Does My Website Need a Privacy Policy?
When a small business in Novi Sad launches its first website, the privacy policy is usually the last thing anyone thinks about - and the first thing that causes problems later. The question is simple: is a privacy policy legally required for a website in Serbia, or is it only needed if the site works with EU clients? The short answer is - it's required for almost every website, under Serbian law, not only under GDPR. As a Novi Sad-based agency working daily on websites for clients across Vojvodina, Belgrade, and the region, we see this topic on every single project. In this guide, we'll show exactly what Serbian law requires, when GDPR applies on top, what the privacy policy must contain, what the fines are for sites that don't have one, and when it's actually worth hiring a lawyer.
The short answer - do you need a privacy policy
So you don't have to read the whole article for an answer to a simple question, here it is up front:
- If the site has a contact form, newsletter, user accounts, or any form at all - a privacy policy is required
- If the site uses Google Analytics, Meta Pixel, Hotjar, or similar tracking tools - it's required
- If the site uses any cookies beyond strictly necessary ones - a cookie policy plus a consent banner is also required
- If the site sells goods or services - both a privacy policy and terms of service are required, and for online stores also a refund policy
- If you work with EU clients (or an English version targets the EU market) - GDPR compliance is added on top
- The only sites that don't need a privacy policy are purely static digital business cards - no forms, no analytics, no cookies beyond strictly necessary
In practice, that means 99% of business websites in Serbia must have a privacy policy. Below we break down exactly what the law requires and what happens if you don't have one.
What Serbian law says - the Personal Data Protection Act (ZZPL)
The primary law regulating this area in Serbia is the Personal Data Protection Act (Zakon o zaštiti podataka o ličnosti, or ZZPL), which came into force on August 21, 2019. The law is largely harmonized with the European GDPR, which in practice means the Serbian standard is not more lenient - in most cases it's almost identical.
A key definition to understand: personal data is any information relating to an identified or identifiable natural person. That includes name, email, phone number, address, IP address, username, photo, and even combinations of data from cookies that make a visitor identifiable. In other words, the moment a site collects any of those - and almost every site does - it legally becomes a data controller.
The body responsible for enforcement in Serbia is the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik). The Commissioner has the authority to initiate proceedings following a citizen complaint or ex officio, and can issue fines against legal entities, sole traders, and responsible individuals.
When GDPR applies on top
GDPR (the General Data Protection Regulation) doesn't only apply to EU companies. It applies to any company, from any country, that processes personal data of EU citizens. That means a Serbian website can be subject to GDPR even if the company is registered in Serbia and has no physical office in the EU.
Concrete cases where GDPR also binds Serbian websites:
- An English-language website targeting clients in Germany, Austria, Italy, or any other EU country
- An online store that ships goods to the EU or accepts payments from the EU
- A SaaS or software company from Novi Sad whose users may come from the EU
- A consulting or marketing agency working with EU-based companies
- Any website with a signup option open to users from EU countries
If the business doesn't fit any of these scenarios, aligning the privacy policy with Serbian ZZPL is enough. If it fits any of them, the policy must additionally cover GDPR obligations, which are slightly more detailed (particularly around user rights and the legal basis for processing).
What a privacy policy must contain
A privacy policy isn't a formality you tick off with three generic paragraphs. To satisfy legal requirements, it has to clearly answer a precisely defined set of questions. The minimum required by ZZPL (and GDPR):
- Who the data controller is - full company name, address, tax number (PIB), and registration number
- Contact details for privacy questions - usually an email address (e.g. privacy@yourcompany.com)
- Which personal data is collected - name, email, IP, cookies, form data, etc.
- Why that data is collected - purpose of processing (responding to inquiries, sending newsletters, fulfilling orders)
- Legal basis for processing - consent, contract performance, legal obligation, or legitimate interest
- Who has access to the data - third parties and processors (Google, hosting company, payment processor)
- Whether data is transferred outside Serbia or the EU - and under what conditions
- How long data is retained - concrete timeframes for each category
- User rights - the right to access, correction, erasure, objection, and data portability
- Information about the Commissioner and the right to file a complaint
A privacy policy must be written in clear, understandable language - not legalese that nobody reads. This is explicitly required by law. Copy-pasted English text from a foreign site or a translation not adapted to the specific company will not hold up if a complaint is filed.
