Serbia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Serbia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Serbia copied Europe's privacy law almost word for word, so the duties feel familiar. Data can leave the country. For most of Europe and a long list of other countries, it can leave with no paperwork at all. The privacy regulator is busy. It ran over a thousand inspections in 2025. But it hands out warnings, not fines. The biggest fine any Serbian court imposed for a privacy breach in 2025 was about $950.
Data governance in Serbia
The eight things that decide how you handle data about people in Serbia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it reaches you even with no office in Serbia. The law covers a company anywhere in the world that offers goods or services to people in Serbia. It also covers a company that watches what they do in Serbia. There is no size or revenue threshold. If the law catches you, you must appoint a representative living or based in Serbia, in writing. The exceptions are narrow: occasional low-risk work, and public bodies.
- What you have to do here:
- Appoint a representative
Article 3(4) of the Law on Personal Data Protection covers companies and their suppliers with no office in Serbia. It applies where the work relates to offering goods or services to people in Serbia, paid or free. It also applies where the work relates to monitoring their behaviour in Serbia. Article 44 requires you to appoint a representative in Serbia, in writing. The exemptions are narrow. Failing to appoint one is a fixed 100,000 dinar offence under Article 95(2)(4). The Commissioner can fine you for it directly, without going to court. Almost nobody complies. The Commissioner's 2025 annual report records only 22 appointment decisions from foreign companies in the whole year.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionZakon o zaštiti podataka o ličnosti, Službeni glasnik RS 87/2018, Articles 3 and 44
poverenik.rs
“Овај закон примењује се на обраду података о личности лица на које се подаци односе које има пребивалиште, односно боравиште на територији Републике Србије од стране руковаоца, односно обрађивача који нема седиште ... ако су радње обраде везане за: 1) понуду робe, односно услуге ... 2) праћење активности лица на које се подаци односе.”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025, Table 2 — 22 representative-appointment decisions processed
poverenik.rs
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork. Often with none at all. Serbia treats a very long list of countries as automatically safe. That list is every member of the Council of Europe's data protection treaty. It covers all of Europe plus Argentina, Mexico, Morocco, Mauritius, Senegal, Tunisia, Uruguay, Cape Verde and others. It also covers every country the European Union has approved. Sending data there needs no permission and no contract. Everywhere else, you sign the Commissioner's standard contract or use approved group rules. Only one industry has a strict rule: online gambling. Banking has a permission gate instead.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules
Article 64(2) treats two groups of destinations as safe by law. They are the parties to Council of Europe Convention 108, and the destinations the European Union has officially approved. The Government published the list on 1 August 2019, in Official Gazette 55/2019. Part I names 54 Convention 108 states. Part II names Guernsey, Israel, Japan, Canada (commercial organisations), the Isle of Man, New Zealand, the Faroe Islands, Jersey, and the United States 'limited to the Privacy Shield framework'. That list has never been amended. So it is out of date in both directions. It still names an American arrangement the European Court of Justice killed in July 2020. And it has never been updated to add South Korea, approved by the European Union in December 2021, or the current EU-US Data Privacy Framework of July 2023. Article 64(2) works by law rather than through the list. So the better reading is that the safe group tracks whatever the European Union currently recognises. But no Serbian authority has confirmed that in writing for the 2023 arrangement. Industry exceptions. Online gambling is a copy must stay in the country A live or copy database must sit in Serbia. Banking, insurance and payments are data can leave only if conditions are met You must notify the central bank, and it can veto. Telecoms must keep traffic data for 12 months, with no rule about where it sits. The public sector runs a State Data Centre in Kragujevac, but we could not find a legal duty to use it. We found no rule forcing data to stay in the country for health, education, securities, mapping or defence, checked 18 August 2026, medium confidence.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionZakon o zaštiti podataka o ličnosti, Articles 63 to 71 (transfer to other states and international organisations)
poverenik.rs
“Сматра се да је примерени ниво заштите ... обезбеђен у државама и међународним организацијама које су чланице Конвенције Савета Европе о заштити лица у односу на аутоматску обраду личних података, односно у државама ... за које је од стране Европске уније утврђено да обезбеђују примерени ниво заштите.”
