🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
RS v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing12 sources retrieved model claude-sonnet-5 · 2026-08-07

Serbia

RS schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 31 claims · 19 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
31Claimsbaseline..claims[]
8Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Serbia's data protection authority, the Commissioner for Information of Public Importance and Personal Data Protection, has confirmed that work on a new Law on Personal Data Protection has progressed significantly. The Commissioner, who combines data protection and freedom-of-information mandates in a single independent body, is understood to be preparing a more GDPR-aligned framework intended to bring clearer rules for artificial intelligence and advanced digital systems, although the details of the draft are not yet public. No enacted AI-specific data protection provision currently exists in Serbia; the anticipated reform is at a preparatory, pre-publication stage.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core statute and regulator are well-documented, in force, and actively enforced (including against multinational platforms); only the registration/filing sub-module lacks direct confirmatory evidence.

Primary frameworkLaw on Personal Data Protection (Official Gazette of RS No. 87/2018)
Traffic-light rationale — GreenCore statute and regulator are well-documented, in force, and actively enforced (including against multinational platforms); only the registration/filing sub-module lacks direct confirmatory evidence.

Sub-modules (5)

Regulator And AuthorityGreen

The Commissioner combines DP and FOI mandates in one office, elected by the National Assembly.

Claims (1):

  • The Commissioner for Information of Public Importance and Personal Data Protection is Serbia's primary data protection authority, combining data-protection and freedom-of-information supervisory mandates in one office.

Act And InstrumentsGreen

LPDP (Official Gazette RS No. 87/2018) is the core GDPR-aligned omnibus instrument.

Claims (1):

  • The Law on Personal Data Protection (Official Gazette of RS No. 87/2018) is Serbia's omnibus data-protection statute, adopted as part of Serbia's EU-candidacy harmonization with the GDPR.

Material ScopeAmber

General LPDP material scope mirrors GDPR; not independently re-verified article-by-article in this run.

Absence provenance: unavailable. Searched: Serbia LPDP material scope Article 3 GDPR equivalent.

Territorial ScopeGreen

Extraterritorial application requiring local representative appointment (LPDP Art. 44), tested via 2020 Google/Facebook investigation.

Claims (1):

  • The LPDP applies to foreign controllers/processors that are not established in Serbia, mandating appointment of a local representative under Article 44, similar to GDPR Article 27 requirements for non-EU controllers.

Regulator Registration And FilingAmber

No evidence found of a general notification/registration regime for controllers.

Absence provenance: unavailable. Searched: Serbia LPDP controller registration filing requirement Poverenik.

Claims (1):

  • Serbia's LPDP does not appear to impose a general controller registration/filing requirement with the Commissioner, consistent with the GDPR's abolition of general notification obligations.
Category narrative126 words

Serbia's data-protection regime is anchored in the Law on Personal Data Protection ('Official Gazette of RS' No. 87/2018, 'LPDP'), adopted as part of Serbia's EU-candidacy harmonization obligations and structurally mirroring the GDPR. The LPDP is supervised by the Commissioner for Information of Public Importance and Personal Data Protection ('Poverenik'), a single body combining data-protection and freedom-of-information oversight functions, structurally analogous to Hungary's NAIH. The LPDP applies extraterritorially to foreign controllers/processors targeting or monitoring Serbian data subjects, who must appoint a local representative under LPDP Article 44 (mirroring GDPR Article 27); enforcement of this requirement has already been tested against major global platforms. No specific general controller registration/filing regime with the Commissioner was identified in available sources, consistent with the GDPR's own move away from notification-based regimes.

Periodic update · new data 2026-09-28

Regulator & Framework

Serbia's data protection regime is overseen by the Commissioner for Information of Public Importance and Personal Data Protection, an independent body that combines data protection supervision with a freedom-of-information mandate in a single institution. This dual-mandate structure is a standing feature of Serbia's regulatory architecture and distinguishes the Commissioner from single-purpose data protection authorities found in many other jurisdictions.

The most significant development this cycle is the Commissioner's confirmation that work on a new Law on Personal Data Protection has progressed significantly. The stated aim of the anticipated law is to bring clearer, more GDPR-aligned rules, with particular attention to artificial intelligence and advanced digital systems. The Commissioner has publicly indicated that the reform is intended to better address AI and advanced digital systems, though it should be understood that no enacted AI-specific data protection provision currently exists in Serbia — the current framework remains the 2018 Law on Personal Data Protection, and the reform is a drafting-stage signal rather than a change in force. The specific contents of the draft, including its treatment of AI systems, have not been made public, and this brief does not speculate on provisions not yet disclosed.

This is a forward-looking, preparatory development: it signals regulatory direction rather than an immediate change to controller or processor obligations. Organisations operating in Serbia should treat the current 2018 framework as the operative law while the reform remains undisclosed and unenacted.

