Some employees of the National Security Agency (ANB) filed an anonymous criminal complaint with the Special State Prosecutor's Office (SDT) at the end of April, claiming that all employees of the agency are illegally under constant surveillance by the ANB, via an application installed on their official mobile phones. They also anonymously contacted the Personal Data Protection Agency (AZLP) and the Security and Defense Committee.
From SDT, AZLP, as well as the chairman of the parliamentary committee Nikola Zirojevic they confirmed for Center for Investigative Journalism of Montenegro (CIN-CG) that they received these letters.
According to the criminal complaint that CIN-CG had access to, officials claim that there is reason to suspect that "in the ANB during 2025, at the latest from June, a systematic, massive and indiscriminate GPS was established, i.e. monitoring of the location of employees via the 'Hexnode for work' application, installed on official mobile devices, which, according to available information, was still active at the time of filing the report, contrary to constitutional and legal guarantees of the right to privacy and protection of personal data."
Several unrelated sources from the security sector that CIN-CG spoke to confirmed that this type of employee surveillance was established during 2025.
The “Hexnode For Work” application is an MDM (Mobile Device Management) system, i.e. a solution for centralized management of official devices, which allows administrators to remotely install or restrict applications, manage certain device functions and, depending on the configuration, track data such as device location.
The surveillance system, as stated in the documentation, is applied "to all ANB officers, without a specific and individually determined basis or suspicion in relation to certain persons, without a clear demarcation between working and non-working hours, without a properly and transparently communicated purpose of processing, and without a known internal act that would precisely regulate in advance the legal basis, scope of application, data retention periods, circle of authorized users and appropriate protective guarantees," it says, among other things, in the criminal report to the SDT, which CIN-CG had access to.
It is emphasized that "certain categories of employees, especially operational personnel, were ordered to carry their official mobile phones outside of working hours in order to be constantly available for official needs." Monitoring of employees during that period "could also include the private lives of employees, their movements, place of residence, habits, contacts and other sensitive circumstances," a group of ANB officers states in a criminal complaint.
The SDT told CIN-CG that a case has been opened based on this criminal report and that an investigation is underway.
The letter to the Security and Defense Committee, which CIN-CG had access to, states that "it is particularly concerning that there is a feeling of constant surveillance, psychological pressure, insecurity and distrust among employees, which can lead to self-censorship, violation of professional autonomy and deterrence from internally reporting possible illegalities and abuses."
The complainants request the SDT to verify whether certain people in the ANB have committed criminal offenses of unauthorized collection and use of personal data, abuse of official position, and negligent performance of duties by establishing such a surveillance system. They request the AZLP to determine whether there has been a violation of the Law on Personal Data Protection, while they request the Committee to examine this issue within the jurisdiction of the Parliament of Montenegro.
The AZLP confirmed to CIN-CG that they have initiated proceedings in connection with this case, but that they cannot provide any more information at this stage.
"As the chairman of the Committee, I received a report from an ANB officer, I am aware of the case, but the Committee has not yet considered these issues," said Nikola Zirojević, chairman of the Committee for Security and Defense, in an interview with CIN-CG.
He added that the Committee would address these serious allegations.
CIN-CG journalists asked the ANB several questions about this case, but did not receive answers by the time the article was published.
How the system works
The system, as stated on the official website of the manufacturer “Hexnode”, allows setting up periodic location monitoring at intervals of 15 minutes to 24 hours, instant location reading through the “Scan Location” option and viewing the device’s location history. It also describes the functions of remote control and device monitoring, including the ability to view the device’s screen in real time.
The "Hexnode for work" application also has permanent access to the device's location, in the "allow all the time" mode, meaning it can access the location even when the application is not open, nor is the user actively using it.
The criminal complaint states that this option was administratively imposed, meaning that employees could not disable or limit it themselves.
The report included screenshots of official phones, showing that the application accessed the employee's location multiple times on the same day. In another case, the option "use precise location" is also visible, as well as the label "enabled by admin", which suggests that the settings were not under the control of the device user, but of a specific system administrator.
The application to the AZLP also states that the application has access to the camera, contacts, location, notifications, phone, and nearby devices.
“Hexnode for work,” according to documentation reviewed by CIN-CG, also has the ability to download files without displaying a notification to the user. This, as the criminal complaint points out, further indicates a high level of administrative control over employees' devices.
“Hexnode” makes historical data available to the administrator in easily readable formats, such as PDF or CSV (text-based spreadsheet format).
The complaint states that the employees only signed an internal document confirming that they were familiar with the rules for using the official phone. The document, they claim, states that employees are not allowed to install or delete applications on their own initiative, take the phone out of the country without ANB approval, or reset the device to factory settings without consent.
Violation of the principles of the Personal Data Protection Act?
In a complaint to the AZLP, a group of ANB employees are requesting that an investigation be initiated into whether there has been a violation of the provisions of the Personal Data Protection Act (the Act), "in particular the obligation to process personal data fairly and lawfully, for the purpose for which they were collected and to the extent necessary," as outlined in the Act.
"It is particularly noteworthy that, according to available information, employees were not clearly informed about the identity of the controller of the personal data collection, the purpose of processing, the legal basis, the data users, or the rights they have, although the Law prescribes the obligation of such information," the report to the AZLP states.
This law states that the controller of a personal data collection must, unless otherwise prescribed by a special law, "provide the person from whom he directly collects data with information about his personal name, or title and address, the purpose and legal basis for processing personal data, the user of personal data and the legal basis for providing data for use."
According to the Law, persons under surveillance must have the choice to consent to providing personal data and be informed of the possible consequences of refusing to provide such data, and must also have the right to access their data.
The controller of the personal data collection is obliged to provide technical, personnel and organizational protection measures, as well as automatic records of access, use and processing of data in the information system, which would imply detailed information to employees about the stored data.
The law stipulates that data that allows for the identification of a person can only be stored for as long as necessary for the purpose, but ANB officials claim that they have no knowledge of how and for what period of time their personal data is stored.
Violations of the Law also occur in cases where location surveillance is used to assess the behavior, reliability, performance at work, or other personal characteristics of employees, as it is prohibited to assess employees solely on the basis of automatic data processing.
The law also contains a limitation according to which, except for provisions relating to surveillance initiated under appropriate legal conditions, it does not apply to the processing of personal data for the purposes of defense and national security, unless otherwise prescribed by a special law.
"If the ANB claims that it is processing data for national security purposes, it is obliged to point to a special law, a precisely defined purpose, the scope of the applied measure and appropriate protective guarantees. If, on the other hand, it is a matter of internal organizational, disciplinary, personnel or other control of employees, then the regular rules of the Law relating to the lawfulness of processing, transparency, record-keeping, retention periods and the rights of the persons to whom the data relate apply," the applicants state.
MDM systems in the EU under strict rules, Montenegro still does not have a harmonized legal framework for personal data protection
Although security institutions have the right to protect their data, communications, and equipment, this does not mean that they can monitor employees in an uncontrolled and mass manner.
European standards in the field of privacy and personal data protection require that employee surveillance be clearly legally based, necessary, proportionate and transparent, and only undertaken in exceptional circumstances. This means that employees must know in advance that they are being monitored, why, who has access to their personal data, how long it is kept and what their rights are in this process.
In regulated countries of the European Union (EU), MDM systems are used, but under clear rules and within the framework of a developed European system of digital rights protection. They serve to protect official devices, install security updates, prevent unauthorized access to official data, find lost or stolen devices, and separate official from private content. However, their use does not mean that the employer has the right to unlimited insight into the movements, communications, or private life of the employee.
The General Data Protection Regulation (GDPR), which is directly applicable in EU member states, assumes that the processing of personal data must be lawful, transparent, limited to a clear purpose and limited to what is strictly necessary. In other words, an institution or employer cannot justify afterwards why they collected the location of employees, but before introducing such a system they must clearly explain what they are collecting, why they are doing it, how long they are keeping the data, who has access to it and whether the same objective can be achieved with a less stringent measure.
