Skip to the content
Global Data RulesData governance rules, country by country

Serbia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Active

Serbia copied Europe's privacy law almost word for word, so the duties feel familiar. Data can leave the country, and for most of Europe and a long list of other countries it can leave with no paperwork at all. The privacy regulator is busy — over a thousand inspections in 2025 — but it hands out warnings, not fines. The biggest fine any Serbian court imposed for a privacy breach in 2025 was about $950.

Eight questions about Serbia

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Serbia's rules apply to my company?

Yes. The law reaches a company anywhere in the world if it offers goods or services to people in Serbia, or watches what they do in Serbia. There is no size or revenue threshold to hide behind. If you are caught this way you must appoint a written representative living or based in Serbia, unless your processing is occasional and low risk or you are a public body.

High confidenceNational rulesAppoint a local representativeLocal representative

Can I store my users' data outside Serbia?

Yes, with paperwork — and often with none at all. Serbia treats a very long list of countries as automatically safe: every member of the Council of Europe's data protection treaty, which covers all of Europe plus Argentina, Mexico, Morocco, Mauritius, Senegal, Tunisia, Uruguay, Cape Verde and others, and separately every country the European Union has approved. Sending data there needs no permission and no contract. Everywhere else you sign the Commissioner's standard contract or use approved group rules. Only one industry has a hard wall: online gambling. Banking has a gate rather than a wall.

High confidenceYes, with paperworkAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rules

What do I need in place before data leaves Serbia?

First check the destination. If it is on the safe list, you need nothing — no contract, no filing, no approval. If it is not, you sign the standard contract the Serbian regulator published in January 2020, or you get approved group-wide rules. If you want to use your own wording instead of the standard contract, the regulator must approve it and has 60 days to answer. As a last resort there are narrow exceptions such as the person's explicit consent.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesApproved code of conductCertification schemeGovernment sign-off neededExplicit consentPut a transfer safeguard in place

Who enforces the rules in Serbia, and what can they do?

The Commissioner for Information of Public Importance and Personal Data Protection, and it is genuinely working. In 2025 it finished 1,169 inspections, received 5,310 cases and issued 102 corrective orders. But it almost never fines. Of those 102 orders, 101 were warnings and one was a ban on processing. It asked the courts to punish only three organisations all year. Banks answer to the National Bank of Serbia instead, and it is fully active. A brand-new Office for Information Security exists on paper since October 2025 but we could find no sign it is running yet.

High confidenceActiveRegulator

How long do I have to keep the data?

There is no single national rule. The privacy law says keep data only as long as you need it, and each sector sets its own clock. Online gambling operators must keep every transaction for at least ten years. Phone and internet companies must keep who-called-whom records for exactly 12 months and then destroy them. Anyone selling a phone line must keep the customer's identity check for 12 months after the service ends. Financial firms must keep a live register of every outsourced service, including which countries the data sits in.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logsKeep records of processing

What happens if there is a breach?

Count three clocks. Privacy breach: tell the Commissioner without delay and at the latest within 72 hours, and if you miss that you must explain why. Cyber incident: if you run an information system the state has classed as important, you have only 24 hours to report it. Then a third clock starts — updates every 24 hours for a serious incident, every three days for a middling one, and a final report within 15 days of the incident ending. Banks report cyber incidents to the central bank instead, promptly, with no fixed hour count.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Serbia?

Five. (1) A child can consent for themselves at 15, not 13 or 16 — plan your age gates around 15. (2) A foreign court order or foreign tax authority demand for data is recognised in Serbia only if a treaty backs it, so handing data to an overseas authority on request can itself be unlawful. (3) Individuals, not just companies, can be prosecuted; the regulator has filed 49 criminal complaints since 2010. (4) Dozens of older Serbian laws still contradict the privacy law and were never fixed. (5) The government's official list of safe destination countries has not been touched since 2019 and still names a United States framework that died in 2020.

High confidenceGet a parent's consent for childrenDo not hand data to foreign authorities on demandCriminal liabilityUnenforceable

What is changing soon in Serbia?

One dated change and several unscheduled ones. From 1 January 2027 the ministry formally takes over supervising the new Office for Information Security, which should mean the office is actually up and running by then. A rewrite of the privacy law is being drafted by a special working group covering video surveillance, biometrics, genetic data and artificial intelligence, and a separate group is drafting an artificial intelligence law. Neither has been published as a bill, so neither is binding.

