Appointing a Data Protection Officer is mandatory if you process personal data on a large scale, regularly monitor user behaviour, or are a public authority.
The DPO does not have to be an employee: the law allows the function to be performed externally under a service agreement, which brings senior expertise, independence and continuity.
As a managed service, the DPO function runs on our platform. Your records of processing, data subject requests, incidents and DPIAs are kept in one place, and management receives a quarterly report generated from that work. The service covers GDPR and the Serbian Data Protection Act.