Technology

Sending Data Out of Montenegro: The Outsourcing Rule That Contractual Clauses May Not Solve

Article 41 permits, the nine Article 42 exemptions, the outsourcing carve-out, and why an EU parent still needs standard contractual clauses.

Rohat Kahraman· 25 August 2026Updated · 25 August 2026
Abstract cover for an article on transferring personal data into and out of Montenegro

Cross-border data flows into and out of Montenegro run on two separate bodies of law that do not reference each other. Data leaving Montenegro is governed by Articles 41 and 42 of the Zakon o zaštiti podataka o ličnosti. Data arriving from the European Union is governed by Chapter V of the GDPR, and Montenegro is not on the European Commission's adequacy list. Neither regime is optional, and a group that documents only one has documented half its exposure.

Inside the Montenegrin half there is one provision that behaves differently from everything around it. Article 41(3) singles out transfers made in order to entrust processing operations — outsourcing — and exempts them from the consent requirement in only one case, not nine. If your Montenegrin entity sends personal data to a processor abroad, that sentence is the one that decides your position, and it is not the sentence most compliance files are built on.

The default: a permit, assessed on five criteria

Article 41(1) is the general rule. Personal data being processed may be transferred out of Montenegro to another state, or made available to an international organisation that applies adequate protection measures, on the basis of the prior consent of the supervisory authority.

Article 41(2) sets out how adequacy is judged — on the concrete circumstances of the transfer, taking into account in particular: the nature of the personal data; the purpose and duration of the proposed processing; the state of origin and the state of final destination; the rules of law in force in the state to which the data are transferred; and the professional rules and security measures which must be observed in that country.

That is a case-by-case assessment of a specific transfer, not a standing finding about a country. There is no Montenegrin equivalent of an adequacy decision that a company can point to.

The nine exemptions from the permit

Article 42 lists nine cases in which the consent required by Article 41(1) is not needed. The wording of that opening line matters and we return to it below.

#Exemption from the Article 41(1) consent
1Transfer is prescribed by a special law or by an international treaty binding on Montenegro
2Prior consent of the data subject, who has been informed of the possible consequences of the transfer
3Transfer is necessary to perform a contract between a person and the controller, or to meet pre-contractual obligations
4Transfer is necessary to save the life of the data subject or is in their interest
5Transfer is made from registers or records that are publicly available under law or other regulation
6Transfer to EU or EEA member states, or to states on the EU list as having an adequate level of protection
7Transfer is necessary to realise a public interest, or to establish or protect the legal interests of the data subject
8The controller concludes a contract containing the contractual obligations accepted by EU member states with a processor in a non-EU state
9Transfer is necessary to conclude or perform a contract between the controller and a person, where the contract is in the data subject's interest

Two of these carry almost all corporate traffic. Exemption 6 is the destination test: EU, EEA, or an EU adequacy-listed state, and no permit is needed. Exemption 8 is the instrument test: the contractual obligations accepted by EU member states — in practice the European Commission's standard contractual clauses — concluded with a processor in a third country.

The provision that changes the answer for outsourcing

Now read Article 41(3), which provides that for the transfer of personal data for the purpose of entrusting particular processing operations, within the meaning of Article 16 of the Act, the consent of the supervisory authority is necessary, except in the case referred to in Article 42 point 6.

Three things follow from that sentence, and they are uncomfortable.

First, it applies precisely to outsourcing. Article 16 is the processor provision: a controller may entrust particular processing operations to a processor by a contract that must be in writing, governing the parties' rights and obligations and in particular the processor's duty to act on the controller's instructions; the work may be entrusted only to a processor that meets the conditions for implementing technical, staffing and organisational protection measures; and the processor must destroy or return the data after processing.

Second, the carve-out names one exemption, not the list. Article 42 opens by exempting transfers from "the consent under Article 41 paragraph 1" — so on the face of the text those nine exemptions answer the general rule in 41(1), while 41(3) sets its own, narrower carve-out for outsourcing transfers and admits only Article 42(6).

