
New Law on Personal Data Protection has been published in Official Gazette of BiH, No.12/25 and comes into force on March 8th 2025.
Bosnia and Herzegovina wants to come closer to European Union and adoption of Law that is harmonised with the General Data Protection Regulation (GDPR) was one of prerequisites to advancement of negotiation.
Law that was in force before the newly adopted offered weaker protection to data subjects.
The main novelties of the law are the introduction of new rights for data subjects, such as the right to erasure, restriction of processing and data portability.
Novelties
The GDPR demands that each Member State shall provide one or more independent public authorities to be responsible for monitoring the application of the regulation. In Bosnia and Herzegovina, the Personal Data Protection Agency was founded in 2008, but the new Law gives the expansion of the competences and powers of the Personal Data Protection Agency, which now gains the status of an independent supervisory body.
New topics like data protection impact assessments, codes of conduct and certification, the introduction of fines in administrative proceedings for greater efficiency, and special rules for data protection by competent authorities for the prevention and detection of criminal offences are also envisaged.
The Law regulates, among other things, the conditions for the consent of a child for information society services, the obligation to notify of personal data breaches, the establishment of a data protection officer and the accreditation of certification bodies, and the transfer of data according to adequacy decisions and binding business rules.
Extraterritorial applicability
The new Law on personal data protection shall apply, according to Article 6 if:
- a data controller or processor has its registered office or business establishment, permanent residence or temporary residence in Bosnia and Herzegovina, regardless of whether the processing is carried out in Bosnia and Herzegovina or not,
- processing of personal data of data subjects occurs in Bosnia and Herzegovina by a data controller or processor who does not have a registered office or business establishment, permanent residence or habitual residence in Bosnia and Herzegovina, if the processing activity is related to:
- offering goods or services to those data subjects in Bosnia and Herzegovina, regardless of whether the data subject is required to make a payment or
- monitoring the behavior of data subjects, provided that their behavior occurs within Bosnia and Herzegovina.
Representative
If Article 6, paragraph (2) of this Law applies, the data controller or processor shall be obliged to appoint its representative in Bosnia and Herzegovina.
The data controller or processor shall authorize a representative to, instead of addressing the data controller or processor separately, the Agency and the data subject address representative regarding all issues related to the processing of personal data in order to ensure compliance of the processing of personal data with the Law.
“Representative” is a natural or legal person with a place of residence or temporary place of residence, i.e. headquarters or place of business in Bosnia and Herzegovina, who was appointed in writing by the data controller or processor and it is point of contact with both the Agency and data subject.
Data Protection Officer (DPO)
Controller and processor are obliged to appoint DPO in cases:
- where the processing is carried out by a public authority, other than courts acting within the limits of their jurisdiction;
- where the core activities of the data controller or processor consist of processing operations which, by their nature, scope and/or purposes, require regular and systematic monitoring of data subjects on a large scale or
- where the core activities of the data controller or processor consist of the extensive processing of special categories of data and personal data relating to criminal convictions and offences.
DPO advises controller and/or processor, their employees, monitors compliance with the Law and collaborates with Agency.
Fines
Fines for non-compliance, and depending on the type of the breach, can come to up to 2% or 4% of of the total worldwide annual turnover of the preceding financial year or up to 40 million KM.
The Law will apply after the expiry of 210 days from the date of entry into force.
Companies that do business in Bosnia and Herzegovina should become aware of the new requirements that the Law on Personal Data Protection puts in front of them and react as soon as possible to appoint their representative and DPO.
Matea Maric, Compliance and Ethics Specialist
