Appointing a Data Protection Officer is mandatory if you process personal data on a large scale, regularly monitor user behaviour, or are a public authority.
The DPO does not have to be an employee: the law allows the function to be performed externally under a service agreement, which brings senior expertise, independence and continuity.
Our external DPO service combines legal knowledge, administrative discipline and technical understanding, covering GDPR and the Serbian Data Protection Act.
Delivery is operational: DPIAs, training, data subject requests, incident oversight and cooperation with the Commissioner and other supervisory authorities, with independence and direct access to management.