Serbia
ComprehensiveLaw on Personal Data Protection (2018)
Authority: Commissioner for Information of Public Importance and Personal Data Protection | Enforcement: Active | Enacted: August 2019
Overview
Serbia enacted a new data protection law in 2018, closely modelled on the GDPR. The Commissioner actively enforces compliance. Serbia is an EU candidate country seeking alignment with the EU data protection framework.
14-Topic Coverage
Data Protection Authority
Fully AddressedCommissioner oversees compliance, handles complaints, and issues enforcement measures.
Consent Requirements
Fully AddressedGDPR-aligned consent requirements. Must be freely given, specific, informed, and unambiguous.
Data Subject Rights
Fully AddressedFull GDPR-aligned rights: access, rectification, erasure, restriction, portability, objection.
Cross-Border Transfer
Fully AddressedTransfers to adequate countries or with appropriate safeguards (SCCs, BCRs).
Breach Notification
Fully AddressedMust notify Commissioner within 72 hours. Must notify data subjects if high risk.
DPO Requirements
Fully AddressedDPO required per GDPR-aligned criteria.
Children's Data
Fully AddressedParental consent for children under 15 for information society services.
Penalties & Enforcement
Fully AddressedFines up to RSD 2 million (approx. EUR 17,000). Lower than GDPR maximums.
Sector-Specific Rules
Fully AddressedNBS financial data rules, health data regulations.
Cookie/Tracking
Partially AddressedGeneral consent requirements apply. e-Communications provisions.
AI & Automated Decisions
Fully AddressedRight to not be subject to automated decisions (GDPR Article 22 equivalent).
Data Localisation
Not AddressedNo general data localisation requirement.
Significant Data Fiduciary
Not AddressedNo equivalent concept.
Government Data
Fully AddressedLaw applies to government processing with limited exemptions.
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Serbia's regulations.
Book a Consultation