Bosnia and Herzegovina
SubstantialLaw on the Protection of Personal Data (2006, amended)
Authority: Personal Data Protection Agency (AZLP) | Enforcement: partial | Enacted: December 2006
Overview
Bosnia and Herzegovina enacted data protection legislation in 2006, based on the EU Data Protection Directive. The AZLP oversees compliance. The country is working on GDPR alignment as part of EU approximation.
14-Topic Coverage
Data Protection Authority
Fully AddressedAZLP oversees compliance, handles complaints, and maintains data controller registry.
Consent Requirements
Fully AddressedConsent required. Must be free, express, and informed.
Data Subject Rights
Fully AddressedRights to access, correction, blocking, and erasure.
Cross-Border Transfer
Fully AddressedTransfers to countries with adequate protection.
Breach Notification
Partially AddressedNo explicit statutory requirement.
DPO Requirements
Partially AddressedMust register data collections with AZLP.
Children's Data
Partially AddressedGeneral provisions apply.
Penalties & Enforcement
Fully AddressedAdministrative fines. Enforcement capacity developing.
Sector-Specific Rules
Partially AddressedCBBH financial data rules, health data regulations.
Cookie/Tracking
Not AddressedNo specific cookie regulation.
AI & Automated Decisions
Not AddressedNo specific provisions.
Data Localisation
Not AddressedNo general data localisation requirement.
Significant Data Fiduciary
Not AddressedNo equivalent concept.
Government Data
Fully AddressedLaw applies to government processing with national security exemptions.
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Bosnia and Herzegovina's regulations.
Book a Consultation