Outlook

The key event to watch is publication of the draft new Law on Personal Data Protection. Until its text becomes available, the scope of any AI-specific provisions, and the extent of GDPR alignment being pursued, cannot be assessed. This module will be revisited once draft or enacted text is located.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ConfirmedPoverenik.rs — The Commissioner for Information of Public Importance and Personal Data Protection is Serbia's primary data protection authority, combining data-protection and freedom-of-information supervisory mandates in one office.observed
  2. ConfirmedPoverenik.rs — The Law on Personal Data Protection (Official Gazette of RS No. 87/2018) is Serbia's omnibus data-protection statute, adopted as part of Serbia's EU-candidacy harmonization with the GDPR.observed
  3. ProbableDataGuidance — The LPDP applies to foreign controllers/processors that are not established in Serbia, mandating appointment of a local representative under Article 44, similar to GDPR Article 27 requirements for non-EU controllers.observed
  4. UncertainPoverenik.rs — Serbia's LPDP does not appear to impose a general controller registration/filing requirement with the Commissioner, consistent with the GDPR's abolition of general notification obligations.observed

#

Lawful bases and special-category rules are evidenced as GDPR-mirroring with one concrete regulator opinion (biometrics); consent-threshold detail and pseudonymisation/anonymisation provisions lack direct primary-source confirmation in this run.

Primary frameworkLaw on Personal Data Protection (Official Gazette of RS No. 87/2018)
Traffic-light rationale — AmberLawful bases and special-category rules are evidenced as GDPR-mirroring with one concrete regulator opinion (biometrics); consent-threshold detail and pseudonymisation/anonymisation provisions lack direct primary-source confirmation in this run.

Sub-modules (4)

Lawful BasesAmber

LPDP legal-basis provisions mirror GDPR Article 6 normative structure.

Claims (1):

  • The LPDP's provisions on legal basis for processing mirror the normative provisions of the GDPR, including the enumerated lawful bases for processing personal data.

Special CategoriesGreen

Article 8(7) proportionality test applied restrictively to biometric data.

Claims (1):

  • Under LPDP Article 8(7)'s proportionality requirement, processing of biometric data (e.g., fingerprint scanning) is impermissible where the purpose can be achieved through less intrusive means, even where the data subject has consented.

Pseudonymisation And AnonymisationRed

No Serbia-specific pseudonymisation/anonymisation safe-harbour text identified.

Absence provenance: unavailable. Searched: Serbia LPDP pseudonymisation anonymisation definition safe harbour.

Claims (1):

  • No Serbia-specific pseudonymisation or anonymisation safe-harbour definitions were located in available sources for this run.
Category narrative69 words

The LPDP's provisions on legal basis for processing, consent, and special-category data mirror the normative provisions of the GDPR, though the absence of GDPR-style recitals makes some provisions harder to interpret without recourse to EU materials. The Commissioner has applied a strict proportionality/data-minimization test to biometric data processing, holding that even employee consent does not legitimize disproportionate biometric collection. No Serbia-specific pseudonymisation/anonymisation safe-harbour provisions were identified in available sources.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ProbableIAPP — The LPDP's provisions on legal basis for processing mirror the normative provisions of the GDPR, including the enumerated lawful bases for processing personal data.observed
  2. ConfirmedPoverenik.rs — Under LPDP Article 8(7)'s proportionality requirement, processing of biometric data (e.g., fingerprint scanning) is impermissible where the purpose can be achieved through less intrusive means, even where the data subject has consented.observed
  3. ProbableIAPP — LPDP consent standards are modeled on the GDPR's requirements, though the absence of GDPR-style recitals makes some consent provisions more difficult to interpret without recourse to GDPR recitals and EDPB opinions.observed
  4. UncertainIAPP — No Serbia-specific pseudonymisation or anonymisation safe-harbour definitions were located in available sources for this run.observed

#

Rights framework is confirmed as GDPR-mirroring at a general level via secondary commentary, but granular deadline/response-window detail and low utilization data indicate weak practical traction.

Primary frameworkLaw on Personal Data Protection (Official Gazette of RS No. 87/2018)
Traffic-light rationale — AmberRights framework is confirmed as GDPR-mirroring at a general level via secondary commentary, but granular deadline/response-window detail and low utilization data indicate weak practical traction.

Sub-modules (5)

Access RightAmber

Access right mirrors GDPR Art. 15 per secondary commentary.

Claims (1):

  • LPDP data-subject-rights provisions mirror GDPR normative provisions on data subject rights, though implementation and enforcement of these rights remains limited, with only 139 complaints lodged with the DPA in 2020.

Rectification And ErasureAmber

Rectification/erasure rights mirror GDPR structure.

Claims (1):

  • LPDP data-subject-rights provisions mirror GDPR normative provisions on data subject rights, though implementation and enforcement of these rights remains limited, with only 139 complaints lodged with the DPA in 2020.

Restriction And ObjectionAmber

Restriction/objection rights mirror GDPR structure.

