Law on Personal Data Protection
Zakon o zastiti podataka o licnosti (Law on Personal Data Protection) Official Gazette RS No. 87/2018, arts. 1-15, 20, 41-51, 54-62, 88-94 (general provisions, principles, lawful basis, controller and processor obligations, data protection impact assessment, data protection officer, and special processing cases)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 21 August 2019.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Have one of the lawful grounds Article 12 lists, such as consent, contract necessity, legal obligation, vital interest, public interest, or legitimate interest, before processing personal data of a person in Serbia.
- Take consent only where you can demonstrate it was given, present a bundled consent request separately from other matters in plain, simple language, and let the person withdraw consent at any time as easily as they gave it.
- Take appropriate technical, organizational and staff measures proportionate to the processing's risk, keep them under review, and be able to demonstrate compliance.
- Build data protection into your processing by design and by default, including pseudonymization and data minimization.
- Appoint a written representative in Serbia when established outside Serbia and processing personal data of a person there, unless a listed exemption applies.
- Engage only a processor who guarantees appropriate technical, organizational and staff measures under a written processing agreement, and never let a processor act outside a controller's documented instructions.
- Maintain a record of processing activities covering your identity, the purposes, the categories of data subjects and data, the recipients including in other countries, any cross-border transfer and its safeguards, and the retention periods, and make it available to the Commissioner on request.
- Carry out a data protection impact assessment before processing likely to create high risk to a person's rights and freedoms, and consult the Commissioner first where the assessment shows the risk cannot be brought down.
- Designate a data protection officer where a government body processes personal data, where core activities require regular and systematic large-scale monitoring, or where core activities involve large-scale processing of special categories of personal data, and give that officer the independence and resources Article 58 requires.
What it reaches
Obligation class
Consent, Security, Retention, Governance, DPIA
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 1 sets out the law's subject matter as the right to protection of natural persons in relation to personal data processing, the free flow of such data, the principles of processing, the rights of the data subject, the duties of controllers and processors, codes of conduct, transfer of personal data to other states, and the powers of the Commissioner.
Article 3 applies the law to processing carried out wholly or partly by automated means and to non-automated processing that forms part of, or is intended for, a filing system, covering a controller or processor established in Serbia and, extraterritorially, a foreign controller or processor that offers goods or services to a person in Serbia or monitors their behavior there, and it exempts only processing by a natural person for purely personal or household purposes.
Article 12 permits processing only on one of six grounds, consent, contract necessity, legal obligation, vital interest, public interest or official authority, or legitimate interest, with legitimate interest unavailable to a public authority acting within its remit and weighed with particular care where the person is a minor.
Article 15 requires a controller to be able to demonstrate that consent was given, present a bundled consent request separately from other matters in plain and simple language, and let the person withdraw consent at any time as easily as they gave it. Article 41 makes the controller responsible for appropriate technical, organizational and staff measures proportionate to the risk and able to demonstrate compliance.
Article 42 requires data protection by design and by default, including pseudonymization and data minimization.
Article 44 requires a controller or processor established outside Serbia to appoint a written representative in Serbia unless a listed exemption applies, articles 45 and 46 require a written processing agreement before engaging a processor and bar a processor from acting outside the controller's instructions, and article 47 requires a record of processing activities covering the controller's identity, the purposes, the categories of data and data subjects, the recipients including abroad, any cross-border transfer and its safeguards, and the retention periods.
Article 54 requires a data protection impact assessment before processing likely to create high risk to a person's rights and freedoms. Article 55 requires the controller to consult the Commissioner first where the assessment shows the risk cannot be brought down.
Articles 56 to 58 require a data protection officer where a government body processes personal data, where core activities require regular and systematic large-scale monitoring, or where core activities involve large-scale processing of special categories of personal data, and set the officer's independence, resourcing and minimum duties, and articles 59 to 62 let industry bodies adopt codes of conduct and establish a data-protection certification scheme.
Articles 88 to 94 carve out narrower rules for processing in journalistic, artistic or literary expression, access to information of public importance, the unique personal identification number, employment, archiving and scientific, historical or statistical research, a religious community's own rules, and humanitarian fundraising.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreach
Read the law
Zakon o zastiti podataka o licnosti, full consolidated statute text (paragraf.rs)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.