Law / Serbia

Law on Personal Data Protection, the Commissioner, legal remedies and penalties

Law on Personal Data Protection, arts. 73-87 and 95 (the Commissioner, legal remedies and penalties), Official Gazette RS No. 87/2018

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 21 August 2019.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Expect the independent Commissioner for Information of Public Importance and Personal Data Protection to supervise compliance, free from external instruction, with inspection, information-demand and corrective powers.
  • Expect a person in Serbia to be able to complain to the Commissioner about processing they believe violates this law, and to challenge the Commissioner's decision in an administrative dispute within 30 days.
  • Expect a person to be able to authorize a privacy advocacy association to represent them in a complaint, an administrative dispute, a court action, or a damages claim.
  • Expect a person in Serbia to have a court-enforceable damages claim under Article 86 for material or non-material harm from an infringement of this law, separate from a complaint to the Commissioner, with the controller liable and a processor liable only where it acted outside the controller's lawful instructions.
  • Expect fines to be set case by case for an effective, proportionate and dissuasive effect, weighing the nature, gravity and duration of the violation, intent or negligence, mitigation efforts, prior violations, cooperation with the Commissioner, and the categories of data involved.
  • Expect a fine of 50,000 to 2,000,000 dinars for a legal-entity controller or processor's breach of most of the act's substantive duties, smaller fixed fines for narrower violations, 5,000 to 150,000 dinars for a natural person or a responsible person, and 20,000 to 500,000 dinars for an entrepreneur, imposed as a misdemeanor sanction rather than a criminal offense.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

Article 95's general band (RSD 50,000 to 2,000,000) covers a legal-entity controller or processor's breach of most of the Act's substantive duties (processing principles, purpose limitation, transparency, data-subject rights, cross-border transfer, and more, enumerated across 32 clauses). Narrower violations carry smaller amounts: a separate fixed RSD 100,000 fine for a shorter list of legal-entity violations (e.g. failing to inform a recipient of special conditions, failing to give a data subject a reasoned decision); RSD 5,000 to 150,000 for a natural person or a responsible person within a legal entity, public authority, or foreign representative office; and RSD 20,000 to 500,000 for an entrepreneur. These are misdemeanor (prekrsaj) sanctions rather than Criminal Code offenses, imposed by the Commissioner directly through a prekrsajni nalog (misdemeanor order) issued during inspection, or through misdemeanor court proceedings, and are far lower than the GDPR-modelled figures used in EU member states since Serbia is not an EU jurisdiction.

Rule
Fixed only
As of
19 September 2026
Minimum
50,000
Currency
RSD
Fixed cap
2,000,000

Who enforces it

Enforcement body

Poverenik za informacije od javnog znacaja i zastitu podataka o licnosti (the Commissioner for Information of Public Importance and Personal Data Protection), which both investigates and, through a prekrsajni nalog issued at inspection or through misdemeanor court proceedings, imposes Article 95's fines

What it reaches

Obligation class

Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 73 makes the Commissioner for Information of Public Importance and Personal Data Protection an independent state authority responsible for monitoring the law's application. Article 74 bars the Commissioner from taking instructions from anyone or holding other paid or unpaid work, public office, or political role. Article 79 gives the Commissioner inspection powers, including ordering a controller or processor to supply information, checking compliance, and warning of possible violations.

Article 82 gives a person the right to complain to the Commissioner about processing they believe breaches the law. Article 83 lets any party to the Commissioner's decision challenge it in an administrative dispute within 30 days. Article 85 lets a person authorize a privacy advocacy association to represent them in a complaint, an administrative dispute, a court action, or a damages claim.

Article 86 gives a person who suffered material or non-material damage from a breach of the law a court-enforceable right to monetary compensation from the controller, or from the processor only where it acted outside the controller's lawful instructions or its own duties under the law.

Article 87 requires fines to be set case by case for an effective, proportionate and dissuasive effect, weighing factors including the nature, gravity and duration of the violation, intent or negligence, mitigation efforts, prior violations, and cooperation with the Commissioner.

Article 95 fixes those fines as misdemeanor sanctions rather than criminal offenses: 50,000 to 2,000,000 dinars for a legal-entity controller or processor's breach of most of the act's substantive duties, a separate fixed 100,000 dinars for a shorter list of narrower violations, 5,000 to 150,000 dinars for a natural person or a responsible person within an entity, and 20,000 to 500,000 dinars for an entrepreneur, imposed by the Commissioner through a misdemeanor order or misdemeanor court proceedings.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • high_risk_decisions

Read the law

Zakon o zastiti podataka o licnosti, full consolidated statute text (paragraf.rs)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app