Serbia’s Draft Personal Data Protection Law: Major Expansion on AI, Surveillance and Transfers

Table of Contents

Serbia’s Ministry of Justice released a draft Law on Personal Data Protection on 30 July 2026 and opened public consultation through 10 September. The proposal would expand the current 2018 framework from 102 to 175 articles, restructure the statute, and introduce rules in areas the existing law never addressed.

While the text remains subject to revision, the draft signals closer alignment with core GDPR concepts while preserving Serbia’s more modest sanctions model.

Structural Split for Law Enforcement Processing

A recurring criticism of the 2018 law was that it mixed ordinary commercial and public-sector processing with rules governing law enforcement and national security activities (modeled on the EU Law Enforcement Directive). The new draft corrects this by dividing the statute into three distinct parts and placing processing by competent authorities for “special purposes” in its own dedicated section. The general regime applies only secondarily to those activities.

New Rules for Artificial Intelligence

For the first time, the draft expressly regulates personal data processing through AI systems. It distinguishes:

  • High-risk systems, which trigger a mandatory data protection impact assessment and a prior opinion from the Commissioner for Information of Public Importance and Personal Data Protection;
  • Systems that interact directly with individuals; and
  • Minimal-risk systems.

It also requires labeling of synthetically generated or modified audio and video content. Training AI models on a legitimate-interest basis is permitted only in exceptional cases where that interest clearly overrides the rights of data subjects.

Detailed Video Surveillance Regime

Equally new is a comprehensive set of rules covering video surveillance in business premises, residential buildings, and public areas. The draft introduces a general prohibition on monitoring employees’ work performance, subject only to narrow exceptions, and imposes a six-month maximum retention period for footage.

It further bans remote, mass, and indiscriminate biometric identification conducted through video surveillance systems—an explicit restriction absent from the 2018 law.

Legitimate Interest Clarified and Legal Bases Reordered

Legitimate interest already exists as a legal basis, but the draft supplies a statutory definition centered on necessity, suitability, proportionality, and the data subject’s reasonable expectations. The ordering of legal bases is also revised: compliance with legal obligations and performance of public-interest tasks now appear ahead of consent, and each basis receives its own dedicated article.

Special-category data rules are tightened. “Membership in a political entity” is expressly added to the list of sensitive data, and biometric processing based on consent must offer a less-intrusive alternative.

Modular Standard Contractual Clauses

One of the most practical changes concerns international transfers. Under the current law, standard contractual clauses cover only controller-to-processor transfers. The draft expands SCCs to all four relationships—controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller—mirroring the EU’s modular approach. It also places an express duty on the Commissioner to draft and publish the clauses in line with European practice.

Sanctions Remain Limited

The draft does not adopt GDPR-style turnover-based fines. The maximum fixed fine for legal entities stays at RSD 2 million. The minimum fine rises from RSD 50,000 to RSD 200,000. A new proportionality multiplier allows the fine to be increased up to 20 times the damage caused or the value of the unfulfilled obligation, but the total remains capped at five times the highest prescribed fine (approximately €85,000). The multiplier applies only where quantifiable harm or an unmet obligation can be shown.

Updated Remedies and Procedural Timeline

The remedies framework is reworked. A “complaint” now specifically concerns the exercise of data subject rights, while a broader “petition” covers alleged breaches of the law. Complaints will be handled under the general administrative procedure with a 60-day decision deadline, replacing the current reliance on the inspection-oversight framework.

Next Steps

Public consultation remains open until 10 September 2026. Provisions may still be added, modified, or removed. Overall, the draft moves Serbia closer to the GDPR’s structural and conceptual architecture—particularly on AI, video surveillance, legitimate interest, and modular transfer tools—while deliberately retaining a sanctions regime that stops well short of the EU’s maximum exposure levels.

Organizations processing personal data in or from Serbia should monitor the consultation closely and begin assessing how the proposed AI, surveillance, and transfer rules may affect their compliance programs once the final text is adopted.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.