Technology

What a Foreign Company Must Actually File With Montenegro's Data Protection Authority

Controller registration, filing-system notification, the video surveillance permit set and the complaint procedure, with the regulator's 2024 figures.

Rohat Kahraman· 25 August 2026Updated · 25 August 2026
Abstract cover for an article on registering and notifying personal data filing systems with Montenegro's data protection authority

In 2024 the Montenegrin data protection authority carried out 101 supervisions. Not one of them was a routine, planned audit. The Agency says so itself: because of an unexpectedly large number of citizen approaches — initiatives to open supervision and requests for protection of rights — no routine supervisions were performed at all that year. All 101 were extraordinary: 34 triggered by a request for protection of rights and 62 by an initiative to open a supervision, with the small balance falling under the Act's third ground, supervision on the order of the head of the authority.

That single fact should reorganise how a foreign company thinks about data protection risk in Montenegro. Your realistic exposure is not an inspector arriving on a schedule. It is one person — a departing employee, a candidate you rejected, a customer, a neighbour who noticed your camera — filling in a one-page form. Under Article 65 of the Zakon o zaštiti podataka o ličnosti, anyone may file an initiative to open a supervision, and the Agency publishes the form on its website.

So the useful question is not "are we broadly compliant?" It is: what exactly have we filed, and what will the file look like when someone complains? This page is the filing chain, in order. The separate question of which regime applies — Montenegrin law, GDPR, or both — is covered in our note on why Montenegro is not a GDPR country.

Step 1 — register the controller, on paper as well as online

Before you can notify anything, your company has to exist in the Agency's system as a rukovalac zbirke ličnih podataka. The Agency operates this through Montenegro's eGovernment portal, and the procedure is hybrid — electronic, then physical:

  1. Register an account on the eUprava portal of Montenegro.
  2. Run the electronic service for registering a controller, entering the company's details and those of the authorised person inside your company.
  3. Print the submitted form, certify it with the company stamp, and deliver it by post to the Agency's archive. The Agency then compares the paper against the electronic submission and assigns a status.
  4. If the status comes back ODOBREN — approved — you are registered in the Agency's system.

Step 3 is the one that derails foreign groups. The submission is not complete when the portal says it is sent; it is complete when a stamped hard copy reaches Podgorica and is matched. Budget calendar time for it, and give the authorised person named in the form real authority, because that name is what the Agency will contact.

The controller registration is run once. You re-run it only when something changes — address, telephone, or the authorised person.

Step 2 — notify each filing system separately

Registration as a controller is not notification of processing. Under Article 27(1) the controller must notify the supervisory authority before establishing an automated personal data filing system, and again on any significant change. Each filing system is a separate submission: the electronic service must be run once per zbirka. If you are amending one you already notified, use the same name for it, or the Agency will treat it as new.

What goes in is set by Article 26(2) — the name of the filing system, the legal basis, the controller's identity and seat, the purpose, the categories of data subjects, the types of data, the retention and use period, the recipients, the details of any transfer out of Montenegro, and the controller's internal processing and protection rules. The form itself is prescribed by a pravilnik on the form and manner of keeping the record, made under Article 26(3) by the Ministry of Interior and Public Administration and published in Sl. list CG 73/2010 of 10 December 2010 — a 2010 instrument still governing the 2026 filing. The Agency publishes the form, an instruction sheet for completing it, and the pravilnik together.

Two consequences worth planning around. First, the Register is public: Article 29 has the supervisory authority keep it and Article 30 makes its entries available to the public. What you write in the purpose and data-type fields is a published description of your processing. Second, this is a populated register, not a formality — the Agency's 2024 report records it as holding 810 controllers and 2,426 filing-system records.

Step 3 — write the internal rule, because four other things depend on it

Article 26(2)(10) requires the record to include the controller's internal rules on processing and protection, described in the Act as rules enabling a prior analysis of the adequacy of security measures. This is not a formality either: the internal rule is the first document the Agency asks for when you apply for a permit, and it is the document a supervision starts from.

Around it sit the operational duties: technical, staffing and organisational security measures proportionate to the data (Art. 24(1)–(2)); automatic logging in electronic systems of who accessed which data, on what legal basis, with case number and login and logout times (Art. 24(3)); a determination of which employees may access which data and on what conditions (Art. 24(4)), applied through the controller's own act (Art. 24(5)); a duty on staff to act exclusively on the instructions of the responsible person and to keep the data secret (Art. 25); and a register of every third-party recipient, what was disclosed, why, on what basis and for how long, kept for ten years (Art. 19).

The Agency publishes a model internal rule alongside its forms. Use it as the skeleton and then make it describe your actual systems, because the version that helps you is the one that matches what a kontrolor will see.

Step 4 — the permit, and the document set it really requires

Article 28(1) requires the Agency's prior consent for automated processing that presents a special risk — special categories of data, data used to assess personality, ability or behaviour, video surveillance of public areas, and biometric data. Article 28(2) then disapplies the requirement where processing rests on a law, on the data subject's consent, or on the necessity of performing a contract with the data subject.

What the permit traffic actually consists of is worth knowing before you build a compliance plan around it. In 2024 the Agency issued 74 consents, and its report states that all of them were consents for introducing video surveillance. If your Montenegrin operation has cameras, this is your permit process. The Agency also sets out what must accompany the application:

Document required with a video surveillance consent applicationAnchored in
Internal rule on the protection of personal dataArt. 26(2)(10)
Decision introducing video surveillanceArt. 35(2)–(3), Art. 36(3)
Opinion or statement of the trade union or employees' representativeArt. 36(4)
Filing-system record for video surveillance, on the prescribed formArt. 26–27
Information on the general characteristics of the camerasArt. 28 assessment

The third row is the one foreign employers most often cannot produce, because nothing in a GDPR programme generates it. If your Montenegrin office has no trade union, the Act still requires the opinion of the employees' representative before the decision is taken — which means there has to be one, and the sequence has to be documented in that order.

Transfers: the permit exists, but almost nobody uses it

Article 41 makes transferring personal data out of Montenegro subject to the Agency's prior consent. In 2024 the Agency issued three. That number is not evidence of a dormant obligation; it is evidence that the traffic runs through the Article 42 exemptions instead — principally Article 42(6) for transfers to EU and EEA states or states on the EU adequacy list, and Article 42(8) for a contract carrying the contractual obligations accepted by EU member states, concluded with a processor in a non-EU state.

The practical instruction follows from those two numbers. Do not plan on obtaining a transfer permit. Plan on documenting, before the data moves, which Article 42 exemption each flow sits in — and keep that reasoning where a kontrolor can read it, since Article 26(2)(9) already requires the transfer details to be in your filing-system record.

What happens when someone complains

StageRule
Anyone files an initiative; supervision runs ex officioArt. 65
Inspector accesses data, files and systems — registered or not, regardless of secrecy classificationArt. 66
Controller must enable access and hand over documentsArt. 67
Minutes (zapisnik) issued within 15 days — or 8 days where triggered by a rights requestArt. 68(1)–(2)
Objection (prigovor) to the Agency8 days from receiving the minutes (Art. 68(3))
Objection unfounded → measures imposed and misdemeanour proceedings requestedArt. 69
Decision on a request for protection of rights60 days (Art. 47(2))
Interim ban on further processing while the case runsArt. 47(4)
Challenge to the Agency's decisionAdministrative dispute (Art. 47(5), Art. 72)

Two features of that chain deserve emphasis because they are the opposite of what a GDPR-trained team expects.

The Agency does not fine you. Where an objection is unfounded, Article 69 has the Agency impose measures and separately file a request to open misdemeanour proceedings. The penalty in Article 74 — €500 to €20,000 for a legal person — is imposed by a court in those proceedings, not by the regulator. There is no administrative fining power to negotiate with.

The measures bite harder than the fine. Article 71 lets the Agency order irregularities remedied within a set deadline, temporarily prohibit processing carried out contrary to the Act, order deletion of data collected without legal basis, prohibit transfer out of Montenegro or disclosure to recipients, and prohibit entrusting processing to a processor that does not meet the conditions. For an operating business, an order deleting a dataset or stopping a transfer is a materially larger event than a €20,000 ceiling.

