Law / Montenegro

Law on Personal Data Protection

Official Gazette of Montenegro Nos. 79/08 70/09, 44/12, 22/17 and 77/24, as amended, arts. 1-10, 16-30 and 33-40 (general processing, security and registration)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Commencement not set.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Establish a lawful basis, such as the data subject's prior consent or one of the grounds listed in Article 10, before processing personal data of a person in Montenegro.
  • Enter into a written contract before entrusting personal data processing to a processor, and use only a processor registered to carry out personal data processing and able to guarantee technical, personnel and organizational protection measures, under Article 16.
  • Implement technical, personnel and organizational safeguards appropriate to the nature of the data processed to protect it against loss, destruction, unauthorized access, alteration, publicizing and abuse, under Article 24, and keep confidential any personal data your staff become privy to in the course of their work, under Article 25.
  • Keep records of every personal data filing system you establish, covering the matters Article 26 lists, and obtain the Agency for Personal Data Protection and Free Access to Information's prior consent before establishing or materially altering one, under Articles 27 and 28.
  • Where you run video surveillance of business or official premises, display a public notice of it, avoid recording residential interiors or apartment entrances, and store the recordings for no longer than one year, under Articles 35 to 40.

What it reaches

Obligation class

Consent, Contract terms, Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

This is the working resolution of a genuinely unresolved status question: whether the 2008 Law on Personal Data Protection, as amended through the August 2024 amendment (OG 77/24), or a separately reported 2023 replacement (OG No. 21/2023) currently governs, and it is recorded as enacted rather than in force because no promulgation, publication or commencement date for the act or any of its four amendments is available at primary source.

This law binds the state authority, public administration body, local self-government and local administration authority, commercial enterprise and other legal person, entrepreneur and natural person, with the seat or domicile in Montenegro, and a controller whose seat or domicile is outside Montenegro if the equipment used for processing personal data is situated in Montenegro, under Article 5.

Article 7 applies the law to processing personal data wholly or partly by automatic means, and to processing otherwise than by automatic means that forms part of, or is intended to form part of, a personal data filing system.

Article 10 permits processing with the data subject's prior consent, or without it where processing is necessary for one of five listed grounds running from performance of a legal obligation to a legitimate interest that does not override the data subject's rights and freedoms.

A processor of personal data may be entrusted specific processing activities only by way of a written contract under Article 16, and only where the processor is registered for carrying out the processing of personal data and can guarantee technical, personnel and organizational protection measures.

Article 24 requires the controller and the recipient of personal data to implement technical, personnel and organizational safeguards appropriate to the nature of the data processed, and Article 25 requires every officer and employee who processes personal data to keep it secret.

Article 26 requires the controller to keep records of every personal data filing system it establishes, and Articles 27 and 28 require the Agency's prior consent before establishing or materially altering one, with the Agency's silence for 30 days counting as consent.

Articles 33 to 40 let business and official premises keep entry and exit records and run video surveillance for safety and security purposes, subject to a public notice, a bar on recording residential interiors or apartment entrances, and a one year storage limit.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach

Read the law

70/09-consolidated English translation hosted by the Agency for Personal Data Protection and Free Access to Information (azlp.me)
read in full (54,193 characters, not truncated)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app