What Is Law on Personal Data Protection, Official Gazette No. 87/2018?
Serbia’s operative privacy statute is the Law on Personal Data Protection, Official Gazette No. 87/2018, adopted on 9 November 2018 and published on 13 November 2018. Under Article 102, it entered into force eight days after publication and applies from 22 August 2019, nine months later. No amending instrument was located in the official current-law materials reviewed. A genuinely current, active finding is that a replacement Draft Law on Personal Data Protection was under official public consultation from 30 July to 10 September 2026. The draft had not itself replaced the operative 2018 law in the research record. The statute is GDPR-aligned in structure and provides consent withdrawal, transparency, access, rectification, erasure, restriction, portability, objection, automated-decision safeguards, complaints, judicial protection, and compensation routes. The Commissioner for Information of Public Importance and Personal Data Protection is an independent state authority. Serbia’s law remains a domestic Serbian statute rather than the EU GDPR itself, and its penalties use specified RSD amounts rather than the EU GDPR’s worldwide-turnover formula.
At a glance
- Full name
- Law on Personal Data Protection, Official Gazette No. 87/2018
- Short code
- Law 87/2018
- Jurisdiction
- Serbia
- Enacted
- 2018
- Last major update
- A replacement Draft Law on Personal Data Protection was under official public consultation from 30 July to 10 September 2026; it had not replaced the operative 2018 law in the 28 August 2026 research record
- Regulator
- Commissioner for Information of Public Importance and Personal Data Protection
- Private right of action
- Limited
- Statutory citation
- Law on Personal Data Protection, Official Gazette No. 87/2018
Scope, who Law 87/2018 covers
Protected data
Data subject rights
Right to withdraw consent at any time, without retroactively affecting the lawfulness of prior processing
Right to information and transparency for direct and indirect collection
Right of access to confirmation, copies, purposes, categories, recipients, retention, sources, transfers, and automated-decision information
Right to rectification and completion
Right to erasure on specified grounds, subject to statutory exceptions
Right to restriction of processing
Right to data portability for subject-supplied data processed by automated means on consent or contract grounds
Right to object to public-interest or legitimate-interest processing, with an absolute objection to direct marketing and profiling
Protection against specified automated decisions
Right to complain to the Commissioner
Right to judicial protection, representation, and compensation
Notable features
The law follows a GDPR-aligned structure while remaining Serbian domestic law. Its currentness issue is the active replacement Draft Law consultation spanning 30 July to 10 September 2026. The statute uses RSD-denominated penalties rather than a GDPR-style turnover percentage.
Enforcement & penalties
Regulator: Commissioner for Information of Public Importance and Personal Data Protection
Penalties: Article 95 provides RSD 50,000-2,000,000 fines for a legal-person controller or processor for Article 95(1) violations, RSD 20,000-500,000 for an entrepreneur, and RSD 5,000-150,000 for a responsible individual. Article 95(2) violations carry fixed fines of RSD 100,000 for a legal-person controller or processor, RSD 50,000 for an entrepreneur, and RSD 20,000 for a responsible individual. The statute does not use the EU GDPR’s 4% of worldwide-turnover penalty formula.
Private right of action: Judicial protection, representation, and compensation routes exist under Articles 83-86, alongside a 60-day route to an administrative dispute for Commissioner inaction and a 30-day period for a lawsuit against a Commissioner decision. No fixed deadline was located for direct court protection against a controller or processor.
Relevance to data brokers
No Serbia-specific data-broker complaint, deletion channel, or dedicated public-record removal procedure was located. The general route is to request access, rectification, erasure, restriction, portability, or objection from the controller and then complain to the Commissioner under Article 82 if necessary. Article 69(1)(7) mentions public-register transfers as a transfer exception, not as a dedicated public-record deletion or complaint route.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is Serbia’s 2018 personal-data law still operative?+
Yes, based on the reviewed materials. The Law on Personal Data Protection, Official Gazette No. 87/2018, applies from 22 August 2019. A replacement draft was under official public consultation from 30 July to 10 September 2026, but had not replaced the operative 2018 law in the research record.
Does Serbia have a dedicated data-broker deletion route?+
No Serbia-specific data-broker complaint, deletion channel, or dedicated public-record removal procedure was located. The general route is to request the relevant rights from the controller and complain to the Commissioner if necessary.
How long does a Serbian controller have to respond to an ordinary rights request?+
The controller ordinarily must respond within 30 days. The period may be extended by up to 60 additional days, with the data subject informed during the initial period.
Official sources & citations
Other international privacy regimes
Law 87/2018 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
