Privacy Policy

Last updated: 14 July 2026 · Version 2026-05-28

This Privacy Policy explains how the Ministry of Agriculture, Forestry and Fisheries — Directorate of Fisheries ("we", "the Ministry", "the Controller") processes personal data collected through the Trapula mobile application ("the App") when you report suspected illegal fishing activity. We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the Croatian Act on the Implementation of the General Data Protection Regulation.

You can submit a report without an account and without giving your name. Verifying an e-mail is optional and only links your own reports across your devices.

1. Who is the controller

The controller is the Ministry of Agriculture, Forestry and Fisheries — Directorate of Fisheries (address above). For any privacy question you may contact our Data Protection Officer at zop@mps.hr.

2. What the App is for

Trapula lets any citizen anonymously report suspected irregularities in marine and freshwater fisheries (e.g. unmarked fishing gear, sale of fish without traceability, catching fish and other aquatic organisms during closed season, fishing in prohibited areas, unauthorised fish shops, sale of catch from sport or recreational fishing). Reports are stored locally on the device and synchronised to our server when an internet connection is available.

3. What personal data we process

DataPurposeNotes
Photos and videos you capture or selectEvidence of the reported activityMay incidentally contain personal data (faces, licence plates, vessel markings, persons).
GPS coordinates (optional)To locate the reported activityOnly if you add a location.
Date and time of the reportTo process and prioritise the report
Device identifier (installation UUID) and device modelTo group your reports across your devices, prevent abuse, and provide supportThe UUID is app-generated, not the hardware serial.
App version and interface languageTechnical processing and localisation
Report description and report type (marine/freshwater)The substance of your report
E-mail address (optional)Only if you choose to verify it, to link your reports across your devicesNever required to submit a report.
Record of legal-notice acceptance (version and time)To demonstrate you were informed before use

4. Anonymity and its limits

The App is designed so reports are anonymous towards other users and you are not required to identify yourself or create an account. However, technical data (such as the device identifier or content of photos/videos) may, if strictly required by law and by a competent authority, allow a device or person to be identified. Do not include your own identifying data in the description unless you want to.

5. Purposes and legal bases (GDPR Art. 6)

PurposeLegal basis
Receiving, reviewing and acting on reports of suspected fisheries-law violations, and forwarding them to inspection and other competent authoritiesPerformance of a task carried out in the public interest / in the exercise of official authority (Art. 6(1)(e) GDPR), based on national fisheries and inspection legislation.
Linking your reports across devices via a verified e-mailYour consent (Art. 6(1)(a) GDPR), which you may withdraw at any time by removing the e-mail link in the App.
Preventing and investigating abuse, false or malicious reports, and securing the servicePerformance of a task carried out in the public interest or in the exercise of official authority (Art. 6(1)(e) GDPR).

6. Who receives the data

Personal data from reports may be made available to: the fisheries inspection and other inspection services of the Ministry; other competent state authorities where a violation is suspected (e.g. police, State Attorney's Office) strictly within their legal powers; and our IT processors who host and maintain the system under a data-processing agreement. We do not sell personal data and do not use it for advertising.

7. International transfers

Personal data is stored and processed within the European Economic Area (EEA). We do not transfer your personal data to third countries.

8. Retention

We keep report data only as long as necessary for the purposes above and for the periods required by applicable fisheries, inspection and archiving rules. Reports that lead to no action and contain no evidentiary value are deleted or anonymised once review is complete. Device records and an optional e-mail link are kept while the device uses the App and are removed on request or after prolonged inactivity.

9. Your rights

Under the GDPR you have the right to: access your personal data; rectification; erasure ("right to be forgotten"); restriction of processing; object to processing based on public interest or legitimate interest; and data portability where applicable. Because reports can be submitted fully anonymously, we may be unable to link a specific report to you without additional information from you (Art. 11 GDPR). To exercise your rights contact zop@mps.hr. You also have the right to lodge a complaint with the supervisory authority, the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr.

10. Automated decision-making

We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects on you.

11. Data security

We apply appropriate technical and organisational measures (encryption in transit, access controls, audit logging) to protect personal data against unauthorised access, loss or misuse.

12. Children

The App is not intended for children. If you are a minor, use it only with the consent of a parent or guardian.

13. Changes to this Policy

We may update this Policy; the current version and date are shown at the top. Material changes are indicated by a new legal-notice version, which the App may ask you to accept again.

14. Contact

Data Protection Officer — e-mail: zop@mps.hr. Controller: Ministry of Agriculture, Forestry and Fisheries — Directorate of Fisheries, Ulica grada Vukovara 78, 10000 Zagreb.