Montenegro's data protection authority is the Agency for Personal Data Protection and Free Access to Information (Agencija za zaštitu ličnih podataka i slobodan pristup informacijama, "AZLP"). It supervises compliance with the Law on Personal Data Protection, and on 7 May 2026 its Council adopted a new Rulebook on the manner of carrying out supervision in the field of personal data protection (Pravilnik o načinu vršenja nadzora u oblasti zaštite ličnih podataka), replacing the rulebook of 16 May 2018 and in force on the day it was adopted (Rulebook, Articles 29-30).
For a foreign company processing data in Montenegro, the Rulebook matters for one reason above all: it turns an inspection into a sequence of short, fixed deadlines — three days' notice, a window of at least three days to answer the inspection minutes, eight days to object, fifteen days to fix what was found — and silence at the wrong moment counts as agreement.
Sources, checked 11 September 2026: the Law on Personal Data Protection ("ZZPL", "Sl. list CG" 079/08, 070/09, 044/12, 022/17 and 077/24) in the AZLP's consolidated text; and the 2026 Rulebook as published on the AZLP's website (a scanned document, read page by page). The Agency's list of applicable regulations, read on 11 September 2026, links both. A bill to replace the ZZPL is before Parliament and had not replaced it on that date. General information, not advice on a specific inspection.
How an inspection starts
| Trigger | What it is | Source |
|---|---|---|
| Annual plan | Regular supervision follows the annual work plan of the supervision unit; the chief inspector drafts it by the end of November for the following year and the director adopts it | Rulebook, Articles 6(1), 10 |
| Individual order | An order of the director or an assistant director | Rulebook, Article 6(1) |
| A person's complaint | A written request for protection of rights by a person who believes their rights were breached; the Agency must decide within 60 days | ZZPL, Article 47(1)-(2); Rulebook, Articles 6(2), 11 |
| An initiative by anyone | Anyone may submit an initiative in writing, by post or electronically; if it lacks information, the submitter has seven days to complete it | ZZPL, Article 65(4); Rulebook, Article 6(3) |
| Suspicion | Ex officio, on the director's order or in other justified cases of suspected unlawful processing | Rulebook, Article 6(4) |
The Rulebook states that supervision is primarily preventive, aimed at improving how controllers treat their legal obligations (Article 3(2)), and the chief inspector may issue warnings and point out harmful consequences before anything goes wrong (Article 23). That is the tone of the procedure, not a promise about its outcome.
Four kinds of inspection — and the one done from a desk
Supervision can be regular (under the annual plan), extraordinary (on a complaint, an initiative or ex officio), control (to check that irregularities were fixed) or supplementary (ordered by the Agency Council after an objection) (Rulebook, Articles 14-15). A control inspection is as a rule carried out within 30 days of the deadline for fixing irregularities, extendable to no more than 60 days (Article 14(5)).
It can also be done without anyone visiting you. A desk inspection is used where the facts can be established unambiguously from publicly available data — the internet, the media and similar — or from documents and your written statements (Rulebook, Article 7(2)). In practice your website's privacy notice, cookie banner and published policies are already part of the evidence.
Notice: three days, unless notice would defeat the purpose
As a rule, supervision is announced (Rulebook, Article 13(1)). A written notice is sent at least three days before the date set, stating the purpose, time, place and subject of the inspection, the names of the inspectors and whether your responsible persons need to be present (Article 13(2)). The inspector may announce orally where written notice is not possible (Article 13(3)) — and exceptionally need not announce at all if notice would reduce the effectiveness of the supervision (Article 13(4)).
The inspection itself is carried out under a written order naming the entity, the subject and the legal basis, the inspector and the chief inspector's signature (Rulebook, Article 12).
What inspectors may do on site
The ZZPL gives the Agency's inspectors (kontrolori) access to personal data in any filing system, whether or not it is entered in the register, and to files, documentation and electronic processing equipment — regardless of the classification level of the data (ZZPL, Article 66). The controller, user or processor must allow that access and deliver the files and documents requested (Article 67).
The Rulebook lists the working powers (Article 17). An inspector may:
- enter all premises where personal data is processed;
- inspect them and, where needed, photograph and film the premises and technical equipment such as computers and monitors;
- request access to documentation, records and registers containing personal data and other relevant business documents;
- require documents and information from you and from your processors;
- establish the identity of the persons involved in processing;
- take oral or written statements from your responsible persons and employees;
- order measures needed for the inspection to proceed;
- temporarily seize items needed to establish the facts, against a receipt;
- order a temporary ban on particular actions that could defeat the purpose of the inspection or the protection of the data subjects' rights.
If the inspection is obstructed or resistance is reasonably expected, the inspector may ask for police assistance (Rulebook, Article 4(4)).
