Data Protection Policy
Please read these guidelines carefully to understand how we process personal data and to find out your rights regarding that processing. This regulation aims to protect the personal data of a natural person, which means that this personal data belongs to someone who is called a data subject.
Last updated: 24 June 2026, Belgrade
Basic provisions
- Personal data
- all information related to an identified or identifiable natural person (data subject); an identifiable natural person is a person who can be identified, directly or indirectly, by reference to an identifier such as name, identification number, location data, network identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
- Processing
- any operation or set of operations performed on personal data or sets of personal data, by automated means or otherwise, such as collecting, recording, organising, structuring, storing, adapting or modifying, finding, consulting, using, disclosing by transfer, dissemination or otherwise making available, aligning or combining, restricting, deleting or destroying.
- Sensitive personal data
- personal information about a person's racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic, biometric, physical or mental health data, sexual orientation or sexual life. It may also contain information on criminal offences or convictions. Sensitive personal data may be processed under strict conditions, with the obligatory consent of the individual.
AIESEC in Serbia processes personal data about members/employees, volunteers, partners, former/alumni members and customers, while protecting and respecting the privacy of each interested party. Personal data must be processed lawfully and in an appropriate manner, in compliance with the General Data Protection Regulation and the Law on Personal Data Protection ("Official Gazette of the Republic of Serbia", No. 87/2018).
Data controller and data protection officer
The data controller is a natural or legal person, public authority, agency or other body that, independently or together with others, determines the purposes and means of personal data processing. The data controller can process the collected data using its own processes. In some cases, however, the controller may work with an independent or external service to handle the data, which is known as the processor.
- Name
- International Student Organization AIESEC in Serbia
- ID number
- 17149610
- Tax ID
- 100352131
- Headquarters
- Gandijeva 44, Belgrade
- Website
- www.aiesec.org.rs
- office@aiesec.org.rs
- Phone
- +381 61 444 2737
The Data Protection Officer (DPO) is bound by secrecy and confidentiality in the performance of their tasks. A member of AIESEC in Serbia or someone outside the organisation can be responsible for data protection.
From 1 July 2026 to 30 June 2027, the Data Protection Officer for AIESEC in Serbia is the Head of Finance and Legal Affairs, Emilija Miloš. For any request or question regarding the processing of personal data, you can contact us at: emilija.milos@aiesec.org.rs
Principles of data protection
Personal data:
- is processed lawfully, fairly and in a transparent manner in relation to the data subject;
- is collected for specific, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes;
- must be appropriate, relevant and limited to what is necessary in relation to the purposes for which it is processed;
- is accurate and, where necessary, kept up to date;
- is kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed;
- is processed in a manner that ensures adequate security of personal data, including protection against unauthorised or unlawful processing and accidental loss, destruction or damage, using appropriate technical or organisational measures.
Consent must be obtained in a free, concrete, unambiguous, explicit and informed manner. The request for consent shall be submitted in an understandable and easily accessible form and in clear language. AIESEC in Serbia must be able to prove that the data subject has consented to the processing of their personal data, and guarantees that the data subject has the right to withdraw consent at any time, without affecting the lawfulness of the processing prior to withdrawal. Prior to giving consent, the data subject must be informed. AIESEC in Serbia also guarantees that withdrawing consent is as easy as giving it.
Data security
AIESEC in Serbia takes appropriate security measures against the unlawful or unauthorised processing of personal data and against accidental or unlawful destruction, damage, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed.
Personal data is transferred to an external data processor only if there is a contract and if the other party agrees to adhere to the procedures and policies and/or sets appropriate measures itself. AIESEC in Serbia has the right to share personal data with other AIESEC entities for the purpose of their communication with an intern in that country, or with a member of AIESEC in Serbia regarding participation in a project in that country.