In addition to the GDPR, the EU has also adopted a broader package of digital regulations, including the Digital Services Act (DSA), which introduces higher standards of accountability, transparency and oversight in the digital space. Although the DSA primarily applies to online platforms and not directly to MDM systems, it demonstrates that in European law, digital technologies cannot function without clear control and accountability.
Unlike EU member states, Montenegro has not yet completed the legal framework for the protection of personal data and digital privacy according to European standards. The European Commission (EC) warned in its reports for 2024 and 2025 that the domestic Law on the Protection of Personal Data is not yet aligned with the EU acquis, while the rules for data processing in the police and security sector are still being aligned with the GDPR and the European Directive on the Processing of Data for Law Enforcement Purposes.
In March 2026, the EC, in connection with the amendments to the Law on Internal Affairs and the new Law on the National Security Agency, pointed out that the data protection provisions in these laws were not yet fully aligned with the EU acquis, in particular with the General Data Protection Regulation (GDPR) and the Law Enforcement Directive (LED), which regulates the processing of data for police and criminal justice purposes.
Although the Government of Montenegro adopted some amendments in February 2026 and announced harmonisation, stating that they were the result of consultations with the EC, the Ministry of Internal Affairs (MUP) only submitted the text of the new Law on Personal Data Protection to the EC for its opinion at the end of March 2026.
EU sees surveillance as a serious threat to privacy
The French Data Protection Agency, CNIL, is an independent government regulator that oversees how public institutions and private companies collect, store and use personal data, including employee data, GPS location, video surveillance, cookies and other digital systems. It is one of the most influential data protection authorities in the EU.
In its guidelines on the geolocation of employees' company vehicles, the CNIL states that such systems may only be used for specific and justified purposes, such as the safety of the employee, goods or vehicles, better organization of field work, monitoring working hours when this cannot be achieved by less invasive means, or finding a stolen vehicle. At the same time, the CNIL warns that geolocation must not become a means of constant control of the employee, especially outside working hours, and that employees must be able to exclude the collection or transmission of location data when they are not at work.
The practice of the CNIL also shows that such warnings are not declarative: in November 2023, the agency imposed ten sanctions on employers, including for illegal geolocation of company vehicles and video surveillance of employees. In these cases, the problem was not the use of the technology itself, but its disproportionate and excessive application in relation to the purpose for which it was introduced.
The Spanish Data Protection Agency also requires clear, explicit and prior information to employees about the existence and characteristics of GPS systems and their rights.
The Article 29 Working Party (WP 29), the former European independent advisory body on personal data protection, warned in a 2017 Opinion that modern technologies enable the monitoring of employees not only at the workplace but also in other places, including the home, with a high risk of non-transparent and disproportionate surveillance. The Opinion states that, due to the pronounced imbalance of power between employer and employee, the employee's consent should not constitute a valid legal basis for data processing.
The European Court of Human Rights (ECHR) has held in several cases that an employee does not lose their right to privacy even in the workplace. Surveillance must be limited, justified and subject to control, as there is a risk of abuse.
One of the most important examples is the case of “Barbulescu v. Romania”, in which the Grand Chamber of the ECtHR found a violation of the European Convention on Human Rights (the Convention) because the domestic courts had failed to sufficiently protect the privacy of an employee whose communications were being monitored by the employer. The judgment stressed that an employer, even when it has a legitimate interest in controlling the use of official means, must first clearly inform the employee of the possibility and scope of the monitoring, explain the reasons for such a measure, consider less intrusive alternatives and provide safeguards against abuse.
The judgment “Antović and Mirković v. Montenegro” is also important for Montenegro. In that case, the ECHR found that video surveillance in university amphitheaters, where professors were teaching, constituted an interference with their right to private life.
See more:
Download the app and follow the news
FOLLOW US ON