Comments on the Draft Law On Personal Data Protection with Proposed Amendments

Below is my commentary on the recently published Draft Law on Personal Data Protection, which I submitted to the Ministry of Justice as part of the public consultation process.

I submitted these comments in my capacity as a citizen. They do not represent the views of my employer, but rather my own independent opinion, given my familiarity with this area.

Given the importance of personal data protection for the exercise of fundamental rights and freedoms, as well as the increasing scale and complexity of data processing resulting from the emergence of new technologies, which are also addressed by the Draft Law, I believe that, when adopting the new law, particular attention should be paid to ensuring that the proposed solutions are sustainable in the long term and sufficiently flexible to address forms of processing that are not yet widespread today.

In this regard, the comments below focus primarily on several issues that I consider essential to the effectiveness of the future system: the territorial scope of application of the law, the principle of technological neutrality, restrictions on video surveillance, the proper definition of legitimate interest, and the establishment of an effective, proportionate and dissuasive system of sanctions.

1. Territorial Scope of Application of the Law – Article 3

The Draft Law proposes a departure from the solution contained in the current law, which, in this respect, adopted the approach set out in the GDPR. Under the Draft Law, the territorial scope of application is linked to processing carried out “within the framework of activities on the territory of the Republic of Serbia.”

This formulation does not adequately reflect the modern manner in which personal data are processed, as it essentially makes the application of the law dependent on the existence of activities of the controller or processor in the territory of the Republic of Serbia. As a result, entities that have neither a registered office nor a physical presence in Serbia, but offer goods and services to Serbian citizens, monitor their behaviour, carry out profiling, or otherwise process their personal data, including for the purposes of developing and improving artificial intelligence systems, may fall outside the scope of the law. This is particularly problematic.

This is precisely why the GDPR provides for extraterritorial application to controllers and processors that do not have an “establishment” in the EU, where they process personal data in connection with the offering of goods or services to individuals in the EU or the monitoring of their behaviour. Removing a similar provision from the current law creates a risk of a regulatory gap, as well as the possibility of circumventing the application of the law through the formal relocation or reorganisation of business operations outside the territory of the Republic of Serbia.

I therefore propose that the territorial scope of application under the new law should not be narrowed compared to the current solution, and that Article 3, insofar as relevant, should be retained as in Article 3 of the current Law, in the following wording:

This Law applies to the processing of personal data performed by a controller and/or processor with the seat and/or domicile or habitual residence in the territory of the Republic of Serbia in the course of activities performed in the territory of the Republic of Serbia, irrespective of whether the processing activity is performed in the territory of the Republic of Serbia or not.

This Law applies to the processing of personal data of data subjects who have their domiciles and/or habitual residence in the territory of the Republic of Serbia by a controller and/or processor who do not have their seat and/or domicile or habitual residence in the territory of the Republic of Serbia if the processing activities are related to:

1) the offering of goods and/or services, irrespective of whether or not a payment from the data subject is required for such goods and/or services, to such data subjects in the territory of the Republic of Serbia;

2) the monitoring of activities of the data subjects, as far as their activities occur within the Republic of Serbia.

2. Technological Neutrality as a Fundamental Principle

One of the significant advantages of the GDPR, which continues to make it a relevant regulatory framework without the need for substantive amendments, is the principle of technological neutrality.

The provisions of the GDPR are designed to apply to the processing of personal data regardless of the technology used by controllers and processors. The central question is whether personal data are being processed and what the consequences of such processing are, including the risks it poses to the rights and freedoms of data subjects.

Thanks to this approach, the same rules under the GDPR remain relevant as technology evolves, which is of particular importance in the context of rapid technological development.

In this way, the GDPR remains a relevant regulatory framework that can be applied without constant amendments and without the need to determine whether a particular new technology falls within its scope of application.

The Draft Law, however, not only recognises but also regulates in detail certain technologies, such as artificial intelligence and video surveillance.

Although this represents a significant step forward and will provide greater clarity regarding the application of the law to the technologies expressly addressed, it may also create significant risks.

