Data Protection Workshop

Personal Data Protection

ABOUT THE LECTURER

Denis Thoule is a PhD student in law, a legal consultant with a narrow specialization in the regulation of ICT systems (personal data protection, AI law, intellectual property law and trade secret protection).

Denis has worked with a large number of renowned clients in Serbia, Bosnia and Herzegovina, the region and the EU (Denmark). Some of the clients include Mad Head Games, the Chamber of Commerce, the Faculty of Law for Economy and Justice, DPMetals, Cinaplexx, CreenIT, Re5, BrainCapture (and others still under trade secret). Denis has worked with start-ups, primarily technology-oriented, often with IT companies, as well as with medium and large companies across various industries—from energy and transport to hospitality and the entertainment industry. He has carried out business compliance processes for numerous clients domestically and internationally via websites and applications.

Denis is the author of the manual “Personal Data Protection”, through which he refined and publicly presented the methodology he applies in business compliance with the GDPR and local personal data protection regulations. He is also the author of several international scientific papers in his field and a speaker at many regional scientific and professional conferences. Additionally, Denis is the author of the DPO Training program, numerous seminars, and the online course “IT Law”.

He is currently working on his doctoral dissertation entitled: “Corporate Implementation of the AI Act with Special Reference to Personal Data Protection: Framework of Obligations, Proportionality and Provability of Compliance”.

Denis is a Certified Trainer and Examiner for the PIMS Training Group (ISO/IEC 27701, GDPR) at the Global Standards Consortium.

LinkedIn: linkedin.com/in/denistul
Website: lawit.rs


WORKSHOP: PERSONAL DATA PROTECTION IN PRACTICE – FROM CHAOS TO ORDER IN 90 DAYS

The workshop will be held on February 12, 2026, at the Center for Digital Transformation, Kneza Miloša 11, Belgrade, in the Training Center hall on the mezzanine floor, from 10:00 to 15:00. Coffee will be provided during the break.

Registration for the workshop is done via the following link: APPLICATION LINK

The workshop is intended for both individuals and legal entities. Registration can be done individually or through a company. A discount is available for legal entities sending three or more participants. For more information, contact cdt@pks.rs.

The price of the workshop is 15,000 RSD + VAT. After completing the registration form, all registered participants will receive a pro forma invoice via email. Payment must be completed no later than three days before the workshop.

The effective duration of the workshop is 4 hours. All participants will receive a certificate of attendance issued by the Center for Digital Transformation and a certificate of 4 Professional Education Hours (PEH).

For additional information, contact the Center for Digital Transformation at cdt@pks.rs with the subject “Workshop: Digital Business in Practice”.

LECTURE SUMMARY

The lecture provides insight into the process of aligning business operations with regulations in the field of personal data protection (GDPR and the Law on Personal Data Protection in Serbia, applicable in Bosnia and Herzegovina as well). We break down the key phases of the process and the methodology that delivers the best results in practice and has proven successful across various industries.

We cover which documents need to be prepared and which measures help protect personal data. Business owners and management will learn how to implement this procedure in the simplest way possible, without overburdening themselves or their employees.

Practical advice is drawn from years of hands-on experience at the highest professional level.

OBJECTIVES OF THE WORKSHOP

BENEFITS FOR PARTICIPANTS

WORKSHOP AGENDA

PART I: INTRODUCTION TO PERSONAL DATA PROTECTION

⏱ 10:00 – 11:30 (90 minutes)

  1. Introduction: The Logic Behind the Personal Data Protection System
    • Privacy as a human right
    • Basic principles – minimization
    • Risk assessment and mitigation
    • Regulation in the EU and the Balkans
  2. Basic concepts
    • Personal data
    • Special categories of data
    • Processors
    • DPO
  3. Principles of personal data protection
    • Legality: purpose and legal basis
    • Minimization
    • Transparency

PART II: THE PROCESS OF ALIGNING BUSINESS OPERATIONS WITH REGULATION

⏱ 12:00 – 13:30 (90 minutes)

  1. Aligning business with regulation
    • Decision to initiate the process
    • Resources required
    • Stages of the procedure
  2. Data mapping within the company (Phase I)
    • Process and business needs
    • Tools
  3. Analysis and proposal of documentation and measures
    • Analysis
    • Designing an individual personal data protection system
    • Documentation proposal
    • Proposed measures

☕ Coffee break — 13:30 – 13:45

PART III: DOCUMENTATION

⏱ 13:45 – 14:45 (60 minutes)

  1. Preparation of documentation
    • Document preparation and implementation
    • Personal Data Protection Policy
    • Records
    • Controller–Processor contracts
    • Website documentation
    • Video surveillance
    • Risk assessments and DPIA
    • Procedures
  2. Implementation of measures
    • Measure definition and application
  3. Conclusion of the process
    • Handover and results

PART IV: CONCLUSIONS AND Q&A

14:45 – 15:00 (15 minutes)