That this is used is on the record. In 2024 the Agency issued a decision temporarily prohibiting processing through public-area video surveillance systems in Podgorica, Bar and Budva, and then a decision permitting surveillance to continue — pending the outcome of the administrative dispute — only with cameras that had no biometric facial recognition software installed. Alongside those, six administrative disputes were brought against Agency decisions in the same year.

2024 in numbers

Agency activity, personal data protection2024
Supervisions carried out (all extraordinary)101
— on requests for protection of rights34
— on initiatives to open supervision62
— balance, on the third statutory ground5
Routine planned supervisions0
Decisions (rješenja) issued19
Consents for introducing video surveillance74
Consents for transferring data out of Montenegro3
Formal opinions issued7
Administrative disputes brought against the Agency6
Controllers in the Register / filing-system records810 / 2,426

These are the Agency's own figures for 2024, published in its annual report in March 2025. The report for 2025 is listed on the Agency's site but the file returns a 404, checked on 25 August 2026 — so the most recent complete picture available is the one above, and it should be read as a year old.

Before your Montenegrin entity processes anything

The sequence that works is dull and short: identify every filing system you will actually operate; write the internal rule so it describes those systems; register the controller and post the stamped copy; notify each filing system on the prescribed form; apply for the camera consent with the five documents in the order the Act requires, union or employee opinion first; and record, per flow, which Article 42 exemption carries your transfers.

The sequence that fails is the common one: arrive with a GDPR pack, treat the Montenegrin filings as an administrative afterthought, install the cameras before taking the employee opinion, and then discover the gaps in a zapisnik you have eight days to object to.

If you are opening or already running a Montenegrin entity, send us your processing inventory, your draft internal rule and your camera plan, and we will tell you what has to be filed, in what order, and what is missing from the permit file. This work sits in our data protection practice, next to IT and technology contracts and AI. If the entity is still being formed, start with company formation in Montenegro; if you are hiring, the employee-facing duties sit beside these in our employer labour law and payroll guide and our recruitment and work permit practice. Regulated financial entities carry an additional ICT resilience layer, set out in our note on Montenegro's payment services regime.

Statutory references are to the consolidated Zakon o zaštiti podataka o ličnosti (Sl. list CG 079/08, 070/09, 044/12, 022/17, 077/24 of 5 August 2024). Procedural detail, forms, the register and the 2024 figures come from the supervisory authority's own website and its annual report for 2024 (Podgorica, March 2025), read on 25 August 2026. The 2010 pravilnik reference is taken from the scanned copy the Agency publishes; verify the gazette issue before relying on the citation. General information on Montenegrin law, not advice on a specific processing operation.

Frequently asked questions

Do we have to register with the Montenegrin data protection authority?

Yes, in two distinct steps that are often confused. First the company is registered as a controller (rukovalac zbirke ličnih podataka) in the Agency's system. Second, each automated personal data filing system is notified separately under Article 27(1), before it is established, with the content set out in Article 26(2). Registering the controller does not notify any processing.

How does the filing actually work?

Through Montenegro's eUprava portal, with a paper step in the middle. You register an account, run the electronic service for controller registration entering the company and the authorised person inside it, then print the submitted form, certify it with the company stamp and post it to the Agency's archive. The Agency compares paper against electronic submission and assigns a status; approval shows as ODOBREN. Once approved, you run a separate electronic service for each filing system you notify.

Is our filing public?

Yes. Article 29 has the supervisory authority keep the Register and Article 30 makes its entries available to the public. Treat the purpose and data-type fields as a published description of your processing rather than an internal note. The Agency's 2024 report records the Register as holding 810 controllers and 2,426 filing-system records.

How likely is an inspection?

Not likely on a schedule, and quite likely on a complaint. In 2024 the Agency carried out 101 supervisions and states that none were routine planned audits — 34 followed requests for protection of rights and 62 followed initiatives to open a supervision. Under Article 65 anyone may file such an initiative, and the Agency publishes the form.

When do we need the Agency's prior consent rather than just a notification?

