Montenegro Law on Personal Data Protection (2023)
Montenegro's Law on Personal Data Protection (Official Gazette No. 44/2023), effective August 2023, replaces the 2008 law and is fully aligned with the EU GDPR. The Agency for Personal Data Protection and Free Access to Information oversees enforcement. The new law incorporates GDPR principles, data subject rights, DPO requirements, DPIA, breach notification, and GDPR-level administrative fines. Enacted as part of Montenegro's advanced EU accession negotiations (Chapter 23 — Judiciary and Fundamental Rights).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Chapter I — General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Legal Recognition of Data Messages |
| Art.1 | Purpose |
| Art.2 | Definitions |
| Art.3 | Cybersecurity Policy |
| Art.4 | Credit Information Business Licensing |
| Art.8 | Prohibited Acts |
| HUN-1 | Purpose and Scope |
| HUN-2 | Definitions |
| HUN-3 | Fundamental Rules |
| URY-1 | Fundamental Right (Article 1) |
| URY-2 | Scope and Definitions (Article 2–4) |
Chapter II — Principles and Conditions for Processing
| Code | Title |
|---|---|
| Art. 13 | Data Security and Privacy |
| Art. 15 | Cybersecurity Requirements |
| Art. 5 | Legal Recognition of Data Messages |
| Art. 8 | Data Categories |
Chapter III — Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 14 | Direct Data Flows |
| Art. 16 | Data Quality |
| Art. 17 | Governance Structure |
| Art. 18 | Central Bank Supervision |
| Art. 19 | Consent Management Controls |
| Art. 20 | Executive Accountability |
| Art. 21 | Administrative Sanctions |
| Art. 23 | Transitional Provisions |
| Art. 25 | Criminal Penalties |
| URY-7 | Right of Access (Article 13) |
| URY-8 | Right of Rectification (Article 15) |
| URY-9 | Right of Deletion (Article 15) |
Chapter IV — Controller and Processor Obligations
| Code | Title |
|---|---|
| Art. 30 | Privacy Policy |
| Art. 35 | Right of Access |
| Art. 38 | Processing in Employment Context |
| Art. 40 | Establishment and Composition |
| Art. 42 | Processing for Archiving Purposes |
| Art. 45 | Data Protection Officer |
Chapter V — Transfer of Personal Data
| Code | Title |
|---|---|
| Art. 29 | Safety Measures |
| Art. 30 | Privacy Policy |
| Art. 50 | Right to Compensation |
| Art. 52 | Appropriate Safeguards |
Chapter VI — Agency for Personal Data Protection
| Code | Title |
|---|---|
| Art. 55 | Repeal of Prior Law |
| Art. 60 | Initiation of Proceedings |
| Art. 67 | Inspection Powers |
Chapter VII — Criminal and Administrative Penalties
| Code | Title |
|---|---|
| Art. 70 | Criminal Penalties for False Consent |
| Art. 73 | Administrative Fines |
| Art. 75 | Administrative Fines |
Maps to 591 other frameworks
Frequently Asked Questions
What is Montenegro Law on Personal Data Protection (2023)?
Montenegro Law on Personal Data Protection (2023) is a compliance framework from Montenegro with 7 domains and 47 controls. Montenegro's Law on Personal Data Protection (Official Gazette No. 44/2023), effective August 2023, replaces the 2008 law and is fully aligned with the EU GDPR. The Agency for Personal Data Protection and Free Access to Information oversees enforcement. The new law incorporates GDPR principles, data subject rights, DPO requirements, DPIA, breach notification, and GDPR-level administrative fines. Enacted as part of Montenegro's advanced EU accession negotiations (Chapter 23 — Judiciary and Fundamental Rights). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Montenegro Law on Personal Data Protection (2023) have?
Montenegro Law on Personal Data Protection (2023) has 47 controls organised across 7 domains. The largest domains are Chapter I — General Provisions (15 controls), Chapter III — Rights of Data Subjects (12 controls), Chapter IV — Controller and Processor Obligations (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Montenegro Law on Personal Data Protection (2023) map to?
Montenegro Law on Personal Data Protection (2023) maps to 591 other compliance frameworks. The top mapping partners are Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) (47% coverage), BS 65000:2014 — Guidance on Organizational Resilience (47% coverage), China Personal Information Protection Law (PIPL) (44% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Montenegro Law on Personal Data Protection (2023) compliance?
Start your Montenegro Law on Personal Data Protection (2023) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Montenegro Law on Personal Data Protection (2023) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 47 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required