Operate Montenegro PDPL governance structure including DPO designation + ROPA + DPIA + Codes of Conduct + sub-regulations. DPO mandatory for public authorities + bodies whose core activities consist of large-scale regular and systematic monitoring + bodies whose core activities consist of large-scale processing of sensitive data + bodies whose processing likely to result in high risk (GDPR Article 37 alignment). DPO independent + reports to highest management + contact published + AZLP notification. ROPA under GDPR Article 30 alignment in Montenegrin or English covering controller and processor activities. DPIA under GDPR Article 35 for high-risk processing including large-scale sensitive + systematic monitoring of public areas + profiling presenting significant risk + AI/ML processing with significant individual impact + AZLP consultation under Article 36 for unmitigated high residual risk. Codes of Conduct registered with AZLP for sectors (banking + insurance + telecommunications + healthcare + tourism). Certification mechanisms via accredited certification bodies. Sub-regulations and bylaws issued by AZLP and Ministry providing operational detail. Privacy by Design under AZLP guidance.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.