Most foreign companies that open something in Montenegro — a subsidiary, a development office, a hotel, a payroll of ten — carry their GDPR file across the border and assume it does the job. That assumption is wrong in two directions at once.
It is wrong downward, because the General Data Protection Regulation is not Montenegrin law and the Montenegrin supervisory authority does not enforce it. The statute that binds your local entity is the Zakon o zaštiti podataka o ličnosti, Službeni list Crne Gore nos. 079/08, 070/09, 044/12, 022/17 and 077/24 of 5 August 2024 — a 2008 law built on the pre-GDPR European model, with a maximum corporate fine of €20,000. It asks for things GDPR abolished, and it does not ask for several things your GDPR programme is built around.
And it is wrong upward, because GDPR can still reach you under its own Article 3(2), and because Montenegro is not on the European Commission's adequacy list — so your EU parent cannot send personal data to its Montenegrin subsidiary the way it sends data to Dublin.
You are not in one regime. You are in two, and they ask different questions.
What is actually in force, checked today
A replacement was drafted: the Ministry of Internal Affairs published a Nacrt zakona o zaštiti podataka o ličnosti on 8 March 2024, intended to transpose GDPR. As at 25 August 2026 it has not been adopted, and the supervisory authority's own list of applicable regulations still names the existing Act with no successor. That list is maintained — it already carries the new Freedom of Information Act (Sl. list CG 160/25 of 30 December 2025) — so the absence of a new data protection act is a fact about the law, not about the website.
Note the sequence: the draft appeared in March 2024, and five months later Montenegro amended the old law instead (077/24, 5 August 2024). We have not sourced the amending act's text and attribute no specific change to it — but the direction of travel is amendment, not replacement.
The supervisory authority is the body Article 49 establishes as the Agencija za zaštitu ličnih podataka, independent and with legal personality, now operating as the Agencija za zaštitu ličnih podataka i slobodan pristup informacijama (AZLP) — a combined data protection and freedom of information regulator, a structure the EU model does not use. Its powers are listed in Article 50, including giving consent to the establishment of filing systems (Art. 50(4)).
The divergences that cost money
| Question | GDPR | Zakon o zaštiti podataka o ličnosti |
|---|---|---|
| Maximum corporate fine | €20m or 4% of global turnover | €500 to €20,000 (Art. 74) |
| Register your processing with the regulator | Abolished; internal records only | Required before you start (Art. 26–27) |
| Prior regulator approval for risky processing | No — self-assessed DPIA | Yes, prior consent for listed categories (Art. 28) |
| Data protection officer | Risk and scale based | Required, except under 10 processing staff (Art. 27(3)) |
| Breach notification to the regulator | 72 hours | No general duty in the Act |
| Direct marketing | Consent-led in practice | Opt-out, unless special categories (Art. 15) |
| Consent | Any clear affirmative act | In writing, or orally on the record (Art. 9(6)) |
| Sending data abroad | Adequacy, SCCs, BCRs — no permit | Prior consent of the authority, with exemptions (Art. 41–42) |
| Genetic and biometric data as special categories | Yes | Not in the Art. 9(7) list; biometrics regulated separately |
| Criminal-record data | Permitted under law, with safeguards | Only by or under the supervision of a state authority (Art. 14) |
The low fine ceiling is the part everyone notices and the least important line in the table. The obligations in the middle matter more: your GDPR programme has no equivalent of them, so you cannot comply by doing more of what you already do.
One line runs the opposite way and catches employers directly. Article 14 allows processing relating to criminal offences, imposed criminal and misdemeanour penalties or security measures only by, or under the supervision of, the competent state authority, with safeguards. GDPR Article 10 permits it where authorised by Union or Member State law with appropriate safeguards; Montenegro's rule is narrower. An employer running criminal background screening as group policy should settle its footing under Article 14 before collecting the first certificate.
The obligation GDPR abolished and Montenegro kept
Under Article 27(1), a controller must notify the supervisory authority before establishing an automated personal data filing system, and again on any significant change in the processing — with the full content listed in Article 26(2): filing system name, legal basis, controller identity, purpose, categories of data subjects, types of data, retention period, recipients, any transfers out of Montenegro, and the controller's internal processing and security rules.