High confidenceProposedPartly in force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    4 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    4 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules4 rules

Zakon o zaštiti podataka o ličnosti

Act of parliament · Službeni glasnik RS, br. 87/2018

In forceYes, with paperwork

Serbia's general privacy law, a close adaptation of Europe's General Data Protection Regulation. It reaches foreign companies that target Serbia and makes them appoint a local representative. Transfers abroad are free to a long list of presumed-safe countries and otherwise need the Commissioner's standard contract or equivalent. The penalties are the striking difference from Europe: a hard ceiling of two million dinars, roughly $19,000, with no percentage-of-turnover option.

In force since 21 November 2018But only enforceable from 21 August 2019

Enforced by Commissioner for Information of Public Importance and Personal Data Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Certification scheme, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

High confidence

Odluka o Listi država, delova njihovih teritorija ili jednog ili više sektora određenih delatnosti u tim državama i međunarodnih organizacija u kojima se smatra da je obezbeđen primereni nivo zaštite podataka o ličnosti

Adequacy decision · Službeni glasnik RS, br. 55/2019; 05 broj 021-7718/2019

In forceYes — store it anywhere

The Government's list of destinations treated as safe. Part one names 54 members of the Council of Europe data protection treaty — all of Europe plus Argentina, Mexico, Morocco, Mauritius, Senegal, Tunisia, Uruguay, Cape Verde, Turkey, Russia and others. Part two names the destinations the European Union had approved in 2019. Sending personal data to anywhere on this list needs no contract and no permission.

In force since 10 August 2019But only enforceable from 21 August 2019

Enforced by Government of the Republic of Serbia

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Nothing required

High confidence

Lista država, Deo II, tačka 7) — Sjedinjene Američke Države (ograničeno na „Privacy Shield framework”)

Adequacy decision · Službeni glasnik RS, br. 55/2019, Part II item 7

UnenforceableYes, with paperwork

The Government's list still says the United States is safe under the Privacy Shield framework. That framework was struck down by the European Court of Justice on 16 July 2020, and Serbia's own regulator said in August 2020 that the entry can no longer be relied on. The line is still printed in the Official Gazette six years later, so a naive reading of the list gives the wrong answer.

In force since 21 August 2019

Enforced by Commissioner for Information of Public Importance and Personal Data Protection

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Standard contract clauses, Approved group rules

High confidence

Industry rules4 rules

Pravilnik o informaciono-komunikacionom sistemu za priređivanje posebnih igara na sreću preko sredstava elektronske komunikacije

Government rules · Službeni glasnik RS, br. 152/2020, izmene 58/2025 · Online gaming

In forceA copy must stay

Serbia's one true storage wall. An online gambling operator must hold its database of everything reported to the Gaming Administration inside Serbia — either the live database or a mirror of it. Transactions must be kept for at least ten years, and the Administration gets constant data access plus a remote connection into the system.

In force since 26 December 2020

Enforced by Administration for Games of Chance

Transfer model: Approval each time

High confidence

Odluka o uslovima i načinu poveravanja aktivnosti u vezi sa informaciono-komunikacionim sistemom finansijske institucije trećim licima

Directly binding regulation · Službeni glasnik RS, br. 100/2023; NBS EB No 83 of 9 November 2023 · Finance

In forceYes, with paperwork

Banks, insurers and other financial firms in Serbia may put IT work and data abroad, but only through a gate. You tell the central bank 30 days before signing, you prove the destination country would let Serbian supervisors inspect the supplier on site, and you keep a register of exactly which countries hold the data. The central bank can block the deal or force you to unwind one you have already signed.

In force since 25 November 2023But only enforceable from 1 March 2024

Enforced by National Bank of Serbia

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Odluka o minimalnim standardima upravljanja informaciono-komunikacionim sistemom finansijske institucije

Directly binding regulation · Službeni glasnik RS, br. 102/2024; NBS EB No 85 of 20 December 2024 · Banking

In forceYes, with paperwork

The new rulebook for how Serbian banks, insurers and payment firms run and secure their technology. It replaced the 2013 rules and only started to apply on 1 January 2026, with a short extension to 30 June 2026 for banks that had already notified a core-system migration. It sets a 24-hour clock to classify a cyber incident and report it to the central bank.

In force since 28 December 2024But only enforceable from 1 January 2026

Enforced by National Bank of Serbia

Transfer model: Approval each time

High confidence

Who you would hear from

  • Повереник за информације од јавног значаја и заштиту података о личности

    General privacy law; also freedom of information

    Clearly working. 5,310 cases received and 1,169 inspections completed in 2025; 1,354 cases in July 2026 alone; senior vacancies advertised in August 2026. But it issues warnings, not fines: 101 of its 102 corrective measures in 2025 were warnings, and it asked the courts to punish only three organisations. Commissioner Milan Marinović was elected on 26 July 2019.

  • Влада Републике Србије

    Adopts and amends the list of countries treated as providing adequate protection

    Holds the power to add to, amend or restrict the adequacy list at any time by decision. Has not used it since 1 August 2019.

  • Народна банка Србије

    Banking, insurance, payments, financial leasing, virtual currency services; supervision of their information systems and outsourcing

    Fully active. Issues binding decisions, receives outsourcing notifications and cyber incident reports, and can veto an outsourcing arrangement.

  • Регулаторно тело за електронске комуникације и поштанске услуге (РАТЕЛ)

    Telecoms and postal services; also hosts the National CERT

    Active. Still operating the national computer emergency response team at cert.rs, with advisories published as recently as 12 August 2026.

  • Канцеларија за информациону безбедност

    Cyber incident handling and the national CERT role under the 2025 information security law

    Created by the Law on Information Security in force since 31 October 2025, but we found no website, no director announcement and no published decisions as of 18 August 2026. The telecoms regulator is still running the national CERT. Ministry supervision of the Office only begins on 1 January 2027, which suggests the build-out is still under way.

  • Управа за игре на срећу

    Land-based and online games of chance; approves and inspects operators' technical systems

    Active; issues and updates technical rulebooks, most recently amending the online gaming system rulebook in 2025.

  • Канцеларија за информационе технологије и електронску управу

    Public sector information technology; runs the State Data Centre in Kragujevac

    Active. Operates the State Data Centre, which also sells commercial hosting. We could not confirm any statutory duty forcing public bodies to keep their data there.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether transfers to United States organisations certified under the EU-US Data Privacy Framework (adopted by the European Union in July 2023) are treated as adequate in Serbia

    The statutory presumption in Article 64(2) points at whatever the European Union has approved, which would cover it, but the Government's list has never been updated and no Serbian authority has published a confirmation. Same gap for South Korea, approved by the European Union in December 2021. Safer to use the standard contractual clauses.

  • Whether Serbian public bodies are legally obliged to keep their systems and data in the State Data Centre in Kragujevac or otherwise in Serbia

    The Office for Information Technology and eGovernment operates the centre under the Law on Electronic Government, but we could not open the statute text — the official legal information system serves its content only through JavaScript and blocks automated fetching. No localisation duty is asserted here.

  • Whether the Office for Information Security has been constituted, has a director, and is issuing decisions

    The law creating it has been in force since 31 October 2025, but we could find no website, no appointment notice and no published output. We can evidence that the telecoms regulator still runs the national CERT; we cannot prove the negative about the new Office.

  • Whether Commissioner Milan Marinović's mandate is still current

    The institution's own pages state he was elected by the National Assembly on 26 July 2019 and still name him in August 2026, but they do not state the term length and we found no re-election notice. Serbia has previously run this office for months on a deputy after a mandate expired.

  • Any localisation or storage rule for health records, education, securities markets, mapping and geospatial data, or defence

    No rule found, checked 18 August 2026, medium confidence. The health ministry's own laws page lists only the Healthcare Act and does not publish the Act on Health Documentation and Records, so we could not read the retention periods for medical files.

  • Whether a dedicated law on lawful interception and data retention has been adopted since 2023

    The 2023 electronic communications law repeatedly defers to such a law and preserved the old retention articles pending it. We found no adopted text, but we could not search the Official Gazette systematically because the state legal information portal blocks automated access.

  • Precise dinar-to-dollar conversions for the penalty figures

    Converted at roughly 105 dinars to the dollar. We could not read the National Bank's live middle rate, which is served through a separate web application. Treat every dollar figure here as an approximation.

  • The exact date the National Assembly adopted the Law on Personal Data Protection

    The gazette number (87/2018) and the commencement arithmetic are solid, and both give 21 November 2018 for entry into force and 21 August 2019 for application. The adoption date of 9 November 2018 is inferred from the publication date rather than read off a gazette page we could open.

60-day cadence. Three things can move without warning: the Government can rewrite the adequacy list by decision at any time (it is six years stale, so a correction is overdue); the new Office for Information Security could stand up at any point and change who you report a cyber incident to; and the working groups on a rewritten privacy law and an artificial intelligence law could produce bills. The Commissioner's mandate status is also unresolved.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.