Link checked 18 August 2026
- Official sourceGovernment of the Republic of SerbiaOdluka o Listi država ... u kojima se smatra da je obezbeđen primereni nivo zaštite podataka o ličnosti, Službeni glasnik RS 55/2019, 1 August 2019
poverenik.rs
“7) Сједињене Америчке Државе (ограничено на „Privacy Shield framework”)”
Link checked 18 August 2026
- Official sourceAdministration for Games of Chance, Ministry of FinanceRulebook on the information and communication system for organising online games of chance, Article 2(6) — database must be in Serbia
uis.gov.rs
“which must be located on the territory of the Republic of Serbia, either as a production base or as a replica of that base (e.g. mirror or replica server)”
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Serbia.
Sending data out of the country
First check the destination. If it is on the safe list, you need nothing. No contract, no filing, no approval. If it is not on the list, you sign the standard contract the Serbian regulator published in January 2020. Or you get approved group-wide rules. If you want to use your own wording instead of the standard contract, the regulator must approve it. It has 60 days to answer. As a last resort there are narrow exceptions, such as the person's explicit consent.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Approved code of conduct · Certification scheme · Government sign-off needed · Explicit consent
Article 65(2) lists the safeguards you can use with no approval. There are five. A legally binding arrangement between public authorities. The standard contract clauses drawn up by the Commissioner (Decision, Official Gazette 5/2020). Approved group-wide rules. An approved code of conduct. Or a certification. Article 65(3) covers contract terms you write yourself. Those need the Commissioner's specific approval, which must come within 60 days. Article 69 lists the narrow exceptions. Take-up is tiny. In the whole of 2025 the Commissioner approved exactly one set of group-wide rules, for ACUMATICA d.o.o. Belgrade. So either the destination is already treated as safe, or you build the safeguard yourself. There is no list of banned countries. The Government has never used its Article 64(3) power to declare a country unsafe.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionOdluka o utvrđivanju standardnih ugovornih klauzula, Službeni glasnik RS 5/2020
poverenik.rs
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionPodzakonski akti — the complete list of bylaws made under the Law on Personal Data Protection
poverenik.rs
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025 — one set of binding corporate rules approved in the year
poverenik.rs
Link checked 18 August 2026
What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.
The regulator, and whether it actually acts
The Commissioner for Information of Public Importance and Personal Data Protection, and it really works. In 2025 it finished 1,169 inspections, received 5,310 cases and issued 102 corrective orders. But it almost never fines. Of those 102 orders, 101 were warnings and one was a ban on using data. It asked the courts to punish only three organisations all year. Banks answer to the National Bank of Serbia instead, and it is fully active. A brand-new Office for Information Security has existed on paper since October 2025. We found no sign it is running yet.
The Commissioner cannot impose the large fines itself. Under Article 79(2)(9) it may fine you only by misdemeanour warrant, and only where the law sets a fixed amount. Everything else goes to the misdemeanour courts. In 2025 those courts delivered eight first-instance decisions on the Commissioner's requests. Four cases were discontinued, three of them because they had timed out. Four convictions produced one warning and three fines. Two of those were 100,000 dinars against a company, plus 10,000 against the responsible individual. One was 50,000 plus 5,000. Since 2010 the Commissioner has filed 49 criminal complaints. Prosecutors brought only two charges. Those produced one conviction, six months suspended, and one acquittal. Twenty-three complaints were dismissed and five investigations timed out. The Commissioner is Milan Marinović, elected by the National Assembly on 26 July 2019. The institution was still publishing monthly caseload figures and advertising senior vacancies in August 2026. The national computer emergency response team is still run by the telecoms regulator. The new Office for Information Security, created by the 2025 information security law, has no website we could find.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025 — 1,169 inspections, 102 corrective measures, 3 misdemeanour requests, 49 criminal complaints since 2010
poverenik.rs
“Повереник је у току 2025. године окончао укупно 1.169 надзора ... донете су 102 корективнe мерe којима је изрекао 101 опомену руковаоцима и 1 руковаоцу привремено/трајно ограничио вршење радње обраде”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's news feed — July 2026 monthly caseload (1,354 cases) and August 2026 recruitment notices
poverenik.rs
Link checked 18 August 2026
- Official sourceRegulatory Authority for Electronic Communications and Postal ServicesNational CERT of Serbia — still operated by the telecoms regulator, advisories published 12 August 2026
cert.rs
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is no single national rule. The privacy law says keep data only as long as you need it, and each sector sets its own clock. Online gambling operators must keep every transaction for at least ten years. Phone and internet companies must keep who-called-whom records for exactly 12 months and then destroy them. Anyone selling a phone line must keep the customer's identity check for 12 months after the service ends. Financial firms must keep a live register of every outsourced service, including which countries the data sits in.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep records of how you use data
The maximum. Article 5(1)(5) of the Law on Personal Data Protection says do not keep data longer than you need it. Telecoms are unusual, because the same rules set both a minimum and a maximum. Article 128(6) of the 2010 electronic communications law requires 12 months of keeping, counted from the date of the communication. That article is still in force as a surviving fragment. Article 130(1)(4) requires destruction once that period ends. Minimums. The online gambling rulebook requires at least ten years of transaction data. After that, archived data must still be produced to the Administration within five days. The 2023 electronic communications law covers the identity check taken when a subscriber signs up. That data must be kept for the subscription and for 12 months after it ends. What happens when they clash. Article 100 of the privacy law said other laws should have been brought into line by the end of 2020. The Commissioner's 2025 report says flatly that this never happened. So people follow the specific industry law.
