Data & Privacy · Bosnia & Herzegovina
Data protection & privacy laws in Bosnia & Herzegovina (2026)
Bosnia & Herzegovina shaded by its data & privacy status
Bosnia and Herzegovina enacted a new, comprehensive Law on Personal Data Protection in early 2025, replacing the outdated 2006 legislation and aligning the country's data-protection regime with EU Regulation 2016/679 (GDPR) and Directive 2016/680. The law was published in the Official Gazette on 28 February 2025, entered into force on 8 March 2025, and became fully applicable on 4 October 2025 after a 210-day transition period. The reform reflects BiH's EU accession obligations and mirrors GDPR structure, principles, rights, and enforcement mechanisms.
Key points
The Law on Personal Data Protection (OG BiH No. 12/25) was adopted by the Parliamentary Assembly on 30 January 2025 and repeals the 2006 Personal Data Protection Act. It is directly modelled on the GDPR (EU 2016/679) and also transposes Directive 2016/680 (law-enforcement data processing).
The Agency for Personal Data Protection (AZLP) is the independent national supervisory authority. The 2025 law substantially strengthens its powers, granting it investigatory, corrective, and sanctioning competencies explicitly modelled on GDPR Article 58.
The law codifies the full GDPR suite of rights: access, rectification, erasure (right to be forgotten), restriction of processing, data portability, and the right to object, as well as rights related to automated decision-making and profiling.
Controllers must maintain records of processing activities, apply data-protection-by-design and by-default, conduct data-protection impact assessments for high-risk processing, and appoint a Data Protection Officer (DPO) where required. Foreign controllers processing BiH residents' data must designate a local representative.
For the most serious infringements, fines can reach up to BAM 40 million (approximately EUR 20 million) or 4% of total worldwide annual turnover, whichever is higher — a direct parallel to GDPR's two-tier penalty structure.
Alignment with GDPR is a formal EU accession requirement for BiH, which received candidate status in 2022. As of early 2026 the AZLP had not yet published all secondary implementing bylaws and guidelines, meaning some operational detail remains pending.
Bosnia & Herzegovina - other topics
Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →