In 2024 the Montenegrin data protection authority carried out 101 supervisions. Not one of them was a routine, planned audit. The Agency says so itself: because of an unexpectedly large number of citizen approaches — initiatives to open supervision and requests for protection of rights — no routine supervisions were performed at all that year. All 101 were extraordinary: 34 triggered by a request for protection of rights and 62 by an initiative to open a supervision, with the small balance falling under the Act's third ground, supervision on the order of the head of the authority.
That single fact should reorganise how a foreign company thinks about data protection risk in Montenegro. Your realistic exposure is not an inspector arriving on a schedule. It is one person — a departing employee, a candidate you rejected, a customer, a neighbour who noticed your camera — filling in a one-page form. Under Article 65 of the Zakon o zaštiti podataka o ličnosti, anyone may file an initiative to open a supervision, and the Agency publishes the form on its website.
So the useful question is not "are we broadly compliant?" It is: what exactly have we filed, and what will the file look like when someone complains? This page is the filing chain, in order. The separate question of which regime applies — Montenegrin law, GDPR, or both — is covered in our note on why Montenegro is not a GDPR country.
Step 1 — register the controller, on paper as well as online
Before you can notify anything, your company has to exist in the Agency's system as a rukovalac zbirke ličnih podataka. The Agency operates this through Montenegro's eGovernment portal, and the procedure is hybrid — electronic, then physical:
- Register an account on the eUprava portal of Montenegro.
- Run the electronic service for registering a controller, entering the company's details and those of the authorised person inside your company.
- Print the submitted form, certify it with the company stamp, and deliver it by post to the Agency's archive. The Agency then compares the paper against the electronic submission and assigns a status.
- If the status comes back ODOBREN — approved — you are registered in the Agency's system.
Step 3 is the one that derails foreign groups. The submission is not complete when the portal says it is sent; it is complete when a stamped hard copy reaches Podgorica and is matched. Budget calendar time for it, and give the authorised person named in the form real authority, because that name is what the Agency will contact.
The controller registration is run once. You re-run it only when something changes — address, telephone, or the authorised person.
Step 2 — notify each filing system separately
Registration as a controller is not notification of processing. Under Article 27(1) the controller must notify the supervisory authority before establishing an automated personal data filing system, and again on any significant change. Each filing system is a separate submission: the electronic service must be run once per zbirka. If you are amending one you already notified, use the same name for it, or the Agency will treat it as new.
What goes in is set by Article 26(2) — the name of the filing system, the legal basis, the controller's identity and seat, the purpose, the categories of data subjects, the types of data, the retention and use period, the recipients, the details of any transfer out of Montenegro, and the controller's internal processing and protection rules. The form itself is prescribed by a pravilnik on the form and manner of keeping the record, made under Article 26(3) by the Ministry of Interior and Public Administration and published in Sl. list CG 73/2010 of 10 December 2010 — a 2010 instrument still governing the 2026 filing. The Agency publishes the form, an instruction sheet for completing it, and the pravilnik together.
Two consequences worth planning around. First, the Register is public: Article 29 has the supervisory authority keep it and Article 30 makes its entries available to the public. What you write in the purpose and data-type fields is a published description of your processing. Second, this is a populated register, not a formality — the Agency's 2024 report records it as holding 810 controllers and 2,426 filing-system records.
Step 3 — write the internal rule, because four other things depend on it
Article 26(2)(10) requires the record to include the controller's internal rules on processing and protection, described in the Act as rules enabling a prior analysis of the adequacy of security measures. This is not a formality either: the internal rule is the first document the Agency asks for when you apply for a permit, and it is the document a supervision starts from.
Around it sit the operational duties: technical, staffing and organisational security measures proportionate to the data (Art. 24(1)–(2)); automatic logging in electronic systems of who accessed which data, on what legal basis, with case number and login and logout times (Art. 24(3)); a determination of which employees may access which data and on what conditions (Art. 24(4)), applied through the controller's own act (Art. 24(5)); a duty on staff to act exclusively on the instructions of the responsible person and to keep the data secret (Art. 25); and a register of every third-party recipient, what was disclosed, why, on what basis and for how long, kept for ten years (Art. 19).
The Agency publishes a model internal rule alongside its forms. Use it as the skeleton and then make it describe your actual systems, because the version that helps you is the one that matches what a kontrolor will see.
Step 4 — the permit, and the document set it really requires
Article 28(1) requires the Agency's prior consent for automated processing that presents a special risk — special categories of data, data used to assess personality, ability or behaviour, video surveillance of public areas, and biometric data. Article 28(2) then disapplies the requirement where processing rests on a law, on the data subject's consent, or on the necessity of performing a contract with the data subject.
What the permit traffic actually consists of is worth knowing before you build a compliance plan around it. In 2024 the Agency issued 74 consents, and its report states that all of them were consents for introducing video surveillance. If your Montenegrin operation has cameras, this is your permit process. The Agency also sets out what must accompany the application:
| Document required with a video surveillance consent application | Anchored in |
|---|---|
| Internal rule on the protection of personal data | Art. 26(2)(10) |
| Decision introducing video surveillance | Art. 35(2)–(3), Art. 36(3) |
| Opinion or statement of the trade union or employees' representative | Art. 36(4) |
| Filing-system record for video surveillance, on the prescribed form | Art. 26–27 |
| Information on the general characteristics of the cameras | Art. 28 assessment |
The third row is the one foreign employers most often cannot produce, because nothing in a GDPR programme generates it. If your Montenegrin office has no trade union, the Act still requires the opinion of the employees' representative before the decision is taken — which means there has to be one, and the sequence has to be documented in that order.