Sources
- Official sourceRegulatory Authority for Electronic Communications and Postal ServicesZakon o elektronskim komunikacijama (2010, consolidated), Articles 128 to 130a — 12-month retention and mandatory destruction
ratel.rs
“Operator iz stava 1. ovog člana dužan je da zadržane podatke čuva 12 meseci od dana obavljene komunikacije.”
Link checked 18 August 2026
- Official sourceAdministration for Games of Chance, Ministry of FinanceRulebook on the ICT system for online games of chance, Article 6 — ten-year transaction retention
uis.gov.rs
“The organizer is obliged to store all transactions in the data system for at least ten years from the date of the transaction”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025 — the Article 100 alignment deadline of end-2020 was never met
poverenik.rs
“Обавеза из члана 100. ЗЗПЛ ... није испуњена.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count three clocks. Privacy breach: tell the Commissioner without delay, and at the latest within 72 hours. If you miss that, you must explain why. Cyber incident: if you run an information system the state has classed as important, you have only 24 hours to report it. Then a third clock starts. You send updates every 24 hours for a serious incident, and every three days for a middling one. A final report is due within 15 days of the incident ending. Banks report cyber incidents to the central bank instead, promptly, with no fixed hour count.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Personal data breach. Articles 53 and 54 of the Law on Personal Data Protection apply. Tell the Commissioner within 72 hours where there is a risk to people. Tell the affected people themselves without undue delay where the risk is high. The Commissioner received only 49 breach reports in the whole of 2025. That is very low for a country of seven million, and suggests widespread under-reporting. Cyber. Article 13 of the new Law on Information Security, Official Gazette 91/2025, covers operators of information and communication systems of special importance. They must report without delay, and at the latest within 24 hours of becoming aware. Article 14 sends banking and financial-market operators to the National Bank of Serbia. Firms supervised by the Securities Commission also report to that Commission. Article 24 sets the follow-up rhythm. Send updates every 24 hours for high and very high severity, and every three days for medium. A final report is due within 15 days of the incident ending. Under the National Bank's 2024 technology decision, a financial institution must classify an incident within 24 hours of detecting it. If it cannot, it must file an initial report anyway.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionZakon o zaštiti podataka o ličnosti, Articles 53 and 54 — 72-hour breach notification
poverenik.rs
“Руковалац је дужан да о повреди података о личности која може да произведе ризик по права и слободе физичких лица обавести Повереника без непотребног одлагања, или, ако је то могуће, у року од 72 часа од сазнања за повреду.”
Link checked 18 August 2026
- Official sourceRegulatory Authority for Electronic Communications and Postal Services (official copy of the gazette text)Zakon o informacionoj bezbednosti, Službeni glasnik RS 91/2025, Articles 13, 14 and 24 — 24-hour cyber incident reporting
ratel.rs
“Оператори ИКТ система од посебног значаја дужни су да доставе обавештење о инциденту који може да има значајан утицај на нарушавање информационе безбедности, без одлагања, а најкасније у року од 24 сата од када су сазнали за инцидент.”
