Serbia Project Atlasby Faith Forge Labs
Atlas coordinate 03Data path

Data route sheet

Draw the personal-data path before it disappears into vendors.

A privacy notice is not the first data-control task. First identify every collection point, purpose, recipient, storage location, retention rule and accountable person.

The data route

This is a technical discovery framework, not legal advice. Serbia's Commissioner for Information of Public Importance and Personal Data Protection is the authoritative public authority; qualified counsel should decide legal interpretations where needed.

StationQuestions to answerBuild evidence
CollectionWhat fields, files, identifiers, logs, cookies or model prompts enter? Which are truly necessary for the stated purpose?Field inventory, consent or notice placement, rejected-input tests
AccessWhich staff, contractors, administrators and automated services can read or change each class of data?Role matrix, test accounts, access logs and removal procedure
ProcessorsWhich hosts, email tools, analytics services, payment providers, AI vendors and backups receive data?Vendor register, configured regions, contracts owned by the client
TransferDoes information move between Serbia, the United States or other countries? Who approves the transfer mechanism?Flow diagram and counsel-approved transfer decision when required
RetentionWhen is each record deleted, anonymised or archived? What happens to copies and backups?Retention schedule, deletion test and restoration boundary
Rights and incidentsWho receives a request or security report, verifies identity, gathers records and tracks the response?Named owner, runbook, request test and incident contact route

AI-specific checkpoint

A model is another data destination.

If an AI feature receives customer messages, internal documents or staff input, record exactly what is sent, which provider processes it, whether it is retained or used for training, and what a human can inspect. Retrieval sources should be named. Sensitive information should not be added merely because it improves an output.

  • Test a prompt that includes information the model should never receive.
  • Test what happens when a source is missing, conflicting or stale.
  • Provide a human route for consequential or uncertain output.
  • Log enough to investigate errors without creating a second uncontrolled personal-data store.

What Faith Forge Labs can implement

Within an approved requirements map, the technical work can include data minimisation, permissions, secure configuration, audit trails, export and deletion tools, consent controls, processor boundaries, incident logging and acceptance tests. Faith Forge Labs can document the implemented behaviour and surface unanswered decisions.

Faith Forge Labs does not declare a Serbia-facing system legally compliant, act as a data-protection authority, or choose a legal basis on the client's behalf. Those decisions remain with the responsible organisation and qualified professionals.