Managed ServicesOutsourced DPO
Managed Services

Outsourced DPO

The Data Protection Officer function delivered under a service agreement, for a fixed monthly fee. Independent, senior and continuous, without adding to your internal organisation.

Appointing a Data Protection Officer is mandatory if you process personal data on a large scale, regularly monitor user behaviour, or are a public authority.

The DPO does not have to be an employee: the law allows the function to be performed externally under a service agreement, which brings senior expertise, independence and continuity.

As a managed service, the DPO function runs on our platform. Your records of processing, data subject requests, incidents and DPIAs are kept in one place, and management receives a quarterly report generated from that work. The service covers GDPR and the Serbian Data Protection Act.

Included each month

What the service covers

Six workstreams that make up the monthly service.

01

Strategy, risk and documentation

  • Processing mapping (RoPA) and gap analysis of the privacy policy, processor agreements, retention and legal bases.
  • Advice on legal bases, legitimate interests, risk balancing and DPIA/LIA.
  • Compliance with special regimes: ePrivacy on cookies and marketing, and sector-specific rules.
02

Operational compliance and training

  • Role-based training for sales and marketing, product and IT, HR, support and management.
  • Privacy by design in product development: checklists, feature review stamps and release logs.
  • Risk assessment and mitigation methodology with defined criteria.
03

Data subject requests (DSAR)

  • Procedures, deadlines and response templates.
  • Management of complex cases, including competing requests and abuse of rights.
  • Identification and verification of the requester.
  • Exceptions and restrictions, communicated clearly.
04

Incidents and breaches

  • A playbook for detection, risk assessment and the decision on whether to report.
  • Coordination with IT, information security and communications.
  • Preparation and submission of reports to the authority.
  • Communication with affected individuals where required.
05

Vendors and data transfers

  • Processor agreements and subprocessor checks.
  • International transfer assessments and standard contractual clauses.
  • Cookie policy alignment with online advertising and measurement, weighed against legitimate interest and consent rules.
06

Supervisory authority cooperation and audit readiness

  • Communication with the Commissioner and other authorities.
  • Preparation of oversight documentation.
  • Internal audits and reports to management and the board.
Benefits

Why outsource it as a service

What an outsourced DPO gives you compared with appointing someone internally.

Independence built in

An external DPO avoids the conflicts that disqualify management, IT, HR or marketing leads from the role.

No in-house hire

No recruitment, training or backup for a specialist role that is hard to fill.

Audit-ready at any time

Records, requests, incidents and DPIAs are documented on the platform as the work happens.

GDPR and Serbian law

One appointment covering both the GDPR and the Serbian Data Protection Act.

Continuity

The function does not stop when someone leaves, goes on leave or changes roles.

Fixed monthly fee

The cost of the DPO function is known in advance and set by the agreed scope.

How it works

Onboarding, ongoing work and reporting

Five steps, from appointment to quarterly reporting.

01

Onboarding and appointment

Service agreement and formal appointment decision, with channels defined, the DPO contact published and the authority notified.

02

Early health-check

A quick gap analysis across policies, RoPA, cookies and marketing, vendors, transfers and incidents, with a remediation plan.

03

Process setup and training

DSAR flows, DPIA methodology, incident playbook, vendor and DPA standards, and initial role-based training.

04

Ongoing DPO work

Advice on initiatives, review of new features and participation in risk management and oversight.

05

Reporting and audit prep

Quarterly reports to management, KPIs and preparation for inspections and audits.

Platform

Your privacy programme, visible at any time

The work of the DPO is recorded as it happens, so you always know what is open and what has been done.

Every new processing activity is recorded, screened for risk and flagged for a DPIA where one is required.

Who it's for

When you need a DPO

The appointment is mandatory in these cases, and advisable in many others.

Large-scale processing

Health, financial or other sensitive data, or personal data of a large number of users.

Regular monitoring

Tracking, profiling or behavioural advertising as part of your core activity.

Public authorities

Public bodies and institutions, regardless of the volume of processing.

Groups of companies

One DPO serving several related entities, accessible to each of them.

Model

How the subscription works

One agreement per function, or several functions combined under one.

Fixed monthly fee

Priced on the scope and volume agreed at onboarding, so the cost is known in advance.

Defined scope

The agreement lists what is included each month and how much of it.

Agreed response times

Turnaround for each type of request is set in the agreement and tracked on the platform.

Regular reporting

A monthly report on volumes and open items, and a quarterly review with management.

Work outside the agreed scope is quoted separately before it starts.

FAQ

Most common questions

What clients ask before appointing an external DPO.

Does the DPO have to be our employee?

No. The law allows an external DPO acting under a service agreement.

Who decides on budget and priorities?

Management. The DPO advises and monitors, must not receive instructions on how to perform the tasks, and must have sufficient resources and access.

Can one DPO cover several entities?

Yes, provided the DPO is easily accessible to each unit or branch.

Where is the DPO contact published?

In the privacy policy or contact page, and it is communicated to the supervisory authority.

Does the DPO keep the records and file the reports?

The DPO can assist and oversee, but the organisation remains responsible for compliance. The DPO is an adviser and supervisor, not the operational controller.

What if we already have a representative for Serbia or the EU?

The representative and the DPO are different roles, and both are often required — for example a non-EU entity targeting these markets that also processes data on a large scale.

How is independence ensured when you are also our legal advisers?

Through the contract and the process: a reporting line directly to management, separation from sales and projects, and documented access and escalation in line with the independence rules.

Who cannot be a DPO?

Anyone who determines the purposes and means of processing or would end up auditing their own decisions: CEO, COO and CFO, heads of IT, marketing, sales, HR or production, CISO and data platform leads.

A quick test: does this person define the why and how of processing, control the budget and tools, or need to audit their own decisions? If so, the role is incompatible.

Related

Other managed services

Combine the DPO with other functions under one agreement.

Next step

Let’s scope your outsourced DPO

Send us a short description of your processing activities, industry and target markets and we will propose a model and a 90-day calendar.

Contact us
Newsletter

Learn legal updates, and what to do about them

Legal developments in Serbia and the EU, each with the step it asks of your business.

Sign up

Two emails a month. Unsubscribe any time.