Law note · Bosnia and Herzegovina

Law on the Protection of Personal Data of Bosnia and Herzegovina

cite Law on the Protection of Personal Data, Official Gazette of Bosnia and Herzegovina No. 12/25, applicable 4 October 2025 stage In effect since 2025-10-04 reviewed 2026-08-24

The new Law on the Protection of Personal Data replaced the 2006 act and, per CMS, Lexology and Vixio, substantially transposes General Data Protection Regulation (GDPR) principles, concepts and structure alongside Directive (EU) 2016/680 elements, including mandatory Data Protection Officers and DPIAs, though this research did not independently confirm the lawful-basis article against primary text.

Primary text confirms biometric data as a special category with two dedicated processing articles, Article 57a on secure-identification biometric processing and Article 57b on workplace biometric processing, both conditioned on explicit consent, going beyond a bare definitional listing. A cross-border transfer regime keyed to Council of Ministers adequacy decisions, and a standalone judicial remedy alongside the administrative complaint to the Agency, are both confirmed on primary text. Breach notification is reported to exist as a duty but its threshold and deadline were not located in this research.

What it asks of an app

  • Establish a lawful basis and allocate controller and processor duties before processing personal data of a person in Bosnia and Herzegovina, including appointing a Data Protection Officer where the law requires one.
  • Obtain explicit consent before processing a biometric identifier for secure identification or workplace time recording and access control, under Articles 57a and 57b.
  • Rely on a Council of Ministers adequacy decision or an appropriate safeguard before transferring personal data of a person in Bosnia and Herzegovina outside the country.
  • Expect a person in Bosnia and Herzegovina to have both an administrative complaint route to the Agency and a separate right to bring an action before the competent court for any infringement of this law.

When LexLint raises it

Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics

Primary source: Official English-language statute PDF hosted by the Agency for Statistics of Bosnia and Herzegovina (bhas.gov.ba), read in full through crawler infrastructure (212,466 characters, untruncated)

← Back to the example  ·  Lint your app →