Service Overview

Serbian PDPL Representative (Article 44)

Lionheart Squared (Europe) Limited · Dublin, Ireland · with an established partner in Serbia

The Serbian Law on Personal Data Protection requires controllers and processors not established in Serbia to appoint a representative in Serbia if they offer goods or services to individuals in Serbia or monitor their behaviour. The representative acts as a contact point for the Commissioner for Information of Public Importance and Personal Data Protection and for data subjects in relation to the organisation's obligations under the law. Closely modelled on the EU GDPR, the law also requires certain organisations to keep records of their processing activities and make them available to the Commissioner on request.

Service Detail

What this service covers

Our focus

Senior-led support for complex cross-border privacy operations

Your Serbian mandate is handled by experienced privacy and technology professionals who understand both the legal framework and the operational realities of global services, SaaS, adtech, AI, media and online platforms. We work as an extension of your privacy function, helping ensure that regulatory correspondence is received, logged, escalated and actioned correctly.

Coordinated with your wider European footprint

Many organisations needing a Serbian representative also require an EU GDPR representative, UK GDPR representative, Swiss FADP representative, or support under adjacent digital regulations. Lionheart coordinates these mandates under a single relationship — consistent procedures, aligned records and a unified escalation path across jurisdictions.

Our services include

Custom email address

A dedicated @LionheartSquared.rs address published in your privacy notice and records of processing activities, monitored year-round.

Serbian physical address

A postal address in Serbia — provided through our established in-country partner — available for inclusion in your privacy documentation and registration with the Commissioner, satisfying the Article 44 presence requirement.

Commissioner liaison

Registering a formal contact point for the Commissioner for Information of Public Importance and Personal Data Protection on your behalf — receiving, logging and forwarding all correspondence without delay.

Unlimited data subject enquiries

Receiving and forwarding access, erasure, rectification, restriction and objection requests from individuals in Serbia to your privacy team for handling.

Escalation procedures

Defined escalation paths and service levels for time-sensitive regulatory communications, including data breach notifications. Activity reporting available on request.

ROPA record-keeping

Lionheart holds a copy of your Records of Processing Activities (ROPA), as required under the Serbian Law on Personal Data Protection, available to the Commissioner upon request.

Legal basis: Article 44, Serbian Law on Personal Data Protection ("Official Gazette of the Republic of Serbia", No. 87/2018)

Get started

Not sure if you are in scope?

Use the guided self-check tool to map which representative obligations may apply.