Law / Serbia

Serbia

privacy

Serbia is not a General Data Protection Regulation (GDPR) jurisdiction. Its comprehensive personal data statute, the Law on Personal Data Protection (Zakon o zastiti podataka o licnosti), Official Gazette RS No. 87/2018, has been applicable since 2019 and is closely GDPR-modelled.

Serbia is simultaneously running a live reform: the Ministry of Justice published a draft replacement for public consultation on 30 July 2026, running through 10 September 2026, that is reported to grow the act from 102 to 175 articles and add new AI-processing, video-surveillance, biometric-identification, and cross-border-transfer regimes.

Primary text confirms a standalone civil damages right under Article 86 of the 2018 act and a real, moderate cross-border transfer regime; the lawful-basis chapter, biometric-definition text, and breach notification duty were not independently confirmed against primary text in this research.

8 instruments named 2 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

Draft Law on Personal Data Protection (2026 reform)

cite Draft Law on Personal Data Protection, Ministry of Justice of the Republic of Serbia, public consultation opened 30 July 2026 stage Proposed source IAPP news analysis, corroborated by Chambers and Partners' 2026 practice guide describing the reform as well advanced

The Ministry of Justice published a draft replacement Law on Personal Data Protection for public consultation on 30 July 2026, with consultation running through 10 September 2026.

The draft is reported to grow from 102 to 175 articles and restructure the law into three parts, adding an explicit legitimate-interest basis for AI training in exceptional cases, a video-surveillance regime with a six-month retention cap, and new biometric-identification and cross-border-transfer regimes not present in the current 2018 act. It has not been introduced to the National Assembly and has not been adopted; this instrument is not currently binding.

What it asks of an app

Law on Personal Data Protection

cite Zakon o zastiti podataka o licnosti (Law on Personal Data Protection), Official Gazette RS No. 87/2018 stage In effect since 2019-08-21 source Chambers and Partners 2026 Serbia Data Protection and Privacy practice guide

The Personal Data Protection Act has been applicable since 2019 and is closely General Data Protection Regulation (GDPR)-modelled per Chambers and Partners' 2026 practice guide, though the lawful-basis and controller and processor articles were not independently confirmed against primary text. Biometric data for unique identification is confirmed as an explicit special category, generally prohibited unless a specific exemption applies.

A real, moderate cross-border transfer regime is confirmed: transfers to adequate-level countries proceed freely, and other destinations need safeguards such as standard contractual clauses, binding corporate rules, or Commissioner-authorized clauses. Primary text confirms a standalone civil damages right under Article 86, separate from the administrative complaint and lawsuit procedures at Articles 82 to 84. Breach notification's existence was not confirmed either way.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.