Technology

What a Montenegrin Employer May Ask, Must Record and Cannot Keep: The Employee Data Rules After April 2026

Since 23 April 2026 a Montenegrin employer cannot ask a candidate's salary history. The duty sits in the Labour Law; the fine sits in a different statute.

Rohat Kahraman· 26 August 2026Updated · 26 August 2026
Abstract cover for an article on employer obligations for employee personal data in Montenegro

If your company employs people in Montenegro, your HR file is governed by two statutes at once, enforced by two regulators with two fine ranges. That split is why employer data failures here are usually found late: the labour inspectorate reads one statute, the data protection agency reads the other, and the HR manual was written for a third country. And on 23 April 2026 the recruitment side changed — a question that appears on almost every interview scoresheet in Europe became a misdemeanour.

Two statutes, two regulators, one HR file

The duty is Article 19(1)(10) of the Zakon o radu: the employer must respect the employee's personality, protect their privacy and ensure the protection of their personal data.

Now read the Labour Law's own penalty articles. Article 208 punishes failures under Article 19(1)(1) and 19(1)(3) — the systematisation act and the paperwork kept on site — while Article 19(1)(7), (8) and (10), the records duty and the privacy duty, appear nowhere in Articles 208 or 209. The Labour Law states the duty and declines to enforce it.

Enforcement comes instead from the Zakon o zaštiti podataka o ličnosti, Službeni list Crne Gore nos. 079/08, 070/09, 044/12, 022/17 and 077/24 of 5 August 2024, and from the Agency for Personal Data Protection and Free Access to Information (AZLP). Its Article 74 range for a legal person is €500 to €20,000, with €150 to €2,000 for the responsible person and €150 to €6,000 for an entrepreneur. Why this statute rather than GDPR is covered in Montenegro is not a GDPR country.

Four questions that became misdemeanours on 23 April 2026

The Labour Law in force is Sl. list CG nos. 074/19, 008/21, 059/21, 068/21, 145/21, 077/24, 084/24, 086/24, 122/25, 165/25 and 051/26. The last — Zakon o izmjenama i dopunama Zakona o radu, published 15 April 2026, in force 23 April 2026 — rewrote Article 25(2), the provision limiting what an employer may demand from a candidate.

CategoryWhat the law now bars an employer from requestingSource
Family statusData on family status and family planningArt. 25(2) as amended by 051/26
Partnership statusWhether the person lives in a marriage or extramarital union, or has a same-sex life partnershipArt. 25(2) as amended by 051/26
Pay historyThe pay they currently earn, and the pay earned at previous employersArt. 25(2) as amended by 051/26
Irrelevant documentsDocuments and evidence of no direct relevance to the jobArt. 25(2), unchanged
Pre-signed exitA statement of resignation from the candidateArt. 25(2), unchanged

The pay-history item is the one that catches foreign employers. "What are you on at the moment?" is standard screening in most markets; in Montenegro it is now a misdemeanour under Article 209(1)(5), punished by €1,000 to €10,000 for a legal person, €100 to €1,000 for the responsible person and €500 to €5,000 for an entrepreneur.

The same amendment adds the mirror duty in Article 24: when advertising a vacancy, or by another route stated in the advertisement, the employer must tell the person intending to conclude a contract the starting pay or pay range for the post, and the collective agreement governing pay. An employer with no advertising obligation must give the same information anyway. A new item in Article 209(1) makes failure the same €1,000 to €10,000 misdemeanour.

The direction comes from the EU pay-transparency file: you may not ask what they earn, and you must state what you pay.

The pregnancy question binds the agency too

Article 121(3) is drafted more widely than employers expect. The employer may not seek any data about pregnancy, nor instruct another person to seek it, unless the employee is personally claiming a statutory right.

The second half is the operative half. Outsourcing the screening does not move the obligation: brief a recruiter, staffing agency or background-check vendor to find out, and the prohibition still reaches you. Article 121(1) and (2) complete it — refusal because of pregnancy is barred, as is conditioning employment on proof of pregnancy, except for work carrying substantial risk to the health of woman and child established by the competent health authority.

Unlike the Article 19 privacy duty, this one is penalised, at the top bracket. Article 208(1)(17) covers failure to protect employees under Articles 119 to 126, which includes Article 121 — €2,000 to €20,000 for a legal person. What else stays with you when an agency hires is set out in using a recruitment agency in Montenegro.

