Skip to content

Personal Data Protection

Companies' obligations under the Personal Data Protection Act - DPO, records of processing activities, breach notification.

Area overview

This page concerns a company's obligations as a controller or processor of the personal data of its clients, employees, and business partners - that is, the compliance of its business operations with the Personal Data Protection Act (Zakon o zaštiti podataka o ličnosti), not the technical security of information systems as such.

Every processing of personal data must have a legal basis (for example, the data subject's consent, performance of a contract, a statutory obligation, or the controller's legitimate interest) and must be limited to what is necessary for the specific purpose. The controller is obliged to take appropriate technical, organizational, and personnel measures so that processing complies with the law, including applying data-protection principles already at the design stage of business processes (privacy by design) and default protection (privacy by default).

One of the central obligations is keeping a record of processing activities - an internal register describing which categories of data are processed, for what purpose, who the recipients are, and how long the data is kept. The law exempts businesses and organisations with fewer than 250 employees, unless the processing is likely to result in a high risk to the rights and freedoms of individuals, the processing is not occasional, or it covers special categories of data (e.g. health data) or data on criminal convictions and offences (Art. 47 para. 5). In practice, even a smaller company that regularly processes client or employee data usually keeps the record.

Appointing a data protection officer (also known as a DPO) is mandatory in three situations: when the controller or processor is a government authority (except courts acting in their judicial capacity), when the core activity requires regular and systematic monitoring of persons on a large scale, or when the core activity consists of processing special categories of data or data on criminal convictions on a large scale. Outside these cases, appointment is not a statutory obligation, but it can be a useful organizational measure.

If a personal data breach occurs (e.g. unauthorized access to a database or loss of data) that poses a risk to the rights and freedoms of persons, the controller is obliged to notify the Commissioner for Information of Public Importance and Personal Data Protection without delay, and at the latest within 72 hours of becoming aware of it. If the controller cannot provide all the information within that deadline, it is obliged to provide it subsequently. In certain cases, when the breach is likely to result in a high risk to the rights of persons, the data subject itself must also be notified of it.

Failure to comply with these obligations is sanctioned as a misdemeanor, and a controller or processor that is a legal entity faces a fine of RSD 50,000 to 2,000,000, depending on the type of violation (Art. 95). Independent of misdemeanor liability, a person whose data has been processed unlawfully may claim damages.

Sources

FAQ

Does a small company with no employees even need to worry about this law?

Yes, to some extent - every business entity that processes personal data (e.g. data of clients, employees, or business partners) has the status of a controller and is subject to the law's basic obligations, even without employees. The scope of the obligations - for example, whether it is mandatory to keep a record of processing activities or appoint a data protection officer - depends on the volume and type of data the company processes, not just on the size of the company.

Who is the Commissioner and what does it do?

The Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti) is an independent state authority responsible for overseeing the application of the Personal Data Protection Act in Serbia. It receives data breach notifications, handles complaints from persons whose data has been processed, and carries out supervision over controllers and processors.