Claims (1):

  • LPDP data-subject-rights provisions mirror GDPR normative provisions on data subject rights, though implementation and enforcement of these rights remains limited, with only 139 complaints lodged with the DPA in 2020.

Data PortabilityRed

Portability right presumed present via GDPR mirroring; not independently verified.

Absence provenance: unavailable. Searched: Serbia LPDP data portability right article.

Deadlines And Response WindowsRed

No specific statutory deadline figures (e.g., 30-day response window) were confirmed for Serbia in this run.

Absence provenance: unavailable. Searched: Serbia LPDP data subject request response deadline days.

Category narrative52 words

The LPDP's data-subject-rights provisions (access, rectification, erasure, restriction, objection, portability) are described by secondary legal commentary as mirroring GDPR normative provisions, but practical exercise of these rights has historically been limited — Serbia's DPA reported only 139 complaints lodged in 2020. No Serbia-specific statutory response-deadline figures were independently confirmed in this run.

Sources and claims (1)
  1. ProbableIAPP — LPDP data-subject-rights provisions mirror GDPR normative provisions on data subject rights, though implementation and enforcement of these rights remains limited, with only 139 complaints lodged with the DPA in 2020.observed

#

DPIA tooling is concretely evidenced; DPO/security/breach provisions rest on general secondary-source mirroring language; ROPA, joint-controller and retention specifics are unconfirmed gaps.

Primary frameworkLaw on Personal Data Protection (Official Gazette of RS No. 87/2018)
Traffic-light rationale — AmberDPIA tooling is concretely evidenced; DPO/security/breach provisions rest on general secondary-source mirroring language; ROPA, joint-controller and retention specifics are unconfirmed gaps.

Sub-modules (7)

Accountability And DpiaGreen

Commissioner-issued DPIA blacklist under LPDP Arts. 54-55.

Claims (1):

  • The Commissioner has published a list of processing activities requiring a Data Protection Impact Assessment (the 'DPIA Blacklist') pursuant to LPDP Articles 54-55.

Dpo RequirementsAmber

DPO appointment treated as formal but often superficial compliance step.

Claims (1):

  • Formal DPO appointment is among the compliance steps taken under the LPDP, though appointment alone does not equate to substantive compliance with the law's underlying principles.

Ropa RequirementsRed

No Serbia-specific ROPA format/content detail confirmed.

Claims (1):

  • No Serbia-specific detail on ROPA content/format, joint-controller liability allocation, or retention/disposal limits was located in available sources for this run.

Joint Controller ArrangementsRed

No Serbia-specific joint-controller liability allocation detail confirmed.

Claims (1):

  • No Serbia-specific detail on ROPA content/format, joint-controller liability allocation, or retention/disposal limits was located in available sources for this run.

Security MeasuresAmber

Security-of-processing provisions described as GDPR-mirroring.

Claims (1):

  • LPDP provisions on security of processing and personal-data-breach notification mirror the corresponding GDPR provisions.

Breach NotificationAmber

Breach notification provisions described as GDPR-mirroring; specific timelines/thresholds unconfirmed.

Claims (1):

  • LPDP provisions on security of processing and personal-data-breach notification mirror the corresponding GDPR provisions.

Retention And DisposalRed

No Serbia-specific retention/disposal limits confirmed.

Claims (1):

  • No Serbia-specific detail on ROPA content/format, joint-controller liability allocation, or retention/disposal limits was located in available sources for this run.
Category narrative80 words

The Commissioner has issued a Data Protection Impact Assessment 'blacklist' of processing activities requiring a DPIA under LPDP Articles 54-55, evidencing active accountability tooling. DPO appointment is treated by commentators as a formal compliance step that many public authorities complete without achieving substantive compliance with underlying LPDP principles (lawfulness, fairness, transparency, minimization, privacy-by-design). Security-of-processing and breach-notification provisions are described as mirroring GDPR equivalents. No Serbia-specific detail on ROPA formats, joint-controller allocation-of-liability mechanics, or retention/disposal limits was confirmed in this run.

Sources and claims (4)
  1. ConfirmedDataGuidance — The Commissioner has published a list of processing activities requiring a Data Protection Impact Assessment (the 'DPIA Blacklist') pursuant to LPDP Articles 54-55.observed
  2. ProbableIAPP — Formal DPO appointment is among the compliance steps taken under the LPDP, though appointment alone does not equate to substantive compliance with the law's underlying principles.observed
  3. ProbableIAPP — LPDP provisions on security of processing and personal-data-breach notification mirror the corresponding GDPR provisions.observed
  4. UncertainIAPP — No Serbia-specific detail on ROPA content/format, joint-controller liability allocation, or retention/disposal limits was located in available sources for this run.observed

#

Transfer-mechanism mirroring is evidenced at a general level; adequacy status (received) is a confirmed gap; SCC evidence is narrow/EU-instrument-specific; localisation and TIA sub-modules are unconfirmed.

