Position as at 14 September 2026. Status: Adopted, not yet in force. Instrument: Zakon o zaštiti podataka o ličnosti (Personal Data Protection Act), "Sl. list CG" 133/2026, act 2294; adopted by the Skupština on 4 September 2026 (EPA 1164 XXVIII), decree of promulgation 01-009/26-1569/2 of 8 September 2026, published 11 September 2026. It has 106 articles and replaces the 2008 Act rather than amending it. It enters into force on the eighth day after publication, 19 September 2026, and applies six months after that, from 19 March 2027 (Article 106).
Most Montenegrin compliance files we are shown were built in one of two ways. Some were copied from a group GDPR programme. Others were sized to the 2008 Act, whose ceiling for a company was €20,000 — the figure we set out in Montenegro is not a GDPR country. The second approach had a defensible logic. From 19 March 2027 it stops having one: the ceiling becomes €2,000,000 or 4% of worldwide annual turnover, whichever is higher. The first approach has its own trap, and it sits in Article 104, in the clauses most groups use to move data.
What the text says
Reach comes first. The Act applies to processing in the context of a Montenegrin establishment, wherever the processing happens (Article 3(1)). It also applies to a controller or processor with no establishment in Montenegro when the processing relates to offering goods or services to people in Montenegro, paid or not, or to monitoring their behaviour there (Article 3(2)). Such a controller must appoint a representative in Montenegro in writing (Article 28(1)). Two exceptions exist: occasional processing that does not involve special categories or criminal data on a large scale and is unlikely to create a risk, and public bodies (Article 28(2)).
The clock for data subject requests is now written. The controller answers without undue delay and at the latest within one month of receipt; that period can be extended by up to two further months, but the person must be told of the extension and the reasons within the first month (Article 13(3)). Answers are free. Where a request is manifestly unfounded or excessive the controller may charge a reasonable fee or refuse, and the burden of proving that sits with the controller (Article 13(5)-(6)). Consent to information society services is valid from age 16 (Article 9).
Four company duties carry dates or numbers. A breach goes to the Agency without undue delay and, where feasible, within 72 hours of becoming aware of it; a later notice must give the reasons for the delay, and every breach is documented (Article 34). A data protection officer is mandatory for public bodies, for core activities involving regular and systematic monitoring on a large scale, and for large-scale processing of special categories and criminal data (Article 38(1)). Records of processing are required; the exemption for organisations with fewer than 250 employees falls away as soon as the processing is not occasional (Article 31(5)). And every controller and processor must set up a mechanism for confidential reporting of breaches of the Act (Article 82(1)).
| Breach | Ceiling or range | Article |
|---|---|---|
| Duties in Articles 9, 12 and 26-40 (representative, records, security, 72-hour notice, DPIA, DPO) | up to €1,000,000 or, for a company, 2% of worldwide annual turnover, whichever is higher | Art. 88(1) |
| Principles and consent (Arts 6-8), data subject rights (Arts 13-23), transfers contrary to Arts 46-50 | up to €2,000,000 or 4%, whichever is higher | Art. 88(2) |
| Failing to cooperate with the Agency or to comply with its act or order | up to €2,000,000 or 4% | Art. 88(3) |
| Missed 72-hour notice, breach of secrecy, refusing the Agency's inspector access, no confidential reporting channel | €150 to €2,000 for a legal person (misdemeanour) | Art. 89(1) |
| The same misdemeanours: responsible person / entrepreneur | €20 to €200 / €50 to €400 | Art. 89(2)-(3) |
| State bodies, local government, public institutions | no administrative fine | Art. 88(4) |
The fines are imposed by the Agency itself, and a company challenges them in the administrative court (Articles 87, 90).
