Your Rights Under Serbia’s Data Protection Rules
Personal data is part of everyday life in Serbia. It appears in identity documents, employment records, medical files, bank accounts, school systems, online forms, loyalty programs, and social media profiles. Whenever an organization collects information that can identify you, data protection rules determine what it may do with that information and what control you retain.
Serbia’s main framework is the Law on Personal Data Protection, which broadly follows the principles of the European Union’s General Data Protection Regulation. The law applies to public authorities, companies, institutions, associations, and other organizations that process personal data in Serbia. It can also apply to certain organizations outside Serbia when they offer services to people in Serbia or monitor their behavior.
Understanding these rights helps citizens recognize excessive requests, challenge inaccurate records, and respond when information is used without a proper legal basis. Legal literacy is particularly important for smaller communities and civil society groups that may lack dedicated privacy officers or legal departments.
What Counts As Personal Data
Personal data means information relating to an identified or identifiable individual. A name, national identification number, address, telephone number, email address, photograph, identification document, and bank account detail are familiar examples. Online identifiers, location data, device information, and account activity may also identify a person when combined with other information.
Some information receives stronger protection because misuse could create a greater risk to an individual. This includes data about health, biometric characteristics used for identification, political opinions, religious or philosophical beliefs, trade union membership, genetic information, and sexual life or orientation. Processing these special categories is generally prohibited unless a specific legal exception applies.
Data protection concerns both digital and paper records. A clinic’s patient file, an employer’s personnel folder, and a municipality’s registry can all involve regulated processing. Even a small association that stores a membership list has responsibilities if those records contain information connected to identifiable people.
Who Is Responsible For Your Information
The controller decides why and how personal data will be processed. This might be a public institution collecting information to provide a service, a company operating a customer account, or an association organizing an event. A processor handles data on the controller’s behalf, such as a payroll provider, cloud storage company, or mailing platform.
Organizations must have a lawful basis for processing. Common bases include consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task in the public interest, and legitimate interests that do not override the individual’s rights. Consent is therefore important, but it is not the only possible justification.
A valid privacy notice should explain who controls the data, why it is collected, which categories are involved, how long it will be stored, who may receive it, whether it will leave Serbia, and how rights can be exercised. A vague statement that data will be used “for business purposes” may fail to provide meaningful information.
When using digital services, people should examine these details before submitting identity documents, payment information, or contact details. Even pages focused on entertainment or account creation, such as guidance about online casino registration, can illustrate why users should know what information is requested and how an online operator handles it.
The Core Rights You Can Exercise
You may ask an organization to confirm whether it processes your personal data and, if so, provide access to that information. Access usually includes the purposes of processing, categories of data, recipients, retention periods, and information about the source of the data. You are generally entitled to receive a copy, although reasonable safeguards may be used to protect other people’s information.
If information is incorrect or incomplete, you can request rectification. You can also request erasure in circumstances such as withdrawal of consent, unlawful processing, or the data no longer being necessary. Erasure is not absolute: an organization may need to retain information to meet a legal duty, establish or defend a legal claim, or protect another important public interest.
You may request restriction of processing while the accuracy of data is disputed, when processing is unlawful but you prefer restriction to deletion, or when the organization no longer needs the data but you require it for a legal claim. Restriction usually means the organization may store the information but cannot use it freely.
In certain situations, you can receive data in a structured, commonly used, machine-readable format and ask for its transfer to another controller. This right to data portability generally applies where processing is based on consent or a contract and carried out by automated means. You may also object to processing based on public interest or legitimate interests, including some forms of direct marketing.
| Right | What it can provide | Important limitation |
|---|---|---|
| Access | Confirmation and a copy of personal data | Other people’s rights and confidentiality must be protected |
| Rectification | Correction of inaccurate or incomplete records | The organization may verify the requested change |
| Erasure | Deletion in defined circumstances | Legal retention duties can override deletion |
| Restriction | Temporary limitation on use | Storage may continue while an issue is resolved |
| Portability | Transferable electronic data | Usually concerns automated processing based on consent or contract |
| Objection | Challenge to certain processing activities | Overriding legal grounds may permit continued processing |
Consent, Marketing, And Automated Decisions
Consent must be voluntary, specific, informed, and unambiguous. It should be distinguishable from unrelated terms and conditions, and refusing consent should not generally result in unfair pressure. Where processing relies on consent, you can withdraw it at any time. Withdrawal does not usually make earlier lawful processing unlawful, but it should stop future processing unless another legal basis applies.
