World Watch/Serbia/Data & Privacy

Data & Privacy · Serbia

Data protection & privacy laws in Serbia (2026)

Comprehensive lawLaw on Personal Data Protection (Official Gazette of the Republic of Serbia No. 87/2018), effective 21 August 2019; supervised by the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik)Country index 81 · B+

Serbia shaded by its data & privacy status

Serbia has a comprehensive, GDPR-aligned data protection law in force since August 2019, adopted as part of its EU accession obligations. The Commissioner (Poverenik) serves as the independent supervisory authority, with powers to investigate, issue corrective orders and impose fines. A working group was formed in January 2025 to draft a new or substantially amended law covering gaps such as cookies, video surveillance, AI, and biometric data.

Key points

Primary legislation

The Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti, Official Gazette No. 87/2018) entered into force on 21 August 2019. It mirrors the GDPR's core architecture: lawful-basis requirements, data-subject rights (access, rectification, erasure, portability, objection), privacy-by-design, data-protection impact assessments, and breach notification obligations.

Supervisory authority

The Commissioner for Information of Public Importance and Personal Data Protection (Poverenik) is the independent national DPA. It is empowered to conduct inspections (over 1,280 supervisory inspections reported in recent years), receive complaints, issue binding corrective orders, and impose fines directly.

DPO requirement

Controllers and processors must appoint a Data Protection Officer when processing is carried out by a public authority, or when core activities involve regular and systematic large-scale monitoring of data subjects, or large-scale processing of special categories of personal data — closely tracking GDPR Article 37.

Sanctions

Violations constitute misdemeanours: fines for legal entities range from RSD 50,000 to RSD 2 million (approx. EUR 425–17,000). The Commissioner may also impose fixed administrative fines (approx. EUR 850) for specific procedural breaches such as failing to publish DPO contact details. Enforcement is active but penalties remain modest compared to EU GDPR maximums.

Cross-border data transfers

Serbia has not received an EU adequacy decision. International transfers rely on standard contractual clauses or other safeguards under the PDPA. Transfer impact assessments are required for transfers to countries without equivalent protection, and EU CJEU rulings (e.g. Schrems II) are treated as persuasive authority by Serbian regulators.

Law reform in progress

In January 2025 a government working group began drafting a new or significantly amended PDPA. Priority areas include explicit regulation of cookies, video surveillance, AI-system data processing, and biometric/genetic data — gaps identified under the National Data Protection Strategy 2023–2030 adopted by the Serbian Government in August 2023. No new law has been enacted as of May 2026.

Serbia - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →