Law on Personal Data Protection
Personal Data Protection Agency in Bosnia and Herzegovina
Personal Data Protection Agency in Bosnia and Herzegovina
The Law on Personal Data Protection, Official Gazette of Bosnia and Herzegovina No. 12/25, replaces the former framework and aligns the country's general processing rules with the GDPR while also addressing competent-authority processing. The Personal Data Protection Agency in Bosnia and Herzegovina supervises the law.
The law has territorial and extraterritorial rules, legal bases, transparent notices, individual rights, processor contracts, records, security, breach response, DPIAs, DPOs and international-transfer mechanisms. The digital-consent age is 16. Rights requests normally must be handled within 30 days, with a possible further 60 days where justified.
National provisions also address video surveillance and biometric processing. Video systems require documented controls and logging; specific rules apply to residential buildings.
Replace any checklist based on the repealed law. Use the 2025 accountability model, including Article 32 internal records rather than the old filing-system registration process, and separately assess surveillance and biometric use.