Link checked 18 August 2026
- Official sourceNational Bank of SerbiaDecision on Minimum Information-Communication System Management Standards for Financial Institutions, Official Gazette 102/2024, Sections 41 and 44
nbs.rs
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five. (1) A child can consent for themselves at 15, not 13 or 16. Plan your age gates around 15. (2) A foreign court order or foreign tax demand for data is recognised in Serbia only if a treaty backs it. So handing data to an overseas authority on request can itself be unlawful. (3) Individuals can be prosecuted, not just companies. The regulator has filed 49 criminal complaints since 2010. (4) Dozens of older Serbian laws still contradict the privacy law and were never fixed. (5) The government's official list of safe destination countries has not been touched since 2019. It still names a United States arrangement that died in 2020.
- What you have to do here:
- Get a parent's consent for children · Do not hand data to foreign authorities on demand
- What it costs if you get it wrong:
- Criminal liability
(1) Article 16. A minor who has turned 15 may consent alone to online services. Below 15 a parent must consent, and you must take reasonable steps to check that. (2) Article 68. A foreign court or administrative authority may order you to transfer or disclose personal data. Serbia recognises or enforces that order only if it rests on an international agreement. A mutual legal assistance treaty is the usual example. This mirrors the European resistance to overseas surveillance demands. It hits cloud providers with United States parents hardest. (3) The Commissioner's criminal complaints run under Criminal Code Articles 143 to 146. Those cover unauthorised interception, photography, publication and collection of personal data. They also run under Articles 299, 302, 329, 355 and 359. Conviction rates are near zero and cases often time out. But the exposure is personal. (4) Article 100 required all other laws touching personal data to be brought into line by the end of 2020. The Commissioner reports this was never done. So industry rules on video surveillance, policing and health records still sit awkwardly against the privacy law. (5) The Government's Decision of 1 August 2019 has never been amended. The Commissioner formally wrote to the Government in August 2020 asking for it to be brought into line. That was after the European Court of Justice struck down the Privacy Shield. Nothing changed.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionZakon o zaštiti podataka o ličnosti, Articles 16, 68 and 100
poverenik.rs
“Одлуке суда или управног органа друге државе, којима се од руковаоца или обрађивача захтева пренос или откривање података о личности, могу бити признате или извршене у Републици Србији само ако се заснивају на међународном споразуму.”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's notice of 11 August 2020 on the effect of the European Court of Justice ruling on Privacy Shield transfers
poverenik.rs
“Повереник је упутио допис Влади у циљу усаглашавања те одлуке са Законом о заштити података о личности и европском праксом.”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025 — 49 criminal complaints since 2010, two indictments, one conviction
poverenik.rs
Link checked 18 August 2026
What's changing next
One dated change and several unscheduled ones. From 1 January 2027 the ministry formally takes over supervising the new Office for Information Security. That should mean the office is actually up and running by then. A special working group is drafting a rewrite of the privacy law. It covers video surveillance, biometrics, genetic data and artificial intelligence. A separate group is drafting an artificial intelligence law. Neither has been published as a bill, so neither is binding.
Dated. Article 58 of the Law on Information Security, Official Gazette 91/2025, brought the law into force eight days after publication on 23 October 2025. The exception is Article 29, on ministry supervision of the Office for Information Security. That applies from 1 January 2027. Financial institutions have already absorbed the National Bank's new technology decision, which applied from 1 January 2026. A narrow exception ran to 30 June 2026, for banks that had notified a core-system migration. Powers that already exist and can be used at any time, with no consultation. The Government can replace or amend the safe-country list by decision. It can also declare a country unsafe under Article 64(3), except for parties to the Council of Europe treaty. It has never used that power. The National Bank can order a financial institution to unwind an outsourcing contract on concentration grounds. It can do that at any time, before or after the fact. Watch also for the lawful interception and record-keeping law that the 2023 electronic communications law assumed would arrive. Until it does, Serbia's record-keeping rules survive only as a fragment of a repealed statute.