Primary frameworkLaw on Personal Data Protection (Official Gazette of RS No. 87/2018)
Traffic-light rationale — AmberTransfer-mechanism mirroring is evidenced at a general level; adequacy status (received) is a confirmed gap; SCC evidence is narrow/EU-instrument-specific; localisation and TIA sub-modules are unconfirmed.

Sub-modules (6)

Transfer MechanismsAmber

LPDP transfer regime mirrors GDPR adequacy/safeguards/derogations structure.

Claims (1):

  • LPDP provisions on international transfer of personal data mirror the corresponding GDPR transfer regime, requiring adequacy, appropriate safeguards, or derogations for onward transfers outside Serbia.

Adequacy ReceivedAmber

Serbia has not received an EU Commission adequacy decision; it holds EU-candidate status instead.

Claims (1):

  • Serbia does not hold an EU Commission adequacy decision under the GDPR, reflecting its status as an EU-candidate country undergoing accession-related legal harmonization rather than a recognized third country.

Adequacy GrantedRed

No evidence Serbia has granted formal adequacy decisions to other jurisdictions under LPDP.

Absence provenance: unavailable. Searched: Serbia LPDP adequacy decisions granted third countries.

Sccs And BcrsAmber

Colombia recognizes Serbia on its adequacy list; EU authorized narrow SCC use for Erasmus+ Serbian counterpart.

Claims (2):

  • Colombia's national data-protection adequacy list has historically recognized Serbia, alongside Mexico, South Korea, Costa Rica, Peru and the US, as providing an adequate level of data protection for cross-border transfer purposes.
  • The European Data Protection Supervisor authorized use of standard contractual clauses between the European Commission and the Serbian National Agency (Fondacija Tempus) for Erasmus+ and European Solidarity Corps data transfers under EDPS Decision 67/2025.

Transfer Impact AssessmentRed

No Serbia-specific TIA requirement confirmed.

Claims (1):

  • No Serbia-specific data-localisation mandate or formal transfer-impact-assessment requirement was identified in available sources.

Data LocalisationRed

No data-localisation mandate identified for Serbia's general LPDP regime.

Claims (1):

  • No Serbia-specific data-localisation mandate or formal transfer-impact-assessment requirement was identified in available sources.
Category narrative117 words

LPDP international-transfer provisions are described as mirroring the GDPR transfer regime (adequacy, safeguards, derogations). Serbia does not hold an EU Commission adequacy decision, reflecting its status as an EU-candidate country undergoing accession-related harmonization rather than a recognized third country; instead, Serbia's own alignment work is inbound (adopting GDPR-equivalent domestic law) rather than outbound recognition-seeking. Notably, Colombia's national adequacy list has historically named Serbia among countries recognized as providing adequate protection for transfer purposes. The EU has authorized standard contractual clauses for specific EU-institution data flows involving Serbian counterparts (e.g., Erasmus+ programme administration), though this is a narrow EU-side instrument rather than a general Serbian SCC regime. No data-localisation mandate or formal transfer-impact-assessment requirement was identified for Serbia.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ProbableIAPP — LPDP provisions on international transfer of personal data mirror the corresponding GDPR transfer regime, requiring adequacy, appropriate safeguards, or derogations for onward transfers outside Serbia.observed
  2. UncertainIAPP — Serbia does not hold an EU Commission adequacy decision under the GDPR, reflecting its status as an EU-candidate country undergoing accession-related legal harmonization rather than a recognized third country.observed
  3. ProbableIAPP — Colombia's national data-protection adequacy list has historically recognized Serbia, alongside Mexico, South Korea, Costa Rica, Peru and the US, as providing an adequate level of data protection for cross-border transfer purposes.observed
  4. ConfirmedEDPS — The European Data Protection Supervisor authorized use of standard contractual clauses between the European Commission and the Serbian National Agency (Fondacija Tempus) for Erasmus+ and European Solidarity Corps data transfers under EDPS Decision 67/2025.observed
  5. UncertainIAPP — No Serbia-specific data-localisation mandate or formal transfer-impact-assessment requirement was identified in available sources.observed

#

Only the employment-data sub-module has a concrete regulator opinion; the remaining six sub-modules carry no confirmed sector-specific findings, consistent with commentary describing broad sectoral non-harmonization.

Primary frameworkLaw on Personal Data Protection (Official Gazette of RS No. 87/2018)
Traffic-light rationale — RedOnly the employment-data sub-module has a concrete regulator opinion; the remaining six sub-modules carry no confirmed sector-specific findings, consistent with commentary describing broad sectoral non-harmonization.

Sub-modules (7)

Financial Sector OverlayRed

No confirmed financial-sector DP overlay findings.

Absence provenance: unavailable. Searched: Serbia banking secrecy data protection overlay NBS personal data.

