Law on Personal Data Protection, personal data breach notification
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 21 August 2019.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Commissioner of a breach that may create risk to a person's rights and freedoms without undue delay, and within 72 hours of becoming aware of the breach where that is possible; give reasons for any delay beyond 72 hours.
- As a processor, notify the controller without undue delay after becoming aware of a breach.
- Notify the affected person of a breach without undue delay, in clear language, whenever the breach may create high risk to their rights and freedoms.
- Describe in the Commissioner notification the nature of the breach, the data protection officer's or another contact point's details, the likely consequences, and the measures taken or proposed, and supply the information in phases without undue further delay where it cannot all be given at once.
- Document every breach, including its facts, effects and remedial action, so the Commissioner can assess compliance.
- Skip notifying the affected person only where you have made the data unintelligible, such as by encryption, where subsequent measures have removed the high risk, or where notifying would take disproportionate effort and you have made an equally effective public communication instead; the Commissioner can still order the notice.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 52 requires a controller to notify the Commissioner of a personal data breach that may create risk to a person's rights and freedoms without undue delay, and within 72 hours of becoming aware of the breach where that is possible, giving reasons for any delay beyond that period. A processor must notify the controller without undue delay after becoming aware of a breach.
The notification to the Commissioner must describe the nature of the breach, give the data protection officer's or another contact point's details, describe the likely consequences and the measures taken or proposed, and article 52 lets the controller supply this information in phases without undue further delay where it cannot all be given at once; the controller must also document every breach, including its facts, effects and remedial action, so the Commissioner can assess compliance.
Article 53 requires the controller to notify the affected person without undue delay, in clear and understandable language, wherever the breach may create high risk to their rights and freedoms, but excuses that notice where encryption or another measure has made the data unintelligible, subsequent measures have removed the high risk, or notifying would take disproportionate effort and a public communication substitutes for it, with the Commissioner able to order the notice anyway.
The act states no fixed number of hours for notifying the affected person; only the notice to the Commissioner carries the 72-hour figure.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
Zakon o zastiti podataka o licnosti, full consolidated statute text (paragraf.rs)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.