What Is Law on Protection of Personal Data?
Bosnia and Herzegovina’s operative statute is the state-level Law on Protection of Personal Data, Official Gazette of BiH No. 12/25. It was adopted on 30 January 2025, published on 28 February 2025, and became operative after the publication period and a further 210-day application delay. It replaces the former 2006 law. No official post-enactment consolidated version or enacted amendment was located; a 23 June 2026 amendment proposal remains in procedure rather than enacted law. A distinctive structural finding is that personal-data protection is a unified state-level competency, not a fragmented Federation, Republika Srpska, and Brčko District system. One independent Agency has jurisdiction across the country, except for courts acting in their judicial function. The statute references GDPR and Directive 2016/680 for EU-acquis-alignment tracking, but those references do not make GDPR directly applicable.
At a glance
- Full name
- Law on Protection of Personal Data
- Short code
- Law 12/25
- Jurisdiction
- Bosnia and Herzegovina
- Enacted
- 2025
- Last major update
- Official Gazette of BiH No. 12/25 entered into operation after publication and a further 210-day application delay; no official post-enactment consolidated version or enacted amendment was located, and a 23 June 2026 amendment proposal remains in procedure
- Regulator
- Agency for the Protection of Personal Data in Bosnia and Herzegovina
- Private right of action
- Yes
- Statutory citation
- Law on Protection of Personal Data, Official Gazette of BiH No. 12/25
Scope, who Law 12/25 covers
Protected data
Data subject rights
Right to transparency and assistance
Right to information for direct and indirect collection
Right of access
Right to rectification
Right to erasure, subject to expression, legal-obligation, public-health, archiving, research, statistical, and legal-claims exceptions
Right to restriction of processing
Right to notification of third parties
Right to data portability for qualifying automated consent- or contract-based processing of subject-supplied data
Right to object, with an absolute objection to direct marketing
Protection against specified automated decisions
Right to complain, seek judicial review, use representation routes, and seek compensation
Notable features
The statute creates one unified state-level personal-data protection competency and one regulator across Bosnia and Herzegovina. It has separate ordinary and law-enforcement regimes, and its GDPR and Directive 2016/680 references are alignment references rather than direct application. The law is current and operative, but no official consolidated version or enacted amendment was located, while a 23 June 2026 amendment proposal remains in procedure.
Enforcement & penalties
Regulator: Agency for the Protection of Personal Data in Bosnia and Herzegovina
Penalties: Violations of Articles 10, 13, 27-41, and 44-45 may attract 10,000-20,000,000 KM, or 2% of worldwide turnover for entrepreneurs, whichever is higher. Unlawful processing under Articles 7-9 and 11, violations of Articles 14-24 rights, unlawful transfers under Articles 46-51, or non-compliance with Agency orders may attract 20,000-40,000,000 KM, or 4% of worldwide turnover, whichever is higher. Responsible persons may face 5,000-70,000 KM, and employees or specified public authorities 500-5,000 KM. Public or competent authorities themselves generally cannot be fined, though responsible-person or employee fines may still apply. The fine limitation period is five years.
Private right of action: The law provides judicial, representation, and compensation routes under Articles 108-112. An administrative dispute against an Agency decision has a 60-day deadline from receipt, while no fixed civil-action filing limitation was stated in the Law itself; separate civil-procedure rules apply.
Relevance to data brokers
Not located. No dedicated data-broker, people-search, or public-record-aggregator route was found. The general mechanisms identified are the Articles 14-24 rights and the Articles 108-112 complaint, judicial, representation, and compensation routes. Certain public registries appear among limited transfer derogations, but that is not a dedicated broker deletion mechanism.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is Bosnia and Herzegovina’s privacy system fragmented by entity?+
No. The law establishes a unified state-level personal-data protection competency with one statute and one Agency across the country, except for courts acting in their judicial function.
Do GDPR references make GDPR directly applicable in Bosnia and Herzegovina?+
No. The law states that its GDPR and Directive 2016/680 references are for EU-acquis-alignment tracking purposes only and do not make GDPR directly applicable.
How long does a controller generally have to answer a rights request?+
The ordinary response period is 30 days, extendable by up to 60 more days. For law-enforcement access, the response period is 30 days, and no extension provision was located.
Official sources & citations
Other international privacy regimes
Law 12/25 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