Health Sector OverlayRed

No confirmed health-sector DP overlay findings.

Absence provenance: unavailable. Searched: Serbia health data protection law overlay LPDP.

Telecoms And EprivacyRed

No dedicated ePrivacy-equivalent instrument identified for Serbia.

Absence provenance: unavailable. Searched: Serbia ePrivacy law cookies electronic communications.

Employment DataAmber

Commissioner opinion restricting employer biometric processing despite consent.

Claims (1):

  • The Commissioner has opined that employers may not process employees' biometric data (e.g., fingerprint-based time-and-attendance tracking) on the basis of employee consent alone, given the LPDP's proportionality/data-minimization requirement, notwithstanding employers' separate obligations under Serbia's Labour Law to maintain time-and-attendance records.

Credit And ScoringRed

No confirmed credit-scoring DP overlay findings.

Absence provenance: unavailable. Searched: Serbia credit scoring personal data regulation.

EducationRed

No confirmed education-sector DP overlay findings beyond general Commissioner training activities.

Absence provenance: unavailable. Searched: Serbia education sector personal data protection rules.

InsuranceRed

No confirmed insurance-sector DP overlay findings.

Absence provenance: unavailable. Searched: Serbia insurance sector personal data regulation.

Category narrative84 words

Sector-specific overlays remain thin: the Commissioner has opined that employers may not rely on employee consent alone to justify disproportionate biometric processing (e.g., fingerprint-based time-and-attendance tracking) despite separate Labour Law record-keeping obligations. More broadly, secondary commentary indicates that other Serbian sectoral laws touching personal data remained unharmonized with the LPDP beyond the Article 100 end-2020 alignment deadline, leaving fragmentation across the 'dozens of laws' that regulate personal data processing. No confirmatory findings were located for financial-sector, health-sector, telecoms/eprivacy, credit-scoring, education, or insurance overlays specifically.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ConfirmedPoverenik.rs — The Commissioner has opined that employers may not process employees' biometric data (e.g., fingerprint-based time-and-attendance tracking) on the basis of employee consent alone, given the LPDP's proportionality/data-minimization requirement, notwithstanding employers' separate obligations under Serbia's Labour Law to maintain time-and-attendance records.observed
  2. ProbableIAPP — Other Serbian sectoral laws regulating personal data processing remained unharmonized with the LPDP beyond the Article 100 deadline set for end-2020, leaving a sectoral fragmentation gap across the numerous laws that touch personal data processing.observed

#

Only a historical regulator statement about a persistent direct-marketing regulatory gap was located; the remaining five sub-modules carry no confirmed findings.

Traffic-light rationale — RedOnly a historical regulator statement about a persistent direct-marketing regulatory gap was located; the remaining five sub-modules carry no confirmed findings.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent regime identified.

Absence provenance: unavailable. Searched: Serbia cookie consent law ePrivacy equivalent.

Dark PatternsRed

No dark-pattern prohibition identified.

Absence provenance: unavailable. Searched: Serbia dark patterns data protection prohibition.

Opt Out SignalsRed

No recognized opt-out signal (e.g., GPC) framework identified.

Absence provenance: unavailable. Searched: Serbia Global Privacy Control opt-out signal recognition.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules identified.

Absence provenance: unavailable. Searched: Serbia data clean room regulation.

Cross Context AdvertisingRed

No cross-context-advertising specific rules identified.

Absence provenance: unavailable. Searched: Serbia cross-context advertising data sale share regulation.

Direct MarketingAmber

Commissioner historically flagged direct marketing as inadequately regulated relative to EU standards.

Claims (1):

  • As of the Commissioner's 2016-2017 model-law consultation, direct marketing, biometrics, video surveillance and internet data-security processing were identified as inadequately regulated areas of Serbian law, a gap the Commissioner sought to close via a proposed new Model Law.
Category narrative64 words

As of the Commissioner's 2016-2017 model-law consultation period, direct marketing, biometrics, video surveillance and internet data-security processing were identified by the Commissioner (citing the European Commission's 2016 Serbia Progress Report) as inadequately regulated areas of Serbian law. No dedicated ePrivacy-equivalent cookie/tracker consent regime, dark-pattern prohibition, recognized opt-out signal framework (e.g., GPC), clean-room rules, or cross-context-advertising regime specific to Serbia were identified in available sources.

Sources and claims (1)
  1. UncertainPoverenik.rs — As of the Commissioner's 2016-2017 model-law consultation, direct marketing, biometrics, video surveillance and internet data-security processing were identified as inadequately regulated areas of Serbian law, a gap the Commissioner sought to close via a proposed new Model Law.observed

#

Biometric regime has a concrete regulator opinion; AI/genetic/video-surveillance regulation is confirmed as pending (proposed, not yet in force); profiling/ADM transparency and state-surveillance carve-outs are unconfirmed gaps.

