Law / Serbia

Serbia

13 of 15 named instruments researched to a stage, across five of the six areas of law we track: 12 in force and 1 proposed. As of 19 September 2026.

When they take effect9 of 13 carry a date, 4 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 6 instruments (6 in force) 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 2 instruments (2 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 7
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law7 instruments, 6 in force, 1 proposed

Research summary (307 words)

Serbia is not an EU or General Data Protection Regulation (GDPR) jurisdiction, but its comprehensive personal data statute, the Law on Personal Data Protection (Zakon o zastiti podataka o licnosti), Official Gazette RS No. 87/2018, has applied since 21 August 2019 and closely mirrors the GDPR's structure. The act engages six of the seven law families this corpus tracks.

A general regime covers lawful basis, consent, controller and processor duties, data protection impact assessments, and a data protection officer (arts. 1-15, 20, 41-51, 54-62, 88-94).

A special-categories regime prohibits processing that reveals race, ethnicity, political opinion, religious or philosophical belief, trade union membership, genetic data, biometric data used for unique identification, health data, or sexual life or orientation absent a listed exception, and sets a minors' consent rule for information-society services (arts. 16-19).

A full set of data-subject rights covers access, rectification, erasure, restriction, portability, objection and protection against automated decision-making (arts. 21-40). A two-track breach-notification duty runs to the Commissioner within 72 hours and to the affected person without undue delay where the breach is high-risk (arts. 52-53).

A moderate cross-border transfer regime runs on adequacy findings, standard contractual clauses, and Commissioner-approved binding corporate rules (arts. 63-72). An enforcement and supervision structure centers on the independent Commissioner, with a civil damages right of action under Article 86 and misdemeanor fines under Article 95 rather than a general criminal offense (arts. 73-87, 95).

Serbia has not adopted a standalone biometric-identifier statute; biometric data is one item in the special-categories list rather than its own regime.

Serbia is simultaneously running a live reform: the Ministry of Justice published a draft replacement for public consultation on 30 July 2026, running through 10 September 2026, reported to grow the act from 102 to 175 articles and add new AI-processing, video-surveillance, biometric-identification, and cross-border-transfer regimes; it has not been adopted and does not currently bind.

Breach notification

Law on Personal Data Protection, personal data breach notification

Law on Personal Data Protection, arts. 52-53 (personal data breach notification), Official Gazette RS No. 87/2018Zakon o zastiti podataka o licnosti, full consolidated statute text (paragraf.rs)

In force since 21 August 2019. Binds public and private bodies.

What this law does

Article 52 requires a controller to notify the Commissioner of a personal data breach that may create risk to a person's rights and freedoms without undue delay, and within 72 hours of becoming aware of the breach where that is possible, giving reasons for any delay beyond that period. A processor must notify the controller without undue delay after becoming aware of a breach.

The notification to the Commissioner must describe the nature of the breach, give the data protection officer's or another contact point's details, describe the likely consequences and the measures taken or proposed, and article 52 lets the controller supply this information in phases without undue further delay where it cannot all be given at once; the controller must also document every breach, including its facts, effects and remedial action, so the Commissioner can assess compliance.

Article 53 requires the controller to notify the affected person without undue delay, in clear and understandable language, wherever the breach may create high risk to their rights and freedoms, but excuses that notice where encryption or another measure has made the data unintelligible, subsequent measures have removed the high risk, or notifying would take disproportionate effort and a public communication substitutes for it, with the Commissioner able to order the notice anyway.

The act states no fixed number of hours for notifying the affected person; only the notice to the Commissioner carries the 72-hour figure.

What it requires

Comprehensive regime

Draft Law on Personal Data Protection (2026 reform)

Draft Law on Personal Data Protection, Ministry of Justice of the Republic of Serbia, public consultation opened 30 July 2026IAPP news analysis, corroborated by Chambers and Partners' 2026 practice guide describing the reform as well advanced

Proposed: draft date not recorded. A published draft that has not reached a legislature, dated 30 July 2026, as of 12 September 2026. Binds public and private bodies.

What this law does

The Ministry of Justice published a draft replacement Law on Personal Data Protection for public consultation on 30 July 2026, with consultation running through 10 September 2026.

