Skip to content

Evidence request lists

Serbia Law on Personal Data Protection (2018)

Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Breach

SERBIA-5
Breach + Enforcement

Per Serbia Law: 72-hr breach + enforcement.

Artefacts an auditor will ask for
  • Serbia evidence for SERBIA-5
Where this commonly fails
  • DPO + Commissioner partial

Governance

SERBIA-4
DPO + Governance

Per Serbia Law: DPO + RoPA + governance.

Artefacts an auditor will ask for
  • Serbia evidence for SERBIA-4
Where this commonly fails
  • DPO + Commissioner partial

Rights

SERBIA-2
Consent, Notice, Rights

Per Serbia Law: standard GDPR consent + notice + rights.

Artefacts an auditor will ask for
  • Serbia evidence for SERBIA-2
Where this commonly fails
  • DPO + Commissioner partial

Scope

SERBIA-1
Scope, Lawful Basis (Serbia)

Per Serbia Law on Personal Data Protection 2018 implementing GDPR: scope + lawful basis. Align with Commissioner for Information of Public Importance and Personal Data Protection.

Artefacts an auditor will ask for
  • Serbia evidence for SERBIA-1
Where this commonly fails
  • DPO + Commissioner partial

Security

SERBIA-3
Security and Cross-Border

Per Serbia Law: standard GDPR security + cross-border with Commissioner approval.

Artefacts an auditor will ask for
  • Serbia evidence for SERBIA-3
Where this commonly fails
  • DPO + Commissioner partial

Serbia LPDP: Accountability and Records

RS-DPL-10.1
Data Protection Officer

Public bodies, controllers with core activities involving large scale regular and systematic monitoring, or large scale special category processing must designate a DPO with sufficient expertise and independence.

Artefacts an auditor will ask for
  • DPO appointment record
  • Commissioner notification
  • Reporting line to highest management
  • Independence statement
  • Resource allocation
  • Tasks under Article 58 documented
Where this commonly fails
  • DPO role combined with conflicting role
  • Reports to mid level management
  • Tasks performed without independence
RS-DPL-11.1
Processor Engagement and Contracts

Engagement of processors requires a written contract containing prescribed terms including subject matter, duration, nature and purpose, types of data, controller obligations, and processor obligations.

Artefacts an auditor will ask for
  • DPA template aligned with Article 45
  • Signed DPAs per processor
  • Sub processor approval workflow
  • Audit rights exercised
  • Termination data return or deletion evidence
Where this commonly fails
  • DPAs missing prescribed terms
  • Sub processors not notified
  • Audit rights never exercised
RS-DPL-7.1
Data Protection by Design and Default

Controllers must implement appropriate technical and organisational measures at the time of determining means of processing and during processing, and by default only process data necessary for each purpose.

Artefacts an auditor will ask for
  • Privacy by design framework
  • Default minimisation settings evidence
  • DPIA outcomes integrated into design
  • Pseudonymisation use cases
  • Architecture diagrams with privacy controls
Where this commonly fails
  • Privacy considered only at launch
  • Defaults set to maximum collection
  • Pseudonymisation theoretical not implemented
RS-DPL-8.1
Records of Processing Activities

Controllers and processors with 250 or more employees, or where processing is not occasional or includes special categories, must maintain records of processing activities with prescribed content.

Artefacts an auditor will ask for
  • ROPA documents per Article 47
  • Annual ROPA review records
  • Linked DPIAs
  • Processor ROPA inputs
  • Provision to Commissioner on request evidence
Where this commonly fails
  • ROPA created but not updated
  • Categories of recipients generic
  • Cross border transfers missing safeguards documentation
RS-DPL-9.1
Data Protection Impact Assessment

A DPIA is required where processing is likely to result in high risk to rights and freedoms, particularly for systematic and extensive profiling, large scale processing of special categories, or systematic monitoring of publicly accessible areas.

Artefacts an auditor will ask for
  • DPIA methodology
  • DPIA register
  • Threshold assessments
  • Stakeholder consultation records
  • Prior consultation with Commissioner where high residual risk
Where this commonly fails
  • Threshold assessments skipped
  • DPIAs treated as documentation exercise
  • Prior consultation not requested where required

Serbia LPDP: Cross-Border Transfers

RS-DPL-13.1
Cross-Border Transfers

Transfers outside Serbia require adequacy decision, appropriate safeguards (standard contractual clauses, binding corporate rules), or derogations for specific situations, with documentation of mechanism used.

