Serbia’s expanding electricity and digital infrastructure could create a new export model in which power is consumed domestically by data centres and converted into cloud, storage and computing services sold to European Union customers, avoiding the direct CBAM exposure attached to physical electricity exports while creating a new set of energy, carbon and regulatory risks for banks financing the sector.
The distinction is important.
Electricity physically exported from Serbia into the EU falls within the Carbon Border Adjustment Mechanism and can be exposed to Serbia’s electricity default emissions factor unless the importer qualifies to use verified actual emissions.
A Serbian data centre consuming the same electricity domestically and selling data-storage, hosting or computing services to a customer in Germany, France or another EU country does not create the same CBAM liability.
What crosses the border commercially is a service rather than electricity or another CBAM-covered good.
That could turn data centres into an increasingly important mechanism for converting Serbian electricity into higher-value exports.
But carbon does not disappear from the transaction.
Instead of appearing at the EU customs border through CBAM, it moves into the European customer’s supply-chain emissions, sustainability reporting and procurement requirements.
For banks, that means the key financing question is not whether a Serbian data centre is “CBAM compliant”.
It is whether the asset can reliably convert Serbian electricity into long-term euro-denominated digital-service revenue while satisfying European customers’ energy, carbon, cyber and data-protection requirements.
Electricity can be exported without physically leaving Serbia
The economic distinction can be illustrated using one megawatt-hour.
If a Serbian power producer exports 1 MWh directly into the EU, that electricity enters the CBAM framework.
If the same megawatt-hour is consumed by a Serbian steel or aluminium plant and incorporated into a CBAM-covered product, its emissions can become relevant to the embedded-emissions calculation of that exported good.
But if the electricity powers servers inside Serbia and the resulting storage or computing service is sold to an EU company, the electricity itself never crosses the EU customs border.
There is therefore no CBAM certificate obligation attached to the digital service under the current regime.
The commercial chain becomes:
Serbian electricity → Serbian data centre → computing/storage → EU customer
rather than:
Serbian electricity → interconnector → EU electricity importer → CBAM
This is not a CBAM exemption mechanism or regulatory loophole.
It simply reflects the present structure of the EU system, which applies CBAM to specified imported goods rather than cross-border digital services.
For Serbia, however, the economic consequences could be significant.
Instead of monetising electricity primarily at the wholesale power price, data-centre infrastructure can use the same energy input to support recurring revenues from cloud, colocation, artificial-intelligence computing and data-storage services.
That turns electricity into an input for a higher-value export.
Carbon risk moves from customs to the customer
The absence of direct CBAM exposure does not mean electricity emissions become irrelevant.
European companies increasingly need information on emissions associated with purchased cloud-computing and data-centre services.
Under Europe’s sustainability reporting framework, these services can form part of the customer’s Scope 3 emissions.
The emissions chain therefore changes from:
Serbian electricity → EU CBAM importer
to:
Serbian electricity → Serbian data-centre Scope 2 → EU customer Scope 3.
That makes the carbon intensity of the data centre commercially important even if it does not generate a CBAM bill.
A European corporation choosing between two hosting providers may increasingly compare not just price, latency and uptime but also energy efficiency and the carbon intensity of the service.
That creates a possible disadvantage for Serbian facilities relying heavily on conventional grid electricity.
It also creates an opportunity for facilities capable of demonstrating access to renewable electricity through a robust PPA, guarantees of origin and independently verified consumption data.
For Serbia’s renewable sector, data centres could therefore become a new category of large domestic offtaker.
Renewable PPAs could become part of the data-centre product
A Serbian data centre targeting EU customers does not need to reproduce the complex CBAM electricity actual-emissions architecture used for physical electricity exports.
It does not require an EU authorised CBAM declarant or cross-border electricity nominations merely because its customer sits inside the EU.
The more relevant energy architecture is domestic:
Serbian renewable producer → PPA → data-centre meter → consumption records → guarantees of origin → carbon accounting → EU customer reporting.
For a lender, this makes the electricity contract a critical part of the project’s bankability.
Banks should examine PPA tenor, supplier creditworthiness, expected generation, balancing responsibility, curtailment, price indexation, termination rights, replacement supply and ownership of guarantees of origin.
A simple annual renewable-volume calculation is not enough.
Data centres operate around the clock.
Wind and solar do not.
A project claiming 100% renewable electricity on an annual basis may still consume conventional grid electricity during many hours when its contracted renewable generator is not producing.
The bank therefore needs to model the difference between annual renewable coverage and actual hourly energy requirements.
Storage, hydroelectric supply, diversified renewable portfolios or shaped supply contracts can reduce that mismatch.
Hourly electricity matching could become a premium product
CBAM does not require a Serbian data centre selling services to EU customers to match its electricity consumption with renewable generation hour by hour.
