Cross-border data flows into and out of Montenegro run on two separate bodies of law that do not reference each other. Data leaving Montenegro is governed by Articles 41 and 42 of the Zakon o zaštiti podataka o ličnosti. Data arriving from the European Union is governed by Chapter V of the GDPR, and Montenegro is not on the European Commission's adequacy list. Neither regime is optional, and a group that documents only one has documented half its exposure.
Inside the Montenegrin half there is one provision that behaves differently from everything around it. Article 41(3) singles out transfers made in order to entrust processing operations — outsourcing — and exempts them from the consent requirement in only one case, not nine. If your Montenegrin entity sends personal data to a processor abroad, that sentence is the one that decides your position, and it is not the sentence most compliance files are built on.
The default: a permit, assessed on five criteria
Article 41(1) is the general rule. Personal data being processed may be transferred out of Montenegro to another state, or made available to an international organisation that applies adequate protection measures, on the basis of the prior consent of the supervisory authority.
Article 41(2) sets out how adequacy is judged — on the concrete circumstances of the transfer, taking into account in particular: the nature of the personal data; the purpose and duration of the proposed processing; the state of origin and the state of final destination; the rules of law in force in the state to which the data are transferred; and the professional rules and security measures which must be observed in that country.
That is a case-by-case assessment of a specific transfer, not a standing finding about a country. There is no Montenegrin equivalent of an adequacy decision that a company can point to.
The nine exemptions from the permit
Article 42 lists nine cases in which the consent required by Article 41(1) is not needed. The wording of that opening line matters and we return to it below.
| # | Exemption from the Article 41(1) consent |
|---|---|
| 1 | Transfer is prescribed by a special law or by an international treaty binding on Montenegro |
| 2 | Prior consent of the data subject, who has been informed of the possible consequences of the transfer |
| 3 | Transfer is necessary to perform a contract between a person and the controller, or to meet pre-contractual obligations |
| 4 | Transfer is necessary to save the life of the data subject or is in their interest |
| 5 | Transfer is made from registers or records that are publicly available under law or other regulation |
| 6 | Transfer to EU or EEA member states, or to states on the EU list as having an adequate level of protection |
| 7 | Transfer is necessary to realise a public interest, or to establish or protect the legal interests of the data subject |
| 8 | The controller concludes a contract containing the contractual obligations accepted by EU member states with a processor in a non-EU state |
| 9 | Transfer is necessary to conclude or perform a contract between the controller and a person, where the contract is in the data subject's interest |
Two of these carry almost all corporate traffic. Exemption 6 is the destination test: EU, EEA, or an EU adequacy-listed state, and no permit is needed. Exemption 8 is the instrument test: the contractual obligations accepted by EU member states — in practice the European Commission's standard contractual clauses — concluded with a processor in a third country.
The provision that changes the answer for outsourcing
Now read Article 41(3), which provides that for the transfer of personal data for the purpose of entrusting particular processing operations, within the meaning of Article 16 of the Act, the consent of the supervisory authority is necessary, except in the case referred to in Article 42 point 6.
Three things follow from that sentence, and they are uncomfortable.
First, it applies precisely to outsourcing. Article 16 is the processor provision: a controller may entrust particular processing operations to a processor by a contract that must be in writing, governing the parties' rights and obligations and in particular the processor's duty to act on the controller's instructions; the work may be entrusted only to a processor that meets the conditions for implementing technical, staffing and organisational protection measures; and the processor must destroy or return the data after processing.
Second, the carve-out names one exemption, not the list. Article 42 opens by exempting transfers from "the consent under Article 41 paragraph 1" — so on the face of the text those nine exemptions answer the general rule in 41(1), while 41(3) sets its own, narrower carve-out for outsourcing transfers and admits only Article 42(6).
Third, and this is the practical sting: Article 42(8) — the standard contractual clauses route — is not among the exceptions listed in Article 41(3), even though Article 42(8) is itself written about a contract with a processor in a non-EU state. On a literal reading the two provisions point in opposite directions for exactly the same transaction: sending data to a processor in the United States, India or Serbia under SCCs.
We are not going to tell you this question is settled, because it is not. What we can say is what the text says and what the enforcement record shows. The supervisory authority issued three transfer consents in the whole of 2024 — a figure we set out with the rest of the Agency's numbers in our note on what a foreign company must file with the authority. Three consents is not consistent with a market that applies for a permit every time it uses a non-EU processor. It is consistent either with a market reading Article 42(8) as covering the case, or with a market that has not read Article 41(3) at all.
The workable response is not to pick a side and hope. It is to sort your outbound flows by destination and by role:
- Processor in the EU or EEA, or in an adequacy-listed state. Covered by Article 41(3)'s own carve-out. No permit issue.
- Processor in any other state. The literal reading requires the Agency's consent. Document the SCCs, document the Article 42(8) analysis, and take a considered decision on whether to file — recognising that a kontrolor reading Article 41(3) may reach a different conclusion, and that Article 71 lets the Agency prohibit the transfer outright.