Primary frameworkLaw on Personal Data Protection (Official Gazette of RS No. 87/2018); draft LPDP amendments (biometric/genetic/AI/video surveillance) in preparation since 2025
Traffic-light rationale — AmberBiometric regime has a concrete regulator opinion; AI/genetic/video-surveillance regulation is confirmed as pending (proposed, not yet in force); profiling/ADM transparency and state-surveillance carve-outs are unconfirmed gaps.

Sub-modules (6)

Profiling RestrictionsRed

No Serbia-specific profiling-restriction detail confirmed beyond general GDPR mirroring.

Absence provenance: unavailable. Searched: Serbia LPDP profiling restrictions Article 22 equivalent.

Automated Decision Making TransparencyRed

No Serbia-specific ADM transparency/explanation-right detail confirmed.

Absence provenance: unavailable. Searched: Serbia LPDP automated decision making transparency.

Ai Risk AssessmentsAmber

Draft LPDP amendments addressing AI-based processing are in preparation (2025- ), not yet enacted.

Claims (1):

  • A Special Working Group convened by the Commissioner in April 2025 is drafting amendments to the LPDP to introduce specific legal regulation of genetic and biometric data, audio/video surveillance, and AI-based processing of personal data — areas the current 2018 LPDP does not comprehensively address.

Biometric RegimeGreen

Article 8(7) proportionality restricts biometric processing even with consent.

Claims (1):

  • Under LPDP Article 8(7)'s proportionality requirement, processing of biometric data (e.g., fingerprint scanning) is impermissible where the purpose can be achieved through less intrusive means, even where the data subject has consented.

Genetic DataAmber

Draft LPDP amendments addressing genetic data are in preparation (2025- ), not yet enacted.

Claims (1):

  • A Special Working Group convened by the Commissioner in April 2025 is drafting amendments to the LPDP to introduce specific legal regulation of genetic and biometric data, audio/video surveillance, and AI-based processing of personal data — areas the current 2018 LPDP does not comprehensively address.

State Surveillance CarveoutsRed

No state-surveillance/national-security carve-out detail confirmed.

Absence provenance: unavailable. Searched: Serbia LPDP national security exemption state surveillance carveout.

Category narrative71 words

The current 2018 LPDP does not comprehensively regulate genetic and biometric data, audio/video surveillance, or AI-based processing; a Special Working Group convened by the Commissioner in April 2025 is drafting amendments specifically to address these gaps, alongside profiling and ADM more broadly still relying on general GDPR-mirroring provisions. In the interim, the Commissioner has applied a strict proportionality standard to biometric processing (Article 8(7)). No confirmed findings exist for state-surveillance/national-security carve-outs.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. ProbablePoverenik.rs — A Special Working Group convened by the Commissioner in April 2025 is drafting amendments to the LPDP to introduce specific legal regulation of genetic and biometric data, audio/video surveillance, and AI-based processing of personal data — areas the current 2018 LPDP does not comprehensively address.observed

#

Only a general statutory-mandate reference to minors was confirmed; all five declared sub-modules otherwise lack primary-source-verified detail.

Primary frameworkLaw on Personal Data Protection (Official Gazette of RS No. 87/2018)
Traffic-light rationale — RedOnly a general statutory-mandate reference to minors was confirmed; all five declared sub-modules otherwise lack primary-source-verified detail.

Sub-modules (5)

Age VerificationRed

No confirmed age-verification mechanism specific to Serbia's LPDP.

Claims (1):

  • The LPDP's precise age-of-consent threshold for a minor's independent consent to information-society-service processing was not independently confirmed from primary-source Serbian statutory text in this run.

Minor Profiling BansRed

No confirmed minor-profiling ban findings.

Absence provenance: unavailable. Searched: Serbia LPDP minor profiling ban children advertising.

Education SettingsRed

No confirmed education-setting-specific DP rules beyond general Commissioner training activity.

Absence provenance: unavailable. Searched: Serbia education settings student data protection rules.

Dependent AdultsRed

No confirmed dependent-adult protection findings.

Absence provenance: unavailable. Searched: Serbia LPDP dependent adults elderly incapacitated data protection.

Category narrative61 words

The LPDP assigns the Commissioner a statutory duty to promote public awareness of risks, rules, safeguards and rights in relation to processing, with particular reference to processing of data concerning underage persons. However, the LPDP's precise age-of-consent threshold for information-society services, parental-consent verification mechanics, minor-profiling bans, education-setting-specific rules, and dependent-adult protections were not independently confirmed in available sources within this run.

Sources and claims (2)
  1. ConfirmedPoverenik.rs — The LPDP assigns the Commissioner a statutory duty to promote public awareness of risks, rules, safeguards and rights in relation to processing, particularly regarding processing of data on an underage person.observed
  2. UncertainIAPP — The LPDP's precise age-of-consent threshold for a minor's independent consent to information-society-service processing was not independently confirmed from primary-source Serbian statutory text in this run.observed

#

Enforcement powers, penalty structure, and recent enforcement/case-volume activity are well-evidenced with multiple independent confirmations; only collective-redress/private-right-of-action detail is an unconfirmed gap.

