SSL Certificate, GDPR, and Website Security in BiH — Must Read
Website security isn't a topic only for IT specialists. Every BiH business that collects client data — whether through a contact form, newsletter, or web shop — has legal and technical obligations. Ignoring security can cost money, reputation, and client trust.
In this guide, we cover SSL certificates, GDPR and domestic data protection law, cookie consent, and practical steps to protect your website.
SSL Certificate — What It Is and Why You Need It
SSL (Secure Sockets Layer), today practically TLS (Transport Layer Security), is technology that encrypts communication between the user's browser and your server. When you see the padlock in the address bar and https:// instead of http://, SSL is active.
What SSL Protects
Encrypts data in transit — passwords, card numbers, personal data from forms. Prevents man-in-the-middle attacks where someone intercepts communication. Confirms server identity — user knows they're really on your site, not a fake copy.
Free vs. Paid Certificates
Let's Encrypt offers free SSL certificates fully valid for most websites. Most modern hosting providers (including BiH providers) automatically install Let's Encrypt certificates. Paid certificates (EV, OV) add extended validation — green bar with company name in browser. For most small and medium BiH businesses, free Let's Encrypt certificate is perfectly sufficient.
How to Check SSL
Visit the site and click the padlock in the address bar. Check certificate expiration date. Use SSL Labs test (ssllabs.com/ssltest) for detailed configuration analysis. Set a renewal reminder — Let's Encrypt certificates last 90 days but renew automatically if hosting is properly configured.
GDPR and Personal Data Protection Law in BiH
GDPR (General Data Protection Regulation) is EU regulation applying to everyone processing EU citizens' data — including BiH companies with clients or visitors from the EU. In BiH, the Personal Data Protection Law (Official Gazette of BiH, No. 49/06) regulates the same area domestically.
Key Principles
Lawfulness, fairness, and transparency — you must have legal basis for collecting data. Purpose limitation — collect only data needed for specific purpose. Data minimization — don't request more than you need. Accuracy — data must be current. Storage limitation — don't keep data longer than necessary. Integrity and confidentiality — you must protect data from unauthorized access.
User Rights
You must inform users about what data you collect and why. Users have right of access to their data, right to correction, right to erasure (right to be forgotten), right to data portability, and right to object.
Privacy Policy
Every website collecting personal data must have a clear privacy policy in Bosnian/Croatian/Serbian. Policy must contain: who is the data controller (your company), what data you collect, legal basis for collection, how long you keep data, who you share data with, user rights, and how to contact you.
Cookie Consent — Obligation, Not Option
If your site uses cookies other than strictly necessary ones (session cookies), you must get user consent before setting them. This includes: Google Analytics, Facebook Pixel, advertising cookies, chat widgets that track users.
How to Implement Cookie Banner
Banner must appear on first visit, before any tracking cookie is set. User must have option to accept or reject non-essential cookies. Rejection must not block access to the site. You must keep consent records. Recommended tools: Cookiebot, CookieYes, or custom solution respecting local regulations.
Google Consent Mode v2
Since 2024, Google requires Consent Mode v2 for using Google Analytics and Google Ads in the EU. Implement it if you use Google tools — otherwise you lose conversion data.
Security Best Practices — Practical Guide
Regular Updates
WordPress core, themes, and plugins must be current. Over 90% of compromised WordPress sites use outdated software. Set automatic updates for minor versions. Before major updates, make a backup.
Backup Strategy
3-2-1 rule: three copies of data, on two different media, one offsite. Automatic daily backup of database and files. Test restore process — a backup you can't restore is worthless. Keep backup minimum 30 days.
Strong Password and 2FA
Admin access to website, hosting panel, FTP, and email must have strong password — minimum 16 characters, combination of letters, numbers, and symbols. Never use the same password on multiple services. Enable two-factor authentication (2FA) everywhere possible.
Generate secure passwords using our tool at /alati/password-generator. The tool creates cryptographically secure passwords you can't guess by memory.
Access Restriction
Principle of least privilege — each user has only access they need. Remove inactive admin accounts. Change default admin username (don't use "admin"). Limit login attempts (max 3–5 before lockout). Use IP whitelist for admin panel if possible.
Web Application Firewall (WAF)
Cloudflare free plan includes basic WAF. For WordPress, plugins like Wordfence or Sucuri offer additional protection. WAF filters malicious requests before they reach your site.
Most Common Website Vulnerabilities
SQL injection — attacker injects malicious SQL code through forms. Protection: prepared statements, input validation. Cross-Site Scripting (XSS) — injecting malicious JavaScript. Protection: output encoding, Content Security Policy headers. Cross-Site Request Forgery (CSRF) — forcing authenticated user to perform action. Protection: CSRF tokens in forms. Brute force attacks — guessing passwords. Protection: rate limiting, 2FA, captcha. Outdated software — most common cause of compromise. Protection: regular updates and monitoring.
HTTPS as Ranking Factor
Google has used HTTPS as a ranking signal since 2014. Sites with SSL certificate rank better than equivalent HTTP sites. Chrome marks HTTP sites as "Not Secure" — that repels users and reduces conversions. Modern browser features (HTTP/2, HTTP/3, Service Workers) require HTTPS.
Security Checklist for BiH Businesses
SSL certificate installed and auto-renewing. Privacy policy published and current. Cookie consent banner implemented. WordPress/software updated. Backup automated and tested. Strong password and 2FA on all admin accounts. WAF active. Contact form with CAPTCHA protection. Security headers configured (HSTS, X-Frame-Options, CSP).
Website security is a continuous process, not a one-time action. Personal Data Protection Law in BiH applies, and EU clients require GDPR compliance. Combination of SSL, legal documentation, and technical protection protects both you and your clients.
Autonoma.ba helps BiH businesses implement complete web security — from SSL configuration to GDPR compliance and security audits. Contact Autonoma.ba for a free security assessment of your website.