Third, and this is the practical sting: Article 42(8) — the standard contractual clauses route — is not among the exceptions listed in Article 41(3), even though Article 42(8) is itself written about a contract with a processor in a non-EU state. On a literal reading the two provisions point in opposite directions for exactly the same transaction: sending data to a processor in the United States, India or Serbia under SCCs.

We are not going to tell you this question is settled, because it is not. What we can say is what the text says and what the enforcement record shows. The supervisory authority issued three transfer consents in the whole of 2024 — a figure we set out with the rest of the Agency's numbers in our note on what a foreign company must file with the authority. Three consents is not consistent with a market that applies for a permit every time it uses a non-EU processor. It is consistent either with a market reading Article 42(8) as covering the case, or with a market that has not read Article 41(3) at all.

The workable response is not to pick a side and hope. It is to sort your outbound flows by destination and by role:

  • Processor in the EU or EEA, or in an adequacy-listed state. Covered by Article 41(3)'s own carve-out. No permit issue.
  • Processor in any other state. The literal reading requires the Agency's consent. Document the SCCs, document the Article 42(8) analysis, and take a considered decision on whether to file — recognising that a kontrolor reading Article 41(3) may reach a different conclusion, and that Article 71 lets the Agency prohibit the transfer outright.
  • Transfer to a controller rather than a processor. Article 41(3) does not apply; the ordinary Article 41(1) rule and the full Article 42 list do.

That last line is why the controller-or-processor characterisation of every counterparty matters more in Montenegro than it does under GDPR alone. It is not only about which contract you sign; it decides which permit rule applies.

There is a further trap in the same area. Article 74(1)(5) makes it a misdemeanour for a controller to entrust processing to a processor that is not registered for the activity of personal data processing, or that does not meet the conditions for technical, staffing and organisational protection measures. That registration requirement has no GDPR analogue, and it is worth resolving before a large offshore processing arrangement is signed rather than after.

Coming the other way: there is no adequacy decision

For data moving from an EU establishment to a Montenegrin one, the analysis is ordinary GDPR Chapter V — with the unhelpful feature that Montenegro is not among the jurisdictions the European Commission has recognised as adequate. Checked on 25 August 2026, that list is Andorra, Argentina, Brazil, Canada (commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States (organisations in the EU–US Data Privacy Framework), Uruguay, and the European Patent Organisation.

So an intra-group flow to a Montenegrin subsidiary is a third-country transfer requiring an Article 46 safeguard — in practice the standard contractual clauses under Article 46(2)(c), supported by a transfer impact assessment of Montenegrin law. The Article 49 derogations exist but are drafted for occasional and non-repetitive situations; they are not a basis for a standing payroll, CRM or ticketing flow.

The assessment cuts both ways once you have read the Montenegrin side. Some of what a transfer impact assessment looks for is present here — an independent supervisory authority with binding powers, a right to judicial review by administrative dispute, and a statutory damages route. Some of it is thinner than an EU reviewer expects, including the absence of a general breach-notification duty and a fine ceiling of €20,000. Say both, rather than producing an assessment that only recites the good half.

What Montenegro has actually signed

Montenegro's treaty position is a better guide to where this is heading than any commentary, and it is precise and public.

InstrumentMontenegro's position
Convention 108 (ETS 108)Signature and ratification 06/09/2005; in force for Montenegro 06/06/2006
Additional Protocol on supervisory authorities and transborder data flows (ETS 181)Signature 24/02/2009; ratification 03/03/2010; in force for Montenegro 01/07/2010
Convention 108+ (CETS 223), the modernised textNeither signed nor ratified

Montenegro is therefore inside the 1981 Council of Europe framework, including the protocol that specifically addresses transborder data flows, and outside the modernised convention that most European states have moved to. As at 25 August 2026 Convention 108+ has 34 ratifications or accessions and a further 12 signatures not followed by ratification, and Montenegro appears in neither column.

That is coherent with everything else on this page: a 2008 statute, a draft replacement that has sat unadopted since March 2024, and no EU adequacy decision. If you are modelling when a Montenegrin flow might become simpler, the signature of Convention 108+ and the adoption of the draft law are the two observable events to watch, and neither has happened.

