The case of illegal disclosure of personal data of thousands of public officials and persons connected with them outside the borders of Montenegro represents a new compromise of the Agency for the Prevention of Corruption (ASK), although they should represent an example of compliance with laws and regulations in society.
This is what the director of the Research Center of the Network for the Affirmation of the Non-Governmental Sector (MANS) told "Vijesta". Dejan Milovac, pointing out that almost a quarter of a million was paid to a company from Serbia in the previous six years, and that it has now turned out to be a violation of the Law on the Protection of Personal Data, as a result of which the state budget may suffer, if the officials and their family members decide to they are suing ASK.
The Council of the Agency for the Protection of Personal Data and Free Access to Information (AZLP) recently made a decision that the ASK violates the Personal Data Protection Act, because information about public officials and members of their households was disclosed and processed outside of Montenegro.
The initiative to initiate proceedings before the AZLP was submitted by MANS back in April of this year.
According to the decision of the Council of the Agency, ASK entrusted these tasks to the Novi Sad company "Prozone", contrary to the Personal Data Protection Act, which is why the institution, headed by Jelena Perović, forbidden to do so. ASK should submit proof of this to AZLP, no later than the end of December.
"In the last six years, according to the available data on public procurement, ASK concluded several contracts with the Novi Sad company 'Prozone', which had access to personal data, worth around 250.000 euros," specified Milovac in a statement to "Vijesti".
AZLP sought and received the help of colleagues from Serbia and established illegalities
According to the documents that "Vijesti" had access to, the AZLP, on the initiative of MANS, has been determining since April whether ASK is violating the Personal Data Protection Act.
That's what they're for, according to the controller's minutes Ljiljane Brajović i Mladen Prelević, from AZLP also asked for the help of their colleagues from the Republic of Serbia.
"In order to undisputedly establish the factual situation in part of the oral and written allegations that 'Prozone', when monitoring the functioning of the system, accesses data that are not personal data of the officials of the Agency for the Prevention of Corruption or third parties, and due to the fact that the headquarters of 'Prozone' doo is located outside On April 20, 4, the Agency of Montenegro sent a request to the Commissioner for Information of Public Importance and Protection of Personal Data, as the competent supervisory body for the protection of personal data in the Republic of Serbia, to carry out supervision in the 'Prozone'", according to the minutes of the AZLP controller. -a.
The control established that from the collected material "... two facts clearly and unequivocally emerge: that the subject of supervision, as the handler of personal data collections, entrusted the business company 'Prozone', to carry out tasks related to the processing of personal data, i.e. conducting inspections ( availability) in them, revealing through transfer from its scope which business company in the specific case has the status of a processor in terms of the Personal Data Protection Act, as well as that the processor has its seat outside the territory of Montenegro, in the Republic of Serbia".
"That authorized persons from 'Prozone' i Mina Krstić (authorized person according to the statements of 'Prozone' from the Minutes of the inspection carried out by the commissioner), as users of the information system (IS) of the subject of supervision, in accordance with the contracts in question, have VPN access to the ASK application from the ASK information system, which was established on the basis of the law the competence of this subject of supervision, and to process the personal data of public officials and members of the family household, in the way that they were disclosed to them through transmission, or to have access to personal and other related data related to this category of persons, namely: name and surname, unique identity number, place of residence, i.e. place of residence and residential address, educational background and title, and for public officials, the name of father and mother, mother's maiden name and contact telephone number, as well as data related to the public function performed, membership in working bodies, management and supervisory bodies of companies, public institutions and other legal entities, data on the assets and income of officials and members of a joint household, i.e. all data reported in accordance with the Law on Prevention of Corruption, as well as data on political subjects (proof: Record of the performed inspection supervision made by the Commissioner from 1 July 7, notification of the authorized controller of the Commissioner from 2022 August 5...)", it is stated in the minutes of the controller.
KAS filed an objection to that record on October 3, stating, among other things, that the AZLP controllers ignored "the relevant fact that the Ministry of Justice of Montenegro and the Anti-Corruption Agency of the Republic of Serbia signed the Protocol on the Assignment of Source Code" in 2015. ” in order to establish the KAS information system, and that the protocol represents an international bilateral agreement based on the principles of the United Nations Convention on International and Regional Cooperation in the Field of Prevention and Fight Against Corruption.
Also, according to the decision of the AZLP Council, they also state that UNDP provided logistical support for the implementation of the protocol, and that as part of the support, it hired a company from Novi Sad, which was the author of the software solution for the needs of the Anti-Corruption Agency of Serbia. They claim that because of all this, KAS had no obligation to obtain the opinion of AZLP, and they also point out that the controllers did not review the signed Protocol, which would have properly established the factual situation...
According to "Vijesti" information, the AZLP Council considered the complete material related to ASK in at least two sessions from the beginning of October to December 22. The Council of AZLP rejected the complaint of ASK and stood by the position of its controllers. ASK is prohibited from entrusting the processing and presentation of personal data from the information system to the Novi Sad company "Prozone", contrary to the law.
Milovac: Mass violation of the law can be costly
Milovac points out that AZLP, in the control procedure, confirmed the suspicions of MANS that the authorities in KAS, contrary to the law, provided unimpeded access to the personal data of thousands of Montenegrin public officials, their spouses and children, and other related persons.
"In this particular case, it is a massive violation of the Law on the Protection of Personal Data and it can potentially expose the KAS, that is, the state budget, to lawsuits from those whose data were taken outside the borders of Montenegro without authorization," warns Milovac.
According to him, MANS has previously warned that the director Jelena Perović and the Council of the ASK are not able to ensure the legal conduct of that institution, and the latest example of violation of the Personal Data Protection Act once again calls into question its credibility.
"Unfortunately, even so far we have had the opportunity to see that the sense of personal and professional responsibility does not reside in the address of director Perović or any member of the Council who until now silently supported all the violations of the law that we witnessed in previous years. There is no doubt that the changes in this institution must be radical and result in personnel solutions that would ensure full compliance with laws and regulations, Milovac concluded.
See more:
Download the app and follow the news
FOLLOW US ON