Montenegro Law on Personal Data Protection (2026)
Montenegro's GDPR-aligned Law on Personal Data Protection (Sluzbeni list CG 133/2026), adopted 4 September 2026, in force 19 September 2026 and applicable from 19 March 2027, replacing the 2008 Law: principles, lawful bases, consent (age 16 for online services), special categories, data subject rights, accountability, privacy by design, representatives for foreign businesses, processor contracts, records, security, 72-hour breach notification, impact assessments, DPOs, transfers with Government adequacy decisions (EU clauses only from accession), confidential infringement reporting, the JMBG identifier, fines up to 2,000,000 euros or 4 percent of turnover; with the 2008 Law's video surveillance rules that stay in force. Built from the official gazette text.
Montenegro Law on Personal Data Protection (2026) is a compliance framework from Montenegro with 7 domains and 48 controls. The largest domains are Chapter IV: controller and processor, security, breach, impact assessment, DPO (Articles 25 to 44) – Montenegro Law on Personal Data Protection (2026) (17 controls), Chapter III: rights of the data subject (Articles 13 to 24) – Montenegro Law on Personal Data Protection (2026) (11 controls), Chapter II: principles, lawfulness, consent, special categories (Articles 6 to 12) – Montenegro Law on Personal Data Protection (2026) (7 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Chapter II: principles, lawfulness, consent, special categories (Articles 6 to 12) – Montenegro Law on Personal Data Protection (2026)
| Code | Title |
|---|---|
| montenegro-law-on-personal-data-protection-2026::10 | Article 10: processing of special categories of personal data |
| montenegro-law-on-personal-data-protection-2026::11 | Article 11: criminal convictions and offences data only under official control or law |
| montenegro-law-on-personal-data-protection-2026::12 | Article 12: processing that does not require identification |
| montenegro-law-on-personal-data-protection-2026::6 | Article 6: the processing principles and accountability |
| montenegro-law-on-personal-data-protection-2026::7 | Article 7: a lawful basis for every processing and the compatibility test |
| montenegro-law-on-personal-data-protection-2026::8 | Article 8: conditions for consent |
| montenegro-law-on-personal-data-protection-2026::9 | Article 9: a child's consent to information society services at 16 |
Chapter III: rights of the data subject (Articles 13 to 24) – Montenegro Law on Personal Data Protection (2026)
| Code | Title |
|---|---|
| montenegro-law-on-personal-data-protection-2026::13 | Article 13: transparent information and the handling of rights requests within one month |
| montenegro-law-on-personal-data-protection-2026::14 | Article 14: information when data is collected from the data subject |
| montenegro-law-on-personal-data-protection-2026::15 | Article 15: information when data is not obtained from the data subject |
| montenegro-law-on-personal-data-protection-2026::16 | Article 16: right of access and a copy of the data |
| montenegro-law-on-personal-data-protection-2026::17 | Article 17: right to rectification and completion |
| montenegro-law-on-personal-data-protection-2026::18 | Article 18: right to erasure |
| montenegro-law-on-personal-data-protection-2026::19 | Article 19: right to restriction of processing |
| montenegro-law-on-personal-data-protection-2026::20 | Article 20: notify recipients of rectification, erasure or restriction |
| montenegro-law-on-personal-data-protection-2026::21 | Article 21: right to data portability |
| montenegro-law-on-personal-data-protection-2026::22 | Article 22: right to object, including to direct marketing |
| montenegro-law-on-personal-data-protection-2026::23 | Article 23: automated individual decisions, including profiling |
Chapter IV: controller and processor, security, breach, impact assessment, DPO (Articles 25 to 44) – Montenegro Law on Personal Data Protection (2026)
| Code | Title |
|---|---|
| montenegro-law-on-personal-data-protection-2026::25 | Article 25: responsibility of the controller |
| montenegro-law-on-personal-data-protection-2026::26 | Article 26: data protection by design and by default |
| montenegro-law-on-personal-data-protection-2026::27 | Article 27: joint controllers and their arrangement |
| montenegro-law-on-personal-data-protection-2026::28 | Article 28: representative in Montenegro for controllers and processors established abroad |
| montenegro-law-on-personal-data-protection-2026::29(1) | Article 29(1), (2), (4) and its final paragraph: choosing processors with sufficient guarantees and authorising sub-processors |
| montenegro-law-on-personal-data-protection-2026::29(3) | Article 29(3) and the paragraphs on form and standard clauses: the controller-processor contract |
| montenegro-law-on-personal-data-protection-2026::30 | Article 30 and 33(4): processing only on the controller's instructions |
| montenegro-law-on-personal-data-protection-2026::31 | Article 31: records of processing activities |
| montenegro-law-on-personal-data-protection-2026::32 | Article 32: cooperation with the Agency |
| montenegro-law-on-personal-data-protection-2026::33 | Article 33: security of processing |
| montenegro-law-on-personal-data-protection-2026::34 | Article 34: notify the Agency of a breach within 72 hours and document every breach |
