Cross-Border Data Transfer
Law on Personal Data Protection — transfer of personal data to other countries and international organisations
Serbia · August 21, 2019
Verify detailsSerbia mirrors GDPR Chapter V's structure but runs its own adequacy list. Transfer without prior authorisation is permitted to a country, territory, sector, or international organisation the Serbian Government has decided ensures an adequate level of protection — a list that presumptively includes parties to Council of Europe Convention 108, countries the EU has found adequate, and countries with which Serbia has a relevant treaty. Where the destination is not covered, transfer is allowed if the controller or processor provides appropriate safeguards and enforceable data subject rights and effective remedies are available; where authorisation is required, the Commissioner must decide within 60 days of the request. The trap for an EU-centric compliance program: Serbia is outside the EU and the EEA, so data moving between an EU parent and a Serbian subsidiary is a restricted transfer in Serbia's direction too. Marked 'check': the operative text is Serbian-language and the article numbering came from independent legal-reference sources.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.