Law / Bosnia and Herzegovina

Bosnia and Herzegovina

privacy

Bosnia and Herzegovina is not a General Data Protection Regulation (GDPR) jurisdiction. Its comprehensive personal data statute is the Law on the Protection of Personal Data, Official Gazette of BiH No. 12/25, applicable since 4 October 2025 and superseding the pre-GDPR 2006 act (OG BiH Nos. 49/06, 76/11).

Primary text confirms biometric data as an explicit special category with two dedicated processing articles beyond the bare definition, a real adequacy-plus-safeguards cross-border transfer regime, and a standalone judicial remedy alongside the administrative complaint route. Breach notification is confirmed to exist as a duty but its threshold and deadline, and the full lawful-basis and data-subject-rights chapters, were not independently confirmed against primary text in this research pass.

5 instruments named 1 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

Law on the Protection of Personal Data of Bosnia and Herzegovina

cite Law on the Protection of Personal Data, Official Gazette of Bosnia and Herzegovina No. 12/25, applicable 4 October 2025 stage In effect since 2025-10-04 source Official English-language statute PDF hosted by the Agency for Statistics of Bosnia and Herzegovina (bhas.gov.ba), read in full through crawler infrastructure (212,466 characters, untruncated)

The new Law on the Protection of Personal Data replaced the 2006 act and, per CMS, Lexology and Vixio, substantially transposes General Data Protection Regulation (GDPR) principles, concepts and structure alongside Directive (EU) 2016/680 elements, including mandatory Data Protection Officers and DPIAs, though this research did not independently confirm the lawful-basis article against primary text.

Primary text confirms biometric data as a special category with two dedicated processing articles, Article 57a on secure-identification biometric processing and Article 57b on workplace biometric processing, both conditioned on explicit consent, going beyond a bare definitional listing. A cross-border transfer regime keyed to Council of Ministers adequacy decisions, and a standalone judicial remedy alongside the administrative complaint to the Agency, are both confirmed on primary text. Breach notification is reported to exist as a duty but its threshold and deadline were not located in this research.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.