Cookie law in Serbia: what actually exists and what is a common mix-up - Zephyra Studio
The first thing to clarify: Serbia does NOT have a separate, named "cookie law" the way the EU has the ePrivacy Directive. The obligation to get consent for cookies in Serbia comes from the general Law on Personal Data Protection, not a dedicated cookie regulation. This is NOT legal advice, consult a lawyer for your specific situation.
Why there is no separate law, yet the obligation still exists
The European Union has a dedicated ePrivacy Directive that explicitly regulates cookies (often called the "cookie law" colloquially). Serbia has not directly adopted that directive as a standalone regulation. Instead, a cookie that identifies an individual visitor (analytics, advertising, social media) is treated as personal data processing under the general Law on Personal Data Protection, the same principle, just without a dedicated named law for the cookie technology itself.
The practical consequence is the same as if a dedicated law existed: a cookie that collects or links data to an individual needs a legal basis for processing, and the usual basis for non-essential cookies (analytics, marketing) is consent, not "legitimate interest", the same standard as the EU ePrivacy rules, just applied through the general data law instead of a dedicated cookie regulation.
Essential versus non-essential cookies
Essential cookies (a login session, cart contents, a language choice) are necessary for a function the visitor themselves requested and generally do not need separate consent. Non-essential cookies (Google Analytics, the Facebook Pixel, marketing tools) collect data beyond what the visitor asked for, and consent is the standard, safe approach for them.
A technical detail that is often gotten wrong: non-essential cookies must not load BEFORE consent. A banner that shows up while scripts already run in the background does not fulfil the obligation, it just makes it visible.
What this means for a site also targeting the EU market
If your site has visitors from the EU/EEA, the EU's ePrivacy rules (which ARE a dedicated, named regulation) can apply directly to those visitors, regardless of Serbia lacking its own equivalent. In that case it is reasonable to apply the EU standard (explicit consent, rejecting as easy as accepting) across the WHOLE site, not just the EU share of traffic, simpler to implement and safer than trying to split behaviour by visitor location.
Source
Key takeaways
- Serbia has no separate, named "cookie law", the obligation comes from the general Law on Personal Data Protection.
- The practical outcome is the same as if a dedicated law existed: non-essential cookies need consent.
- Essential cookies (session, cart, language) generally do not need separate consent.
- Non-essential cookies must not load before consent, a common technical mistake, not just a legal one.
- A site with EU visitors is safest applying the EU consent standard across the whole site, not just the EU share of traffic.
Conclusion
The absence of a dedicated "cookie law" in Serbia does not mean the absence of an obligation, it just means that obligation is read from the general data protection law rather than a dedicated regulation. Our website builds include a correctly set up cookie consent flow (consent before loading, rejecting as easy as accepting) as a standard part of the work.
Frequently asked questions
The first thing to clarify: Serbia does NOT have a separate, named "cookie law" the way the EU has the ePrivacy Directive. The obligation to get consent for cookies in Serbia comes from the general Law on Personal Data Protection, not a dedicated cookie regulation. This is NOT legal advice, consult a lawyer for your specific situation.