Technology

Montenegro Is Not a GDPR Country — and the Law That Actually Binds Your Local Entity Is From 2008

GDPR is not Montenegrin law. The 2008 Data Protection Act still requires filing-system registration, prior permits and a €20,000 fine ceiling.

Rohat Kahraman· 25 August 2026Updated · 25 August 2026
Abstract cover for an article on Montenegro's 2008 personal data protection act and its divergence from GDPR

Most foreign companies that open something in Montenegro — a subsidiary, a development office, a hotel, a payroll of ten — carry their GDPR file across the border and assume it does the job. That assumption is wrong in two directions at once.

It is wrong downward, because the General Data Protection Regulation is not Montenegrin law and the Montenegrin supervisory authority does not enforce it. The statute that binds your local entity is the Zakon o zaštiti podataka o ličnosti, Službeni list Crne Gore nos. 079/08, 070/09, 044/12, 022/17 and 077/24 of 5 August 2024 — a 2008 law built on the pre-GDPR European model, with a maximum corporate fine of €20,000. It asks for things GDPR abolished, and it does not ask for several things your GDPR programme is built around.

And it is wrong upward, because GDPR can still reach you under its own Article 3(2), and because Montenegro is not on the European Commission's adequacy list — so your EU parent cannot send personal data to its Montenegrin subsidiary the way it sends data to Dublin.

You are not in one regime. You are in two, and they ask different questions.

What is actually in force, checked today

A replacement was drafted: the Ministry of Internal Affairs published a Nacrt zakona o zaštiti podataka o ličnosti on 8 March 2024, intended to transpose GDPR. As at 25 August 2026 it has not been adopted, and the supervisory authority's own list of applicable regulations still names the existing Act with no successor. That list is maintained — it already carries the new Freedom of Information Act (Sl. list CG 160/25 of 30 December 2025) — so the absence of a new data protection act is a fact about the law, not about the website.

Note the sequence: the draft appeared in March 2024, and five months later Montenegro amended the old law instead (077/24, 5 August 2024). We have not sourced the amending act's text and attribute no specific change to it — but the direction of travel is amendment, not replacement.

The supervisory authority is the body Article 49 establishes as the Agencija za zaštitu ličnih podataka, independent and with legal personality, now operating as the Agencija za zaštitu ličnih podataka i slobodan pristup informacijama (AZLP) — a combined data protection and freedom of information regulator, a structure the EU model does not use. Its powers are listed in Article 50, including giving consent to the establishment of filing systems (Art. 50(4)).

The divergences that cost money

QuestionGDPRZakon o zaštiti podataka o ličnosti
Maximum corporate fine€20m or 4% of global turnover€500 to €20,000 (Art. 74)
Register your processing with the regulatorAbolished; internal records onlyRequired before you start (Art. 26–27)
Prior regulator approval for risky processingNo — self-assessed DPIAYes, prior consent for listed categories (Art. 28)
Data protection officerRisk and scale basedRequired, except under 10 processing staff (Art. 27(3))
Breach notification to the regulator72 hoursNo general duty in the Act
Direct marketingConsent-led in practiceOpt-out, unless special categories (Art. 15)
ConsentAny clear affirmative actIn writing, or orally on the record (Art. 9(6))
Sending data abroadAdequacy, SCCs, BCRs — no permitPrior consent of the authority, with exemptions (Art. 41–42)
Genetic and biometric data as special categoriesYesNot in the Art. 9(7) list; biometrics regulated separately
Criminal-record dataPermitted under law, with safeguardsOnly by or under the supervision of a state authority (Art. 14)

The low fine ceiling is the part everyone notices and the least important line in the table. The obligations in the middle matter more: your GDPR programme has no equivalent of them, so you cannot comply by doing more of what you already do.

One line runs the opposite way and catches employers directly. Article 14 allows processing relating to criminal offences, imposed criminal and misdemeanour penalties or security measures only by, or under the supervision of, the competent state authority, with safeguards. GDPR Article 10 permits it where authorised by Union or Member State law with appropriate safeguards; Montenegro's rule is narrower. An employer running criminal background screening as group policy should settle its footing under Article 14 before collecting the first certificate.

The obligation GDPR abolished and Montenegro kept

Under Article 27(1), a controller must notify the supervisory authority before establishing an automated personal data filing system, and again on any significant change in the processing — with the full content listed in Article 26(2): filing system name, legal basis, controller identity, purpose, categories of data subjects, types of data, retention period, recipients, any transfers out of Montenegro, and the controller's internal processing and security rules.

This is the regime GDPR swept away in favour of internal record-keeping. In Montenegro it is live infrastructure: AZLP operates a searchable Registar zbirki ličnih podataka inside its information system. Failing to notify before establishing the filing system is a misdemeanour under Article 74(1)(9).

