Comprehensive Privacy Law
Law on Personal Data Protection
Serbia · August 21, 2019
Verify detailsSerbia's law is a close transposition of the GDPR, adopted ahead of EU accession, and Article 3 mirrors GDPR Article 3 almost verbatim: it applies to processing by a controller or processor established in Serbia, and to a controller or processor outside Serbia that offers goods or services to data subjects in Serbia (whether or not payment is required) or monitors their behavior in Serbia. Foreign controllers caught by the extraterritorial limb must appoint a representative in Serbia. Enforced by the Commissioner for Information of Public Importance and Personal Data Protection. Substantively GDPR-like, but it is a separate legal regime — an EU-adequate posture does not automatically discharge Serbian registration and representative duties.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.