The minutes: the deadline that decides the case
| Step | Deadline | Source |
|---|---|---|
| Minutes drafted after a complaint-based inspection | Immediately, at the latest within 8 days of the complaint (ZZPL); within 8 days of the inspection (Rulebook) | ZZPL, Article 68(2); Rulebook, Article 19(3) |
| Minutes after an initiative | Within 15 days of the inspection | Rulebook, Article 19(3) |
| Minutes after a regular inspection | The ZZPL says 15 days; the Rulebook allows up to 30 days | ZZPL, Article 68(1); Rulebook, Article 19(3) |
| Your written comments on the minutes | A deadline set by the inspector, not shorter than 3 days from receipt | Rulebook, Article 19(4) |
| If you do not comment | You are deemed to agree with the facts established in the minutes | Rulebook, Article 19(5) |
| Objection to the minutes | Within 8 days of receipt, to the Agency Council | ZZPL, Article 68(3); Rulebook, Articles 19(8), 22(1) |
| Council decision on the objection | Within 30 days of receipt | Rulebook, Article 22(2) |
Two points in that table are traps. First, the comment window can be as short as three days, and the Rulebook turns silence into acceptance of the facts. Comments on the facts and an objection to the minutes are two different instruments with two different clocks; treat them as separate deadlines. Second, the ZZPL gives 15 days for minutes after a supervision while the Rulebook allows up to 30 for a regular inspection. Where the timing matters to your position, the statute is the higher rule.
Minutes are prepared in three copies, one handed to you immediately; a refusal to receive or sign them is noted and the minutes are then treated as duly delivered (Rulebook, Article 19(4), (6)). They must list the documents inspected, the provisions breached and the provisions that require lawful conduct, any photo or video evidence, employees' statements and the legal remedy (Article 20(1)).
Orders, deadlines to fix, and when the file closes
Where the inspector finds a breach, the minutes point it out, say how to remedy it and set a deadline of no more than 15 days, extendable to no more than 60 days where the complexity requires (Rulebook, Article 21(1)(a)). If you notify the Agency in writing and prove that you have complied, there is no control inspection (Articles 21(5), 27(2)); if you do not object to the minutes and you remove the irregularities within the deadline, the procedure is treated as closed (Article 21(6)).
Where the responsible person does not object, or does not carry out the measures ordered in the minutes, or does not agree to remove the irregularities found, the Agency Council issues a decision ordering their removal (Rulebook, Article 25). The measures available to the Agency by decision are set in the statute (ZZPL, Article 71):
- ordering irregularities in processing to be removed within a set time;
- temporarily banning processing carried out contrary to the Act;
- ordering the deletion of data collected without a legal basis;
- banning transfers of personal data out of Montenegro, or disclosure to users, contrary to the Act;
- banning the outsourcing of processing to a processor that does not meet the protection conditions.
A decision of the Agency can be challenged in an administrative dispute (ZZPL, Article 72). Pending a final decision on a complaint, the Agency may, on the complainant's written request, temporarily ban further processing where a breach exists or has been made probable (ZZPL, Article 47(4); Rulebook, Article 24).
When it becomes a misdemeanour case
The director files a request to open misdemeanour proceedings where the responsible person obstructs the inspection, fails to provide accurate data or documents on time, or does not follow the inspector's orders (Rulebook, Article 21(3)), and where the controller fails to comply with the minutes or the decision (Article 21(4)). The ZZPL itself requires such a request where an objection to minutes recording unlawful processing is rejected as unfounded (ZZPL, Article 69).
Fines for a company under the ZZPL run from €500 to €20,000, including for failing to comply with an order or ban issued by the Agency (ZZPL, Article 74(1), item 21); the responsible person faces €150 to €2,000 and an entrepreneur €150 to €6,000 (Article 74(2)-(3)). Where the inspector finds grounds to suspect a criminal offence, the file goes to the competent authority (Rulebook, Article 21(1)(c)); where it points to breaches outside the Agency's remit, the competent body is informed (Article 11(4)). A person who suffered harm from a breach can claim damages from the controller under the general rules (ZZPL, Article 48).
What to have ready before the notice arrives
- The records of your filing systems and the notice given to the supervisory authority before establishing an automated filing system (ZZPL, Articles 26-27).
- The privacy information given to data subjects, as it appears on your website — a desk inspection starts there (Rulebook, Article 7(2)).
- Processor contracts, and any Agency consent needed for transfers out of Montenegro (ZZPL, Articles 16, 41) — see cross-border data transfers from Montenegro.
- For CCTV, the written decision, employee notices and sign text — see CCTV in Montenegro.
- A named person who can receive the notice, sit with the inspector and answer the minutes inside the three-day window.
- A decision, taken in advance, on who drafts comments on the minutes and who decides whether to object within eight days.
How we work on these files
We prepare companies before an inspection — a document set that answers the Rulebook's Article 17 requests and the ZZPL's Articles 66-67 — and act when the notice or the minutes arrive: comments inside the three-day window, the eight-day objection to the Council, the remedy plan against the 15-day deadline, and the administrative dispute where it is warranted. The substantive obligations sit with our data protection practice; what a foreign company must do from day one is in Montenegro data protection: what a foreign company must do.
If you have received an AZLP notice, minutes or a data subject's complaint, send it to us with the date you received it. The first thing we will tell you is how many days you have left.




