Practice areas

Data Protection and Privacy

Compliance that survives an inspection.

Legal support in ensuring compliance with personal data protection requirements, including records of processing activities, privacy policies and notices, internal policies and procedures, agreements with data processors, and handling requests from data subjects. Our services also include preparation for regulatory inspections and supervisory proceedings, response to personal data breaches, and representation before the competent authorities.

Data protection compliance is not limited to preparing a single document or publishing a privacy policy on a website. Compliance requires an organisation to understand what personal data it processes, why it uses the data, how long it retains them, to whom they are disclosed, and what measures are implemented to protect them.

The Law Office provides legal support to companies, entrepreneurs, institutions, associations, and other organisations processing personal data relating to employees, clients, service users, business partners, and other individuals.

Assessment of the Existing Compliance Framework

The first step towards compliance is understanding the actual flow of personal data within the organisation. Documentation should reflect the organisation’s actual operations, information systems, and relationships with other parties involved in processing.

The initial assessment may include:

  • identifying organisational units that process personal data;
  • identifying categories of data subjects whose personal data are processed;
  • identifying the categories of personal data collected;
  • determining the purpose of each processing activity;
  • analysing the legal basis for processing;
  • identifying the sources from which personal data are obtained;
  • identifying recipients to whom personal data are disclosed;
  • reviewing retention periods and data deletion procedures;
  • analysing information systems and physical records;
  • reviewing relationships with external service providers;
  • identifying international data transfers;
  • assessing existing organisational and technical security measures;
  • identifying processing activities that may pose an increased risk to the rights of individuals.

Based on the assessment, an overview of identified compliance gaps and an action plan for achieving compliance are prepared.

Records of Processing Activities

Controllers and processors should be able to demonstrate which processing activities they carry out and how they comply with their legal obligations. Records of processing activities constitute one of the fundamental documents for organising and demonstrating data protection compliance.

The Law Office provides support in:

  • identifying processing activities that should be recorded;
  • preparing records of processing activities;
  • determining the purpose and legal basis of each processing activity;
  • identifying categories of data subjects and personal data;
  • recording recipients to whom personal data are disclosed;
  • determining retention periods;
  • recording international data transfers;
  • describing organisational and technical security measures;
  • establishing procedures for regular review and updating of records;
  • aligning records of processing activities with other internal policies and procedures.

Records are prepared according to the organisation’s actual processes and updated whenever a new service, information system, type of processing, or external service provider is introduced.

Legal Basis and Principles of Processing

Every processing activity must have a specified purpose and an appropriate legal basis. Consent is only one possible legal basis and should not be relied upon where processing is based on law, contract, legitimate interests, or another applicable legal ground.

Legal support includes:

  • determining the appropriate legal basis for processing;
  • assessing whether personal data are adequate, relevant, and limited to what is necessary;
  • assessing whether the purpose of processing is justified;
  • analysing whether legitimate interests may be relied upon;
  • conducting legitimate interests assessments;
  • determining the conditions for obtaining valid consent;
  • preparing clear consent wording;
  • establishing procedures for withdrawal of consent;
  • assessing whether personal data may be used for a new purpose;
  • aligning retention periods with the purpose of processing and applicable sector-specific legislation.

Privacy Notices and Policies

Individuals should receive clear and understandable information about who processes their personal data, for what purpose, on what legal basis, for how long, and what rights they may exercise.

The Law Office prepares and adapts:

  • privacy policies for websites and applications;
  • privacy notices for clients and service users;
  • privacy notices for employees and job applicants;
  • privacy notices for business partners and contact persons;
  • CCTV privacy notices;
  • privacy notices for visitors to business premises;
  • information provided during telephone calls or electronic communications;
  • consent wording where consent constitutes the appropriate legal basis;
  • notices concerning cookies and similar technologies.

Documents are prepared in clear language and adapted to the time and manner in which personal data are collected.

Data Subject Rights

Organisations should establish a clear procedure for receiving, verifying, and responding to requests from individuals. Responses must be complete, timely, and consistent with the rights of other persons and applicable confidentiality obligations.

The Law Office provides support in relation to the exercise of rights concerning:

  • access to personal data;
  • obtaining a copy of personal data;
  • rectification of inaccurate or incomplete personal data;
  • erasure of personal data where the statutory requirements are met;
  • restriction of processing;
  • data portability;
  • objection to processing;
  • withdrawal of consent;
  • protection in relation to automated decision-making and profiling;
  • lodging complaints with the Personal Data Protection Agency;
  • judicial remedies and compensation for damage.

Support for controllers also includes preparing internal procedures, request forms, registers of requests received, and response templates.

