Serbia Law on Personal Data Protection (2018)
Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Breach
Per Serbia Law: 72-hr breach + enforcement.
- Serbia evidence for SERBIA-5
- DPO + Commissioner partial
Governance
Per Serbia Law: DPO + RoPA + governance.
- Serbia evidence for SERBIA-4
- DPO + Commissioner partial
Rights
Per Serbia Law: standard GDPR consent + notice + rights.
- Serbia evidence for SERBIA-2
- DPO + Commissioner partial
Scope
Per Serbia Law on Personal Data Protection 2018 implementing GDPR: scope + lawful basis. Align with Commissioner for Information of Public Importance and Personal Data Protection.
- Serbia evidence for SERBIA-1
- DPO + Commissioner partial
Security
Per Serbia Law: standard GDPR security + cross-border with Commissioner approval.
- Serbia evidence for SERBIA-3
- DPO + Commissioner partial
Serbia LPDP: Accountability and Records
Public bodies, controllers with core activities involving large scale regular and systematic monitoring, or large scale special category processing must designate a DPO with sufficient expertise and independence.
- DPO appointment record
- Commissioner notification
- Reporting line to highest management
- Independence statement
- Resource allocation
- Tasks under Article 58 documented
- DPO role combined with conflicting role
- Reports to mid level management
- Tasks performed without independence
Engagement of processors requires a written contract containing prescribed terms including subject matter, duration, nature and purpose, types of data, controller obligations, and processor obligations.
- DPA template aligned with Article 45
- Signed DPAs per processor
- Sub processor approval workflow
- Audit rights exercised
- Termination data return or deletion evidence
- DPAs missing prescribed terms
- Sub processors not notified
- Audit rights never exercised
Controllers must implement appropriate technical and organisational measures at the time of determining means of processing and during processing, and by default only process data necessary for each purpose.
- Privacy by design framework
- Default minimisation settings evidence
- DPIA outcomes integrated into design
- Pseudonymisation use cases
- Architecture diagrams with privacy controls
- Privacy considered only at launch
- Defaults set to maximum collection
- Pseudonymisation theoretical not implemented
Controllers and processors with 250 or more employees, or where processing is not occasional or includes special categories, must maintain records of processing activities with prescribed content.
- ROPA documents per Article 47
- Annual ROPA review records
- Linked DPIAs
- Processor ROPA inputs
- Provision to Commissioner on request evidence
- ROPA created but not updated
- Categories of recipients generic
- Cross border transfers missing safeguards documentation
A DPIA is required where processing is likely to result in high risk to rights and freedoms, particularly for systematic and extensive profiling, large scale processing of special categories, or systematic monitoring of publicly accessible areas.
- DPIA methodology
- DPIA register
- Threshold assessments
- Stakeholder consultation records
- Prior consultation with Commissioner where high residual risk
- Threshold assessments skipped
- DPIAs treated as documentation exercise
- Prior consultation not requested where required
Serbia LPDP: Cross-Border Transfers
Transfers outside Serbia require adequacy decision, appropriate safeguards (standard contractual clauses, binding corporate rules), or derogations for specific situations, with documentation of mechanism used.
- Transfer mechanism inventory
- SCCs signed and stored
- BCR approvals
- Adequacy reliance documentation
- Transfer impact assessments
- EU SCCs adopted without Serbian compatibility review
- Adequacy reliance assumed without Serbian list
- TIAs missing for high risk destinations
Transfers may rely on Government adequacy decisions or, in their absence, on Commissioner authorised safeguards or derogations, requiring documentation of the basis used.
- Government adequacy list reference
- Commissioner authorisations for specific transfers
- Derogation justifications
- Documentation in ROPA
- Subject information about transfers
- Authorisation expired or scope exceeded
- Derogations used as routine basis
- Subjects not informed of transfers
Controllers and processors not established in Serbia but subject to the law must designate in writing a representative in Serbia, unless processing is occasional and does not involve large scale special categories.
- Representative appointment letter
- Contact details published
- Mandate scope
- Communication evidence with subjects and Commissioner
- Exemption analysis if applicable
- Representative not designated where required
- Contact details not published
- Exemption assumed without analysis
Serbia LPDP: Scope and Lawful Basis
The law applies to processing of personal data by controllers and processors established in Serbia, and to processing of data of subjects in Serbia by entities outside Serbia when offering goods or services or monitoring behaviour in Serbia.
- Establishment review
- Service targeting analysis for Serbia
- Monitoring activities map
- Cookie and tracking inventory
- Representative appointment if required
- EU GDPR applied without Serbian specific assessment
- Targeting tests overlooked
- No Serbian representative appointed where needed
Processing requires a lawful basis from the enumerated list (consent, contract, legal obligation, vital interests, public interest, legitimate interests), aligned with GDPR Article 6 equivalents.
