Skip to content

Serbian Personal Data Protection Act (ZZPL) in brief: rights, duties, deadlines

Zakon o zaštiti podataka o ličnosti (ZZPL): scope, Official Gazette number, legal bases for processing, data subject rights, 30-day and 72-hour deadlines.

INFO
Short answer. The Personal Data Protection Act (Zakon o zaštiti podataka o ličnosti, ZZPL) governs when and how companies, public bodies and other organisations may process data about individuals, what rights individuals have, and what the Commissioner (Poverenik) does. It was published in Sl. glasnik RS, No. 87/2018, has not been amended since, and has applied since 21 August 2019. In substance it follows the EU General Data Protection Regulation (GDPR). This page explains the Act in plain language and does not replace the official text.

What the Personal Data Protection Act (Zakon o zaštiti podataka o ličnosti) covers and whom it applies to

Zakon o zaštiti podataka o ličnosti, abbreviated ZZPL, governs the protection of individuals with regard to the processing of their data and the free movement of such data. Personal data is any information relating to an individual whose identity is determined or determinable: a name, personal ID number (JMBG), address, location, IP address, camera footage, health data (Art. 4).

The Act applies to all automated processing and to non-automated processing of data that forms part of a filing system (Art. 3). It binds controllers, meaning those who determine the purpose and means of processing, and processors, who process data on their behalf. In practice that is almost every company, sole trader, association, school, healthcare institution and public body. The Act does not apply to processing by an individual for personal or household purposes. It also applies to controllers outside Serbia when they offer goods or services to individuals in Serbia or monitor their behaviour; under Art. 44 they designate a representative in Serbia.

Official citation: Zakon o zaštiti podataka o ličnosti (Sl. glasnik RS, No. 87/2018). The Act has not been amended to date. It was published in November 2018 and has applied since 21 August 2019.

How the Act is structured

The Act has 102 articles in ten chapters:

  • I Basic provisions (subject matter, application, definitions)
  • II Principles (lawfulness, purpose limitation, minimisation, accuracy, storage limitation, security, legal basis, consent, special categories of data)
  • III Rights of the data subject
  • IV Controller and processor (obligations, records, security, data breaches, impact assessment, data protection officer)
  • V Transfers of data to other countries and international organisations
  • VI The Commissioner
  • VII Remedies, liability and penalties
  • VIII Special cases of processing
  • IX Penal provisions
  • X Transitional and final provisions

Some provisions concern only processing by competent authorities for the prevention and prosecution of criminal offences. Those parts are not of direct relevance to companies and individuals.

The most searched provisions

Processing principles (Art. 5). Data is processed lawfully, fairly and transparently, only for specified purposes, to the extent necessary, kept accurate and stored only as long as needed, with appropriate safeguards. The controller must be able to demonstrate compliance with these principles.

Legal basis for processing (Art. 12). Without one of the six bases, processing is not lawful.

Consent (Art. 15 and 16). The controller must be able to prove that consent was given. Consent buried in general terms, or made a condition of a contract for which it is not necessary, is not considered freely given.

Special categories of data (Art. 17). Processing that reveals racial or ethnic origin, political opinion, religious belief or trade union membership is prohibited, as is processing of genetic and biometric data, health data and data on sex life, apart from the exceptions listed in the Act.

Information at collection (Art. 23). At the time of collection the individual must receive information about the controller, the purpose and legal basis, recipients, the storage period and their rights. This is the legal basis for a website privacy policy.

Data subject rights (Art. 26-38). The right of access (Art. 26), rectification (Art. 29), erasure (Art. 30), restriction of processing (Art. 31), portability (Art. 36), objection (Art. 37) and the right not to be subject to a decision based solely on automated processing (Art. 38).

Processor (Art. 45). The relationship with a processor, for example a bookkeeping agency or a hosting company, is governed by a contract with prescribed content.

Records of processing activities (Art. 47). Controllers keep records of processing, with exceptions for smaller organisations.