This is the regime GDPR swept away in favour of internal record-keeping. In Montenegro it is live infrastructure: AZLP operates a searchable Registar zbirki ličnih podataka inside its information system. Failing to notify before establishing the filing system is a misdemeanour under Article 74(1)(9).
Article 27(3) then requires the controller to designate a person responsible for data protection once the automated filing system is established — with a bright-line exemption for controllers having fewer than 10 staff who process personal data. That is a headcount test, not GDPR's risk-and-scale test, and it cuts both ways: a twelve-person office doing mundane processing needs the appointment, a five-person office doing sensitive work does not.
Article 28 goes further and requires prior consent from the authority before automated processing presenting a special risk, naming in particular: special categories of data; data relating to the assessment of personality, ability or behaviour; video surveillance of public areas; and biometric data. Article 28(2) carves out processing carried out on the basis of a law, with the data subject's consent, or as necessary to perform a contract with the data subject. That exemption absorbs a great deal of ordinary commercial processing, and it is the first thing to test before assuming you need a permit.
That this is administered rather than theoretical is not an inference: on 24 July 2026 AZLP ran a workshop with the EU Delegation for municipal police from every municipality, specifically on the documentation to be filed with the Agency before establishing public-area video surveillance.
The workplace rules a foreign employer breaks in the first week
Entrance video surveillance (Article 35). Permitted for the safety of people and property, access control, or where the nature of the work creates risk to employees. The decision must be in writing and state its reasons (Art. 35(2)–(3)), and employees in the monitored area must be informed in writing (Art. 35(5)). Then Article 35(6): access to that footage through internal or public cable television, the internet, or other electronic communications means is prohibited — at the moment of recording or afterwards. A cloud camera at the office door that head office can pull up on a phone is not a grey area under this provision.
Workplace video surveillance (Article 36). Permitted only where required to protect people, property, classified information or trade secrets, and only where the objective cannot be achieved another way (Art. 36(1)). Prohibited outright outside the workplace — the Act names changing rooms, lifts, sanitary facilities and areas intended for clients and visitors (Art. 36(2)). Before deciding to introduce it the employer must obtain the opinion of the representative trade union or the employees' representative (Art. 36(4)), and employees must be informed in writing before it starts (Art. 36(5)).
Signage (Article 39). The public notice must be displayed before surveillance begins and must state the title of the person carrying out the surveillance and a telephone number on which one can find out where the footage is kept and for how long. A generic "CCTV in operation" sticker does not satisfy Article 39(3).
What a visitor may be asked for is itemised in Article 33(3): name, type and number of identification document, residence, address, employment.
Biometrics. Article 28(1)(3) puts biometric processing into the prior-consent regime. The Act's dedicated provision on biometric entry and attendance systems, Article 32, is written for the public sector and bodies exercising public authority, and requires the measure to be prescribed by law. For a private employer the position rests on Article 31 read with Article 28 rather than on a provision written for that case — which is why a fingerprint time-clock is a question to settle before installation.
Most carry misdemeanour liability directly — Article 74(1)(10) to (17) enumerate the video surveillance breaches. And under Article 40a, public-area surveillance run without the Article 27 notification or the Article 28 consent is met with an order to physically remove the equipment.
The clocks and ceilings, in one place
| Obligation | Limit | Source |
|---|---|---|
| Answer a request for an information notice | 15 days | Art. 43(1) |
| Complete, correct or erase data on request | 15 days | Art. 44(1) |
| Tell the person and recipients what you changed | 8 days | Art. 44(2) |
| Keep video surveillance footage | 6 months maximum | Art. 37(3) |
| Keep entry and exit records | 1 year maximum | Art. 34(4) |
| Keep the record of third-party disclosures | 10 years, then delete | Art. 19(2) |
| Appoint a person responsible for data protection | Required unless under 10 processing staff | Art. 27(3) |
| Corporate fine range | €500 to €20,000 | Art. 74(1) |
Article 19 deserves a second look: a register of every recipient given personal data, what was given, the purpose, the legal basis and the period of use — kept for ten years. Most groups do not hold a record in that form. Failing to keep it is a misdemeanour under Article 74(1)(6).