Article 27(3) then requires the controller to designate a person responsible for data protection once the automated filing system is established — with a bright-line exemption for controllers having fewer than 10 staff who process personal data. That is a headcount test, not GDPR's risk-and-scale test, and it cuts both ways: a twelve-person office doing mundane processing needs the appointment, a five-person office doing sensitive work does not.

Article 28 goes further and requires prior consent from the authority before automated processing presenting a special risk, naming in particular: special categories of data; data relating to the assessment of personality, ability or behaviour; video surveillance of public areas; and biometric data. Article 28(2) carves out processing carried out on the basis of a law, with the data subject's consent, or as necessary to perform a contract with the data subject. That exemption absorbs a great deal of ordinary commercial processing, and it is the first thing to test before assuming you need a permit.

That this is administered rather than theoretical is not an inference: on 24 July 2026 AZLP ran a workshop with the EU Delegation for municipal police from every municipality, specifically on the documentation to be filed with the Agency before establishing public-area video surveillance.

The workplace rules a foreign employer breaks in the first week

Entrance video surveillance (Article 35). Permitted for the safety of people and property, access control, or where the nature of the work creates risk to employees. The decision must be in writing and state its reasons (Art. 35(2)–(3)), and employees in the monitored area must be informed in writing (Art. 35(5)). Then Article 35(6): access to that footage through internal or public cable television, the internet, or other electronic communications means is prohibited — at the moment of recording or afterwards. A cloud camera at the office door that head office can pull up on a phone is not a grey area under this provision.

Workplace video surveillance (Article 36). Permitted only where required to protect people, property, classified information or trade secrets, and only where the objective cannot be achieved another way (Art. 36(1)). Prohibited outright outside the workplace — the Act names changing rooms, lifts, sanitary facilities and areas intended for clients and visitors (Art. 36(2)). Before deciding to introduce it the employer must obtain the opinion of the representative trade union or the employees' representative (Art. 36(4)), and employees must be informed in writing before it starts (Art. 36(5)).

Signage (Article 39). The public notice must be displayed before surveillance begins and must state the title of the person carrying out the surveillance and a telephone number on which one can find out where the footage is kept and for how long. A generic "CCTV in operation" sticker does not satisfy Article 39(3).

What a visitor may be asked for is itemised in Article 33(3): name, type and number of identification document, residence, address, employment.

Biometrics. Article 28(1)(3) puts biometric processing into the prior-consent regime. The Act's dedicated provision on biometric entry and attendance systems, Article 32, is written for the public sector and bodies exercising public authority, and requires the measure to be prescribed by law. For a private employer the position rests on Article 31 read with Article 28 rather than on a provision written for that case — which is why a fingerprint time-clock is a question to settle before installation.

Most carry misdemeanour liability directly — Article 74(1)(10) to (17) enumerate the video surveillance breaches. And under Article 40a, public-area surveillance run without the Article 27 notification or the Article 28 consent is met with an order to physically remove the equipment.

The clocks and ceilings, in one place

ObligationLimitSource
Answer a request for an information notice15 daysArt. 43(1)
Complete, correct or erase data on request15 daysArt. 44(1)
Tell the person and recipients what you changed8 daysArt. 44(2)
Keep video surveillance footage6 months maximumArt. 37(3)
Keep entry and exit records1 year maximumArt. 34(4)
Keep the record of third-party disclosures10 years, then deleteArt. 19(2)
Appoint a person responsible for data protectionRequired unless under 10 processing staffArt. 27(3)
Corporate fine range€500 to €20,000Art. 74(1)

Article 19 deserves a second look: a register of every recipient given personal data, what was given, the purpose, the legal basis and the period of use — kept for ten years. Most groups do not hold a record in that form. Failing to keep it is a misdemeanour under Article 74(1)(6).

Moving data across the border, in both directions

Out of Montenegro. Article 41 makes transfer abroad subject to the prior consent of the supervisory authority, assessed against the nature of the data, the purpose and duration, the countries of origin and destination, and the rules in force there.

Article 42 lists nine exemptions. The two carrying most commercial traffic are Article 42(6) — transfers to EU and EEA member states, or to states on the EU's adequacy list — and Article 42(8), a contract containing the contractual obligations accepted by EU member states, concluded with a processor in a non-EU state. In plain terms: Montenegro to the EU is free; to a third country on standard contractual clauses, free; to a third country on nothing, a permit application.

Into Montenegro. Here most GDPR programmes have a gap. Montenegro is not among the jurisdictions the European Commission has recognised as adequate. Checked on 25 August 2026, that list runs: Andorra, Argentina, Brazil, Canada (commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States (organisations in the EU–US Data Privacy Framework), Uruguay, and the European Patent Organisation. Montenegro is not on it.

So an EU parent sending employee, customer or supplier data to its Montenegrin subsidiary is making a third-country transfer and needs an Article 46 safeguard — in practice standard contractual clauses plus a transfer impact assessment. Intra-group flows into a Montenegrin entity are the most common thing we see left undocumented.

When GDPR reaches you anyway

None of this makes GDPR irrelevant to a Montenegrin company. Article 3(2) of Regulation (EU) 2016/679 applies the Regulation to controllers and processors not established in the Union where the processing relates to offering goods or services to data subjects in the Union, or to monitoring their behaviour in the Union. A Podgorica software company selling to EU customers, or a hotel marketing to and tracking EU visitors, is inside GDPR on its own terms — and Article 27 then generally requires a representative in the Union.

So: an entity serving only the domestic market is governed by the 2008 Act alone; an entity inside an EU group, or selling into the EU, is governed by both — and the work is not "apply GDPR and you are covered", because GDPR contains no Article 27 notification, no Article 28 permit, no Article 36 union consultation, and no Article 35(6) prohibition on remote access to entrance footage.

Regulated financial entities carry a third layer: Montenegro transposed the EU's digital operational resilience regime separately, in the Zakon o digitalnoj operativnoj otpornosti finansijskog sektora (Sl. list CG 014/26 of 9 February 2026), reaching credit institutions, payment institutions, e-money institutions and crypto-asset service providers — set out in our note on Montenegro's payment services regime.

Before your Montenegrin entity starts processing

The pattern is consistent and avoidable. A group rolls out its GDPR templates, appoints a DPO on GDPR criteria, keeps an internal processing register, signs its standard data processing agreements and installs the cameras it uses everywhere else — and has, in Montenegrin terms, filed nothing with AZLP, taken no union opinion, put up the wrong signage, kept footage too long, and given head office remote access the Act prohibits. A GDPR audit catches none of it, because a GDPR audit does not look for it.

Map the processing once, then run it against both regimes: what must be notified under Article 27, what needs an Article 28 permit or falls inside the Article 28(2) carve-out, what the surveillance decisions and notices must say, how your retention periods sit against the ceilings above, and how data reaches you from the EU parent. Send us your processing map, your camera plan and your intra-group agreements before the office opens, and we will tell you which regime each item lands in. This work sits in our data protection practice, alongside IT and technology contracts and AI.

If the entity is still being built, start with company formation in Montenegro; if you are hiring, the employment-side duties sit beside these in our employer labour law and payroll guide and the work permit guide for employers, with the hiring chain covered by our recruitment and work permit practice.

Statutory references are to the consolidated Zakon o zaštiti podataka o ličnosti (Sl. list CG 079/08, 070/09, 044/12, 022/17, 077/24 of 5 August 2024). The draft replacement law, AZLP's list of applicable regulations, its filing-system register and its 24 July 2026 announcement, and the European Commission's adequacy list were read on 25 August 2026. General information on Montenegrin and EU law, not advice on a specific processing operation.

Frequently asked questions

Does GDPR apply in Montenegro?

Not as domestic law. Montenegro is not an EU or EEA member, and the Montenegrin supervisory authority enforces the Zakon o zaštiti podataka o ličnosti (Sl. list CG 079/08, 070/09, 044/12, 022/17, 077/24 of 5 August 2024), not the Regulation. GDPR can still reach a Montenegrin company directly under its own Article 3(2) where the company offers goods or services to people in the EU or monitors their behaviour there, and Article 27 then generally requires a representative in the Union. The practical answer for most groups is that both regimes apply to different parts of the same operation.

Has Montenegro adopted a GDPR-aligned law yet?

Not as at 25 August 2026. The Ministry of Internal Affairs published a Nacrt zakona o zaštiti podataka o ličnosti on 8 March 2024 intended to transpose GDPR, and it has not been adopted. The supervisory authority's own list of applicable regulations still names the existing Act with no successor — and that list is current enough to carry the new Freedom of Information Act (Sl. list CG 160/25 of 30 December 2025). Five months after the draft appeared, Montenegro amended the old law instead (077/24, 5 August 2024).

What is the maximum fine?

Article 74 sets €500 to €20,000 for a legal person, €150 to €2,000 for the responsible person in a legal person or state body and for a natural person, and €150 to €6,000 for an entrepreneur. That ceiling is roughly one thousandth of GDPR's headline maximum. It is not, however, the whole exposure: the supervisory authority can order processing to stop, and under Article 40a can order physical removal of unlawful public-area surveillance equipment.

Do I have to register my processing with the regulator?

Yes, and this is the obligation most GDPR programmes have no equivalent of. Article 27(1) requires a controller to notify the supervisory authority before establishing an automated personal data filing system, and again on any significant change, with the full content set out in Article 26(2). AZLP operates a searchable register of filing systems. Failing to notify is a misdemeanour under Article 74(1)(9).

