Serbia’s proposed overhaul of personal-data legislation would introduce new compliance requirements for companies using artificial intelligence in recruitment, customer services, profiling and automated business processes. Public consultation on the draft Law on Personal Data Protection ended on September 10. The proposal specifically addresses the use of personal information to develop, train and test AI systems, although the legislation has not yet been adopted.
The changes would expand data-governance obligations for companies already deploying AI tools, with the greatest exposure among banks, insurers, telecom operators, retailers, recruitment companies, e-commerce platforms, technology businesses and large employers processing significant amounts of customer or employee information.
AI training linked to personal-data governance
Under the draft framework, information collected for one business purpose could not automatically be reused to train or test an AI model. Companies would need to determine whether additional processing is compatible with the original purpose for which information was collected or whether another valid legal basis applies.
This would place greater emphasis on documenting what data enters AI systems, why it is processed, whether it contains personal information and which safeguards are applied. Measures such as data minimisation, pseudonymisation and anonymisation could consequently become more important for businesses deploying AI. Companies already using generative AI with internal documents, customer databases or employee information could need to review those practices under the proposed framework.
Automated decisions face additional controls
Recruitment is among the areas where AI applications can directly affect individuals. Businesses can use AI to rank applications, analyse CVs and assist in candidate selection. Similar applications are used for customer segmentation and credit processes in banking, risk analysis in insurance and personalised offers in retail. Greater regulatory scrutiny would apply when automated processing produces decisions with significant consequences for individuals.
Companies could therefore require stronger arrangements for human oversight, explainability and documentation of automated decision-making. For banks and insurers, AI governance would operate alongside existing financial-sector regulation and National Bank of Serbia supervision.
Eight-day implementation period
The draft also establishes a short implementation timetable. The proposed law would take effect eight days after publication, while some secondary legislation could be introduced later. Large companies could consequently have limited time to map AI applications, examine contracts, identify datasets, update internal procedures and introduce additional controls after adoption.
Businesses with established privacy, cybersecurity and risk-management functions would already have relevant structures in place. Smaller companies relying on third-party AI products could face difficulties in determining where information entered into external systems is stored and how it is subsequently processed.
Data protection and future AI legislation
Serbia is also preparing separate legislation specifically addressing artificial intelligence, creating potential overlap between the two regulatory frameworks. Companies could therefore have to adapt to data-protection requirements before additional obligations emerge under dedicated AI legislation.
The two areas are closely connected because AI systems depend on data, while higher-risk applications can involve information concerning employees, customers and other identifiable individuals. Regulatory coordination will consequently affect how companies determine which obligations arise from data-protection law, which may come from future AI legislation and which supervisory authority handles overlapping requirements.
Compliance services could expand
The proposed changes could create additional demand for services covering legal advice, cybersecurity, privacy engineering, AI assurance, governance software and independent compliance assessments. Companies will need to identify where AI is deployed, classify applications by risk, map data flows and demonstrate that appropriate safeguards are in place. For larger Serbian businesses, AI governance could become a continuing corporate function alongside existing cybersecurity and financial controls.
Technology providers could also face greater demand for systems demonstrating controlled data processing, human oversight and transparent AI governance, particularly from banks, international companies and Serbian businesses operating with EU-facing activities. The draft legislation therefore places greater emphasis on how companies manage the data used by AI systems, in addition to the technology’s business applications.


