AI LAW RADAR · Daily Last verified 28 Aug 2026

Jurisdiction dossier

Bosnia and Herzegovina: AI regulation & deadlines

Bosnia and Herzegovina has no AI-specific statute in force and two binding automated-decision rules that have applied since 4 October 2025. The Zakon o zaštiti ličnih podataka («Službeni glasnik BiH» broj 12/25), adopted 30 January 2025 and published 28 February 2025, replaced the 2006 Act and carries the GDPR and the Law Enforcement Directive in a single state-level instrument, split by Part as Albania's Law 124/2024 is. Art. 24 in DIO DRUGI is GDPR art. 22 with the same trigger, the same three exits of contract, authorising law and explicit consent, and the same special-categories bar routed through art. 11(2)(a) and (g). Art. 67 in DIO TREĆI is the law-enforcement counterpart: a flat prohibition with no contract or consent way out, a special-categories bar, and an unconditional ban on profiling that discriminates on sensitive-data grounds, the twin of Serbia's art. 39(3) and Albania's art. 53(3). The divergence that runs through both is the safeguard formula: where the GDPR and the LED give a right to obtain human intervention on the part of the controller, arts. 24(3) and 67(1) give «prava na učešće fizičkog lica u donošenju odluke» — the right to the participation of a natural person in the making of the decision, drafted into the procedure rather than as something asked for after the fact. Transparency is proactive at arts. 15, 16 and 17 and the impact assessment at art. 37 is triggered by systematic and extensive automated evaluation. Enforcement is GDPR-shaped with two twists: art. 113(5)(b) sets 20,000 KM to 40,000,000 KM or 4% of worldwide turnover, whichever is higher — a floor the GDPR does not have, and a ceiling worth about €20.45m at the currency-board peg rather than €20m — while art. 113(10) bars any fine on a public body or competent authority, so art. 67 has no institutional penalty behind it and only the responsible officer (5,000–70,000 KM) or employee (500–5,000 KM) is exposed. Until 4 October 2025 the rule was art. 29 of the 2006 Act, a Directive 95/46 art. 15 prohibition of the same shape as Montenegro's art. 15a, fineable at 5,000–50,000 KM. Alignment of other laws and of processing already under way is due by 8 March 2027 under art. 116. Supervision sits with the Agencija za zaštitu ličnih podataka u Bosni i Hercegovini. 1 obligation tracked — 1 in force.

Binding — Binding sectoral Flagship law: ZZLP arts. 24 and 67

Bosnia and Herzegovina has no AI-specific statute in force and two binding automated-decision rules that have applied since 4 October 2025. The Zakon o zaštiti ličnih podataka («Službeni glasnik BiH» broj 12/25), adopted 30 January 2025 and published 28 February 2025, replaced the 2006 Act and carries the GDPR and the Law Enforcement Directive in a single state-level instrument, split by Part as Albania's Law 124/2024 is. Art. 24 in DIO DRUGI is GDPR art. 22 with the same trigger, the same three exits of contract, authorising law and explicit consent, and the same special-categories bar routed through art. 11(2)(a) and (g). Art. 67 in DIO TREĆI is the law-enforcement counterpart: a flat prohibition with no contract or consent way out, a special-categories bar, and an unconditional ban on profiling that discriminates on sensitive-data grounds, the twin of Serbia's art. 39(3) and Albania's art. 53(3). The divergence that runs through both is the safeguard formula: where the GDPR and the LED give a right to obtain human intervention on the part of the controller, arts. 24(3) and 67(1) give «prava na učešće fizičkog lica u donošenju odluke» — the right to the participation of a natural person in the making of the decision, drafted into the procedure rather than as something asked for after the fact. Transparency is proactive at arts. 15, 16 and 17 and the impact assessment at art. 37 is triggered by systematic and extensive automated evaluation. Enforcement is GDPR-shaped with two twists: art. 113(5)(b) sets 20,000 KM to 40,000,000 KM or 4% of worldwide turnover, whichever is higher — a floor the GDPR does not have, and a ceiling worth about €20.45m at the currency-board peg rather than €20m — while art. 113(10) bars any fine on a public body or competent authority, so art. 67 has no institutional penalty behind it and only the responsible officer (5,000–70,000 KM) or employee (500–5,000 KM) is exposed. Until 4 October 2025 the rule was art. 29 of the 2006 Act, a Directive 95/46 art. 15 prohibition of the same shape as Montenegro's art. 15a, fineable at 5,000–50,000 KM. Alignment of other laws and of processing already under way is due by 8 March 2027 under art. 116. Supervision sits with the Agencija za zaštitu ličnih podataka u Bosni i Hercegovini.

