WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Europe

Serbia Privacy & Data Protection Laws

Every regime below can apply to a business handling Serbia residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

August 21, 2019
Law on Personal Data Protection
Serbian LPDP
Verify details

Serbia's law is a close transposition of the GDPR, adopted ahead of EU accession, and Article 3 mirrors GDPR Article 3 almost verbatim: it applies to processing by a controller or processor established in Serbia, and to a controller or processor outside Serbia that offers goods or services to data subjects in Serbia (whether or not payment is required) or monitors their behavior in Serbia. Foreign controllers caught by the extraterritorial limb must appoint a representative in Serbia. Enforced by the Commissioner for Information of Public Importance and Personal Data Protection. Substantively GDPR-like, but it is a separate legal regime — an EU-adequate posture does not automatically discharge Serbian registration and representative duties.

Official Gazette of the Republic of Serbia No. 87/2018, Art. 3 (territorial application)Read regulation →

Cross-Border Data Transfer · 1

Serbia mirrors GDPR Chapter V's structure but runs its own adequacy list. Transfer without prior authorisation is permitted to a country, territory, sector, or international organisation the Serbian Government has decided ensures an adequate level of protection — a list that presumptively includes parties to Council of Europe Convention 108, countries the EU has found adequate, and countries with which Serbia has a relevant treaty. Where the destination is not covered, transfer is allowed if the controller or processor provides appropriate safeguards and enforceable data subject rights and effective remedies are available; where authorisation is required, the Commissioner must decide within 60 days of the request. The trap for an EU-centric compliance program: Serbia is outside the EU and the EEA, so data moving between an EU parent and a Serbian subsidiary is a restricted transfer in Serbia's direction too. Marked 'check': the operative text is Serbian-language and the article numbering came from independent legal-reference sources.

Law on Personal Data Protection (Official Gazette of the RS, No. 87/2018), Arts. 63-65Read regulation →

Data Security & Breach Notification · 1

Verify details

Serbia's law is closely modeled on the GDPR and its breach regime tracks Arts. 33-34 almost clause for clause: notify the Commissioner for Information of Public Importance and Personal Data Protection without undue delay and no later than 72 hours after becoming aware, unless the breach is unlikely to create a risk to the rights and freedoms of natural persons, with reasons required if the 72 hours are missed; notify the affected data subject without undue delay where the breach is likely to create a HIGH risk; and processors must notify their controller. The practical point for a business already GDPR-compliant is that Serbia is not in the EU or the EEA, so this is a separate regulator and a separate notification — GDPR compliance does not discharge it. Marked 'check': the operative text is Serbian-language, and the article numbering above was taken from independent legal-reference sources rather than read in the original.

Law on Personal Data Protection (Official Gazette of the RS, No. 87/2018), Arts. 52-53Read regulation →

Other Europe jurisdictions