.

(2) Periodical assessment shall be done as follows:

- for TOP SECRET degree of secrecy at least once every 5 years,

- for SECRET degree of secrecy at least once every 4 years,

- for CONFIDENTIAL degree of secrecy at least once every 3 years,

- for RESTRICTED degree of secrecy at least once every 2 years.

(3) Data owner shall inform, in writing, all the authorities that the data were delivered to

about the change of the degree of secrecy or data declassification.

Article 15

(1) Periodical assessment shall be made in writing for each individual degree of secrecy.

(2) Data owner is authorised to make periodical assessment jointly for certain groups of data.

(3) Periodical assessment shall be classified with the same degree of secrecy as the data it

refers to and shall be attached with the original in the data owner’s archives.

Article 16

(1) When there is public interest, data owner shall determine the proportionality between the

right for data access and protection of the values stipulated in Articles 6, 7, 8 and 9 of this Act

and decide on maintaining the degree of secrecy, changing the degree of secrecy,

declassification or exemption from the obligation to keep data secret.

(2) Prior to making the decision referred to in paragraph 1 of this Article data owner shall ask

for the opinion of the Office of the National Security Council.

(3) Data owner shall inform other competent authorities stipulated by law of the procedure

referred to in paragraph 1 of this Article.

Article 17

The way of identifying classified data degrees of secrecy shall be stipulated by the Regulation

adopted by the Government of the Republic of Croatia.

IV DATA ACCESS

Article 18

(1) Access to classified data shall be granted to persons with a need-to-know and who have

Personnel Security Clearance (hereinafter: Certificate).

(2) State authorities, bodies of local and regional self-government, legal persons with public

authority, legal and natural persons (hereinafter: Applicants) are authorized to submit requests

for Certificate issuance for their employees with a need-to-know.

Official Gazette 79/2007

5

(3) Request for Certificate issuance shall be submitted in writing to the Office of the National

Security Council. The request shall contain the following: first name, last name, duty or the

jobs within which the person will have classified data access and the degree of secrecy for

which the Certificate is requested.

(4) Certificate shall be issued for TOP SECRET, SECRET and CONFIDENTIAL degrees of

secrecy for a period of five years. Certificate shall not be classified with the degree of secrecy

but shall represent unclassified data.

(5) Certificate shall be issued by the Office of the National Security Council based on the

assessment on absence of security impediments for classified data access. Existence of

security impediments shall be determined by security vetting done by competent security

intelligence agency.

(6) Security impediments within the meaning of this Act are the following: false data stated in

the Questionnaire for security vetting, facts that are stipulated by special Act as impediments

for work in the civil service, pronounced disciplinary sanctions and other facts that represent

reasonable doubt in the trustworthiness or reliability of the person to handle classified data.

Article 19

(1) In case the authority referred to in Article 18, paragraph 5 of this Act, based on the report

on results of security vetting, determines that there are security impediments it shall deny the

Certificate issuance by Decision.

(2) The person for whom Certificate issuance was denied by Decision shall not have the right

of appeal, but shall have the right to initiate administrative dispute within 30 days since the

receipt of the said Decision.

(3) During the procedure at the Administrative Court of the Republic of Croatia the Court

shall, while determining facts and presenting evidence that might damage the work of security

intelligence agencies and national security, take measures and actions from its scope of duty

that will prevent the damage from occurring.

Article 20

(1) Classified data access without the Certificate shall be granted to the Member of

Parliament, Minister, State Secretary of the Central State Administrative Office, Judge and

Chief State Attorney within the scope of their work.

(2) Persons referred to in paragraph 1 of this Article shall, before accessing classified data,

sign the Statement of the Office of the National Security Council which confirms that they

were briefed on the provisions of this Act and other rules and regulations that determine the

classified data protection and that they shall handle classified data in accordance with the said

provisions.

Article 21

The content and the template of the Certificate referred to in Article 18 of this Act and the

Statement referred to in Article 20, paragraph 2 of this Act shall be stipulated by the

Regulation adopted by the Government of the Republic of Croatia.

Official Gazette 79/2007

6

Article 22

(1) Access to classified data of another country or international organization shall be granted

to persons with a need-to-know and who have the Certificate stipulated by international treaty

or security agreement.

(2) Certificate referred to in paragraph 1 of this Article shall be issued by the Office of the

National Security Council based on the request of the competent authority.

(3) The request referred to in paragraph 2 of this Article may be submitted only for the

persons who were previously granted appropriate Certificate based on the procedure referred

to in Article 18 of this Act.

Article 23

(1) Access to unclassified data shall be granted to persons with a need-to-know.

(2) Access to unclassified data shall be granted to interested persons with right to access

information based on the submitted request in accordance with relevant Freedom of

Information Act.

Article 24

The President of the Republic of Croatia, the President of the Parliament of the Republic of

Croatia and the President of the Government of the Republic of Croatia shall be exempt to the

procedure stipulated for Certificate issuance.

V DATA PROTECTION

Article 25

The mode and implementation of classified and unclassified data protection shall be stipulated

by the Act that regulates the information security area.

Article 26

State officials and employees, local and regional self-government bodies, legal persons with

public authority as well as legal and natural persons who gain access or handle classified and

unclassified data shall keep the classified data secret during the time and after the cease of

their duty or work until the data is classified or until by the decision of data owner they are

free from the duty of keeping the secrecy thereof.

Article 27

(1) In case classified data are destroyed, stolen or made available to unauthorised persons,

data owner shall take all necessary measures to prevent the occurrence of possible damaging

consequences, shall start the procedure to determine the responsibility and shall at the same

time inform the Office of the National Security Council thereof.

(2) In case classified data are destroyed, stolen or made available to unauthorised persons

within the body that is not the data owner, the responsible person from the said body shall

immediately inform the data owner thereof and the data owner shall then initiate the

procedure referred to in paragraph 1 of this Article.

Official Gazette 79/2007

7

Article 28

(1) The Office of the National Security Council shall, when issuing the Certificate or signing

the Statement referred to in Article 20, paragraph 2 of this Act, brief the persons on the

standards of handling classified data and on other legal and other consequences of

unauthorised handling of the said data.

(2) The procedure referred to in paragraph 1 of this Article shall be implemented at least once

a year during the Certificate validity period.

VI OVERSIGHT OVER THE IMPLEMENTATION OF THE ACT

Article 29

State authorities, bodies of local and regional self-government and legal persons with public

authority shall keep records on insights into and handling of classified data.

Article 30

(1) The Office of the National Security Council shall conduct oversight over data

classification and declassification procedures, the way of gaining access to classified and

unclassified data, the implementation of the measures for the protection of classified data

access and the performance of duties from the international agreements and treaties on

classified data protection.

(2) In conducting the oversight the Head of the Office of the National Security Council has

the authority to:

- determine the facts

- give instructions in order to eliminate the determined defects and irregularities that the

bodies that were subject to oversight must eliminate within the designated period of

time

- initiate the procedure in order to determine the data owner’s responsibility

- take other measures and actions that he or she is authorised to according to special

provisions.

(3) The Office of the National Security Council shall establish registries of Certificates issued,

Decisions on Certificates denied, signed Statements referred to in Article 20, paragraph 2 of

this Act and conducted briefings on standards referred to in Article 28 of this Act.

VII TRANSITIONAL AND FINAL PROVISIONS

Article 31

(1) Regulation of the Government of the Republic of Croatia referred to in Articles 17 and 21

of this Act shall be adopted within 30 days since the date when this Act enters into force.

(2) The Ordinance referred to in Article 10 of this Act shall be adopted by Heads of

competent bodies within 60 days after the date when this Act enters into force.

Official Gazette 79/2007

8

(3) Heads of competent bodies shall determine the list of duties and jobs within their scope of

work, for which the Certificate is necessary, within 90 days.

Article 32

Degrees of secrecy determined by international treaties that the Republic of Croatia confirmed

before the date that this Act enters into force, degrees of data secrecy gained by international

exchange before the date that this Act enters into force, as well as the degrees of data secrecy

that were determined before the date that this Act enters into force shall be translated as

follows:

- STATE SECRET into TOP SECRET

- OFFICIAL SECRET-TOP SECRET and MILITARY SECRET-TOP SECRET into

SECRET

- OFFICIAL SECRET-SECRET and MILITARY SECRET-SECRET into

CONFIDENTIAL

- OFFICIAL SECRET-CONFIDENTIAL and MILITARY SECRET-CONFIDENTIAL

into RESTRICTED

Article 33

(1) Certificates that were issued by the Office of the National Security Council before the date

that this Act enters into force shall be valid until the expiry date stated on the Certificate.

(2) Internal permissions to access classified data that were issued on the basis of the Act on

Data Secrecy Protection (Official Gazette, No.108/96) shall be valid until the issuance of the

Certificate according to the provisions of this Act.

(3) Sub-Acts adopted on the basis of the Act on Data Secrecy Protection (Official Gazette,

No. 108/96) shall be implemented until the date that the appropriate sub-Acts based on this

Act enter into force.

Article 34

On the date of entry into force of this Act the provisions of the Act on Data Secrecy

Protection (Official Gazette, No. 108/96), except the provisions referred to in titles 8 and 9 of

the said Act, shall cease to have effect.

Article 35

This Act shall enter into force 8 days following its publication in the Official Gazette.

Class: 804-04/07-01/01

Zagreb, 13 July 2007

THE CROATIAN PARLIAMENT

The President of the Croatian Parliament

Vladimir Šeks, m.p.


Legislación Reemplaza (1 texto(s)) Reemplaza (1 texto(s)) Referencia del documento de la OMC
IP/N/1/HRV/5
Datos no disponibles.

N° WIPO Lex HR069