Bosnia's New Data Protection Law: Why Compliance Isn't Just a Checkbox Exercise

Bosnia and Herzegovina's new Data Protection Law is now in force. Published on February 28, 2025, it begins full implementation on October 8, 2025. While organizations rush to adapt to the new requirements, most are repeating the same mistakes they made with GDPR seven years ago.
I'm not talking about technical details or administrative procedures. I'm talking about the fundamentally flawed understanding of what data protection really means for modern business.
The Problem Everyone Ignores
The new Bosnian law is essentially harmonized with the GDPR regulation, meaning it brings the same challenges that organizations across Europe have been struggling with since 2018. But instead of learning from others' mistakes, local organizations are approaching compliance as if it's a one-time administrative exercise.
This is a dangerous illusion. Companies must automate and streamline processes, otherwise GDPR compliance challenges will overwhelm them.
The new law comes into force on March 8, 2025, with an adaptation period until October 2025. This gives organizations about seven months to prepare. But prepare for what, exactly?
The Biggest Mistakes Organizations Make
Mistake #1: Treating Compliance as an IT Project
Most organizations delegate data protection to the IT department, thinking it's a technical problem. GDPR implementation challenges can be divided into technical and organizational, but organizational ones are far more complex.
Data protection isn't an IT project – it's a business process transformation. Every department that touches personal data must change how they work. HR, marketing, sales, customer support – all must understand their part of the responsibility.
Mistake #2: Documentation Instead of Implementation
I see organizations spending months creating policies and procedures, then putting them in drawers. Insufficient record-keeping of processing activities represents a continuous obligation under GDPR.
Documentation isn't the goal – it's a tool. The goal is actual privacy protection through operational processes that are executed daily.
Mistake #3: Ignoring Third Parties
One of the basic challenges organizations face is compliance with different regulations in different regions. But an even bigger problem is that organizations forget about their suppliers and partners.
Every vendor with access to your data can become your weakest link. The new law requires rigorous oversight of data processors, but most organizations don't have a clear picture of who has access to their data.
Mistake #4: Lack of Continuous Approach
Several reasons can be cited for delays including limited resources, number of applications, case complexity, and the GDPR law itself which experts and regulators find difficult to apply.
Compliance isn't a destination – it's a journey. The Data Protection Law isn't a static list of requirements you can "solve" once. It's a framework that requires continuous adaptation.
What the New Law Really Means
The new Data Protection Law brings significant changes compared to the previous law:
- Increased Fines: Monetary penalties can go up to 40 million BAM or 4% of annual turnover, whichever is higher. These are GDPR-level fines that can threaten an organization's survival.
- Expanded User Rights: Right to erasure, data portability, and automated decision-making – all require operational changes, not just legal documents.
- Mandatory DPO Appointment: For many organizations, this means a new position or external consultants. But a DPO isn't just a compliance figure – it's a strategic position that must be involved in all business decisions.
- Privacy Impact Assessment: For risky processing, organizations must conduct DPIA (Data Protection Impact Assessment). This isn't paperwork – it's strategic analysis that can change how business is conducted.
Practical Steps That Actually Work
1. Start with Data Mapping
Before you can protect data, you need to know where it is. Create a detailed map of data flow through your organization. This isn't a one-time activity – it's a process you must update with business changes.
2. Implement Privacy by Design
Instead of a retrofit approach, build privacy protection into all new projects from the start. Every new system, process, or service should be designed with privacy as a fundamental principle.
3. Create a Privacy Culture
Data protection isn't the responsibility of one person or department – it's everyone's responsibility. Invest in training that will explain to all employees why privacy is important and how they can contribute.
4. Automate Wherever Possible
Companies must automate and streamline processes to handle the complexity of modern data protection. Subject access requests, data retention, breach notifications – all of this can be automated.
Why Now Is the Right Time for Action
Organizations that invest in proper data protection now won't just avoid fines – they'll create a competitive advantage. Users increasingly value privacy, and regulators are becoming stricter.
The EU is already developing new AI regulations that will further complicate the landscape. Organizations that establish a solid foundation now will be ready for future challenges.
Bottom line: The new Data Protection Law isn't an administrative nuisance – it's an opportunity to transform your relationship with data and create a sustainable competitive advantage.
But it requires a strategic approach, not a checkbox mentality. If you don't know where to start or need help creating a comprehensive data protection program, contact your trusted advisor.
Because while you're planning, your competitors are already implementing. And regulators aren't waiting for anyone.
Data protection in 2025 isn't a compliance project – it's a business transformation that can determine your organization's future success.
