Law on the Protection of Personal Data of Bosnia and Herzegovina
The new Law on the Protection of Personal Data replaced the 2006 act and, per CMS, Lexology and Vixio, substantially transposes General Data Protection Regulation (GDPR) principles, concepts and structure alongside Directive (EU) 2016/680 elements, including mandatory Data Protection Officers and DPIAs, though this research did not independently confirm the lawful-basis article against primary text.
Primary text confirms biometric data as a special category with two dedicated processing articles, Article 57a on secure-identification biometric processing and Article 57b on workplace biometric processing, both conditioned on explicit consent, going beyond a bare definitional listing. A cross-border transfer regime keyed to Council of Ministers adequacy decisions, and a standalone judicial remedy alongside the administrative complaint to the Agency, are both confirmed on primary text. Breach notification is reported to exist as a duty but its threshold and deadline were not located in this research.
What it asks of an app →