Direct marketing deserves particular attention. You can object to the use of your personal data for direct marketing, including related profiling. Once a valid objection is received for that purpose, the organization should stop using the data for direct marketing.
Automated decision-making and profiling may affect credit, recruitment, insurance, access to services, or online visibility. Where a decision is based solely on automated processing and produces legal or similarly significant effects, additional safeguards may apply. These can include information about the logic involved, an opportunity to express a view, and human intervention or review where legally required.
Organizations should collect only data that is adequate, relevant, and limited to what is necessary. Asking for a copy of an identity document when age verification would be enough may raise a proportionality concern. The same principle applies to indefinite retention: data should not be kept forever simply because storage is inexpensive.
How To Make A Request Or Complaint
A rights request should be directed to the controller or its data protection officer, where one has been appointed. Include enough information to identify the relevant account or record, describe the right being exercised, and state how you would like the organization to respond. Keep a copy of the request and proof of submission.
The organization should respond without undue delay and generally within 30 days. That period may be extended in complex cases, but the organization should explain the reason for the extension. It may ask for additional information to verify identity, especially where disclosure could expose sensitive records to the wrong person.
If the response is incomplete, unjustifiably delayed, or refused without adequate explanation, you may submit a complaint to Serbia’s Commissioner for Information of Public Importance and Personal Data Protection. A complaint can be supported with the original request, the response, relevant notices, and evidence of the processing. Court protection may also be available, particularly where unlawful processing has caused damage.
Free legal aid organizations and civic groups can help people formulate requests, understand institutional responses, and identify patterns affecting a wider community. Cooperation with experienced civil society organizations, including Nomcentar partners, can also support educational and advocacy work around privacy and access to justice.
Data Breaches And Cross-Border Transfers
A personal data breach may involve unauthorized access, accidental disclosure, loss, destruction, or alteration. Examples include a stolen laptop containing unencrypted records, an email sent to the wrong recipients, or a compromised database. Controllers must assess the risk and take measures to contain the incident, document it, and notify the Commissioner when the statutory conditions require notification. Individuals should be informed when the breach creates a high risk to their rights and freedoms.
If you receive a breach notice, change reused passwords, activate multi-factor authentication, monitor financial accounts, and be cautious of follow-up phishing messages. Do not assume that a message is genuine merely because it includes personal details; leaked information can be used to make scams appear credible.
Personal data may be transferred outside Serbia only under rules designed to ensure an adequate level of protection. Appropriate safeguards, approved contractual arrangements, or a specific legal exception may be required. Privacy notices should make international transfers understandable rather than hiding them in technical language.
Practical Steps For Protecting Your Privacy
Legal rights are more effective when supported by everyday habits. Before providing information, identify the organization requesting it, ask why each field is necessary, and check whether optional marketing permissions are clearly separated from essential service terms. Avoid sending sensitive documents through insecure channels when a safer alternative exists.
Review old accounts and delete information that is no longer needed where deletion is available. Keep records of consent, privacy notices, requests, and responses. When acting for a community organization, create a simple retention schedule, limit staff access, use strong passwords, and train volunteers who handle membership or beneficiary information.
Useful actions include:
- Read privacy notices before signing up for a service or submitting documents.
- Request correction when an organization holds inaccurate information about you.
- Object promptly to unwanted direct marketing and retain evidence of the objection.
- Report suspected misuse or a serious breach to the organization and, where appropriate, the Commissioner.
- Seek legal guidance when a refusal affects employment, healthcare, benefits, education, or another essential right.
Privacy protection is a shared responsibility between individuals, public bodies, businesses, and civil society. Start by making a clear written request, preserve the response, and use the available complaint mechanisms when your rights are ignored. Accessible legal education and community support can turn data protection from an abstract rule into a practical safeguard for people across Serbia.