Serbia Law on Personal Data Protection (2018)
Serbia's Law on Personal Data Protection (Official Gazette No. 87/2018), effective August 2019, is closely aligned with the EU GDPR as part of Serbia's EU accession process. The Commissioner for Information of Public Importance and Personal Data Protection oversees enforcement. The law covers processing principles, lawful bases (including consent and legitimate interest), data subject rights (access, rectification, erasure, portability), DPO requirements, breach notification, and cross-border transfers. Applies to all personal data processing in Serbia.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
I — Basic Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
II — Principles
| Code | Title |
|---|---|
| Art. 12 | Data Ownership |
| Art. 13 | Data Security and Privacy |
| Art. 17 | Governance Structure |
| Art. 20 | Executive Accountability |
| Art. 5 | Legal Recognition of Data Messages |
III — Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 21 | Administrative Sanctions |
| Art. 26 | Outsourcing of Personal Information Processing |
| Art. 29 | Safety Measures |
| Art. 30 | Privacy Policy |
| Art. 36 | Right to Correction or Deletion |
| Art. 38 | Processing in Employment Context |
IV — Controller and Processor
| Code | Title |
|---|---|
| Art. 41 | Exemptions from Certain GDPR Provisions |
| Art. 45 | Data Protection Officer |
| Art. 49 | Collective Dispute Resolution |
| Art. 51 | Entry into Force |
| Art. 56 | Data Breach Notification |
V — Transfer to Other Countries and International Organisations
| Code | Title |
|---|---|
| Art. 63 | Interim Measures |
| Art. 64 | Transfer Based on Adequacy Decision |
| Art. 65 | Transfer Subject to Appropriate Safeguards |
VI — The Commissioner
| Code | Title |
|---|---|
| Art. 73 | Administrative Fines |
| Art. 77 | Powers of the Commissioner |
| Art. 79 | Inspections |
VII — Remedies, Liability and Penalties
| Code | Title |
|---|---|
| Art. 82 | Inspection Procedure |
| Art. 84 | Entry into Force |
| Art. 87 | Administrative Fines |
Maps to 615 other frameworks
Frequently Asked Questions
What is Serbia Law on Personal Data Protection (2018)?
Serbia Law on Personal Data Protection (2018) is a compliance framework from Serbia with 7 domains and 29 controls. Serbia's Law on Personal Data Protection (Official Gazette No. 87/2018), effective August 2019, is closely aligned with the EU GDPR as part of Serbia's EU accession process. The Commissioner for Information of Public Importance and Personal Data Protection oversees enforcement. The law covers processing principles, lawful bases (including consent and legitimate interest), data subject rights (access, rectification, erasure, portability), DPO requirements, breach notification, and cross-border transfers. Applies to all personal data processing in Serbia. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Serbia Law on Personal Data Protection (2018) have?
Serbia Law on Personal Data Protection (2018) has 29 controls organised across 7 domains. The largest domains are III — Rights of Data Subjects (6 controls), II — Principles (5 controls), IV — Controller and Processor (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Serbia Law on Personal Data Protection (2018) map to?
Serbia Law on Personal Data Protection (2018) maps to 615 other compliance frameworks. The top mapping partners are Chile Personal Data Protection Law (Law No. 21.719) (45% coverage), NIST AI Risk Management Framework (AI RMF 1.0) (45% coverage), NIST AI 600-1 Generative AI Profile (45% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Serbia Law on Personal Data Protection (2018) compliance?
Start your Serbia Law on Personal Data Protection (2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Serbia Law on Personal Data Protection (2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 29 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required