Sources
- Official sourceRegulatory Authority for Electronic Communications and Postal Services (official copy of the gazette text)Zakon o informacionoj bezbednosti, Službeni glasnik RS 91/2025, Article 58 — entry into force, with Article 29 applying from 1 January 2027
ratel.rs
“Овај закон ступа на снагу осмог дана од дана објављивања у „Службеном гласнику Републике Србије”, изузев члана 29. овог закона који почиње да се примењује од 1. јануара 2027. године.”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025 — special working group on amendments to the Law on Personal Data Protection, and a separate working group on an artificial intelligence law
poverenik.rs
“најважнија активност у 2025. години је била рад на доношењу новог Закона о заштити података о личности”
Link checked 18 August 2026
What to do: Diarise 1 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Online gaming data needs a copy kept in the country
Official name: Pravilnik o informaciono-komunikacionom sistemu za priređivanje posebnih igara na sreću preko sredstava elektronske komunikacije · Službeni glasnik RS, br. 152/2020, izmene 58/2025 · Government rules
Serbia's one real rule about keeping data in the country. An online gambling operator must hold its database inside Serbia. That is the database of everything reported to the Gaming Administration. It can be the live database or a copy of it. Transactions must be kept for at least ten years. The Administration gets constant access to the data, plus a remote connection into the system.
Enforced by Administration for Games of Chance
How this country controls where data goes: Approval each time
What you have to do
- Keep the data in the countryThe database of everything reported to the Administration must be on Serbian territory. It can be the live database or a copy of it. Handling the data elsewhere is not forbidden. The Serbian copy is what is compulsory.
- Keep data for a minimum period — 10 yearsAll transactions, at least ten years. After that, archived data must be produced to the Administration within five days on request.
- Register or notifyThe Administration must have permanent access to transaction type, time and amount, and remote access to the system over a private network.
What it costs if you get it wrong
- Loss of your licenceBreach of the technical conditions attached to an online games of chance approval
Sources
- Official sourceAdministration for Games of Chance, Ministry of FinanceRulebook on the information and communication system for organising special games of chance by means of electronic communication (English text), Articles 2, 6 and 7
uis.gov.rs
“which must be located on the territory of the Republic of Serbia, either as a production base or as a replica of that base (e.g. mirror or replica server)”
Link checked 18 August 2026
- Official sourceAdministration for Games of Chance, Ministry of FinanceAdministration for Games of Chance — index of rulebooks, showing gazette 152/2020 as amended by 58/2025
uis.gov.rs
Link checked 18 August 2026
Banking rules
Official name: Odluka o uslovima i načinu poveravanja aktivnosti u vezi sa informaciono-komunikacionim sistemom finansijske institucije trećim licima · Službeni glasnik RS, br. 100/2023; NBS EB No 83 of 9 November 2023 · Directly binding regulation
Banks, insurers and other financial firms in Serbia may put IT work and data abroad. But they have to pass a gate. You tell the central bank 30 days before signing. You prove the destination country would let Serbian supervisors inspect the supplier on site. You keep a register of exactly which countries hold the data. The central bank can block the deal, or force you to unwind one you have already signed.
Enforced by National Bank of Serbia
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Written vendor contractThe contract must require the supplier to follow Serbian law in full. The institution must keep its data in its own possession and under its own control.
- Register or notify — within 720 hoursNotify the National Bank at least 30 days before signing. The signed contract must follow within 15 days.
- Keep records of how you use dataKeep a live register of outsourced activities naming the country or countries where the activity is performed and where the data are located.
- Independent auditThis applies if the supplier is based abroad, or the work is done abroad. You must show that the foreign country's law lets the National Bank of Serbia supervise on site there.
What it costs if you get it wrong
- Order to stopIf the National Bank finds the arrangement creates market concentration or supplier dominance risk, the institution may not proceed, or must terminate an existing contract within a period the Bank sets, never shorter than three months.
Sources
- Official sourceNational Bank of SerbiaDecision on terms and conditions of outsourcing relating to a financial institution's information-communication system, Official Gazette 100/2023, Sections 19 to 22 and 35
nbs.rs
“evidence that the regulations of the country, and/or the countries in which the service provider operates enable the National Bank of Serbia to smoothly perform on-site supervision”
Link checked 18 August 2026
- Official sourceNational Bank of SerbiaNational Bank of Serbia — regulations on the supervision of financial institutions' information systems
nbs.rs
Link checked 18 August 2026
Payment data rules
Official name: Odluka o minimalnim standardima upravljanja informaciono-komunikacionim sistemom finansijske institucije · Službeni glasnik RS, br. 102/2024; NBS EB No 85 of 20 December 2024 · Directly binding regulation
The new rulebook for how Serbian banks, insurers and payment firms run and secure their technology. It replaced the 2013 rules and only started to apply on 1 January 2026. Banks that had already notified a core-system migration got a short extension, to 30 June 2026. It sets a 24-hour clock to classify a cyber incident and report it to the central bank.
