Law on the Protection of Personal Data of Bosnia and Herzegovina
Law on the Protection of Personal Data Official Gazette of Bosnia and Herzegovina No. 12/25, applicable 4 October 2025, arts. 1-9, 13, 26-34, 37-45, 52-65 (excluding 57a-57b), 75-85, 88-90 (general provisions, lawful basis, controller and processor duties, security, DPIA, DPO)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force 12 months, effective 4 October 2025.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Establish a lawful basis under Article 8 before processing personal data of a person in Bosnia and Herzegovina, and appoint a Data Protection Officer under Articles 39 to 41 wherever the processing meets the threshold the Act sets, such as processing carried out by a public authority or large-scale monitoring or special-category processing.
- Keep a written record of processing activities under Article 32, covering the purposes, the categories of data subjects and data, the recipients, any transfer abroad, and the envisaged erasure periods, and make it available to the Agency on request.
- Implement technical and organizational measures appropriate to the risk under Article 34, including pseudonymization and encryption where appropriate, and instruct anyone with access to personal data not to process it beyond the controller's authorization.
- Carry out a data protection impact assessment under Article 37 before processing likely to result in a high risk to a person's rights and freedoms, and consult the Agency in advance under Article 38 wherever the assessment shows a high risk the controller cannot mitigate.
What it reaches
Obligation class
Consent, Security, DPIA, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Law on the Protection of Personal Data transposes Regulation (EU) 2016/679 for ordinary processing under Part One and Directive (EU) 2016/680 for processing by a competent authority for a criminal-law purpose under Part Two, and Article 6 gives it effect across Bosnia and Herzegovina rather than in one entity alone.
Article 8 sets the lawful bases for processing, running from the person's consent through contractual necessity, a legal obligation, vital interests, a public task or a legitimate interest that does not override the person's own rights, and Article 8(2) leaves the legal basis for a public-interest or official-authority task to the laws of the institutions of Bosnia and Herzegovina and, within their own competences, the entities and cantons.
Article 9 sets the conditions for a valid consent, including the controller's burden to demonstrate it and the person's right to withdraw it as easily as it was given, and Article 13 lets a controller that no longer needs to identify a data subject decline to acquire, keep or process additional information solely to comply with this Act.
Articles 26 to 31 allocate controller, joint-controller, processor and representative duties, and Article 27 requires personal data protection by design and by default. Article 32 requires a written record of processing activities naming the purposes, the categories of data and data subjects, the recipients, any transfer abroad and the envisaged erasure periods, with a limited exemption for an organization with fewer than 250 employees.
Article 34 requires technical and organizational security measures appropriate to the risk, including pseudonymization and encryption where appropriate. Article 37 requires a data protection impact assessment before processing likely to result in a high risk, and Article 38 requires prior consultation with the Agency where the assessment shows a risk the controller cannot mitigate.
Articles 39 to 41 require a Data Protection Officer for a public authority, for large-scale systematic monitoring, or for large-scale processing of special categories or criminal-conviction data. Articles 42 to 45 let the Agency approve a code of conduct or a certification mechanism as evidence of compliance.
Articles 52 to 59 carry sector rules for freedom of expression and information, public access to official documents, a unique identification number, the employment context, archiving and research, video surveillance, churches and religious communities, and professional secrecy.
Articles 60 to 65, 75 to 85 and 88 to 90 restate the same lawful-basis, controller-allocation, security, impact-assessment, prior-consultation and Data Protection Officer duties for a competent authority processing personal data for the prevention, investigation, detection or prosecution of a criminal offence.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachgenerates_content
Read the law
Official English-language statute PDF hosted by the Agency for Statistics of Bosnia and Herzegovina (bhas.gov.ba)
read in full (207,438 characters, untruncated)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.