Data Security & Breach Notification
Law on Personal Data Protection — notification of a personal data breach
Serbia · August 21, 2019
Verify detailsSerbia's law is closely modeled on the GDPR and its breach regime tracks Arts. 33-34 almost clause for clause: notify the Commissioner for Information of Public Importance and Personal Data Protection without undue delay and no later than 72 hours after becoming aware, unless the breach is unlikely to create a risk to the rights and freedoms of natural persons, with reasons required if the 72 hours are missed; notify the affected data subject without undue delay where the breach is likely to create a HIGH risk; and processors must notify their controller. The practical point for a business already GDPR-compliant is that Serbia is not in the EU or the EEA, so this is a separate regulator and a separate notification — GDPR compliance does not discharge it. Marked 'check': the operative text is Serbian-language, and the article numbering above was taken from independent legal-reference sources rather than read in the original.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.