WorldPrivacyAtlas
Laws by country

Cross-Border Data Transfer

Law on Personal Data Protection — transfer of personal data to other countries and international organisations

Serbia LPDP Arts. 63-65

Serbia · August 21, 2019

Verify details

Serbia mirrors GDPR Chapter V's structure but runs its own adequacy list. Transfer without prior authorisation is permitted to a country, territory, sector, or international organisation the Serbian Government has decided ensures an adequate level of protection — a list that presumptively includes parties to Council of Europe Convention 108, countries the EU has found adequate, and countries with which Serbia has a relevant treaty. Where the destination is not covered, transfer is allowed if the controller or processor provides appropriate safeguards and enforceable data subject rights and effective remedies are available; where authorisation is required, the Commissioner must decide within 60 days of the request. The trap for an EU-centric compliance program: Serbia is outside the EU and the EEA, so data moving between an EU parent and a Serbian subsidiary is a restricted transfer in Serbia's direction too. Marked 'check': the operative text is Serbian-language and the article numbering came from independent legal-reference sources.

Law on Personal Data Protection (Official Gazette of the RS, No. 87/2018), Arts. 63-65Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.