If a technology emerges that is not regulated by the law, the processing of personal data using such technology would remain outside the explicit regulatory framework until the law is potentially amended to cover it. This could potentially lead to abuses and significant risks for data subjects.

An additional problem may arise from potential conflicts between the new Personal Data Protection Law and laws that constitute lex specialis in particular areas, such as the announced Law on Artificial Intelligence, as well as other legislation, such as the Law on Information Security, particularly as those laws and their implementing regulations are themselves amended over time.

In this regard, if the approach of specifically regulating certain technologies is retained, I propose adding a general provision clarifying that the provisions of the law shall apply irrespective of the technology, means, or technical architecture through which the processing of personal data is carried out.

In addition, it would be advisable to clarify that provisions relating to specific forms of personal data processing constitute a specification of the fundamental principles of the law and do not exclude the application of other provisions of the law to technologies and processing methods that are not specifically regulated.

This approach would make it clear to controllers and processors that the new law will also apply to technologies that are not expressly listed, while technologies that are specifically regulated would be subject to additional rules primarily due to the frequency of their use or the specific risks they entail.

3. Video Surveillance

The Draft Law regulates video surveillance in detail, and the explicit limitation of its use is commendable. Below, I would like to offer a suggestion regarding the retention periods for video recordings.

Article 45, paragraph 4 of the Draft Law provides as follows:

“Recordings obtained through video surveillance systems shall be retained for a maximum period of six months*, unless a longer retention period is prescribed by another law or where such recordings constitute evidence in proceedings regulated by law.”*

I propose that the maximum retention period of six months should expressly apply only as an exception, while the principle of storage limitation should be incorporated into the provision itself, as follows:

“Recordings obtained through video surveillance systems shall be retained only for as long as necessary to achieve the specific purpose of the processing, and in any event for no longer than three months, unless a longer retention period is prescribed by another law or where such recordings constitute evidence in proceedings regulated by law.”

The EDPB Guidelines 3/2019 provide for a period of 24–72 hours as the gold standard for the retention of video recordings. I therefore propose reducing the maximum retention period to three months, while ensuring that such a period is used only exceptionally.

4. Legitimate Interest – An Overly Narrow Definition

In Article 4, paragraph 1, item 36, the Draft Law defines legitimate interest as follows:

“36) ‘legitimate interest’ means a real, specific and legally permissible interest of the controller or a third party, of a business or broader societal nature, to process the personal data of a natural person within the framework of an established relationship with that natural person, including the transfer thereof to a third party, without obtaining the consent of that person, while respecting the principles of necessity, suitability and proportionality in relation to the achievement of the purpose of the processing (prevention of fraud, information security protection, etc.), provided that the interests or fundamental rights and freedoms of the data subject do not override such interest, taking into account the reasonable expectations of such persons based on their relationship with the controller.”

A definition of legitimate interest that is limited to an established relationship with a natural person is too narrow and is inconsistent with the approach set out in the guidance of the European Data Protection Board and the recitals of the GDPR.

Restricting the definition to an established relationship with a natural person would make the lawful processing of personal data more difficult in a number of common situations, such as pursuing claims for damages against third parties (as illustrated by the well-known Rīgas satiksme, C-13/16, case before the Court of Justice of the European Union), where no pre-existing relationship exists and the processing is neither of a business nor broader societal nature (in that particular case, the matter concerned damage to a company vehicle).

In addition, Recital 47 of the GDPR expressly provides that the processing of personal data for the purposes of direct marketing may be regarded as carried out for a legitimate interest. In certain situations, this is incompatible with the Draft Law provision, which appears to require that a relationship with the data subject must already have been established.

For this purpose, I propose amending Article 4, paragraph 1, item 36 of the Draft Law so that the definition of legitimate interest reads as follows:

“36) ‘legitimate interest’ means a real, specific and legally permissible interest of the controller or a third party, of a business or broader societal nature, in the processing of the personal data of a natural person, including the transfer thereof to a third party, without obtaining the consent of that person, while respecting the principles of necessity, suitability and proportionality in relation to the achievement of the purpose of the processing (prevention of fraud, information security protection, etc.), provided that the interests or fundamental rights and freedoms of the data subject do not override such interest, taking into account all the circumstances of the specific processing operation and the reasonable expectations of the data subject.”

5. Penalty Provisions

Although the explanatory memorandum to the Draft Law states that the existing system of misdemeanour and criminal sanctions is inadequate and ineffective, the Draft Law essentially retains the existing enforcement model, with relatively limited amendments.

One of the key reasons for the effectiveness of the sanctioning system established by the GDPR is not only the amount of the administrative fines, which for the most serious infringements may reach up to EUR 20 million or 4% of the total worldwide annual turnover, whichever is higher, but also the very nature of those sanctions. These are administrative fines that may be imposed by the supervisory authority within the scope of its statutory powers, thereby enabling more direct and effective sanctioning of controllers and processors that fail to comply with their obligations in the area of personal data protection.

The essence of the GDPR sanctioning system lies in the principle of effective, proportionate and dissuasive economic penalties. The amount of a sanction is not an end in itself, but rather a means of ensuring that non-compliance with the law is not economically more advantageous than compliance.

It is commendable that the Draft Law regulates in greater detail the criteria for determining the amount of a particular fine. However, the fundamental problem remains the fact that the system of misdemeanour penalties is still retained, which requires the conduct of misdemeanour proceedings, with all the limitations that such proceedings entail in terms of the speed and effectiveness of enforcement.

At the same time, the range of prescribed fines has been increased only marginally. Increasing the minimum fine from RSD 50,000 to RSD 200,000, in itself, is unlikely to produce a genuine deterrent effect, particularly in relation to large business entities.

The Draft Law introduces the possibility of imposing a fine proportionate to the amount of damage caused or the value of an unfulfilled obligation constituting the subject matter of the misdemeanour, up to twenty times those amounts, provided that the fine may not exceed five times the maximum fine that may be imposed under the relevant provision of the law. Although this provision formally allows for higher fines to be imposed, its application raises concerns regarding legal certainty, given the lack of clarity concerning the criteria on the basis of which the “amount of damage caused” or the value of the “unfulfilled obligation” would be determined, as well as their direct connection to the specific misdemeanour.

Even where the maximum possible increase is applied, the maximum fine of RSD 10,000,000 remains incomparably lower than the sanctions available under the GDPR system. Such an approach does not ensure an equally dissuasive effect across different categories of controllers and processors. On the contrary, a system of fines subject to fixed monetary limits may have a disproportionately greater impact on small and medium-sized domestic controllers and processors, while, for the largest, particularly multinational companies, the maximum fine may represent a negligible business expense.

For these reasons, I propose that the sanctioning system be comprehensively reconsidered and amended. Countries in the region, such as Montenegro and Bosnia and Herzegovina, have adopted solutions similar to those provided for under the GDPR.

Furthermore, the domestic legal framework already recognises a model of administrative enforcement based on imposing monetary sanctions proportionate to the revenue of a legal entity. Such an approach exists, among other areas, in competition law, where the Commission for the Protection of Competition may impose a measure amounting to up to 10% of the total annual turnover of an undertaking participating in the market, as well as in other areas in which supervisory authorities, such as the National Bank of Serbia, have powers to impose administrative sanctions.

This approach to enforcement would give the Commissioner for Information of Public Importance and Personal Data Protection a genuine ability to influence compliance with the law, while the fines would primarily serve a deterrent function that could facilitate substantive compliance, which is not the case under the existing system of misdemeanour penalties.

Conclusion

The Draft Law presents an opportunity to further improve the personal data protection framework and adapt it to current and future technological developments, as well as to relevant international standards in this field. It is therefore essential to ensure that the law remains technologically neutral and that its territorial scope enables effective protection of the personal data of Serbian citizens, regardless of where the controller or processor is located.

At the same time, certain provisions should be further examined, including the definition of legitimate interest, the rules governing video surveillance, and the sanctioning system, in order to ensure their alignment with the fundamental principles of data protection and European standards.

The purpose of these proposals is to ensure that the new law is not merely formally aligned with the GDPR, but that it provides genuine, effective and sustainable long-term protection of personal data in the Republic of Serbia.