The draft is reported to grow from 102 to 175 articles and restructure the law into three parts, adding an explicit legitimate-interest basis for AI training in exceptional cases, a video-surveillance regime with a six-month retention cap, and new biometric-identification and cross-border-transfer regimes not present in the current 2018 act. It has not been introduced to the National Assembly and has not been adopted; this instrument is not currently binding.

What it requires

Law on Personal Data Protection

Zakon o zastiti podataka o licnosti (Law on Personal Data Protection) Official Gazette RS No. 87/2018, arts. 1-15, 20, 41-51, 54-62, 88-94 (general provisions, principles, lawful basis, controller and processor obligations, data protection impact assessment, data protection officer, and special processing cases)Zakon o zastiti podataka o licnosti, full consolidated statute text (paragraf.rs)

In force since 21 August 2019. Binds public and private bodies.

What this law does

Article 1 sets out the law's subject matter as the right to protection of natural persons in relation to personal data processing, the free flow of such data, the principles of processing, the rights of the data subject, the duties of controllers and processors, codes of conduct, transfer of personal data to other states, and the powers of the Commissioner.

Article 3 applies the law to processing carried out wholly or partly by automated means and to non-automated processing that forms part of, or is intended for, a filing system, covering a controller or processor established in Serbia and, extraterritorially, a foreign controller or processor that offers goods or services to a person in Serbia or monitors their behavior there, and it exempts only processing by a natural person for purely personal or household purposes.

Article 12 permits processing only on one of six grounds, consent, contract necessity, legal obligation, vital interest, public interest or official authority, or legitimate interest, with legitimate interest unavailable to a public authority acting within its remit and weighed with particular care where the person is a minor.

Article 15 requires a controller to be able to demonstrate that consent was given, present a bundled consent request separately from other matters in plain and simple language, and let the person withdraw consent at any time as easily as they gave it. Article 41 makes the controller responsible for appropriate technical, organizational and staff measures proportionate to the risk and able to demonstrate compliance.

Article 42 requires data protection by design and by default, including pseudonymization and data minimization.

Article 44 requires a controller or processor established outside Serbia to appoint a written representative in Serbia unless a listed exemption applies, articles 45 and 46 require a written processing agreement before engaging a processor and bar a processor from acting outside the controller's instructions, and article 47 requires a record of processing activities covering the controller's identity, the purposes, the categories of data and data subjects, the recipients including abroad, any cross-border transfer and its safeguards, and the retention periods.

Article 54 requires a data protection impact assessment before processing likely to create high risk to a person's rights and freedoms. Article 55 requires the controller to consult the Commissioner first where the assessment shows the risk cannot be brought down.

Articles 56 to 58 require a data protection officer where a government body processes personal data, where core activities require regular and systematic large-scale monitoring, or where core activities involve large-scale processing of special categories of personal data, and set the officer's independence, resourcing and minimum duties, and articles 59 to 62 let industry bodies adopt codes of conduct and establish a data-protection certification scheme.

Articles 88 to 94 carve out narrower rules for processing in journalistic, artistic or literary expression, access to information of public importance, the unique personal identification number, employment, archiving and scientific, historical or statistical research, a religious community's own rules, and humanitarian fundraising.

What it requires

Cross border transfer

Law on Personal Data Protection, transfer of personal data to other states

Law on Personal Data Protection arts. 63-72 (transfer of personal data to other states and international organizations), Official Gazette RS No. 87/2018Zakon o zastiti podataka o licnosti, full consolidated statute text (paragraf.rs)

In force since 21 August 2019. Binds public and private bodies.

What this law does

Article 64 permits a transfer to another country, part of its territory, a sector of activity there, or an international organization without prior approval where an adequate level of protection has been found, a status presumed for parties to the Council of Europe's Convention on the protection of individuals with regard to automatic processing of personal data.

Article 65 lets a controller or processor transfer personal data absent an adequacy finding only where it has put in place appropriate safeguards, such as a legally binding instrument between authorities, standard contractual clauses issued by the Commissioner, or binding corporate rules, and only where the person retains enforceable rights and effective legal remedies.

Article 67 requires the Commissioner to approve binding corporate rules before they may be relied on, checking that they bind every group member and its employees and expressly grant the person enforceable rights. Article 68 bars recognizing or enforcing a foreign court's or administrative authority's order to transfer or disclose personal data in Serbia unless it rests on an international agreement, such as a mutual legal assistance treaty between Serbia and that state.

Absent an adequacy finding or safeguards, article 69 allows a transfer only under a listed derogation, including the person's explicit consent given after being informed of the risks, necessity for a contract with or in the interest of the person, or an important public interest defined by Serbian law.

What it requires

Data subject rights

Law on Personal Data Protection, rights of the data subject

Law on Personal Data Protection, arts. 21-40 (rights of the data subject), Official Gazette RS No. 87/2018Zakon o zastiti podataka o licnosti, full consolidated statute text (paragraf.rs)

In force since 21 August 2019. Binds public and private bodies.

What this law does

Article 23 requires a controller, when it collects personal data directly from a person, to give them its identity and contact details, the purpose and legal basis, the recipients, any cross-border transfer, the retention period, and their rights. Article 24 extends a fuller version of that notice to data obtained from elsewhere, due within a reasonable time and no later than the first communication with the person or the first disclosure of the data.

Article 26 gives a person the right to confirmation of whether their data are processed, access to the data, and information on the purpose, categories, recipients and retention period, while article 28 limits that access only to the extent and duration necessary and proportionate in a democratic society. Article 29 gives a right to rectification of inaccurate data and completion of incomplete data.

Article 30 gives a right to erasure on listed grounds including that the data are no longer necessary, consent has been withdrawn, the person has objected, or the processing was unlawful. Article 31 gives a right to restriction of processing while accuracy is disputed, an objection is pending, or the data are needed only for a legal claim.

Article 33 requires the controller to tell every recipient the data were disclosed to about a correction, erasure or restriction, unless that is impossible or disproportionately burdensome. Article 36 gives a right to receive previously supplied personal data in a structured, commonly used, machine-readable format and to transmit it to another controller without hindrance.

Article 37 gives an unconditional right to object to processing for direct marketing, including related profiling, requiring the controller to stop on the first objection and to flag this right clearly and separately no later than the first contact with the person.

Article 38 gives a person the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or significantly affects them, unless the decision is necessary for a contract, authorized by law with adequate safeguards, or based on explicit consent, and even then guarantees the right to human intervention, to express a view, and to contest the decision.

What it requires

Enforcement supervision

Law on Personal Data Protection, the Commissioner, legal remedies and penalties

Law on Personal Data Protection, arts. 73-87 and 95 (the Commissioner, legal remedies and penalties), Official Gazette RS No. 87/2018Zakon o zastiti podataka o licnosti, full consolidated statute text (paragraf.rs)

In force since 21 August 2019. Binds public and private bodies.

What this law does

Article 73 makes the Commissioner for Information of Public Importance and Personal Data Protection an independent state authority responsible for monitoring the law's application. Article 74 bars the Commissioner from taking instructions from anyone or holding other paid or unpaid work, public office, or political role. Article 79 gives the Commissioner inspection powers, including ordering a controller or processor to supply information, checking compliance, and warning of possible violations.

Article 82 gives a person the right to complain to the Commissioner about processing they believe breaches the law. Article 83 lets any party to the Commissioner's decision challenge it in an administrative dispute within 30 days. Article 85 lets a person authorize a privacy advocacy association to represent them in a complaint, an administrative dispute, a court action, or a damages claim.

Article 86 gives a person who suffered material or non-material damage from a breach of the law a court-enforceable right to monetary compensation from the controller, or from the processor only where it acted outside the controller's lawful instructions or its own duties under the law.

Article 87 requires fines to be set case by case for an effective, proportionate and dissuasive effect, weighing factors including the nature, gravity and duration of the violation, intent or negligence, mitigation efforts, prior violations, and cooperation with the Commissioner.

Article 95 fixes those fines as misdemeanor sanctions rather than criminal offenses: 50,000 to 2,000,000 dinars for a legal-entity controller or processor's breach of most of the act's substantive duties, a separate fixed 100,000 dinars for a shorter list of narrower violations, 5,000 to 150,000 dinars for a natural person or a responsible person within an entity, and 20,000 to 500,000 dinars for an entrepreneur, imposed by the Commissioner through a misdemeanor order or misdemeanor court proceedings.

What it requires

Sensitive categories

Law on Personal Data Protection, special categories of personal data and minors

Law on Personal Data Protection, arts. 16-19 (special categories of personal data and minors), Official Gazette RS No. 87/2018Zakon o zastiti podataka o licnosti, full consolidated statute text (paragraf.rs)

In force since 21 August 2019. Binds public and private bodies.