| montenegro-law-on-personal-data-protection-2026::35 | Article 35: tell data subjects of a high-risk breach |
| montenegro-law-on-personal-data-protection-2026::36 | Article 36: data protection impact assessment |
| montenegro-law-on-personal-data-protection-2026::37 | Article 37(1) to (3): prior consultation of the Agency |
| montenegro-law-on-personal-data-protection-2026::38 | Article 38: designation of a data protection officer |
| montenegro-law-on-personal-data-protection-2026::39 | Article 39: position of the data protection officer |
| montenegro-law-on-personal-data-protection-2026::40 | Article 40: tasks of the data protection officer |
Chapter IX: specific processing situations (Articles 91 to 97) – Montenegro Law on Personal Data Protection (2026)
| Code | Title |
|---|---|
| montenegro-law-on-personal-data-protection-2026::93 | Article 93: the unique master citizen number (JMBG) only under conditions set by law |
| montenegro-law-on-personal-data-protection-2026::95 | Article 95: safeguards for archiving, research and statistics |
Chapter V: transfers to third countries and international organisations (Articles 45 to 51) – Montenegro Law on Personal Data Protection (2026)
| Code | Title |
|---|---|
| montenegro-law-on-personal-data-protection-2026::45 | Articles 45 and 46: transfers abroad only under Chapter V; adequacy decided by the Government |
| montenegro-law-on-personal-data-protection-2026::47 | Article 47: transfers with appropriate safeguards, and the deferred EU clauses |
| montenegro-law-on-personal-data-protection-2026::48 | Article 48: binding corporate rules approved by the Agency |
| montenegro-law-on-personal-data-protection-2026::49 | Article 49: foreign court or authority demands only through international agreements |
| montenegro-law-on-personal-data-protection-2026::50 | Article 50: derogations for specific situations and the one-off compelling interest transfer |
Chapters VI to VIII: the Agency, supervision, remedies and fines (Articles 52 to 90) – Montenegro Law on Personal Data Protection (2026)
| Code | Title |
|---|---|
| montenegro-law-on-personal-data-protection-2026::75 | Article 75: give Agency inspectors access to data, records and premises |
| montenegro-law-on-personal-data-protection-2026::82 | Article 82: confidential channels for reporting infringements and protection of reporters |
Surviving video surveillance rules of the 2008 Law (Articles 35 to 40a) – Montenegro Law on Personal Data Protection (2026)
| Code | Title |
|---|---|
| montenegro-law-on-personal-data-protection-2026::2008-35 | 2008 Law Articles 35, 38 and 40: video surveillance of access to premises, residential buildings and public areas |
| montenegro-law-on-personal-data-protection-2026::2008-36 | 2008 Law Article 36: video surveillance inside business premises |
| montenegro-law-on-personal-data-protection-2026::2008-37 | 2008 Law Article 37: video surveillance records kept no longer than six months |
| montenegro-law-on-personal-data-protection-2026::2008-39 | 2008 Law Article 39: public notice of video surveillance and protection of the system |
What is Montenegro Law on Personal Data Protection (2026) and who does it apply to?
Montenegro Law on Personal Data Protection (2026) is a compliance framework from Montenegro with 7 domains and 48 controls. Montenegro's GDPR-aligned Law on Personal Data Protection (Sluzbeni list CG 133/2026), adopted 4 September 2026, in force 19 September 2026 and applicable from 19 March 2027, replacing the 2008 Law: principles, lawful bases, consent (age 16 for online services), special categories, data subject rights, accountability, privacy by design, representatives for foreign businesses, processor contracts, records, security, 72-hour breach notification, impact assessments, DPOs, transfers with Government adequacy decisions (EU clauses only from accession), confidential infringement reporting, the JMBG identifier, fines up to 2,000,000 euros or 4 percent of turnover; with the 2008 Law's video surveillance rules that stay in force. Built from the official gazette text. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Montenegro Law on Personal Data Protection (2026) actually require?
Montenegro Law on Personal Data Protection (2026) has 48 controls organised across 7 domains. The largest domains are Chapter IV: controller and processor, security, breach, impact assessment, DPO (Articles 25 to 44) – Montenegro Law on Personal Data Protection (2026) (17 controls), Chapter III: rights of the data subject (Articles 13 to 24) – Montenegro Law on Personal Data Protection (2026) (11 controls), Chapter II: principles, lawfulness, consent, special categories (Articles 6 to 12) – Montenegro Law on Personal Data Protection (2026) (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Montenegro Law on Personal Data Protection (2026) do I already cover?
Montenegro Law on Personal Data Protection (2026) does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement Montenegro Law on Personal Data Protection (2026)?
Start your Montenegro Law on Personal Data Protection (2026) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Montenegro Law on Personal Data Protection (2026) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 48 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.
Get Started Free →Free forever — no credit card required