Serbia tightens white-collar crime laws with EU-aligned data protections

by Isadora Blume -259 min ago
Serbia tightens white-collar crime laws with EU-aligned data protections
The core of data protection rests in the Law on Personal Data Protection, which mirrors the EU General Data Protection Regulation (GDPR).

Serbia’s legal approach to white-collar crime and data protection blends domestic regulations with international commitments, creating a structure that harmonizes EU-aligned data standards with a broad criminal code addressing fraud, corruption, and financial misconduct.

The core of data protection rests in the Law on Personal Data Protection, which mirrors the EU General Data Protection Regulation (GDPR). This law establishes strict rules for handling personal data, demanding a valid legal foundation—such as consent, contractual needs, or legal obligations—before processing can occur. Transparency, purpose limitation, and data minimization are mandatory, while sensitive categories like health or financial records require heightened security measures. Data transfers outside Serbia are strictly regulated, with foreign recipients needing adequacy decisions or approved safeguards.

Non-compliance triggers serious repercussions: administrative penalties, misdemeanour liability, and potential exclusion of evidence from internal investigations. These rules are particularly critical in corporate environments, where whistleblowing, employee monitoring, and internal audits must strictly adhere to the framework. Failing to document processing activities, including legal justifications, purposes, and data categories, can lead to evidence being ruled inadmissible in legal proceedings.

Criminal Code Targets Corruption and Fraud

Serbia’s criminal justice system for economic offenses is governed by the Criminal Code (CC), last revised in 2024. Corruption, fraud, and corporate misconduct are explicitly outlawed, with penalties ranging from bribery to official misconduct. Key supporting laws include the Law on the Prevention of Corruption (2019), the Law on Money Laundering (2017), and the Law on Seizure and Confiscation of Proceeds of Crime (2013). Serbia has also joined international agreements, such as the Civil Law Convention on Corruption, allowing victims to claim compensation for damages.

Unlike some legal systems, Serbia does not have a separate civil liability framework for criminal acts. Instead, victims must pursue claims either within criminal proceedings or through independent civil lawsuits. This dual system ensures accountability while maintaining clear procedural boundaries.

Corporate liability is regulated by the Law on the Liability of Legal Entities for Criminal Offences (Official Gazette No. 97/2008). This includes negligence in supervising employees. A legal entity may also be liable where a responsible person fails to exercise due supervision or control over individuals under their authority, thereby enabling the commission of a criminal offence for the benefit of the legal entity.

Expansive Jurisdiction Over Offenses

Serbia’s jurisdiction is expansive. The CC applies to crimes committed on its territory, including those on Serbian vessels or aircraft, regardless of location. Under the principle of ubiquity, offenses are considered domestic if their actions or effects occur in Serbia-a key rule for cross-border financial fraud. Foreign entities are liable for criminal offences committed on the territory of Serbia and for offences committed abroad to the detriment of Serbia, its citizens or a Serbian legal entity.

The CC outlines core offenses: bribery, fraud, and abuse of office. Bribery requires intent to influence official decisions in exchange for benefits, with penalties including fines and imprisonment. Fraud demands proof of unlawful financial gain, while abuse of office involves exceeding authority or failing duties, both punishable by imprisonment and fines, depending on the financial impact.

Intent is central to most offenses. Prosecutors must prove it, though some cases presume intent based on the nature of the act. This legal emphasis shapes defense strategies, which often challenge the prosecution’s ability to establish criminal intent.

Employee Monitoring Rules and Risks

Data processing in employment contexts, such as employee monitoring, is permitted only when justified by a legitimate business interest and does not disproportionately violate workers’ rights. Surveillance must be transparent, with employees informed of its scope and purpose. Violations can lead to administrative penalties and misdemeanour liability, and courts may also exclude evidence obtained through non-compliant monitoring, weakening potential criminal or civil cases.

Fraud is categorized by the value of the unlawful gain or damage. If the amount exceeds RSD 5 million, penalties rise to one to five years in prison, combined with fines up to RSD 3 million. Abuse of office in severe cases-where the gain surpasses RSD 3 million-results in three to ten years imprisonment. Financial damage is required in some offences, while in others the offence exists regardless of whether damage occurred. Prosecutors often rely on circumstantial evidence, including digital records or witness statements, to establish intent when direct proof is unavailable.

Serbia’s enforcement mechanisms include more than 50 bilateral treaties on mutual legal assistance in criminal matters, enabling cross-border evidence sharing, asset freezing, and suspect extradition. The Civil Law Convention on Corruption ensures victims can seek compensation in Serbian courts for damages caused by foreign actors, provided the offense affects Serbian interests.

Leave a Reply

Your email address will not be published. Required fields are marked *