Serbia Law on Personal Data Protection (2018)
Serbia's Law on Personal Data Protection (Official Gazette No. 87/2018), effective August 2019, is closely aligned with the EU GDPR as part of Serbia's EU accession process. The Commissioner for Information of Public Importance and Personal Data Protection oversees enforcement. The law covers processing principles, lawful bases (including consent and legitimate interest), data subject rights (access, rectification, erasure, portability), DPO requirements, breach notification, and cross-border transfers. Applies to all personal data processing in Serbia.
Serbia Law on Personal Data Protection (2018) is a compliance framework from Serbia with 11 domains and 26 controls. The largest domains are Serbia LPDP: Accountability and Records (5 controls), Serbia LPDP: Scope and Lawful Basis (4 controls), Serbia LPDP: Transparency and Data Subject Rights (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
Breach
| Code | Title |
|---|---|
| SERBIA-5 | Breach + Enforcement |
Governance
| Code | Title |
|---|---|
| SERBIA-4 | DPO + Governance |
Rights
| Code | Title |
|---|---|
| SERBIA-2 | Consent, Notice, Rights |
Scope
| Code | Title |
|---|---|
| SERBIA-1 | Scope, Lawful Basis (Serbia) |
Security
| Code | Title |
|---|---|
| SERBIA-3 | Security and Cross-Border |
Serbia LPDP: Accountability and Records
| Code | Title |
|---|---|
| RS-DPL-10.1 | Data Protection Officer |
| RS-DPL-11.1 | Processor Engagement and Contracts |
| RS-DPL-7.1 | Data Protection by Design and Default |
| RS-DPL-8.1 | Records of Processing Activities |
| RS-DPL-9.1 | Data Protection Impact Assessment |
Serbia LPDP: Cross-Border Transfers
| Code | Title |
|---|---|
| RS-DPL-13.1 | Cross-Border Transfers |
| RS-DPL-13.2 | Adequacy and Commissioner Authorisation |
| RS-DPL-18.1 | Representative Appointment for Non-Established Controllers |
Serbia LPDP: Scope and Lawful Basis
| Code | Title |
|---|---|
| RS-DPL-1.1 | Scope and Territorial Application |
| RS-DPL-2.1 | Lawful Basis for Processing |
| RS-DPL-3.1 | Consent Requirements |
| RS-DPL-6.1 | Special Categories of Data |
Serbia LPDP: Security and Breach Notification
| Code | Title |
|---|---|
| RS-DPL-12.1 | Personal Data Breach Notification to Commissioner |
| RS-DPL-12.2 | Breach Notification to Data Subjects |
| RS-DPL-14.1 | Security of Processing |
Serbia LPDP: Supervision and Sanctions
| Code | Title |
|---|---|
| RS-DPL-16.1 | Commissioner Cooperation and Inspections |
| RS-DPL-17.1 | Sanctions and Administrative Fines |
Serbia LPDP: Transparency and Data Subject Rights
| Code | Title |
|---|---|
| RS-DPL-15.1 | Automated Decisions and Profiling |
| RS-DPL-4.1 | Transparency and Information to Subjects |
| RS-DPL-5.1 | Data Subject Rights |
| RS-DPL-5.2 | Right to Erasure and Restriction |
What is Serbia Law on Personal Data Protection (2018) and who does it apply to?
Serbia Law on Personal Data Protection (2018) is a compliance framework from Serbia with 11 domains and 26 controls. Serbia's Law on Personal Data Protection (Official Gazette No. 87/2018), effective August 2019, is closely aligned with the EU GDPR as part of Serbia's EU accession process. The Commissioner for Information of Public Importance and Personal Data Protection oversees enforcement. The law covers processing principles, lawful bases (including consent and legitimate interest), data subject rights (access, rectification, erasure, portability), DPO requirements, breach notification, and cross-border transfers. Applies to all personal data processing in Serbia. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Serbia Law on Personal Data Protection (2018) actually require?
Serbia Law on Personal Data Protection (2018) has 26 controls organised across 11 domains. The largest domains are Serbia LPDP: Accountability and Records (5 controls), Serbia LPDP: Scope and Lawful Basis (4 controls), Serbia LPDP: Transparency and Data Subject Rights (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Serbia Law on Personal Data Protection (2018) do I already cover?
Serbia Law on Personal Data Protection (2018) does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement Serbia Law on Personal Data Protection (2018)?
Start your Serbia Law on Personal Data Protection (2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Serbia Law on Personal Data Protection (2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 26 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required