Appoint us
EU representative under Article 27 GDPR for companies established in Serbia

REP27 · EU representative · Serbia

Article 27 GDPR · Serbia

EU representative for Serbia companies, signed in 24 hours.

If your company is established in Serbia and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why Serbian companies fall under Article 27

The Serbian Law on Personal Data Protection closely follows the GDPR and expressly requires foreign controllers to appoint a representative in Serbia. Article 27 is the mirror duty for the Union, and Serbia is not a member state.

€525,000The Dutch supervisory authority fined Locatefamily.com €525,000 for failing to designate an EU representative, and added periodic penalties until the company complied. No other breach was needed.

Who typically needs it here

IT outsourcing and software development for European clients, automotive suppliers, agriculture, and e-commerce serving the region.

Marketing that reaches the Union

A campaign targeted at European users, a European language on the landing page, a local phone number: the test is whether you envisaged those customers, not whether you meant to.

Cookies and pixels on EU visitors

Behavioural analytics on people in the Union is monitoring under Article 3(2)(b). This route catches companies with no European revenue at all.

Support and warranty data

Tickets, RMA forms and warranty registrations from European customers are personal data you process. B2B does not change that.

Your regulator at home, and why it does not help here

The Serbian Law on Personal Data Protection closely follows the GDPR and expressly requires foreign controllers to appoint a representative in Serbia. The Commissioner enforces it. Serbia is not a member state.

Who supervises you locally

the Commissioner for Information of Public Importance and Personal Data Protection. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

Serbian companies reach the Union through IT outsourcing and product development for European clients, automotive suppliers, agriculture, and regional e-commerce.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

Signed designation letter

The written designation Article 27(1) requires, countersigned by Europe Services, SE and signed electronically under eIDAS, naming the member states covered.

Verifiable certificate

A certificate with a QR code and a public verification page, so a regulator, a client or a buyer can confirm the designation is live at that moment.

Request desk in Prague

A dedicated address, inbox and form. Every request from a data subject or an authority is logged and forwarded to you within two business days.

Questions from Serbian companies

Our law is a copy of the GDPR. Does that make us exempt?

No. A similar national law does not put Serbia inside the Union. If you reach people in the EU, you designate a representative established in a member state.

We already appointed a representative in Serbia for foreign clients. Is it reciprocal?

No. That designation exists under Serbian law for foreign companies. Article 27 wants one in the Union for you: same structure, opposite direction.

Most of our clients are German. Does the language matter?

For the designation, no. For the desk, yes: requests arrive in German and are handled in German, and the privacy notice wording is generated in German.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

Cover your EU customers from Serbia

Serbian IT firms usually understand this faster than most, because their own law taught them the same mechanism.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check