PracticesMost Awarded Attorneys for Data Protection in Serbia
Tech expertise

Most Awarded Attorneys
for Data Protection in Serbia

Consistently recognized as global and thought leaders by top international legal directories for leadership in data protection.

Contact us
Lexology Index Client Choice Awards 2024
WWL Thought Leaders Global Elite — Data 2024
WWL hosted by Lexology — Data 2024
WWL Thought Leaders — Data 2023
WWL — Data Privacy & Protection 2023
WWL — Information Technology 2023
WWL Thought Leaders — Data Privacy & Protection 2022
WWL — Data 2022
WWL Thought Leaders — Data 2021
WWL — Data 2021
Lexology Index Client Choice Awards 2024
WWL Thought Leaders Global Elite — Data 2024
WWL hosted by Lexology — Data 2024
WWL Thought Leaders — Data 2023
WWL — Data Privacy & Protection 2023
WWL — Information Technology 2023
WWL Thought Leaders — Data Privacy & Protection 2022
WWL — Data 2022
WWL Thought Leaders — Data 2021
WWL — Data 2021
The cost of non-compliance

Failing to be GDPR Compliant
Is Too Expensive

What non-compliance actually costs a business.

Hefty GDPR Penalties

Up to €20 million or 4% of global turnover — and it reaches non-EU companies too.

Risks of Lawsuits

Claims from affected individuals — and lost contracts with clients who demand compliance.

Lost Deals or Procurements

Without proof of compliance, tenders disqualify you and deals stall.

Reputational Damage

A breach costs trust instantly, and the damage outlasts the incident.

What we do

Data Protection Types of Support

Four ways we take data protection off your desk.

Legal Consulting for Data Protection

We interpret GDPR provisions and align them with your business model, for legal certainty in complex environments.

Explore legal consulting services

DPO-as-a-Service

Outsourced Data Protection Officer for organizations without an internal one. We monitor compliance and act as the contact point for supervisory authorities.

Explore DPO-as-a-Service

Information Security & Regulatory Alignment

Compliance now demands information security as well. We integrate GDPR with broader frameworks, including NIS 2 and DORA.

Explore information security services

Data Representative for Foreign Companies

The EU-mandated GDPR Data Representative for businesses outside the EU — your official contact point with data subjects and authorities.

Explore GDPR representative services
Data protection training

Data Protection Law Training

Two programmes: one for the whole team, one for the people who carry formal responsibility.

Training for Staff

Practical sessions on everyday risks, best practices and compliance awareness, so your team becomes the first line of defense against data breaches. Under GDPR, staff must stay continuously informed, so refreshers matter.

Book training

Training for DPOs

Advanced expertise for Data Protection Officers: GDPR obligations, risk management, dealing with supervisory authorities and building compliance into business processes.

Book training
Technology partnership

Zunic Law & Whisperly AI
Smarter GDPR Compliance

Our team works inside Whisperly, an AI-powered privacy platform. Legal advice and the software that carries it out sit in one place, so compliance is documented and audit-ready from day one.

Whisperly RoPA Controller — Employee HR Data Management
1Records

RoPA for controller and processor roles

A guided seven-step record. The AI suggests legal bases, retention periods and transfer mechanisms.

2Visibility

Track your compliance or audit progress

A live tracker shows every phase of the programme, with owners, deadlines and completion rates.

3One workspace

No more Excel. No more back and forth emails.

Records, recipients, DPAs and assessments live in one workspace shared with your legal team.

4Output

Generate policies and reports in a few clicks

RoPAs, DPIAs, measures and open risks are drawn straight from your records into finished documents.

See how your compliance would look in Whisperly

We set up your workspace, map your existing documentation and show you where the gaps are.

Learn about Whisperly
FAQ

Frequently Asked Questions

The questions companies ask us most often about data protection.

Who needs to comply with the GDPR?

Any organization that offers goods or services to people in the EU, or monitors their behaviour, regardless of where it is established. Serbian companies are also covered by the domestic Law on Personal Data Protection.

What is a Record of Processing Activities (RoPA) and do we need one?

A RoPA sets out what personal data you process, why, on what basis, who receives it and how long you keep it. It is usually the first document a supervisory authority asks to see.

When do we have to appoint a Data Protection Officer?

Where processing is carried out by a public authority, where core activities involve regular and systematic monitoring on a large scale, or where special categories of data are processed on a large scale. The role can be filled externally.

How long does a GDPR compliance project take?

With a structured methodology and the right tooling, weeks rather than months. The timeline depends on how many systems, vendors and cross-border transfers are in scope.

Can we transfer personal data outside the EU?

Yes, where an appropriate transfer mechanism is in place, such as an adequacy decision or standard contractual clauses, supported by an assessment of the recipient country and any additional safeguards it calls for.

What happens if the supervisory authority opens an inspection?

We represent you throughout, prepare the responses and documentation the authority requests, and work to keep the financial and reputational exposure as low as possible.

Next step

Let's talk about your data protection setup

Tell us where you are today and we will map the fastest route to compliance.

Contact us
Newsletter

Learn legal updates, and what to do about them

Legal developments in Serbia and the EU, each with the step it asks of your business.

Sign up

Two emails a month. Unsubscribe any time.