#
Core statute and regulator are well-documented, in force, and actively enforced (including against multinational platforms); only the registration/filing sub-module lacks direct confirmatory evidence.
Sub-modules (5)
Regulator And AuthorityGreen
The Commissioner combines DP and FOI mandates in one office, elected by the National Assembly.
Claims (1):
- The Commissioner for Information of Public Importance and Personal Data Protection is Serbia's primary data protection authority, combining data-protection and freedom-of-information supervisory mandates in one office.
Act And InstrumentsGreen
LPDP (Official Gazette RS No. 87/2018) is the core GDPR-aligned omnibus instrument.
Claims (1):
- The Law on Personal Data Protection (Official Gazette of RS No. 87/2018) is Serbia's omnibus data-protection statute, adopted as part of Serbia's EU-candidacy harmonization with the GDPR.
Material ScopeAmber
General LPDP material scope mirrors GDPR; not independently re-verified article-by-article in this run.
Absence provenance: unavailable. Searched: Serbia LPDP material scope Article 3 GDPR equivalent.
Territorial ScopeGreen
Extraterritorial application requiring local representative appointment (LPDP Art. 44), tested via 2020 Google/Facebook investigation.
Claims (1):
- The LPDP applies to foreign controllers/processors that are not established in Serbia, mandating appointment of a local representative under Article 44, similar to GDPR Article 27 requirements for non-EU controllers.
Regulator Registration And FilingAmber
No evidence found of a general notification/registration regime for controllers.
Absence provenance: unavailable. Searched: Serbia LPDP controller registration filing requirement Poverenik.
Claims (1):
- Serbia's LPDP does not appear to impose a general controller registration/filing requirement with the Commissioner, consistent with the GDPR's abolition of general notification obligations.
Regulator & Framework
Serbia's data protection regime is overseen by the Commissioner for Information of Public Importance and Personal Data Protection, an independent body that combines data protection supervision with a freedom-of-information mandate in a single institution. This dual-mandate structure is a standing feature of Serbia's regulatory architecture and distinguishes the Commissioner from single-purpose data protection authorities found in many other jurisdictions.
The most significant development this cycle is the Commissioner's confirmation that work on a new Law on Personal Data Protection has progressed significantly. The stated aim of the anticipated law is to bring clearer, more GDPR-aligned rules, with particular attention to artificial intelligence and advanced digital systems. The Commissioner has publicly indicated that the reform is intended to better address AI and advanced digital systems, though it should be understood that no enacted AI-specific data protection provision currently exists in Serbia — the current framework remains the 2018 Law on Personal Data Protection, and the reform is a drafting-stage signal rather than a change in force. The specific contents of the draft, including its treatment of AI systems, have not been made public, and this brief does not speculate on provisions not yet disclosed.
This is a forward-looking, preparatory development: it signals regulatory direction rather than an immediate change to controller or processor obligations. Organisations operating in Serbia should treat the current 2018 framework as the operative law while the reform remains undisclosed and unenacted.
Outlook
The key event to watch is publication of the draft new Law on Personal Data Protection. Until its text becomes available, the scope of any AI-specific provisions, and the extent of GDPR alignment being pursued, cannot be assessed. This module will be revisited once draft or enacted text is located.
1 further periodic run re-emitted the standing brief unchanged and is not shown.
Sources and claims (4)
- ConfirmedPoverenik.rs — The Commissioner for Information of Public Importance and Personal Data Protection is Serbia's primary data protection authority, combining data-protection and freedom-of-information supervisory mandates in one office.observed
- ConfirmedPoverenik.rs — The Law on Personal Data Protection (Official Gazette of RS No. 87/2018) is Serbia's omnibus data-protection statute, adopted as part of Serbia's EU-candidacy harmonization with the GDPR.observed
- ProbableDataGuidance — The LPDP applies to foreign controllers/processors that are not established in Serbia, mandating appointment of a local representative under Article 44, similar to GDPR Article 27 requirements for non-EU controllers.observed
- UncertainPoverenik.rs — Serbia's LPDP does not appear to impose a general controller registration/filing requirement with the Commissioner, consistent with the GDPR's abolition of general notification obligations.observed