What Does "Exposing a Registry" to GSB Mean?
Exposing a registry or data source to the Government Service Bus (GSB), a key component of the Central Interoperability System (SSI), is the process by which a public authority enables other institutions secure and automated access to its data.
Instead of physical document exchange or establishing individual (point-to-point) connections, exposing data creates a web service that is catalogued and accessible via the Government Service Bus. This enables the application of the "once-only" principle, ensures data authenticity in real-time, and significantly accelerates administrative procedures.
DATA EXPOSURE PROCEDURE (Step-by-Step)
In accordance with Article 22 of the State Information Infrastructure Act (NN 72/2025, hereinafter ZODII), the process of obtaining technical implementation consent is mandatory for every newly established registry and consists of the following phases:
1. Entry into the Metaregistry
First step: Registering registry metadata in the Metaregistry.
Procedure:
The authorised official logs into the Metaregistry via the National Identification and Authentication System (NIAS) (using substantial or high-level security credentials).
Entering metadata:
Selects the "Add Registry" option.
Fills in mandatory fields: legal basis (link to Official Gazette), purpose of data collection, update frequency, data authenticity level, and others.
Then selects "Add Service" and repeats the above procedure.
2. Technical Compliance and Test Environment
After entering metadata:
Submit a request to expose the registry data to ssi@cdu.gov.hr.
The GSB team reviews the technical specification – template available as attachment: GSB-integracijska-specifikacija.
Resources:
Standards: Detailed instructions on technical standards available on the Wiki Portal ("Government Service Bus Standards" section).
Testing: Access to the GSB test environment is granted for service development and functionality verification.
3. Compliance Verification Questionnaire
After successful testing:
The registry owner completes the Technical Solution Compliance Verification Questionnaire (proof that the service meets validation, encryption, and transaction logging standards).
The completed questionnaire is sent to: ssi@cdu.gov.hr.
4. Mandatory Security Testing (ZSIS)
Security is a prerequisite for interoperability:
Every new service must undergo mandatory testing by the Institute for Information Systems Security (ZSIS).
Penetration testing ensures system resilience against cyber threats.
Positive ZSIS report or opinion is a mandatory attachment to the consent documentation.
5. Issuance of Technical Implementation Consent
Based on the technical questionnaire and positive ZSIS report, MPUDT issues official Technical Implementation Consent (Article 22 ZODII).
Only with this consent is the service activated in the production environment of the service bus.
IMPORTANT: Procedure for Technical Changes
System stability depends on timely communication. If you plan changes to existing services:
Announcement: Change implementation request submitted to ssi@cdu.gov.hr at least 60 days in advance.
User Notification: Service owner must notify users of planned downtimes (at least 48 hours in advance for minor works, 30 days for major changes).
Re-testing: Significant changes may require re-compliance verification or security testing.
CONTACT POINTS
Purpose Contact
Official enquiries and document submission ssi@cdu.gov.hr
Technical support (GSB Admin) gsbadmin@cdu.gov.hr
Technical documentation Wiki Portal (Government Service Bus Standards)