UDC 342.738:061.1EU
Biblid: 1451‑3188, 25 (2026)
Vol. 25, No 94-95, pp. 94-119
DOI: https://doi.org/10.18485/iipe_ez.2026.25.94_95.5

Оriginal article
Received: 13 May 2026
Accepted: 02 Jun 2026

Normative parallels of personal data protection in the European Union and in the Republic of Serbia

Uljanov Sergej (Fakultet za poslovne studije i pravo, Univerzitet \\\"Union - Nikola Tesla\\\", Beograd), sergej.uljanov@fpsp.edu.rs

In the era of the fourth industrial revolution, personal data has become the most valuable resource of the digital economy, yet also the most vulnerable point for individual privacy. Mass collection, algorithmic processing, and global information flows have necessitated a robust and uniform legal framework to address challenges unforeseen by traditional law. This paper analyses the degree of compliance and key normative parallels between the legal frameworks for personal data protection in the European Union and the Republic of Serbia. The central subject of the research is the relationship between the General Data Protection Regulation (GDPR) and the domestic Law on Personal Data Protection (LPDP) of 2018. The author proceeds from the thesis that the Republic of Serbia, within the European integration process, has carried out extensive harmonisation of its regulations, adopting the basic concepts, processing principles, and data subject rights from the European model. The first part of the paper examines the evolutionary processes that led to the adoption of current regulations. The central part provides a comparative analysis of institutes, such as processing principles, legal bases, and the role of supervisory authorities. Special emphasis is placed on the institutional framework, comparing the powers of the Commissioner for Information of Public Importance and Personal Data Protection in the Republic of Serbia with those of supervisory authorities in EU member states, while noting significant differences in penal policy and enforcement mechanisms. The final segment of the paper is dedicated to the challenges of cross‐border data transfer and Serbia’s prospects for obtaining an Adequacy Decision from the European Commission. Concluding remarks indicate that, despite a high rate of normative alignment, practical application and ensuring the full effectiveness of rights in the Republic of Serbia still face challenges due to specific socio‐legal circumstances and administrative capacities.

Keywords: personal data protection, General Data Protection Regulation (GDPR), Law on Personal Data Protection (LPDP), Commissioner for Information of Public Importance and Personal Data Protection, harmonisation of law