Does GDPR apply in Serbia, and what does that mean for your website - Zephyra Studio
The short answer: not directly, but you likely need to follow almost the same rule anyway. Serbia has its own law, not GDPR itself, deliberately built to mirror it. This is NOT legal advice, for a final assessment of your specific situation consult a lawyer, but here is what actually applies, without the confusion that circulates online.
GDPR is an EU regulation - Serbia has its own, similar law
GDPR (General Data Protection Regulation) is an EU regulation that directly applies to businesses registered in the EU/EEA, or to businesses outside the EU that specifically monitor or sell goods/services to EU/EEA visitors (its extraterritorial scope, Article 3). A business registered solely in Serbia, serving only the Serbian market, is not formally a direct GDPR obligor.
But Serbia passed its own Law on Personal Data Protection in 2018 (Official Gazette of RS, No. 87/2018), in force since August 2019, deliberately aligned with GDPR: the same principles (transparency, purpose limitation, data minimisation, the right to access/correct/delete). This law applies to processing the data of people in Serbia, regardless of whether the processor is based domestically or abroad.
When you need both
If your site targets only the Serbian market and does not specifically track or sell to EU visitors, you are practically bound by the domestic Law on Personal Data Protection, not GDPR directly, but since the principles are nearly identical, whatever you do for one in practice covers the other.
If you have visitors or customers from the EU/EEA (selling beyond Serbia, running EU-market-facing content in multiple languages), GDPR's extraterritorial reach can bind you directly, not just the domestic law, in which case it is reasonable to treat both as applicable rather than picking one.
What this practically means for a website
Regardless of which of the two formally applies, the practical checklist is nearly the same: a clear privacy policy matching what you actually collect, consent BEFORE loading non-essential cookies, a clear mechanism for deletion/access requests, and newsletter sign-up with an active opt-in, never a pre-checked box.
The most common mistake we see is not missing these mechanisms, but a privacy policy copied from a foreign site that mentions GDPR articles but never mentions the domestic law at all - for a site targeting the Serbian market, that reads as unconvincing to a visitor who actually reads the fine print.
Source
Key takeaways
- GDPR directly applies only to EU/EEA businesses or businesses specifically targeting EU visitors, not to every business worldwide.
- Serbia has its own Law on Personal Data Protection (2018/2019), deliberately aligned with GDPR principles.
- If you have both domestic and EU visitors, it is reasonable to treat both regulations as applicable, not pick just one.
- The practical checklist (cookie consent, privacy policy, opt-in) is nearly identical regardless of which regulation formally applies.
- This is general orientation, not legal advice, consult a lawyer for your specific situation.
Conclusion
The question "does GDPR apply in Serbia" almost always hides the real question: "do I need to do anything about visitor data". The answer to that second question is almost always yes, whether through the domestic law or GDPR directly. Our website builds include baseline compliance (cookie consent, a privacy policy matched to what is actually collected) as a standard part of the work, with a recommended legal review before launch for any site that also targets the EU market.
Frequently asked questions
The short answer: not directly, but you likely need to follow almost the same rule anyway. Serbia has its own law, not GDPR itself, deliberately built to mirror it. This is NOT legal advice, for a final assessment of your specific situation consult a lawyer, but here is what actually applies, without the confusion that circulates online.