Cookie policy - separate document or part of the same policy
If a site uses any cookies that aren't strictly necessary for it to function - and most sites do, through Google Analytics, Facebook Pixel, Hotjar, or remarketing tools - a cookie policy is required. Alongside it, a cookie consent banner is required to ask visitors for explicit consent BEFORE those cookies are set.
The cookie policy can be a separate document or a section inside the privacy policy. Either way, it must contain:
- An explanation of what cookies are and how they're used
- A list of cookies by category (strictly necessary, analytics, marketing, functional)
- The name of each specific cookie, who sets it, and how long it lasts
- Instructions on how a visitor can withdraw consent or delete cookies
The most common mistake we see on Serbian websites is a banner that only notifies the visitor that the site uses cookies, with no option to refuse. That doesn't meet ZZPL or GDPR requirements. The banner must offer a clear choice - accept all, reject all (or accept only strictly necessary), and ideally a per-category customization option.
What happens if a site has no privacy policy - the fines
The absence of a privacy policy isn't a direct violation on its own - but everything that goes with it is. If a site collects data without clearly published information about processing, without consent where consent is required, or without meeting information obligations - that's a violation of ZZPL, and the consequences can be serious.
ZZPL fines for legal entities range from 50,000 to 2,000,000 dinars per offense. For sole traders they're lower (up to 500,000 dinars), and for the responsible individual inside a legal entity up to 150,000 dinars. These fines aren't theoretical - the Commissioner has already issued multiple fines against Serbian companies for non-compliant websites.
For sites subject to GDPR, fines are incomparably higher - up to €20 million or 4% of global annual revenue, whichever is higher. Small Serbian companies rarely receive maximum fines, but it's enough for one dissatisfied EU client to file a complaint to trigger a procedure that, even without a maximum fine, easily costs thousands of euros in legal fees and time.
On top of direct fines, practical consequences include suspension of Google Ads and Meta Ads accounts - both platforms require a site to have a privacy policy and clear cookie consent before ads can run. Sites without them are periodically auto-suspended without warning.
Do you need a lawyer or is a template enough
The answer to this question varies by business. For most small businesses - local service companies, digital business cards, simple contact websites - a quality template adapted to the specific company is fully sufficient. Hiring a lawyer for a basic version is an overreach that most agencies and good templates can cover for far less money.
Hiring a lawyer specialized in data protection is justified in the following cases:
- The site processes sensitive data - health, biometric, financial
- An online store with a large user base and international shipping
- A SaaS or software company processing data on behalf of third parties
- A company working with large EU clients that require a Data Processing Agreement (DPA)
- Any platform working with minors as users
For all other cases, a standard template adapted to the specific company (with the correct name, tax number, list of tools used, and a realistic description of processing) is both legally sufficient and practical. What matters is that the template isn't just a copy-paste from another site - it must accurately match the actual data processing on your website.
Where exactly on the site the privacy policy should live
The privacy policy must be reachable from every page of the site, at any moment. It doesn't need to be in the main navigation (and usually isn't - it confuses visitors), but there must be a permanent link leading to it. The standard location is the site footer, alongside the terms of service and the cookie policy.
Additional places where a link to the privacy policy must exist:
- Below every form (contact, newsletter, signup) - with a clear note about data processing and a link
- In the cookie consent banner - a link to the cookie policy (or the relevant section of the privacy policy)
- On thank-you pages shown after form submission
- On signup and account pages
- If the site has a checkout - required before order finalization
The privacy policy is one of the pages that must exist on every serious business website - we wrote a more detailed list of all the pages a website should have in our guide to the essential pages of a website, where the privacy policy is discussed specifically in the context of legal obligations in Serbia.
For businesses in Novi Sad - the local specifics
For companies registered in Novi Sad, Belgrade, or any other Serbian city, the Serbian ZZPL applies without exception. Regardless of whether the hosting is abroad or the site is in English, if the company is legally registered in Serbia - the obligations follow Serbian law.
