📖 14 MIN READ • EDVISION EDITORIAL

What changes does the GDPR bring and how to apply it in Bosnia and Herzegovina?

The digital age we live in has transformed the way individuals and organizations communicate and exchange data. More and more services can be completed online, and these online services increasingly require us to provide our personal information. Individuals are making their personal details more publicly and globally accessible than ever before. What about security? Is […]

The digital age we live in has transformed the way individuals and organizations communicate and exchange data. More and more services can be completed online, and these online services increasingly require us to provide our personal information. Individuals are making their personal details more publicly and globally accessible than ever before.

What about security? Is it being compromised? How can we ensure the flow of information while maintaining a high level of personal data protection?

These are just a few of the questions we will address in this article.

Let’s dive in!

What is GDPR?

In the race of market competition, the more data you have at your disposal, the more information you possess to anticipate market trends, make strategic decisions, and outperform competitors to secure your spot under the sun. Due to the increasing exposure of data in such an environment, the need arises to legally regulate this area in order to protect individuals.

For this reason, the European Union (EU) enacted the General Data Protection Regulation (GDPR). Adopted in 2016, it entered into force on May 25, 2018—a date that also served as the final deadline for aligning all processes and IT systems. This Regulation aims to contribute to establishing an area of freedom, security, and justice, as well as an economic union, economic and social progress, the strengthening and convergence of economies within the internal market, and the well-being of individuals.

Many companies and organizations frequently treat their clients’ personal data as a free resource, using it without consent and collecting it without limits or protective safeguards.

The GDPR represents a legal framework for protecting the personal data of EU citizens. The legal foundation of the GDPR rests upon the Treaty on the Functioning of the European Union and the Charter of Fundamental Rights of the European Union, both of which explicitly state that everyone has the right to the protection of their personal data—a right the EU intends to defend uncompromisingly through this document. The GDPR serves as a tool that compels companies to rethink and systematically regulate how they collect, analyze, and store data.

Scope of Application

The GDPR applies to any organization that stores or processes personal data of EU citizens within the EU territory. This includes micro, small, and medium-sized enterprises, public institutions, bodies, and agencies that collect personal data, regardless of whether the organization is based inside the EU or not, and irrespective of company size, legal form, or industry sector. All legal entities are obligated to adhere to the prescribed regulations, encompassing not only online business operations, but also anyone who has access to your personal data.

Covering only select fragments of a business will not suffice; compliance must extend to the entire lifecycle of how personal data is collected and used.

Personal Data

Personal data refers to any piece of data/information, or combination thereof, that can identify an individual. This is not limited to just a first and last name. It includes, among other things: age, gender, national identification number, phone number, email address, IP addresses on computers and mobile devices, GPS location, salary details, credit obligations, bank account information, educational background, professional qualifications, photos, video recordings of individuals, lists of favorite literature or music, physical characteristics, personal tax ID (OIB), RFID tags, website cookies, and many other data points.

What Does the GDPR Bring to Individuals?

The fundamental differences between the GDPR and previous laws lie in granting greater rights to individuals, who gain easier access to and stronger control over their data, which is predominantly used for advertising purposes. The rights of data subjects regarding their personal data are clearly defined. Individuals have the right to know how their personal data is used, to access their personal data, and to request the rectification, erasure, restriction of processing, and portability of their personal data, among others.

This is precisely what the implementation of the GDPR enables.

To store a user’s personal data, we must obtain their consent (permission, authorization, agreement). When someone grants permission to process their personal data, we can only process that data for the specific purposes for which consent was provided. Further reinforcement of data subjects’ rights is ensured through data protection impact assessments regarding the risks that collecting and processing data pose to the rights and freedoms of individuals, as well as mandatory notification to competent authorities and data subjects in the event of a data breach or misuse (within 72 hours).

One of the GDPR’s novelties concerns the manner in which users grant permission for the collection and use of their personal data. The terms must be written in plain, easily understandable language, with a clear explanation of the purposes for which the personal data is being collected.

Personal data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed. The only exceptions are personal data processed solely for archiving purposes in the public interest, scientific or historical research, or statistical purposes, which must be adequately secured in accordance with the GDPR.

To ensure compliance with all these requirements, lawmakers have mandated the establishment of an independent supervisory authority in each member state to handle reports and oversee this domain, with their work coordinated by a centralized European body.

What Does the GDPR Bring to Businesses?

