Legal Updates

What Montenegrin police hold on you: the right that opens on 17 March 2027, and the window that stays shut

Montenegro's new law 132/2026 on police data: the right to ask what is held on you, the refusal that needs no reason, and when the data goes abroad.

Rohat Kahraman· 12 September 2026· 8 min readUpdated · 12 September 2026
Police data in Montenegro — law 132/2026, access right from 17 March 2027

Position as at 12 September 2026. Status: Adopted, not yet in force. Instrument: Zakon o zaštiti podataka o ličnosti koje obrađuju nadležni organi u svrhu sprečavanja, istraživanja, otkrivanja ili gonjenja krivičnih djela ili izvršenja krivičnih sankcija (law on the protection of personal data processed by competent authorities in criminal matters), "Sl. list CG" 132/2026, act 2261; adopted by the Skupština on 4 September 2026 (EPA 1165 XXVIII), decree of promulgation 8 September 2026, published 9 September 2026. Sixty articles, a free-standing statute rather than an amendment. It enters into force on the eighth day after publication, 17 September 2026, and applies six months after that, from 17 March 2027 (Article 60).

Readers pulled aside at the border, called in as a witness, or named in someone else's file all arrive at the same three questions. Has a record been opened on me, what is in it, and who has been sent a copy. Until now those questions had no addressee in writing. This statute writes one — and the same text also writes down when the answer may be withheld. The two halves have to be read together.

What the text says

The law separates police and prosecution processing from the general data protection regime. Its addressees are nadležni organi: the authorities responsible for preventing, investigating, detecting or prosecuting criminal offences or executing criminal sanctions, including protection against threats to public safety, and any other body entrusted by law with public powers for those purposes (Article 5, item 8). The territorial test attaches to the authority, not to the hardware: if the authority is established in Montenegro, it does not matter whether the processing happens on Montenegrin soil (Article 3).

Article 16 carries the access right. You may ask for confirmation that data about you is being processed and, if it is, for the data itself plus seven items: the purpose and legal basis, the categories of data, the recipients to whom it has been disclosed — the text says "in particular recipients in other states or international organisations" — the retention period or the criteria for setting it, your right to seek rectification, erasure or restriction, your right to complain to the supervisory authority, and any available information about the source. As a rule the reply comes in the form the request arrived in, at no charge, and any step taken on your request is notified in writing (Article 14). Where the authority calls a request manifestly unfounded or excessive, Article 14(7) puts the burden of proving that on the authority.

The limit sits in Article 17. Access may be restricted in whole or in part on the five grounds listed in Article 15(3): avoiding obstruction of investigations or checks, avoiding prejudice to the prosecution or execution of sanctions, public security, national security, and the rights and freedoms of others. A refusal must be in writing and reasoned — but Article 17(4) releases the authority from giving reasons where giving them would itself endanger one of those five aims. An answer of the shape "we cannot tell you, and we cannot tell you why" is therefore within the text.

What you can ask forTodayFrom 17 March 2027Article
Whether a record exists and what is in itNo written procedureConfirmation, access and seven items of informationArt. 16
Who received the dataRecipients, in particular recipients abroadArt. 16(3)
Reasons for a refusalIn writing; reasons may be withheld on the five groundsArt. 17(1)-(4)
What to do when refusedExercise the right through the supervisory authorityArt. 19
ComplaintSupervisory authority informs you within 90 daysArt. 53(2)
SilenceAfter 90 days, administrative court proceedingsArt. 54
Record of who lookedAccess, disclosure and transfer logged with both identitiesArt. 27

Article 19 is the hinge. When the authority will not answer you directly, the right does not disappear; it changes hands. You exercise it through the supervisory authority, which checks on your behalf and must at least tell you that it has carried out the necessary verification or supervision, and inform you of the judicial remedy. You do not see the file. You learn that someone independent has seen it. The authority is separately obliged to tell you this route exists (Article 19(2)).

Chapter V governs data leaving the country, and for a foreign reader it is the hardest part. The general rule stacks four conditions: the transfer must be necessary for the purposes in Article 1; the recipient must be a public authority competent for those purposes in the receiving state; if the data came from an EU member state, onward transfer outside the Union needs that state's prior authorisation; and one of the bases in Articles 38, 39 or 40 must be present (Article 37). Article 41 then builds the exception. In individual and specific cases, where the authority judges that going through the competent authority in the third country would not be effective — because of delay, or because rights could not be exercised — the data may go directly to a private recipient established there. Five conditions apply together and the transfer must be documented. Article 40(2) pushes the other way: in individual cases the data may not be sent where the fundamental rights and freedoms of the person concerned outweigh the public interest in the transfer.

What the text does not say

There is no penalty figure in this statute. Article 58 refers liability and penalties to "the law regulating personal data protection, which applies from the date of the start of application of this law". At the same sitting, on 4 September 2026, the Skupština also adopted the general personal data protection law, and its decree of promulgation was signed on 8 September 2026 (EPA 1164, 106 articles). As at 12 September 2026 the most recent issue of the Službeni list is 132/2026 and that general law is not in it. Because it has not been published, its own dates cannot be calculated. So we cannot show which penalty regime will be running on 17 March 2027.

The second gap is Article 20. Where the data sits in a court decision or in the file of a criminal investigation or proceedings, the rights in Articles 15, 16 and 18 are exercised "in accordance with special regulations" — that is, the Criminal Procedure Code. The text does not say which instrument prevails when the two give different answers. Third, Article 19 opens the route through the supervisory authority without setting a deadline for it; the only period written into the law is the 90 days Article 53 gives for complaints.

