Key Facts
Overview
Bosnia and Herzegovina adopted a new GDPR-aligned Data Protection Act on January 30, 2025, with enforcement beginning October 2025. The law aligns with both the GDPR and the EU Law Enforcement Directive, establishing GDPR-level penalties and granting the AZLP significant enforcement powers.
What This Means for Your Website
- Consent will be required for personal data processing including cookies when enforcement begins in October 2025
- GDPR-level penalties apply: up to EUR 20 million or 4% of global annual turnover
- The AZLP has been granted significant enforcement powers, though its initial approach remains to be seen
- Data breach notification and cross-border transfer rules apply
Key Requirements
The AZLP enforces the new law with GDPR-level penalties of up to EUR 20 million or 4% of global turnover. The law introduces strengthened data subject rights, data breach notification obligations, and an accountability-based compliance framework. Whether the AZLP will take an aggressive or gradual advisory approach to initial enforcement remains unclear.
How ConsentStack Handles This
ConsentStack applies GDPR-compliant consent standards for visitors from Bosnia and Herzegovina, ensuring compliance as enforcement begins in October 2025.
Penalties
Up to 4% of global annual turnover or EUR 20 million (GDPR-aligned).
Key Requirements
- Consent for personal data processing including cookies
- Strengthened data subject rights
- Data breach notification obligations
- Cross-border data transfer regulations
- Accountability-based compliance framework
Notable Provisions
- GDPR-level penalties (up to 4% turnover / EUR 20 million)
- Enforcement begins October 2025
- AZLP granted significant enforcement powers
- Aligns with both GDPR and Law Enforcement Directive
Other Europe Regulations
Frequently Asked Questions
Stay compliant with BiH DPA 2025
ConsentStack helps you implement Opt-in consent for Bosnia and Herzegovina automatically.