Record what you relied on, before the data moves

Whatever route each flow takes, the paperwork obligation is the same and it runs ahead of the transfer, not after it. Article 26(2)(9) requires the details of transfers out of Montenegro — the destination state, international organisation or foreign recipient, and the purpose established by treaty, by law, or by the data subject's written consent — to appear in the filing-system record you notify to the Agency. Article 19 requires a separate register of every recipient given data, what was given, the purpose, the legal basis and the period of use, kept for ten years. And Article 18 obliges the recipient to delete the data once the period stated in the request has expired.

Those three records are what a supervision will actually examine, and they are cheap to keep and expensive to reconstruct.

Before your next data flow leaves the country

Map the flows once, and for each one record four things: who the counterparty is, whether it acts as controller or processor, which state it sits in, and which provision you are relying on — Article 41(3)'s carve-out, one of the nine Article 42 exemptions, or a permit. Then do the same in the inbound direction for anything your EU parent sends you.

If you are setting up or reviewing those flows, send us the data map, the processor contracts and your intra-group transfer agreements, and we will tell you which of them sit inside Article 41(3) and which need a decision taken deliberately rather than by default. This work sits in our data protection practice. The regime as a whole is set out in our note on why Montenegro is not a GDPR country, and the filing mechanics in what a foreign company must actually file. Where the flows sit inside SaaS or outsourcing contracts, see our IT and technology practice and our AI practice; if the entity is still being formed, start with company formation in Montenegro; and regulated financial entities carry a separate ICT resilience layer covered in our note on Montenegro's payment services regime.

Statutory references are to the consolidated Zakon o zaštiti podataka o ličnosti (Sl. list CG 079/08, 070/09, 044/12, 022/17, 077/24 of 5 August 2024). Treaty status is from the Council of Europe Treaty Office and the adequacy list from the European Commission, both read on 25 August 2026. The operative text of ETS 181 was not retrievable through automated access, so this page states only Montenegro's ratification position and does not paraphrase the protocol's provisions — read the protocol directly before relying on it. The translation of Article 41(3) is ours. General information on Montenegrin and EU law, not advice on a specific transfer.

Frequently asked questions

Do we need permission to send personal data out of Montenegro?

As a default, yes. Article 41(1) makes transfer abroad subject to the prior consent of the supervisory authority, and Article 41(2) has adequacy assessed case by case on the nature of the data, the purpose and duration, the state of origin and final destination, the rules of law in force there, and the professional rules and security measures observed in that country. Article 42 then lists nine situations in which that consent is not required, and most corporate flows sit inside one of them.

Which of the nine exemptions actually get used?

Two carry most traffic. Article 42(6) exempts transfers to EU and EEA member states and to states on the EU list as having an adequate level of protection — a destination test. Article 42(8) exempts a contract containing the contractual obligations accepted by EU member states, in practice the European Commission's standard contractual clauses, concluded with a processor in a non-EU state — an instrument test. The others cover consent, contract necessity, vital interests, public registers, public interest and legal claims.

What is different about sending data to a processor?

Article 41(3) treats it separately. It provides that for transfers made in order to entrust particular processing operations within the meaning of Article 16, the supervisory authority's consent is necessary, except in the case referred to in Article 42 point 6. So for outsourcing, the text carves out one exemption — the EU, EEA and adequacy-list destinations — rather than the whole Article 42 list.

Does that mean standard contractual clauses do not work for outsourcing from Montenegro?

That is the open question, and we will not pretend it is resolved. Article 42 exempts transfers from the consent "under Article 41 paragraph 1", while Article 41(3) states its own narrower carve-out naming only Article 42(6) — so on a literal reading the SCC exemption in Article 42(8) does not answer Article 41(3), even though Article 42(8) is itself about a contract with a processor in a non-EU state. The enforcement record does not settle it either: the Agency issued only three transfer consents in the whole of 2024. Treat it as a decision to take deliberately, with the SCCs and the Article 42(8) analysis documented, rather than as a question that has an obvious answer.

Does it matter whether our counterparty is a controller or a processor?