One more note. We could not find a footnote in this text citing any EU directive, and in the same gazette issue four statutes carry the Službeni list transposition marker on their titles while this one does not. We therefore do not write that the law transposes a particular directive. We write what it says.

Our reading

After 17 March 2027 we would put the request in writing and cite Article 16 expressly; because the form of the reply follows the form of the request (Article 14(2)), a written request pulls a written answer. If it is refused, ask for two things: a written copy of the decision, and that the factual and legal grounds recorded under Article 17(6) be placed before the supervisory authority. Even where the reasons are withheld from you, that record exists inside the authority and the supervisory body can call for it.

On the corporate side the provision to work with is Article 27. Who looked, when, and who received a copy are answered in the logs, and that is what to ask the supervisory authority to examine. Until that date the practical route is unchanged: if your name is in a file, access runs through criminal procedure and through counsel, not through data protection law.

What did not change

Nothing in the police-data field becomes available in writing before 17 March 2027; until then the general data protection law of 2008 continues to govern. Access to a criminal file still runs through the Criminal Procedure Code, not through this statute (Article 20). The certificate of no criminal record (uvjerenje o nekažnjavanju) is a separate procedure and is not regulated here. Nor does the scope widen: the addressees are the authorities processing for the purposes in Article 1, so an employer's or a bank's processing is not the subject of this text. And three provisions — Article 11(2)-(3), Article 32(7) and Article 50 — will not start on 17 March 2027 either; the law holds them back until the day Montenegro accedes to the European Union (Article 59).

How to verify

The official text sits on the Službeni list site: sluzbenilist.me/propisi/397967. The record number in the top left corner of the first typeset page is 2261, and the text runs to 20 pages. The full issue is in the 132/2026 contents list, where the publication date reads 9 September 2026. The provisions to look for are Articles 16 (access), 17 (restriction), 19 (through the supervisory authority), 27 (logs), 37-41 (transfers), 53-54 (complaint and court) and 59-60 (deferral and entry into force). The parliamentary file number is 23-3/26-13, EPA 1165 XXVIII; the decree number is 01-009/26-1566/2.

The criminal procedure amendment published in the same issue — the rights of a foreign national in custody — is in our note on what changes on 17 September, and the treaty side of police data sharing is in our note on the DNA and fingerprint exchange protocol. If your question is about the commercial regime instead, the law binding your Montenegrin entity until 17 March 2027 is still the 2008 statute we set out in Montenegro is not a GDPR country. Where your name appears in a file and you need to decide who holds the power of attorney, we describe how a matter is set up on our Montenegro lawyer page; when the general law gets its gazette number we will record it under Legal Updates.

Legal basis

  • Zakon o zaštiti podataka o ličnosti koje obrađuju nadležni organi u svrhu sprečavanja, istraživanja, otkrivanja ili gonjenja krivičnih djela ili izvršenja krivičnih sankcijačl. 3, 5, 6, 8, 12, 13, 14, 15, 16, 17, 18, 19, 20, 27, 32, 37, 38, 39, 40, 41, 42, 53, 54, 56, 58, 59, 60Sl. list CG 132/2026, 09.09.2026 (akt 2261)Official text
  • Službeni list Crne Gore, broj 132/2026sadržaj brojaSl. list CG 132/2026, 09.09.2026Official text
  • Ukaz o proglašenju zakona (EPA 1165 XXVIII) — Skupština Crne Gore, 28. sazivbroj 01-009/26-1566/2 · akt 23-3/26-13/10Skupština Crne Gore, 04.09.2026 · ukaz 08.09.2026Official text

Frequently asked questions

Can I write to the Montenegrin police today and ask what they hold on me?

Not on the basis of this law. It enters into force on 17 September 2026 but applies only from 17 March 2027 (Article 60). Until then the access procedure in Article 16 does not operate.

If my request is refused, will I be told why?

As a rule yes: the refusal must be in writing and reasoned (Article 17(1)). The exception is wide. Where giving the reasons would endanger an investigation, public security, national security or the rights of others, the authority does not have to give them (Article 17(4)). Even then it must remind you of the complaint and the judicial remedy (Article 17(5)), and it must record the factual and legal grounds and hand them to the supervisory authority on request (Article 17(6)).

Can my data in Montenegro be sent to the police in my own country?

The text treats this as a list of conditions rather than a prohibition. On the main route the recipient must be a public authority competent for the same purposes in that state (Article 37(1), item 2). If the data was received from an EU member state, onward transfer outside the Union needs that state's prior authorisation (Article 37(1), item 3). Where there is no adequacy decision, either a legally binding instrument with safeguards or the authority's own assessment applies, and the transfer is documented (Article 39).

Can it go to someone who is not a state body?

Article 41 allows that in individual and specific cases only. Five conditions apply together, one of them being an assessment that routing the data through the competent authority in that country would not be effective because of delay or because rights could not be exercised. The recipient must be told the purpose for which the data may be processed, and the supervisory authority must be informed of transfers made.

What happens if nobody answers my complaint?

The supervisory authority must inform you about the course of the procedure and the decision within 90 days at the latest (Article 53(2)). Failure to do so within that period is itself a ground for going to the administrative court (Article 54). You may also authorise a not-for-profit body active in data protection to bring the complaint on your behalf (Article 56).

Is there a record of who opened my file?

In automated systems, yes. Article 27 requires logging of collection, alteration, access, disclosure, transfer, combination and erasure, and the log must contain the justification for the operation, its date and time, the identity of the person who consulted, entered, altered or disclosed the data, and the identity of the recipient. Those logs go to the supervisory authority on request.