Data protection in Montenegro — RoNa Legal service hero

Technology & Innovation

Data Protection in Montenegro

Montenegro data protection compliance: filing systems, permits, cross-border transfers, and the replacement bill now in parliamentary procedure.

Updated ·

What this page decides

A foreign group that opens something in Montenegro — a subsidiary, a development office, a hotel, a payroll of ten — usually carries its GDPR file across the border and assumes it does the job. It does not, and it fails in two directions at once.

It fails downward, because the General Data Protection Regulation is not Montenegrin law and the Montenegrin supervisory authority does not enforce it. Your local entity is bound by the Zakon o zaštiti podataka o ličnosti, "Službeni list Crne Gore" br. 079/08, 070/09, 044/12, 022/17 and 077/24 of 5 August 2024 — a 2008 statute built on the pre-GDPR European model. It requires things GDPR abolished, and it does not require several things your GDPR programme is built around.

It fails upward, because GDPR can still reach a Montenegrin company under its own Article 3(2), and because Montenegro is not on the European Commission's adequacy list — so an EU parent cannot send personal data to its Montenegrin subsidiary the way it sends data to Dublin.

This page gives the article numbers on the Montenegrin side, and it says plainly where the ground is currently moving. Scope: the article-level treatment below is Montenegrin. Our Türkiye practice handles the Turkish side of a cross-border data file; we do not state Turkish statute on this page, because a page that mixes two regimes without citing either causes the mistake it is meant to prevent. General information on Montenegrin and EU law, not advice on a specific processing operation.

The statute in force, and the bill that is in Parliament right now

Two facts have to be held at the same time, and most published guidance holds only one of them.

The Act in force is still the 2008 Act. The supervisory authority's own list of applicable regulations, read on 8 September 2026, still names the Zakon o zaštiti podataka o ličnosti and links to the consolidated 2024 text. No successor act appears on that list. The same list carries the newer Freedom of Information Act ("Službeni list CG" br. 160/25 of 30 December 2025), so it is a maintained list rather than a stale page.

A replacement is in parliamentary procedure. The Government's Predlog zakona o zaštiti podataka o ličnosti (parliamentary file EPA 1164 XXVIII, act no. 23-3/26-12) was published on 10 August 2026 and its document record was last updated on 8 September 2026. A second, separate bill covering processing by competent authorities for criminal-law purposes was published on the same date.

The distance between those two facts is where the planning question sits. Nothing in the bill binds you today. Everything you build against the 2008 Act between now and adoption has a defined shelf life, and one transitional rule already visible in the file will reach back to permits you hold now.

What is actually moving, checked 8 September 2026

The bill's own text is published as a scanned image with no machine-readable text layer, so we make no claim about provisions we could not read. The amendment documents are machine-readable, and we read them. What follows comes from those documents only.

DocumentDateWhat it shows
Predlog zakona o zaštiti podataka o ličnosti (EPA 1164 XXVIII)published 10.08.2026, record updated 08.09.2026The replacement bill is in parliamentary procedure
Government amendments to the billdelivered to Parliament 31.08.2026First amendment set
Proposal to withdraw those amendments from parliamentary procedure01.09.2026Withdrawn after legal-technical suggestions from the Legislative Committee
Replacement set of 70 amendments01.09.2026The set now before Parliament

Three things in that amendment set matter to a company planning compliance work, and each is quoted from the amendment document rather than inferred.

The article numbering is not stable. Amendment 1 inserts a new article after Article 3 and Amendment 2 renumbers the articles that follow; a long tail of the remaining amendments does nothing but move cross-references. Any compliance note written today against a bill article number will cite the wrong number after adoption.

There is a six-month runway. Amendment 70 rewrites the commencement wording in Article 95 of the bill so that the law "shall apply after six months from the day of its entry into force". If the bill is adopted in this form, publication in the gazette does not start the obligations — a separate six-month clock does.

Consents already issued are inside the transition. Amendment 67 rewrites Article 90(1) of the bill so that the supervisory body re-examines consents within one year of entry into force. Which consents that transitional article reaches is stated in the part of the bill we could not read, so we do not put a category on it here — but if your Montenegrin operation holds a consent issued by the current Agency, plan on it being looked at again rather than carried over untouched.

The direction of the bill is a genuine GDPR transposition rather than a patch. Amendment 3 aligns the definition of an enterprise with Article 4(18) of Regulation (EU) 2016/679; Amendment 39 adds approved codes of conduct and approved certification mechanisms to the list of transfer safeguards, mirroring GDPR Article 46(2)(e) and (f); the supervisory measures in Article 86 of the bill read like GDPR Article 58(2), including an express power to order a controller to notify individuals of a personal data breach — a duty the Act in force does not impose at all.

