Consistently recognized as global and thought leaders by top international legal directories for leadership in data protection.
Contact us



















What non-compliance actually costs a business.
Up to €20 million or 4% of global turnover — and it reaches non-EU companies too.
Claims from affected individuals — and lost contracts with clients who demand compliance.
Without proof of compliance, tenders disqualify you and deals stall.
A breach costs trust instantly, and the damage outlasts the incident.
Four ways we take data protection off your desk.
We interpret GDPR provisions and align them with your business model, for legal certainty in complex environments.
Explore legal consulting servicesOutsourced Data Protection Officer for organizations without an internal one. We monitor compliance and act as the contact point for supervisory authorities.
Explore DPO-as-a-ServiceCompliance now demands information security as well. We integrate GDPR with broader frameworks, including NIS 2 and DORA.
Explore information security servicesThe EU-mandated GDPR Data Representative for businesses outside the EU — your official contact point with data subjects and authorities.
Explore GDPR representative servicesThe work we are engaged for most often, from a first compliance project to due diligence in a transaction.
Two programmes: one for the whole team, one for the people who carry formal responsibility.
Practical sessions on everyday risks, best practices and compliance awareness, so your team becomes the first line of defense against data breaches. Under GDPR, staff must stay continuously informed, so refreshers matter.
Book trainingAdvanced expertise for Data Protection Officers: GDPR obligations, risk management, dealing with supervisory authorities and building compliance into business processes.
Book trainingOur team works inside Whisperly, an AI-powered privacy platform. Legal advice and the software that carries it out sit in one place, so compliance is documented and audit-ready from day one.

A guided seven-step record. The AI suggests legal bases, retention periods and transfer mechanisms.
A live tracker shows every phase of the programme, with owners, deadlines and completion rates.
Records, recipients, DPAs and assessments live in one workspace shared with your legal team.
RoPAs, DPIAs, measures and open risks are drawn straight from your records into finished documents.
We set up your workspace, map your existing documentation and show you where the gaps are.
The questions companies ask us most often about data protection.
Any organization that offers goods or services to people in the EU, or monitors their behaviour, regardless of where it is established. Serbian companies are also covered by the domestic Law on Personal Data Protection.
A RoPA sets out what personal data you process, why, on what basis, who receives it and how long you keep it. It is usually the first document a supervisory authority asks to see.
Where processing is carried out by a public authority, where core activities involve regular and systematic monitoring on a large scale, or where special categories of data are processed on a large scale. The role can be filled externally.
With a structured methodology and the right tooling, weeks rather than months. The timeline depends on how many systems, vendors and cross-border transfers are in scope.
Yes, where an appropriate transfer mechanism is in place, such as an adequacy decision or standard contractual clauses, supported by an assessment of the recipient country and any additional safeguards it calls for.
We represent you throughout, prepare the responses and documentation the authority requests, and work to keep the financial and reputational exposure as low as possible.
Tell us where you are today and we will map the fastest route to compliance.
Contact usLegal developments in Serbia and the EU, each with the step it asks of your business.
Two emails a month. Unsubscribe any time.