More than it does under GDPR alone. Article 41(3) is triggered by the transfer being made in order to entrust processing operations. If the recipient takes the data as a controller in its own right, Article 41(3) does not apply and the ordinary Article 41(1) rule with the full Article 42 list governs. The characterisation therefore decides which permit rule you are in, not just which contract you sign.

Is there anything else about using a foreign processor?

Yes, and it is easy to miss. Article 74(1)(5) makes it a misdemeanour for a controller to entrust processing to a processor that is not registered for the activity of personal data processing, or that does not meet the conditions for implementing technical, staffing and organisational protection measures. There is no GDPR equivalent of that registration requirement, so it is worth resolving before a large offshore processing arrangement is signed.

What does the Article 16 processor contract have to contain?

It must be in writing, and it must govern the mutual rights and obligations of controller and processor, in particular the processor's obligation to act on the controller's instructions. Processing may be entrusted only to a processor that meets the conditions for technical, staffing and organisational protection measures. And the processor must destroy the data after processing or return it to the controller.

Can our EU parent send data to the Montenegrin subsidiary?

Only with a GDPR Chapter V safeguard, because Montenegro is not on the European Commission's adequacy list. In practice that means the standard contractual clauses under Article 46(2)(c), supported by a transfer impact assessment of Montenegrin law. The Article 49 derogations are drafted for occasional and non-repetitive transfers and are not a basis for a standing payroll, CRM or ticketing flow.

What should a transfer impact assessment on Montenegro actually say?

Both halves. On the supportive side, Montenegro has an independent supervisory authority with binding powers under Article 71, judicial review of its decisions by administrative dispute under Article 72, and a statutory damages route under Article 48. On the other side, the Act contains no general personal data breach notification duty, and the maximum fine for a legal person under Article 74 is €20,000. An assessment that recites only the first half will not survive review.

Is Montenegro party to Convention 108?

Yes. Convention 108 (ETS No. 108) entered into force for Montenegro on 06/06/2006, following signature and ratification recorded on 06/09/2005. Montenegro also ratified the Additional Protocol regarding supervisory authorities and transborder data flows (ETS No. 181) on 03/03/2010, in force for Montenegro from 01/07/2010.

Has Montenegro signed Convention 108+?

No. As at 25 August 2026 the Council of Europe Treaty Office records Montenegro with no signature, no ratification and no entry into force for the modernised convention (CETS No. 223), which by then had 34 ratifications or accessions and a further 12 signatures not followed by ratification. Montenegro is therefore inside the 1981 framework and outside the modernised one.

Is an EU adequacy decision for Montenegro likely soon?

We will not predict one. What we can point to are the two observable events that would normally precede it: the adoption of the draft data protection law that the Ministry of Internal Affairs published on 8 March 2024 and which remains unadopted, and Montenegro's accession to Convention 108+. As at 25 August 2026 neither has happened.

What do we have to record about our transfers?

Three things, all of which run ahead of the transfer. Article 26(2)(9) requires the transfer details — the destination state, international organisation or foreign recipient, and the purpose as established by treaty, by law or by the data subject's written consent — to appear in the filing-system record you notify to the supervisory authority. Article 19 requires a separate register of every recipient given data, what was given, the purpose, the legal basis and the period of use, kept for ten years. And Article 18 obliges the recipient to delete the data once the period stated in the request has expired.

Can the Agency stop a transfer that is already running?

Yes. Article 71 lets it order irregularities remedied within a deadline, temporarily prohibit unlawful processing, order deletion of data collected without legal basis, and specifically prohibit the transfer of personal data out of Montenegro or their disclosure to recipients contrary to the Act. For an operating business, a prohibition on an established data flow is usually a larger event than the fine.

Where does consent from the individual fit?

Article 42(2) exempts a transfer where the data subject has given prior consent and has been informed of the possible consequences of the transfer. Note the second limb: consent alone is not enough, the person must have been told what the transfer may mean for them. It is a workable route for occasional transfers and a fragile one for systematic flows, since consent under Article 9(6) must be given in writing or orally on the record, and can be withdrawn at any time under Article 10.