Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011)
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
BiH DP Law Chapter I: General Provisions
Purpose of the Law. Article 1 establishes the purpose: to secure, in the territory of Bosnia and Herzegovina, the protection of the fundamental rights and freedoms of individuals, in particular the right to privacy, with respect to the processing of personal data.
- Recognition that processing is subject to the BiH Law
- Mapping of obligations to processing activities
- Processing not assessed against the Law
- Privacy purpose not reflected in the programme
Scope of the Law. Article 2 provides that the Law applies to personal data processed by all public authorities and by natural and legal persons (controllers) processing personal data, with stated exceptions.
- Determination of controller status under the Law
- Records of processing within scope (public/private sector)
- Processing wrongly scoped out
- Public vs private application misjudged
Definitions. Article 3 defines the key terms of the Law (personal data, processing, controller, processor, personal data filing system, consent, special categories and others).
- Mapping of statutory definitions to internal terminology
- Classification of data as personal/special-category per Article 3
- Statutory definitions not applied
- Special-category data not identified
BiH DP Law Chapter II: Principles and Lawful Processing
Data Security. Article 11 requires the controller to take the necessary technical and organisational measures and procedures against unauthorised or accidental access, alteration, destruction, loss or disclosure of personal data.
- Technical and organisational security measures
- Access controls and protection against accidental loss
- Security measures proportionate to the data and risk
- Inadequate technical/organisational measures
- No access controls
- Security not documented
Data processing by a processor. Article 12 requires that where processing is entrusted to a processor it be governed by a contract specifying the processor's obligations, including security and confidentiality.
- Written processing contracts specifying processor obligations
- Due diligence on processors
- Security and confidentiality terms in processor contracts
- Processing entrusted without a compliant contract
- Processor security not assured
- No processor due diligence
Principles of Personal Data Processing. Article 4 sets out the core principles: fair and lawful processing, purpose specification, adequacy/relevance/non-excessiveness, accuracy, and retention no longer than necessary.
- Documentation that processing meets each Article 4 principle
- Data minimisation and retention controls
- Purpose specification records
- Principles not demonstrably applied
- Excessive data or over-retention
- Purposes unspecified
Consent by a Data Subject. Article 5 sets the conditions under which personal data may be processed on the basis of the data subject's consent.
- Consent records demonstrating valid consent
- Consent withdrawal mechanism
- Evidence consent was informed and freely given
- Consent not demonstrable
- No withdrawal mechanism
- Consent bundled or coerced
Right to process without consent. Article 6 sets out the grounds on which personal data may be processed without the data subject's consent (e.g. legal obligation, contract, vital/public interest).
- Record of the non-consent ground relied on for each processing
- Necessity assessment for the ground
- Documentation supporting legal-obligation or public-interest grounds
- Processing without a valid Article 6 ground
- Ground not documented
- Reliance on an inapplicable ground
Data Authenticity. Article 7 requires the controller to check whether the personal data being processed are authentic, accurate and up to date, and to correct or delete inaccurate data.
- Accuracy verification and update procedures
- Correction/deletion of inaccurate data
- Source verification of personal data
- Data accuracy not verified
- Inaccurate data not corrected
- No update process
Special categories. Article 9 imposes stricter conditions on processing special categories of personal data (e.g. racial/ethnic origin, political opinions, religion, health, sexual life, criminal records).
- Identification of special-category data held
- Lawful condition for special-category processing under Article 9
- Enhanced safeguards for sensitive data
- Special-category data processed without an Article 9 condition
- Sensitive categories not identified
- No enhanced safeguards
BiH DP Law Chapter III: Records, Confidentiality and Transfers
Personal data filing system. Article 13 requires the controller to establish and maintain prescribed records of personal data filing systems.
- Maintained records of personal data filing systems
- Documentation of the structure and content of filing systems
- Filing-system records not maintained
- Records incomplete or outdated
Central Registry. Article 14 requires controllers to register their personal data filing systems with the Personal Data Protection Agency's central registry within the prescribed time and to keep registrations current.