What we did not verify, and will not assert. We could not confirm from a primary source whether Parliament has voted on the bill, and no gazette publication of a new data protection act had appeared on the supervisory authority's list of applicable regulations when we read it on 8 September 2026. Treat the bill as a bill. Before anyone in your organisation relies on an article number from it, confirm the gazette issue.

The four obligations a GDPR programme does not generate

Under the Act in force, four duties have no GDPR equivalent, which is exactly why a GDPR audit does not find them missing.

Notification before you start (Article 27(1)). A controller must notify the supervisory authority before establishing an automated personal data filing system, and again on any significant change. The content is set by Article 26(2): the name of the filing system, the legal basis, the controller's identity and seat, the purpose, the categories of data subjects, the types of data, the retention and use period, the recipients, the details of any transfer out of Montenegro, and the controller's internal processing and protection rules. Failing to notify is a misdemeanour under Article 74(1)(9). GDPR replaced this regime with internal record-keeping; Montenegro kept it, and the Register is live infrastructure.

A permit for risky processing (Article 28). Prior consent of the authority is required for automated processing presenting a special risk — special categories of data, data used to assess personality, ability or behaviour, video surveillance of public areas, and biometric data. Article 28(2) then disapplies that where processing rests on a law, on the data subject's consent, or on the necessity of performing a contract with them. That carve-out absorbs a great deal of ordinary commercial processing, and it is the first thing to test before assuming a permit is needed.

A responsible person on a headcount test (Article 27(3)). Once an automated filing system exists, the controller designates a person responsible for data protection — with an exemption for controllers having fewer than 10 staff who process personal data. That is a bright line, not GDPR's risk-and-scale assessment, and it cuts both ways: a twelve-person office doing mundane processing needs the appointment, a five-person office doing sensitive work does not.

A ten-year register of recipients (Article 19). Every third party given personal data, what was given, the purpose, the legal basis and the period of use — kept for ten years under Article 19(2). Most groups hold nothing in that form. Failing to keep it is a misdemeanour under Article 74(1)(6).

The clocks and ceilings that go with them:

ObligationLimitProvision
Answer a request for an information notice15 daysArt. 43(1)
Complete, correct or erase data on request15 daysArt. 44(1)
Tell the person and the recipients what you changed8 daysArt. 44(2)
Keep video surveillance footage6 months maximumArt. 37(3)
Keep entry and exit records1 year maximumArt. 34(4)
Keep the register of third-party disclosures10 years, then deleteArt. 19(2)
Person responsible for data protectionRequired unless fewer than 10 processing staffArt. 27(3)
Fine range, legal person€500 to €20,000Art. 74(1)

The full comparison against GDPR, provision by provision, is in Montenegro is not a GDPR country.

The filing chain, in the order the Agency expects it

Registration as a controller is not notification of processing. They are separate steps and foreign groups routinely do the first and stop.

  1. Register the company as a controller, through Montenegro's eGovernment portal. The procedure is hybrid: run the electronic service, then print the submitted form, certify it with the company stamp and deliver it by post to the authority's archive. The submission is complete when the paper copy is matched against the electronic one, not when the portal says sent. Approval shows as ODOBREN.
  2. Notify each filing system separately under Article 27(1), on the prescribed form, with the Article 26(2) content. Your HR, payroll, attendance, CRM and applicant systems are each capable of being a separate filing system.
  3. Write the internal rule required by Article 26(2)(10). It is the first document requested in a permit application and the document a supervision starts from. Around it sit Article 24(1)–(2) security measures, the Article 24(3) automatic logging duty in electronic systems, the Article 24(4) determination of who may access what, and the Article 25 duty of secrecy on staff.
  4. Apply for the camera consent, if you have cameras, with the document set the authority expects.
Document required with a video surveillance consent applicationAnchored in
Internal rule on the protection of personal dataArt. 26(2)(10)
Decision introducing video surveillanceArt. 35(2)–(3), Art. 36(3)
Opinion or statement of the trade union or the employees' representativeArt. 36(4)
Filing-system record for video surveillance, on the prescribed formArt. 26–27
Information on the general characteristics of the camerasArt. 28 assessment

The third row is the one a GDPR programme never produces. Where there is no trade union in the Montenegrin entity, the employees' representative gives the opinion — and it must come before the decision to introduce surveillance is taken, so the sequence is as auditable as the content. Two further provisions catch groups that install first: Article 35(6) prohibits access to entrance surveillance footage through internal or public cable television, the internet or other electronic communications means, at the moment of recording or afterwards; and Article 36(2) prohibits workplace surveillance outside the workplace altogether, naming changing rooms, lifts, sanitary facilities and areas intended for clients and visitors.