Transfers: the permit exists, but almost nobody uses it
Article 41 makes transferring personal data out of Montenegro subject to the Agency's prior consent. In 2024 the Agency issued three. That number is not evidence of a dormant obligation; it is evidence that the traffic runs through the Article 42 exemptions instead — principally Article 42(6) for transfers to EU and EEA states or states on the EU adequacy list, and Article 42(8) for a contract carrying the contractual obligations accepted by EU member states, concluded with a processor in a non-EU state.
The practical instruction follows from those two numbers. Do not plan on obtaining a transfer permit. Plan on documenting, before the data moves, which Article 42 exemption each flow sits in — and keep that reasoning where a kontrolor can read it, since Article 26(2)(9) already requires the transfer details to be in your filing-system record.
What happens when someone complains
| Stage | Rule |
|---|---|
| Anyone files an initiative; supervision runs ex officio | Art. 65 |
| Inspector accesses data, files and systems — registered or not, regardless of secrecy classification | Art. 66 |
| Controller must enable access and hand over documents | Art. 67 |
| Minutes (zapisnik) issued within 15 days — or 8 days where triggered by a rights request | Art. 68(1)–(2) |
| Objection (prigovor) to the Agency | 8 days from receiving the minutes (Art. 68(3)) |
| Objection unfounded → measures imposed and misdemeanour proceedings requested | Art. 69 |
| Decision on a request for protection of rights | 60 days (Art. 47(2)) |
| Interim ban on further processing while the case runs | Art. 47(4) |
| Challenge to the Agency's decision | Administrative dispute (Art. 47(5), Art. 72) |
Two features of that chain deserve emphasis because they are the opposite of what a GDPR-trained team expects.
The Agency does not fine you. Where an objection is unfounded, Article 69 has the Agency impose measures and separately file a request to open misdemeanour proceedings. The penalty in Article 74 — €500 to €20,000 for a legal person — is imposed by a court in those proceedings, not by the regulator. There is no administrative fining power to negotiate with.
The measures bite harder than the fine. Article 71 lets the Agency order irregularities remedied within a set deadline, temporarily prohibit processing carried out contrary to the Act, order deletion of data collected without legal basis, prohibit transfer out of Montenegro or disclosure to recipients, and prohibit entrusting processing to a processor that does not meet the conditions. For an operating business, an order deleting a dataset or stopping a transfer is a materially larger event than a €20,000 ceiling.
That this is used is on the record. In 2024 the Agency issued a decision temporarily prohibiting processing through public-area video surveillance systems in Podgorica, Bar and Budva, and then a decision permitting surveillance to continue — pending the outcome of the administrative dispute — only with cameras that had no biometric facial recognition software installed. Alongside those, six administrative disputes were brought against Agency decisions in the same year.
2024 in numbers
| Agency activity, personal data protection | 2024 |
|---|---|
| Supervisions carried out (all extraordinary) | 101 |
| — on requests for protection of rights | 34 |
| — on initiatives to open supervision | 62 |
| — balance, on the third statutory ground | 5 |
| Routine planned supervisions | 0 |
| Decisions (rješenja) issued | 19 |
| Consents for introducing video surveillance | 74 |
| Consents for transferring data out of Montenegro | 3 |
| Formal opinions issued | 7 |
| Administrative disputes brought against the Agency | 6 |
| Controllers in the Register / filing-system records | 810 / 2,426 |
These are the Agency's own figures for 2024, published in its annual report in March 2025. The report for 2025 is listed on the Agency's site but the file returns a 404, checked on 25 August 2026 — so the most recent complete picture available is the one above, and it should be read as a year old.
Before your Montenegrin entity processes anything
The sequence that works is dull and short: identify every filing system you will actually operate; write the internal rule so it describes those systems; register the controller and post the stamped copy; notify each filing system on the prescribed form; apply for the camera consent with the five documents in the order the Act requires, union or employee opinion first; and record, per flow, which Article 42 exemption carries your transfers.
The sequence that fails is the common one: arrive with a GDPR pack, treat the Montenegrin filings as an administrative afterthought, install the cameras before taking the employee opinion, and then discover the gaps in a zapisnik you have eight days to object to.
If you are opening or already running a Montenegrin entity, send us your processing inventory, your draft internal rule and your camera plan, and we will tell you what has to be filed, in what order, and what is missing from the permit file. This work sits in our data protection practice, next to IT and technology contracts and AI. If the entity is still being formed, start with company formation in Montenegro; if you are hiring, the employee-facing duties sit beside these in our employer labour law and payroll guide and our recruitment and work permit practice. Regulated financial entities carry an additional ICT resilience layer, set out in our note on Montenegro's payment services regime.
Statutory references are to the consolidated Zakon o zaštiti podataka o ličnosti (Sl. list CG 079/08, 070/09, 044/12, 022/17, 077/24 of 5 August 2024). Procedural detail, forms, the register and the 2024 figures come from the supervisory authority's own website and its annual report for 2024 (Podgorica, March 2025), read on 25 August 2026. The 2010 pravilnik reference is taken from the scanned copy the Agency publishes; verify the gazette issue before relying on the citation. General information on Montenegrin law, not advice on a specific processing operation.