Artefacts an auditor will ask for
  • Transfer mechanism inventory
  • SCCs signed and stored
  • BCR approvals
  • Adequacy reliance documentation
  • Transfer impact assessments
Where this commonly fails
  • EU SCCs adopted without Serbian compatibility review
  • Adequacy reliance assumed without Serbian list
  • TIAs missing for high risk destinations
RS-DPL-13.2
Adequacy and Commissioner Authorisation

Transfers may rely on Government adequacy decisions or, in their absence, on Commissioner authorised safeguards or derogations, requiring documentation of the basis used.

Artefacts an auditor will ask for
  • Government adequacy list reference
  • Commissioner authorisations for specific transfers
  • Derogation justifications
  • Documentation in ROPA
  • Subject information about transfers
Where this commonly fails
  • Authorisation expired or scope exceeded
  • Derogations used as routine basis
  • Subjects not informed of transfers
RS-DPL-18.1
Representative Appointment for Non-Established Controllers

Controllers and processors not established in Serbia but subject to the law must designate in writing a representative in Serbia, unless processing is occasional and does not involve large scale special categories.

Artefacts an auditor will ask for
  • Representative appointment letter
  • Contact details published
  • Mandate scope
  • Communication evidence with subjects and Commissioner
  • Exemption analysis if applicable
Where this commonly fails
  • Representative not designated where required
  • Contact details not published
  • Exemption assumed without analysis

Serbia LPDP: Scope and Lawful Basis

RS-DPL-1.1
Scope and Territorial Application

The law applies to processing of personal data by controllers and processors established in Serbia, and to processing of data of subjects in Serbia by entities outside Serbia when offering goods or services or monitoring behaviour in Serbia.

Artefacts an auditor will ask for
  • Establishment review
  • Service targeting analysis for Serbia
  • Monitoring activities map
  • Cookie and tracking inventory
  • Representative appointment if required
Where this commonly fails
  • EU GDPR applied without Serbian specific assessment
  • Targeting tests overlooked
  • No Serbian representative appointed where needed
RS-DPL-2.1
Lawful Basis for Processing

Processing requires a lawful basis from the enumerated list (consent, contract, legal obligation, vital interests, public interest, legitimate interests), aligned with GDPR Article 6 equivalents.

Artefacts an auditor will ask for
  • Lawful basis register per activity
  • Legitimate interest balancing tests
  • Consent records
  • Contract necessity analysis
  • Legal references for obligations
Where this commonly fails
  • Consent applied to employment relationships inappropriately
  • Balancing tests absent or template only
  • Mixed bases not separated
RS-DPL-3.1
Consent Requirements

Where consent is the basis, it must be freely given, specific, informed, and unambiguous through a clear affirmative action, with the right to withdraw at any time as easily as it was given.

Artefacts an auditor will ask for
  • Consent screens with affirmative action
  • Consent records with timestamps
  • Withdrawal interface
  • Granular options
  • Demonstrability evidence per data subject
Where this commonly fails
  • Pre-ticked boxes used
  • Bundled consents
  • Withdrawal requires email rather than equivalent action
RS-DPL-6.1
Special Categories of Data

Processing of special categories (racial origin, political opinions, religious beliefs, trade union membership, genetic, biometric, health, sex life) is prohibited unless specific conditions apply including explicit consent and substantial public interest.

Artefacts an auditor will ask for
  • Special category register
  • Condition documentation per activity
  • Explicit consent records
  • Member state law basis
  • Enhanced security measures
Where this commonly fails
  • Biometrics processed without explicit consent
  • Health data conditions confused with general lawful basis
  • No additional protections for special categories

Serbia LPDP: Security and Breach Notification

RS-DPL-12.1
Personal Data Breach Notification to Commissioner

Controllers must notify the Commissioner of personal data breaches without undue delay and where feasible within 72 hours of becoming aware, unless the breach is unlikely to result in risk to rights and freedoms.

