Serbia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Serbia copied Europe's privacy law almost word for word, so the duties feel familiar. Data can leave the country, and for most of Europe and a long list of other countries it can leave with no paperwork at all. The privacy regulator is busy — over a thousand inspections in 2025 — but it hands out warnings, not fines. The biggest fine any Serbian court imposed for a privacy breach in 2025 was about $950.
Eight questions about Serbia
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Serbia's rules apply to my company?
Yes. The law reaches a company anywhere in the world if it offers goods or services to people in Serbia, or watches what they do in Serbia. There is no size or revenue threshold to hide behind. If you are caught this way you must appoint a written representative living or based in Serbia, unless your processing is occasional and low risk or you are a public body.
Article 3(4) of the Law on Personal Data Protection applies it to controllers and processors with no establishment in Serbia where the processing relates to (1) offering goods or services to people in Serbia, whether or not payment is required, or (2) monitoring their behaviour in Serbia. Article 44 requires the written appointment of a representative in Serbia; the exemptions are narrow. Failure to appoint one is a fixed 100,000 dinar offence under Article 95(2)(4) that the Commissioner can fine directly by misdemeanour warrant without going to court. Compliance is very thin in practice: the Commissioner's 2025 annual report records only 22 appointment decisions from foreign companies processed in the whole year.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionZakon o zaštiti podataka o ličnosti, Službeni glasnik RS 87/2018, Articles 3 and 44
poverenik.rs
“Овај закон примењује се на обраду података о личности лица на које се подаци односе које има пребивалиште, односно боравиште на територији Републике Србије од стране руковаоца, односно обрађивача који нема седиште ... ако су радње обраде везане за: 1) понуду робe, односно услуге ... 2) праћење активности лица на које се подаци односе.”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025, Table 2 — 22 representative-appointment decisions processed
poverenik.rs
Link checked 18 August 2026
Can I store my users' data outside Serbia?
Yes, with paperwork — and often with none at all. Serbia treats a very long list of countries as automatically safe: every member of the Council of Europe's data protection treaty, which covers all of Europe plus Argentina, Mexico, Morocco, Mauritius, Senegal, Tunisia, Uruguay, Cape Verde and others, and separately every country the European Union has approved. Sending data there needs no permission and no contract. Everywhere else you sign the Commissioner's standard contract or use approved group rules. Only one industry has a hard wall: online gambling. Banking has a gate rather than a wall.
Article 64(2) creates a statutory presumption of adequacy for parties to Council of Europe Convention 108 and for destinations the European Union has found adequate. The Government published the list on 1 August 2019 (Official Gazette 55/2019): 54 Convention 108 states in Part I, and in Part II Guernsey, Israel, Japan, Canada (commercial organisations), the Isle of Man, New Zealand, the Faroe Islands, Jersey and the United States 'limited to the Privacy Shield framework'. That list has never been amended. It is therefore out of date in both directions: it still names an American framework the European Court of Justice killed in July 2020, and it has never been updated to add South Korea (approved by the European Union in December 2021) or the current EU-US Data Privacy Framework (July 2023). Because Article 64(2) operates by law rather than by the list, the better reading is that the presumption tracks whatever the European Union currently recognises, but no Serbian authority has confirmed this in writing for the 2023 framework. Sector overrides: online gambling is a copy must stay in the country (a production or replica database must sit in Serbia); banking, insurance and payments are data can leave with the right paperwork with a central-bank notification and veto gate; telecoms retain traffic data for 12 months with no location rule; the public sector operates a State Data Centre in Kragujevac but we could not find a statutory duty to use it. No localisation rule was found for health, education, securities, mapping or defence — checked 18 August 2026, medium confidence.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionZakon o zaštiti podataka o ličnosti, Articles 63 to 71 (transfer to other states and international organisations)
poverenik.rs
“Сматра се да је примерени ниво заштите ... обезбеђен у државама и међународним организацијама које су чланице Конвенције Савета Европе о заштити лица у односу на аутоматску обраду личних података, односно у државама ... за које је од стране Европске уније утврђено да обезбеђују примерени ниво заштите.”
Link checked 18 August 2026
- Official sourceGovernment of the Republic of SerbiaOdluka o Listi država ... u kojima se smatra da je obezbeđen primereni nivo zaštite podataka o ličnosti, Službeni glasnik RS 55/2019, 1 August 2019
poverenik.rs
“7) Сједињене Америчке Државе (ограничено на „Privacy Shield framework”)”
Link checked 18 August 2026
- Official sourceAdministration for Games of Chance, Ministry of FinanceRulebook on the information and communication system for organising online games of chance, Article 2(6) — database must be in Serbia
uis.gov.rs
“which must be located on the territory of the Republic of Serbia, either as a production base or as a replica of that base (e.g. mirror or replica server)”
Link checked 18 August 2026
What do I need in place before data leaves Serbia?