- Evidence of registration of filing systems with the Agency
- Updates to registrations on change
- Internal record of registered systems
- Filing systems not registered
- Registrations not updated
- No internal register
Confidentiality Requirement. Article 16 obliges persons who process personal data, and those who become aware of personal data in the course of their work, to keep them confidential.
- Confidentiality undertakings for staff and processors
- Awareness of confidentiality obligations
- Controls limiting access to those who need it
- No confidentiality undertakings
- Staff unaware of obligations
- Access not limited
Data Transfer Abroad. Article 18 sets the conditions under which personal data may be transferred outside Bosnia and Herzegovina, requiring an adequate level of protection in the receiving country or other safeguards.
- Inventory of transfers abroad and destinations
- Adequacy assessment or safeguards for each transfer
- Agency authorisation where required
- Transfers abroad without adequacy/safeguards
- Transfers not inventoried
- Required authorisation not obtained
BiH DP Law Chapter IV: Rights of Data Subjects
Notification on Data Collection. Article 22 requires the controller to notify the data subject, at collection, of the purpose of processing and other prescribed information.
- Collection notices covering the Article 22 information
- Process to provide notice at or before collection
- No collection notice
- Notice missing required information
Right of access. Article 24 gives data subjects the right to access their personal data held by a controller and information about its processing.
- Procedure for handling access requests
- Records of access requests and responses
- Identity verification for requesters
- Access requests not handled
- No procedure
- Statutory timeframes missed
Correction and deletion. Article 27 gives data subjects the right to request correction, supplementation, or deletion of their personal data where inaccurate or unlawfully processed.
- Procedure for correction/deletion requests
- Records of corrections and deletions
- Propagation of corrections to recipients
- Requests not actioned
- No procedure
- Corrections not propagated
Automated decisions. Article 29 regulates decisions producing legal effects or significantly affecting a data subject that are based solely on automatic processing.
- Inventory of solely-automated decisions affecting individuals
- Safeguards (human involvement, contestation) for such decisions
- Automated decisions without safeguards
- No human review option
- Individuals not informed
BiH DP Law Chapter V: Complaints and Liability
Filing Complaints. Article 30 gives data subjects the right to file a complaint with the Agency where they find or suspect that a controller or processor has breached the Law.
- Procedure for handling and cooperating with Agency complaints
- Records of complaints and responses
- Internal complaint-handling for data subjects
- Complaints not handled or escalated
- No cooperation with Agency complaints
- No internal complaint route
Liability for Damage. Article 32 establishes the controller's liability to compensate damage caused to a data subject by unlawful processing.
- Awareness of damage-liability exposure
- Claim-handling records
- Legal review of unlawful-processing exposure
- Liability exposure not assessed
- Claims not handled
- Contraventions not remediated
BiH DP Law Chapter VI: The Personal Data Protection Agency
The Personal Data Protection Agency. Article 35 defines the Personal Data Protection Agency as the independent supervisory authority for the Law.
- Recognition of the Agency as supervisory authority
- Engagement and cooperation records with the Agency
- Agency role not recognised
- No engagement with the Agency
Competencies of the Agency. Article 40 sets out the Agency's competencies, including supervision, issuing decisions and orders, maintaining the central registry and handling complaints.
- Responses to Agency decisions, orders and requests
- Tracking of Agency correspondence to closure
- Cooperation with Agency supervision
- Agency orders not complied with
- Requests not responded to
- Correspondence not tracked
Control by the Agency. Article 41 empowers the Agency to carry out controls (inspections) of controllers and processors, who must extend support and provide access.
- Procedures for supporting Agency inspections
- Records of inspections and findings
- Remediation of inspection findings
- Inspections not supported
- Findings not remediated
- Access to the Agency refused
BiH DP Law Chapter VII: Offences and Penalties
Offences and Penalties. Articles 48 to 52 set out the offences under the Law and the corresponding fines for controllers, responsible persons within public authorities and other parties.
- Awareness of the offences and fine exposure under the Law
- Controls preventing the conduct penalised
- Records of any penalties and remediation
- Offence exposure not assessed
- No controls against penalised conduct
- Penalties not remediated
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) framework page.