But the same principle could become commercially valuable.
A stronger Serbian data-centre product could demonstrate:
hourly facility load → hourly renewable generation → contractual allocation → certificate retirement → customer workload allocation.
That would go substantially beyond a conventional annual green-electricity claim.
It would allow a Serbian provider to tell a European customer not merely that it bought renewable certificates equal to annual consumption but that the customer’s workload was associated with demonstrably renewable supply at a much more granular level.
For multinational companies under pressure to reduce supply-chain emissions, that could become a procurement differentiator.
For banks, it could improve customer retention and reduce transition risk.
EU efficiency standards will influence Serbian projects indirectly
EU data-centre policy is also becoming more demanding.
European rules increasingly track metrics including Power Usage Effectiveness, Water Usage Effectiveness, Energy Reuse Factor and Renewable Energy Factor, while policymakers are moving towards more formal efficiency classifications and minimum performance requirements.
A Serbian facility is not automatically subject to all EU reporting obligations simply because it serves EU customers.
But commercially, banks should assume that serious European buyers will increasingly expect similar information from their non-EU suppliers.
A Serbian data centre seeking long-term European contracts should therefore be designed to report the same metrics voluntarily.
That should include:
PUE, WUE, renewable-energy share, total electricity consumption, cooling performance, Scope 1 emissions, location-based Scope 2, market-based Scope 2 and customer-attributed emissions.
Facilities unable to generate those numbers could face an increasing competitive disadvantage even if they are legally permitted to sell services into the EU.
Banks should treat electricity like a critical feedstock
For lenders, the biggest mistake would be to finance a data centre as if it were primarily a commercial property development.
Electricity is closer to a critical industrial feedstock.
The bank needs to understand:
available MW, contracted MW, grid connection, firm versus interruptible capacity, annual MWh demand, PUE, network charges, power price, backup generation and redundancy.
A data centre with cheaper construction but unstable electricity economics can be less bankable than a more expensive facility with long-term energy certainty.
The same applies to grid reliability.
Banks should examine whether the project has dual power feeds, independent transformers, backup generators, battery storage, sufficient fuel reserves and an electrical design capable of maintaining service during faults or planned maintenance.
For a data centre, a short outage can produce customer penalties and reputational damage vastly greater than the value of the electricity not consumed during those hours.
Availability therefore matters more than average power price alone.
Revenue contracts are as important as the physical asset
The second major lending question is customer quality.
Banks should analyse who is buying the capacity and under what terms.
Critical metrics include:
contracted IT load, contracted rack capacity, minimum volume commitments, contract duration, termination rights, service-level penalties, renewal assumptions and customer concentration.
A facility with long-term contracts from investment-grade European corporations is fundamentally different from a speculative development relying on future demand.
The biggest customer should be stress-tested separately.
Banks should ask what happens to debt service if the largest tenant terminates or does not renew.
That is particularly important because digital workloads can sometimes be relocated much more easily than physical industrial production.
Customer contracts therefore become part of the infrastructure value of the project.
GDPR may matter more than CBAM
For many EU customers, the biggest regulatory question will not be carbon.
It will be data.
Serbia does not currently benefit from an EU GDPR adequacy decision.
Where personal data is transferred from the EU to a Serbian data centre, European customers therefore need an appropriate legal transfer mechanism.
That can include Standard Contractual Clauses and associated safeguards.
Banks should therefore analyse the facility’s entire data-protection architecture, including:
data-processing agreements, encryption, key management, access controls, data-location transparency, subcontractors and customer audit rights.
A technically strong data centre unable to satisfy European data-protection requirements could struggle to attract premium customers.
That risk directly affects projected occupancy and therefore debt capacity.
NIS2 can directly affect a Serbian provider
Cyber regulation creates another layer.
The EU’s NIS2 framework covers cloud-computing and data-centre service providers and can extend obligations to certain non-EU providers offering services inside the Union.
A Serbian operator targeting EU customers may therefore need an EU representative and governance systems capable of satisfying European cyber-resilience requirements.
Banks should examine incident-management systems, security certifications, business continuity, disaster recovery, cyber insurance and subcontractor controls.
These are not peripheral ESG issues.
They can determine whether the facility remains legally and commercially acceptable to major European customers.
EU banks bring DORA into the credit case
A Serbian facility targeting European financial institutions faces an even higher compliance threshold.
Under the EU’s Digital Operational Resilience Act, banks, insurers and other regulated financial companies must exercise detailed oversight of critical ICT suppliers.
That creates additional requirements around resilience, outsourcing, subcontractors, concentration risk, data locations, audit rights and exit strategies.
A lender financing a Serbian data centre targeting EU financial institutions should therefore ask a very practical question:
Can an EU bank’s procurement and risk committee approve this provider?