Employee and Applicant Data

Employers process significant amounts of personal data from the recruitment stage until termination of employment and expiry of statutory retention periods. Processing should be based on a clearly defined purpose and limited to personal data that are genuinely necessary.

Legal support includes:

  • applicant data and recruitment procedures;
  • content and retention of personnel files;
  • records relating to working hours, remuneration, and absences;
  • processing of employees’ health data;
  • access control to business premises and information systems;
  • use of business email accounts and devices;
  • entry and exit records;
  • workplace CCTV;
  • internal investigations and whistleblowing procedures;
  • publication of employee photographs and personal data;
  • disclosure of personal data to accounting service providers, insurance companies, and other recipients;
  • retention periods and deletion of documentation following termination of employment.

Clients, Service Users and Marketing

Client and user data are often processed through multiple systems and for different purposes. Processing necessary for entering into and performing a contract should be distinguished from marketing, profiling, and other additional purposes.

The Law Office provides support in:

  • collection of personal data during sales and provision of services;
  • conclusion and performance of contracts;
  • maintenance of customer and CRM records;
  • verification of user identity;
  • recording communications and customer requests;
  • direct marketing by email, telephone, and other channels;
  • customer segmentation and profiling;
  • organisation of loyalty programmes;
  • recording telephone calls;
  • use of cookies and analytics tools;
  • organisation of promotional activities;
  • publication of photographs, testimonials, and customer experiences;
  • combining personal data obtained from different sources.

Special Categories of Personal Data

Health data, biometric and genetic data, and other special categories of personal data specified by law require a higher level of protection and additional assessment of the lawfulness of processing.

Legal support may include:

  • identifying the specific legal condition permitting processing;
  • restricting access to authorised personnel;
  • regulating confidentiality and professional secrecy obligations;
  • preparing specific notices and procedures;
  • determining retention periods;
  • assessing whether a data protection impact assessment is required;
  • regulating relationships with processors by contract;
  • handling requests for access to particularly sensitive personal data;
  • assessing the consequences of incidents involving such categories of personal data.

Controllers, Joint Controllers and Processors

Before engaging an external service provider, its actual role in processing personal data should be determined. The title of the agreement is not decisive — responsibility depends on who determines the purposes and means of processing.

The Law Office provides support in:

  • determining the role of each party involved in processing;
  • distinguishing between controllers and processors;
  • regulating relationships between joint controllers;
  • drafting and reviewing data processing agreements;
  • defining permissible instructions to processors;
  • establishing contractual confidentiality and security obligations;
  • engagement of sub-processors;
  • regulating assistance with the exercise of data subject rights;
  • procedures in the event of a personal data breach;
  • return or deletion of personal data following termination of the agreement;
  • establishing the controller’s audit and inspection rights in relation to processors.

These agreements are particularly important in relationships with accounting service providers, IT support providers, cloud platforms, marketing agencies, call centres, and other external service providers.

Data Protection Impact Assessments

Where planned processing is likely to result in a high risk to the rights and freedoms of individuals, its impact on data protection should be assessed before the processing begins.

The Law Office provides support in:

  • determining whether a data protection impact assessment is required;
  • describing the proposed processing and its purposes;
  • assessing the necessity and proportionality of processing;
  • identifying risks to individuals;
  • determining measures to mitigate identified risks;
  • documenting conclusions and adopted measures;
  • involving the Data Protection Officer;
  • preparing for prior consultation with the Personal Data Protection Agency where a high risk cannot be sufficiently mitigated;
  • periodically reviewing the assessment following changes to systems or processing activities.

Data Protection by Design and by Default

Data protection should be incorporated into a product, service, or process from the outset rather than added after a system has already been implemented.

Legal support includes:

  • reviewing new applications, platforms, and information systems;
  • determining the minimum amount of personal data necessary for the intended purpose;
  • regulating user permissions and access rights;
  • establishing appropriate privacy-friendly default settings;
  • defining automatic deletion periods;
  • pseudonymisation and other risk-reduction measures;
  • reviewing profiling and automated decision-making functionalities;
  • preparing privacy notices and user controls;
  • regulating relationships with technology providers by contract.

Data Protection Officer

Certain organisations are required to appoint a Data Protection Officer, while others may do so voluntarily. Whether an appointment is required depends on the nature, scope, and manner of processing rather than solely on the number of employees.

The Law Office provides support in:

  • assessing whether there is an obligation to appoint a Data Protection Officer;
  • defining the position, duties, and responsibilities of the Data Protection Officer;
  • preparing the appointment decision;
  • ensuring the Data Protection Officer’s independence and access to senior management;
  • notification of contact details to the competent Personal Data Protection Agency;
  • defining cooperation between the Data Protection Officer and organisational units;
  • preparing annual work and reporting plans;
  • providing professional legal support to the appointed Data Protection Officer.