Moving data across the border, in both directions
Out of Montenegro. Article 41 makes transfer abroad subject to the prior consent of the supervisory authority, assessed against the nature of the data, the purpose and duration, the countries of origin and destination, and the rules in force there.
Article 42 lists nine exemptions. The two carrying most commercial traffic are Article 42(6) — transfers to EU and EEA member states, or to states on the EU's adequacy list — and Article 42(8), a contract containing the contractual obligations accepted by EU member states, concluded with a processor in a non-EU state. In plain terms: Montenegro to the EU is free; to a third country on standard contractual clauses, free; to a third country on nothing, a permit application.
Into Montenegro. Here most GDPR programmes have a gap. Montenegro is not among the jurisdictions the European Commission has recognised as adequate. Checked on 25 August 2026, that list runs: Andorra, Argentina, Brazil, Canada (commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States (organisations in the EU–US Data Privacy Framework), Uruguay, and the European Patent Organisation. Montenegro is not on it.
So an EU parent sending employee, customer or supplier data to its Montenegrin subsidiary is making a third-country transfer and needs an Article 46 safeguard — in practice standard contractual clauses plus a transfer impact assessment. Intra-group flows into a Montenegrin entity are the most common thing we see left undocumented.
When GDPR reaches you anyway
None of this makes GDPR irrelevant to a Montenegrin company. Article 3(2) of Regulation (EU) 2016/679 applies the Regulation to controllers and processors not established in the Union where the processing relates to offering goods or services to data subjects in the Union, or to monitoring their behaviour in the Union. A Podgorica software company selling to EU customers, or a hotel marketing to and tracking EU visitors, is inside GDPR on its own terms — and Article 27 then generally requires a representative in the Union.
So: an entity serving only the domestic market is governed by the 2008 Act alone; an entity inside an EU group, or selling into the EU, is governed by both — and the work is not "apply GDPR and you are covered", because GDPR contains no Article 27 notification, no Article 28 permit, no Article 36 union consultation, and no Article 35(6) prohibition on remote access to entrance footage.
Regulated financial entities carry a third layer: Montenegro transposed the EU's digital operational resilience regime separately, in the Zakon o digitalnoj operativnoj otpornosti finansijskog sektora (Sl. list CG 014/26 of 9 February 2026), reaching credit institutions, payment institutions, e-money institutions and crypto-asset service providers — set out in our note on Montenegro's payment services regime.
Before your Montenegrin entity starts processing
The pattern is consistent and avoidable. A group rolls out its GDPR templates, appoints a DPO on GDPR criteria, keeps an internal processing register, signs its standard data processing agreements and installs the cameras it uses everywhere else — and has, in Montenegrin terms, filed nothing with AZLP, taken no union opinion, put up the wrong signage, kept footage too long, and given head office remote access the Act prohibits. A GDPR audit catches none of it, because a GDPR audit does not look for it.
Map the processing once, then run it against both regimes: what must be notified under Article 27, what needs an Article 28 permit or falls inside the Article 28(2) carve-out, what the surveillance decisions and notices must say, how your retention periods sit against the ceilings above, and how data reaches you from the EU parent. Send us your processing map, your camera plan and your intra-group agreements before the office opens, and we will tell you which regime each item lands in. This work sits in our data protection practice, alongside IT and technology contracts and AI.
If the entity is still being built, start with company formation in Montenegro; if you are hiring, the employment-side duties sit beside these in our employer labour law and payroll guide and the work permit guide for employers, with the hiring chain covered by our recruitment and work permit practice.
Statutory references are to the consolidated Zakon o zaštiti podataka o ličnosti (Sl. list CG 079/08, 070/09, 044/12, 022/17, 077/24 of 5 August 2024). The draft replacement law, AZLP's list of applicable regulations, its filing-system register and its 24 July 2026 announcement, and the European Commission's adequacy list were read on 25 August 2026. General information on Montenegrin and EU law, not advice on a specific processing operation.



