Law / Bosnia and Herzegovina

Bosnia and Herzegovina

10 of 12 named instruments researched to a stage, across three of the six areas of law we track: 10 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 7
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law7 instruments, 7 in force

Research summary (349 words)

Bosnia and Herzegovina is not a General Data Protection Regulation (GDPR) jurisdiction, but its comprehensive personal-data statute, the Law on the Protection of Personal Data, Official Gazette of BiH No. 12/25, in force since 7 or 8 March 2025 and applicable since 4 October 2025, transposes Regulation (EU) 2016/679 for ordinary processing and Directive (EU) 2016/680 for processing by a competent authority for a criminal-law purpose, replacing the pre-GDPR 2006 Law on Protection of Personal Data (OG BiH Nos. 49/06, 76/11).

The Act binds Bosnia and Herzegovina as a state, with Article 8(2) leaving the legal basis for certain public-interest and official-authority processing to the laws of the state institutions and, within their own competences, the entities and cantons, rather than to Republika Srpska or the Federation of Bosnia and Herzegovina alone.

Reading the full text confirms a lawful-basis chapter at Article 8, a full data-subject-rights chapter at Articles 14 to 25 (mirrored for competent-authority processing at Articles 67 to 74), a heightened-processing chapter for special categories of personal data, criminal-conviction data and a child's consent to an information-society service at Articles 10 to 12, two dedicated biometric-data articles conditioned on explicit consent for secure identification and for workplace time recording and access control at Articles 57a and 57b, a personal-data-breach notification duty to the Agency within 72 hours of becoming aware of the breach and to the affected person without delay wherever the breach is a high risk (Articles 35, 36, 86 and 87), an adequacy-or-safeguards cross-border-transfer regime keyed to Council of Ministers decisions (Articles 46 to 51, mirrored at Articles 91 to 95), and an independent Personal Data Protection Agency with administrative fines reaching BAM 40,000,000 or 4 percent of worldwide turnover and a standalone judicial remedy alongside the administrative complaint (Articles 96 to 115).

What the primary text does not resolve is the maximum criminal penalty a gross violation carries: Article 115 refers that question to Bosnia and Herzegovina's Criminal Codes, plural, since the state, the Federation of Bosnia and Herzegovina, Republika Srpska and Brcko District each keep their own, and none of those four codes was read in full.

Biometric privacy

Law on the Protection of Personal Data of Bosnia and Herzegovina, biometric data processing

Law on the Protection of Personal Data, arts. 57a-57b (biometric data processing)Official English-language statute PDF hosted by the Agency for Statistics of Bosnia and Herzegovina (bhas.gov.ba)

In force 12 months, effective 4 October 2025. Binds public and private bodies.

What this law does

Article 57a permits processing biometric data only where required by law or necessary to protect a person, property, classified information or a trade secret, or for the individual secure identification of a service user, provided the person's conflicting interest does not prevail, and Article 57a(2) makes the person's explicit consent the legal basis for processing their biometric data for secure identification.

Article 57b permits processing an employee's biometric data to record working time or to control entry to and exit from official premises only where required by law or offered as an alternative to another recording or access method, and only with the employee's explicit consent.

What it requires

Breach notification

Law on the Protection of Personal Data of Bosnia and Herzegovina, personal data breach notification

Law on the Protection of Personal Data, arts. 35-36, 86-87 (personal data breach notification)Official English-language statute PDF hosted by the Agency for Statistics of Bosnia and Herzegovina (bhas.gov.ba)

In force 12 months, effective 4 October 2025. Binds public and private bodies.

What this law does

Article 35 requires the data controller to notify the Agency of a personal data breach without undue delay and, if possible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to endanger a person's rights and freedoms, giving the Agency the reasons for the delay if notice comes later than 72 hours.

Article 35(2) requires a processor to notify the controller without undue delay after becoming aware of a breach, and Article 35(3) fixes what the notification to the Agency must contain: the nature of the breach and, where possible, the categories and approximate numbers of people and records concerned, the data protection officer's or another contact point's details, the likely consequences, and the measures taken or proposed, which Article 35(4) lets the controller supply in phases where they cannot all be given at once.

Article 35(5) requires the controller to document every breach, its facts, consequences and remedial action, so the Agency can review compliance.

Article 36 requires the controller to notify the affected person in writing without delay wherever the breach is likely to result in a high risk to their rights and freedoms, describing the breach in clear and plain language and giving the same contact-point, consequences and measures information, unless the data were rendered unintelligible by a measure such as encryption, a later measure has removed the high risk, or notice would take disproportionate effort and a public notice reaches people as effectively; Article 36(4) lets the Agency require the notice anyway where none of those conditions is met.