What this law does

Article 17 prohibits processing that reveals racial or ethnic origin, political opinion, religious or philosophical belief, or trade union membership, or that involves genetic data, biometric data used to uniquely identify a person, health data, or data about a person's sex life or sexual orientation, unless one of ten listed exceptions applies, among them the person's explicit consent for one or more specified purposes, necessity under employment or social-security law, protecting vital interests where the person cannot consent, a nonprofit political, philosophical, religious or trade-union body processing only its own members' data, data the person has manifestly made public, preventive or occupational medicine, and archiving or scientific, historical or statistical research.

Article 18 applies a narrower version of the same prohibition to a competent authority processing special categories of personal data for law-enforcement or national-security purposes, permitting it only where the authority is authorized by law, the processing protects vital interests, or the data was manifestly made public by the person.

Article 19 confines processing of data on criminal convictions, offences and security measures to processing under the control of, or specifically authorized by law for, a competent authority, and keeps any unified register of criminal convictions solely under that authority's control.

Article 16 lets a minor of 15 or older give their own consent to processing personal data for an information-society service, and below that age consent must come from the parent exercising parental responsibility or another legal representative, with the controller required to take reasonable steps, considering available technology, to verify it.

Serbia has not adopted a standalone biometric-identifier statute, and the definition in article 4 and the restriction in article 17 treat biometric data as one item within this special-categories regime rather than a dedicated one.

What it requires

Scraping law2 instruments, 2 in force

Research summary (236 words)

Serbia has no scraping-specific statute, so general law governs each dimension separately. The Criminal Code's computer-crime chapter criminalises unauthorised access achieved by circumventing a protection measure, so a plain reading does not reach a scraper reading a public, unauthenticated page that defeats no access control, and no reported Serbian decision has tested the point. No Serbian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Law on Copyright and Related Rights permits temporary, transient reproduction that is an integral part of a technological process and has no independent economic significance, and a separate right of quotation for short excerpts, but carries no text-and-data-mining-specific exception, so training a model on scraped copyrighted text rests only on those general grounds.

The Act confers a sui generis database producer's right against extraction or re-utilisation of the whole or a substantial part of a database, unauthorised reproduction of which is also a punishable economic offence.

The Personal Data Protection Act, which already has its own jurisdiction document under the privacy topic, applies to personal data without a general carve-out for information the data subject has made public, so scraping personal data from a public Serbian website remains subject to that Act's lawful-basis and purpose-limitation duties.

No Serbian statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Criminal Code, Offences Against the Security of Computer Data

Krivicni zakonik (Criminal Code), Official Gazette RS No. 85/2005 et seq., Arts. 298-304aOfficial English translation of the Criminal Code, WIPO Lex

In force since 1 January 2006. Binds public and private bodies.

What this law does

Article 302 punishes whoever, by circumventing protection measures, accesses a computer, computer network, or electronic data processing without authorisation, with a fine or imprisonment up to six months, rising to up to two years for using data obtained that way, and up to five years where the offence causes a hold-up or serious malfunction.

Article 298 separately punishes unauthorised deletion, alteration, damage or concealment of computer data or a program, and Article 304a punishes producing, procuring, or distributing devices or access codes designed for committing an offence under Arts. 298 to 303. Because Article 302's offence is triggered by circumventing a protection measure, reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision.

The consolidated Criminal Code, per the WIPO Lex record's own metadata, entered into force on 1 January 2006; the chapter has since been carried through further gazetted amendments up to 94/2016.

What it requires

Database right

Law on Copyright and Related Rights, Right of the Database Producer

Zakon o autorskom i srodnim pravima Arts. 137-140v (Right of the Database Producer), Official Gazette RS No. 104/2009, 99/2011, 119/2012, 29/2016 and 66/2019Consolidated statute text, Paragraf Lex

In force. Binds public and private bodies.

What this law does

Article 137 defines a database producer as the person who has made a substantial investment, quantitative or qualitative, in obtaining, verifying, or presenting a database's contents.

Article 138 gives that producer the right to prohibit extraction or re-utilisation of the whole or a substantial part, quantitatively or qualitatively, of the database's contents, and Article 139 additionally prohibits systematic extraction or re-utilisation of insubstantial parts where that conflicts with normal exploitation of the database or unreasonably prejudices the producer's legitimate interests.

