Preskoči na sadržaj
BeoHosting
BeoHosting

8 min

GDPR for Websites in Serbia

Privacy policy, cookie banner, and compliance.

BeoHosting Tim

10+ godina iskustva — Stručnjaci za web hosting i infrastrukturu

Poslednje ažurirano:

GDPR (General Data Protection Regulation) applies to any website that processes personal data of EU citizens — and Serbia's ZZPL (Law on Personal Data Protection) mirrors it almost completely. If your site has a contact form, newsletter signup, or webshop, GDPR compliance is mandatory. This guide covers everything you need: privacy policy, cookie banner, SSL, consent management, and avoiding fines of up to €18,803.42.

GDPR for Websites in Serbia

1

Create a privacy policy

A privacy policy is mandatory and must clearly state: who processes the data, what data is collected and why, legal basis, retention period, who the data is shared with, user rights and contact info. Use generators like PrivacyPolicies.com as a starting point and adapt to your site.

2

Add a cookie banner

If you use Google Analytics, Facebook Pixel, YouTube embeds or any marketing/analytics tool, a cookie banner with granular consent options is mandatory. WordPress plugins: Cookie Notice, CookieYes, Complianz. Banner must show before any non-essential cookie is set.

3

Install an SSL certificate

GDPR requires "appropriate technical measures" to protect personal data. SSL/HTTPS is a baseline. BeoHosting includes free Let's Encrypt SSL on every package — enable AutoSSL in cPanel and force HTTPS via .htaccess.

4

Add consent checkboxes to forms

Every form that collects personal data (contact, newsletter, registration) must have an explicit opt-in checkbox (not pre-ticked) with a clear link to the privacy policy. Save the consent timestamp with each submission for audit purposes.

5

Define data retention and user rights

Store personal data only as long as necessary. Document retention periods. Implement user rights: access, rectification, erasure, portability and objection. Provide a clear contact channel for data subject requests (e.g. privacy@yourcompany.com).

6

Sign a Data Processing Agreement (DPA)

You must have a DPA with every processor that handles personal data on your behalf — hosting provider, email provider, analytics, CRM, payment gateway. BeoHosting offers a DPA on request.

Spremni da pokrenete svoj sajt?

SSL zaštita
Brzina
24/7 podrška

Pridružite se 4.000+ zadovoljnih korisnika. Besplatna migracija i 15 dana garancije povrata novca.

15 dana garancija povrata novca
Besplatna migracija15 dana garancija24/7 podrška

FAQ

Odgovori na najčešća pitanja o našim uslugama.

GDPR applies directly if your site processes data of EU citizens (visitors or customers from the EU). Serbia also adopted the Law on Personal Data Protection (ZZPL) in 2018 which is largely aligned with GDPR and applies to every site processing data of Serbian citizens. In practice, most Serbian sites must comply with ZZPL, and those with EU visitors with GDPR.

The Commissioner for Information of Public Importance can impose fines for ZZPL breaches. For legal entities, fines go up to €18,803.42; for sole proprietors up to €4,700.85. GDPR fines can reach 20 million EUR or 4% of annual turnover (whichever is higher). Beyond fines, non-compliance damages reputation and user trust.

Strictly speaking, if you use only essential cookies (session, login, cart), you do not need a consent banner. However, if you use Google Analytics, Facebook Pixel, YouTube embeds or any marketing/analytics tool, you are required to have a cookie banner with granular consent options.

You can use free generators (e.g. PrivacyPolicies.com, Termly.io) as a starting point, but adapt it to your site. The policy must be in plain language and include: who processes the data, what data is collected and why, legal basis, retention period, sharing, user rights and contact. For complex cases, consult an IT lawyer.

BeoHosting provides the technical infrastructure for compliance: free SSL for data encryption, servers with security measures (firewall, DDoS protection, backup), and the ability to install cookie consent plugins for WordPress. BeoHosting also stores data per ZZPL and provides a Data Processing Agreement (DPA) on request.

Naše garancije za vaš mir

Zaštićeni ste sa svake strane

15 dana garancije

Vraćamo novac bez pitanja u prvih 15 dana.

Besplatna migracija

Mi prebacimo vaš sajt bez prekida — vi ništa ne radite.

24/7 podrška

Naši stručnjaci su tu 24/7 kroz tikete i live chat.