Enforced by National Bank of Serbia
How this country controls where data goes: Approval each time
What you have to do
- Secure the data — from 1 January 2026
- Report cyber incidents — within 24 hours, from 1 January 2026Classify an incident within 24 hours of detection. If you cannot classify it in time, file an initial report to the National Bank anyway.
- Independent audit — from 1 January 2026
Sources
- Official sourceNational Bank of SerbiaDecision on Minimum Information-Communication System Management Standards for Financial Institutions, Official Gazette 102/2024, Sections 41, 44, 62 and 65
nbs.rs
“This Decision shall enter into force on the eighth day following its publication in the RS Official Gazette and shall apply as of 1 January 2026.”
Link checked 18 August 2026
Telecoms rules
Official name: Zakon o elektronskim komunikacijama (2010) — surviving Articles 126(1), 127 to 130a and 137(1)(2)-(4) · Službeni glasnik RS, br. 44/10, 60/13 – US, 62/14, 95/18; kept alive by Article 180 of the 2023 law (35/2023) · Act of parliament
Serbian phone and internet companies must keep who-called-whom records for 12 months, then destroy them. Access needs a court order. Oddly, this duty now survives as a fragment of a law that was otherwise repealed in 2023. The new electronic communications law kept these articles alive until a dedicated interception and record-keeping law arrives. That law has not appeared. The ministry's power to write detailed rules here was struck down as unconstitutional in 2013 and never replaced.
Enforced by Regulatory Authority for Electronic Communications and Postal Services
How this country controls where data goes: Approval each time
What you have to do
- Keep logs — 1 yearWho contacted whom, when, from where and on what device. Retaining the content of a communication is forbidden.
- Delete data after a period — 1 yearRetained data must be destroyed once the 12 months expire, unless already handed over under a court order.
- Keep records of how you use dataOperators and the authorities that access retained data must each keep a secret log of every access request. The Commissioner processed 104 such access records in 2025.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fineFailure to comply with the retained-data rules is a misdemeanour under Article 137 of the 2010 law
Sources
- Official sourceRegulatory Authority for Electronic Communications and Postal ServicesZakon o elektronskim komunikacijama (2010, consolidated text), Articles 128 to 130a, and the note on Constitutional Court decision IUz-1245/2010
ratel.rs
“Odlukom Ustavnog suda IUz-1245/2010 ("Sl. glasnik RS", br. 60/13) utvrđeno je da stav 4. člana 129. Zakona o elektronskim komunikacijama ... nije u saglasnosti sa Ustavom”
Link checked 18 August 2026
- Official sourceRegulatory Authority for Electronic Communications and Postal ServicesZakon o elektronskim komunikacijama, Službeni glasnik RS 35/2023, Article 180 — repeal with carve-outs for the retention articles
ratel.rs
“Даном ступања на снагу овог закона престаје да важи Закон о електронским комуникацијама ... осим одредаба члана 126. став 1, чл. 127–130а и члана 137. став 1. тач. 2)–4).”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Europe's main privacy law
Official name: Zakon o zaštiti podataka o ličnosti · Službeni glasnik RS, br. 87/2018 · Act of parliament
Serbia's general privacy law, a close copy of Europe's General Data Protection Regulation. It reaches foreign companies that target Serbia and makes them appoint a local representative. Sending data abroad is free to a long list of countries treated as safe. Everywhere else needs the Commissioner's standard contract or something equivalent. The penalties are the striking difference from Europe. Fines are capped at two million dinars, roughly $19,000. There is no percentage-of-turnover option.
Enforced by Commissioner for Information of Public Importance and Personal Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Certification scheme, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest
What you have to do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hoursIf you miss 72 hours you must give the Commissioner your reasons.
- Tell affected peopleOnly where the breach is likely to cause a high risk to the person.
- Keep records of how you use data
- Assess high-risk projectsRequired for the kinds of data use on the Commissioner's published list (Official Gazette 45/2019, amended 112/2020). Some kinds also need the Commissioner's opinion first.
- Appoint a data protection officer — applies at: Public bodies; large-scale regular monitoring; large-scale special-category or criminal data
- Appoint a representative — applies at: Foreign controllers and processors caught by Article 3(4)Must be based in Serbia and appointed in writing. Narrow exemptions for occasional low-risk work and for public bodies.