Primary frameworkLaw on Personal Data Protection (Official Gazette of RS No. 87/2018)
Traffic-light rationale — GreenEnforcement powers, penalty structure, and recent enforcement/case-volume activity are well-evidenced with multiple independent confirmations; only collective-redress/private-right-of-action detail is an unconfirmed gap.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

DPA can warn/order correction/directly fine (850 EUR); Court of Offences imposes higher fines (~17,000 EUR max).

Claims (1):

  • Serbia's DPA is authorized to issue warnings, order correction or deletion of unlawfully processed data, order rectification of other irregularities, and directly fine controllers/processors for certain misdemeanors at 850 euros, while the Court of Offences has jurisdiction to impose fines up to approximately 17,000 euros for other LPDP violations, sanctions considerably lower than GDPR's maximum fines.

Enforcement Activity IndexGreen

>1,280 inspections in 2024/2025 reporting cycle; 1,388 cases received June 2026; Google/Facebook investigation 2020.

Claims (3):

  • The Commissioner's Supervision Sector carried out more than 1,280 supervision inspections in the reporting period discussed at the National Assembly's June 2025 review of the Commissioner's 2022-2024 activity reports.
  • In June 2026, the Office of the Commissioner received a total of 1,388 cases, reflecting continuing high case volume before the combined DP/FOI authority.
  • The Commissioner initiated a supervisory procedure against Google and Facebook in 2020 for failing to appoint a local representative in Serbia as required by LPDP Article 44, following complaints from the SHARE Foundation.

Regulator Funding And CapacityAmber

DPA self-reported early capacity/personnel shortfalls relative to LPDP mandate.

Claims (1):

  • In the two years following LPDP implementation, Serbia's DPA reported lacking sufficient organizational capabilities and qualified personnel to meet its expanded GDPR-aligned mandate, having unsuccessfully requested postponement of the law's commencement shortly before it took effect.

Collective Redress And Class ActionsRed

No confirmed collective-redress/class-action mechanism findings.

Absence provenance: unavailable. Searched: Serbia LPDP collective redress class action data subjects.

Private Right Of ActionRed

No confirmed private-right-of-action (direct court access) findings.

Claims (1):

  • No confirmed findings on private-right-of-action (direct court access) or collective-redress/class-action mechanisms available to data subjects under the LPDP were located in available sources.

Recent Developments 180DGreen

Within the 180-day window: June 2026 case-volume statistics and EDPB 121st plenary participation.

Claims (2):

  • In June 2026, the Office of the Commissioner received a total of 1,388 cases, reflecting continuing high case volume before the combined DP/FOI authority.
  • The Commissioner and Deputy Commissioner participated in the 121st plenary meeting of the European Data Protection Board held on 8-9 June 2026 in Brussels, reflecting Serbia's continued informal alignment with EU data-protection cooperation mechanisms notwithstanding its non-EU-member status.
Category narrative135 words

Serbia's DPA can issue warnings, order correction/deletion of unlawfully processed data, and directly fine controllers/processors for certain misdemeanors (850 euros), while the Court of Offences (Misdemeanour Court) handles other LPDP violations with fines reported up to approximately 17,000 euros — substantially below GDPR's maximum penalty tiers. Enforcement activity is measurable: the Commissioner's Supervision Sector conducted over 1,280 inspections in the year reviewed by the National Assembly in June 2025, and the combined DP/FOI office received 1,388 cases in June 2026 alone. The Commissioner initiated a 2020 supervisory procedure against Google and Facebook for failure to appoint local representatives. Ongoing EU cooperation continued via Commissioner/Deputy Commissioner attendance at the EDPB's 121st plenary meeting in June 2026. Capacity constraints were self-reported early in LPDP implementation. No confirmed findings exist on private-right-of-action or collective-redress/class-action mechanisms under the LPDP.

Periodic update · new data 2026-09-28

Enforcement & Redress

The Commissioner for Information of Public Importance and Personal Data Protection holds the power to enforce its orders by threatening a company with a fine of up to ten percent of its annual income in Serbia for non-compliance. This is understood to be a significant enforcement lever on paper, though it is reported that this particular option has not yet been exercised in practice, leaving its real-world deterrent effect untested.

Separately, the current Law on Personal Data Protection sets out a distinct sanctions structure: fines of up to approximately EUR 17,000 for a legal entity and approximately EUR 1,275 for a responsible person within a legal entity, with the Commissioner also able to directly fine controllers or processors approximately EUR 850 in certain situations. These figures sit well below the scale implied by the ten-percent-of-income enforcement threat, and the coexistence of a large discretionary enforcement power alongside comparatively modest fixed statutory fines is a structural feature of the current regime.