First check the destination. If it is on the safe list, you need nothing — no contract, no filing, no approval. If it is not, you sign the standard contract the Serbian regulator published in January 2020, or you get approved group-wide rules. If you want to use your own wording instead of the standard contract, the regulator must approve it and has 60 days to answer. As a last resort there are narrow exceptions such as the person's explicit consent.
Article 65(2) lists safeguards usable without any approval: a legally binding instrument between public authorities, the standard contractual clauses drawn up by the Commissioner (Decision, Official Gazette 5/2020), approved binding corporate rules, an approved code of conduct, or a certification. Article 65(3) covers bespoke contract terms, which need the Commissioner's specific approval within 60 days. Article 69 lists the derogations. Take-up is tiny: in the whole of 2025 the Commissioner approved exactly one set of binding corporate rules (for ACUMATICA d.o.o. Belgrade). The model is an allowlist in the sense that the destination is either presumed adequate or you must build the safeguard yourself; there is no blocklist of banned countries, and the Government has never used its Article 64(3) power to declare a country inadequate.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionOdluka o utvrđivanju standardnih ugovornih klauzula, Službeni glasnik RS 5/2020
poverenik.rs
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionPodzakonski akti — the complete list of bylaws made under the Law on Personal Data Protection
poverenik.rs
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025 — one set of binding corporate rules approved in the year
poverenik.rs
Link checked 18 August 2026
Who enforces the rules in Serbia, and what can they do?
The Commissioner for Information of Public Importance and Personal Data Protection, and it is genuinely working. In 2025 it finished 1,169 inspections, received 5,310 cases and issued 102 corrective orders. But it almost never fines. Of those 102 orders, 101 were warnings and one was a ban on processing. It asked the courts to punish only three organisations all year. Banks answer to the National Bank of Serbia instead, and it is fully active. A brand-new Office for Information Security exists on paper since October 2025 but we could find no sign it is running yet.
The Commissioner cannot impose the large fines itself. Under Article 79(2)(9) it may issue a fine only by misdemeanour warrant and only where the law sets a fixed amount; everything else goes to the misdemeanour courts. In 2025 those courts delivered eight first-instance decisions on the Commissioner's requests: four proceedings were discontinued (three because they had timed out), and four convictions produced one warning and three fines — two of 100,000 dinars against a company plus 10,000 against the responsible individual, and one of 50,000 plus 5,000. Since 2010 the Commissioner has filed 49 criminal complaints; prosecutors brought only two indictments, producing one conviction (six months suspended) and one acquittal, with 23 complaints dismissed and five investigations timed out. The Commissioner is Milan Marinović, elected by the National Assembly on 26 July 2019; the institution was still publishing monthly caseload figures and advertising senior vacancies in August 2026. The national computer emergency response team is still run by the telecoms regulator; the new Office for Information Security created by the 2025 information security law has no website we could find.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025 — 1,169 inspections, 102 corrective measures, 3 misdemeanour requests, 49 criminal complaints since 2010
poverenik.rs
“Повереник је у току 2025. године окончао укупно 1.169 надзора ... донете су 102 корективнe мерe којима је изрекао 101 опомену руковаоцима и 1 руковаоцу привремено/трајно ограничио вршење радње обраде”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's news feed — July 2026 monthly caseload (1,354 cases) and August 2026 recruitment notices
poverenik.rs
Link checked 18 August 2026
- Official sourceRegulatory Authority for Electronic Communications and Postal ServicesNational CERT of Serbia — still operated by the telecoms regulator, advisories published 12 August 2026
cert.rs
Link checked 18 August 2026
How long do I have to keep the data?
There is no single national rule. The privacy law says keep data only as long as you need it, and each sector sets its own clock. Online gambling operators must keep every transaction for at least ten years. Phone and internet companies must keep who-called-whom records for exactly 12 months and then destroy them. Anyone selling a phone line must keep the customer's identity check for 12 months after the service ends. Financial firms must keep a live register of every outsourced service, including which countries the data sits in.