Article 140b lets a lawful user of a database made available to the public extract or re-utilise insubstantial parts for any purpose, and Article 140v allows a lawful user to extract substantial parts without the producer's authorisation only for personal non-commercial use, non-commercial teaching, or judicial or public-security proceedings, each under the conditions the Act sets for the equivalent copyright exception.

Unauthorised reproduction, publication, or public communication of a database, in whole or in part, is also a punishable economic offence (privredni prestup) for a business entity or other legal person, distinct from a criminal offence under the Criminal Code. The Act commences the eighth day after publication in the Official Gazette, a formula the reviewed source does not resolve to a calendar date for this consolidated text.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (440 words)

Serbia replaced its 2016 information-security statute with a new Law on Information Security ("Sl. glasnik RS", br. 91/2025), which aligns the country's cyber-resilience regime with the EU's NIS2 Directive ahead of accession.

The new law sorts a duty-bearer into one of two tiers, a priority ICT system (energy and mining, transport, banking and financial markets, health, drinking water, wastewater, digital infrastructure including cloud computing and data-centre services, managed ICT and managed security services, and a residual list including trust services, DNS, top-level domain registries, and electronic-communications activity, plus every government organ and every designated critical-infrastructure operator) or an important ICT system (postal services, waste and packaging-waste management, chemicals, food wholesale and industrial production, several manufacturing sectors, an information-society service under Serbia's e-commerce law, arms production, ground-based space services, research institutions, and any other Article 5 subject not already classified as priority).

Both tiers carry the same core duties: registration in the Ministry's registry, a risk-assessment act and a security act each reviewed at least annually, thirty-seven itemised technical, operational, organisational and physical protection measures, and a duty to notify a significant incident without delay and at the latest within 24 hours of becoming aware of it, with further status reports every three days (medium-level incident) or every 24 hours (high or very high-level incident) and a final report within 15 days of the incident ending.

A Government bylaw still to be issued will add general and sector-specific criteria, including a size threshold, for classifying priority and important operators; until it exists, classification runs on the statutory sector list alone.

The National Bank of Serbia and the Securities Commission enforce this law's duties for banking and financial-market operators under their own sectoral rules rather than through this law's general fines, and that banking-sector duty-bearer is not an activity this corpus's vocabulary can express, the same treatment this profile gives Singapore's and Japan's individually-designated critical-infrastructure operators, so it is named here rather than raised against a declared activity.

A narrow cryptographic-product approval scheme (Arts. 43-44), administered by the ministry responsible for defence, and a voluntary, anonymisable vulnerability-disclosure database the National CERT authority maintains (Art. 36) sit alongside the law without creating a general product-security or vulnerability-handling duty on a manufacturer placing a product on the market, so Serbia has no product_security_requirements instrument.

The Law on Personal Data Protection carries its own security-of-processing duty for a controller or processor; that stays this jurisdiction's privacy-topic finding and is not restated here. Unauthorised access to a computer or IKT system is dealt with by the Criminal Code, Article 302, already this jurisdiction's scraping-topic instrument, which binds the intruder rather than the operator this topic researches.

Sector security regimes

Law on Information Security, ICT Systems of Special Importance and Security Measures

Zakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 5-12Consolidated statute text, Paragraf Lex (paragraf.rs), sourced from "Službeni glasnik Republike Srbije", br. 91/2025

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

Articles 5 and 6 sort a duty-bearer into a priority or an important ICT system of special importance by sector, reaching an information-society service provider under Serbia's e-commerce law directly among the important-system sectors.

Articles 7 and 10 through 12 require every such operator to register, adopt and annually revise a risk-assessment act, adopt a security act built on it, check applied measures against that act at least once a year, and take thirty-seven itemised technical, operational, organisational and physical protection measures including multi-factor or continuous authentication.

A Government bylaw still to be issued will add general and sectoral criteria, including a size threshold, for designating an operator of either tier. A banking or financial-market operator instead follows sector-specific information-security rules the National Bank of Serbia or the Securities Commission issues under this law, which must provide at least the same level of effectiveness as Article 10's measures.

