Understanding Serbia’s Personal Data Protection Rules
Personal information now moves easily between Serbia, Australia and the wider European market. A Serbian community group may use a cloud platform hosted overseas, an Australian partner may receive participant records, and a website may collect analytics from visitors in Belgrade, Sydney or Melbourne. Understanding the applicable rules helps organisations reduce risk while preserving public trust.
Serbia’s main framework is the Law on Personal Data Protection, adopted in 2018 and closely modelled on the European Union’s General Data Protection Regulation (GDPR). It covers how public bodies, companies, nonprofits and other organisations collect, use, store and disclose information about identifiable people. The comparison below places the Serbian framework beside familiar Australian concepts.
| Issue | Serbia | Australia |
|---|---|---|
| Main regulator | Commissioner for Information of Public Importance and Personal Data Protection | Office of the Australian Information Commissioner (OAIC) |
| Core framework | Law on Personal Data Protection, broadly aligned with GDPR | Privacy Act 1988 and the Australian Privacy Principles |
| Individual rights | Access, correction, deletion, restriction, objection and data portability in relevant cases | Access and correction, with additional protections under the APPs |
| Breach response | Risk-based notification duties, including notification to the Commissioner where required | Notifiable Data Breaches scheme for eligible breaches likely to cause serious harm |
| Small organisations | No blanket exemption comparable to Australia’s small-business rule | Many businesses under the annual turnover threshold may be exempt, subject to exceptions |
What the Serbian law protects
Personal data means information relating to an identified or identifiable natural person. Names, identification numbers, contact details, employment records and location information can qualify. So can online identifiers, device data, photographs, voice recordings and combinations of details that make an individual recognisable.
The law treats some information as particularly sensitive. Health records, biometric and genetic data, political opinions, religious or philosophical beliefs, trade union membership, sexual orientation and information about criminal convictions require heightened care. A spreadsheet containing workshop attendees’ names may be ordinary personal data, while a file describing medical needs or political activity may involve special categories.
Processing is defined broadly. It includes collecting, recording, organising, storing, consulting, changing, sharing, restricting and deleting data. This means a Serbian nonprofit can be subject to the law even when it does not sell information. A mailing list, volunteer database, casework file or online registration form may all involve regulated processing.
Lawful grounds and transparent collection
An organisation must identify a lawful basis before processing personal data. Common grounds include consent, performance of a contract, compliance with a legal obligation, protection of vital interests, a task carried out in the public interest, and a legitimate interest that is not overridden by the person’s rights.
Consent must be informed, specific, freely given and capable of withdrawal. Ticking a preselected box or bundling marketing consent into an unrelated service may not meet that standard. A community organisation should explain what it will collect, why it needs the information, how long it will retain it and who may receive it.
Transparency is especially important when services are delivered to people with limited legal knowledge. Clear Serbian-language privacy notices should identify the controller, contact details, purposes, legal grounds, retention periods, individual rights and international transfers. If an Australian partner is involved, plain English can be supplied alongside the Serbian version so participants in Brisbane or Perth can understand the arrangement.
A useful practical example is an online gaming or entertainment service: online gaming example illustrates why websites should explain cookies, account information, payment details and responsible use of user data rather than hiding everything in a long notice.
Individual rights and organisational duties
People can generally ask whether an organisation processes their data and request access to the relevant information. They may seek correction of inaccurate records, deletion where the legal conditions are met, restriction of processing, and objection to certain uses. In appropriate circumstances, they can request data portability in a structured, commonly used format.
These rights are not unlimited. Retention may be required by law, and deletion may be refused where information is needed for legal claims, freedom of expression, public interest tasks or other recognised reasons. An organisation should assess each request rather than automatically accepting or rejecting it.
Controllers must apply data minimisation, accuracy, purpose limitation, storage limitation, confidentiality and accountability. In practice, that means collecting only what a legal clinic needs, limiting staff access, using strong passwords and multi-factor authentication, keeping devices updated, and deleting records according to a documented schedule.
For a nonprofit, Nomcentar’s mission reflects the wider public value of making legal knowledge accessible. That mission still requires careful handling of intake forms and case files: compassionate service and privacy compliance should operate together, especially where people disclose housing, family, immigration or financial difficulties.
Breaches, impact assessments and oversight
A personal data breach may involve loss, unauthorised access, accidental disclosure, ransomware or sending information to the wrong recipient. Organisations should have an incident process that records what happened, which data was affected, how many people may be at risk, and what steps were taken to contain the problem.
Under the Serbian framework, a controller generally must notify the Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of a qualifying breach, unless the incident is unlikely to create a risk to individuals. Affected people must also be informed when the risk is high, subject to statutory exceptions. The 72-hour period is a useful operational benchmark, not a reason to delay immediate containment.
Serbian controllers and processors may need a data protection officer, particularly where their core activities involve regular and systematic monitoring or extensive processing of sensitive information. A data protection impact assessment may be required before high-risk processing begins, such as large-scale biometric monitoring, extensive profiling or the use of new technology involving vulnerable groups.
The Commissioner can investigate, order compliance, restrict processing and impose administrative fines. Penalties may be significant, while reputational damage can be even more disruptive for a small association. Internal training, access logs, processor contracts and written policies provide evidence that the organisation takes accountability seriously.
Cross-border work with Australia
Transfers from Serbia to an organisation in Australia require careful analysis. Australia is not treated as an automatic substitute for a European Union adequacy decision, so a Serbian controller should examine the transfer mechanism, the recipient’s safeguards, the categories of data and the possibility of access by public authorities. Contracts, approved safeguards and additional technical measures may be necessary.
Australian partners must also consider their own obligations. The Privacy Act and Australian Privacy Principles govern many organisations, while the OAIC oversees privacy regulation. Australia’s Notifiable Data Breaches scheme may apply to an eligible breach likely to cause serious harm. The small-business exemption can be relevant, although it has important exceptions involving health information, employee records and certain other activities.
A Serbian organisation sending a participant list to a Sydney consultancy should document who controls the data, who processes it, the permitted purposes, security requirements, retention period and incident notification procedure. It should also check whether the Australian recipient has a privacy policy and safeguards that match the sensitivity of the information. Contract language should be supported by real controls, not treated as a substitute for them.
Australian audiences are accustomed to asking about privacy through familiar settings such as Medicare, My Health Record, university portals and online banking. Community groups in Adelaide or the Western Sydney suburbs may therefore expect short, practical explanations: what is collected, whether it leaves Serbia, how long it stays on a server, and whom to contact when something is wrong. The Nomcentar team can be a useful reference point for understanding how legal education and civic support can be organised around those questions.
Building a workable compliance system
Compliance begins with a data map. List every form, register, email account, cloud service, case-management tool and website feature that handles personal information. Record the source of the data, the purpose, the lawful basis, the retention period, the people with access and any external recipients.
Next, separate routine information from high-risk records. A public event mailing list may need basic safeguards, while legal advice files, children’s information and health-related documents require stricter access controls. Use role-based permissions, encryption where appropriate, secure backups and a reliable process for removing former volunteers and staff.
Privacy notices should be easy to find and written for the people who actually use the service. Staff should know how to verify an access request, report a suspected breach and escalate uncertainty. Processors should be selected carefully and bound by written terms covering confidentiality, security, subcontractors, deletion and cooperation with rights requests.
For organisations working across Serbia and Australia, the goal is a coordinated privacy programme rather than two disconnected checklists. Clear responsibilities, documented decisions and respectful communication allow legal clinics, NGOs, researchers and community partners to support people while meeting the standards expected in both jurisdictions.