Ceiling: Article 5(1)(5) of the Law on Personal Data Protection sets the storage-limitation principle. The telecoms regime is unusual in being both a floor and a ceiling — Article 128(6) of the 2010 electronic communications law (still in force as a surviving fragment) requires 12 months' retention from the date of the communication, and Article 130(1)(4) requires destruction once that period ends. Floors: the online gambling rulebook requires at least ten years of transaction data, after which archived data must still be produced to the Administration within five days. The 2023 electronic communications law requires identity-check data captured at subscriber registration to be kept for the subscription and 12 months after it ends. Where a sector floor and the privacy ceiling conflict, Article 100 of the privacy law says other laws should have been brought into line by the end of 2020 — the Commissioner's 2025 report states flatly that this never happened, so in practice the specific sector law is what people follow.
Sources
- Official sourceRegulatory Authority for Electronic Communications and Postal ServicesZakon o elektronskim komunikacijama (2010, consolidated), Articles 128 to 130a — 12-month retention and mandatory destruction
ratel.rs
“Operator iz stava 1. ovog člana dužan je da zadržane podatke čuva 12 meseci od dana obavljene komunikacije.”
Link checked 18 August 2026
- Official sourceAdministration for Games of Chance, Ministry of FinanceRulebook on the ICT system for online games of chance, Article 6 — ten-year transaction retention
uis.gov.rs
“The organizer is obliged to store all transactions in the data system for at least ten years from the date of the transaction”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025 — the Article 100 alignment deadline of end-2020 was never met
poverenik.rs
“Обавеза из члана 100. ЗЗПЛ ... није испуњена.”
Link checked 18 August 2026
What happens if there is a breach?
Count three clocks. Privacy breach: tell the Commissioner without delay and at the latest within 72 hours, and if you miss that you must explain why. Cyber incident: if you run an information system the state has classed as important, you have only 24 hours to report it. Then a third clock starts — updates every 24 hours for a serious incident, every three days for a middling one, and a final report within 15 days of the incident ending. Banks report cyber incidents to the central bank instead, promptly, with no fixed hour count.
Personal data breach: Articles 53 and 54 of the Law on Personal Data Protection — notify the Commissioner within 72 hours where there is a risk to people, and notify affected individuals without undue delay where the risk is high. The Commissioner received only 49 breach notifications in the whole of 2025, which is implausibly low for a country of seven million and suggests widespread under-reporting. Cyber: Article 13 of the new Law on Information Security (Official Gazette 91/2025) requires operators of information and communication systems of special importance to report without delay and at the latest within 24 hours of becoming aware. Article 14 routes banking and financial-market operators to the National Bank of Serbia, and firms supervised by the Securities Commission also to that Commission. Article 24 sets the follow-up rhythm: every 24 hours for high and very high severity, every three days for medium, and a final report within 15 days of the incident ending. Under the National Bank's 2024 ICT decision a financial institution must classify an incident within 24 hours of detection and, if it cannot, must file an initial report anyway.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionZakon o zaštiti podataka o ličnosti, Articles 53 and 54 — 72-hour breach notification
poverenik.rs
“Руковалац је дужан да о повреди података о личности која може да произведе ризик по права и слободе физичких лица обавести Повереника без непотребног одлагања, или, ако је то могуће, у року од 72 часа од сазнања за повреду.”
Link checked 18 August 2026
- Official sourceRegulatory Authority for Electronic Communications and Postal Services (official copy of the gazette text)Zakon o informacionoj bezbednosti, Službeni glasnik RS 91/2025, Articles 13, 14 and 24 — 24-hour cyber incident reporting
ratel.rs
“Оператори ИКТ система од посебног значаја дужни су да доставе обавештење о инциденту који може да има значајан утицај на нарушавање информационе безбедности, без одлагања, а најкасније у року од 24 сата од када су сазнали за инцидент.”
Link checked 18 August 2026
- Official sourceNational Bank of SerbiaDecision on Minimum Information-Communication System Management Standards for Financial Institutions, Official Gazette 102/2024, Sections 41 and 44
nbs.rs
Link checked 18 August 2026
What trips people up in Serbia?
Five. (1) A child can consent for themselves at 15, not 13 or 16 — plan your age gates around 15. (2) A foreign court order or foreign tax authority demand for data is recognised in Serbia only if a treaty backs it, so handing data to an overseas authority on request can itself be unlawful. (3) Individuals, not just companies, can be prosecuted; the regulator has filed 49 criminal complaints since 2010. (4) Dozens of older Serbian laws still contradict the privacy law and were never fixed. (5) The government's official list of safe destination countries has not been touched since 2019 and still names a United States framework that died in 2020.