It is particularly interesting that the GDPR does not apply solely to companies operating within the EU territory, but to all entities that process data of individuals residing within the Union, regardless of location or size. Therefore, all organizations, institutions, enterprises, and other legal entities that employ, sell to, or provide services on any basis to EU citizens (i.e., holders of an EU member state passport) are required to comply with the GDPR regulation regarding the protection of their personal data.

From all individuals, institutions, and organizations that process personal data in any way, the GDPR requires an inventory, categorization, and coding of all user information defined as personal data. An individual’s consent to the use of their personal data is regarded as a clear, affirmative act of authorization. A unified personal data and privacy protection standard is imposed on organizations across the EU territory; on one hand, this represents a single standard to align with, while on the other, it places exceptionally high and strict demands on organizations, backed by severe penalties. Non-compliance results in fines that can reach up to €20 million or up to 4% of global annual turnover, whichever is higher. Supervisory oversight will likely continue to be managed by the relevant Data Protection Agency (such as AZOP).

To ensure your organization’s compliance with this Regulation, you need professionals who thoroughly understand its requirements, and in certain cases, appointing a qualified Data Protection Officer is mandatory. External specialists may also be appointed for this role via a service agreement or contract. Key designated roles include: Data Controller, Data Processor, and Data Protection Officer (DPO). Organizations must ensure they have a data protection plan, risk assessments, and remediation measures in place.

If you are a company or organization, your data protection plan will depend on several factors, such as data sensitivity levels, data volume, and the complexity of your digital infrastructure. The baseline measures you must implement include reviewing what personal data you possess, mapping where it is stored, conducting a risk assessment to identify potential sources of unauthorized access or data leaks, restricting access privileges, and verifying that the data is securely stored and encrypted.

How to Apply GDPR in Bosnia and Herzegovina?

The most comprehensive overhaul in European data protection policy in recent decades also applies to Bosnia and Herzegovina, even though it is not an EU member state. By signing the Stabilization and Association Agreement with the EU, Bosnia and Herzegovina committed to aligning its domestic legislation with the European Union acquis, with the final deadline originally set for mid-2021, at which point citizens of BiH will also be protected. Nevertheless, starting from May 25, BiH must actively protect EU citizens both within and beyond its borders.

It is critical that companies in Bosnia and Herzegovina handling citizens’ data adapt to the requirements of the GDPR as soon as possible. BiH will have to respect the GDPR—first for the sake of EU citizens, and later for its own benefit once it becomes a member state.

The fundamental first step for every organization in BiH is to conduct a “Compliance Assessment” regarding personal data protection in relation to the current Law on the Protection of Personal Data in BiH and the GDPR.

The penal provisions of the existing Law on the Protection of Personal Data will continue to apply in BiH until the entry into force of the new law aligned with the Regulation. BiH is particularly specific in this context, as a significant portion of its citizens simultaneously hold citizenship of an EU country.

How Can ED Vision Help You Comply with GDPR?

Implement this Regulation within your organization and show your clients that you grant them full control over their personal data!

A crucial channel for collecting personal data from your clients is your website. If you run a website, process personal data, regularly send out newsletters, disburse payroll, operate an online store, process numerous daily orders… and if your database includes individuals (whether customers or employees) who are EU citizens, we will help you align your business operations with GDPR requirements.

Although the GDPR is explicit regarding personal data protection, it does not mandate the specific technologies or processes businesses must implement to achieve that security. Many business owners and executives are not fully aware of the obstacles they must overcome to implement the Regulation’s standards, with very little time remaining for compliance. They should recognize that alignment is not a simple process and will introduce significant operational changes. Therefore, the sooner they begin the transition, the smoother it will be. We can help you navigate this process.

What does the GDPR actually mean for your website? With the GDPR shaping the business landscape, collecting user data through a website has become a far more complex procedure. We will help you provide users with complete control over their personal data, delivering clear, unambiguous, and accessible guidelines for granting or withdrawing consent from your system.

Below, we outline the GDPR-compliant updates applicable to your website so you can begin implementing them promptly.

Privacy Policy

If you do not have a privacy policy, we will implement one for you. A privacy policy is an essential document and page on your domain that every website must possess. This policy represents a fundamental aspect of GDPR compliance, fulfilling the core principle of transparency. We will help ensure that your privacy policy is drafted accurately so that the data processing consents you obtain remain legally valid. We will communicate with your users in plain, accessible language so they understand—precisely, clearly, and unambiguously—what their rights are, how you process data, how they can modify or request the deletion of their information, and the security standards you implement.