checked 28 Aug 2026 primary source ↗

The Register

1 obligation
Bosnia and Herzegovina Binding

ZZLP arts. 24 and 67 — GDPR art. 22 and LED art. 11 in one state-level act since 4 October 2025, with «participation of a natural person in the decision» in place of human intervention

Binds Art. 24 binds data controllers and processors — natural persons, legal persons and public bodies alike — under DIO DRUGI. Art. 5 applies the Act to wholly automated processing and to non-automated processing of personal data forming or intended to form part of a filing system, and excludes purely personal or household activity. Art. 6 is GDPR art. 3 in substance: establishment, seat, domicile or residence in Bosnia and Herzegovina regardless of where processing happens; and, for controllers or processors without one, processing of data subjects in BiH where the activity is connected to offering goods or services to them or to monitoring their behaviour as it occurs within BiH. Art. 67 binds «nadležni organ» only — the bodies competent for the prevention, investigation and detection of criminal offences, prosecution of offenders or execution of criminal sanctions, including protection against and prevention of threats to public security, and legal persons where a law empowers them to perform those tasks — when processing for those purposes, which art. 5(3) and art. 6(4) route to DIO TREĆI instead of DIO DRUGI. Impact tier: all entities.. Arts. 24 and 67 of the Zakon o zaštiti ličnih podataka («Službeni glasnik BiH» broj 12/25) are Bosnia and Herzegovina's automated-decision rules, and they have applied since 4 October 2025. The Act is a state-level statute adopted under art. IV.4.a) of the Constitution — passed by the House of Representatives at its 16th emergency session on 23 January 2025 and signed on 30 January 2025 — and it carries the GDPR and the Law Enforcement Directive in one instrument, split by Part, on the Albanian rather than the Macedonian or Montenegrin pattern. Art. 24, in DIO DRUGI (processing by a natural person, legal person or public body as controller), is GDPR art. 22: «Nosilac podataka ima pravo da se na njega ne primjenjuje odluka zasnovana isključivo na automatiziranoj obradi, uključujući i profiliranje, koja proizvodi pravni učinak koji se na njega odnosi ili na sličan način značajno na njega utiče.» The same solely-automated trigger, the same legal-effects-or-similarly-significantly-affects threshold, and the same three exits at art. 24(2) — necessary for concluding or performing a contract between the data subject and the controller, permitted by a law applying to the controller that itself lays down suitable safeguards, or based on the data subject's explicit consent. Art. 24(4) bars such decisions from resting on special categories under art. 11(1) unless art. 11(2)(a) or (g) applies, landing exactly where GDPR art. 22(4) does. «Izrada profila» is defined in GDPR terms at art. 4. The one drafting divergence is in the safeguards, and it runs through the whole Act: art. 24(3) requires, for the contract and consent exits, «najmanje prava na učešće fizičkog lica u donošenju odluke, prava izražavanja vlastitog stava i prava na osporavanje odluke» — at least the right to the PARTICIPATION of a natural person IN THE MAKING of the decision, rather than the GDPR's right to obtain human intervention on the part of the controller. The right to express a view and the right to contest are unchanged, but the first limb is drafted as something built into the decision procedure rather than something the data subject asks for afterwards. Art. 67, in DIO TREĆI (processing by a competent authority for criminal-law purposes), is the LED art. 11 counterpart and is a flat prohibition: a competent authority may not take a decision based solely on automated processing, profiling included, that produces negative legal effects for or significantly affects the data subject, unless authorised by a special law laying down safeguards — and the only safeguard the statute names there is, again, «prava na učešće fizičkog lica u donošenju odluke». There is no contract exit and no consent exit on the police side. Art. 67(2) bars reliance on special categories, and art. 67(3) prohibits outright any profiling that leads to discrimination on special-category grounds — untied to any decision or effects threshold and admitting no exception, the twin of Serbia's art. 39(3) and Albania's art. 53(3). Transparency is proactive and triple-anchored: arts. 15, 16 and 17 each require disclosure of «postojanju automatiziranog donošenja odluka, uključujući i izradu profila iz člana 24. st. (1) i (4)» with, in arts. 16 and 17, reasonable information about the criterion used and, in art. 15, the manner of operation, plus in all three the significance and envisaged consequences; art. 37 makes systematic and extensive automated evaluation a mandatory impact-assessment trigger. Supersession is the other half of the story: until 4 October 2025 the rule in force was art. 29 of the 2006 Act («Sl. glasnik BiH» br. 49/06, 76/11, 89/11), a Directive 95/46 art. 15 prohibition of the same shape as Montenegro's art. 15a — no profiling concept, contract-or-law exits only, no consent. Art. 119(1) of the new Act repealed it on the day the new Act became applicable.

