Rethinking Serbia’s Data Protection Framework: Key Issues in the New Draft Law

Rethinking Serbia’s Data Protection Framework: Key Issues in the New Draft Law

September 08, 2026

Public consultation is currently underway in Serbia on the Draft Law on Personal Data Protection, which is intended to replace the law currently in force since 2018. The public consultation will remain open until 10 September 2026, and as part of the consultation process, a roundtable discussion was also held, at which PR Legal was represented.

PR Legal has also submitted written comments and proposals to the Ministry of Justice, focusing in particular on provisions that may raise concerns in practice regarding legal certainty and the relationship between Serbian law and the GDPR framework.

Opportunity to Improve the Existing Framework

The current Serbian Law on Personal Data Protection (“LPDP”) is largely based on the GDPR. However, its incorporation into the Serbian legal system was not always adequately adapted to Serbian legal terminology and the existing regulatory framework. The adoption of a new law therefore presents an opportunity to address certain ambiguities, harmonise terminology and make the rules easier to apply in practice.

At the same time, the Draft goes a step further in certain areas by seeking to further define or modify concepts derived from the GDPR. This is precisely where particular caution is required. Departing from GDPR concepts, especially where their meaning has since been extensively developed through the practice of European institutions and supervisory authorities, may create new uncertainties in application rather than provide greater legal certainty.

Legitimate Interest – Clarification That May Narrow Its Application

One example is the new definition of legitimate interest. The Draft seeks to define this legal basis in greater detail by introducing additional conditions, including the nature of the interest, the existence of a pre-existing relationship with the individual and the absence of their consent.

This approach is problematic. Neither the current LPDP nor the GDPR makes legitimate interest conditional upon a pre-existing relationship between the controller and the individual. The existence of such a relationship may be relevant when assessing the individual’s reasonable expectations, but it should not constitute a prerequisite for relying on this legal basis.

It is particularly important that legitimate interest is not treated as a fallback legal basis to be used where consent has not been obtained. Consent and legitimate interest are separate and independent legal bases for processing, and the appropriate legal basis must be determined by the nature and circumstances of the specific processing activity.

Consent – Its Essential Elements Should Remain Clear

The proposed definition of consent also raises questions. The Draft departs from the well-established GDPR wording and does not include, within the definition itself, all the elements required for valid consent – namely, that it must be freely given, specific, informed and unambiguous.

PR Legal has therefore proposed retaining a clear definition that expressly incorporates these elements and makes it equally clear that silence, inactivity or a pre-ticked box cannot constitute valid consent.

Where concepts form part of the foundations of the entire data protection framework, changing established terminology without a clear need may create more problems than it resolves.

AI and Data Subject Rights

For the first time, the Draft also regulates in greater detail the processing of personal data using artificial intelligence systems, representing a significant development compared with the current LPDP. However, certain proposed solutions require further consideration.

Of particular concern is that, for certain processing activities involving the development and use of AI systems, the Draft excludes a range of data subject rights, including the rights to rectification, restriction of processing, erasure and data portability, as well as certain rights relating to automated decision-making. At the same time, the rights of access and objection are further restricted by a relatively broad criterion under which their exercise must not significantly hinder the achievement of the purpose of processing.

The development of specific rules for AI is undoubtedly necessary, but their introduction should not result in an unjustified reduction in the level of protection already afforded to individuals under general data protection rules.

Fines – A Mechanism Without a Basis in the Serbian Misdemeanour Law Framework

Another particularly problematic proposal concerns the new system of fines. In addition to the prescribed ranges of fines, the Draft provides that, for certain misdemeanours, a fine may be imposed in proportion to the amount of damage caused or the value of an unfulfilled obligation, up to twenty times the relevant amount.

However, there is no basis for introducing such a regime in the field of personal data protection under the Serbian Law on Misdemeanours. That law permits fines proportionate to the amount of damage caused, the value of an unfulfilled obligation or the value of the subject matter of the misdemeanour as an exception to the general system of prescribed ranges of fines, and limits this possibility to specifically identified areas (public revenue, public information, customs, foreign trade and foreign exchange operations, trade in goods and services, and securities trading). Personal data protection is not among the areas in which this method of determining fines is permitted.

Moreover, the proposed mechanism raises serious questions regarding its practical application. It is unclear how the value of an unfulfilled obligation could be determined where many data protection obligations have no monetary value – such as the obligation to provide information to data subjects, maintain records or conduct a data protection impact assessment. In addition, the damage caused is already one of the criteria for determining the amount of a fine, meaning that using it again as a mathematical basis for calculating the sanction could result in the same circumstance being taken into account twice.

The proposed system of fines therefore requires substantive reconsideration and alignment with the Serbian Law on Misdemeanours, rather than merely further clarification of the criteria for its application.

Alignment with the GDPR Without Creating New Uncertainties

The new law provides an opportunity to improve Serbia’s data protection framework based on almost eight years of experience with the current LPDP. This should include clearer terminology, the removal of ambiguities and better adaptation of the rules to the Serbian legal system.

At the same time, where the Serbian framework is based on the GDPR, the need to redefine its fundamental concepts should be carefully assessed. The objective should be to make the existing rules clearer and more workable in Serbia, without creating domestic versions of concepts that already have an established meaning and a developed body of practice within the European data protection framework.

PR Legal will continue to monitor the legislative process. In light of the upcoming parliamentary elections and the expected dynamics of the work of the National Assembly, adoption of the new law is not expected in the near term.

This article is for informational purposes only and does not constitute legal advice. Should you require any further information, please feel free to contact us.