(1) Article 16: a minor who has turned 15 may consent alone to information-society services; below 15 a parent must consent and the controller must take reasonable steps to verify this. (2) Article 68: a decision of a foreign court or administrative authority requiring a controller or processor to transfer or disclose personal data may be recognised or enforced in Serbia only if based on an international agreement, such as a mutual legal assistance treaty. This is the Serbian analogue of the European resistance to overseas surveillance demands and it bites on cloud providers with United States parents. (3) The Commissioner's criminal complaints run under Criminal Code Articles 143 to 146 (unauthorised interception, photography, publication, and collection of personal data) and Articles 299, 302, 329, 355 and 359; conviction rates are near zero and cases frequently time out, but the exposure is personal. (4) Article 100 required all other laws touching personal data to be aligned by the end of 2020; the Commissioner reports this was never done, so sector rules on video surveillance, policing and health records still sit awkwardly against the privacy law. (5) The Government's Decision of 1 August 2019 has never been amended, despite the Commissioner formally writing to the Government in August 2020 asking it to be brought into line after the European Court of Justice struck down the Privacy Shield.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionZakon o zaštiti podataka o ličnosti, Articles 16, 68 and 100
poverenik.rs
“Одлуке суда или управног органа друге државе, којима се од руковаоца или обрађивача захтева пренос или откривање података о личности, могу бити признате или извршене у Републици Србији само ако се заснивају на међународном споразуму.”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's notice of 11 August 2020 on the effect of the European Court of Justice ruling on Privacy Shield transfers
poverenik.rs
“Повереник је упутио допис Влади у циљу усаглашавања те одлуке са Законом о заштити података о личности и европском праксом.”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025 — 49 criminal complaints since 2010, two indictments, one conviction
poverenik.rs
Link checked 18 August 2026
What is changing soon in Serbia?
One dated change and several unscheduled ones. From 1 January 2027 the ministry formally takes over supervising the new Office for Information Security, which should mean the office is actually up and running by then. A rewrite of the privacy law is being drafted by a special working group covering video surveillance, biometrics, genetic data and artificial intelligence, and a separate group is drafting an artificial intelligence law. Neither has been published as a bill, so neither is binding.
Dated: Article 58 of the Law on Information Security (Official Gazette 91/2025) brought the law into force eight days after publication on 23 October 2025, except Article 29 — ministry supervision of the Office for Information Security — which applies from 1 January 2027. Financial institutions have already absorbed the National Bank's new ICT decision, which applied from 1 January 2026, with a narrow carve-out running to 30 June 2026 for banks that had notified a core-system migration. Dormant switches, any of which can change the picture without consultation: the Government can replace or amend the country adequacy list by decision at any time; it can also declare a country inadequate under Article 64(3), except for parties to the Council of Europe treaty, and has never used that power; and the National Bank can order a financial institution to unwind an outsourcing contract on concentration grounds, at any time, before or after the fact. Watch also for the lawful interception and data retention law that the 2023 electronic communications law assumed would arrive — until it does, Serbia's retention regime survives only as a fragment of a repealed statute.
Sources
- Official sourceRegulatory Authority for Electronic Communications and Postal Services (official copy of the gazette text)Zakon o informacionoj bezbednosti, Službeni glasnik RS 91/2025, Article 58 — entry into force, with Article 29 applying from 1 January 2027
ratel.rs
“Овај закон ступа на снагу осмог дана од дана објављивања у „Службеном гласнику Републике Србије”, изузев члана 29. овог закона који почиње да се примењује од 1. јануара 2027. године.”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025 — special working group on amendments to the Law on Personal Data Protection, and a separate working group on an artificial intelligence law
poverenik.rs
“најважнија активност у 2025. години је била рад на доношењу новог Закона о заштити података о личности”
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
4 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
4 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules4 rules
Zakon o zaštiti podataka o ličnosti
Act of parliament · Službeni glasnik RS, br. 87/2018
Serbia's general privacy law, a close adaptation of Europe's General Data Protection Regulation. It reaches foreign companies that target Serbia and makes them appoint a local representative. Transfers abroad are free to a long list of presumed-safe countries and otherwise need the Commissioner's standard contract or equivalent. The penalties are the striking difference from Europe: a hard ceiling of two million dinars, roughly $19,000, with no percentage-of-turnover option.
Enforced by Commissioner for Information of Public Importance and Personal Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Approved code of conduct, Certification scheme, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest
What it makes you do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hoursIf you miss 72 hours you must give the Commissioner your reasons.