What it requires

Vulnerability and incident reporting

Law on Information Security, Incident Reporting Obligations

Zakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 13-14, 24-25Consolidated statute text, Paragraf Lex (paragraf.rs), sourced from "Službeni glasnik Republike Srbije", br. 91/2025

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

Article 13 requires a priority or important ICT system operator to notify a significant incident without delay and at the latest within 24 hours of becoming aware of it, and to report a near-miss that constitutes a serious threat on the same basis.

Article 14 routes that notification through a single incident-reporting system, with a banking or financial-market operator also notifying the National Bank of Serbia or the Securities Commission and an electronic-communications or postal operator instead notifying the Regulatory Body for Electronic Communications and Postal Services, and requires notice to affected users without delay where an incident harms or may harm the provision or use of a service.

Article 24 adds a during-incident reporting clock of every three days for a medium-level incident or every 24 hours for a high or very high-level incident, plus a final report within 15 days of the incident ending. Article 25 adds an annual statistical return, covering incidents and near-misses, due to the National CERT authority by 28 February of the following year.

What it requires

Age gating law1 instrument, 1 in force

Research summary (87 words)

Serbia has no adult-content age-verification statute, social-media minor-access restriction, or app-store age-verification requirement confirmed in the primary text reviewed.

The Law on Electronic Media, Official Gazette RS No. 92/2023 and 51/2025, binds every media service provider to a general duty of protecting minors from content harmful to their physical, mental or moral development, and adds a video-sharing platform provider to appropriate measures against the same harm, sourced from the platform's own user-generated content. No separate adult-content age-verification bill was located in the sources reached during this visit.

Age-appropriate design code

Law on Electronic Media, Protection of Minors and Video-Sharing Platform Obligations

Zakon o elektronskim medijima (Law on Electronic Media), Official Gazette RS No. 92/2023 and 51/2025, Arts. 64, 115-116, 125Consolidated statute text, Paragraf Lex

In force. Binds public and private bodies.

What this law does

Article 64 requires every media service provider to take all measures necessary so that its program content does not harm the physical, mental or moral development of minors, and to act in a minor's best interest when timing or otherwise publishing content that could cause that harm.

Article 115 additionally requires a video-sharing platform provider to take appropriate measures to protect minors from program content, user-generated video content, or audiovisual commercial communications that could harm that development. Article 116 lets the Regulatory Authority for Electronic Media specify those measures further, having regard to the nature and potential harm of the content and the categories of persons to protect.

A legal-entity provider that fails to comply with either duty is liable to a fine of 500,000 to 2,000,000 dinars. The law commences the eighth day after publication in the Official Gazette, a formula the reviewed source does not resolve to a calendar date.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (169 words)

Serbia has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Law on Copyright and Related Rights (2009, as amended through 2019) is the only law reaching an aggregator's reproduction of news content.

Its quotation right permits reproducing and publicly communicating short excerpts of a published work without the author's consent, subject to a good-practice test and source attribution, with no headline-length cap or restriction to the press industry.

The Act separately gives publishers of printed editions a right to a share of the private-copying remuneration levy, a right tied to reprography and personal-use recording rather than to online reproduction, so it does not function as a Digital Single Market (DSM) Article 15-style neighbouring right against a news aggregator.

No statute or reported Serbian decision addresses whether a hyperlink is a communication to the public, whether framing or inline display changes the answer, or a hot-news or misappropriation doctrine distinct from ordinary copyright law, and the Act predates the concept of a machine-readable text-and-data-mining reservation.

Snippet reproduction

Law on Copyright and Related Rights, Right of Quotation

Zakon o autorskom i srodnim pravima, Art. 49 (Right of Quotation), Official Gazette RS No. 104/2009, 99/2011, 119/2012, 29/2016 and 66/2019Consolidated statute text, Paragraf Lex

In force. Binds public and private bodies.

What this law does

Article 49 permits, without the author's authorization or payment of remuneration, reproducing and other forms of publicly communicating short excerpts of a copyrighted work, or individual short works, provided the work quoted has been published and the excerpt is integrated unaltered into another work where necessary for illustration, confirmation or reference, clearly marked as a quotation in accordance with good practice.

The author's name, the title of the quoted work, and where and when it was published or issued must also be indicated where known. The article carries no headline-length or short-extract cap distinct from this good-practice test, and no reported Serbian decision applies it to a systematic news aggregator rather than an individual quoting a published work. The Act commences the eighth day after publication in the Official Gazette, a formula the reviewed source does not resolve to a calendar date.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.