Skip to the content
Global Data RulesData governance rules, country by country

Serbia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Serbia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Active

Serbia copied Europe's privacy law almost word for word, so the duties feel familiar. Data can leave the country. For most of Europe and a long list of other countries, it can leave with no paperwork at all. The privacy regulator is busy. It ran over a thousand inspections in 2025. But it hands out warnings, not fines. The biggest fine any Serbian court imposed for a privacy breach in 2025 was about $950.

Data governance in Serbia

The eight things that decide how you handle data about people in Serbia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it reaches you even with no office in Serbia. The law covers a company anywhere in the world that offers goods or services to people in Serbia. It also covers a company that watches what they do in Serbia. There is no size or revenue threshold. If the law catches you, you must appoint a representative living or based in Serbia, in writing. The exceptions are narrow: occasional low-risk work, and public bodies.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, with paperwork. Often with none at all. Serbia treats a very long list of countries as automatically safe. That list is every member of the Council of Europe's data protection treaty. It covers all of Europe plus Argentina, Mexico, Morocco, Mauritius, Senegal, Tunisia, Uruguay, Cape Verde and others. It also covers every country the European Union has approved. Sending data there needs no permission and no contract. Everywhere else, you sign the Commissioner's standard contract or use approved group rules. Only one industry has a strict rule: online gambling. Banking has a permission gate instead.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules

What to do: Get the paperwork for one of the routes below signed before any data leaves Serbia.

Sending data out of the country

First check the destination. If it is on the safe list, you need nothing. No contract, no filing, no approval. If it is not on the list, you sign the standard contract the Serbian regulator published in January 2020. Or you get approved group-wide rules. If you want to use your own wording instead of the standard contract, the regulator must approve it. It has 60 days to answer. As a last resort there are narrow exceptions, such as the person's explicit consent.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Approved code of conduct · Certification scheme · Government sign-off needed · Explicit consent

What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.

The regulator, and whether it actually acts

The Commissioner for Information of Public Importance and Personal Data Protection, and it really works. In 2025 it finished 1,169 inspections, received 5,310 cases and issued 102 corrective orders. But it almost never fines. Of those 102 orders, 101 were warnings and one was a ban on using data. It asked the courts to punish only three organisations all year. Banks answer to the National Bank of Serbia instead, and it is fully active. A brand-new Office for Information Security has existed on paper since October 2025. We found no sign it is running yet.

How long you must keep it — and when to delete it

There is no single national rule. The privacy law says keep data only as long as you need it, and each sector sets its own clock. Online gambling operators must keep every transaction for at least ten years. Phone and internet companies must keep who-called-whom records for exactly 12 months and then destroy them. Anyone selling a phone line must keep the customer's identity check for 12 months after the service ends. Financial firms must keep a live register of every outsourced service, including which countries the data sits in.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count three clocks. Privacy breach: tell the Commissioner without delay, and at the latest within 72 hours. If you miss that, you must explain why. Cyber incident: if you run an information system the state has classed as important, you have only 24 hours to report it. Then a third clock starts. You send updates every 24 hours for a serious incident, and every three days for a middling one. A final report is due within 15 days of the incident ending. Banks report cyber incidents to the central bank instead, promptly, with no fixed hour count.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five. (1) A child can consent for themselves at 15, not 13 or 16. Plan your age gates around 15. (2) A foreign court order or foreign tax demand for data is recognised in Serbia only if a treaty backs it. So handing data to an overseas authority on request can itself be unlawful. (3) Individuals can be prosecuted, not just companies. The regulator has filed 49 criminal complaints since 2010. (4) Dozens of older Serbian laws still contradict the privacy law and were never fixed. (5) The government's official list of safe destination countries has not been touched since 2019. It still names a United States arrangement that died in 2020.

What you have to do here:
Get a parent's consent for children · Do not hand data to foreign authorities on demand
What it costs if you get it wrong:
Criminal liability

What's changing next

One dated change and several unscheduled ones. From 1 January 2027 the ministry formally takes over supervising the new Office for Information Security. That should mean the office is actually up and running by then. A special working group is drafting a rewrite of the privacy law. It covers video surveillance, biometrics, genetic data and artificial intelligence. A separate group is drafting an artificial intelligence law. Neither has been published as a bill, so neither is binding.

What to do: Diarise 1 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Online gaming data needs a copy kept in the country

Official name: Pravilnik o informaciono-komunikacionom sistemu za priređivanje posebnih igara na sreću preko sredstava elektronske komunikacije · Službeni glasnik RS, br. 152/2020, izmene 58/2025 · Government rules

In forceA copy must stay

Serbia's one real rule about keeping data in the country. An online gambling operator must hold its database inside Serbia. That is the database of everything reported to the Gaming Administration. It can be the live database or a copy of it. Transactions must be kept for at least ten years. The Administration gets constant access to the data, plus a remote connection into the system.

In force since 26 December 2020

Enforced by Administration for Games of Chance

How this country controls where data goes: Approval each time

Finance

Banking rules

Official name: Odluka o uslovima i načinu poveravanja aktivnosti u vezi sa informaciono-komunikacionim sistemom finansijske institucije trećim licima · Službeni glasnik RS, br. 100/2023; NBS EB No 83 of 9 November 2023 · Directly binding regulation

In forceYes, with paperwork

Banks, insurers and other financial firms in Serbia may put IT work and data abroad. But they have to pass a gate. You tell the central bank 30 days before signing. You prove the destination country would let Serbian supervisors inspect the supplier on site. You keep a register of exactly which countries hold the data. The central bank can block the deal, or force you to unwind one you have already signed.

In force since 25 November 2023Enforced from 1 March 2024

Enforced by National Bank of Serbia

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Banking

Payment data rules

Official name: Odluka o minimalnim standardima upravljanja informaciono-komunikacionim sistemom finansijske institucije · Službeni glasnik RS, br. 102/2024; NBS EB No 85 of 20 December 2024 · Directly binding regulation

In forceYes, with paperwork

The new rulebook for how Serbian banks, insurers and payment firms run and secure their technology. It replaced the 2013 rules and only started to apply on 1 January 2026. Banks that had already notified a core-system migration got a short extension, to 30 June 2026. It sets a 24-hour clock to classify a cyber incident and report it to the central bank.

In force since 28 December 2024Enforced from 1 January 2026

Enforced by National Bank of Serbia

How this country controls where data goes: Approval each time

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Europe's main privacy law

Official name: Zakon o zaštiti podataka o ličnosti · Službeni glasnik RS, br. 87/2018 · Act of parliament

In forceYes, with paperwork

Serbia's general privacy law, a close copy of Europe's General Data Protection Regulation. It reaches foreign companies that target Serbia and makes them appoint a local representative. Sending data abroad is free to a long list of countries treated as safe. Everywhere else needs the Commissioner's standard contract or something equivalent. The penalties are the striking difference from Europe. Fines are capped at two million dinars, roughly $19,000. There is no percentage-of-turnover option.

In force since 21 November 2018Enforced from 21 August 2019

Enforced by Commissioner for Information of Public Importance and Personal Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Certification scheme, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

Government data rules

Official name: Odluka o Listi država, delova njihovih teritorija ili jednog ili više sektora određenih delatnosti u tim državama i međunarodnih organizacija u kojima se smatra da je obezbeđen primereni nivo zaštite podataka o ličnosti · Službeni glasnik RS, br. 55/2019; 05 broj 021-7718/2019 · Official “this country is safe” decision

In forceYes — store it anywhere

The Government's list of destinations treated as safe. Part one names 54 members of the Council of Europe data protection treaty. That is all of Europe plus Argentina, Mexico, Morocco, Mauritius, Senegal, Tunisia, Uruguay, Cape Verde, Turkey, Russia and others. Part two names the destinations the European Union had approved in 2019. Sending personal data anywhere on this list needs no contract and no permission.

In force since 10 August 2019Enforced from 21 August 2019

Enforced by Government of the Republic of Serbia

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Nothing required

Cyber security rules

Official name: Zakon o informacionoj bezbednosti · Službeni glasnik RS, br. 91/2025 · Act of parliament

Partly in forceYes — store it anywhere

Serbia's replacement cyber security law, in force since 31 October 2025. It creates a new Office for Information Security. It gives operators of important systems 24 hours to report a serious incident. It makes them register with the ministry, including how many physical locations their system occupies. It has no requirement to keep data in Serbia. One part of it, on ministry supervision of the new Office, only starts on 1 January 2027.

In force since 31 October 2025

Enforced by Office for Information Security — not yet operational

How this country controls where data goes: No restriction · Accepted routes: Nothing required

On the books, but not enforceable1 rule

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

Government data rules (not enforced)

Official name: Lista država, Deo II, tačka 7) — Sjedinjene Američke Države (ograničeno na „Privacy Shield framework”) · Službeni glasnik RS, br. 55/2019, Part II item 7 · Official “this country is safe” decision

UnenforceableYes, with paperwork

The Government's list still says the United States is safe under the Privacy Shield arrangement. The European Court of Justice struck that arrangement down on 16 July 2020. Serbia's own regulator said in August 2020 that the entry can no longer be relied on. The line is still printed in the Official Gazette six years later. So reading the list at face value gives you the wrong answer.