- Transfer to a controller rather than a processor. Article 41(3) does not apply; the ordinary Article 41(1) rule and the full Article 42 list do.
That last line is why the controller-or-processor characterisation of every counterparty matters more in Montenegro than it does under GDPR alone. It is not only about which contract you sign; it decides which permit rule applies.
There is a further trap in the same area. Article 74(1)(5) makes it a misdemeanour for a controller to entrust processing to a processor that is not registered for the activity of personal data processing, or that does not meet the conditions for technical, staffing and organisational protection measures. That registration requirement has no GDPR analogue, and it is worth resolving before a large offshore processing arrangement is signed rather than after.
Coming the other way: there is no adequacy decision
For data moving from an EU establishment to a Montenegrin one, the analysis is ordinary GDPR Chapter V — with the unhelpful feature that Montenegro is not among the jurisdictions the European Commission has recognised as adequate. Checked on 25 August 2026, that list is Andorra, Argentina, Brazil, Canada (commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States (organisations in the EU–US Data Privacy Framework), Uruguay, and the European Patent Organisation.
So an intra-group flow to a Montenegrin subsidiary is a third-country transfer requiring an Article 46 safeguard — in practice the standard contractual clauses under Article 46(2)(c), supported by a transfer impact assessment of Montenegrin law. The Article 49 derogations exist but are drafted for occasional and non-repetitive situations; they are not a basis for a standing payroll, CRM or ticketing flow.
The assessment cuts both ways once you have read the Montenegrin side. Some of what a transfer impact assessment looks for is present here — an independent supervisory authority with binding powers, a right to judicial review by administrative dispute, and a statutory damages route. Some of it is thinner than an EU reviewer expects, including the absence of a general breach-notification duty and a fine ceiling of €20,000. Say both, rather than producing an assessment that only recites the good half.
What Montenegro has actually signed
Montenegro's treaty position is a better guide to where this is heading than any commentary, and it is precise and public.
| Instrument | Montenegro's position |
|---|---|
| Convention 108 (ETS 108) | Signature and ratification 06/09/2005; in force for Montenegro 06/06/2006 |
| Additional Protocol on supervisory authorities and transborder data flows (ETS 181) | Signature 24/02/2009; ratification 03/03/2010; in force for Montenegro 01/07/2010 |
| Convention 108+ (CETS 223), the modernised text | Neither signed nor ratified |
Montenegro is therefore inside the 1981 Council of Europe framework, including the protocol that specifically addresses transborder data flows, and outside the modernised convention that most European states have moved to. As at 25 August 2026 Convention 108+ has 34 ratifications or accessions and a further 12 signatures not followed by ratification, and Montenegro appears in neither column.
That is coherent with everything else on this page: a 2008 statute, a draft replacement that has sat unadopted since March 2024, and no EU adequacy decision. If you are modelling when a Montenegrin flow might become simpler, the signature of Convention 108+ and the adoption of the draft law are the two observable events to watch, and neither has happened.
Record what you relied on, before the data moves
Whatever route each flow takes, the paperwork obligation is the same and it runs ahead of the transfer, not after it. Article 26(2)(9) requires the details of transfers out of Montenegro — the destination state, international organisation or foreign recipient, and the purpose established by treaty, by law, or by the data subject's written consent — to appear in the filing-system record you notify to the Agency. Article 19 requires a separate register of every recipient given data, what was given, the purpose, the legal basis and the period of use, kept for ten years. And Article 18 obliges the recipient to delete the data once the period stated in the request has expired.
Those three records are what a supervision will actually examine, and they are cheap to keep and expensive to reconstruct.
Before your next data flow leaves the country
Map the flows once, and for each one record four things: who the counterparty is, whether it acts as controller or processor, which state it sits in, and which provision you are relying on — Article 41(3)'s carve-out, one of the nine Article 42 exemptions, or a permit. Then do the same in the inbound direction for anything your EU parent sends you.
If you are setting up or reviewing those flows, send us the data map, the processor contracts and your intra-group transfer agreements, and we will tell you which of them sit inside Article 41(3) and which need a decision taken deliberately rather than by default. This work sits in our data protection practice. The regime as a whole is set out in our note on why Montenegro is not a GDPR country, and the filing mechanics in what a foreign company must actually file. Where the flows sit inside SaaS or outsourcing contracts, see our IT and technology practice and our AI practice; if the entity is still being formed, start with company formation in Montenegro; and regulated financial entities carry a separate ICT resilience layer covered in our note on Montenegro's payment services regime.
Statutory references are to the consolidated Zakon o zaštiti podataka o ličnosti (Sl. list CG 079/08, 070/09, 044/12, 022/17, 077/24 of 5 August 2024). Treaty status is from the Council of Europe Treaty Office and the adequacy list from the European Commission, both read on 25 August 2026. The operative text of ETS 181 was not retrievable through automated access, so this page states only Montenegro's ratification position and does not paraphrase the protocol's provisions — read the protocol directly before relying on it. The translation of Article 41(3) is ours. General information on Montenegrin and EU law, not advice on a specific transfer.