Criminal record screening and automated scoring

Article 14 of the Data Protection Act is short and rarely read: processing of data on criminal offences, imposed criminal and misdemeanour penalties or security measures may be carried out only by or under the supervision of the competent state body. There is no legitimate-interest route around it, and Article 74(1)(3) puts breach in the €500 to €20,000 band. Requiring a candidate to produce a certificate where a special law makes a clean record a condition of the post is different; what Article 14 reaches is the screening database you hold about offences.

If recruitment or performance runs on a scoring engine, three provisions apply at once. Article 15a prohibits decisions on a person's rights, obligations and interests being based solely on automated processing where they assess personal characteristics and abilities. Article 15a(2) leaves two narrow exits, including appropriate measures protecting the person's legitimate interests.

Article 28(1)(2) requires the supervisory authority's consent before each automated processing presenting a special risk, and names assessment of personality, abilities or behaviour. Article 28(2) disapplies that where processing rests on law, on consent, or on necessity to perform a contract between controller and person — and note what that last exit reaches: an employment contract exists with your employees; with a candidate you have not hired, it does not.

Article 43(2)(7) then requires the controller, on written request and within 15 days, to state the manner of the automated processing in an Article 15a case — a constraint on model choice, not a disclosure formality, because you cannot answer it about a system you cannot explain. The wider point is in AI law in Montenegro.

What you are required to record, and by which statute

Three record-keeping regimes land on the same file.

Labour Law. Article 19(1)(7) requires records of employees in an employment relationship covering data on employees, attendance, all forms of working-time organisation and annual leave, in accordance with a special law; Article 19(1)(8) requires a separate record of employees engaged through a temporary staffing agency. The 2026 amendment adds a separate register of employees with disabilities, containing sex or gender, type of engagement, duration, the post and pay.

The special law is the Zakon o evidencijama u oblasti rada i zapošljavanja, Sl. list CG no. 45/12. Records on employed persons and on pay are kept by employers themselves unless a special law provides otherwise; the state-side data sits in the Central Register of Obligors and Insured Persons (CROO).

Social insurance. Article 33 requires registering the employee for compulsory health, pension, disability and unemployment insurance on the day work starts, filing with the competent authority within eight days, and handing the employee a copy within five days of issue. That statutory transfer is why it needs no consent under Article 10(2)(1) of the Data Protection Act, and why Article 27(2) exempts public registers established by law from filing-system notification. It is also the chain an inspection follows when the workforce is foreign — see work permits from the employer's side.

The work booklet. Articles 204 and 205 are still in force and still physical: the employee hands the radna knjižica over on the first day against a receipt, entering negative data about their work is prohibited, and it must be returned properly completed on the day employment ends — failing to return it being a misdemeanour under Article 208(1)(21).

Health data: what reaches the employer and what does not

The employer refers the employee for the health examination matching the workplace risk — Article 32 of the Zakon o zaštiti i zdravlju na radu, Sl. list CG nos. 034/14, 044/18 and 084/24. What comes back is deliberately narrow.

ItemWho holds itWhat the employer getsSource
Findings of the medical examinationAuthorised institution or chosen doctorNothingZZZR Art. 49
Fitness for the particular jobAuthorised institutionThe fitness report onlyZZZR Art. 49
Onward disclosure to a third partyRequires the employee's written consentNot the employer's decisionZZZR Art. 49
Record of prior and periodic examinationsEmployerThe record, not the findingsZZZR Art. 50
Health data as a categorySpecial category under the Data Protection ActMust be specially markedZZPL Art. 9(7), Art. 13(2)

Under Article 49, data collected in connection with health examinations are confidential, held by the authorised occupational health institution or the chosen doctor, and may be given to others only with the employee's written consent. The employer receives a report on fitness for performing particular work, delivered so as not to breach confidentiality. Using that data contrary to its purpose, or to discriminate, is prohibited.

Article 50 obliges the employer to keep prescribed records under eleven headings, among them posts with increased risk, injuries at work, and prior and periodic health examinations. Failing to keep them is a misdemeanour under Article 57, which the statute itself labels a minor one: €200 to €2,000 for a legal person, a flat €50 for the responsible person and a flat €150 for an entrepreneur. Set against €500 to €20,000 under the Data Protection Act for mishandling the same health data, the incentive structure is upside down: the record-keeping failure is cheap, the confidentiality failure is not.

The systems obligations nobody ports from a GDPR programme

Four provisions bite on how the HR system is configured, not on what the privacy notice says.

Article 24(3). Where processing is electronic, the system must automatically log the users of personal data, the data processed, the legal basis for use, the case number, and log-in and log-out times. A shared mailbox and a spreadsheet on a network drive do not satisfy it. Note the asymmetry: Article 74(1)(8) penalises failure under Article 24(1), the general technical, staffing and organisational measures, and does not name Article 24(3) or (4) — the logging duty is real and unpenalised in its own right.

Article 24(4). The controller must determine which employees have access to which personal data, and which categories may be released and on what conditions. Article 25 has those persons act exclusively on the instructions of the responsible person, keeping secrecy of what they learn unless a law provides otherwise.

Article 16. Entrusting processing requires a contract in written form, and Article 16(4) requires the processor to destroy or return the data afterwards. Article 74(1)(5) adds a criterion the operative provision does not spell out: it penalises entrusting processing to a processor not registered for the activity of personal data processing, or one failing the technical, staffing and organisational conditions. Read that item before signing with a payroll bureau or HR platform chosen on price and features. Contract mechanics are in IT and outsourcing contracts in Montenegro.

Before establishing an automatic filing system, the controller must notify the supervisory authority with the Article 26(2) particulars — including purpose, categories of persons, types of data, the retention and use period, users, any transfer abroad, and the internal protection rules — and Article 27(1) repeats that on any significant change. Failing to notify is a misdemeanour under Article 74(1)(9). Your HR, payroll, attendance and applicant systems are each capable of being a separate filing system; the mechanics are in what a foreign company must file with AZLP. Article 27(3) requires a person responsible for data protection once such a system exists, unless the controller has fewer than ten officials who process personal data.

Consent has a form requirement. Article 9(6) defines it as a freely given statement in written form or given orally on the record, after the person is informed of the purpose. A tick-box in an HR portal is not that. It matters less than it looks, because most employment processing runs on Article 10(2)(1) — necessary to fulfil the controller's statutory obligations — not on consent. Employers who reach for consent as the default inherit a formality problem they did not need.

Special categories. Article 9(7) covers racial or ethnic origin, political opinion, religious or philosophical belief, trade union membership, and data on health or sexual life. Article 13(1)(2) permits processing necessary for employment in accordance with the law governing employment relations, provided adequate protection measures are prescribed — written down, not assumed. Article 13(2) requires special categories to be specially marked and protected against unauthorised access. Union membership lists kept for dues deduction fall inside this. So does the health file.

What we could not verify, and said so

Publicly available consolidated Labour Law texts stop at gazette 086/24 of 10 September 2024. For Articles 24, 25, 208 and 209 we worked from the Government's bill (EPA 898 XXVIII, 26 February 2026) that became gazette 051/26, checked against the parliamentary committee report of 7 April 2026 and the tabled amendments, none of which touched the bill article rewriting Article 25(2). Anyone relying on the exact paragraph numbering inside Article 24 should read it in the gazette. We did not source the 45/12 records law in full and cite no article numbers from it, and we attribute no specific change to the 077/24 amendment of the Data Protection Act.

Everything above was checked on 26 August 2026. Workplace video surveillance under Articles 35, 36 and 39 sits in the earlier piece rather than here; penalties for employing foreign workers outside the permit regime are in illegal employment of foreign workers; sending employee data to an EU parent is in cross-border data transfers.

Before your next hire, and before your next HR system goes live

If you run a payroll in Montenegro the sequence is short: delete the pay-history question from the interview scoresheet; put the starting pay or pay range into the vacancy advertisement; write down which employees may see which data; and confirm whether your HR filing systems were ever notified to AZLP.

Send us your interview template, HR system configuration and processor contracts, and we will tell you which statute each item lands in and what the exposure is. This work sits in our data protection practice, and connects to work permits and recruitment where the workforce is foreign.

Frequently asked questions

Can a Montenegrin employer ask a candidate what they currently earn?

No. Since 23 April 2026, Article 25(2) of the Labour Law, as amended by gazette 051/26, bars an employer from requesting data on the pay a candidate currently earns or earned at previous employers. Asking is a misdemeanour under Article 209(1)(5), €1,000 to €10,000 for a legal person.

Does the employer have to state the salary in a job advertisement?

