Data Protection in Bosnia and Herzegovina

Security in Bosnia and Herzegovina

Under the new DP Law, controllers and processors are required to implement appropriate technical and organizational measures to ensure the security of personal data throughout its lifecycle.

Key points include:

  • Confidentiality, integrity, and availability. Personal data must be protected against unauthorized or unlawful access, accidental loss, destruction, or damage.
  • Risk-based approach. Security measures should be proportional to the risks associated with the processing, taking into account the nature, scope, context, and purposes of the processing, as well as the likelihood and severity of potential risks to the rights and freedoms of data subjects.
  • Data breach management. Controllers must establish procedures for detecting, reporting, and investigating personal data breaches.
    • The Agency must be notified within 72 hours of a breach.
    • If the breach poses a high risk to the rights and freedoms of data subjects, the affected individuals must also be notified.
  • Ongoing review and adaptation. Security measures should be regularly tested, assessed, and updated to ensure their continued effectiveness.
  • Accountability. Controllers and processors must document the security measures taken and be able to demonstrate compliance to the Agency if requested.
  • Support to the DPO. The DPO must be properly involved and supported in assessing and monitoring security measures, ensuring compliance with the law and internal policies.

Continue reading

  • no results

Previous topic
Back to top