Montenegro Law on Personal Data Protection (2026)
Chapter IV: controller and processor, security, breach, impact assessment, DPO (Articles 25 to 44) – Montenegro Law on Personal Data Protection (2026)

Montenegro Law on Personal Data Protection (2026) 36: Article 36: data protection impact assessment

Where processing, particularly with new technologies, is likely to result in a high risk, the controller must assess its impact before processing, seeking the DPO's advice where designated; an assessment is required in particular for systematic and extensive automated evaluation including profiling with legal or similarly significant effects, large-scale special category or criminal data, and large-scale systematic monitoring of publicly accessible areas, and for processing on the Agency's published list. It contains at least a systematic description and purposes, an assessment of necessity and proportionality, an assessment of the risks, and the measures to address them. Compliance with approved codes counts; the views of data subjects are sought where appropriate; one assessment may cover similar operations; and the controller reviews whether processing follows the assessment, at least when the risk changes. No assessment is needed where a law regulating the specific processing was already accompanied by a general impact assessment, unless one is still considered necessary.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Chapter IV: controller and processor, security, breach, impact assessment, DPO (Articles 25 to 44) – Montenegro Law on Personal Data Protection (2026)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.