Cyber Law at Bosnia and Herzegovina
Bosnia and Herzegovina has developed a multifaceted legal and institutional framework to address cybercrime, data protection, and cybersecurity, aligning with European Union standards and international conventions.
Cybercrime Legislation
The country has enacted specific laws to combat cybercrime:
Criminal Law of the Federation of Bosnia and Herzegovina: Defines offenses such as unauthorized access to computer systems and data, with penalties including fines and imprisonment up to 12 years for severe cases.
Criminal Code of Republika Srpska: Establishes criminal offenses related to computer data security, including unauthorized access and data manipulation, with penalties up to 10 years of imprisonment.
Criminal Law of District Brčko: Contains provisions addressing cybercrimes, though specific details are less comprehensive compared to the other two jurisdictions.
Data Protection
Bosnia and Herzegovina's data protection landscape is evolving:
Personal Data Protection Law (2006): The existing law is being updated to align with the EU's General Data Protection Regulation (GDPR). The new law, adopted in January 2025, introduces enhanced rights for individuals, such as data portability and the right to be forgotten, and imposes stricter obligations on organizations, including mandatory data breach notifications within 72 hours and the appointment of Data Protection Officers for certain entities.
Convention 108+: Bosnia and Herzegovina ratified the Amending Protocol to Convention 108 in July 2023, reinforcing its commitment to international data protection standards.
Cybersecurity Framework
The country has established several initiatives to bolster cybersecurity:
National Cyber Security Incident Response Team (CSIRT): Established in 2017, CSIRT facilitates the reporting and management of cybersecurity incidents, providing guidance and support to organizations in mitigating cyber threats.
CyberSEE Project: In May 2024, Bosnia and Herzegovina hosted a workshop on electronic evidence for law enforcement, judges, and prosecutors, focusing on advanced financial forensics and methods for tracing cryptocurrencies and combating online fraud.
Institutional Oversight
The Personal Data Protection Agency (PDPA) oversees data protection enforcement, including the registration of data processing activities and the imposition of fines for non-compliance. The Ministry of Security manages the national CSIRT, while regional CERTs operate within the entities of Republika Srpska and the Federation of Bosnia and Herzegovina.
Conclusion
Bosnia and Herzegovina is actively enhancing its legal and institutional frameworks to address cybercrime, data protection, and cybersecurity, aligning with EU standards and international conventions. These efforts aim to strengthen the country's resilience against cyber threats and ensure the protection of personal data for its citizens.

0 comments