Legal Updates

Montenegro's new data protection law: the €20,000 fine ceiling ends on 19 March 2027

Montenegro's new data protection law applies from 19 March 2027: fines up to €2 million or 4% of turnover, 72-hour breach notice, reach abroad.

Rohat Kahraman· 14 September 2026· 7 min readUpdated · 14 September 2026
Montenegro data protection law — law 133/2026, applies from 19 March 2027

Position as at 14 September 2026. Status: Adopted, not yet in force. Instrument: Zakon o zaštiti podataka o ličnosti (Personal Data Protection Act), "Sl. list CG" 133/2026, act 2294; adopted by the Skupština on 4 September 2026 (EPA 1164 XXVIII), decree of promulgation 01-009/26-1569/2 of 8 September 2026, published 11 September 2026. It has 106 articles and replaces the 2008 Act rather than amending it. It enters into force on the eighth day after publication, 19 September 2026, and applies six months after that, from 19 March 2027 (Article 106).

Most Montenegrin compliance files we are shown were built in one of two ways. Some were copied from a group GDPR programme. Others were sized to the 2008 Act, whose ceiling for a company was €20,000 — the figure we set out in Montenegro is not a GDPR country. The second approach had a defensible logic. From 19 March 2027 it stops having one: the ceiling becomes €2,000,000 or 4% of worldwide annual turnover, whichever is higher. The first approach has its own trap, and it sits in Article 104, in the clauses most groups use to move data.

What the text says

Reach comes first. The Act applies to processing in the context of a Montenegrin establishment, wherever the processing happens (Article 3(1)). It also applies to a controller or processor with no establishment in Montenegro when the processing relates to offering goods or services to people in Montenegro, paid or not, or to monitoring their behaviour there (Article 3(2)). Such a controller must appoint a representative in Montenegro in writing (Article 28(1)). Two exceptions exist: occasional processing that does not involve special categories or criminal data on a large scale and is unlikely to create a risk, and public bodies (Article 28(2)).

The clock for data subject requests is now written. The controller answers without undue delay and at the latest within one month of receipt; that period can be extended by up to two further months, but the person must be told of the extension and the reasons within the first month (Article 13(3)). Answers are free. Where a request is manifestly unfounded or excessive the controller may charge a reasonable fee or refuse, and the burden of proving that sits with the controller (Article 13(5)-(6)). Consent to information society services is valid from age 16 (Article 9).

Four company duties carry dates or numbers. A breach goes to the Agency without undue delay and, where feasible, within 72 hours of becoming aware of it; a later notice must give the reasons for the delay, and every breach is documented (Article 34). A data protection officer is mandatory for public bodies, for core activities involving regular and systematic monitoring on a large scale, and for large-scale processing of special categories and criminal data (Article 38(1)). Records of processing are required; the exemption for organisations with fewer than 250 employees falls away as soon as the processing is not occasional (Article 31(5)). And every controller and processor must set up a mechanism for confidential reporting of breaches of the Act (Article 82(1)).

BreachCeiling or rangeArticle
Duties in Articles 9, 12 and 26-40 (representative, records, security, 72-hour notice, DPIA, DPO)up to €1,000,000 or, for a company, 2% of worldwide annual turnover, whichever is higherArt. 88(1)
Principles and consent (Arts 6-8), data subject rights (Arts 13-23), transfers contrary to Arts 46-50up to €2,000,000 or 4%, whichever is higherArt. 88(2)
Failing to cooperate with the Agency or to comply with its act or orderup to €2,000,000 or 4%Art. 88(3)
Missed 72-hour notice, breach of secrecy, refusing the Agency's inspector access, no confidential reporting channel€150 to €2,000 for a legal person (misdemeanour)Art. 89(1)
The same misdemeanours: responsible person / entrepreneur€20 to €200 / €50 to €400Art. 89(2)-(3)
State bodies, local government, public institutionsno administrative fineArt. 88(4)

The fines are imposed by the Agency itself, and a company challenges them in the administrative court (Articles 87, 90).

Transfers are where group templates break. An adequacy decision is taken by the Government of Montenegro after the Agency's prior opinion, not by the European Commission (Article 46(1)). Without one, Article 47(2) lists the safeguards that need no separate approval, and point 3 on that list is the European Commission's standard contractual clauses. Article 104 then holds point 3 back until the day Montenegro joins the European Union. Contractual clauses between a controller and a recipient abroad remain possible, but under Article 47(3) they need the Agency's approval. A foreign court judgment or administrative order demanding data is recognised only if it rests on an international agreement in force with Montenegro, such as a mutual legal assistance treaty (Article 49). Transfer consents already granted by the Agency are to be reviewed within one year of 19 September 2026 (Article 100).

The transitional rules close the old system. The register of filing systems stops being kept on 19 March 2027 (Article 99). Other laws dealing with personal data must be brought into line by 1 December 2026 (Article 102). On 19 March 2027 the 2008 Act ceases to apply, except its video surveillance articles 35 to 40a (Article 105).

What the text does not say

A missed 72-hour notice falls under two provisions at once: Article 88(1), because Article 34 sits inside the 26-40 range, and Article 89(1), item 1. Article 89 says the administrative fine and the misdemeanour sanction cannot both be imposed for the same breach. It does not say how the Agency chooses between a ceiling of €1,000,000 and a range of €150 to €2,000. We cannot show that criterion.

