Is your business ready?Serbian Monitor

Is your business ready?Serbian Monitor
September 5, 2026

LATEST NEWS

Is your business ready?Serbian Monitor

By Željko Loci, Solicitor at Galić Law

There is powers-that-be hardly a business in Serbia today that does not process personal data – from employees and clients to website visitors. 

That is why the new act is not a matter for tomorrow: eight years after the enactment of the current Law on Personal Data Protection, and almost seven years into its implementation, we are approaching a new, redefined, and significantly expanded version of the Personal Data Protection Act.

With 175 articles compared to the 102 in the previous version, the working group has attempted to finally secure personal data protection across all sectors, systematise all provisions, iron out the “teething troubles” of the original law, and simultaneously contribute to the direct application of EU law.

Shortcomings of the current Personal Data Protection Act

The drawbacks of the current legislation are manifold and have manifested in practice over the past seven years of its application:

Indefinite controller obligations

The data controller – as the entity determining the very purpose and means of processing, and most frequently making direct contact with the data of every individual who has consented to share their personal details – bears a broad scope of ill-defined obligations.

Specifically, a controller is obliged to implement “appropriate technical, organisational, and staffing measures” to ensure processing is carried out in line with the provisions of the law in question. However, given that the law failed to detail the specific measures a controller was required to take, it proved difficult in practice to ascertain whether the measures actually implemented were appropriate and sufficient, or whether the controller had properly satisfied their statutory duties.

In practice, this legal vacuum frequently led companies towards a minimalist interpretation of their obligations – doing just enough to formally pass an audit, but insufficient to genuinely protect the data. The new draft attempts to narrow this scope by introducing more concrete standards. This will require companies to turn compliance into measurable procedures rather than mere boilerplate documentation.

Digitalisation of public services and the expansion of personal data processing

From 2018 onwards, there has been a qualitative and quantitative surge in electronic personal data processing across Serbia. The public sector, on the one hand, introduced and expanded several public e-platforms:

The private sector, on the other hand, faced fresh challenges driven by the rapid advancement of generative artificial intelligence. With generative AI becoming widely available from late 2022, data processing tied to the development, testing, and deployment of AI systems has emerged as a key regulatory issue.

In practice, many Serbian companies are already using AI tools for candidate screening, customer support, and analytics, often without a clearly defined data protection policy for those specific purposes. Consequently, the new framework will matter not only to compliance teams, but also to IT departments, HR professionals, and business executives selecting and onboarding these tools.

In this segment, the Republic of Serbia is on track to pass regulations that will more closely govern the use of video and audio surveillance tools, artificial intelligence, and the processing of genetic and biometric data.

Frequency of breaches under the current law

Regrettably, numerous controllers and processors still fail to fully meet all obligations stemming from current legislation. This has led to widespread violations of data protection rights and potential leaks of confidential data.

A case in point was the news from April this year, when the Football Association of Serbia itself, acting as a data controller, faced severe disruption following an alleged compromise of a database containing details on over 45,000 athletes who had consented to share their personal data.

This case clearly illustrates that even large, high-profile organisations remain vulnerable. For the private sector, the message is simple: the question is not if an incident will occur, but when – and whether the company is prepared to respond quickly, cohesively, and transparently.

This brings us to the further issue of how such incidents are resolved, and whether the penalties and liabilities for breaches are severe enough. The answer is both yes and no. The current law provides for fines ranging from 50,000 to 2,000,000 dinars for legal entities, and 5,000 to 150,000 dinars for responsible individuals per violation.

While the risk of an €18,000 fine per breach can undoubtedly represent a substantial sum for an individual, micro-enterprise, or SME, it hardly leaves a mark on enterprise-level corporations, which might treat such a risk as negligible operational overheads.

By way of comparison, the GDPR provides for fines of up to €20 million or 4% of total global annual turnover – a disproportionately higher figure that serves as the benchmark Serbia is gradually moving towards.

Furthermore, misdemeanor and criminal court practice regarding violations of the current law remains insufficiently developed and widespread.

Significant changes to existing data protection rules

Consent as a basis for processing, privacy notices, and withdrawal of consent

Unlike the former definition of consent as a “freely given, specific, informed, and unambiguous indication of wishes” by statement or clear affirmative action, the new draft expands on the concept. It distinguishes between a clear affirmative action and other implied actions, leaving additional room for interpretation as to which implied actions may constitute valid consent.

In practice, this means companies will need to review all existing consent forms and privacy notices. Cookie banners, web forms, and mobile apps will all need aligning with the new requirements.

When informing individuals about intended processing, controllers will have to pay specific attention to a now structured list of details that must be provided, particularly regarding the categories of personal data subject to processing.

Withdrawal of consent takes effect the moment it is received by the controller. This requires the controller to cease consent-based processing without delay, unless another appropriate legal basis for further processing exists. While this provision protects the individual, it may create technical hurdles for controllers, particularly during a spike in withdrawal requests.

Increased sanctions for breaches

A major change is the increase in the minimum fine per established breach, rising from 50,000 to 200,000 dinars. Although the maximum fixed fine remains capped at 2,000,000 dinars, quadrupling the minimum marks a notable shift in enforcement policy. In practice, a first-time offence by a legal entity would likely trigger a fine at or near the statutory minimum. The fine for an individual in charge remains between 50,000 and 150,000 dinars, whereas sole traders face ranges between 200,000 and 500,000 dinars.

Crucially, for all offences subject to the aforementioned statutory fine, an additional fine may be imposed corresponding to the amount of damage caused or financial obligation evaded – up to twenty times that value. However, this is capped at five times the maximum statutory fine, or a total ceiling of 10,000,000 dinars.

