Back to Digital Security

    Bosnia's New Data Protection Law: Why Compliance Isn't Just a Checkbox Exercise

    July 29, 2025DSS Team
    Data Protection

    Bosnia and Herzegovina's new Data Protection Law is now in force. Published on February 28, 2025, it begins full implementation on October 8, 2025. While organizations rush to adapt to the new requirements, most are repeating the same mistakes they made with GDPR seven years ago.

    I'm not talking about technical details or administrative procedures. I'm talking about the fundamentally flawed understanding of what data protection really means for modern business.

    The Problem Everyone Ignores

    The new Bosnian law is essentially harmonized with the GDPR regulation, meaning it brings the same challenges that organizations across Europe have been struggling with since 2018. But instead of learning from others' mistakes, local organizations are approaching compliance as if it's a one-time administrative exercise.

    This is a dangerous illusion. Companies must automate and streamline processes, otherwise GDPR compliance challenges will overwhelm them.

    The new law comes into force on March 8, 2025, with an adaptation period until October 2025. This gives organizations about seven months to prepare. But prepare for what, exactly?

    The Biggest Mistakes Organizations Make

    Mistake #1: Treating Compliance as an IT Project

    Most organizations delegate data protection to the IT department, thinking it's a technical problem. GDPR implementation challenges can be divided into technical and organizational, but organizational ones are far more complex.

    Data protection isn't an IT project – it's a business process transformation. Every department that touches personal data must change how they work. HR, marketing, sales, customer support – all must understand their part of the responsibility.

    Mistake #2: Documentation Instead of Implementation

    I see organizations spending months creating policies and procedures, then putting them in drawers. Insufficient record-keeping of processing activities represents a continuous obligation under GDPR.

    Documentation isn't the goal – it's a tool. The goal is actual privacy protection through operational processes that are executed daily.

    Mistake #3: Ignoring Third Parties

    One of the basic challenges organizations face is compliance with different regulations in different regions. But an even bigger problem is that organizations forget about their suppliers and partners.

    Every vendor with access to your data can become your weakest link. The new law requires rigorous oversight of data processors, but most organizations don't have a clear picture of who has access to their data.

    Mistake #4: Lack of Continuous Approach

    Several reasons can be cited for delays including limited resources, number of applications, case complexity, and the GDPR law itself which experts and regulators find difficult to apply.

    Compliance isn't a destination – it's a journey. The Data Protection Law isn't a static list of requirements you can "solve" once. It's a framework that requires continuous adaptation.

    What the New Law Really Means

    The new Data Protection Law brings significant changes compared to the previous law:

    • Increased Fines: Monetary penalties can go up to 40 million BAM or 4% of annual turnover, whichever is higher. These are GDPR-level fines that can threaten an organization's survival.
    • Expanded User Rights: Right to erasure, data portability, and automated decision-making – all require operational changes, not just legal documents.
    • Mandatory DPO Appointment: For many organizations, this means a new position or external consultants. But a DPO isn't just a compliance figure – it's a strategic position that must be involved in all business decisions.
    • Privacy Impact Assessment: For risky processing, organizations must conduct DPIA (Data Protection Impact Assessment). This isn't paperwork – it's strategic analysis that can change how business is conducted.

    Practical Steps That Actually Work

    1. Start with Data Mapping

    Before you can protect data, you need to know where it is. Create a detailed map of data flow through your organization. This isn't a one-time activity – it's a process you must update with business changes.

    2. Implement Privacy by Design

    Instead of a retrofit approach, build privacy protection into all new projects from the start. Every new system, process, or service should be designed with privacy as a fundamental principle.

    3. Create a Privacy Culture

    Data protection isn't the responsibility of one person or department – it's everyone's responsibility. Invest in training that will explain to all employees why privacy is important and how they can contribute.

    4. Automate Wherever Possible

    Companies must automate and streamline processes to handle the complexity of modern data protection. Subject access requests, data retention, breach notifications – all of this can be automated.

    Why Now Is the Right Time for Action

    Organizations that invest in proper data protection now won't just avoid fines – they'll create a competitive advantage. Users increasingly value privacy, and regulators are becoming stricter.

    The EU is already developing new AI regulations that will further complicate the landscape. Organizations that establish a solid foundation now will be ready for future challenges.

    Bottom line: The new Data Protection Law isn't an administrative nuisance – it's an opportunity to transform your relationship with data and create a sustainable competitive advantage.

    But it requires a strategic approach, not a checkbox mentality. If you don't know where to start or need help creating a comprehensive data protection program, contact your trusted advisor.

    Because while you're planning, your competitors are already implementing. And regulators aren't waiting for anyone.

    Data protection in 2025 isn't a compliance project – it's a business transformation that can determine your organization's future success.