Articles 86 and 87 restate the same 72-hour Agency notice and high-risk person notice for a competent authority processing personal data for a criminal-law purpose, and Article 86(8) additionally requires the competent authority to pass the breach information on to the data controller of another country without undue delay wherever the breached data were transmitted by or to that controller.

What it requires

Comprehensive regime

Law on the Protection of Personal Data of Bosnia and Herzegovina

Law on the Protection of Personal Data Official Gazette of Bosnia and Herzegovina No. 12/25, applicable 4 October 2025, arts. 1-9, 13, 26-34, 37-45, 52-65 (excluding 57a-57b), 75-85, 88-90 (general provisions, lawful basis, controller and processor duties, security, DPIA, DPO)Official English-language statute PDF hosted by the Agency for Statistics of Bosnia and Herzegovina (bhas.gov.ba)

In force 12 months, effective 4 October 2025. Binds public and private bodies.

What this law does

The Law on the Protection of Personal Data transposes Regulation (EU) 2016/679 for ordinary processing under Part One and Directive (EU) 2016/680 for processing by a competent authority for a criminal-law purpose under Part Two, and Article 6 gives it effect across Bosnia and Herzegovina rather than in one entity alone.

Article 8 sets the lawful bases for processing, running from the person's consent through contractual necessity, a legal obligation, vital interests, a public task or a legitimate interest that does not override the person's own rights, and Article 8(2) leaves the legal basis for a public-interest or official-authority task to the laws of the institutions of Bosnia and Herzegovina and, within their own competences, the entities and cantons.

Article 9 sets the conditions for a valid consent, including the controller's burden to demonstrate it and the person's right to withdraw it as easily as it was given, and Article 13 lets a controller that no longer needs to identify a data subject decline to acquire, keep or process additional information solely to comply with this Act.

Articles 26 to 31 allocate controller, joint-controller, processor and representative duties, and Article 27 requires personal data protection by design and by default. Article 32 requires a written record of processing activities naming the purposes, the categories of data and data subjects, the recipients, any transfer abroad and the envisaged erasure periods, with a limited exemption for an organization with fewer than 250 employees.

Article 34 requires technical and organizational security measures appropriate to the risk, including pseudonymization and encryption where appropriate. Article 37 requires a data protection impact assessment before processing likely to result in a high risk, and Article 38 requires prior consultation with the Agency where the assessment shows a risk the controller cannot mitigate.

Articles 39 to 41 require a Data Protection Officer for a public authority, for large-scale systematic monitoring, or for large-scale processing of special categories or criminal-conviction data. Articles 42 to 45 let the Agency approve a code of conduct or a certification mechanism as evidence of compliance.

Articles 52 to 59 carry sector rules for freedom of expression and information, public access to official documents, a unique identification number, the employment context, archiving and research, video surveillance, churches and religious communities, and professional secrecy.

Articles 60 to 65, 75 to 85 and 88 to 90 restate the same lawful-basis, controller-allocation, security, impact-assessment, prior-consultation and Data Protection Officer duties for a competent authority processing personal data for the prevention, investigation, detection or prosecution of a criminal offence.

What it requires

Cross border transfer

Law on the Protection of Personal Data of Bosnia and Herzegovina, cross-border transfer

Law on the Protection of Personal Data, arts. 46-51, 91-95 (cross-border transfer)Official English-language statute PDF hosted by the Agency for Statistics of Bosnia and Herzegovina (bhas.gov.ba)

In force 12 months, effective 4 October 2025. Binds public and private bodies.

What this law does

Article 46 lets a transfer to another country or international organisation take place only in compliance with this chapter, including an onward transfer. Article 47 lets a transfer proceed without further safeguards where the Council of Ministers, on the Agency's proposal, has decided that the destination ensures an adequate level of protection, a decision the Agency continuously reviews and reports on.

Absent an adequacy decision, Article 48 lets a transfer proceed on appropriate safeguards such as a legally binding instrument between public authorities, binding business rules under Article 49, an approved code of conduct or certification mechanism, or standard contractual clauses the Agency adopts, some subject to the Agency's prior approval.

Article 50 bars recognizing or carrying out a foreign court judgment or administrative decision that would require a transfer or disclosure of personal data unless it rests on an international agreement such as a mutual-legal-assistance treaty between the requesting country and Bosnia and Herzegovina.

Article 51 permits a transfer absent an adequacy decision or appropriate safeguards only on a listed derogation, such as the person's informed explicit consent, contractual necessity, an essential public interest, or a legal claim, and bars relying on the narrower residual derogation in Article 51(2) for a transfer that is repetitive or systematic.