The Commissioner's most recent annual publication, covering cases resolved in 2025, is understood to show a shift in enforcement approach: rather than framing decisions around abstract compliance discussion, the Commissioner is moving toward a fact-specific approach that weighs accountability, proportionality and necessity in individual cases. This suggests a maturing enforcement practice, though it is a qualified rather than confirmed characterisation, and it is not yet clear whether it corresponds to a rise in the number or severity of enforcement actions.

Outlook

Whether the Commissioner's fact-specific enforcement approach translates into a higher volume of published decisions, and whether the ten-percent-of-income fine-threat power is ever actually exercised, are the two enforcement-trajectory questions to watch. Both would be significant markers of a genuinely tightening enforcement posture in Serbia, distinct from the separate legislative-reform signal tracked under Regulator & Framework.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ConfirmedIAPP — Serbia's DPA is authorized to issue warnings, order correction or deletion of unlawfully processed data, order rectification of other irregularities, and directly fine controllers/processors for certain misdemeanors at 850 euros, while the Court of Offences has jurisdiction to impose fines up to approximately 17,000 euros for other LPDP violations, sanctions considerably lower than GDPR's maximum fines.observed
  2. ConfirmedPoverenik.rs — The Commissioner's Supervision Sector carried out more than 1,280 supervision inspections in the reporting period discussed at the National Assembly's June 2025 review of the Commissioner's 2022-2024 activity reports.observed
  3. ConfirmedPoverenik.rs — In June 2026, the Office of the Commissioner received a total of 1,388 cases, reflecting continuing high case volume before the combined DP/FOI authority.observed
  4. ConfirmedPoverenik.rs — The Commissioner and Deputy Commissioner participated in the 121st plenary meeting of the European Data Protection Board held on 8-9 June 2026 in Brussels, reflecting Serbia's continued informal alignment with EU data-protection cooperation mechanisms notwithstanding its non-EU-member status.observed
  5. UncertainIAPP — No confirmed findings on private-right-of-action (direct court access) or collective-redress/class-action mechanisms available to data subjects under the LPDP were located in available sources.observed
  6. ProbableIAPP — In the two years following LPDP implementation, Serbia's DPA reported lacking sufficient organizational capabilities and qualified personnel to meet its expanded GDPR-aligned mandate, having unsuccessfully requested postponement of the law's commencement shortly before it took effect.observed
  7. ConfirmedDataGuidance — The Commissioner initiated a supervisory procedure against Google and Facebook in 2020 for failing to appoint a local representative in Serbia as required by LPDP Article 44, following complaints from the SHARE Foundation.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct53.33
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Serbia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 31 claim(s) (31 category placement(s)), 19 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated for JID=RS. Strong T1 coverage (poverenik.rs primary source pages) for regulator_and_framework, controller_processor_duties.accountability_and_dpia, lawful_processing_and_special_data.special_categories, sectoral_watch.employment_data, and enforcement_and_redress (powers, activity index, recent developments). Moderate T2/T3 coverage (IAPP retrospective, DataGuidance notes) for lawful_bases, consent_thresholds, data_subject_rights, DPO, security/breach, and cross_border transfer-mechanism mirroring claims — these rest on secondary-source characterization rather than primary Serbian statutory-article citation, consistent with the seed's flag that T2 is thin for this JID. Weak/absent coverage (T4 or no source, absent_field_provenance emitted) for: pseudonymisation/anonymisation definitions, ROPA/joint-controller/retention specifics, data portability, response-deadline windows, adequacy-granted, data-localisation/TIA, most of sectoral_watch (financial/health/telecoms/credit/education/insurance), most of adtech_and_commercial_privacy (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising), most of algorithmic_biometric_and_surveillance_governance (profiling, ADM transparency, state-surveillance carve-outs), and most of children_and_vulnerable_groups (age-verification threshold, minor profiling bans, education settings, dependent adults).

Unresolved questions (7):

  • What is the LPDP's codified age-of-consent threshold (article number) for a minor's independent consent to information-society-service processing?
  • Does the LPDP impose specific statutory response-deadline windows (e.g., 30/15 days) for data-subject-rights requests, and where are they codified?
  • What are the LPDP's specific ROPA (records of processing) content/format requirements and joint-controller liability-allocation rules?
  • Is there a dedicated Serbian ePrivacy-equivalent instrument governing cookies/electronic communications, or does LPDP alone cover this space?
  • What is the current status (as of August 2026) of the draft LPDP amendments addressing biometric, genetic, video-surveillance and AI-based processing first discussed by the Special Working Group in April 2025 — has a bill been tabled in the National Assembly?
  • Does Serbian law provide any private right of action or collective-redress/class-action mechanism for data-protection violations distinct from Commissioner complaint-handling?
  • Are there confirmed data-localisation mandates or transfer-impact-assessment requirements under the LPDP or sector-specific Serbian law?

Escalate to primary-source review: yes