Law / Serbia

Law on Information Security, Incident Reporting Obligations

Zakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 13-14, 24-25

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 9 months, effective 1 January 2026.

A vulnerability and incident reporting rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • This duty reaches the same priority and important ICT system operators as this law's security-measures duty, including a business that provides an information society service under Serbia's e-commerce law.
  • Notify the single incident-reporting system, through the Ministry's or the Office for Information Security's website, of an incident that may significantly disrupt information security, without delay and at the latest within 24 hours of becoming aware of it.
  • If you operate a banking or financial-market ICT system, send that notification to the National Bank of Serbia, and also to the Securities Commission if it supervises you; if you provide an electronic-communications or postal service, send it to the Regulatory Body for Electronic Communications and Postal Services instead.
  • Notify the users of your service, without delay, of an incident that causes or may cause a harmful effect on providing or using your service, together with any measures they can take to reduce or remove the harmful effect.
  • While the incident continues, submit a status report to the single incident-reporting system every three days for a medium-level incident, or every 24 hours for a high or very high-level incident.
  • Submit a final report within 15 days after the incident ends, covering its type, cause, duration, scope of impact, any cross-border effect, and the steps you took to remedy it.
  • Report a near-miss that constitutes a serious threat, and submit an annual statistical return covering all incidents and near-misses in your ICT system to the National CERT authority by 28 February of the following year.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

The sanction Article 52 and Article 53 set for a reporting failure is a misdemeanor fine (novčana kazna za prekršaj), not a criminal offence; the banking and financial-market carve-out in Article 52 routes a reporting failure by that sector to the National Bank of Serbia's own supervisory sanctions instead of this Article's fine.

Penalty structure

Article 52: a legal entity that is a priority-system operator faces a misdemeanor fine of 50,000 to 500,000 dinars for failing to notify the incident to the required authorities, failing to notify affected users, or failing to submit during- and after-incident reports; a natural person operating as a registered subject faces 10,000 to 500,000 dinars, and a responsible person faces 5,000 to 50,000 dinars. Article 53 sets the identical 50,000-to-500,000-dinar range for an important-system legal entity for the same failures, and 5,000 to 50,000 dinars for a responsible person; its own text states the natural-person tier as 10,000 to 250,000 dinars but, read literally, names the fine-bearer "operator prioritetnog IKT sistema" rather than "operator važnog IKT sistema" in that one sentence, which appears to be a drafting inconsistency in the source text rather than a deliberate cross-reference, worth a reviewer's separate check against a later official consolidation. Article 52 exempts a banking or financial-market operator from this Article's fine for a reporting failure toward the National Bank of Serbia, which instead applies its own sectoral measures and sanctions.

Rule
Fixed only
As of
18 September 2026
Minimum
50,000
Currency
RSD
Fixed cap
500,000

Who enforces it

Enforcement body

The ministry responsible for information security affairs and, once established on 1 January 2027, the Office for Information Security, receiving reports through the single incident-reporting system; the National Bank of Serbia, the Securities Commission, and the Regulatory Body for Electronic Communications and Postal Services each receive and forward reports for the sector each supervises.

Settledness

As of
18 September 2026
Open questions
Article 53's natural-person fine sentence names "operator prioritetnog IKT sistema" where the rest of the Article addresses "operator važnog IKT sistema": is this a drafting error in the gazette text itself, or a considered cross-reference?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 13 requires a priority or important ICT system operator to notify a significant incident without delay and at the latest within 24 hours of becoming aware of it, and to report a near-miss that constitutes a serious threat on the same basis.

Article 14 routes that notification through a single incident-reporting system, with a banking or financial-market operator also notifying the National Bank of Serbia or the Securities Commission and an electronic-communications or postal operator instead notifying the Regulatory Body for Electronic Communications and Postal Services, and requires notice to affected users without delay where an incident harms or may harm the provision or use of a service.

Article 24 adds a during-incident reporting clock of every three days for a medium-level incident or every 24 hours for a high or very high-level incident, plus a final report within 15 days of the incident ending. Article 25 adds an annual statistical return, covering incidents and near-misses, due to the National CERT authority by 28 February of the following year.

When LexLint raises it

  • operates_social_platform

Read the law

Consolidated statute text, Paragraf Lex (paragraf.rs), sourced from "Službeni glasnik Republike Srbije", br. 91/2025

Back to the example  ·  Lint your app