- Tell affected peopleOnly where the breach is likely to cause a high risk to the person.
- Keep records of processing
- Assess high-risk projectsMandatory for the processing types on the Commissioner's published list (Official Gazette 45/2019, amended 112/2020); some types also require the Commissioner's prior opinion.
- Appoint a data protection officer — applies at: Public bodies; large-scale regular monitoring; large-scale special-category or criminal data
- Appoint a local representative — applies at: Foreign controllers and processors caught by Article 3(4)Must be based in Serbia and appointed in writing. Narrow exemptions for occasional low-risk processing and for public bodies.
- Written vendor contract
- Put a transfer safeguard in place
- Get a parent's consent for children — applies at: under 15
- Delete data after a period
What it costs if you get it wrong
- Fixed maximum fine: RSD 2,000,000 — about $19 thousandMain misdemeanour range for a company under Article 95(1), including unlawful transfer abroad. Minimum 50,000 dinars (about $475).
- Fixed maximum fine: RSD 100,000 — about $950Fixed-amount offences under Article 95(2), including failing to appoint a representative in Serbia. The Commissioner can impose this one directly.
- Fixed maximum fine: RSD 150,000 — about $1 thousandAn individual who breaches the professional secrecy duty
- Order to stopThe Commissioner may temporarily or permanently limit or ban processing, and may suspend a transfer to a recipient abroad
- Criminal liabilitySeparate offences under the Criminal Code, including unauthorised collection of personal data. Attaches to individuals.
- Claims by individualsCompensation claims by the person whose data was mishandled
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionZakon o zaštiti podataka o ličnosti, Službeni glasnik RS 87/2018 (full text published by the Commissioner)
poverenik.rs
“Новчаном казном од 50.000 до 2.000.000 динара казниће се за прекршај руковалац, односно обрађивач који има својство правног лица”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionBylaws made under the Law on Personal Data Protection, including the impact-assessment list 45/2019 and 112/2020
poverenik.rs
Link checked 18 August 2026
Odluka o Listi država, delova njihovih teritorija ili jednog ili više sektora određenih delatnosti u tim državama i međunarodnih organizacija u kojima se smatra da je obezbeđen primereni nivo zaštite podataka o ličnosti
Adequacy decision · Službeni glasnik RS, br. 55/2019; 05 broj 021-7718/2019
The Government's list of destinations treated as safe. Part one names 54 members of the Council of Europe data protection treaty — all of Europe plus Argentina, Mexico, Morocco, Mauritius, Senegal, Tunisia, Uruguay, Cape Verde, Turkey, Russia and others. Part two names the destinations the European Union had approved in 2019. Sending personal data to anywhere on this list needs no contract and no permission.
Enforced by Government of the Republic of Serbia
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Nothing required
Sources
- Official sourceGovernment of the Republic of Serbia (copy published by the Commissioner)Odluka o Listi država ..., Službeni glasnik RS 55/2019, adopted 1 August 2019
poverenik.rs
“Ова одлука ступа на снагу осмог дана од дана објављивања у „Службеном гласнику Републике Србије”, а примењује се од 21. августа 2019. године.”
Link checked 18 August 2026
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's Annual Report for 2025 — confirms 55/2019 is still the only Government bylaw under the privacy law and has not been amended
poverenik.rs
Link checked 18 August 2026
Lista država, Deo II, tačka 7) — Sjedinjene Američke Države (ograničeno na „Privacy Shield framework”)
Adequacy decision · Službeni glasnik RS, br. 55/2019, Part II item 7
The Government's list still says the United States is safe under the Privacy Shield framework. That framework was struck down by the European Court of Justice on 16 July 2020, and Serbia's own regulator said in August 2020 that the entry can no longer be relied on. The line is still printed in the Official Gazette six years later, so a naive reading of the list gives the wrong answer.
Enforced by Commissioner for Information of Public Importance and Personal Data Protection
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Standard contract clauses, Approved group rules
What it makes you do
- Put a transfer safeguard in placeFor United States transfers, use the Commissioner's standard contractual clauses or binding corporate rules. Do not rely on the entry printed in the Government's list.
Sources
- Official sourceCommissioner for Information of Public Importance and Personal Data ProtectionCommissioner's notice of 11 August 2020 — Privacy Shield no longer provides an adequate level of protection under Serbian law either
poverenik.rs
“може се закључити да, следствено томе, Сједињене Америчке Државе на основу „Privacy Shield framework“ више не обезбеђују примерени ниво заштите ни са становишта Закона о заштити података о личности.”
