Bosnia and Herzegovina

Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011)

23 controls. 3 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

23 controls 3 frameworks share controls with it Bosnia and Herzegovina verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
BA-DPA-1Purpose of the Law0
BA-DPA-11Data Security1
BA-DPA-12Data Processing by a Processor1
BA-DPA-13Personal Data Filing System0
BA-DPA-14Central Registry0
BA-DPA-16Confidentiality Requirement2
BA-DPA-18Data Transfer Abroad1
BA-DPA-2Scope of the Law0
BA-DPA-22Notification on Data Collection0
BA-DPA-24The Right to Personal Data Access0
BA-DPA-27Corrigenda and Deletion of Data0
BA-DPA-29Issuing Decisions Based on Automatic Data Processing0
BA-DPA-30Filing Complaints0
BA-DPA-32Liability for Damage0
BA-DPA-35Definition of the Agency0
BA-DPA-4Principles of Personal Data Processing1
BA-DPA-40Competencies of the Agency0
BA-DPA-41Control Carried Out by the Agency0
BA-DPA-48Offences and Fines0
BA-DPA-5Consent by a Data Subject1
BA-DPA-6The Right to Process Without the Data Subject's Consent1
BA-DPA-7Data Authenticity1
BA-DPA-9Processing of Special Categories of Personal Data1

Tell me when Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Control testing plan
  • Test results
  • Effectiveness metrics
  • Remediation plan
  • internal audit plan and schedule
  • internal audit reports of the ISMS
  • Consent UX
  • Granular preference centre
  • Audit trail of consents
  • Withdrawal mechanism as easy as giving

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition