Skip to content

Does GDPR apply in Serbia, and what does that mean for your website - Zephyra Studio

The short answer: not directly, but you likely need to follow almost the same rule anyway. Serbia has its own law, not GDPR itself, deliberately built to mirror it. This is NOT legal advice, for a final assessment of your specific situation consult a lawyer, but here is what actually applies, without the confusion that circulates online.

GDPR is an EU regulation - Serbia has its own, similar law

GDPR (General Data Protection Regulation) is an EU regulation that directly applies to businesses registered in the EU/EEA, or to businesses outside the EU that specifically monitor or sell goods/services to EU/EEA visitors (its extraterritorial scope, Article 3). A business registered solely in Serbia, serving only the Serbian market, is not formally a direct GDPR obligor.

But Serbia passed its own Law on Personal Data Protection in 2018 (Official Gazette of RS, No. 87/2018), in force since August 2019, deliberately aligned with GDPR: the same principles (transparency, purpose limitation, data minimisation, the right to access/correct/delete). This law applies to processing the data of people in Serbia, regardless of whether the processor is based domestically or abroad.

When you need both

If your site targets only the Serbian market and does not specifically track or sell to EU visitors, you are practically bound by the domestic Law on Personal Data Protection, not GDPR directly, but since the principles are nearly identical, whatever you do for one in practice covers the other.

If you have visitors or customers from the EU/EEA (selling beyond Serbia, running EU-market-facing content in multiple languages), GDPR's extraterritorial reach can bind you directly, not just the domestic law, in which case it is reasonable to treat both as applicable rather than picking one.

What this practically means for a website

Regardless of which of the two formally applies, the practical checklist is nearly the same: a clear privacy policy matching what you actually collect, consent BEFORE loading non-essential cookies, a clear mechanism for deletion/access requests, and newsletter sign-up with an active opt-in, never a pre-checked box.

The most common mistake we see is not missing these mechanisms, but a privacy policy copied from a foreign site that mentions GDPR articles but never mentions the domestic law at all - for a site targeting the Serbian market, that reads as unconvincing to a visitor who actually reads the fine print.

Source

Key takeaways

  • GDPR directly applies only to EU/EEA businesses or businesses specifically targeting EU visitors, not to every business worldwide.
  • Serbia has its own Law on Personal Data Protection (2018/2019), deliberately aligned with GDPR principles.
  • If you have both domestic and EU visitors, it is reasonable to treat both regulations as applicable, not pick just one.
  • The practical checklist (cookie consent, privacy policy, opt-in) is nearly identical regardless of which regulation formally applies.
  • This is general orientation, not legal advice, consult a lawyer for your specific situation.

Conclusion

The question "does GDPR apply in Serbia" almost always hides the real question: "do I need to do anything about visitor data". The answer to that second question is almost always yes, whether through the domestic law or GDPR directly. Our website builds include baseline compliance (cookie consent, a privacy policy matched to what is actually collected) as a standard part of the work, with a recommended legal review before launch for any site that also targets the EU market.

Frequently asked questions

The short answer: not directly, but you likely need to follow almost the same rule anyway. Serbia has its own law, not GDPR itself, deliberately built to mirror it. This is NOT legal advice, for a final assessment of your specific situation consult a lawyer, but here is what actually applies, without the confusion that circulates online.

Yes, the domestic Law on Personal Data Protection applies regardless of whether you have EU customers, as soon as you process the personal data of people in Serbia (email addresses, names, IP addresses through analytics).

Want to talk through your project?

Send a quick message or reach us on WhatsApp, no obligation. We will tell you honestly what you need and what you do not. If a website is not the answer to your problem, we will say that too.

Calculate your project price

No obligation. Reply within 24-48h.