Transfers are where group templates break. An adequacy decision is taken by the Government of Montenegro after the Agency's prior opinion, not by the European Commission (Article 46(1)). Without one, Article 47(2) lists the safeguards that need no separate approval, and point 3 on that list is the European Commission's standard contractual clauses. Article 104 then holds point 3 back until the day Montenegro joins the European Union. Contractual clauses between a controller and a recipient abroad remain possible, but under Article 47(3) they need the Agency's approval. A foreign court judgment or administrative order demanding data is recognised only if it rests on an international agreement in force with Montenegro, such as a mutual legal assistance treaty (Article 49). Transfer consents already granted by the Agency are to be reviewed within one year of 19 September 2026 (Article 100).
The transitional rules close the old system. The register of filing systems stops being kept on 19 March 2027 (Article 99). Other laws dealing with personal data must be brought into line by 1 December 2026 (Article 102). On 19 March 2027 the 2008 Act ceases to apply, except its video surveillance articles 35 to 40a (Article 105).
What the text does not say
A missed 72-hour notice falls under two provisions at once: Article 88(1), because Article 34 sits inside the 26-40 range, and Article 89(1), item 1. Article 89 says the administrative fine and the misdemeanour sanction cannot both be imposed for the same breach. It does not say how the Agency chooses between a ceiling of €1,000,000 and a range of €150 to €2,000. We cannot show that criterion.
Article 98 sends proceedings not finally concluded by 19 March 2027 to the 2008 Act. It does not deal with a breach committed before that date where proceedings open afterwards. The text does not settle which fine regime applies to it.
Article 104 suspends Commission clauses as a no-approval safeguard, but it does not say whether an existing contract built on them counts as contractual clauses under Article 47(3) needing approval. And Article 105(2) ties the life of the old CCTV articles to a law "governing video surveillance" without naming that law or a date.
Our reading
Three pieces of work belong before 19 March 2027, in this order. First, test Article 3(2): if you sell into Montenegro or track users there without an establishment, the written appointment of a representative under Article 28 is the step with a name and a signature, and we would do it first. Second, list every flow leaving Montenegro and mark the ones resting on Commission clauses. While Article 104 holds point 3 back, we read such a contract as contractual clauses under Article 47(3) and would put it to the Agency for approval; the reading that the clauses still work unapproved has no article to stand on. Third, write the 72-hour procedure and the confidential reporting channel as documents with an owner. Both carry misdemeanour liability under Article 89, and both are what an inspector asks to see.
Do not dismantle the 2008 compliance early. Until the day of application the old Act binds, including registration of filing systems, and proceedings still open then finish under it (Article 98).
What did not change
The supervisory authority stays the same body, the Agencija za zaštitu ličnih podataka i slobodan pristup informacijama (Article 52), and its Council and director serve out their mandates (Article 101). Until 19 March 2027 the 2008 Act applies with its €20,000 ceiling; the inspection procedure under it is in our note on how AZLP inspections run. Police and prosecution processing for criminal-law purposes is outside this Act (Article 2(2), item 2) and governed by law 132/2026, which we set out in what Montenegrin police hold on you. The Agency still does not supervise courts acting in their judicial capacity (Article 63(2)). The GDPR does not become Montenegrin law either: the provisions tied to EU law wait for accession (Article 104).
How to verify
The official text is on the Službeni list site: sluzbenilist.me/propisi/398066. The record summary reads published 11.09.2026, in force 19.09.2026, application from 19.03.2027. Act number 2294 is in the top left corner of the first typeset page, and the text runs to 45 pages with Articles 102 to 106 on the last. The parliamentary file is on the Skupština act page: number 23-3/26-12/11, EPA 1164 XXVIII, status Usvojen. If you compare against the bill, note that a Government amendment inserted a new Article 4 and renumbered what followed, so quote the published numbering only.
For the regime that binds you today, our notes on what a foreign company must do, cross-border data transfers and employer data obligations remain the working reference until 19 March 2027. How we take on a matter is described on our Montenegro lawyer page, and later dated steps will appear under Legal Updates.



