evidoria

← Back to browse

Good practice Imported

Belgrade's 'Safe City' — Serbia's Huawei-Built AI Surveillance Network Ruled Unlawful for Facial Recognition

Serbia · Belgrade · See the Serbia profile · See the Belgrade profile

Evidence: Descriptive / self-reported Top 97% 20/100 · Ask Evidence Copilot about this practice

Belgrade deployed 1,000+ Huawei-built AI cameras from 2017. Serbia's data-protection commissioner twice ruled the impact assessment unlawful; 2024 orders were still sized for 3,500 more cameras, and a 2025 breach at contractor Informatika AD exposed 1.7M files.

1,000+
Cameras initially deployed (2017)
57%
First contract price discount (2017)
92%
Software package price discount (2017)
3,500 cameras
Additional camera capacity in 2024 procurement order (March 2024)
1.7 million+ files
Files exposed in the 2025 Informatika AD breach (June 2025)
Belgrade's 'Safe City' — Serbia's Huawei-Built AI Surveillance Network Ruled Unlawful for Facial Recognition

Details

Maturity
Scaling
Promoter
Ministry of Interior of Serbia, with Huawei and state IT contractor Informatika AD
Period
Announced 2017; camera network expanded through at least a March 2024 procurement order; facial-recognition legal status unresolved as of 2025
Keywords
public safety, video surveillance, facial recognition, policing

Context

Belgrade's 'Safe City' project, announced by Serbia's Ministry of Interior in 2017, deployed AI-enabled video cameras with facial-recognition and licence-plate-recognition capability built around Huawei technology. It initially covered roughly 1,000 cameras, framed as a crime-reduction measure for the 1.1-million-resident capital. The first contract was discounted 57%, from an initial $3 million to about $1.2 million, with one software package discounted 92%, from $1.1 million to roughly $71,000.

Results

Serbia's Commissioner for Personal Data Protection twice rejected the Ministry of Interior's Data Protection Impact Assessment, finding it lacked a risk assessment, did not clearly specify which system it covered, and provided no legal basis for processing biometric facial-recognition data. Despite this unresolved legal status, a March 2024 procurement order was sized to support up to 3,500 additional cameras on Serbia's police-only eLTE network, and the system's footprint expanded beyond Belgrade to other Serbian cities. In June 2025, a cyberattack on state IT contractor Informatika AD resulted in more than 1.7 million files being published on the dark web, including over 200 documents related to Interior Ministry procurement.

Conclusions

The government has repeatedly proposed, then withdrawn, legislation intended to retroactively authorise the system following domestic and European Parliament pressure. Authorities have not disclosed a current total camera count or published any independent evaluation of the system's effect on crime.

Implementation

Indicative cost
High (€500k–€5M)
Time to results
Long (> 3 years)
Staffing & skills
Ministry of Interior of Serbia, Huawei, state IT contractor Informatika AD

Conditions for success

  • lawful data protection impact assessment
  • clear legal basis for biometric processing
  • independent oversight

Common failure modes

  • DPA twice rejected the impact assessment as unlawful
  • no legal basis established for facial-recognition biometric processing
  • government repeatedly proposed then withdrew legislation to retroactively authorise the system
  • 2025 data breach at contractor exposed 1.7 million+ files
  • no independent evaluation of crime-reduction effect published

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Attachments

Similar practices you may find useful