Yes. The 2026 amendment inserted new paragraphs into Article 24 requiring the employer to inform the person intending to conclude an employment contract of the starting pay or the pay range for the post, and of the collective agreement governing pay. An employer with no advertising obligation must give the same information by another route.

Which regulator enforces employee data protection in Montenegro?

Two. The labour inspectorate enforces the Labour Law's own misdemeanours in Articles 208 and 209. The Agency for Personal Data Protection and Free Access to Information enforces the Data Protection Act, whose Article 74 range for a legal person is €500 to €20,000.

Is the Labour Law's privacy duty itself punishable?

Not under the Labour Law. Article 19(1)(10) states the duty, but it is not listed in Articles 208 or 209. The penalty for mishandling employee data comes from the Data Protection Act instead.

Can we ask about marital status or a same-sex partnership?

No. The amended Article 25(2) bars requesting data on family status and family planning, and on whether the person lives in a marriage or an extramarital union or has concluded a same-sex life partnership.

Can we ask a recruiter to check whether a candidate is pregnant?

No. Article 121(3) of the Labour Law bars the employer from seeking any data about pregnancy and from instructing another person to seek it, unless the employee is personally claiming a specific statutory right. Failure to protect employees under Articles 119 to 126 is a misdemeanour under Article 208(1)(17), €2,000 to €20,000 for a legal person.

Can a private employer run criminal record checks on candidates?

Article 14 of the Data Protection Act limits processing of data relating to criminal offences and imposed penalties to processing by or under the supervision of the competent state body. Requiring a candidate to produce a certificate where a special law makes a clean record a condition of the post is a different thing from maintaining a screening database, which is what Article 14 reaches.

Can we use an automated tool to score applicants?

Not as the sole basis of the decision. Article 15a prohibits decisions on a person's rights, obligations and interests being based solely on automated processing of personal characteristics and abilities, subject to the narrow exits in Article 15a(2). Article 28(1)(2) also requires the supervisory authority's prior consent for processing relating to assessment of personality, abilities or behaviour, with the exceptions in Article 28(2).

How long do we have to answer an employee's request about their data?

Fifteen days from the request, under Article 43(1), after establishing identity. Where Article 15a automated processing is involved, the reply must also state the manner of that automated processing, under Article 43(2)(7). Corrections and erasures follow the same fifteen-day clock under Article 44(1), with an eight-day duty to notify the person and the recipients.

Do we have to notify our HR system to the data protection authority?

Article 27(1) requires notification to the supervisory authority before an automatic filing system is established, containing the Article 26(2) particulars, and again on any significant change in the processing. Public registers and records established by law are exempt under Article 27(2). Failing to notify is a misdemeanour under Article 74(1)(9).

Must we appoint a data protection officer?

Article 27(3) requires a person responsible for data protection to be appointed after an automatic filing system is established. A controller with fewer than ten officials who process personal data is not required to appoint one.

Is an employee's tick-box consent in our HR portal valid?

Article 9(6) defines consent as a freely given statement in written form or given orally on the record, after the person has been informed of the purpose. In most employment processing the question is moot, because Article 10(2)(1) allows processing without consent where it is necessary to fulfil the controller's statutory obligations.

What can the employer see of an employee's medical examination?

The report on health fitness for performing particular work, delivered so as not to breach confidentiality. Under Article 49 of the Occupational Safety and Health Act, the underlying data are confidential and held by the authorised institution or chosen doctor, and may be given to others only with the employee's written consent. Using them contrary to their purpose or to discriminate is prohibited.

Does the work booklet still exist?

Yes. Articles 204 and 205 of the Labour Law are in force: the employee hands the work booklet to the employer on the first day against a receipt, entering negative data about the employee's work is prohibited, and it must be returned properly completed on the day the employment ends, with failure to return it a misdemeanour under Article 208(1)(21).

What must we do about employees hired through a staffing agency?

Article 19(1)(8) of the Labour Law requires a separate record of employees engaged through a temporary staffing agency, kept in addition to the record of your own employees under Article 19(1)(7). The liability that stays with the user employer when an agency supplies the workforce is a separate question from the record-keeping duty.

Are trade union membership records special category data?

Yes. Article 9(7) of the Data Protection Act lists membership in trade union organisations among the special categories, alongside health and sexual life. Article 13(2) requires special categories to be specially marked and protected against unauthorised access, which reaches union lists kept for dues deduction.