Also note that the Register is public: Article 29 has the authority keep it and Article 30 makes its entries available to the public. What you write in the purpose and data-type fields is a published description of your processing. The mechanics, forms and figures are set out in what a foreign company must actually file.

Sending data out — and the outsourcing sentence most files miss

Article 41(1) makes transfer of personal data out of Montenegro subject to the prior consent of the supervisory authority, and Article 41(2) sets out how adequacy is judged: on the concrete circumstances of the transfer, taking into account the nature of the data, the purpose and duration of the processing, the states of origin and destination, the law in force in the destination state, and the professional rules and security measures observed there. There is no Montenegrin equivalent of an adequacy decision a company can simply point to.

Article 42 then lists nine exemptions. Two carry almost all corporate traffic: Article 42(6), transfers to EU and EEA member states or to states on the EU adequacy list, and Article 42(8), a contract containing the contractual obligations accepted by EU member states — in practice the standard contractual clauses — concluded with a processor in a non-EU state.

Then comes the provision that changes the answer for outsourcing. Article 41(3) provides that for a transfer made in order to entrust processing operations within the meaning of Article 16, the authority's consent is necessary except in the case referred to in Article 42 point 6. On a literal reading it carves out one exemption, not the list — so the standard-contractual-clauses route in Article 42(8) is not among the exceptions it names, even though Article 42(8) is itself written about a contract with a processor in a non-EU state.

We are not going to tell you the question is settled, because it is not. What can be said is what the text says and what the enforcement record shows: the authority issued three transfer consents in the whole of 2024, which is not the profile of a market applying for a permit every time it uses a non-EU processor. The workable response is to sort outbound flows by destination and by role, and to record the reasoning before the data moves:

  • Processor in the EU, EEA or an adequacy-listed state — inside Article 41(3)'s own carve-out. No permit question.
  • Processor anywhere else — the literal reading requires consent. Document the clauses, document the Article 42(8) analysis, and take the filing decision deliberately, recognising that Article 71 lets the authority prohibit the transfer outright.
  • Counterparty acting as controller, not processor — Article 41(3) does not apply; the ordinary Article 41(1) rule and the full Article 42 list do.

One trap sits next to this. Article 74(1)(5) makes it a misdemeanour to entrust processing to a processor not registered for the activity of personal data processing, or one that does not meet the technical, staffing and organisational conditions. That requirement has no GDPR analogue and is resolved before a payroll bureau, HR platform or offshore processing arrangement is signed. The full analysis is in sending data out of Montenegro, and the contract mechanics in our IT and technology law practice.

Data coming in: there is no adequacy decision

For data moving from an EU establishment to a Montenegrin one, the analysis is ordinary GDPR Chapter V, with the unhelpful feature that Montenegro is not among the jurisdictions the European Commission has recognised as adequate. An intra-group flow into a Montenegrin subsidiary is therefore a third-country transfer requiring an Article 46 safeguard — in practice the standard contractual clauses supported by a transfer impact assessment of Montenegrin law. The Article 49 derogations are drafted for occasional and non-repetitive situations and are not a basis for a standing payroll, CRM or ticketing flow.

A transfer impact assessment written honestly says both halves. Present: an independent supervisory authority with binding powers, judicial review by administrative dispute, and a statutory damages route. Thinner than an EU reviewer expects: no general breach-notification duty in the Act in force, and a fine ceiling of €20,000. Intra-group flows into a Montenegrin entity are the single most common thing we see left undocumented, because the subsidiary feels internal.

The HR file: two statutes, two regulators

An employer in Montenegro holds one HR file governed by two statutes with two fine ranges. The Zakon o radu states the privacy duty in Article 19(1)(10) and does not penalise it; enforcement comes from the data protection Act and its Article 74 range. Four provisions decide how the HR system is configured, and none of them is about the privacy notice:

  • Article 14 allows processing relating to criminal offences, imposed criminal and misdemeanour penalties or security measures only by, or under the supervision of, the competent state authority. That is narrower than GDPR Article 10, so a group background-screening policy does not transfer unexamined.
  • Article 15a prohibits decisions on a person's rights, obligations and interests that assess personal characteristics and abilities — it names work performance, reliability, creditworthiness and behaviour — from being based solely on automated processing, with narrow exceptions. Article 43(2)(7) then requires the controller to state the manner of that automated processing on written request within 15 days, which is a constraint on model choice rather than a disclosure formality.
  • Article 9(6) requires consent to be given in writing or orally on the record. A tick-box in an HR portal is not that — which matters less than it looks, because most employment processing runs on statutory obligation rather than consent, and employers who reach for consent inherit a formality problem they did not need.
  • Article 13(2) requires special categories to be specially marked and protected against unauthorised access. Union membership lists kept for dues deduction sit inside this. So does the occupational health file.

