Back to Frameworks

Montenegro Law on Personal Data Protection (2026)

Montenegro
vSl. list CG 133/2026 (adopted 4 September 2026; in force 19 September 2026; applicable 19 March 2027)
7 domains
48 controls

Montenegro's GDPR-aligned Law on Personal Data Protection (Sluzbeni list CG 133/2026), adopted 4 September 2026, in force 19 September 2026 and applicable from 19 March 2027, replacing the 2008 Law: principles, lawful bases, consent (age 16 for online services), special categories, data subject rights, accountability, privacy by design, representatives for foreign businesses, processor contracts, records, security, 72-hour breach notification, impact assessments, DPOs, transfers with Government adequacy decisions (EU clauses only from accession), confidential infringement reporting, the JMBG identifier, fines up to 2,000,000 euros or 4 percent of turnover; with the 2008 Law's video surveillance rules that stay in force. Built from the official gazette text.

Verified

Montenegro Law on Personal Data Protection (2026) is a compliance framework from Montenegro with 7 domains and 48 controls. The largest domains are Chapter IV: controller and processor, security, breach, impact assessment, DPO (Articles 25 to 44) – Montenegro Law on Personal Data Protection (2026) (17 controls), Chapter III: rights of the data subject (Articles 13 to 24) – Montenegro Law on Personal Data Protection (2026) (11 controls), Chapter II: principles, lawfulness, consent, special categories (Articles 6 to 12) – Montenegro Law on Personal Data Protection (2026) (7 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Chapter II: principles, lawfulness, consent, special categories (Articles 6 to 12) – Montenegro Law on Personal Data Protection (2026)

7 controls
Controls in the Chapter II: principles, lawfulness, consent, special categories (Articles 6 to 12) – Montenegro Law on Personal Data Protection (2026) domain of Montenegro Law on Personal Data Protection (2026) — 7 controls
CodeTitle
montenegro-law-on-personal-data-protection-2026::10Article 10: processing of special categories of personal data
montenegro-law-on-personal-data-protection-2026::11Article 11: criminal convictions and offences data only under official control or law
montenegro-law-on-personal-data-protection-2026::12Article 12: processing that does not require identification
montenegro-law-on-personal-data-protection-2026::6Article 6: the processing principles and accountability
montenegro-law-on-personal-data-protection-2026::7Article 7: a lawful basis for every processing and the compatibility test
montenegro-law-on-personal-data-protection-2026::8Article 8: conditions for consent
montenegro-law-on-personal-data-protection-2026::9Article 9: a child's consent to information society services at 16

Chapter III: rights of the data subject (Articles 13 to 24) – Montenegro Law on Personal Data Protection (2026)

11 controls
Controls in the Chapter III: rights of the data subject (Articles 13 to 24) – Montenegro Law on Personal Data Protection (2026) domain of Montenegro Law on Personal Data Protection (2026) — 11 controls
CodeTitle
montenegro-law-on-personal-data-protection-2026::13Article 13: transparent information and the handling of rights requests within one month
montenegro-law-on-personal-data-protection-2026::14Article 14: information when data is collected from the data subject
montenegro-law-on-personal-data-protection-2026::15Article 15: information when data is not obtained from the data subject
montenegro-law-on-personal-data-protection-2026::16Article 16: right of access and a copy of the data
montenegro-law-on-personal-data-protection-2026::17Article 17: right to rectification and completion
montenegro-law-on-personal-data-protection-2026::18Article 18: right to erasure
montenegro-law-on-personal-data-protection-2026::19Article 19: right to restriction of processing
montenegro-law-on-personal-data-protection-2026::20Article 20: notify recipients of rectification, erasure or restriction
montenegro-law-on-personal-data-protection-2026::21Article 21: right to data portability
montenegro-law-on-personal-data-protection-2026::22Article 22: right to object, including to direct marketing
montenegro-law-on-personal-data-protection-2026::23Article 23: automated individual decisions, including profiling

Chapter IV: controller and processor, security, breach, impact assessment, DPO (Articles 25 to 44) – Montenegro Law on Personal Data Protection (2026)

17 controls
Controls in the Chapter IV: controller and processor, security, breach, impact assessment, DPO (Articles 25 to 44) – Montenegro Law on Personal Data Protection (2026) domain of Montenegro Law on Personal Data Protection (2026) — 17 controls
CodeTitle
montenegro-law-on-personal-data-protection-2026::25Article 25: responsibility of the controller
montenegro-law-on-personal-data-protection-2026::26Article 26: data protection by design and by default
montenegro-law-on-personal-data-protection-2026::27Article 27: joint controllers and their arrangement
montenegro-law-on-personal-data-protection-2026::28Article 28: representative in Montenegro for controllers and processors established abroad
montenegro-law-on-personal-data-protection-2026::29(1)Article 29(1), (2), (4) and its final paragraph: choosing processors with sufficient guarantees and authorising sub-processors
montenegro-law-on-personal-data-protection-2026::29(3)Article 29(3) and the paragraphs on form and standard clauses: the controller-processor contract
montenegro-law-on-personal-data-protection-2026::30Article 30 and 33(4): processing only on the controller's instructions
montenegro-law-on-personal-data-protection-2026::31Article 31: records of processing activities
montenegro-law-on-personal-data-protection-2026::32Article 32: cooperation with the Agency
montenegro-law-on-personal-data-protection-2026::33Article 33: security of processing
montenegro-law-on-personal-data-protection-2026::34Article 34: notify the Agency of a breach within 72 hours and document every breach
montenegro-law-on-personal-data-protection-2026::35Article 35: tell data subjects of a high-risk breach
montenegro-law-on-personal-data-protection-2026::36Article 36: data protection impact assessment
montenegro-law-on-personal-data-protection-2026::37Article 37(1) to (3): prior consultation of the Agency
montenegro-law-on-personal-data-protection-2026::38Article 38: designation of a data protection officer
montenegro-law-on-personal-data-protection-2026::39Article 39: position of the data protection officer
montenegro-law-on-personal-data-protection-2026::40Article 40: tasks of the data protection officer