When do I need prior permission rather than just notification?

Article 28(1) requires prior consent from the authority for automated processing presenting a special risk, naming special categories of data, data used to assess personality, ability or behaviour, video surveillance of public areas, and biometric data. Article 28(2) then disapplies that requirement where processing is carried out on the basis of a law, with the data subject's consent, or as necessary to perform a contract with the data subject — a carve-out that covers a great deal of ordinary commercial processing. Test the carve-out before assuming you need a permit.

Do we need a data protection officer?

Article 27(3) requires a controller to designate a person responsible for data protection once an automated filing system is established, and exempts controllers with fewer than 10 staff who process personal data. That is a headcount test rather than GDPR's risk-and-scale test, so the answer can differ from your GDPR analysis in either direction.

How long do we have to answer a data subject request?

Fifteen days from the request for the information notice under Article 43(1), and fifteen days to complete, correct or erase data under Article 44(1). Article 44(2) then requires you to inform the person and any third-party recipients of what you did within eight days. Requests are framed as written requests, and the Act requires identity to be established first.

Can we send data from Montenegro to our parent company abroad?

Article 41 makes transfers abroad subject to the prior consent of the supervisory authority, but Article 42 lists nine exemptions. Transfers to EU and EEA member states or to states on the EU adequacy list are exempt under Article 42(6), and a contract containing the contractual obligations accepted by EU member states — standard contractual clauses — with a processor in a non-EU state is exempt under Article 42(8). Montenegro to the EU is free; Montenegro to a third country with no instrument in place is a permit application.

Can our EU parent send data to the Montenegrin subsidiary?

Only with a GDPR transfer safeguard. Montenegro is not on the European Commission's adequacy list, so this is a third-country transfer requiring an Article 46 mechanism — in practice standard contractual clauses supported by a transfer impact assessment. This is the direction groups most often overlook, because the Montenegrin entity feels internal.

We use cloud cameras at our Montenegrin office. Is that allowed?

Not in the form most groups deploy them. Article 35(6) prohibits access to entrance video surveillance footage through internal or public cable television, the internet, or other electronic communications means, whether at the moment of recording or afterwards. Beyond that, the decision to install must be in writing with reasons (Art. 35(2)–(3)), employees in the monitored area must be told in writing (Art. 35(5)), the signage must carry the title of the person conducting surveillance and a telephone number for retention enquiries (Art. 39(3)), and footage may be kept for a maximum of six months (Art. 37(3)).

Do we need to consult anyone before installing workplace cameras?

Yes. Article 36(4) requires the employer to obtain the opinion of the representative trade union or the employees' representative before taking the decision to introduce workplace video surveillance, and Article 36(5) requires employees to be informed in writing before it begins. Article 36(2) prohibits surveillance outside the workplace altogether, naming changing rooms, lifts, sanitary facilities and areas intended for clients and visitors.

Can we run criminal background checks on candidates?

Approach this one carefully. Article 14 provides that processing relating to criminal offences, imposed criminal and misdemeanour penalties, or security measures may be carried out only by or under the supervision of the competent state authority, with safeguards in place. That is narrower than GDPR Article 10, which permits such processing where authorised by Union or Member State law with appropriate safeguards. A group screening policy that works elsewhere in Europe does not transfer unexamined.

Is opt-out enough for marketing emails?

Under the Act, Article 15(1) requires that the person be given the opportunity to object before their data is processed for direct marketing purposes — an opt-out construction — and Article 15(2) requires consent where special categories of data under Article 13 are used. That is the Montenegrin position. If your list includes people in the EU, GDPR and EU e-privacy rules apply to those contacts on their own terms, which is a stricter, consent-led answer.

Can we make automated decisions about staff or credit applicants?

Article 15a prohibits decisions about a person's rights, obligations and interests that assess personal characteristics and abilities — it names work performance, reliability, creditworthiness and behaviour — from being based solely on automated processing. The exceptions are narrow: where, in concluding or performing a contract, the person's request has been accommodated or appropriate safeguards for their legitimate interests exist, such as the opportunity to express a view; or where a law provides for it with prescribed safeguards.

Does the Act reach a company with no Montenegrin entity?

It can. Article 5 applies the Act to controllers processing personal data on Montenegrin territory, and also to a controller established outside Montenegro with no domicile there if the equipment used for processing is located in Montenegro, unless that equipment is used only to transmit data across Montenegrin territory. In that case Article 5(3) requires the controller to appoint a representative established in Montenegro who is responsible for applying the Act. This equipment-based test is the pre-GDPR European approach, which GDPR replaced with its targeting test — so a company can fall outside GDPR's Article 3(2) and inside Montenegro's Article 5 at the same time.