Data breach (Art. 52 and 53). Notification to the Commissioner within 72 hours and, for high risk, notification of the affected individuals.

Transfers abroad (Art. 63-65). Without special approval, transfers are allowed to countries with an adequate level of protection. In other cases appropriate safeguards are needed, for example standard contractual clauses.

Where to read the official text

The official text is available in the Legal Information System of the Republic of Serbia: Zakon o zaštiti podataka o ličnosti at pravno-informacioni-sistem.rs. Complaint forms, opinions and the decision on standard contractual clauses are published by the Commissioner on its website. If you run a business, the Act itself does not hand you ready-made documentation. Which records, notices and contracts are needed depends on what data you process and why.

Sources

What to do

  • The controller responds to a data subject's request (access, rectification, erasure, restriction, portability, objection) without delay, and within 30 days of receipt at the latest; the period may be extended by a further 60 days because of the complexity and number of requests (Art. 21).
  • The controller notifies the Commissioner of a data breach that may pose a risk to individuals' rights and freedoms without undue delay and, where possible, within 72 hours of becoming aware of it (Art. 52).
  • If the breach may pose a high risk, the controller also notifies the data subjects without undue delay (Art. 53).
  • A minor who has turned 15 may independently consent to data processing when using information society services; for younger children, a parent gives consent (Art. 16).
  • Consent may be withdrawn at any time, and withdrawing must be as easy as giving consent (Art. 15).
  • An objection to processing based on legitimate interest or public authority may be filed at any time; for direct marketing, processing stops once an objection is made (Art. 37).
  • A data protection impact assessment is carried out before starting processing that is likely to pose a high risk (Art. 54).
  • The Act entered into force on the eighth day after publication and applies after nine months from entry into force (Art. 102).

FAQ

Is the ZZPL the same as the GDPR?

It is not the same instrument, but it was modelled on the GDPR and uses the same concepts: controller, processor, legal basis for processing, data subject rights, impact assessment, data protection officer. The differences lie in the fines, which in Serbia are misdemeanour fines and considerably lower, and in the supervisory authority, which is the Commissioner for Information of Public Importance and Personal Data Protection. Companies offering goods or services to individuals in the EU may be bound by the GDPR at the same time.

When is the processing of personal data lawful?

Only if one of the six legal bases in Art. 12 exists: the individual's consent, performance of a contract with that individual, a legal obligation of the controller, protection of vital interests, performance of tasks in the public interest, or the controller's legitimate interest that does not override the individual's rights. Consent is only one of the bases and is not always needed.

How quickly must a company respond to a data access request?

Without delay, and within 30 days of receiving the request at the latest. The period may be extended by a further 60 days if necessary because of the complexity and number of requests. The controller must inform the person of the extension and the reasons for it within 30 days of receiving the request. Handling the request is free of charge, unless the request is manifestly unfounded or excessive, for example because it is repeated frequently (Art. 21).

Who must appoint a data protection officer?

Public authorities, except courts acting in their judicial capacity, and controllers and processors whose core activities consist of regular and systematic monitoring of a large number of individuals or of large-scale processing of special categories of data (Art. 56). Others may appoint one voluntarily.

How high are the fines under the Personal Data Protection Act?

For the misdemeanours in Art. 95, the fine is from 50,000 to 2,000,000 dinars for a controller or processor that is a legal entity, and for certain misdemeanours a fixed fine of 100,000 dinars. For the same misdemeanours a sole trader is fined 20,000 to 500,000 dinars (or 50,000 dinars where the fine is fixed), and a natural person or the responsible person in a legal entity or authority 5,000 to 150,000 dinars (or 20,000 dinars).

Where do I complain if someone misuses my data?

You may file a complaint with the Commissioner (Art. 82) and, independently of that, bring a court claim for protection of your rights (Art. 84). Filing a complaint does not exclude court protection. Material and non-material damage caused by a breach of the Act is compensated under Art. 86.