- Lawful basis register per activity
- Legitimate interest balancing tests
- Consent records
- Contract necessity analysis
- Legal references for obligations
- Consent applied to employment relationships inappropriately
- Balancing tests absent or template only
- Mixed bases not separated
Where consent is the basis, it must be freely given, specific, informed, and unambiguous through a clear affirmative action, with the right to withdraw at any time as easily as it was given.
- Consent screens with affirmative action
- Consent records with timestamps
- Withdrawal interface
- Granular options
- Demonstrability evidence per data subject
- Pre-ticked boxes used
- Bundled consents
- Withdrawal requires email rather than equivalent action
Processing of special categories (racial origin, political opinions, religious beliefs, trade union membership, genetic, biometric, health, sex life) is prohibited unless specific conditions apply including explicit consent and substantial public interest.
- Special category register
- Condition documentation per activity
- Explicit consent records
- Member state law basis
- Enhanced security measures
- Biometrics processed without explicit consent
- Health data conditions confused with general lawful basis
- No additional protections for special categories
Serbia LPDP: Security and Breach Notification
Controllers must notify the Commissioner of personal data breaches without undue delay and where feasible within 72 hours of becoming aware, unless the breach is unlikely to result in risk to rights and freedoms.
- Breach register
- 72 hour notification template
- Risk assessment per breach
- Notifications to Commissioner with receipts
- Justifications for non-notification
- Discovery date documented unclearly
- Risk assessment skipped
- Late notifications without explanation
Where a breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller must notify affected subjects without undue delay using clear and plain language.
- Subject notification templates
- Distribution records
- Plain language reviews
- Contact channels (email, post, public)
- Helpline records
- High risk threshold misapplied
- Notifications dense legal language
- Channels not accessible to affected subjects
Controllers and processors must implement appropriate technical and organisational measures to ensure security appropriate to the risk, including pseudonymisation, encryption, confidentiality, integrity, availability, and resilience.
- Security policy
- Risk assessment outputs
- Encryption inventory
- Access control records
- Resilience testing reports
- Controls not risk based
- Encryption inconsistent
- Resilience testing absent
Serbia LPDP: Supervision and Sanctions
Controllers and processors must cooperate with the Commissioner for Information of Public Importance and Personal Data Protection, providing access to information, premises, and equipment during inspections.
- Commissioner correspondence log
- Inspection response packs
- Site visit logs
- Remediation plans agreed
- Follow up evidence
- No central Commissioner contact log
- Response packs incomplete
- Remediation deadlines missed
Entities are aware that administrative fines up to 2,000,000 RSD per infringement may apply, with additional liability for misdemeanours and remediation orders, requiring risk-based compliance prioritisation.
- Compliance risk assessments
- Board reporting on Commissioner enforcement trends
- Insurance considerations
- Past sanctions tracked
- Budget for compliance remediation
- Board unaware of fine levels
- No tracking of Commissioner decisions on peers
- Remediation budget reactive
Serbia LPDP: Transparency and Data Subject Rights
Subjects have the right not to be subject to decisions based solely on automated processing including profiling that produce legal or similarly significant effects, except under specific conditions with safeguards.
- Automated decision register
- Human intervention procedures
- Right to contest mechanism
- Logic explanations
- Lawful condition documentation per case
- Significant effect threshold underestimated
- Human review nominal
- Logic explanations generic
Controllers must provide subjects with concise, transparent, intelligible information about processing including identity, purposes, legal basis, recipients, retention, rights, and complaints to the Commissioner.
- Privacy notice in Serbian
- Layered notice design
- Notice version control
- Just in time prompts at sensitive collection points
- Commissioner contact details included
- Notice in English only
- Commissioner complaint pathway omitted
- Legitimate interests not described
Subjects have rights of access, rectification, erasure, restriction, portability, objection, and rights related to automated decision making, with responses required within 30 days extendable by 60 days for complex requests.
- Rights request procedure
- Request log with deadlines
- Extension notification templates
- Refusal justification templates
- Commissioner complaint signposting
- 30 day deadline missed without extension notice
- Portability scope misunderstood
- Erasure not propagated to backups in policy
Subjects may request erasure where data is no longer necessary, consent is withdrawn, processing is unlawful, or for compliance, and may request restriction during disputes or pending verification.
- Erasure procedures across systems
- Backup deletion or anonymisation approach
- Restriction flagging in databases
- Notification to recipients of erasure
- Justification logs for refusals
- Erasure limited to primary systems
- Restriction implemented as deletion
- No notification to downstream recipients
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.