The framework
Serbia's framework rests on the Law on Personal Data Protection, adopted in 2018, with the Commissioner for Information of Public Importance and Personal Data Protection as the supervisory authority.
That puts Serbia in the global opt-in majority, where permission comes before processing and marketing waits for consent.
Key instruments
Law on Personal Data Protection
Serbia copied the GDPR's structure into national law in 2018 as part of EU accession; the substance is familiar even if the fine ceilings are not. A draft replacement law published on 30 July 2026, grown from 102 to 175 articles with new AI and video-surveillance rules, finished public consultation in September.
Marketing and advertising
GDPR-modeled bases and consent standard. In practice that means consent before tracking or marketing outreach, documented well enough to show a regulator.
Cross-border transfers
GDPR-style: adequacy list, SCCs adopted by the Commissioner.
Enforcement and penalties
Fines reach RSD 2M per violation, low by EU standards; a draft law published in July 2026 would overhaul the regime.