If not, the assumed customer market in the financial model may be overstated.
DORA readiness should therefore form part of commercial due diligence rather than being left to post-construction compliance work.
Technology risk is unusually high
Data centres also have a different obsolescence profile from conventional infrastructure.
Buildings may last decades.
Server and cooling requirements can change far faster.
Artificial-intelligence and high-performance computing are increasing rack densities and accelerating the shift towards liquid cooling.
A facility designed around traditional low-density racks could remain physically intact but become commercially outdated.
Banks should therefore assess:
maximum rack density, liquid-cooling readiness, transformer capacity, spare electrical capacity, fibre connectivity and expansion potential.
The credit model should include additional CAPEX needed to remain competitive during the loan tenor.
That is particularly important for facilities positioned around AI demand, where technology requirements are evolving quickly.
Banks need combined downside scenarios
A base-case EBITDA calculation is not enough for data-centre debt sizing.
Several project risks can occur simultaneously.
The lender should stress:
- power prices rising by 25%-50%;
- renewable PPA output below forecast;
- higher-than-design PUE;
- loss of the largest customer;
- occupancy ramp-up delayed by 12-24 months;
- construction CAPEX rising 10%-20%;
- grid connection delays;
- a major SLA outage;
- higher regulatory and cybersecurity expenditure;
- loss of renewable-energy claims;
- additional CAPEX for new cooling or rack-density requirements.
The critical debt-service test should combine at least higher electricity prices + weaker occupancy + poorer PUE.
Those three variables directly attack both revenue and operating margins.
Carbon becomes part of credit due diligence
Serbian banks are also beginning to face stronger expectations around climate-risk management and the quality of underlying ESG data.
Data centres offer an unusual advantage because their principal operating emissions source — electricity — can be measured accurately.
A lender should therefore require a carbon file containing:
hourly and annual electricity use, renewable coverage, PPA data, guarantees-of-origin cancellation, backup-generator fuel use, PUE, water consumption, Scope 1 emissions, location-based Scope 2, market-based Scope 2 and emissions intensity per service unit.
The objective should not be to label the project “CBAM compliant”.
The objective is to determine whether carbon intensity could affect revenue, customer access, operating costs or refinancing value.
Exit value depends heavily on power
For bank recovery analysis, a data centre’s value is also different from ordinary real estate.
The building is only one component.
Secured electrical capacity, fibre connectivity, customer contracts, renewable procurement and expansion potential can be more valuable than the physical shell.
A site with 50 MW of secured grid capacity, strong fibre connectivity and long-term EU customers may attract infrastructure funds, specialist data-centre operators or private-equity investors.
A technically similar building without secure power can be far less valuable.
Banks should therefore avoid relying too heavily on conventional property valuation in recovery scenarios.
Data centres could become part of Serbia’s energy strategy
The broader implication goes beyond individual projects.
Serbia has several ways to monetise electricity.
It can export electricity directly.
It can use electricity in industrial production and export physical goods.
Or it can use electricity domestically to power digital infrastructure and export services.
The third option can create higher value added while avoiding direct CBAM exposure on the electricity itself.
Instead of exporting:
1 MWh × wholesale power price
Serbia can potentially export:
1 MWh → compute/storage capacity → recurring euro-denominated service revenue.
The electricity stays inside Serbia.
Domestic utilities receive network revenue. Renewable generators gain large offtakers. Telecom infrastructure expands. Skilled employment and tax revenue remain domestic.
The exported product is digital.
That could make renewable-powered data centres an important bridge between Serbia’s energy and services-export strategies.
Banks need a different underwriting framework
The opportunity is significant, but it requires a different credit approach.
CBAM risk for the data-storage service itself is relatively low because the service is not an imported CBAM good.
Energy and carbon-transition risk are materially higher because European clients increasingly care about the emissions associated with their digital supply chains.
Power, cyber, regulatory and customer risks are higher still because they determine whether the facility can continuously produce the service from which debt is repaid.
The bankability equation is therefore:
secure grid connection + resilient electrical design + bankable PPA + efficient facility + strong EU customers + GDPR/NIS2/DORA readiness + measurable low-carbon electricity + technology flexibility.
A project missing one of those elements may still operate.
A project combining all of them can become infrastructure-grade.
For Serbian banks, the key question is therefore not whether data centres offer a way around CBAM.
It is whether Serbia can use domestically consumed electricity to build a durable new category of high-value EU services exports — and whether the projects financing that transformation can still generate predictable cash flow after power prices, technology, customer requirements and European regulation change.
If the answer is yes, data centres could become one of the clearest examples of Serbia moving from exporting energy as a commodity to exporting the economic value created by that energy.

