Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia

INTRODUCTORY NOTE
The Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia, as an independent state authority autonomous in its work, is committed to ensuring the highest level of legality, transparency, and security in the processing of personal data. This Privacy Policy constitutes an overarching legal act informing the public, applicants, complainants, and users of the Commissioner’s digital infrastructure about the manner, scope, purpose, legal basis, and security measures applied in the processing of personal data within this institution.
1. DATA CONTROLLER
The data controller, within the meaning of Article 4(1)(8) of the Law on Personal Data Protection, is the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia (hereinafter: the “Commissioner”), as an independent state authority established for the purpose of exercising and protecting the right of free access to information of public importance and the right to personal data protection.
- Registered seat: 15 Bulevar kralja Aleksandra, 11000 Belgrade, Republic of Serbia
- Official website: www.poverenik.rs
- Telephone: +381 11 3408 900
- Email: office@poverenik.rs
2. INTERNATIONAL STANDARDS AND MANAGEMENT SYSTEM CERTIFICATION
The Commissioner’s Office has established, implemented, and externally certified an integrated management system in accordance with leading international standards:
- SRPS ISO/IEC 27001:2022 – Information Security Management System (ISMS)
- SRPS ISO/IEC 27701:2019 – Privacy Information Management System (PIMS)
These certifications constitute formal confirmation that the processing of all categories of personal data within the institution is carried out through the consistent application of state-of-the-art technical, organisational, and human resource security measures, thereby minimising the risk of personal data breaches.
3. GLOSSARY OF TERMS AND LEGAL TERMINOLOGY
For the purposes of this Privacy Policy, the terms and expressions used throughout the text shall have the following meaning in accordance with the applicable legislation of the Republic of Serbia:
Term / Expression
Official Legal Definition and Meaning
- Personal Data
Any information relating to an identified or identifiable natural person, where an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. - Data Processing
Any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction. - Controller
A natural person or legal entity, public authority, or other body that alone or jointly with others determines the purposes and means of processing personal data. - Processor
A natural person, legal entity, public authority, or other body that processes personal data on behalf of the Controller. - Anonymised Data
Information which has been irreversibly altered or processed in such a manner that the natural person can no longer be identified by any means reasonably likely to be used. Such data permanently ceases to qualify as personal data and is no longer subject to the restrictions of the Law on Personal Data Protection. - Data Protection Regulations
The applicable laws in force in the Republic of Serbia, primarily the Law on Personal Data Protection, secondary legislation adopted on the basis of that Law, as well as relevant international treaties ratified by the Republic of Serbia
4. PURPOSE AND LEGAL BASIS OF PROCESSING
The Commissioner processes personal data solely to the extent necessary for the lawful, timely, and efficient performance of its constitutionally and legally defined competences.
4.1 Purposes of Processing include:
- Exercise of statutory powers and official duties: Handling complaints concerning violations of the Law on Free Access to Information of Public Importance, initiating and conducting supervisory and inspection procedures regarding the application of the Law on Personal Data Protection, imposing measures, and maintaining legally prescribed records and registers.
- Processing of submissions: Processing initiatives, petitions, requests for opinions, and other forms of communication submitted by individuals, legal entities, and public authorities.
- Education and awareness-raising: Conducting legally mandated training activities, professional development programmes, conferences, and partnership projects aimed at improving personal data protection and the right of access to information.
- Ensuring functionality of digital services: Administration and maintenance of the official website and electronic portals of the Commissioner.
4.2 Legal Basis for Processing:
- The primary legal basis for the processing of personal data by the Commissioner consists of the obligations and powers of this public authority established by law, as prescribed by the Law on Personal Data Protection and the Law on Free Access to Information of Public Importance. Personal data are processed solely to the extent necessary for the performance of these legally established obligations and powers, i.e. for carrying out tasks in the public interest within the scope of the Commissioner’s legally prescribed competences. In this regard, Article 12(1)(3) and (5) of the Law on Personal Data Protection provides that processing may be carried out where it is necessary for compliance with a legal obligation of the controller or for the performance of tasks carried out in the public interest or in the exercise of legally prescribed powers, while Article 14(1) of the Law on Personal Data Protection stipulates that the legal basis for processing referred to in Article 12(1)(3) and (5) of this Law shall be established by law.
- The Commissioner also processes personal data for the purpose of ensuring the information security of its information and communication systems, protecting the confidentiality, integrity, availability and resilience of systems and data, preventing, detecting and remedying security incidents, controlling access, maintaining records of security events, ensuring the stable operation of its website, and implementing other organisational and technical protection measures prescribed by law. For these purposes, the Commissioner may process user authentication and authorisation data, access and activity records (logs), device and network identifiers, security event data, and other data necessary for fulfilling legal obligations in the field of information security. Such processing is carried out in accordance with the Law on Information Security, specific laws, and the Law on Personal Data Protection. The legal basis for this processing is the fulfilment of the Commissioner’s legal obligation as an operator of an ICT system of special importance, in accordance with the Law on Information Security. In this regard, Article 12(1)(3) of the Law on Personal Data Protection provides that processing may be carried out where it is necessary for compliance with a legal obligation of the controller, while Article 14(1) of the Law on Personal Data Protection stipulates that the legal basis for processing referred to in Article 12(1)(3) of this Law shall be established by law.
5. COOKIE POLICY
The website www.poverenik.rs is managed by the Commissioner, who is responsible for its content.
The Commissioner respects the privacy of its users and therefore does not process user-related information such as IP addresses, email addresses, and/or other visitor-related data for tracking purposes.
A strict data minimisation regime is applied on the official website. Three (3) strictly necessary technical cookies are used, whose sole purpose is to ensure proper technical functionality of the website, secure session establishment, and optimal content display.
These cookies do not collect personal data that may be used for marketing, commercial purposes, or user profiling. The Commissioner explicitly states that:
- It does not use third-party analytical cookies (such as Google Analytics or non-anonymised Matomo tools).
- It does not implement digital marketing, retargeting, or behavioural advertising tools.
- It does not perform any form of profiling or automated decision-making regarding users.
Detailed information on the technical names, individual purposes, origins, and retention periods of each cookie, as well as instructions for managing cookie settings in your browser, is available in a separate Cookie Policy document permanently accessible in the footer of the Commissioner’s website.
6. CONSENT TO PROCESSING AND RIGHT TO WITHDRAW CONSENT
In specific, legally limited situations where processing is not based directly on the exercise of public authority but on freely given consent of the data subject (e.g. voluntary subscription to the Commissioner’s newsletter, completion of optional satisfaction surveys regarding the work of the Service, or participation in open educational programmes and conferences), the provision of data is entirely voluntary.
The data subject has the right to withdraw consent at any time by sending a clear and unambiguous statement of withdrawal to the email address: lzzpol@poverenik.rs. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to its withdrawal.
7. CONTROLLER–PROCESSOR RELATIONSHIP (EXTERNAL SERVICE PROVIDERS)
For the purpose of performing specific information, communication, hosting, and technical services, the Commissioner may engage external IT service providers who act exclusively as Processors (e.g. cloud/hosting providers, providers of licensed video-conferencing platforms, and remote learning systems).
All relationships with external Processors are governed by legally binding Data Processing Agreements, fully compliant with Article 45 of the Law on Personal Data Protection.
Under these agreements, the processors are legally obliged to:
- act solely on documented instructions of the Commissioner;
- apply the same or stricter technical, organisational, and personnel security measures as those applied by the Commissioner;
- maintain confidentiality and prohibit the disclosure of personal data to third parties without the explicit written consent of the Commissioner.
8. INTERNATIONAL TRANSFER OF PERSONAL DATA
Personal data processed within the Commissioner’s operations are primarily stored, archived, and processed within the territory of the Republic of Serbia (Commissioner’s data center).
Transfers of personal data to other countries or international organisations are not part of regular practice and may only occur exceptionally:
- Where there is an explicit legal obligation or authorisation based on ratified international treaties (e.g. official international legal assistance, cooperation with international bodies and networks of supervisory authorities in the field of privacy protection).
- Where the country, a territory or sector within that country, or an international organisation ensures an adequate level of personal data protection, based on an Adequacy Decision adopted by the Government of the Republic of Serbia, or through the application of appropriate safeguards pursuant to Article 65 of the Law on Personal Data Protection (e.g. standard contractual clauses).
9. DATA RETENTION PERIOD
Personal data are retained only for as long as necessary to fulfil the specific purpose for which they were collected, or for periods expressly prescribed by applicable legislation of the Republic of Serbia governing archival material, office operations, and retention periods for public authority documentation (Law on Archival Material and Archival Activity and related by-laws).
Upon expiry of the legally defined retention period, or once the purpose of processing has been fully achieved, personal data are permanently and securely destroyed, deleted from electronic databases, or subjected to full anonymisation procedures.
10. RIGHTS OF DATA SUBJECTS
Every data subject whose personal data are processed by the Commissioner is guaranteed the rights provided under the Law on Personal Data Protection. The specific nature of the exercise of these rights before a public authority is reflected in the statutory limitations applicable where processing is necessary for the exercise of the official powers and duties of the Commissioner.
