Skip to content

Evidence request lists

Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011)

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

BiH DP Law Chapter I: General Provisions

BA-DPA-1
Purpose of the Law

Purpose of the Law. Article 1 establishes the purpose: to secure, in the territory of Bosnia and Herzegovina, the protection of the fundamental rights and freedoms of individuals, in particular the right to privacy, with respect to the processing of personal data.

Artefacts an auditor will ask for
  • Recognition that processing is subject to the BiH Law
  • Mapping of obligations to processing activities
Where this commonly fails
  • Processing not assessed against the Law
  • Privacy purpose not reflected in the programme
BA-DPA-2
Scope of the Law

Scope of the Law. Article 2 provides that the Law applies to personal data processed by all public authorities and by natural and legal persons (controllers) processing personal data, with stated exceptions.

Artefacts an auditor will ask for
  • Determination of controller status under the Law
  • Records of processing within scope (public/private sector)
Where this commonly fails
  • Processing wrongly scoped out
  • Public vs private application misjudged
BA-DPA-3
Definitions

Definitions. Article 3 defines the key terms of the Law (personal data, processing, controller, processor, personal data filing system, consent, special categories and others).

Artefacts an auditor will ask for
  • Mapping of statutory definitions to internal terminology
  • Classification of data as personal/special-category per Article 3
Where this commonly fails
  • Statutory definitions not applied
  • Special-category data not identified

BiH DP Law Chapter II: Principles and Lawful Processing

BA-DPA-11
Data Security

Data Security. Article 11 requires the controller to take the necessary technical and organisational measures and procedures against unauthorised or accidental access, alteration, destruction, loss or disclosure of personal data.

Artefacts an auditor will ask for
  • Technical and organisational security measures
  • Access controls and protection against accidental loss
  • Security measures proportionate to the data and risk
Where this commonly fails
  • Inadequate technical/organisational measures
  • No access controls
  • Security not documented
BA-DPA-12
Data Processing by a Processor

Data processing by a processor. Article 12 requires that where processing is entrusted to a processor it be governed by a contract specifying the processor's obligations, including security and confidentiality.

Artefacts an auditor will ask for
  • Written processing contracts specifying processor obligations
  • Due diligence on processors
  • Security and confidentiality terms in processor contracts
Where this commonly fails
  • Processing entrusted without a compliant contract
  • Processor security not assured
  • No processor due diligence
BA-DPA-4
Principles of Personal Data Processing

Principles of Personal Data Processing. Article 4 sets out the core principles: fair and lawful processing, purpose specification, adequacy/relevance/non-excessiveness, accuracy, and retention no longer than necessary.

Artefacts an auditor will ask for
  • Documentation that processing meets each Article 4 principle
  • Data minimisation and retention controls
  • Purpose specification records
Where this commonly fails
  • Principles not demonstrably applied
  • Excessive data or over-retention
  • Purposes unspecified
BA-DPA-5
Consent by a Data Subject

Consent by a Data Subject. Article 5 sets the conditions under which personal data may be processed on the basis of the data subject's consent.

Artefacts an auditor will ask for
  • Consent records demonstrating valid consent
  • Consent withdrawal mechanism
  • Evidence consent was informed and freely given
Where this commonly fails
  • Consent not demonstrable
  • No withdrawal mechanism
  • Consent bundled or coerced
BA-DPA-6
The Right to Process Without the Data Subject's Consent

Right to process without consent. Article 6 sets out the grounds on which personal data may be processed without the data subject's consent (e.g. legal obligation, contract, vital/public interest).

Artefacts an auditor will ask for
  • Record of the non-consent ground relied on for each processing
  • Necessity assessment for the ground
  • Documentation supporting legal-obligation or public-interest grounds
Where this commonly fails
  • Processing without a valid Article 6 ground
  • Ground not documented
  • Reliance on an inapplicable ground
BA-DPA-7
Data Authenticity

Data Authenticity. Article 7 requires the controller to check whether the personal data being processed are authentic, accurate and up to date, and to correct or delete inaccurate data.

Artefacts an auditor will ask for
  • Accuracy verification and update procedures
  • Correction/deletion of inaccurate data
  • Source verification of personal data
Where this commonly fails
  • Data accuracy not verified
  • Inaccurate data not corrected
  • No update process
BA-DPA-9
Processing of Special Categories of Personal Data

Special categories. Article 9 imposes stricter conditions on processing special categories of personal data (e.g. racial/ethnic origin, political opinions, religion, health, sexual life, criminal records).

Artefacts an auditor will ask for
  • Identification of special-category data held
  • Lawful condition for special-category processing under Article 9
  • Enhanced safeguards for sensitive data
Where this commonly fails
  • Special-category data processed without an Article 9 condition
  • Sensitive categories not identified
  • No enhanced safeguards

BiH DP Law Chapter III: Records, Confidentiality and Transfers

BA-DPA-13
Personal Data Filing System

Personal data filing system. Article 13 requires the controller to establish and maintain prescribed records of personal data filing systems.

Artefacts an auditor will ask for
  • Maintained records of personal data filing systems
  • Documentation of the structure and content of filing systems
Where this commonly fails
  • Filing-system records not maintained
  • Records incomplete or outdated
BA-DPA-14
Central Registry

Central Registry. Article 14 requires controllers to register their personal data filing systems with the Personal Data Protection Agency's central registry within the prescribed time and to keep registrations current.