Article 28(1) requires prior consent for automated processing presenting a special risk: special categories of data, data used to assess personality, ability or behaviour, video surveillance of public areas, and biometric data. Article 28(2) disapplies that where processing rests on a law, on the person's consent, or on the necessity of performing a contract with them. In practice the permit traffic is video surveillance — all 74 consents the Agency issued in 2024 were for introducing video surveillance.

What documents go with a video surveillance consent application?

The Agency lists five: the internal rule on the protection of personal data; the decision introducing video surveillance; the opinion or statement of the trade union or the employees' representative; the filing-system record for video surveillance on the prescribed form; and information on the general characteristics of the cameras. The employee-representative opinion must come before the decision is taken (Article 36(4)), so the order matters as much as the content.

We have no trade union in Montenegro. Does the consultation still apply?

Article 36(4) requires the opinion of the representative trade union or the employees' representative before the decision to introduce workplace video surveillance is taken. The absence of a union does not remove the step; it means the employees' representative provides the opinion. It is also one of the five documents the Agency expects with the consent application.

Do we need a permit to send data to our parent company abroad?

Article 41 requires the Agency's prior consent for transfers out of Montenegro, but Article 42 sets out nine exemptions, and in practice almost all traffic runs through them: the Agency issued only three transfer consents in the whole of 2024. The two exemptions that carry most corporate flows are Article 42(6), for EU and EEA states and states on the EU adequacy list, and Article 42(8), for a contract carrying the contractual obligations accepted by EU member states with a processor in a non-EU state. Document which exemption each flow relies on, and note that Article 26(2)(9) already requires transfer details in your filing-system record.

What can the inspector see?

Under Article 66 the kontrolor has access to personal data in filing systems whether or not those systems are entered in the Register, to files and other documentation relating to processing, and to the electronic processing systems themselves — and that access applies regardless of the level of secrecy of the data. Article 67 obliges the controller, user or processor to enable that access and hand over requested documents. Confidentiality classification is not a basis for withholding material.

What are the deadlines once a supervision starts?

Minutes of the supervision (zapisnik) are drawn up within 15 days and delivered to the controller (Article 68(1)); where the supervision follows a request for protection of rights the inspector must act immediately and at the latest within 8 days (Article 68(2)). Both the controller and the person who filed the request may lodge an objection with the Agency within 8 days of receiving the minutes (Article 68(3)). A request for protection of rights must be decided by rješenje within 60 days (Article 47(2)).

Can the Agency fine us directly?

No. Where an objection is unfounded, Article 69 has the Agency impose measures and separately file a request to open misdemeanour proceedings. The fine in Article 74 — €500 to €20,000 for a legal person, €150 to €2,000 for the responsible person, €150 to €6,000 for an entrepreneur — is imposed by a court in those proceedings. There is no administrative fining power to negotiate with, and no GDPR-style settlement.

What can the Agency order?

Article 71 gives it five measures by decision: order irregularities remedied within a set deadline; temporarily prohibit processing carried out contrary to the Act; order deletion of data collected without legal basis; prohibit transfer out of Montenegro or disclosure to recipients contrary to the Act; and prohibit entrusting processing to a processor that does not meet the protection conditions. For a running business these usually matter more than the fine ceiling.

Can we challenge a decision?

Yes, by administrative dispute before the Administrative Court — Article 72 for supervision decisions and Article 47(5) for decisions on requests for protection of rights. There is no administrative appeal above the Agency. Six such disputes were brought against Agency decisions in 2024. Separately, Article 47(4) allows the Agency to impose an interim ban on further processing while a rights case is pending, on the written request of the applicant.

Has the Agency actually stopped anyone?

Yes, and recently. In 2024 it issued a decision temporarily prohibiting processing through public-area video surveillance systems in Podgorica, Bar and Budva, and then a decision permitting surveillance to continue pending the administrative dispute only with cameras that had no biometric facial recognition software installed. The Agency describes the purpose as preventing excessive use of video surveillance and use beyond the scope of consents it had previously given.

Are the Agency's current figures available?

The most recent complete published picture is the 2024 report, issued in March 2025. The Agency's site lists a report for 2025, but that file returns a 404 — checked on 25 August 2026. Treat the figures on this page as a year old and confirm against the Agency's site before relying on them.