- Written vendor contract
- Put a transfer safeguard in place
- Get a parent's consent for children — applies at: under 15
- Delete data after a period
What it costs if you get it wrong
- Fixed maximum fine: RSD 2,000,000 — about $19 thousandMain misdemeanour range for a company under Article 95(1), including unlawful transfer abroad. Minimum 50,000 dinars (about $475).
- Fixed maximum fine: RSD 100,000 — about $950Fixed-amount offences under Article 95(2), including failing to appoint a representative in Serbia. The Commissioner can impose this one directly.
- Fixed maximum fine: RSD 150,000 — about $1 thousandAn individual who breaches the professional secrecy duty
- Order to stopThe Commissioner may temporarily or permanently limit or ban processing, and may suspend a transfer to a recipient abroad
- Criminal liabilitySeparate offences under the Criminal Code, including unauthorised collection of personal data. Attaches to individuals.
- Claims by individualsCompensation claims by the person whose data was mishandled
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionZakon o zaštiti podataka o ličnosti, Službeni glasnik RS 87/2018 (full text published by the Commissioner)
poverenik.rs
“Новчаном казном од 50.000 до 2.000.000 динара казниће се за прекршај руковалац, односно обрађивач који има својство правног лица”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionBylaws made under the Law on Personal Data Protection, including the impact-assessment list 45/2019 and 112/2020
poverenik.rs
Link checked 18 August 2026
Government data rules
Official name: Odluka o Listi država, delova njihovih teritorija ili jednog ili više sektora određenih delatnosti u tim državama i međunarodnih organizacija u kojima se smatra da je obezbeđen primereni nivo zaštite podataka o ličnosti · Službeni glasnik RS, br. 55/2019; 05 broj 021-7718/2019 · Official “this country is safe” decision
The Government's list of destinations treated as safe. Part one names 54 members of the Council of Europe data protection treaty. That is all of Europe plus Argentina, Mexico, Morocco, Mauritius, Senegal, Tunisia, Uruguay, Cape Verde, Turkey, Russia and others. Part two names the destinations the European Union had approved in 2019. Sending personal data anywhere on this list needs no contract and no permission.
Enforced by Government of the Republic of Serbia
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Nothing required
Sources
- Official sourceGovernment of the Republic of Serbia (copy published by the Commissioner)Odluka o Listi država ..., Službeni glasnik RS 55/2019, adopted 1 August 2019
poverenik.rs
“Ова одлука ступа на снагу осмог дана од дана објављивања у „Службеном гласнику Републике Србије”, а примењује се од 21. августа 2019. године.”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025 — confirms 55/2019 is still the only Government bylaw under the privacy law and has not been amended
poverenik.rs
Link checked 18 August 2026
Cyber security rules
Official name: Zakon o informacionoj bezbednosti · Službeni glasnik RS, br. 91/2025 · Act of parliament
Serbia's replacement cyber security law, in force since 31 October 2025. It creates a new Office for Information Security. It gives operators of important systems 24 hours to report a serious incident. It makes them register with the ministry, including how many physical locations their system occupies. It has no requirement to keep data in Serbia. One part of it, on ministry supervision of the new Office, only starts on 1 January 2027.
Enforced by Office for Information Security — not yet operational
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — applies at: Operators of information and communication systems of special importance, within 24 hoursThen updates every 24 hours for a high or very high severity incident, and every three days for a medium one. A final report is due within 15 days of the incident ending.
- Register or notifyOperators must file details with the ministry within 90 days, including the number of locations where the system sits.
- Secure the dataAdopt a risk assessment act and a security act; review the risk assessment at least once a year and self-check the system annually.
- Independent audit — 1 year
What it costs if you get it wrong
- Fixed maximum fineMisdemeanour penalties for operators of systems of special importance
Sources
- Official sourceRegulatory Authority for Electronic Communications and Postal Services (official copy of the gazette text)Zakon o informacionoj bezbednosti, Službeni glasnik RS 91/2025 of 23 October 2025, Articles 9 to 14, 24, 28 to 31 and 58
ratel.rs
“Овај закон ступа на снагу осмог дана од дана објављивања у „Службеном гласнику Републике Србије”, изузев члана 29. овог закона који почиње да се примењује од 1. јануара 2027. године.”