Applicable since 4 October 2025. The Act was published in «Službeni glasnik BiH» broj 12/25 on 28 February 2025; art. 120 sets entry into force on the eighth day after publication, i.e. 8 March 2025, and application «nakon isteka 210 dana od dana stupanja na snagu». The Agency's own Central Register notice states the start of application as «dana 04.10.2025», and its transitional notice on the same Act says only «u oktobru tekuće godine»; a strict day-count from 9 March would put the 210th day on 4 October and application from 5 October, and one Bosnian legal publisher reports 5 October. The regulator's stated date is taken as authoritative here, with the one-day divergence recorded rather than smoothed over; nothing in the atlas turns on it. Two follow-on dates are live. Art. 116(1) and (2) require other laws touching personal-data processing, and processing operations already under way, to be aligned within two years of entry into force — 8 March 2027. Art. 117 required all subordinate acts under the Act within 210 days of entry into force. Art. 119 repealed the 2006 Act («Sl. glasnik BiH» br. 49/06, 76/11, 89/11) and its implementing rulebooks on the day application began; the atlas carried no BiH row under the old Act, so this is an addition rather than a supersession edit, but art. 29 of the 2006 Act — the pre-GDPR prohibition it replaced — is recorded in the entry for the comparison it enables. The Act is state-level and applies across both Entities and Brčko District; there is no separate Entity-level automated-decision rule to track.

Stated maximum penalty — 20,000 KM to 40,000,000 KM, or for an undertaking up to 4% of total worldwide annual turnover for the preceding financial year, whichever is higher — art. 113(5)(b) puts breach of the data-subject rights in arts. 14 to 24, art. 24 among them, in the top band. Two things are worth naming. First, the KM figures are not the GDPR's euro ceilings converted at the currency-board peg of 1 EUR = 1.95583 KM but doubled: 40,000,000 KM is about €20.45m against GDPR art. 83(5)'s €20m, and the lower band's 20,000,000 KM at art. 113(4) is about €10.23m against €10m. Second, and unlike the GDPR, the bands have a floor — 20,000 KM, about €10,226, is the minimum for an art. 24 breach, where GDPR art. 83 sets only a ceiling. Against a public body or a competent authority no fine can be imposed at all: art. 113(10) exempts them, leaving only the responsible person at 5,000–70,000 KM (about €2,556–€35,790) and an employee at 500–5,000 KM under art. 113(8), whose list of articles covers arts. 14 to 24 and arts. 67 to 73. So art. 67, the police-side prohibition, carries no institutional fine anywhere in the Act — its enforcement runs through the Agency's art. 103(2) measures, non-compliance with which is itself in the top band. The Agency issues a misdemeanour order or applies to the competent court under the Zakon o prekršajima BiH; limitation is five years from the breach. Under the repealed 2006 Act the equivalent exposure for the same conduct was 5,000–50,000 KM (art. 50(1)(u), breach of art. 29), so the ceiling for a private controller rose roughly eight-hundredfold on 4 October 2025.

In force · 4 Oct 2025 checked 28 Aug 2026 ZZLP arts. 24 and 67 ↗ high confidence

Questions & answers

From the data

When does ZZLP arts. 24 and 67 take effect in Bosnia and Herzegovina?

