If your company employs people in Montenegro, your HR file is governed by two statutes at once, enforced by two regulators with two fine ranges. That split is why employer data failures here are usually found late: the labour inspectorate reads one statute, the data protection agency reads the other, and the HR manual was written for a third country. And on 23 April 2026 the recruitment side changed — a question that appears on almost every interview scoresheet in Europe became a misdemeanour.
Two statutes, two regulators, one HR file
The duty is Article 19(1)(10) of the Zakon o radu: the employer must respect the employee's personality, protect their privacy and ensure the protection of their personal data.
Now read the Labour Law's own penalty articles. Article 208 punishes failures under Article 19(1)(1) and 19(1)(3) — the systematisation act and the paperwork kept on site — while Article 19(1)(7), (8) and (10), the records duty and the privacy duty, appear nowhere in Articles 208 or 209. The Labour Law states the duty and declines to enforce it.
Enforcement comes instead from the Zakon o zaštiti podataka o ličnosti, Službeni list Crne Gore nos. 079/08, 070/09, 044/12, 022/17 and 077/24 of 5 August 2024, and from the Agency for Personal Data Protection and Free Access to Information (AZLP). Its Article 74 range for a legal person is €500 to €20,000, with €150 to €2,000 for the responsible person and €150 to €6,000 for an entrepreneur. Why this statute rather than GDPR is covered in Montenegro is not a GDPR country.
Four questions that became misdemeanours on 23 April 2026
The Labour Law in force is Sl. list CG nos. 074/19, 008/21, 059/21, 068/21, 145/21, 077/24, 084/24, 086/24, 122/25, 165/25 and 051/26. The last — Zakon o izmjenama i dopunama Zakona o radu, published 15 April 2026, in force 23 April 2026 — rewrote Article 25(2), the provision limiting what an employer may demand from a candidate.
| Category | What the law now bars an employer from requesting | Source |
|---|---|---|
| Family status | Data on family status and family planning | Art. 25(2) as amended by 051/26 |
| Partnership status | Whether the person lives in a marriage or extramarital union, or has a same-sex life partnership | Art. 25(2) as amended by 051/26 |
| Pay history | The pay they currently earn, and the pay earned at previous employers | Art. 25(2) as amended by 051/26 |
| Irrelevant documents | Documents and evidence of no direct relevance to the job | Art. 25(2), unchanged |
| Pre-signed exit | A statement of resignation from the candidate | Art. 25(2), unchanged |
The pay-history item is the one that catches foreign employers. "What are you on at the moment?" is standard screening in most markets; in Montenegro it is now a misdemeanour under Article 209(1)(5), punished by €1,000 to €10,000 for a legal person, €100 to €1,000 for the responsible person and €500 to €5,000 for an entrepreneur.
The same amendment adds the mirror duty in Article 24: when advertising a vacancy, or by another route stated in the advertisement, the employer must tell the person intending to conclude a contract the starting pay or pay range for the post, and the collective agreement governing pay. An employer with no advertising obligation must give the same information anyway. A new item in Article 209(1) makes failure the same €1,000 to €10,000 misdemeanour.
The direction comes from the EU pay-transparency file: you may not ask what they earn, and you must state what you pay.
The pregnancy question binds the agency too
Article 121(3) is drafted more widely than employers expect. The employer may not seek any data about pregnancy, nor instruct another person to seek it, unless the employee is personally claiming a statutory right.
The second half is the operative half. Outsourcing the screening does not move the obligation: brief a recruiter, staffing agency or background-check vendor to find out, and the prohibition still reaches you. Article 121(1) and (2) complete it — refusal because of pregnancy is barred, as is conditioning employment on proof of pregnancy, except for work carrying substantial risk to the health of woman and child established by the competent health authority.
Unlike the Article 19 privacy duty, this one is penalised, at the top bracket. Article 208(1)(17) covers failure to protect employees under Articles 119 to 126, which includes Article 121 — €2,000 to €20,000 for a legal person. What else stays with you when an agency hires is set out in using a recruitment agency in Montenegro.