Articles 91 to 95 restate the same adequacy, safeguards and derogation structure for a competent authority transferring personal data for the prevention, investigation, detection or prosecution of a criminal offence, adding that the transferring authority must weigh the seriousness of the offence and the destination's level of protection before authorizing an onward transfer, and that a transfer of data originally received from another country needs that country's prior authorisation except where an immediate and serious threat to public security makes obtaining it impossible in time.

What it requires

Data subject rights

Law on the Protection of Personal Data of Bosnia and Herzegovina, rights of data subjects

Law on the Protection of Personal Data, arts. 14-25, 67-74 (rights of data subjects)Official English-language statute PDF hosted by the Agency for Statistics of Bosnia and Herzegovina (bhas.gov.ba)

In force 12 months, effective 4 October 2025. Binds public and private bodies.

What this law does

Articles 14 to 16 require the controller to tell a person, in a concise, transparent, intelligible and easily accessible form, its identity and contact details, the purposes and legal basis of the processing, the recipients, any transfer abroad, the retention period and the person's rights, giving that information when the data are obtained or, where they come from elsewhere, within a reasonable period and at the latest one month afterward.

Article 17 gives a person the right to confirm whether their personal data are processed and to access them, Article 18 the right to have inaccurate data rectified, Article 19 the right to erasure on the listed grounds, and Article 20 the right to restrict processing; Article 21 requires the controller to tell every recipient the data were disclosed to of a rectification, erasure or restriction, unless that proves impossible or involves disproportionate effort.

Article 22 gives a right to receive personal data in a structured, commonly used and machine-readable format and to have it transmitted to another controller, and Article 23 gives a right to object to processing, including an unconditional right to object to direct marketing that stops the processing as soon as it is exercised.

Article 24 gives a person the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them, with a right to obtain human intervention and to express their point of view, and Article 25 lets a special law restrict these rights only where necessary and proportionate to a listed public interest.

Articles 67 to 74 carry the same information, access, rectification, erasure and restriction rights for a person whose data a competent authority processes for the prevention, investigation, detection or prosecution of a criminal offence, subject to Article 71's narrower grounds for restricting or delaying access in that context.

What it requires

Enforcement supervision

Law on the Protection of Personal Data of Bosnia and Herzegovina, the Agency, enforcement and penalties

Law on the Protection of Personal Data, arts. 96-115 (enforcement, supervision and penalties)Official English-language statute PDF hosted by the Agency for Statistics of Bosnia and Herzegovina (bhas.gov.ba)

In force 12 months, effective 4 October 2025. Binds public and private bodies.

What this law does

Article 96 establishes the Agency as an independent supervisory body seated in Sarajevo, Article 97 secures its independence, and Articles 98 to 100 govern the Agency's management, the appointment and dismissal of its Director and Deputy Director, and the incompatibility and professional-secrecy duties of its staff.

Article 101 makes the Agency responsible for the tasks and powers this Act confers and for supervising controllers and processors, other than a court exercising a judicial function, and Article 102 lists the Agency's tasks, including advising public authorities, raising public and controller awareness, deciding a person's complaint within 90 days, and approving codes of conduct, certification mechanisms and binding business rules.

Article 103 gives the Agency investigative powers, including ordering information, inspecting premises and accessing data, corrective powers, including a warning, an order to comply with a data subject's request, an order to bring processing into compliance, a temporary or permanent restriction or prohibition on processing, an order to notify a breach, and a suspension of a transfer abroad, and authorisation and advisory powers, and Article 103(4) makes an Agency decision final in administrative proceedings, subject only to an administrative dispute before the Court of Bosnia and Herzegovina.

Article 105 lets a person confidentially report a violation of this Act, and Article 107 lets the Agency carry out inspections.

Article 108 gives a person the right to complain to the Agency without prejudice to another remedy, and Article 109 gives a person, controller or processor the right to bring an administrative dispute against an Agency decision before the Court of Bosnia and Herzegovina within 60 days, or, where the Agency misses its 90-day deadline or fails to report progress on a complaint, on that same ground.

Article 110 gives a person a standalone right to judicial redress against a controller or processor, alongside the administrative complaint, and Article 111 lets a person authorize a non-profit body active in personal-data protection to exercise these rights, including a claim for compensation, on their behalf.

Article 112 entitles anyone who suffers material or non-material damage from an infringement of this Act to compensation from the controller or, in the narrower cases the article lists, the processor, with joint and several liability where more than one is responsible.

