Montenegro Law on Personal Data Protection (2026)
Chapter IV: controller and processor, security, breach, impact assessment, DPO (Articles 25 to 44) – Montenegro Law on Personal Data Protection (2026)

Montenegro Law on Personal Data Protection (2026) 29(3): Article 29(3) and the paragraphs on form and standard clauses: the controller-processor contract

Processing by a processor must be governed by a written contract or legal act (electronic form allowed) setting out the subject matter, duration, nature and purpose, type of data, categories of data subjects and the controller's rights and obligations, and requiring the processor to process only on documented instructions (including on transfers abroad, unless the law requires otherwise with prior notice), ensure confidentiality commitments of authorised persons, take all Article 33 security measures, respect the sub-processor conditions, assist with data subject rights and with Articles 33 to 37, delete or return all data at the end of services and delete copies, and make available all information needed to demonstrate compliance and allow and contribute to audits and inspections. The processor must immediately tell the controller if an instruction infringes the Law. Standard contractual clauses adopted by the Agency may be used.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Chapter IV: controller and processor, security, breach, impact assessment, DPO (Articles 25 to 44) – Montenegro Law on Personal Data Protection (2026)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.