Link checked 18 August 2026
- Official sourceGovernment of the Republic of SerbiaOdluka o Listi država, Part II item 7 — the text that remains in the Official Gazette
poverenik.rs
Link checked 18 August 2026
Zakon o informacionoj bezbednosti
Act of parliament · Službeni glasnik RS, br. 91/2025
Serbia's replacement cyber security law, in force since 31 October 2025. It creates a new Office for Information Security, gives operators of important systems 24 hours to report a serious incident, and requires them to register with the ministry, including how many physical locations their system occupies. It contains no requirement to keep data in Serbia. One provision, on ministry supervision of the new Office, only starts on 1 January 2027.
Enforced by Office for Information Security — not yet operational
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — applies at: Operators of information and communication systems of special importance, within 24 hoursThen updates every 24 hours for a high or very high severity incident, every three days for a medium one, and a final report within 15 days of the incident ending.
- Register or notifyOperators must file details with the ministry within 90 days, including the number of locations where the system sits.
- Secure the dataAdopt a risk assessment act and a security act; review the risk assessment at least once a year and self-check the system annually.
- Independent audit — 1 year
What it costs if you get it wrong
- Fixed maximum fineMisdemeanour penalties for operators of systems of special importance
Sources
- Official sourceRegulatory Authority for Electronic Communications and Postal Services (official copy of the gazette text)Zakon o informacionoj bezbednosti, Službeni glasnik RS 91/2025 of 23 October 2025, Articles 9 to 14, 24, 28 to 31 and 58
ratel.rs
“Овај закон ступа на снагу осмог дана од дана објављивања у „Службеном гласнику Републике Србије”, изузев члана 29. овог закона који почиње да се примењује од 1. јануара 2027. године.”
Link checked 18 August 2026
- Official sourceRegulatory Authority for Electronic Communications and Postal ServicesRegulator's index of information security laws, showing 91/2025 as the current law and 6/16, 94/17 and 77/19 as archived
ratel.rs
Link checked 18 August 2026
Industry rules4 rules
Pravilnik o informaciono-komunikacionom sistemu za priređivanje posebnih igara na sreću preko sredstava elektronske komunikacije
Government rules · Službeni glasnik RS, br. 152/2020, izmene 58/2025 · Online gaming
Serbia's one true storage wall. An online gambling operator must hold its database of everything reported to the Gaming Administration inside Serbia — either the live database or a mirror of it. Transactions must be kept for at least ten years, and the Administration gets constant data access plus a remote connection into the system.
Enforced by Administration for Games of Chance
Transfer model: Approval each time
What it makes you do
- Keep the data in the countryThe database of everything reported to the Administration must be on Serbian territory, either as the production database or as a mirror or replica of it. Processing elsewhere is not forbidden, but the Serbian copy is mandatory.
- Keep data for a minimum period — 10 yearsAll transactions, at least ten years. After that, archived data must be produced to the Administration within five days on request.
- Register or notifyThe Administration must have permanent access to transaction type, time and amount, and remote access to the system over a private network.
What it costs if you get it wrong
- Loss of your licenceBreach of the technical conditions attached to an online games of chance approval
Sources
- Official sourceAdministration for Games of Chance, Ministry of FinanceRulebook on the information and communication system for organising special games of chance by means of electronic communication (English text), Articles 2, 6 and 7
uis.gov.rs
“which must be located on the territory of the Republic of Serbia, either as a production base or as a replica of that base (e.g. mirror or replica server)”
Link checked 18 August 2026
- Official sourceAdministration for Games of Chance, Ministry of FinanceAdministration for Games of Chance — index of rulebooks, showing gazette 152/2020 as amended by 58/2025
uis.gov.rs
Link checked 18 August 2026
Odluka o uslovima i načinu poveravanja aktivnosti u vezi sa informaciono-komunikacionim sistemom finansijske institucije trećim licima
Directly binding regulation · Službeni glasnik RS, br. 100/2023; NBS EB No 83 of 9 November 2023 · Finance
Banks, insurers and other financial firms in Serbia may put IT work and data abroad, but only through a gate. You tell the central bank 30 days before signing, you prove the destination country would let Serbian supervisors inspect the supplier on site, and you keep a register of exactly which countries hold the data. The central bank can block the deal or force you to unwind one you have already signed.