Chapter IX: specific processing situations (Articles 91 to 97) – Montenegro Law on Personal Data Protection (2026)

2 controls
Controls in the Chapter IX: specific processing situations (Articles 91 to 97) – Montenegro Law on Personal Data Protection (2026) domain of Montenegro Law on Personal Data Protection (2026) — 2 controls
CodeTitle
montenegro-law-on-personal-data-protection-2026::93Article 93: the unique master citizen number (JMBG) only under conditions set by law
montenegro-law-on-personal-data-protection-2026::95Article 95: safeguards for archiving, research and statistics

Chapter V: transfers to third countries and international organisations (Articles 45 to 51) – Montenegro Law on Personal Data Protection (2026)

5 controls
Controls in the Chapter V: transfers to third countries and international organisations (Articles 45 to 51) – Montenegro Law on Personal Data Protection (2026) domain of Montenegro Law on Personal Data Protection (2026) — 5 controls
CodeTitle
montenegro-law-on-personal-data-protection-2026::45Articles 45 and 46: transfers abroad only under Chapter V; adequacy decided by the Government
montenegro-law-on-personal-data-protection-2026::47Article 47: transfers with appropriate safeguards, and the deferred EU clauses
montenegro-law-on-personal-data-protection-2026::48Article 48: binding corporate rules approved by the Agency
montenegro-law-on-personal-data-protection-2026::49Article 49: foreign court or authority demands only through international agreements
montenegro-law-on-personal-data-protection-2026::50Article 50: derogations for specific situations and the one-off compelling interest transfer

Chapters VI to VIII: the Agency, supervision, remedies and fines (Articles 52 to 90) – Montenegro Law on Personal Data Protection (2026)

2 controls
Controls in the Chapters VI to VIII: the Agency, supervision, remedies and fines (Articles 52 to 90) – Montenegro Law on Personal Data Protection (2026) domain of Montenegro Law on Personal Data Protection (2026) — 2 controls
CodeTitle
montenegro-law-on-personal-data-protection-2026::75Article 75: give Agency inspectors access to data, records and premises
montenegro-law-on-personal-data-protection-2026::82Article 82: confidential channels for reporting infringements and protection of reporters

Surviving video surveillance rules of the 2008 Law (Articles 35 to 40a) – Montenegro Law on Personal Data Protection (2026)

4 controls
Controls in the Surviving video surveillance rules of the 2008 Law (Articles 35 to 40a) – Montenegro Law on Personal Data Protection (2026) domain of Montenegro Law on Personal Data Protection (2026) — 4 controls
CodeTitle
montenegro-law-on-personal-data-protection-2026::2008-352008 Law Articles 35, 38 and 40: video surveillance of access to premises, residential buildings and public areas
montenegro-law-on-personal-data-protection-2026::2008-362008 Law Article 36: video surveillance inside business premises
montenegro-law-on-personal-data-protection-2026::2008-372008 Law Article 37: video surveillance records kept no longer than six months
montenegro-law-on-personal-data-protection-2026::2008-392008 Law Article 39: public notice of video surveillance and protection of the system

What is Montenegro Law on Personal Data Protection (2026) and who does it apply to?

Montenegro Law on Personal Data Protection (2026) is a compliance framework from Montenegro with 7 domains and 48 controls. Montenegro's GDPR-aligned Law on Personal Data Protection (Sluzbeni list CG 133/2026), adopted 4 September 2026, in force 19 September 2026 and applicable from 19 March 2027, replacing the 2008 Law: principles, lawful bases, consent (age 16 for online services), special categories, data subject rights, accountability, privacy by design, representatives for foreign businesses, processor contracts, records, security, 72-hour breach notification, impact assessments, DPOs, transfers with Government adequacy decisions (EU clauses only from accession), confidential infringement reporting, the JMBG identifier, fines up to 2,000,000 euros or 4 percent of turnover; with the 2008 Law's video surveillance rules that stay in force. Built from the official gazette text. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Montenegro Law on Personal Data Protection (2026) actually require?

Montenegro Law on Personal Data Protection (2026) has 48 controls organised across 7 domains. The largest domains are Chapter IV: controller and processor, security, breach, impact assessment, DPO (Articles 25 to 44) – Montenegro Law on Personal Data Protection (2026) (17 controls), Chapter III: rights of the data subject (Articles 13 to 24) – Montenegro Law on Personal Data Protection (2026) (11 controls), Chapter II: principles, lawfulness, consent, special categories (Articles 6 to 12) – Montenegro Law on Personal Data Protection (2026) (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Montenegro Law on Personal Data Protection (2026) do I already cover?

Montenegro Law on Personal Data Protection (2026) does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement Montenegro Law on Personal Data Protection (2026)?

Start your Montenegro Law on Personal Data Protection (2026) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Montenegro Law on Personal Data Protection (2026) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 48 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.

Get Started Free →

Free forever — no credit card required