Serbia

Comprehensive

Law on Personal Data Protection (2018)

Authority: Commissioner for Information of Public Importance and Personal Data Protection | Enforcement: Active | Enacted: August 2019

Overview

Serbia enacted a new data protection law in 2018, closely modelled on the GDPR. The Commissioner actively enforces compliance. Serbia is an EU candidate country seeking alignment with the EU data protection framework.

14-Topic Coverage

Data Protection Authority

Fully Addressed

Commissioner oversees compliance, handles complaints, and issues enforcement measures.

Data Subject Rights

Fully Addressed

Full GDPR-aligned rights: access, rectification, erasure, restriction, portability, objection.

Cross-Border Transfer

Fully Addressed

Transfers to adequate countries or with appropriate safeguards (SCCs, BCRs).

Breach Notification

Fully Addressed

Must notify Commissioner within 72 hours. Must notify data subjects if high risk.

DPO Requirements

Fully Addressed

DPO required per GDPR-aligned criteria.

Children's Data

Fully Addressed

Parental consent for children under 15 for information society services.

Penalties & Enforcement

Fully Addressed

Fines up to RSD 2 million (approx. EUR 17,000). Lower than GDPR maximums.

Sector-Specific Rules

Fully Addressed

NBS financial data rules, health data regulations.

AI & Automated Decisions

Fully Addressed

Right to not be subject to automated decisions (GDPR Article 22 equivalent).

Data Localisation

Not Addressed

No general data localisation requirement.

Significant Data Fiduciary

Not Addressed

No equivalent concept.

Government Data

Fully Addressed

Law applies to government processing with limited exemptions.