Personal Data Law art. 38 — GDPR art. 22 transposed, applicable since 22 August 2019, penalty in fixed dinars
Binds Controllers and processors, on the GDPR's own reach, with no size, sector or turnover threshold and no public/private split. Art. 3(1) applies the Law to processing wholly or partly by automated means and to non-automated processing of personal data forming part of, or intended for, a filing system. Art. 3(3) catches a controller or processor with its seat, domicile or residence in the Republic of Serbia, within activities carried out on Serbian territory, regardless of where the processing operation itself happens. Art. 3(4) reaches a controller or processor with no seat, domicile or residence in Serbia where the processing concerns a data subject domiciled or resident in Serbia and the operations relate to (1) the offering of goods or services to that person on Serbian territory, whether or not payment is required, or (2) monitoring the person's activities where those activities are carried out on Serbian territory — so a foreign scoring, screening or pricing service that reaches Serbian residents is inside art. 38. Art. 3(2) excludes processing by a natural person for personal or household purposes. Hiring, credit scoring and insurance pricing are the paradigm cases: an automated sift producing a hiring outcome significantly affects the candidate's position within the meaning of art. 38(1). A decision with a human materially in the loop falls outside art. 38(1), which reaches only decisions taken «isključivo» on the basis of automated processing, and the Law supplies no gloss on what degree of human involvement defeats that. Competent authorities processing for the special purposes are outside this article by art. 38(5) and inside art. 39.. Art. 38 of the Zakon o zaštiti podataka o ličnosti («Službeni glasnik RS» br. 87/2018) is Serbia's general automated-decision rule and it tracks GDPR art. 22 clause for clause. Art. 38(1): «Lice na koje se podaci odnose ima pravo da se na njega ne primenjuje odluka doneta isključivo na osnovu automatizovane obrade, uključujući i profilisanje, ako se tom odlukom proizvode pravne posledice po to lice ili ta odluka značajno utiče na njegov položaj.» The trigger is a decision resting solely on automated processing, profiling included, that either produces legal consequences for the person or significantly affects their position — the second limb is drafted as «značajno utiče na njegov položaj» rather than the GDPR's «similarly significantly affects», dropping the comparison to the legal-effects limb and leaving the threshold to be read on its own terms. Art. 38(2) supplies the same three exits as GDPR art. 22(2): the decision is necessary for concluding or performing a contract between the data subject and the controller; it is based on a law that itself prescribes appropriate measures protecting the person's rights, freedoms and legitimate interests; or it rests on the person's explicit consent. Art. 38(3) then requires, in the contract and consent cases, at minimum three safeguards: the right to secure the participation of a natural person under the controller's control in the taking of the decision, the right of the data subject to express their point of view on the decision, and the right to contest the decision before the controller's authorised person. Art. 38(4) bars such decisions from resting on the special categories of art. 17(1) unless art. 17(2)(1) or (5) applies — explicit consent, or data manifestly made public by the person — and the safeguards are in place. Art. 38(5) carves the whole article out for processing by competent authorities for the special purposes defined in art. 6(3); those bodies answer to art. 39 instead, and the two articles between them leave no gap. Art. 40(1) allows arts. 36 to 39 to be restricted by law for national security, defence, public security, the prevention, investigation and detection of criminal offences and the other listed grounds, provided the restriction does not touch the essence of the right and is necessary and proportionate in a democratic society.
In force and applicable, and the applicability date is derived rather than stated as a calendar date. Art. 102 reads «Ovaj zakon stupa na snagu osmog dana od dana objavljivanja u ‘Službenom glasniku Republike Srbije’, a primenjuje se po isteku devet meseci od dana stupanja zakona na snagu, osim odredbe člana 98. ovog zakona koja se primenjuje od dana njegovog stupanja na snagu.» Publication was on 13 November 2018, so the eighth day is 21 November 2018 and the nine months expire on 21 August 2019. Because art. 102 starts application «po isteku» — upon the expiry of — that period, the first day of application is 22 August 2019, and the official register masthead on the promulgated text agrees: «Osnovni tekst na snazi od 21/11/2018, u primeni od 22/08/2019». A large body of Serbian practitioner commentary instead names 21 August 2019; the one-day divergence is a reading of «po isteku» and not a conflict between two primary sources, and 22 August 2019 is the date the enacted text supports. Art. 101 repealed the 2008 Law («Sl. glasnik RS» br. 97/08, 104/09 – dr. zakon, 68/12 – US, 107/12) from the same day of first application, so the art. 22 rule of the old Law is superseded rather than supplemented; art. 100 required all other statutes touching personal data to be aligned by the end of 2020. Supersession check, 26 August 2026: the Law is still cited as «Sl. glasnik RS» br. 87/2018 alone, with no amending gazette number in its masthead, so art. 38 stands as enacted. Serbia has no AI-specific statute in force. A first Law on Artificial Intelligence aligned with the EU AI Act has been announced by the Government for adoption by December 2026; no draft text has been published, so it is not tracked as an obligation here. The text relied on is the promulgated Law as published in «Službeni glasnik RS» br. 87/2018 of 13 November 2018, read end to end from the copy the Ministry of Public Administration and Local Self-Government hosts at https://mduls.gov.rs/wp-content/uploads/Zakon-o-zaštiti-podataka-o-ličnosti.pdf, which carries the Ukaz of promulgation signed by the President and the register masthead «Osnovni tekst na snazi od 21/11/2018, u primeni od 22/08/2019». The Pravno-informacioni sistem ELI cited as the source is the official gazette record but is served by a JavaScript-only portal, so it renders in a browser and not to a fetcher — that is the shell, not rot. Two government-hosted PDFs are traps and were ruled out: minrzs.gov.rs/sites/default/files/2018-11/Zakon o zastiti podataka o licnosti.pdf is the SUPERSEDED 2008 Law (97/08) despite its 2018 upload path, and it decodes only through a shifted-glyph font.
Stated maximum penalty — 50,000 to 2,000,000 dinara for a controller or processor that is a legal person. Art. 95(1)(19) names the breach expressly: a misdemeanour is committed where «se donese odluka koja proizvodi pravne posledice po lice na koje se podaci odnose isključivo na osnovu automatizovane obrade, suprotno čl. 38. i 39. ovog zakona», and it sits in the Law's top band at art. 95(1). Art. 95(4) fines an entrepreneur 20,000 to 500,000 dinara for the same misdemeanour, and art. 95(5) fines a natural person, the responsible person in a legal person, in a state body, in an authority of territorial autonomy or of a local self-government unit, and the responsible person in a representative office or business unit of a foreign legal person, 5,000 to 150,000 dinara. These are fixed-dinar misdemeanour fines set in the Law itself, not GDPR-style turnover percentages, and there is no turnover alternative anywhere in art. 95 — the ceiling for the largest multinational is the same 2,000,000 dinara as for the smallest Serbian company. Supervision and enforcement sit with the Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti; misdemeanour proceedings run before the misdemeanour courts. Impact tier: all entities.