Article 98 sends proceedings not finally concluded by 19 March 2027 to the 2008 Act. It does not deal with a breach committed before that date where proceedings open afterwards. The text does not settle which fine regime applies to it.

Article 104 suspends Commission clauses as a no-approval safeguard, but it does not say whether an existing contract built on them counts as contractual clauses under Article 47(3) needing approval. And Article 105(2) ties the life of the old CCTV articles to a law "governing video surveillance" without naming that law or a date.

Our reading

Three pieces of work belong before 19 March 2027, in this order. First, test Article 3(2): if you sell into Montenegro or track users there without an establishment, the written appointment of a representative under Article 28 is the step with a name and a signature, and we would do it first. Second, list every flow leaving Montenegro and mark the ones resting on Commission clauses. While Article 104 holds point 3 back, we read such a contract as contractual clauses under Article 47(3) and would put it to the Agency for approval; the reading that the clauses still work unapproved has no article to stand on. Third, write the 72-hour procedure and the confidential reporting channel as documents with an owner. Both carry misdemeanour liability under Article 89, and both are what an inspector asks to see.

Do not dismantle the 2008 compliance early. Until the day of application the old Act binds, including registration of filing systems, and proceedings still open then finish under it (Article 98).

What did not change

The supervisory authority stays the same body, the Agencija za zaštitu ličnih podataka i slobodan pristup informacijama (Article 52), and its Council and director serve out their mandates (Article 101). Until 19 March 2027 the 2008 Act applies with its €20,000 ceiling; the inspection procedure under it is in our note on how AZLP inspections run. Police and prosecution processing for criminal-law purposes is outside this Act (Article 2(2), item 2) and governed by law 132/2026, which we set out in what Montenegrin police hold on you. The Agency still does not supervise courts acting in their judicial capacity (Article 63(2)). The GDPR does not become Montenegrin law either: the provisions tied to EU law wait for accession (Article 104).

How to verify

The official text is on the Službeni list site: sluzbenilist.me/propisi/398066. The record summary reads published 11.09.2026, in force 19.09.2026, application from 19.03.2027. Act number 2294 is in the top left corner of the first typeset page, and the text runs to 45 pages with Articles 102 to 106 on the last. The parliamentary file is on the Skupština act page: number 23-3/26-12/11, EPA 1164 XXVIII, status Usvojen. If you compare against the bill, note that a Government amendment inserted a new Article 4 and renumbered what followed, so quote the published numbering only.

For the regime that binds you today, our notes on what a foreign company must do, cross-border data transfers and employer data obligations remain the working reference until 19 March 2027. How we take on a matter is described on our Montenegro lawyer page, and later dated steps will appear under Legal Updates.

Legal basis

  • Zakon o zaštiti podataka o ličnostičl. 3, 9, 13, 28, 29, 31, 34, 35, 38, 46, 47, 49, 52, 63, 76, 77, 82, 84, 88, 89, 98, 99, 100, 102, 104, 105, 106Sl. list CG 133/2026, 11.09.2026 (akt 2294)Official text
  • Predlog zakona o zaštiti podataka o ličnosti (EPA 1164 XXVIII) — Skupština Crne Gore, 28. sazivbroj 23-3/26-12/11 · ukaz 01-009/26-1569/2Skupština Crne Gore, 04.09.2026 · ukaz 08.09.2026Official text

Frequently asked questions

Does the new Act apply to a company with no office in Montenegro?

Yes, if its processing relates to offering goods or services to people in Montenegro, paid or free, or to monitoring their behaviour there (Article 3(2)). That company must appoint a representative in Montenegro in writing (Article 28(1)), unless its processing is occasional, excludes large-scale special-category or criminal data and is unlikely to create a risk (Article 28(2)).

From when can the Agency fine up to €2,000,000?

From 19 March 2027, when the Act starts to apply (Article 106). The ceilings in Article 88 are €1,000,000 or 2% and €2,000,000 or 4% of worldwide annual turnover, whichever is higher. Proceedings not finally concluded by that date finish under the 2008 Act (Article 98).

Can we keep using the European Commission's standard contractual clauses?

Not as a safeguard that needs no approval. Article 47(2), point 3 lists them, but Article 104 defers that point until Montenegro joins the European Union. Contractual clauses with a recipient abroad are still available under Article 47(3), with the Agency's approval.

How quickly must a breach be reported?

Without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to create a risk (Article 34(1)). If it is likely to create a high risk, the people affected are told as well (Article 35). Missing the notice is a misdemeanour carrying €150 to €2,000 for a legal person (Article 89(1)).

Do we still register our filing systems with the Agency?

Until 19 March 2027, yes, because the 2008 Act applies until then. On that date the register of filing systems stops being kept (Article 99(1)), and the duty that replaces it is the internal record of processing activities in Article 31.

Do we need a data protection officer?

Where you are a public body, where your core activities involve regular and systematic monitoring of people on a large scale, or where they involve large-scale processing of special categories and criminal data (Article 38(1)). The officer's contact details are published and sent to the Agency (Article 38(7)).