The recruitment side changed separately on 23 April 2026, when an amendment to the Zakon o radu rewrote what an employer may ask a candidate — including pay history. That analysis, and the record-keeping duties that sit beside it, are in what a Montenegrin employer may ask, must record and cannot keep and the employer labour law and payroll guide. Where hiring is cross-border, the permit chain is in the work permit guide for employers.

What happens when someone complains

Your realistic exposure is not a scheduled inspection. In 2024 the authority carried out 101 supervisions and states that none were routine planned audits: 34 followed requests for protection of rights and 62 followed initiatives to open a supervision. Under Article 65 anyone may file such an initiative, and the authority publishes the form.

StageRule
Anyone files an initiative; supervision runs ex officioArt. 65
Inspector accesses data, files and systems — registered or not, regardless of secrecy classificationArt. 66
Controller must enable access and hand over documentsArt. 67
Minutes issued within 15 days — or 8 days where triggered by a rights requestArt. 68(1)–(2)
Objection to the authority8 days from receiving the minutes (Art. 68(3))
Objection unfounded, measures imposed and misdemeanour proceedings requestedArt. 69
Decision on a request for protection of rights60 days (Art. 47(2))
Challenge to the authority's decisionAdministrative dispute (Art. 47(5), Art. 72)

Two features are the opposite of what a GDPR-trained team expects. The authority does not fine you: under Article 69 it imposes measures and separately files a request to open misdemeanour proceedings, and the Article 74 penalty is imposed by a court. There is no administrative fining power to negotiate with. And the measures bite harder than the fine: Article 71 lets the authority order irregularities remedied within a deadline, temporarily prohibit unlawful processing, order deletion of data collected without legal basis, prohibit transfer out of Montenegro or disclosure to recipients, and prohibit entrusting processing to a processor that does not meet the conditions. For an operating business, an order stopping a data flow is a materially larger event than a €20,000 ceiling.

What we do

We map your Montenegrin processing once and run it against both regimes at the same time: what has to be notified under Article 27, what needs an Article 28 permit or sits inside the Article 28(2) carve-out, what the surveillance decision, the employee-representative opinion and the signage must say and in what order, how your retention periods sit against the statutory ceilings, which Article 42 exemption carries each outbound flow, and what safeguard the EU parent needs for the inbound one.

We also read the transition, rather than the marketing version of it: which of your filings and consents will be re-examined if the bill in Parliament is adopted, and which parts of your file are worth building now against the Act in force.

Where the same facts raise a technology or a model question, that work sits with our IT and technology law and AI law practices; regulated financial entities carry a separate ICT resilience layer covered in fintech and crypto. If the entity is still being formed, start with company formation in Montenegro; the governance questions behind it are on our corporate law page.

If you operate, or are about to open, a Montenegrin entity, send us your processing inventory, your draft internal rule, your camera plan and your intra-group transfer agreements, and we will tell you what has to be filed, in what order, and what is missing from the file before someone else reads it.

Sources and currency

Statutory references are to the consolidated Zakon o zaštiti podataka o ličnosti ("Službeni list CG" br. 079/08, 070/09, 044/12, 022/17, 077/24 of 5 August 2024). The supervisory authority's list of applicable regulations was read on 8 September 2026 and still names that Act with no successor. The parliamentary status of the replacement bill, the Government's withdrawal document and the set of 70 amendments were read from the Government's own document library on the same date; the bill's substantive text is published as a scanned image without a text layer and is not analysed here. Supervision, consent and transfer figures are the authority's own for 2024, published in its annual report in March 2025 and read on 25 August 2026 — treat them as a year old. The European Commission adequacy list was read on 25 August 2026. Confirm any figure or article number against the gazette before relying on it in a document you are signing.

Frequently asked questions

Does GDPR apply to our Montenegrin entity?

Not as domestic law. Montenegro is not an EU or EEA member and the Montenegrin supervisory authority enforces the Zakon o zaštiti podataka o ličnosti (Sl. list CG 079/08, 070/09, 044/12, 022/17, 077/24 of 5 August 2024), not the Regulation. GDPR can still reach the same company directly under its own Article 3(2) where it offers goods or services to people in the EU or monitors their behaviour there. For most groups both regimes apply to different parts of one operation, and the Montenegrin half asks questions a GDPR file was never built to answer.

