1. Blog
  2. Data protection

Data protection

GDPR and call center outsourcing: what you need when your provider is in Serbia

9 min readSeptember 20, 2026

Data protection is where outsourcing projects get stuck in the legal department, and usually not because something is impossible, but because nobody prepared the documents. This guide describes what a company in the EU or the UK needs when a contact center in Serbia processes customer data, which questions the data protection officer will ask, and how to answer them. It also covers what changes for US clients. It is not legal advice, but it should make the conversation with your lawyer a short one.

The starting point: Serbia as a third country

From the perspective of the GDPR and the UK GDPR, Serbia is a third country without an adequacy decision. That does not mean a transfer is prohibited. It means the transfer has to rest on one of the safeguards the law provides, in practice standard contractual clauses.

What speaks for Serbia: since 2019 the country has had a data protection law that largely follows the GDPR in structure and terminology, with its own supervisory authority, data subject rights, breach notification duties and fines. Serbia is a party to Convention 108 of the Council of Europe and a candidate for EU membership. For the risk assessment you have to document anyway, that is a good starting position.

The four documents you need

1. Data processing agreement (DPA). The basis is Art. 28 GDPR, identical in the UK GDPR. The agreement states that the provider processes only on your instructions, binds its staff to confidentiality, implements technical and organizational measures, uses sub-processors only with your approval, supports you with data subject requests and breaches, deletes or returns data at the end of the contract, and grants you audit rights. A provider that works for EU or UK clients has this agreement as a template and can send it to you on day one.

2. Transfer mechanism. For EU clients, the European Commission’s 2021 standard contractual clauses (SCCs), module “controller to processor.” For UK clients, the ICO’s International Data Transfer Agreement (IDTA) or the UK addendum to the EU SCCs. The clauses must not be modified; their annexes (description of processing, technical measures, sub-processors) must be filled in.

3. Transfer impact assessment (TIA). Since the Schrems II ruling of the Court of Justice of the EU, you have to document that the law of the destination country does not undermine the protection of the clauses, in particular through government access. For Serbia this assessment is usually short: a GDPR-style data protection law, a supervisory authority, and no known legal basis for indiscriminate mass surveillance of business communications. Document it anyway, with a date, and repeat it when the contract is renewed.

4. Records and notices. The processing by the provider goes into your record of processing activities, and your privacy notice must mention the transfer to a third country and the category of recipient. If calls are recorded, that goes in too.

Call recording: the touchiest question

Quality control in a contact center rests on listening to calls. With us, every successful outbound call is reviewed before the result is delivered; in inbound, samples are reviewed according to an agreed scope. Both require recording, and recording is legally demanding:

  • In several EU countries (Germany among them) and in Switzerland, recording a private conversation without the consent of all participants is a criminal offense. In the US, most states allow one-party consent, but a number of states, including California, Florida, Illinois and Washington, require all-party consent. In practice, consent is obtained through an announcement at the start of the call stating purpose and recording; anyone who disagrees must be able to continue without recording.
  • The recording is purpose-bound: quality control and training, not marketing, not performance surveillance beyond what was agreed.
  • Access is limited to quality control and is logged.
  • There is a retention period that fits the purpose. Keeping recordings for months after the review requires an explanation.
  • The agents must be informed about the recording too; that belongs in their employment contract and the provider’s internal privacy notice.

Ask the provider how the announcement is worded, where the recordings are stored, who has access and when they are deleted. Anyone without an immediate answer has never put the topic in a contract.

Technical and organizational measures

The DPA requires “appropriate” measures. For a contact center these have proven to be the minimum:

  • Role-based access. The agent sees only the CRM fields needed for the task. Export, bulk download and printing are disabled for agent accounts.
  • No local storage. Work in your systems over a secured connection or in a virtual desktop; nothing sits on the agent’s device.
  • Multi-factor authentication and logging. Every access is attributable to a person.
  • Remote work rules. Company device or hardened environment, no personal devices for customer data, a defined workplace without third parties present, USB and screen capture disabled, webcam monitoring only if contractually agreed and permitted under labor law.
  • Confidentiality undertaking and training. Every agent signs before first access and is trained annually.
  • Data minimization. For outbound campaigns the provider receives only the fields needed for the call, not your entire customer database.
  • Sub-processors. Telephony provider, CRM hosting, recording storage: all must be listed in the annex to the SCCs or IDTA, with location.
  • Incident reporting. The provider reports every breach without undue delay to a named contact on your side so that you can meet the 72-hour deadline toward the supervisory authority.
  • Deletion and return. At the end of the contract, data is deleted or returned at your choice, with written confirmation.

Checklist for selecting a provider

Ask these nine questions before signing. The answers belong in the contract:

  1. Can you show me your DPA and completed standard contractual clauses or IDTA?
  2. Which sub-processors do you use and where are their servers?
  3. How is call recording announced, where is it stored, who has access, when is it deleted?
  4. How do remote agents work, and how do you ensure no data is stored locally?
  5. How is access to our CRM restricted, and what can an agent account export?
  6. How do you report an incident, to whom, within what deadline?
  7. Who is responsible for data protection on your side, and how often are agents trained?
  8. Can we or an appointed auditor verify your measures, on site or through evidence?
  9. What happens to the data after the contract ends?

A provider that cannot answer more than two of these immediately is not ready for EU or UK clients, no matter how well its agents speak.

What changes for US clients

If your customers are in the US and you have no EU or UK data subjects, the GDPR does not apply. What does apply is a patchwork: state privacy laws such as the CCPA/CPRA in California and their counterparts in a growing number of states, sector rules such as HIPAA for health data or GLBA for financial data, and the TCPA for outbound calling. In practice, the same documents do the job: a service agreement with data protection terms, a sub-processor list, recording rules that respect all-party-consent states, access controls and incident reporting. Your legal team will recognize the structure even if the statute names differ.

What stays on your side

Outsourcing shifts the work, not the responsibility. You remain the controller in the legal sense. That means you decide purposes and means, you inform your customers, you answer data subject requests (with the provider’s support), and you notify the authority of incidents. The provider is your extended workbench, with all the duties the DPA imposes, but not your replacement.

The practical effort is manageable if the provider brings the documents: sign the DPA and the transfer clauses, check the annexes, document the TIA, update your records and privacy notice. With a prepared partner that happens during the preparation phase, in parallel with training the team, and does not delay the start.

Conclusion

Data protection in call center outsourcing to Serbia is not a question of whether but of preparation: a data processing agreement, standard contractual clauses or an IDTA, a documented transfer impact assessment, and clean rules for call recording and remote work. Settle those four points before signing and you have the legal department on your side and the provider where it belongs: under contract, with clear obligations.


We Connect has worked for partners in Europe and North America since 2016. We present the data processing agreement, transfer clauses and rules on recording and remote work before the start, together with an NDA and an access concept. If you want to find out whether your process can be outsourced, describe it briefly. You will get a proposal within 48 hours.

Frequently asked questions

Can a call center in Serbia process data of EU or UK customers?

Yes, if the transfer is secured. Serbia is a third country without an adequacy decision from the EU or the UK. That is why you need a data processing agreement, the EU standard contractual clauses (or the UK International Data Transfer Agreement or addendum) and a documented transfer impact assessment. Serbia has its own data protection law modeled on the GDPR and is a party to Convention 108 of the Council of Europe.

May calls be recorded for quality control?

Only with a legal basis and notice to the participants. In several EU countries, recording without the consent of all parties is a criminal offense; in the US, a number of states require all-party consent. The usual practice is an announcement at the start of the call stating purpose and recording, combined with purpose limitation, restricted access and fixed retention periods. Anyone who does not want to be recorded must be able to continue without recording.

Who is liable if a data breach happens at the provider?

Toward data subjects and supervisory authorities, the client remains responsible as the controller. The processor is liable to the client under the data processing agreement and must report incidents without undue delay so that the client can meet the GDPR's 72-hour notification deadline. That is why reporting channels and deadlines belong in the contract.

Tell us what you need.

Describe the task, the language and the volume. Within 48 hours you get a team proposal, a collaboration model and a quote.