Data Protection Atlas

Serbia

Tier 3 Comprehensive law Europe

Principal framework: Law on Personal Data Protection (GDPR-modelled) (2018). Regulator: Poverenik (Commissioner). The 2018 law copies the GDPR closely but kept low national fine caps; a new draft aims to close that gap as part of EU accession.

At a glance

Principal law
Law on Personal Data Protection (GDPR-modelled)
Regulator
Poverenik (Commissioner)
Breach notification
72 hours to the Commissioner
Maximum penalty
Misdemeanour-level fines only (about RSD 2m cap) — a known gap
DPO required
Required in GDPR-like cases
Digital consent age
15 for information-society services
Extraterritorial reach
Yes — GDPR-style targeting test

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
RS

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

No instrument profiled yet.

Sources

No source recorded yet. This record cannot rise above Tier 3 until it has one — see depth tiers.

Never independently verified — seeded from the prototype.