We will assist you by providing comprehensive guidance to create or adapt a Privacy Policy whose content satisfies all GDPR requirements. This will allow you to collect user data securely, communicate effectively, and operate in full compliance with the GDPR.

Cookies

A cookie is a small file stored on a user’s computer by a website they visit. Cookies typically save preferences for a website, such as language selection or location details. Later, when the user revisits the same website, these cookies allow the site to display tailored information based on their needs.

The GDPR fundamentally changes how cookies and tracking technologies are handled. Passive notices such as “This website uses cookies” are no longer compliant. Instead, websites must obtain explicit, affirmative consent for each category of cookies stored in the visitor’s browser. While strictly necessary cookies required for core website functionality do not require prior consent, all other types—such as analytics, functional, and marketing cookies—demand explicit approval.

We can implement a consent management solution that allows visitors to accept or reject cookies freely, or – as the GDPR mandates—provide granular consent for specific cookie categories. Furthermore, in full compliance with GDPR regulations, visitors will retain the ability to withdraw or update their cookie preferences at any time.

Obrasci

Under the GDPR, any personal data a user provides can only be used for the specific purpose for which they granted explicit consent. For instance, an email address obtained from a customer via an online store—even with consent provided—can only be used strictly to process and fulfill that order, not for sending promotional marketing emails. If you wish to send promotional content, an un-checked box must appear beneath the form stating: “I agree to receive promotional offers.” Thus, to include that email address in newsletter campaigns, the user must provide separate, affirmative consent.

We will review your website and, in consultation with you, implement all required notices, clarifications, and un-ticked consent checkboxes to ensure all web forms fully comply with GDPR standards.

Before a user clicks the “Register” or submit button, the optimal practice is to include an unchecked checkbox for each distinct consent item where the client can place a checkmark. These consents will be logged digitally, allowing you to demonstrate verifiable proof of consent in the event of a regulatory inspection or a customer dispute. The GDPR applies specifically to personal data; other non-personal data (such as fully anonymized datasets from which an individual’s identity cannot be determined) are governed by the respective national laws of each member state.

Newsletter

Prior to the GDPR, newsletter lists were populated through various methods. If newsletter lists were purchased, their use must cease immediately, as this poses a serious risk of regulatory fines. Many web forms that collect email addresses are designed with copy prompting users to enter their email to download a free e-book or receive a purchase discount. That address is then subsequently used for regular newsletter campaigns.

The GDPR puts an end to this practice: if you wish to send regular newsletters, users must grant explicit consent specifically for that purpose. Under the GDPR, you may only dispatch newsletters to individuals who have actively consented to receive promotional emails. Therefore, if consent is obtained on a form offering a promo code, the email address may only be used to deliver that specific promo code and nothing else.

Our straightforward solution for your website includes adding an unchecked checkbox where visitors can actively opt in to receive newsletters, ensuring it is never pre-checked by default. Another robust option for onboarding new subscribers is a double opt-in mechanism, where the user receives a confirmation email outlining the exact intended uses of their email address, requiring their final confirmation to activate the subscription.

If you have an existing newsletter list collected without transparent disclosures regarding how email addresses would be used, the best course of action is to prepare a re-permission campaign as soon as possible, asking subscribers to confirm whether they wish to continue receiving updates from you. Only contacts who actively re-confirm will remain on your list, while all others must be deleted.

Data Subject Access

If users have submitted their personal data on your website, we can implement a dedicated user profile functionality for you. This allows them to quickly and easily review all the personal information they have provided in a single dashboard, where they can modify or delete it themselves. This will significantly reduce the volume of incoming email requests for data changes. Every user account (for instance, on an online store) must offer the ability for customers to delete their profile and revoke permissions, along with all associated data (personal details, order history, etc.).

Other Mandatory Information

If regulatory scrutiny of websites increases due to the GDPR, compliance with other essential statutory disclosures will undoubtedly be audited as well. We will verify whether all required information is present and highlight any missing elements. Everything outlined in this text is general in nature and represents our interpretation of GDPR regulations. We offer the exact solutions we implemented for our own websites to align them with GDPR requirements; however, this does not constitute a legal guarantee of full compliance. For comprehensive legal advice, we recommend consulting a qualified legal professional.

If you wish to align your online operations with the GDPR, please contact us.