While the baseline shift will affect the vast majority of controllers and processors committing breaches, large corporations will barely feel the financial impact of the base fine. Nevertheless, elevated financial risks should act as a deterrent and encourage companies to strengthen their compliance systems. On the other hand, capping penalties tied to twenty times the damage caused at €85,000 could significantly affect the operations and risk profile of larger businesses.

In short, for a business handling 10,000 requests a year that makes an error in just 1% of cases, the financial risk quickly multiplies.

New framework instruments

Workplace video surveillance

The new draft addresses video surveillance for the first time, placing explicit duties on employers by introducing specific rules and requirements for controllers operating CCTV systems. The objective is to define more clearly the conditions under which video surveillance is permissible and justified.

Specifically, processing personal data via video surveillance is permitted only where necessary and justified to protect individuals, property, or confidential information – provided the rights and interests of the individual or employee do not override the processing interest. In practice, where an employee’s fundamental rights outweigh the processing interest, video surveillance will be barred.

Furthermore, employers cannot use video surveillance in break rooms, changing rooms, rest facilities, or other spaces requiring heightened privacy. This raises the question of whether, and to what extent, installing cameras in these spaces without active data processing can be justified at all. Additionally, employers will be barred from using video surveillance to monitor employee performance, except in rare cases where extraordinary, overriding employer interests apply.

A controller or employer must clearly label every facility, premises, room, and outdoor area covered by video surveillance. Footage must be adequately secured against unauthorised access and made available only for legitimate, legally recognised reasons.

Clear signage

Beyond standard notices provided to individuals whose personal data will be recorded, employers must prominently display signage stating: (i) that the area is under video surveillance, (ii) the name of the controller, and (iii) the controller’s contact details. In practice, many employers currently fail to signpost monitored areas, or do so without specifying who is actually processing the data.

Any business currently operating cameras on its premises should conduct an immediate audit: Are clear signs posted? Is there a documented justification for the surveillance? Was the trade union notified? Non-compliance here could easily make a business an early target for regulatory inspection.

To justify using video surveillance in the workplace, an employer must issue a formal decision confirming that alternative, less intrusive measures were considered but deemed insufficient to safeguard the employer’s interests. Prior to issuing this decision, the employer must inform the representative trade union – a requirement that will heavily impact larger companies where union involvement is more prominent.

Data processing via artificial intelligence

In response to the rapid rise of AI, establishing a legal framework for data processing via AI tools has become essential alongside the drafting of dedicated AI legislation.

This is all the more critical given that many AI platforms use some or all shared personal data by default to train their models. Shared information can subsequently be cross-referenced, ranked, and categorised, leading to varied processing outcomes.

The draft permits data processing for the application, development, and testing of AI systems where such processing aligns with the original collection purpose. Exceptionally, processing based on the legitimate interests of the controller or a third party is permitted provided it does not override the individual’s rights and freedoms. Individuals retain the right to access and object, to which the controller must respond within 60 days.

The key limitation when processing data via AI is human oversight: the system must be operated with human involvement, meaning fully automated processing will be prohibited if it produces legal or similarly significant adverse effects on an individual. Automated processing of this nature is permitted only for historical, scientific, or statistical purposes.

Erasure of personal data

Where the conditions for erasing personal data are met, controllers will be required to notify all other controllers processing that data to ensure complete deletion (the “right to be forgotten”). This creates an added administrative duty for businesses, which must take on the responsibility of contacting third-party controllers and requesting that they follow suit.

In practice, this will prove particularly challenging for companies sharing data across large networks of partners and subcontractors. Without a centralised data transfer register, fulfilling this obligation could become a major logistical hurdle.

Additionally, individuals who gave consent to data processing at age 15 or older will have the right to request erasure on an added ground: if they were unaware of the processing risks or the implications of publishing their data online. This provision offers stronger protections for minors who may have prematurely consented to disclosing personal details online.

Procedure for exercising rights

The new draft establishes strict statutory timelines for requests submitted by individuals seeking to exercise their rights under the Personal Data Protection Act.

Specifically, a controller must notify the applicant of any deficiencies in their request within 15 days, after which the applicant has 15 days to correct them. Furthermore, the controller must act on the request without delay within a strict 30-day deadline (subject to specific exceptions). This enhances legal certainty for both applicants and controllers, who must operate within defined timeframes.

Representatives of foreign controllers / Processors without a Serbian entity

Unlike the current law, which mandated the explicit appointment of a representative, the new draft allows the legal representative of a branch or representative office of a multinational company to automatically serve as the representative for the non-resident entity (whether acting as controller or processor). This streamlined approach relieves non-resident foreign companies from the administrative burden of appointing a separate representative.

(Forbes Serbia, 04.09.2026)

https://forbes.n1info.rs/biznis/propisi/novi-zakon-o-zastiti-podataka-da-li-je-vas-biznis-spreman/

Share this post:

POLL

Who Will Vote For?

Other

Republican

Democrat

RECENT NEWS

Greece Mourns Margarita Papandreou, Pioneering Feminist

Greece Mourns Margarita Papandreou, Pioneering Feminist

Raiffeisen Bank raises Serbia’s economic growth forecast from 2.8% to 3.3%Serbian Monitor

Raiffeisen Bank raises Serbia’s economic growth forecast from 2.8% to 3.3%Serbian Monitor

Fining Bosnia’s Parties for Campaign Violations Won’t Deter Them, Expert Warns

Fining Bosnia’s Parties for Campaign Violations Won’t Deter Them, Expert Warns

Dynamic Country URL Go to Country Info Page