Practical advice we give clients from Novi Sad when we build their site:
- The company name and tax number (PIB) in the privacy policy must match the details registered with the Serbian Business Registers Agency (APR)
- The address listed in the policy must be the registered head office address, not the working office
- If the company is a flat-tax sole trader (paušalac), that also has to be clearly indicated - the legal status affects obligations
- The contact email for privacy questions should be independent from the main contact email (an alias like privacy@company.rs works fine)
- If the site also targets regional visitors (Bosnia, Montenegro, Croatia), the policy should cover those jurisdictions - but for most cases the Serbian ZZPL is a sufficient baseline
For sites that are just launching, we usually include the privacy policy as a standard part of every custom-built website - together with the cookie policy, the consent banner, and the terms of service where applicable. The concrete scope of work and what's included in each package is on our pricing page. For most clients, that's enough for the site to be legally compliant without extra lawyer fees.
When to update or refresh the privacy policy
A privacy policy isn't a document you write once and forget. It has to be updated every time there's a change in how data is processed. Concretely, revision is required in these situations:
- When a tool that handles data is added or removed (new analytics, new chat widget, new CRM)
- When new functionality is added to the site (signup, payments, comments)
- When the company's legal status or registered address changes
- When the law or relevant case law changes (review at least once a year)
- When a new country is added to the list of data destinations or a new third party is introduced
Every version of the privacy policy must have a clear effective date, and as a rule the version history is kept in case of a complaint or dispute. This is the detail most companies forget - but which the Commissioner will ask for in the event of an audit.
Frequently asked questions
- Does the privacy policy have to be in Serbian?
- For websites of companies registered in Serbia, the policy must be available in Serbian (Latin or Cyrillic script). If the site has multiple language versions, the privacy policy must exist in every language of the site - an English version of the site without an English privacy policy is not compliant.
- Do I need a privacy policy if I only have a static site with no forms?
- If the site has no forms, no analytics, no marketing cookies and collects no data at all - a privacy policy isn't required. In practice this is the exception - the moment you turn on Google Analytics or a cookie banner, the obligation kicks in. It's safer to always have at least a minimal version.
- What are the fines if a website doesn't have a privacy policy in Serbia?
- ZZPL fines range from 50,000 to 2,000,000 dinars per single offense for legal entities. For sole traders they're lower, up to 500,000 dinars. For sites also subject to GDPR, fines can be incomparably higher - up to €20 million or 4% of global revenue.
- Can I copy a privacy policy from another website?
- Legally you can, but practically it's dangerous - the policy has to accurately match the actual data processing on your website (which forms, which tools, which third parties). If it doesn't match, it doesn't meet legal requirements even if the text is perfectly written. It's better to use a template and adapt it to the specific company.
- Do I need a cookie policy alongside the privacy policy?
- If the site uses any cookies beyond strictly necessary ones (and most do, through analytics and marketing tools), both a cookie policy and a cookie consent banner with a clear accept/reject choice are required. The cookie policy can be a separate document or a section inside the privacy policy.
- Do I need a lawyer to write my privacy policy?
- For most small businesses, no - a quality template adapted to the specific company, with the correct name, tax number, and list of tools the site uses, is legally sufficient. A lawyer is a justified expense for sensitive industries (health, finance), large stores with EU markets, or companies working with minors.
- Is the privacy policy different from terms of service?
- Yes - they're two different documents. The privacy policy covers processing of personal data. Terms of service define the rights and obligations between the site and the user - what can be used, copyright, liability limits. Most business sites need both, and online stores also need a refund policy.
- When a site targets EU clients - is ZZPL enough or is GDPR needed?
- If the site in any way targets EU users (language, currency, shipping, advertising), GDPR applies alongside ZZPL. The privacy policy must cover additional GDPR obligations - the specific legal basis for processing, user rights under GDPR, and if needed a Data Processing Agreement (DPA) with third parties.
Conclusion
A privacy policy isn't a formality, but it's not a reason to panic either. For most small and medium-sized businesses in Serbia, a well-adapted template that accurately describes the site's data processing is enough to satisfy ZZPL. If the site also targets the EU market - a layer of GDPR obligations is added, which are slightly stricter but manageable without a lawyer for straightforward cases. What's not worth doing is delaying - fines under Serbian law are real, and a Google Ads or Meta Ads account suspension due to a missing policy can cost more than a full year of website expenses.
If you're building a new website or you're not sure whether your current one meets the legal requirements, get in touch - we'll check what's actually set up on the site, which policies are missing, and suggest exactly what needs to be added so the site is fully compliant with Serbian law and GDPR where applicable.
Ready for a website that delivers results?
Schedule a free call and together we'll find a solution tailored to your business.
Schedule a free call