Rights of individuals
AIESEC in Serbia processes all personal data based on the rights of individuals, including:
- The right to be informed about the processing activities - the data subject has the right to receive a confirmation from the controller as to whether their personal data is processed and where;
- The right of access to their personal data - the data subject has the right to obtain confirmation from the controller as to whether or not their personal data is being processed and for what purposes;
- The right to correction - the right of individuals to correct or supplement inaccurate or incomplete personal data by submitting a written or oral request;
- The right to object to (part of) the processing, including for the purposes of direct marketing;
- The right to erasure - the data subject has the right to request the controller to erase personal data relating to them if:
- the personal data is no longer required in relation to the purposes for which it was collected or otherwise processed;
- the data subject withdraws consent and there is no other legal basis for processing;
- the data subject objects to the processing and there is no predominantly justifiable basis for processing;
- the personal data has been processed unlawfully;
- the personal data must be deleted in accordance with a legal obligation;
- The right to restriction of processing - the data subject has the right to obtain a restriction of processing from the controller when one of the following applies:
- the accuracy of the personal data is challenged by the data subject, for a period allowing the controller to verify that accuracy;
- the processing is unlawful and the data subject opposes erasure and instead requests a restriction on use;
- the controller no longer needs the personal data for processing purposes, but the data subject requires it for the establishment, exercise or defence of legal claims;
- the data subject has objected to the processing and is awaiting verification as to whether the controller's legitimate grounds override their objection.
- The right to data portability - the data subject has the right to receive personal data relating to them, which they provided to the controller, in a structured, commonly used and machine-readable format, and has the right to transfer it to another controller without hindrance from the controller to which the personal data was provided;
- The right not to be subject to automated decision-making (including profiling) in certain circumstances. Should this occur, the individual has the right to be informed, to express their position, to challenge the decision and to request human intervention;
- The right to liability/compensation in case of violation of the right to privacy, as well as the right to file a complaint with the appropriate supervisory authority.
Disclosure and sharing of personal data
AIESEC in Serbia may internally share personal data with the narrowest circle of persons who need the data to perform their work. Personal data will not be sold to external parties or handled by individuals outside AIESEC in Serbia, nor by people or organisations located in countries without adequate protection and without prior individual counselling. Data transfers to other countries are subject to the requirements of the General Data Protection Regulation.
Obligations
AIESEC in Serbia keeps records of its processing activities and can prove compliance upon request. It follows the internal data protection policy, the provisions of the General Data Protection Regulation and national/local data protection laws.
Local entities of AIESEC in Serbia are subject to data protection clauses and must adhere to these rules.
Final provisions
AIESEC in Serbia keeps personal data for two years from the end of the experience (active membership*, internship, project), in compliance with all the above principles related to data security and with the possibility for the data subject to request the deletion of such data at any time.
Through surveys for users, AIESEC in Serbia collects personal data such as name and surname, email address, telephone number, faculty and year of study, place of residence (city) and the like.
AIESEC in Serbia uses the collected data for the purpose of:
- communication with members, volunteers, interns, project delegates, partners in internships or projects, as well as other stakeholders whose personal data is collected regarding the membership, project, internship or other service of AIESEC in Serbia for which the data subject has applied;
- statistical processing for a better insight into the processes of AIESEC in Serbia and their improvement, as well as for building profiles for future outreach to stakeholders regarding recruitment, internships and projects organised by AIESEC.
AIESEC in Serbia undertakes to contact data subjects exclusively in connection with the service of the organisation for which they have applied. Where the data subject has accepted consent to be contacted for other purposes (for other projects, internships or membership), they may be contacted in connection with several services they have opted into.
* The name, surname and contact details of members who acquire the status of alumni member automatically remain in the alumni database until further notice, for guest appearances at internal conferences and meetings, unless the alumni member expresses a wish to change or delete their data from the alumni database. Upon completion of the experience and entry of the alumni member's data into the alumni database, AIESEC in Serbia undertakes to consult with the alumni member and enter only the data for which it has received approval.