Link checked 18 August 2026
- Official sourceRegulatory Authority for Electronic Communications and Postal ServicesRegulator's index of information security laws, showing 91/2025 as the current law and 6/16, 94/17 and 77/19 as archived
ratel.rs
Link checked 18 August 2026
On the books, but not enforceable1 rule
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
Government data rules (not enforced)
Official name: Lista država, Deo II, tačka 7) — Sjedinjene Američke Države (ograničeno na „Privacy Shield framework”) · Službeni glasnik RS, br. 55/2019, Part II item 7 · Official “this country is safe” decision
The Government's list still says the United States is safe under the Privacy Shield arrangement. The European Court of Justice struck that arrangement down on 16 July 2020. Serbia's own regulator said in August 2020 that the entry can no longer be relied on. The line is still printed in the Official Gazette six years later. So reading the list at face value gives you the wrong answer.
Enforced by Commissioner for Information of Public Importance and Personal Data Protection
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Approved group rules
What you have to do
- Put a transfer safeguard in placeFor United States transfers, use the Commissioner's standard contractual clauses or binding corporate rules. Do not rely on the entry printed in the Government's list.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's notice of 11 August 2020 — Privacy Shield no longer provides an adequate level of protection under Serbian law either
poverenik.rs
“може се закључити да, следствено томе, Сједињене Америчке Државе на основу „Privacy Shield framework“ више не обезбеђују примерени ниво заштите ни са становишта Закона о заштити података о личности.”
Link checked 18 August 2026
- Official sourceGovernment of the Republic of SerbiaOdluka o Listi država, Part II item 7 — the text that remains in the Official Gazette
poverenik.rs
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether transfers to United States organisations certified under the EU-US Data Privacy Framework (adopted by the European Union in July 2023) are treated as adequate in Serbia
We could not confirm that the current EU-US Data Privacy Framework counts as a safe destination in Serbia. Article 64(2) points at whatever the European Union has approved, which would cover it. But the Government's list has never been updated, and no Serbian authority has published a confirmation. The same gap applies to South Korea, approved by the European Union in December 2021. Safer to use the standard contract clauses.
Whether Serbian public bodies are legally obliged to keep their systems and data in the State Data Centre in Kragujevac or otherwise in Serbia
We could not confirm the legal basis for the State Data Centre. The Office for Information Technology and eGovernment runs it under the Law on Electronic Government. We could not read that law. We make no claim that data must be kept in the country here.
Whether the Office for Information Security has been constituted, has a director, and is issuing decisions
We could not confirm whether the Office for Information Security is actually operating. The law creating it has been in force since 31 October 2025. We found no website, no appointment notice and no published output. We can show that the telecoms regulator still runs the national computer emergency response team. Ask the ministry if you need the Office's current status.
Whether Commissioner Milan Marinović's mandate is still current
We could not confirm that the Commissioner's term is still running. The institution's own pages say he was elected by the National Assembly on 26 July 2019, and still name him in August 2026. But they do not state the term length, and we found no re-election notice. Serbia has previously run this office for months on a deputy after a term expired.
Any localisation or storage rule for health records, education, securities markets, mapping and geospatial data, or defence
We found no health rule requiring data to stay in Serbia, checked 18 August 2026, medium confidence. The health ministry's own laws page lists only the Healthcare Act. It does not publish the Act on Health Documentation and Records, so we could not read the keeping periods for medical files. If you work in health, check before you rely on this.
Whether a dedicated law on lawful interception and data retention has been adopted since 2023
We could not confirm whether a dedicated interception and record-keeping law has been passed. The 2023 electronic communications law repeatedly defers to such a law, and kept the old articles alive pending it. We found no adopted text. But we could not search the Official Gazette properly, because the state legal information portal blocks automated access.
Precise dinar-to-dollar conversions for the penalty figures
Dollar figures here are converted at roughly 105 dinars to the dollar. We could not read the National Bank's live middle rate, which is served through a separate web application. Treat every dollar figure here as an approximation.
The exact date the National Assembly adopted the Law on Personal Data Protection
We could not confirm the adoption date from a gazette page we could open. The gazette number (87/2018) and the date arithmetic are solid. Both give 21 November 2018 for entry into force and 21 August 2019 for application. The adoption date of 9 November 2018 is our inference from the publication date.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.