Personal data is not just a matter of bureaucracy, but property that is strictly protected by new laws. Citizens increasingly complain about the misuse of personal data, most often due to marketing tricks or inappropriate private video surveillance. In 2025, the BiH Data Protection Agency conducted 213 procedures based on complaints by personal data holders and 27 procedures on official duty.
Although we think we control our data, the reality is often different. Citizens are aware of the risks, but admit that in certain institutions they simply do not review the rules.
Survey:
– personal, driver’s license, account number, of each other. (Do you know that not everyone can search for your data?) I know, but they rarely do.
– taking out a bank account, during employment, yes. (what do you know about data protection, do you know where that data is now?) Of course, if I don’t have to give it, I don’t give it to anyone.
And while the provision of data in banks or at the employer is legally regulated, the gray area remains where we assume the role of security ourselves. Private video surveillance often goes beyond what is allowed.
“The largest number of complaints related to video surveillance and that to individual residential buildings. A certain person, to protect his property and household members, hires either a private company or installs cameras and video surveillance on his own initiative and in this way protects his property and property. In this sense, others who are in his immediate vicinity often complain to us precisely because of the fact that they either believe or it actually happens that the video surveillance cameras that should cover a certain area actually cover an area beyond the area owned by a certain person who installed those cameras”, Samira Champara, Sector for Inspection Supervision.
Abuse of phone numbers for marketing purposes is another complaint from citizens. Private contacts become a target of the agency, without a clear trace of how they got the data.
“I was bombarded, so to speak, with some calls from insurance agencies, medical services and the like. (What did you do about it?) I blocked all the contacts I could, that’s the only thing I could do,” says one interviewee who was texted and called.
Blocking the number is only an apparent solution. The problem is systemic, as our data on health, education and habits are often circulated for marketing purposes without our actual consent.
“Processing data on health status both in the education sector and at private companies regardless of their activities and at providers of communal services, communication services, due to direct marketing, sending marketing messages to individuals”, explains Čampara.
The new Law on Data Protection, harmonized with European standards, sets strict barriers for institutions and companies. Every organization that processes data must now appoint a Data Protection Officer.
“Not everyone in any institution can have access to all data. Someone may have one in the staff, another in finance, another in the IT sector. Care must also be taken to ensure that the person in charge is someone who will be trained and who will really follow our site and our solutions and opinions, because it is not a simple branch of law,” Dragoljub Reljić, director of the Agency for the Protection of Personal Data, points out.
With fines that according to the new law can reach millions, privacy protection ceases to be only an administrative item. Privacy Day is a good occasion to remind citizens that they have the right to see how their data is used, the right to object, but also the right to have it completely deleted, writes N1 BiH.




