Law / Bosnia and Herzegovina

Law on the Protection of Personal Data of Bosnia and Herzegovina, personal data breach notification

Law on the Protection of Personal Data, arts. 35-36, 86-87 (personal data breach notification)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force 12 months, effective 4 October 2025.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the Agency of a personal data breach without undue delay and, if possible, within 72 hours of becoming aware of the breach, giving the Agency the reasons for the delay where notice comes later.
  • As a processor, notify the controller without undue delay after becoming aware of a personal data breach.
  • Notify the affected person of a personal data breach without delay, in writing and in clear language, wherever the breach is likely to result in a high risk to that person's rights and freedoms, unless the data were rendered unintelligible, the high risk can no longer materialize, or notice would take disproportionate effort and a public notice reaches the person as effectively.
  • Describe in the notification the nature of the breach, the data protection officer's or another contact point's details, the likely consequences and the measures taken or proposed, supplying the information in phases if it cannot all be given at once, and document every breach, its facts, effects and remedial action for the Agency to review.
  • As a competent authority processing personal data for a criminal-law purpose, notify the Agency of a breach within the same 72-hour window and the affected person without delay under the same high-risk test, and pass the breach information to the data controller of another country without undue delay wherever the breached data were transmitted by or to it.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 35 requires the data controller to notify the Agency of a personal data breach without undue delay and, if possible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to endanger a person's rights and freedoms, giving the Agency the reasons for the delay if notice comes later than 72 hours.

Article 35(2) requires a processor to notify the controller without undue delay after becoming aware of a breach, and Article 35(3) fixes what the notification to the Agency must contain: the nature of the breach and, where possible, the categories and approximate numbers of people and records concerned, the data protection officer's or another contact point's details, the likely consequences, and the measures taken or proposed, which Article 35(4) lets the controller supply in phases where they cannot all be given at once.

Article 35(5) requires the controller to document every breach, its facts, consequences and remedial action, so the Agency can review compliance.

Article 36 requires the controller to notify the affected person in writing without delay wherever the breach is likely to result in a high risk to their rights and freedoms, describing the breach in clear and plain language and giving the same contact-point, consequences and measures information, unless the data were rendered unintelligible by a measure such as encryption, a later measure has removed the high risk, or notice would take disproportionate effort and a public notice reaches people as effectively; Article 36(4) lets the Agency require the notice anyway where none of those conditions is met.

Articles 86 and 87 restate the same 72-hour Agency notice and high-risk person notice for a competent authority processing personal data for a criminal-law purpose, and Article 86(8) additionally requires the competent authority to pass the breach information on to the data controller of another country without undue delay wherever the breached data were transmitted by or to that controller.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • operates_essential_service

Read the law

Official English-language statute PDF hosted by the Agency for Statistics of Bosnia and Herzegovina (bhas.gov.ba)
read in full (207,438 characters, untruncated)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app