Criminal record screening and automated scoring
Article 14 of the Data Protection Act is short and rarely read: processing of data on criminal offences, imposed criminal and misdemeanour penalties or security measures may be carried out only by or under the supervision of the competent state body. There is no legitimate-interest route around it, and Article 74(1)(3) puts breach in the €500 to €20,000 band. Requiring a candidate to produce a certificate where a special law makes a clean record a condition of the post is different; what Article 14 reaches is the screening database you hold about offences.
If recruitment or performance runs on a scoring engine, three provisions apply at once. Article 15a prohibits decisions on a person's rights, obligations and interests being based solely on automated processing where they assess personal characteristics and abilities. Article 15a(2) leaves two narrow exits, including appropriate measures protecting the person's legitimate interests.
Article 28(1)(2) requires the supervisory authority's consent before each automated processing presenting a special risk, and names assessment of personality, abilities or behaviour. Article 28(2) disapplies that where processing rests on law, on consent, or on necessity to perform a contract between controller and person — and note what that last exit reaches: an employment contract exists with your employees; with a candidate you have not hired, it does not.
Article 43(2)(7) then requires the controller, on written request and within 15 days, to state the manner of the automated processing in an Article 15a case — a constraint on model choice, not a disclosure formality, because you cannot answer it about a system you cannot explain. The wider point is in AI law in Montenegro.
What you are required to record, and by which statute
Three record-keeping regimes land on the same file.
Labour Law. Article 19(1)(7) requires records of employees in an employment relationship covering data on employees, attendance, all forms of working-time organisation and annual leave, in accordance with a special law; Article 19(1)(8) requires a separate record of employees engaged through a temporary staffing agency. The 2026 amendment adds a separate register of employees with disabilities, containing sex or gender, type of engagement, duration, the post and pay.
The special law is the Zakon o evidencijama u oblasti rada i zapošljavanja, Sl. list CG no. 45/12. Records on employed persons and on pay are kept by employers themselves unless a special law provides otherwise; the state-side data sits in the Central Register of Obligors and Insured Persons (CROO).
Social insurance. Article 33 requires registering the employee for compulsory health, pension, disability and unemployment insurance on the day work starts, filing with the competent authority within eight days, and handing the employee a copy within five days of issue. That statutory transfer is why it needs no consent under Article 10(2)(1) of the Data Protection Act, and why Article 27(2) exempts public registers established by law from filing-system notification. It is also the chain an inspection follows when the workforce is foreign — see work permits from the employer's side.
The work booklet. Articles 204 and 205 are still in force and still physical: the employee hands the radna knjižica over on the first day against a receipt, entering negative data about their work is prohibited, and it must be returned properly completed on the day employment ends — failing to return it being a misdemeanour under Article 208(1)(21).
Health data: what reaches the employer and what does not
The employer refers the employee for the health examination matching the workplace risk — Article 32 of the Zakon o zaštiti i zdravlju na radu, Sl. list CG nos. 034/14, 044/18 and 084/24. What comes back is deliberately narrow.
| Item | Who holds it | What the employer gets | Source |
|---|---|---|---|
| Findings of the medical examination | Authorised institution or chosen doctor | Nothing | ZZZR Art. 49 |
| Fitness for the particular job | Authorised institution | The fitness report only | ZZZR Art. 49 |
| Onward disclosure to a third party | Requires the employee's written consent | Not the employer's decision | ZZZR Art. 49 |
| Record of prior and periodic examinations | Employer | The record, not the findings | ZZZR Art. 50 |
| Health data as a category | Special category under the Data Protection Act | Must be specially marked | ZZPL Art. 9(7), Art. 13(2) |
Under Article 49, data collected in connection with health examinations are confidential, held by the authorised occupational health institution or the chosen doctor, and may be given to others only with the employee's written consent. The employer receives a report on fitness for performing particular work, delivered so as not to breach confidentiality. Using that data contrary to its purpose, or to discriminate, is prohibited.
Article 50 obliges the employer to keep prescribed records under eleven headings, among them posts with increased risk, injuries at work, and prior and periodic health examinations. Failing to keep them is a misdemeanour under Article 57, which the statute itself labels a minor one: €200 to €2,000 for a legal person, a flat €50 for the responsible person and a flat €150 for an entrepreneur. Set against €500 to €20,000 under the Data Protection Act for mishandling the same health data, the incentive structure is upside down: the record-keeping failure is cheap, the confidentiality failure is not.
