Regulation Finder/Bosnia and Herzegovina

Bosnia and Herzegovina

Substantial

Law on the Protection of Personal Data (2006, amended)

Authority: Personal Data Protection Agency (AZLP) | Enforcement: partial | Enacted: December 2006

Overview

Bosnia and Herzegovina enacted data protection legislation in 2006, based on the EU Data Protection Directive. The AZLP oversees compliance. The country is working on GDPR alignment as part of EU approximation.

14-Topic Coverage

Data Protection Authority

Fully Addressed

AZLP oversees compliance, handles complaints, and maintains data controller registry.

Data Subject Rights

Fully Addressed

Rights to access, correction, blocking, and erasure.

Cross-Border Transfer

Fully Addressed

Transfers to countries with adequate protection.

Breach Notification

Partially Addressed

No explicit statutory requirement.

DPO Requirements

Partially Addressed

Must register data collections with AZLP.

Children's Data

Partially Addressed

General provisions apply.

Penalties & Enforcement

Fully Addressed

Administrative fines. Enforcement capacity developing.

Sector-Specific Rules

Partially Addressed

CBBH financial data rules, health data regulations.

AI & Automated Decisions

Not Addressed

No specific provisions.

Data Localisation

Not Addressed

No general data localisation requirement.

Significant Data Fiduciary

Not Addressed

No equivalent concept.

Government Data

Fully Addressed

Law applies to government processing with national security exemptions.

Coverage Summary

Fully Addressed6/14
Partially Addressed4/14
Not Addressed4/14
Pending0/14

Need Compliance Help?

Our data privacy team can help you navigate Bosnia and Herzegovina's regulations.

Book a Consultation