Enforced by National Bank of Serbia
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Written vendor contractThe contract must oblige the supplier to comply fully with Serbian law, and the institution must keep its data in its own possession and under its own control.
- Register or notify — within 720 hoursNotify the National Bank at least 30 days before signing. The signed contract must follow within 15 days.
- Keep records of processingKeep a live register of outsourced activities naming the country or countries where the activity is performed and where the data are located.
- Independent auditIf the supplier is based abroad, or the work is done abroad, you must supply evidence that the foreign country's law lets the National Bank of Serbia carry out on-site supervision there.
What it costs if you get it wrong
- Order to stopIf the National Bank finds the arrangement creates market concentration or supplier dominance risk, the institution may not proceed, or must terminate an existing contract within a period the Bank sets, never shorter than three months.
Sources
- Official sourceNational Bank of SerbiaDecision on terms and conditions of outsourcing relating to a financial institution's information-communication system, Official Gazette 100/2023, Sections 19 to 22 and 35
nbs.rs
“evidence that the regulations of the country, and/or the countries in which the service provider operates enable the National Bank of Serbia to smoothly perform on-site supervision”
Link checked 18 August 2026
- Official sourceNational Bank of SerbiaNational Bank of Serbia — regulations on the supervision of financial institutions' information systems
nbs.rs
Link checked 18 August 2026
Odluka o minimalnim standardima upravljanja informaciono-komunikacionim sistemom finansijske institucije
Directly binding regulation · Službeni glasnik RS, br. 102/2024; NBS EB No 85 of 20 December 2024 · Banking
The new rulebook for how Serbian banks, insurers and payment firms run and secure their technology. It replaced the 2013 rules and only started to apply on 1 January 2026, with a short extension to 30 June 2026 for banks that had already notified a core-system migration. It sets a 24-hour clock to classify a cyber incident and report it to the central bank.
Enforced by National Bank of Serbia
Transfer model: Approval each time
What it makes you do
- Secure the data — from 1 January 2026
- Report cyber incidents — within 24 hours, from 1 January 2026Classify an incident within 24 hours of detection. If you cannot classify it in time, file an initial report to the National Bank anyway.
- Independent audit — from 1 January 2026
Sources
- Official sourceNational Bank of SerbiaDecision on Minimum Information-Communication System Management Standards for Financial Institutions, Official Gazette 102/2024, Sections 41, 44, 62 and 65
nbs.rs
“This Decision shall enter into force on the eighth day following its publication in the RS Official Gazette and shall apply as of 1 January 2026.”
Link checked 18 August 2026
Zakon o elektronskim komunikacijama (2010) — surviving Articles 126(1), 127 to 130a and 137(1)(2)-(4)
Act of parliament · Službeni glasnik RS, br. 44/10, 60/13 – US, 62/14, 95/18; kept alive by Article 180 of the 2023 law (35/2023) · Telecoms
Serbian phone and internet companies must keep who-called-whom records for 12 months and then destroy them. Access needs a court order. Oddly, this duty now lives on as a fragment of a law that was otherwise repealed in 2023: the new electronic communications law kept these articles alive until a dedicated interception and retention law arrives, and that law has not appeared. The ministry's power to write detailed retention rules was struck down as unconstitutional in 2013 and never replaced.
Enforced by Regulatory Authority for Electronic Communications and Postal Services
Transfer model: Approval each time
What it makes you do
- Keep logs — 1 yearWho contacted whom, when, from where and on what device. Retaining the content of a communication is forbidden.
- Delete data after a period — 1 yearRetained data must be destroyed once the 12 months expire, unless already handed over under a court order.
- Keep records of processingOperators and the authorities that access retained data must each keep a secret log of every access request. The Commissioner processed 104 such access records in 2025.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fineFailure to comply with the retained-data rules is a misdemeanour under Article 137 of the 2010 law
Sources
- Official sourceRegulatory Authority for Electronic Communications and Postal ServicesZakon o elektronskim komunikacijama (2010, consolidated text), Articles 128 to 130a, and the note on Constitutional Court decision IUz-1245/2010
ratel.rs
“Odlukom Ustavnog suda IUz-1245/2010 ("Sl. glasnik RS", br. 60/13) utvrđeno je da stav 4. člana 129. Zakona o elektronskim komunikacijama ... nije u saglasnosti sa Ustavom”
Link checked 18 August 2026
- Official sourceRegulatory Authority for Electronic Communications and Postal ServicesZakon o elektronskim komunikacijama, Službeni glasnik RS 35/2023, Article 180 — repeal with carve-outs for the retention articles
ratel.rs
“Даном ступања на снагу овог закона престаје да важи Закон о електронским комуникацијама ... осим одредаба члана 126. став 1, чл. 127–130а и члана 137. став 1. тач. 2)–4).”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether transfers to United States organisations certified under the EU-US Data Privacy Framework (adopted by the European Union in July 2023) are treated as adequate in Serbia
The statutory presumption in Article 64(2) points at whatever the European Union has approved, which would cover it, but the Government's list has never been updated and no Serbian authority has published a confirmation. Same gap for South Korea, approved by the European Union in December 2021. Safer to use the standard contractual clauses.
