Data subject requests and communication
- Receipt and handling of requests for access, deletion and objection.
- Communication with the Commissioner on your behalf.
- Defined response deadlines and multi-channel availability.
A local contact point in Serbia for the Commissioner and data subjects, for companies with no establishment here that offer services to or monitor individuals in Serbia.
Contact usIf your company has no business presence in Serbia but processes the personal data of individuals here, in many cases you are obliged to appoint a Data Protection Representative.
The Representative is a local natural person or legal entity, formally authorised to represent you in data protection matters and available to the Commissioner and to data subjects.
The obligation usually applies where you offer goods or services to individuals in Serbia, including free services, or monitor their activity through cookies, analytics, profiling or targeted advertising.
There is no obligation for public authorities, or where processing is occasional, does not involve large-scale special categories or criminal conviction data, and is unlikely to pose a risk to rights and freedoms.
Six areas the appointment covers.
Five steps, from the obligation assessment to ongoing support.
Screening under the Serbian Data Protection Act and the Commissioner’s practice.
Power of attorney, contact points and service levels agreed.
A dedicated address set up and the privacy notice updated with the Representative’s contact.
Where required: RoPA and procedures for handling data subject requests.
Regular review of compliance in communication and cooperation with the Commissioner.
A sample of recent work in the sector.
Where a registered office is used for actual and stable operations, a separate Representative is generally not required — we review the specific case.
Complaints and claims are directed at the controller or processor. The Representative is a contact point and intermediary, not a shield from liability.
Where you target or monitor individuals in the EU, an EU representative is usually required in a Member State, subject to the same exemptions.
Beyond reputational risk and obstructed cooperation with the authority, misdemeanour proceedings and fines under the Act are possible.
Yes. The law allows the representative to be a natural person or a legal entity with residence or seat in Serbia, and data protection expertise is advisable for the role to be performed properly.
No. A DPO is an independent function that advises and monitors compliance; the Representative is a local contact point for external communication and handling of requests in Serbia.
The Representative does not monitor compliance — the role is accessibility and communication.
Yes. The identity and contact details must be published transparently so the Commissioner and data subjects can make contact, most commonly in the privacy policy and on the contact page.
If the office is used for actual and stable operations, the usual position is that a separate Representative is not required. We recommend reviewing the specific business model, contracts and data flows.
Primary responsibility stays with the controller or processor. The Representative is a contact point acting on instructions; complaints and claims are directed at the controller.
If you target individuals in the EU or monitor their behaviour, Article 27 GDPR usually requires an EU representative, unless an exemption applies.
Yes, where you delegate it and the criteria for mandatory records are met. In any case the Representative must have access to the necessary information.
Send us a short description of your business model and processing in Serbia and you will get a quick assessment and a step plan.
Contact usRecent writing on data protection obligations in Serbia.






Legal developments in Serbia and the EU, each with the step it asks of your business.
Two emails a month. Unsubscribe any time.