Montenegro Law on Personal Data Protection (2023)
Montenegro's Law on Personal Data Protection (Official Gazette No. 44/2023), effective August 2023, replaces the 2008 law and is fully aligned with the EU GDPR. The Agency for Personal Data Protection and Free Access to Information oversees enforcement. The new law incorporates GDPR principles, data subject rights, DPO requirements, DPIA, breach notification, and GDPR-level administrative fines. Enacted as part of Montenegro's advanced EU accession negotiations (Chapter 23 — Judiciary and Fundamental Rights).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Chapter I — General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art.1 | Purpose of the Law |
| Art.2 | Scope |
| Art.3 | Definitions |
| Art.4 | Principles for Data Processing |
| Art.8 | Rights of Data Subjects |
| HUN-1 | Purpose and Scope |
| HUN-2 | Definitions |
| HUN-3 | Fundamental Rules |
| URY-1 | Fundamental Right (Article 1) |
| URY-2 | Scope and Definitions (Article 2–4) |
Chapter II — Principles and Conditions for Processing
| Code | Title |
|---|---|
| Art. 13 | Transparency and Provision of Information to Deployers |
| Art. 15 | Accuracy, Robustness and Cybersecurity |
| Art. 5 | Prohibited AI Practices |
| Art. 8 | Compliance with the Requirements |
Chapter III — Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 14 | Human Oversight |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 17 | Quality Management System |
| Art. 18 | Documentation Keeping |
| Art. 19 | Automatically Generated Logs |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 21 | Cooperation with Competent Authorities |
| Art. 23 | Transitional Provisions |
| Art. 25 | Criminal Penalties |
| URY-7 | Right of Access (Article 13) |
| URY-8 | Right of Rectification (Article 15) |
| URY-9 | Right of Deletion (Article 15) |
Chapter IV — Controller and Processor Obligations
| Code | Title |
|---|---|
| Art. 30 | Privacy Policy |
| Art. 35 | Right of Access |
| Art. 38 | Processing in Employment Context |
| Art. 40 | Establishment and Composition |
| Art. 42 | Processing for Archiving Purposes |
| Art. 45 | Data Protection Officer |
Chapter V — Transfer of Personal Data
| Code | Title |
|---|---|
| Art. 29 | Application of a Conformity Assessment Body for Notification |
| Art. 30 | Privacy Policy |
| Art. 50 | Transparency Obligations for Providers and Deployers of Certain AI Systems |
| Art. 52 | Procedure |
Chapter VI — Agency for Personal Data Protection
| Code | Title |
|---|---|
| Art. 55 | Obligations for Providers of General-Purpose AI Models with Systemic Risk |
| Art. 60 | Initiation of Proceedings |
| Art. 67 | Inspection Powers |
Chapter VII — Criminal and Administrative Penalties
| Code | Title |
|---|---|
| Art. 70 | Criminal Penalties for False Consent |
| Art. 73 | Reporting of Serious Incidents |
| Art. 75 | Administrative Fines |
Data Lifecycle
| Code | Title |
|---|---|
| ME-DPA-13 | Retention and Erasure |
Employment
| Code | Title |
|---|---|
| ME-DPA-14 | Employee Personal Data Processing |
Enforcement
| Code | Title |
|---|---|
| ME-DPA-16 | Sanctions and Misdemeanour Penalties |
Governance
| Code | Title |
|---|---|
| ME-DPA-08 | Appointment of Data Protection Officer |
Incident Response
| Code | Title |
|---|---|
| ME-DPA-07 | Personal Data Breach Notification |
Individual Rights
| Code | Title |
|---|---|
| ME-DPA-03 | Data Subject Rights |
International Transfers
| Code | Title |
|---|---|
| ME-DPA-05 | Cross Border Data Transfer |
Lawfulness
| Code | Title |
|---|---|
| ME-DPA-01 | Lawful Basis for Processing |
Marketing
| Code | Title |
|---|---|
| ME-DPA-11 | Direct Marketing Restrictions |
Processor Management
| Code | Title |
|---|---|
| ME-DPA-12 | Processor Engagement Contract |
Regulator Engagement
| Code | Title |
|---|---|
| ME-DPA-15 | Supervision and Inspection by the Agency |
Regulator Notification
| Code | Title |
|---|---|
| ME-DPA-04 | Notification of Processing to the Agency |
Security
| Code | Title |
|---|---|
| ME-DPA-06 | Data Security Measures |
Sensitive Data
| Code | Title |
|---|---|
| ME-DPA-02 | Special Categories of Personal Data |
| ME-DPA-10 | Biometric Data Processing |
Strategic Alignment
| Code | Title |
|---|---|
| ME-DPA-17 | Alignment with EU GDPR for Accession Track |
Surveillance
| Code | Title |
|---|---|
| ME-DPA-09 | Video Surveillance and CCTV |
Your Compliance Coverage
If you comply with Montenegro Law on Personal Data Protection (2023), you already cover:
EU AI Act
35%
22 controls mapped
Compare →Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014)
34%
21 controls mapped
Compare →NIS2 Directive
34%
21 controls mapped
Compare →+ 614 more: DORA (34%), BS 65000:2014 — Guidance on Organizational Resilience (34%)
See all 617 mapped frameworks ↓Maps to 617 other frameworks
Frequently Asked Questions
What is Montenegro Law on Personal Data Protection (2023)?
Montenegro Law on Personal Data Protection (2023) is a compliance framework from Montenegro with 23 domains and 64 controls. Montenegro's Law on Personal Data Protection (Official Gazette No. 44/2023), effective August 2023, replaces the 2008 law and is fully aligned with the EU GDPR. The Agency for Personal Data Protection and Free Access to Information oversees enforcement. The new law incorporates GDPR principles, data subject rights, DPO requirements, DPIA, breach notification, and GDPR-level administrative fines. Enacted as part of Montenegro's advanced EU accession negotiations (Chapter 23 — Judiciary and Fundamental Rights). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Montenegro Law on Personal Data Protection (2023) have?
Montenegro Law on Personal Data Protection (2023) has 64 controls organised across 23 domains. The largest domains are Chapter I — General Provisions (15 controls), Chapter III — Rights of Data Subjects (12 controls), Chapter IV — Controller and Processor Obligations (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Montenegro Law on Personal Data Protection (2023) map to?
Montenegro Law on Personal Data Protection (2023) maps to 617 other compliance frameworks. The top mapping partners are EU AI Act (35% coverage), Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) (34% coverage), NIS2 Directive (34% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Montenegro Law on Personal Data Protection (2023) compliance?
Start your Montenegro Law on Personal Data Protection (2023) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Montenegro Law on Personal Data Protection (2023) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 64 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required