Articles 113 and 114 fix the fines: BAM 10,000 to BAM 20,000,000, or up to 2 percent of worldwide turnover, whichever is higher, for the lighter Article 113(4) violations such as a code-of-conduct or certification breach; BAM 20,000 to BAM 40,000,000, or up to 4 percent of worldwide turnover, whichever is higher, for processing contrary to the principles, lawful-basis or special-category articles, for violating a data subject's rights, for an unlawful transfer abroad, or for defying an Agency order; and a separate fine of BAM 5,000 to BAM 70,000 on the responsible natural person and BAM 500 to BAM 5,000 on an employee for the same violations, with no fine reaching the public body itself.

Article 115 refers a gross violation of this Act to Bosnia and Herzegovina's Criminal Codes for criminal liability rather than stating a penalty in this Act itself, and because the state, the Federation of Bosnia and Herzegovina, Republika Srpska and Brcko District each keep their own criminal code, more than one code can carry the offence depending on which authority is responsible.

What it requires

Sensitive categories

Law on the Protection of Personal Data of Bosnia and Herzegovina, special categories, criminal-conviction data and children's consent

Law on the Protection of Personal Data, arts. 10-12 (special categories, criminal-conviction data and children's consent)Official English-language statute PDF hosted by the Agency for Statistics of Bosnia and Herzegovina (bhas.gov.ba)

In force 12 months, effective 4 October 2025. Binds public and private bodies.

What this law does

Article 11 prohibits processing personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union affiliation, and processing genetic data, biometric data for uniquely identifying a person, health data, or data about a person's sex life or sexual orientation, unless one of the listed exceptions in Article 11(2) applies, chief among them the person's explicit consent, employment or social-security law, a vital interest, or a substantial public interest carried by a proportionate law.

Article 11(4) lets a specific law add further conditions, including limitations, on processing genetic, biometric or health data. Article 12 confines processing personal data about a criminal conviction, offence or related security measure to the supervision of a public authority or to a special law with safeguards, and keeps a register of criminal convictions exclusively under a public authority's control.

Article 10 makes a child's consent to an information-society service offered directly to them lawful from age 16, and below that age lawful only where a parent, adoptive parent or guardian gives or approves it, with the controller required to make reasonable efforts to verify that consent given available technology.

What it requires

Scraping law2 instruments, 2 in force

Research summary (305 words)

Bosnia and Herzegovina has no scraping-specific statute, so general law governs each dimension separately.

Unauthorized computer access is a criminal-law matter for the Federation of Bosnia and Herzegovina, Republika Srpska and Brcko District under their own separate entity-level criminal codes, because the state-level Criminal Code of Bosnia and Herzegovina reaches only an offense committed by an official or responsible person of a Bosnia and Herzegovina state institution; neither the state-level provision's own text nor any entity-level general unauthorized-access offense is described here.

No reported Bosnia and Herzegovina court decision addresses the enforceability of a browsewrap or clickwrap terms-of-service against a scraper. The state-level Law on Copyright and Related Rights (Official Gazette of BiH Nos. 63/10, 86/10) confines its content limitations to a closed list that includes no general text-and-data-mining exception, so training a model on scraped copyrighted text rests only on the closed list's specific exceptions, principally the quotation exception.

The same Law confers a sui generis right on the producer of a database whose creation required a qualitatively or quantitatively substantial investment, running 15 years from completion or first lawful publication and reaching even the repeated and systematic extraction of insubstantial parts where that conflicts with the database's normal use.

The Law on the Protection of Personal Data of Bosnia and Herzegovina, Official Gazette of BiH No. 12/25 (the instrument recorded under this jurisdiction's privacy topic), applies to personal data without a general carve-out for information a person has made public, so scraping personal data from a public Bosnia and Herzegovina website remains subject to that Act's lawful-basis, purpose-limitation and cross-border-transfer duties; whether that Act carries its own publicly-available-data exemption is not described here.

No Bosnia and Herzegovina statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

News aggregation law1 instrument, 1 in force

Research summary (170 words)

Bosnia and Herzegovina has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code.

Its general copyright statute, the state-level Law on Copyright and Related Rights (Official Gazette of BiH Nos. 63/10, 86/10), excludes daily news and information having the character of a brief news item conveyed in a press notice from copyright protection outright, and separately permits the faithful quotation of excerpts from a published work for scientific research, criticism, polemic, review, teaching or other commentary, without a headline-length cap or a provision naming the press specifically.

No reported decision of a Bosnia and Herzegovina court applies either provision to a systematic news aggregator rather than an individual quoting a published work. The statute predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists, and no statute or case law located addresses whether a hyperlink is itself a communication to the public or whether framing or inline display changes the answer. No hot-news or misappropriation doctrine distinct from ordinary copyright law was located.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.