In force since 21 August 2019

Enforced by Commissioner for Information of Public Importance and Personal Data Protection

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Approved group rules

Who you would hear from

  • Повереник за информације од јавног значаја и заштиту података о личности

    General privacy law; also freedom of information

    Clearly working. It received 5,310 cases and completed 1,169 inspections in 2025. It handled 1,354 cases in July 2026 alone. It advertised senior vacancies in August 2026. But it issues warnings, not fines. 101 of its 102 corrective measures in 2025 were warnings. It asked the courts to punish only three organisations. Commissioner Milan Marinović was elected on 26 July 2019.

  • Влада Републике Србије

    Adopts and amends the list of countries treated as providing adequate protection

    Can add to, change or cut back the safe-country list at any time by decision. It has not used that power since 1 August 2019.

  • Народна банка Србије

    Banking, insurance, payments, financial leasing, virtual currency services; supervision of their information systems and outsourcing

    Fully active. Issues binding decisions, receives outsourcing notifications and cyber incident reports, and can veto an outsourcing arrangement.

  • Регулаторно тело за електронске комуникације и поштанске услуге (РАТЕЛ)

    Telecoms and postal services; also hosts the National CERT

    Active. Still operating the national computer emergency response team at cert.rs, with advisories published as recently as 12 August 2026.

  • Канцеларија за информациону безбедност

    Cyber incident handling and the national CERT role under the 2025 information security law

    Created by the Law on Information Security, in force since 31 October 2025. But we found no website, no director announcement and no published decisions as of 18 August 2026. The telecoms regulator is still running the national computer emergency response team. Ministry supervision of the Office only begins on 1 January 2027, which suggests it is still being built.

  • Управа за игре на срећу

    Land-based and online games of chance; approves and inspects operators' technical systems

    Active; issues and updates technical rulebooks, most recently amending the online gaming system rulebook in 2025.

  • Канцеларија за информационе технологије и електронску управу

    Public sector information technology; runs the State Data Centre in Kragujevac

    Active. Operates the State Data Centre, which also sells commercial hosting. We could not confirm any statutory duty forcing public bodies to keep their data there.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether transfers to United States organisations certified under the EU-US Data Privacy Framework (adopted by the European Union in July 2023) are treated as adequate in Serbia

    We could not confirm that the current EU-US Data Privacy Framework counts as a safe destination in Serbia. Article 64(2) points at whatever the European Union has approved, which would cover it. But the Government's list has never been updated, and no Serbian authority has published a confirmation. The same gap applies to South Korea, approved by the European Union in December 2021. Safer to use the standard contract clauses.

  • Whether Serbian public bodies are legally obliged to keep their systems and data in the State Data Centre in Kragujevac or otherwise in Serbia

    We could not confirm the legal basis for the State Data Centre. The Office for Information Technology and eGovernment runs it under the Law on Electronic Government. We could not read that law. We make no claim that data must be kept in the country here.

  • Whether the Office for Information Security has been constituted, has a director, and is issuing decisions

    We could not confirm whether the Office for Information Security is actually operating. The law creating it has been in force since 31 October 2025. We found no website, no appointment notice and no published output. We can show that the telecoms regulator still runs the national computer emergency response team. Ask the ministry if you need the Office's current status.

  • Whether Commissioner Milan Marinović's mandate is still current

    We could not confirm that the Commissioner's term is still running. The institution's own pages say he was elected by the National Assembly on 26 July 2019, and still name him in August 2026. But they do not state the term length, and we found no re-election notice. Serbia has previously run this office for months on a deputy after a term expired.

  • Any localisation or storage rule for health records, education, securities markets, mapping and geospatial data, or defence

    We found no health rule requiring data to stay in Serbia, checked 18 August 2026, medium confidence. The health ministry's own laws page lists only the Healthcare Act. It does not publish the Act on Health Documentation and Records, so we could not read the keeping periods for medical files. If you work in health, check before you rely on this.

  • Whether a dedicated law on lawful interception and data retention has been adopted since 2023

    We could not confirm whether a dedicated interception and record-keeping law has been passed. The 2023 electronic communications law repeatedly defers to such a law, and kept the old articles alive pending it. We found no adopted text. But we could not search the Official Gazette properly, because the state legal information portal blocks automated access.

  • Precise dinar-to-dollar conversions for the penalty figures

    Dollar figures here are converted at roughly 105 dinars to the dollar. We could not read the National Bank's live middle rate, which is served through a separate web application. Treat every dollar figure here as an approximation.

  • The exact date the National Assembly adopted the Law on Personal Data Protection

    We could not confirm the adoption date from a gazette page we could open. The gazette number (87/2018) and the date arithmetic are solid. Both give 21 November 2018 for entry into force and 21 August 2019 for application. The adoption date of 9 November 2018 is our inference from the publication date.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.