IndustriesFintech and payment services

Legal support for the fintech industry

We advise payment institutions, e-money issuers, credit intermediaries and account information service providers on licensing, compliance obligations and contractual relations with banks and partners.

NBScompetent for payment service and e-money authorisations
PSD2open banking standards reflected in domestic rules
2 regimespayment institutions and e-money institutions
Industry overview

Regulatory framework and supervision

Providing payment services and issuing electronic money in the Republic of Serbia requires an authorisation from the National Bank of Serbia. The framework follows European rules, including account access and payment initiation.

Supervision focuses on capital requirements, safeguarding of client funds, operational risk management and anti-money laundering. These are the areas where inspections most often identify shortcomings.

Payment Services ActConditions for authorisation, operations and safeguarding of client funds.
National Bank of SerbiaAuthorisations, registers and the conduct of supervision.
Anti-money launderingHigh-risk obliged entities, with reporting and internal control duties.
Data protectionApplication of the Serbian act and the GDPR to client and transaction data.
Consumer protectionPre-contractual information and rules on fees.
Outsourcing and ICT riskRequirements for service providers and business continuity plans.
Our services

Most common areas of support

Six areas in which fintech companies most often ask for legal support.

01

Licensing and registration

  • Choosing the regime: payment institution, e-money institution or agent.
  • Preparing the application and supporting documentation.
  • Drafting the business plan, governance acts and procedures.
  • Representation before the National Bank of Serbia.
  • Notifying changes and extending the scope of activities.
02

Anti-money laundering compliance

  • Risk assessment and drafting of internal acts.
  • Setting up identification and transaction monitoring procedures.
  • Rules on enhanced due diligence and sanctions screening.
  • Appointing the compliance officer and training staff.
  • Preparing for inspections and responding to findings.
03

Contracts with banks and partners

  • Account and safeguarding arrangements.
  • Contracts with processors, card schemes and agents.
  • Terms of use and framework contracts with users.
  • Outsourcing contracts and allocation of responsibility.
  • Negotiating liability and indemnity provisions.
04

Data protection and information security

  • Records of processing and legal bases for payment data.
  • Processor contracts and transfers to third countries.
  • Incident handling and notification duties.
  • Internal information security documentation.
  • External data protection officer.
05

Consumer protection and complaints

  • User information and rules on fees.
  • Complaint handling and out-of-court dispute resolution.
  • Advertising compliance with consumer protection rules.
  • Rules on unauthorised and unexecuted transactions.
  • Representation before supervisory authorities.
06

Investment and transactions

  • Regulatory due diligence of payment institutions and technology companies.
  • Investment structuring and conditions tied to the authorisation.
  • Approvals for the acquisition of a qualifying holding.
  • Transfer of contracts and the user base.
  • Post-closing alignment of operations.
How we work

What working with us looks like

Four stages, from regulatory analysis to ongoing support.

01

Regulatory analysis

We establish which licences, approvals and documents the proposed business model requires.

02

Documentation

We prepare contracts, internal acts and policies and coordinate procedures before the competent authorities.

03

Implementation

We represent the client in proceedings and negotiations through to a decision or the signing of the contract.

04

Ongoing support

We track legislative changes, supervisory procedures and the obligations that arise during operations.

Common questions

Questions clients ask

Is an authorisation required to provide payment services in Serbia?

It is. Providing payment services and issuing electronic money require an authorisation from the National Bank of Serbia, and operating without one is punishable.

How long does the authorisation procedure take?

It depends on the type of authorisation and the completeness of the file. The statutory period runs from a complete application, so most time is gained by preparing the full documentation in advance.

Can a foreign payment institution operate in Serbia?

In practice operations are organised either by incorporating a domestic company holding an authorisation or by partnering with a licensed provider. The model follows the scope and type of services.

What are the anti-money laundering obligations?

The obliged entity must carry out customer due diligence and identification, monitor transactions, report to the competent authority and perform regular internal controls.

What is most often checked in supervision?

Capital adequacy, safeguarding of client funds, anti-money laundering documentation, outsourcing contracts and complaint handling.

Next step

How can we help?

Describe your matter and we will point you to the lawyer who leads that industry.

Contact us
Newsletter

Learn legal updates, and what to do about them

Legal developments in Serbia and the EU, each with the step it asks of your business.

Sign up

Two emails a month. Unsubscribe any time.