ZZLP arts. 24 and 67 is already in force, with obligations live since October 4, 2025. Bosnia and Herzegovina has no AI-specific statute in force and two binding automated-decision rules that have applied since 4 October 2025. The Zakon o zaštiti ličnih podataka («Službeni glasnik BiH» broj 12/25), adopted 30 January 2025 and published 28 February 2025, replaced the 2006 Act and carries the GDPR and the Law Enforcement Directive in a single state-level instrument, split by Part as Albania's Law 124/2024 is. Art. 24 in DIO DRUGI is GDPR art. 22 with the same trigger, the same three exits of contract, authorising law and explicit consent, and the same special-categories bar routed through art. 11(2)(a) and (g). Art. 67 in DIO TREĆI is the law-enforcement counterpart: a flat prohibition with no contract or consent way out, a special-categories bar, and an unconditional ban on profiling that discriminates on sensitive-data grounds, the twin of Serbia's art. 39(3) and Albania's art. 53(3). The divergence that runs through both is the safeguard formula: where the GDPR and the LED give a right to obtain human intervention on the part of the controller, arts. 24(3) and 67(1) give «prava na učešće fizičkog lica u donošenju odluke» — the right to the participation of a natural person in the making of the decision, drafted into the procedure rather than as something asked for after the fact. Transparency is proactive at arts. 15, 16 and 17 and the impact assessment at art. 37 is triggered by systematic and extensive automated evaluation. Enforcement is GDPR-shaped with two twists: art. 113(5)(b) sets 20,000 KM to 40,000,000 KM or 4% of worldwide turnover, whichever is higher — a floor the GDPR does not have, and a ceiling worth about €20.45m at the currency-board peg rather than €20m — while art. 113(10) bars any fine on a public body or competent authority, so art. 67 has no institutional penalty behind it and only the responsible officer (5,000–70,000 KM) or employee (500–5,000 KM) is exposed. Until 4 October 2025 the rule was art. 29 of the 2006 Act, a Directive 95/46 art. 15 prohibition of the same shape as Montenegro's art. 15a, fineable at 5,000–50,000 KM. Alignment of other laws and of processing already under way is due by 8 March 2027 under art. 116. Supervision sits with the Agencija za zaštitu ličnih podataka u Bosni i Hercegovini.

Who must comply with AI rules in Bosnia and Herzegovina?

Current obligations bind, among others, Art. 24 binds data controllers and processors — natural persons, legal persons and public bodies alike — under DIO DRUGI. Art. 5 applies the Act to wholly automated processing and to non-automated processing of personal data forming or intended to form part of a filing system, and excludes purely personal or household activity. Art. 6 is GDPR art. 3 in substance: establishment, seat, domicile or residence in Bosnia and Herzegovina regardless of where processing happens; and, for controllers or processors without one, processing of data subjects in BiH where the activity is connected to offering goods or services to them or to monitoring their behaviour as it occurs within BiH. Art. 67 binds «nadležni organ» only — the bodies competent for the prevention, investigation and detection of criminal offences, prosecution of offenders or execution of criminal sanctions, including protection against and prevention of threats to public security, and legal persons where a law empowers them to perform those tasks — when processing for those purposes, which art. 5(3) and art. 6(4) route to DIO TREĆI instead of DIO DRUGI. Impact tier: all entities.. Scope and thresholds vary per instrument — see each row's source for the legal text.

What are the penalties for AI non-compliance in Bosnia and Herzegovina?

Stated statutory maxima include: ZZLP arts. 24 and 67 — 20,000 KM to 40,000,000 KM, or for an undertaking up to 4% of total worldwide annual turnover for the preceding financial year, whichever is higher — art. 113(5)(b) puts breach of the data-subject rights in arts. 14 to 24, art. 24 among them, in the top band. Two things are worth naming. First, the KM figures are not the GDPR's euro ceilings converted at the currency-board peg of 1 EUR = 1.95583 KM but doubled: 40,000,000 KM is about €20.45m against GDPR art. 83(5)'s €20m, and the lower band's 20,000,000 KM at art. 113(4) is about €10.23m against €10m. Second, and unlike the GDPR, the bands have a floor — 20,000 KM, about €10,226, is the minimum for an art. 24 breach, where GDPR art. 83 sets only a ceiling. Against a public body or a competent authority no fine can be imposed at all: art. 113(10) exempts them, leaving only the responsible person at 5,000–70,000 KM (about €2,556–€35,790) and an employee at 500–5,000 KM under art. 113(8), whose list of articles covers arts. 14 to 24 and arts. 67 to 73. So art. 67, the police-side prohibition, carries no institutional fine anywhere in the Act — its enforcement runs through the Agency's art. 103(2) measures, non-compliance with which is itself in the top band. The Agency issues a misdemeanour order or applies to the competent court under the Zakon o prekršajima BiH; limitation is five years from the breach. Under the repealed 2006 Act the equivalent exposure for the same conduct was 5,000–50,000 KM (art. 50(1)(u), breach of art. 29), so the ceiling for a private controller rose roughly eight-hundredfold on 4 October 2025.. These are the maximum amounts in the instruments; actual enforcement is at the regulator's discretion.