GDPR AI Chatbots in Serbia: Legal Challenges and Guidance for SMBs Using AI Voice Agents
Learn how SMBs in Serbia can use AI chatbots in compliance with GDPR and local data protection laws.

Understanding GDPR and Serbian Data Protection for AI Chatbots
Small and medium-sized businesses (SMBs) in Serbia are increasingly adopting AI chatbots and voice agents to enhance customer support and automate workflows. However, deploying these AI tools brings strict legal responsibilities under Serbia’s Personal Data Protection Act (PDPA, 2019), which is closely aligned with the EU’s GDPR. The PDPA governs any AI system processing personal data, making it essential for SMBs to understand compliance requirements to avoid legal risks and reputational damage.
Serbia’s Evolving Legal Framework for AI Data Processing
In July 2026, Serbia’s Ministry of Justice released a Draft PDPA expanding the law from 102 to 175 articles, explicitly regulating AI-driven personal data processing. This draft introduces new obligations such as mandatory Data Protection Impact Assessments (DPIAs) for high-risk AI applications, requirements to inform individuals when an AI system interacts directly with them, and a ban on fully automated processing without human involvement when it could cause harm.
The public consultation on the draft closes on 10 September 2026, highlighting the urgent need for SMBs to review their AI data practices. Unlike the EU, which postponed some AI compliance deadlines until 2027 and 2028, Serbia’s regulations do not offer a similar grace period.
Key Compliance Requirements for AI Chatbots Under Serbian Law
- Mandatory DPIAs for high-risk AI: If your chatbot or voice agent profiles users, monitors behavior, or processes sensitive data, you must conduct and document a DPIA assessing risks and mitigation measures.
- Transparency and disclosure: AI systems must disclose their nature when communicating directly with users, typically by introducing themselves as AI assistants (e.g., "I am an AI assistant / Ja sam AI asistent").
- Restrictions on automated decision-making: Fully automated decisions with legal or significant effects on individuals are prohibited without human oversight, explicit consent, or legal authorization.
- Documented accountability: Controllers must keep records of prior balancing tests, proportionality assessments, and risk evaluations to demonstrate compliance.
Practical Tips for Safe AI Chatbot Use in Serbia
- Audit your data flows: Map how your chatbot collects, processes, and stores personal data. Identify if any processing is high-risk under the Draft PDPA.
- Implement DPIAs early: Use lightweight DPIA templates tailored for SMBs to efficiently evaluate risks and document mitigation strategies.
- Inform users clearly: Add simple UI text in Serbian and English to disclose chatbot identity and data use.
- Design human-in-the-loop processes: Ensure critical decisions—such as hiring or credit approvals—include human review to comply with the ban on harmful fully automated processing.
- Review vendor contracts carefully: Since Serbian law lacks a dedicated AI liability statute, ensure contracts clearly allocate responsibilities and consider insurance for AI-related risks.
Understanding Liability and Enforcement
Serbia currently applies its 1978 Law on Obligations for AI-related damages, requiring proof of fault and causation—a challenging burden with complex AI systems. Monetary fines under Serbian data protection law remain lower than GDPR levels, but enforcement increasingly focuses on corrective orders like data deletion and processing halts, which can harm business reputation.
Common Misconceptions to Avoid
- "GDPR compliance equals Serbian compliance." Serbia’s Draft PDPA introduces stricter rules not covered by GDPR.
- "No AI law means no restrictions." The 2019 PDPA already applies to AI systems processing personal data.
- "Simple chatbots don’t need DPIAs." Profiling or behavior monitoring triggers DPIA requirements.
- "Low fines mean low risk." Corrective actions and reputational harm pose significant risks.
Preparing for the Future
Serbia’s 2025–2030 AI Strategy aims for comprehensive AI legislation by 2027, modeled on the EU’s risk-based AI Act. Early alignment with emerging standards and ethical guidelines will ease future compliance and reduce legal uncertainty.
Conclusion
For Serbian SMBs using AI chatbots and voice agents, understanding and complying with GDPR-aligned local laws is crucial to avoid legal pitfalls. By conducting DPIAs, maintaining transparency, integrating human oversight, and preparing for evolving regulations, businesses can harness AI benefits while safeguarding personal data and trust.
This article is based on the latest legal updates and statistical insights relevant to GDPR AI chatbots in Serbia as of mid-2026.