Artefacts an auditor will ask for
  • Breach register
  • 72 hour notification template
  • Risk assessment per breach
  • Notifications to Commissioner with receipts
  • Justifications for non-notification
Where this commonly fails
  • Discovery date documented unclearly
  • Risk assessment skipped
  • Late notifications without explanation
RS-DPL-12.2
Breach Notification to Data Subjects

Where a breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller must notify affected subjects without undue delay using clear and plain language.

Artefacts an auditor will ask for
  • Subject notification templates
  • Distribution records
  • Plain language reviews
  • Contact channels (email, post, public)
  • Helpline records
Where this commonly fails
  • High risk threshold misapplied
  • Notifications dense legal language
  • Channels not accessible to affected subjects
RS-DPL-14.1
Security of Processing

Controllers and processors must implement appropriate technical and organisational measures to ensure security appropriate to the risk, including pseudonymisation, encryption, confidentiality, integrity, availability, and resilience.

Artefacts an auditor will ask for
  • Security policy
  • Risk assessment outputs
  • Encryption inventory
  • Access control records
  • Resilience testing reports
Where this commonly fails
  • Controls not risk based
  • Encryption inconsistent
  • Resilience testing absent

Serbia LPDP: Supervision and Sanctions

RS-DPL-16.1
Commissioner Cooperation and Inspections

Controllers and processors must cooperate with the Commissioner for Information of Public Importance and Personal Data Protection, providing access to information, premises, and equipment during inspections.

Artefacts an auditor will ask for
  • Commissioner correspondence log
  • Inspection response packs
  • Site visit logs
  • Remediation plans agreed
  • Follow up evidence
Where this commonly fails
  • No central Commissioner contact log
  • Response packs incomplete
  • Remediation deadlines missed
RS-DPL-17.1
Sanctions and Administrative Fines

Entities are aware that administrative fines up to 2,000,000 RSD per infringement may apply, with additional liability for misdemeanours and remediation orders, requiring risk-based compliance prioritisation.

Artefacts an auditor will ask for
  • Compliance risk assessments
  • Board reporting on Commissioner enforcement trends
  • Insurance considerations
  • Past sanctions tracked
  • Budget for compliance remediation
Where this commonly fails
  • Board unaware of fine levels
  • No tracking of Commissioner decisions on peers
  • Remediation budget reactive

Serbia LPDP: Transparency and Data Subject Rights

RS-DPL-15.1
Automated Decisions and Profiling

Subjects have the right not to be subject to decisions based solely on automated processing including profiling that produce legal or similarly significant effects, except under specific conditions with safeguards.

Artefacts an auditor will ask for
  • Automated decision register
  • Human intervention procedures
  • Right to contest mechanism
  • Logic explanations
  • Lawful condition documentation per case
Where this commonly fails
  • Significant effect threshold underestimated
  • Human review nominal
  • Logic explanations generic
RS-DPL-4.1
Transparency and Information to Subjects

Controllers must provide subjects with concise, transparent, intelligible information about processing including identity, purposes, legal basis, recipients, retention, rights, and complaints to the Commissioner.

Artefacts an auditor will ask for
  • Privacy notice in Serbian
  • Layered notice design
  • Notice version control
  • Just in time prompts at sensitive collection points
  • Commissioner contact details included
Where this commonly fails
  • Notice in English only
  • Commissioner complaint pathway omitted
  • Legitimate interests not described
RS-DPL-5.1
Data Subject Rights

Subjects have rights of access, rectification, erasure, restriction, portability, objection, and rights related to automated decision making, with responses required within 30 days extendable by 60 days for complex requests.

Artefacts an auditor will ask for
  • Rights request procedure
  • Request log with deadlines
  • Extension notification templates
  • Refusal justification templates
  • Commissioner complaint signposting
Where this commonly fails
  • 30 day deadline missed without extension notice
  • Portability scope misunderstood
  • Erasure not propagated to backups in policy
RS-DPL-5.2
Right to Erasure and Restriction

Subjects may request erasure where data is no longer necessary, consent is withdrawn, processing is unlawful, or for compliance, and may request restriction during disputes or pending verification.

Artefacts an auditor will ask for
  • Erasure procedures across systems
  • Backup deletion or anonymisation approach
  • Restriction flagging in databases
  • Notification to recipients of erasure
  • Justification logs for refusals
Where this commonly fails
  • Erasure limited to primary systems
  • Restriction implemented as deletion
  • No notification to downstream recipients
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.