Furthermore, global business practices are becoming increasingly prevalent, and national borders are no longer barriers to product or service deployment. This type of business inevitably leads to international data transfer.
Whether you are a B2B company collaborating with a foreign client and sharing data about your employees who will be involved in the client’s project, or you are a global provider of CRM solutions designed for the companies that will share data about their employees with you, it is clear that to establish and maintain these relationships, data sharing, including personal data, is necessary.
Learn the steps you need to take to avoid high fines for non-compliance with personal data protection regulations.
1. Identify Which Regulations Apply to You and Your Role in Data Transfer
First and foremost, you need to determine which law applies to you to know which rules you need to comply with.
If your company is based in Serbia, you are required to comply with the Law on Personal Data Protection.
In addition, there is a possibility that the General Data Protection Regulation (GDPR) will also apply to you if the conditions for the extraterritorial application of the GDPR are met. To determine whether the GDPR applies to you, read our blog Territorial Scope of GDPR in Serbia.
On the other hand, if your company has headquarters in the EU, the GDPR certainly applies to your business.
Of course, other personal data protection regulations that allow for extraterritorial application, such as the Swiss FADP or UK GDPR, are also in play.
Once you have determined which law applies to you, it is necessary to identify your role in the data transfer.
Your company may act as a data controller, data processor, or sub-processor, and depending on your role in the data transfer, the obligations you must fulfill to comply with the applicable regulations will vary.
2. Verify if You Have Entered Into Appropriate Agreements
The next step is to verify whether you have entered into appropriate agreements that regulate the processing and international transfer of personal data.
Both the Serbian Law on Personal Data Protection and the GDPR require you to regulate contractual relationships with parties with whom you share personal data. Such an agreement is called a Data Processing Agreement (DPA).
The specific content of the agreement will depend on your role and the role of the other party.
Furthermore, if there is an international transfer of personal data, it is crucial to determine which countries the data will be transferred to, as this will affect the application of Standard Contractual Clauses (SCCs) or other mechanisms for adequate data transfers (more on this in the next section).
Why is it important to conclude Data Processing and International Data Transfer Agreements (DPA)?
Because hefty fines await you!
Personal data protection regulations define extremely high penalties for failing to conclude appropriate data processing agreements. For example, according to the Serbian Law on Personal Data Protection, the penalty for violating this obligation can be up to 2 million Serbian dinars, while under the GDPR, this penalty can reach up to 10 million EUR (or 20 million in the case of international transfer) or 2% of your global annual revenue (or 4% in the case of international transfer), whichever amount is higher.