Artefacts an auditor will ask for
  • Evidence of registration of filing systems with the Agency
  • Updates to registrations on change
  • Internal record of registered systems
Where this commonly fails
  • Filing systems not registered
  • Registrations not updated
  • No internal register
BA-DPA-16
Confidentiality Requirement

Confidentiality Requirement. Article 16 obliges persons who process personal data, and those who become aware of personal data in the course of their work, to keep them confidential.

Artefacts an auditor will ask for
  • Confidentiality undertakings for staff and processors
  • Awareness of confidentiality obligations
  • Controls limiting access to those who need it
Where this commonly fails
  • No confidentiality undertakings
  • Staff unaware of obligations
  • Access not limited
BA-DPA-18
Data Transfer Abroad

Data Transfer Abroad. Article 18 sets the conditions under which personal data may be transferred outside Bosnia and Herzegovina, requiring an adequate level of protection in the receiving country or other safeguards.

Artefacts an auditor will ask for
  • Inventory of transfers abroad and destinations
  • Adequacy assessment or safeguards for each transfer
  • Agency authorisation where required
Where this commonly fails
  • Transfers abroad without adequacy/safeguards
  • Transfers not inventoried
  • Required authorisation not obtained

BiH DP Law Chapter IV: Rights of Data Subjects

BA-DPA-22
Notification on Data Collection

Notification on Data Collection. Article 22 requires the controller to notify the data subject, at collection, of the purpose of processing and other prescribed information.

Artefacts an auditor will ask for
  • Collection notices covering the Article 22 information
  • Process to provide notice at or before collection
Where this commonly fails
  • No collection notice
  • Notice missing required information
BA-DPA-24
The Right to Personal Data Access

Right of access. Article 24 gives data subjects the right to access their personal data held by a controller and information about its processing.

Artefacts an auditor will ask for
  • Procedure for handling access requests
  • Records of access requests and responses
  • Identity verification for requesters
Where this commonly fails
  • Access requests not handled
  • No procedure
  • Statutory timeframes missed
BA-DPA-27
Corrigenda and Deletion of Data

Correction and deletion. Article 27 gives data subjects the right to request correction, supplementation, or deletion of their personal data where inaccurate or unlawfully processed.

Artefacts an auditor will ask for
  • Procedure for correction/deletion requests
  • Records of corrections and deletions
  • Propagation of corrections to recipients
Where this commonly fails
  • Requests not actioned
  • No procedure
  • Corrections not propagated
BA-DPA-29
Issuing Decisions Based on Automatic Data Processing

Automated decisions. Article 29 regulates decisions producing legal effects or significantly affecting a data subject that are based solely on automatic processing.

Artefacts an auditor will ask for
  • Inventory of solely-automated decisions affecting individuals
  • Safeguards (human involvement, contestation) for such decisions
Where this commonly fails
  • Automated decisions without safeguards
  • No human review option
  • Individuals not informed

BiH DP Law Chapter V: Complaints and Liability

BA-DPA-30
Filing Complaints

Filing Complaints. Article 30 gives data subjects the right to file a complaint with the Agency where they find or suspect that a controller or processor has breached the Law.

Artefacts an auditor will ask for
  • Procedure for handling and cooperating with Agency complaints
  • Records of complaints and responses
  • Internal complaint-handling for data subjects
Where this commonly fails
  • Complaints not handled or escalated
  • No cooperation with Agency complaints
  • No internal complaint route
BA-DPA-32
Liability for Damage

Liability for Damage. Article 32 establishes the controller's liability to compensate damage caused to a data subject by unlawful processing.

Artefacts an auditor will ask for
  • Awareness of damage-liability exposure
  • Claim-handling records
  • Legal review of unlawful-processing exposure
Where this commonly fails
  • Liability exposure not assessed
  • Claims not handled
  • Contraventions not remediated

BiH DP Law Chapter VI: The Personal Data Protection Agency

BA-DPA-35
Definition of the Agency

The Personal Data Protection Agency. Article 35 defines the Personal Data Protection Agency as the independent supervisory authority for the Law.

Artefacts an auditor will ask for
  • Recognition of the Agency as supervisory authority
  • Engagement and cooperation records with the Agency
Where this commonly fails
  • Agency role not recognised
  • No engagement with the Agency
BA-DPA-40
Competencies of the Agency

Competencies of the Agency. Article 40 sets out the Agency's competencies, including supervision, issuing decisions and orders, maintaining the central registry and handling complaints.

Artefacts an auditor will ask for
  • Responses to Agency decisions, orders and requests
  • Tracking of Agency correspondence to closure
  • Cooperation with Agency supervision
Where this commonly fails
  • Agency orders not complied with
  • Requests not responded to
  • Correspondence not tracked
BA-DPA-41
Control Carried Out by the Agency

Control by the Agency. Article 41 empowers the Agency to carry out controls (inspections) of controllers and processors, who must extend support and provide access.

Artefacts an auditor will ask for
  • Procedures for supporting Agency inspections
  • Records of inspections and findings
  • Remediation of inspection findings
Where this commonly fails
  • Inspections not supported
  • Findings not remediated
  • Access to the Agency refused

BiH DP Law Chapter VII: Offences and Penalties

BA-DPA-48
Offences and Fines

Offences and Penalties. Articles 48 to 52 set out the offences under the Law and the corresponding fines for controllers, responsible persons within public authorities and other parties.

Artefacts an auditor will ask for
  • Awareness of the offences and fine exposure under the Law
  • Controls preventing the conduct penalised
  • Records of any penalties and remediation
Where this commonly fails
  • Offence exposure not assessed
  • No controls against penalised conduct
  • Penalties not remediated
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) framework page.