The systems obligations nobody ports from a GDPR programme
Four provisions bite on how the HR system is configured, not on what the privacy notice says.
Article 24(3). Where processing is electronic, the system must automatically log the users of personal data, the data processed, the legal basis for use, the case number, and log-in and log-out times. A shared mailbox and a spreadsheet on a network drive do not satisfy it. Note the asymmetry: Article 74(1)(8) penalises failure under Article 24(1), the general technical, staffing and organisational measures, and does not name Article 24(3) or (4) — the logging duty is real and unpenalised in its own right.
Article 24(4). The controller must determine which employees have access to which personal data, and which categories may be released and on what conditions. Article 25 has those persons act exclusively on the instructions of the responsible person, keeping secrecy of what they learn unless a law provides otherwise.
Article 16. Entrusting processing requires a contract in written form, and Article 16(4) requires the processor to destroy or return the data afterwards. Article 74(1)(5) adds a criterion the operative provision does not spell out: it penalises entrusting processing to a processor not registered for the activity of personal data processing, or one failing the technical, staffing and organisational conditions. Read that item before signing with a payroll bureau or HR platform chosen on price and features. Contract mechanics are in IT and outsourcing contracts in Montenegro.
Filing, consent and the special-category marking rule
Before establishing an automatic filing system, the controller must notify the supervisory authority with the Article 26(2) particulars — including purpose, categories of persons, types of data, the retention and use period, users, any transfer abroad, and the internal protection rules — and Article 27(1) repeats that on any significant change. Failing to notify is a misdemeanour under Article 74(1)(9). Your HR, payroll, attendance and applicant systems are each capable of being a separate filing system; the mechanics are in what a foreign company must file with AZLP. Article 27(3) requires a person responsible for data protection once such a system exists, unless the controller has fewer than ten officials who process personal data.
Consent has a form requirement. Article 9(6) defines it as a freely given statement in written form or given orally on the record, after the person is informed of the purpose. A tick-box in an HR portal is not that. It matters less than it looks, because most employment processing runs on Article 10(2)(1) — necessary to fulfil the controller's statutory obligations — not on consent. Employers who reach for consent as the default inherit a formality problem they did not need.
Special categories. Article 9(7) covers racial or ethnic origin, political opinion, religious or philosophical belief, trade union membership, and data on health or sexual life. Article 13(1)(2) permits processing necessary for employment in accordance with the law governing employment relations, provided adequate protection measures are prescribed — written down, not assumed. Article 13(2) requires special categories to be specially marked and protected against unauthorised access. Union membership lists kept for dues deduction fall inside this. So does the health file.
What we could not verify, and said so
Publicly available consolidated Labour Law texts stop at gazette 086/24 of 10 September 2024. For Articles 24, 25, 208 and 209 we worked from the Government's bill (EPA 898 XXVIII, 26 February 2026) that became gazette 051/26, checked against the parliamentary committee report of 7 April 2026 and the tabled amendments, none of which touched the bill article rewriting Article 25(2). Anyone relying on the exact paragraph numbering inside Article 24 should read it in the gazette. We did not source the 45/12 records law in full and cite no article numbers from it, and we attribute no specific change to the 077/24 amendment of the Data Protection Act.
Everything above was checked on 26 August 2026. Workplace video surveillance under Articles 35, 36 and 39 sits in the earlier piece rather than here; penalties for employing foreign workers outside the permit regime are in illegal employment of foreign workers; sending employee data to an EU parent is in cross-border data transfers.
Before your next hire, and before your next HR system goes live
If you run a payroll in Montenegro the sequence is short: delete the pay-history question from the interview scoresheet; put the starting pay or pay range into the vacancy advertisement; write down which employees may see which data; and confirm whether your HR filing systems were ever notified to AZLP.
Send us your interview template, HR system configuration and processor contracts, and we will tell you which statute each item lands in and what the exposure is. This work sits in our data protection practice, and connects to work permits and recruitment where the workforce is foreign.




