Serbia’s Draft Personal Data Protection Law: What Controllers and Processors Need to Know Before 10 September – and How It Fits Alongside the EU AI Act 

Serbia’s Draft Personal Data Protection Law: What Controllers and Processors Need to Know Before 10 September – and How It Fits Alongside the EU AI Act 

24.08.2026.

On 30 July 2026, Serbia’s Ministry of Justice published a Draft Law on Personal Data Protection, which substantially expands and redesigns the framework established in 2018 – growing from 102 to 175 articles. The public consultation runs until 10 September 2026. For controllers and processors operating in or into the Serbian market, this is the first time the domestic legal framework has explicitly addressed the processing of personal data through artificial intelligence systems – and it arrives at almost the same moment the European regulatory framework for AI is itself in motion. To give a fuller picture of the obligations ahead, this piece first examines the Draft’s key changes, then turns to how they relate to the EU AI Act.

What the Draft changes? 

Processing through AI systems (Arts. 52-53) 

For the first time, the Draft explicitly regulates the processing of personal data through artificial intelligence systems, following a trend the European Union began with the AI Act. It introduces a mandatory data protection impact assessment for high-risk systems, a duty to inform individuals when a system communicates with them directly, and a prohibition on fully automated processing, without human involvement, where such processing may produce harmful consequences for the individual. This last provision matters particularly for controllers using automated decision-making systems (for example, in hiring, lending, or customer scoring), since it requires human involvement whenever the outcome of processing could be harmful to the individual concerned.

Video surveillance (Arts. 45, 48) 

Video surveillance receives systematic regulation for the first time: footage may be retained for a maximum of six months, and the use of video surveillance to monitor employees is permitted only in exceptional, clearly defined circumstances. Employers currently applying longer retention periods or systematically monitoring staff by camera without a clearly defined and legitimate basis, will need to revisit existing practice. 

Legitimate interest (Art. 4, item 36) 

The Draft provides a statutory definition of legitimate interest for the first time – a real, concrete, and lawfully permissible interest of the controller or a third party, of either a business or a broader societal nature. A more precise definition brings greater legal certainty for controllers, but also a higher evidentiary burden for those currently relying on legitimate interest as a legal basis.

What is further mentioned?

According to available analyses of the Draft, an expansion of special categories of data, an explicit ban on mass biometric identification, and penalties that remain below GDPR levels.

How this relates to the EU AI Act?

The Draft does not emerge in a legal vacuum. Its AI-related provisions conceptually follow the approach already established at EU level by the AI Act – risk-based categorization of systems, impact assessment obligations for high-risk systems, and transparency duties toward users. The difference lies in timing.

The transparency obligations under Article 50 of the AI Act – the duty to inform a user that they are interacting with an AI system rather than a person – became binding on 2 August 2026, on schedule. By contrast, the stricter compliance deadlines for high-risk systems were postponed under the May 2026 Omnibus Agreement, since formally adopted as Regulation (EU) 2026/1744, published in the Official Journal of the European Union on 24 July 2026 and in force as of 27 July 2026. For stand-alone high-risk systems (Annex III), the new deadline is 2 December 2027; for AI embedded in regulated products (Annex I), it is 2 August 2028.

The practical consequence for businesses operating both in Serbia and toward the EU: while the EU’s high-risk deadlines now allow more time to prepare, Serbia’s Draft sets no comparable runway; the public consultation closes on 10 September 2026, and adoption of the law could follow within a relatively short period afterward. For companies whose AI systems process the data of customers or employees in Serbia, the nearer and more pressing regulatory challenge currently comes from the domestic framework, not the European one – even though both frameworks, over the longer term, are moving in the same direction.

Practical steps 

This is the right moment for controllers and processors to begin aligning their internal policies and procedures with the changes ahead, particularly around AI systems and video surveillance, where existing practice is most affected. Companies that have already begun aligning with the EU AI Act have something of a head start, given the conceptual similarity of approach, but compliance with one framework does not automatically mean compliance with the other. Comments can still be submitted to the Ministry of Justice as part of the public consultation until 10 September 2026. 

This text is informational in nature and does not constitute legal advice. 

Scroll