Recording meetings in Bosnia and Herzegovina.
Bosnia and Herzegovina is the more interesting case, because the two assumptions people usually carry into this question are both wrong here: that the GDPR governs, and that there is one criminal code to consult.
Bosnia and Herzegovina is not an EU member state, and it is not covered by an adequacy decision, so data does not move between it and the EU on the same footing as it does between member states. The domestic instrument is the Law on the Protection of Personal Data, supervised by the Personal Data Protection Agency. It predates the Regulation and is not a copy of it, which means reasoning imported from GDPR practice does not transfer point for point.
The second complication is structural. Criminal law is not held at state level alone: the state, both entities and the Brčko District each have their own criminal code, and the provisions relevant to unauthorised recording sit at entity level. A question about a specific recording is therefore a question about a specific place. The GDPR can still reach an organisation based here, through the territorial scope provisions that apply it to offering services to people in the EU or monitoring their behaviour there, so an organisation with EU customers is often answering to both regimes at once.
- The data protection instrument
- Zakon o zaštiti ličnih podataka (Law on the Protection of Personal Data), Službeni glasnik BiH 49/06, 76/11, 89/11
- Who supervises this
- Agencija za zaštitu ličnih podataka u BiH (Personal Data Protection Agency of Bosnia and Herzegovina)
Criminal provisions
These sit alongside data protection law rather than replacing it. They generally address conduct that is covert or that involves conversations the recorder was not part of, which is a narrower category than everyday meeting recording, and a considerably more serious one.
Krivični zakon Federacije BiH / Krivični zakon Republike Srpske, Entity-level provisions
Criminal Code of the Federation of BiH / Criminal Code of Republika Srpska
Criminal law in Bosnia and Herzegovina is not held at state level alone. The state, both entities and the Brčko District each have their own criminal code, and provisions on unauthorised recording and on violating the privacy of correspondence sit at entity level. Which code applies depends on where the conduct takes place.
What is specific to this country
- Bosnia and Herzegovina is not an EU member state and is not covered by an EU adequacy decision, so personal data does not move to or from the EU on the same footing as it does between member states.
- The domestic instrument is the Law on the Protection of Personal Data, supervised by the Personal Data Protection Agency. It predates the GDPR and is not a copy of it, so GDPR reasoning does not transfer point for point.
- Because criminal provisions are split across the entities and the Brčko District, a question about a specific recording is a question about a specific place, not about the country as a whole.
What to do in practice
The practice below is not the legal minimum in every jurisdiction. It is the practice that is defensible in all of them, which is a more useful target when your calls cross borders.
- Say it out loud at the start, before anything substantive is discussed, and say what the recording is for. Not a line in the invite nobody read.
- Give people a real way to decline. An announcement that leaves no room to object is closer to a notification than to consent.
- Write it down. A line in the notes recording that the meeting was recorded, and that nobody objected, is worth more later than anyone's memory of the moment.
- Keep external meetings to a higher standard than internal ones. Colleagues share an employment context; a customer, a candidate, or a supplier does not.
- Decide how long you keep recordings, and actually delete them. Indefinite retention converts a small, well-handled recording into a growing liability.
- Treat sharing as a fresh decision. The question is not whether you were allowed to record, it is whether this particular person was meant to hear it.
Questions
Does the GDPR apply in Bosnia and Herzegovina?
Not directly, because it is not an EU member state. It can still apply extraterritorially under Article 3(2) where processing relates to offering goods or services to people in the EU, or to monitoring their behaviour in the EU. Many organisations here fall within that, which means the domestic law and the Regulation apply together rather than one instead of the other.
Which criminal code applies to a recording made here?
That depends on where the conduct takes place. The state, the Federation of Bosnia and Herzegovina, Republika Srpska and the Brčko District each have their own criminal code, and the relevant provisions sit at entity level, so there is no single national answer.
Does data leaving the country for transcription matter?
It is a question worth asking of any provider, here more than in an EU member state, because there is no adequacy decision doing the work for you. Ask where recordings are stored, where they are processed, and what happens to them afterwards, and expect specifics rather than reassurance.
Where can I check this myself?
The Personal Data Protection Agency publishes the legislation it supervises, and both are linked in the sources below. For a specific situation, particularly one touching the criminal provisions, ask a lawyer qualified in the relevant entity.
Sources
Primary sources, so you can check this rather than take our word for it.
Recording that announces itself.
Canto's notetaker joins as a named participant the organiser admits, and the recording, the transcript and who can see it stay under your control. 300 minutes a month, free forever.