Whether Serbian public bodies are legally obliged to keep their systems and data in the State Data Centre in Kragujevac or otherwise in Serbia
The Office for Information Technology and eGovernment operates the centre under the Law on Electronic Government, but we could not open the statute text — the official legal information system serves its content only through JavaScript and blocks automated fetching. No localisation duty is asserted here.
Whether the Office for Information Security has been constituted, has a director, and is issuing decisions
The law creating it has been in force since 31 October 2025, but we could find no website, no appointment notice and no published output. We can evidence that the telecoms regulator still runs the national CERT; we cannot prove the negative about the new Office.
Whether Commissioner Milan Marinović's mandate is still current
The institution's own pages state he was elected by the National Assembly on 26 July 2019 and still name him in August 2026, but they do not state the term length and we found no re-election notice. Serbia has previously run this office for months on a deputy after a mandate expired.
Any localisation or storage rule for health records, education, securities markets, mapping and geospatial data, or defence
No rule found, checked 18 August 2026, medium confidence. The health ministry's own laws page lists only the Healthcare Act and does not publish the Act on Health Documentation and Records, so we could not read the retention periods for medical files.
Whether a dedicated law on lawful interception and data retention has been adopted since 2023
The 2023 electronic communications law repeatedly defers to such a law and preserved the old retention articles pending it. We found no adopted text, but we could not search the Official Gazette systematically because the state legal information portal blocks automated access.
Precise dinar-to-dollar conversions for the penalty figures
Converted at roughly 105 dinars to the dollar. We could not read the National Bank's live middle rate, which is served through a separate web application. Treat every dollar figure here as an approximation.
The exact date the National Assembly adopted the Law on Personal Data Protection
The gazette number (87/2018) and the commencement arithmetic are solid, and both give 21 November 2018 for entry into force and 21 August 2019 for application. The adoption date of 9 November 2018 is inferred from the publication date rather than read off a gazette page we could open.
60-day cadence. Three things can move without warning: the Government can rewrite the adequacy list by decision at any time (it is six years stale, so a correction is overdue); the new Office for Information Security could stand up at any point and change who you report a cyber incident to; and the working groups on a rewritten privacy law and an artificial intelligence law could produce bills. The Commissioner's mandate status is also unresolved.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Serbia versus Argentina
- Serbia versus Armenia
- Serbia versus Australia
- Serbia versus Austria
- Serbia versus Azerbaijan
- Serbia versus Brazil
- Serbia versus Bulgaria
- Serbia versus Cambodia
- Serbia versus Canada
- Serbia versus China
- Serbia versus Croatia
- Serbia versus Cyprus
- Serbia versus Estonia
- Serbia versus France
- Serbia versus Georgia
- Serbia versus Germany
- Serbia versus Greece
- Serbia versus Hong Kong SAR
- Serbia versus Hungary
- Serbia versus Iceland
- Serbia versus India
- Serbia versus Indonesia
- Serbia versus Ireland
- Serbia versus Israel
- Serbia versus Italy
- Serbia versus Japan
- Serbia versus Latvia
- Serbia versus Lithuania
- Serbia versus Luxembourg
- Serbia versus Malta
- Serbia versus Mexico
- Serbia versus Mongolia
- Serbia versus Nepal
- Serbia versus Netherlands
- Serbia versus Poland
- Serbia versus Russia
- Serbia versus Saudi Arabia
- Serbia versus Singapore
- Serbia versus Slovakia
- Serbia versus Slovenia
- Serbia versus South Korea
- Serbia versus Spain
- Serbia versus Sri Lanka
- Serbia versus Sweden
- Serbia versus Switzerland
- Serbia versus Taiwan
- Serbia versus Thailand
- Serbia versus Turkey
- Serbia versus Ukraine
- Serbia versus United Arab Emirates
- Serbia versus United Kingdom
- Serbia versus United States
- Serbia versus Uzbekistan