Personal Data Security

Controllers and processors are required to implement security measures appropriate to the level of risk, the categories of personal data, the manner of processing, and the potential consequences for individuals.

Legal support includes:

  • legal assessment of existing security measures;
  • preparation of information security and confidentiality policies;
  • regulating access to personal data according to business roles;
  • rules governing the use of business devices and information systems;
  • backup and data recovery procedures;
  • maintaining access logs and other relevant records;
  • management of risks associated with external service providers;
  • employee obligations in the event of a security incident;
  • periodic review of implemented measures;
  • documentation of security measures for the purpose of demonstrating compliance.

Technical measures are determined in cooperation with information security specialists, while the Law Office ensures that their implementation is appropriately regulated through internal policies and contractual arrangements.

Personal Data Breaches

Loss of documentation, unauthorised access, misdirected communications, theft of devices, attacks on information systems, or accidental disclosure may constitute a personal data breach.

The Law Office provides support through:

  • legal assessment of the incident and its scope;
  • identifying the categories of personal data and affected individuals;
  • assessing risks to the rights and freedoms of individuals;
  • documenting the facts, consequences, and measures taken;
  • preparing notification to the Personal Data Protection Agency where legally required;
  • preparing communications to affected individuals where required;
  • coordination with IT specialists and other relevant parties;
  • communication with business partners and processors;
  • preparing responses to requests from competent authorities;
  • revising procedures to prevent recurrence of the incident.

An incident response plan should be prepared in advance because the deadlines for assessing and reporting personal data breaches are short.

CCTV and Access Control

CCTV involves the processing of personal data and must have a defined purpose, an appropriate legal basis, and adequate safeguards. Merely displaying a CCTV notice is not sufficient to ensure the lawfulness of such processing.

Legal support includes:

  • assessing the necessity and proportionality of CCTV;
  • determining which areas may lawfully be monitored;
  • restricting access to recordings;
  • determining retention periods;
  • preparing CCTV privacy notices;
  • preparing internal decisions and procedures;
  • maintaining records of access to and disclosure of recordings;
  • handling requests from individuals;
  • disclosure of recordings to the police, courts, or other competent authorities;
  • assessing CCTV monitoring of employees and workplaces.

International Data Transfers

Use of foreign cloud services, centralised group systems, or service providers located outside Bosnia and Herzegovina may involve international transfers of personal data.

The Law Office provides support in:

  • determining the location of recipients and processing activities;
  • identifying international data transfers;
  • assessing the legal basis for transfers;
  • assessing the level of protection in the recipient country;
  • selecting an appropriate transfer mechanism;
  • agreeing appropriate safeguards with recipients;
  • assessing risks relating to access to personal data in another country;
  • recording transfers in the controller’s documentation;
  • informing data subjects;
  • communication with the Personal Data Protection Agency where its decision or authorisation is required.

Supervision by the Personal Data Protection Agency

During supervisory proceedings, an organisation must demonstrate not only that it possesses the required documentation, but also that the established rules are actually implemented in practice.

The Law Office provides support through:

  • preventive compliance reviews prior to supervision;
  • organisation and legal review of documentation;
  • preparation of responsible persons and employees;
  • responses to requests from the Personal Data Protection Agency;
  • submission of records and other requested evidence;
  • legal support during inspections and supervisory proceedings;
  • submissions concerning identified irregularities;
  • preparation of corrective action plans;
  • implementation of measures ordered by the Agency;
  • use of available legal remedies;
  • representation in administrative disputes and other related proceedings.

GDPR and Businesses Operating from Bosnia and Herzegovina

A business established in Bosnia and Herzegovina may also fall within the territorial scope of the GDPR where it offers goods or services to individuals in the European Union or monitors their behaviour in circumstances covered by the Regulation.

The Law Office provides support in:

  • assessing the territorial applicability of the GDPR;
  • aligning documentation with domestic and European data protection requirements;
  • determining the company’s role in cross-border processing;
  • assessing whether an EU representative must be appointed;
  • regulating contractual relationships with partners in the European Union;
  • international transfers of personal data;
  • handling requests from individuals located in the European Union.

When to Contact Us

You may contact us when beginning a compliance project, introducing a new system or service, engaging an external processor, planning CCTV monitoring, or using a cloud platform located outside Bosnia and Herzegovina.

Legal support is particularly important when an individual requests access to or erasure of personal data, when a security incident occurs, when supervision by the Personal Data Protection Agency is announced, or when existing documentation no longer reflects the organisation’s actual processing activities.