Montenegro Law on Personal Data Protection (2026)
Chapter IV: controller and processor, security, breach, impact assessment, DPO (Articles 25 to 44) – Montenegro Law on Personal Data Protection (2026)

Montenegro Law on Personal Data Protection (2026) 35: Article 35: tell data subjects of a high-risk breach

Where a breach is likely to result in a high risk to individuals, the controller must inform the data subjects without undue delay, in clear and plain language, with at least the contact point, likely consequences and measures taken. This is not required where the data was rendered unintelligible (for example encrypted), subsequent measures mean the high risk is no longer likely, or it would involve disproportionate effort (then a public communication or equally effective measure is used). The Agency may require the communication.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Chapter IV: controller and processor, security, breach, impact assessment, DPO (Articles 25 to 44) – Montenegro Law on Personal Data Protection (2026)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.