Is the law about to change, and should we wait for it?

A replacement is in parliamentary procedure. The Government's Predlog zakona o zaštiti podataka o ličnosti (file EPA 1164 XXVIII) was published on 10 August 2026, and a set of 70 Government amendments was filed on 1 September 2026 after an earlier set was withdrawn following the Legislative Committee's legal-technical suggestions. Read on 8 September 2026, the supervisory authority's own list of applicable regulations still names the 2008 Act with no successor, and we did not verify a plenary vote either way. Two features of the amendment set matter for planning: the article numbering shifts, so anything drafted today against a bill article number will cite the wrong number after adoption; and the amended commencement wording provides that the law applies six months after entry into force. Waiting is not the same as being ready.

Do we have to register our processing with the authority?

Yes, and in two separate steps that are often confused. The company is first registered as a controller through the eGovernment portal, with a paper step in the middle: the submitted form is printed, certified with the company stamp and posted to the authority, which matches it against the electronic submission. Separately, Article 27(1) requires the controller to notify the supervisory authority before establishing each automated personal data filing system, and again on any significant change, with the content set by Article 26(2). Registering the controller notifies no processing at all. Failure to notify is a misdemeanour under Article 74(1)(9), and the Register itself is public under Articles 29 and 30.

When do we need prior consent rather than a notification?

Article 28(1) requires the authority's prior consent for automated processing presenting a special risk, naming special categories of data, data used to assess personality, ability or behaviour, video surveillance of public areas, and biometric data. Article 28(2) then disapplies that requirement where processing rests on a law, on the data subject's consent, or on the necessity of performing a contract with the data subject — a carve-out that absorbs a great deal of ordinary commercial processing, so it is tested before a permit is assumed. In practice the permit traffic is cameras: all 74 consents the authority issued in 2024 were consents for introducing video surveillance, and the application has to carry the internal rule, the decision, the trade union or employees' representative opinion taken before that decision (Article 36(4)), the filing-system record and information on the cameras.

Do we need a data protection officer in Montenegro?

Article 27(3) requires a controller to designate a person responsible for data protection once an automated filing system is established, and exempts controllers having fewer than 10 staff who process personal data. That is a headcount test rather than GDPR's risk-and-scale test, so the answer can differ from your GDPR analysis in either direction: a twelve-person office doing mundane processing needs the appointment, a five-person office doing sensitive work does not.

What is the maximum fine, and who imposes it?

Article 74(1) sets €500 to €20,000 for a legal person. The authority does not impose it: under Article 69, where an objection to the minutes of a supervision is unfounded, the authority imposes measures and separately files a request to open misdemeanour proceedings, and the fine is imposed by a court in those proceedings. There is no administrative fining power to negotiate with. For a running business the measures usually matter more than the ceiling — Article 71 lets the authority order irregularities remedied within a deadline, temporarily prohibit unlawful processing, order deletion of data collected without legal basis, prohibit transfer out of Montenegro or disclosure to recipients, and prohibit entrusting processing to a processor that does not meet the conditions.

Can we send personal data to a processor outside Montenegro?

Article 41(1) makes transfer abroad subject to the authority's prior consent, and Article 42 lists nine exemptions — in practice Article 42(6) for EU and EEA states and states on the EU adequacy list, and Article 42(8) for a contract carrying the contractual obligations accepted by EU member states with a processor in a non-EU state. Outsourcing is the complication. Article 41(3) provides that a transfer made in order to entrust processing operations requires consent except in the case referred to in Article 42 point 6 — on a literal reading, one exemption rather than the list, which leaves the standard-clauses route outside its carve-out. The question is not settled: the authority issued only three transfer consents in the whole of 2024. Sort your flows by destination and by role, record which provision each one relies on, and note separately that Article 74(1)(5) makes it a misdemeanour to entrust processing to a processor not registered for the activity of personal data processing.

Can our EU parent send data to the Montenegrin subsidiary?

Only with a GDPR transfer safeguard. Montenegro is not on the European Commission's adequacy list, so this is a third-country transfer requiring an Article 46 mechanism — in practice the standard contractual clauses supported by a transfer impact assessment of Montenegrin law. The Article 49 derogations are drafted for occasional and non-repetitive situations and do not carry a standing payroll, CRM or ticketing flow. This is the direction groups most often leave undocumented, because the subsidiary feels internal. An honest assessment states both halves: an independent supervisory authority with binding powers, judicial review by administrative dispute and a statutory damages route on one side; no general breach-notification duty in the Act in force and a €20,000 fine ceiling on the other.

Get Expert Advice

Initial assessment within the same business day.

or

Reachable via WhatsApp