Right
Description and Essence of the Right in the Context of the Commissioner’s Activities
- Right of Access (Article 26)
The right to obtain confirmation as to whether the Commissioner processes personal data concerning the data subject, access to such data, as well as information on the purposes of processing, categories of data, recipients, and retention period. - Right to Rectification and Completion (Article 29)
The right to have inaccurate personal data corrected without undue delay, and incomplete data completed, including by providing an additional statement. - Right to Erasure (Article 30)
The right to request the deletion of personal data where statutory conditions are met (e.g. when the purpose of processing has ceased). This right is subject to legal limitations and cannot be exercised where processing is necessary for compliance with the Commissioner’s legal obligations or for reasons of public interest. - Right to Restriction of Processing (Article 31)
The right to request temporary restriction of processing under legally prescribed circumstances (e.g. contesting the accuracy of data or verifying the lawfulness of processing). - Right to Data Portability (Article 36)
The right to receive personal data in a structured, commonly used, and machine-readable format and to transmit such data to another controller. In accordance with applicable law, this right does not apply to processing necessary for the performance of tasks carried out in the public interest or in the exercise of official authority of the Commissioner. - Right to Object (Article 37)
The right to object to processing carried out pursuant to Article 12(1)(5) of the Law on Personal Data Protection (public interest / official authority). The Commissioner shall cease processing unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject.
Modalities for Exercising Rights:
Please pay attention to the correct selection of the email address depending on the type of request you wish to submit:
- office@poverenik.rs – Use this address if you believe that another controller (e.g. a bank, school, employer, private company, etc.) is violating the Law on Personal Data Protection, and you wish to submit a complaint or petition to the Commissioner regarding the processing activities of other controllers, or if you have general inquiries regarding the application of the Law on Personal Data Protection.
- lzzpol@poverenik.rs – Use this address exclusively if you wish to exercise your rights in relation to personal data processed by the Commissioner concerning you (e.g. access to your personal data held by the Commissioner’s Office). Requests must be submitted in formal written form to this email address or to the registered seat of the Commissioner.
Upon submission of a request to exercise data subject rights, the Commissioner shall provide information on the action taken without undue delay and in any event within 30 days from receipt of the request. This period may be extended by an additional 60 days where necessary due to the complexity and number of requests, in which case the data subject shall be informed within 30 days of receipt of the request.
In accordance with Article 82 of the Law on Personal Data Protection, every person has the right to lodge a complaint with the Commissioner (as the competent supervisory authority) if they consider that the processing of their personal data by any controller has been carried out in violation of the provisions of the Law.
11. SECURITY, INTEGRITY AND CONFIDENTIALITY OF DATA
In accordance with Articles 42 and 50 of the Law on Personal Data Protection and the ISO/IEC 27000 series standards, the Commissioner implements comprehensive and rigorous technical, organisational, and personnel measures to ensure a level of security appropriate to the specific risks of processing.
These measures include, but are not limited to:
- Physical and logical access control: Strict access control to official premises, server rooms, and information systems, using advanced authentication and authorisation mechanisms.
- Cryptographic protection: Encryption of data at rest and in transit using state-of-the-art cryptographic protocols (e.g. TLS, HTTPS, VPN).
- Continuous monitoring: Ongoing proactive monitoring of information and communication systems to detect incidents, intrusions, or anomalies (SIEM/SOC solutions).
- Pseudonymisation and minimisation: Application of pseudonymisation techniques in databases wherever operational processes allow it.
- Business continuity: Regular creation of data backups and testing of disaster recovery plans in emergency situations.
All employees of the Commissioner’s Office, as well as externally engaged persons, are legally and contractually bound to maintain professional secrecy and confidentiality of personal data obtained in the course of their duties. This obligation explicitly remains in force after termination of employment or contractual engagement.
12. AMENDMENTS AND UPDATES TO THE PRIVACY POLICY
Privacy Policy is subject to regular periodic review and updates in order to ensure compliance with potential changes in the legal framework of the Republic of Serbia, technological standards, guidelines of the European Data Protection Board (EDPB), or internal institutional changes in data processing practices.
All amendments, additions, and revised versions of the document shall be published in a timely, transparent, and clearly visible manner on the Commissioner’s official website, with a clearly indicated effective date and version number.
FINAL PROVISIONS
Privacy Policy is drafted in the Serbian language and shall be interpreted exclusively in accordance with the applicable laws of the Republic of Serbia.
Privacy Policy shall enter into force and apply eight (8) days after its official publication on the Commissioner’s website.
- Latest updated version: V1.1 (19 June 2026)
- Document archive: The previous version of this Policy (dated 19 September 2017) is available at the following link: https://poverenik.rs/privatnost/