Law / Montenegro

Montenegro

13 of 16 named instruments researched to a stage, across five of the six areas of law we track: 7 in force and 6 enacted but not yet in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 3
  5. Age gating law 1
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 enacted but not yet in force

Research summary (165 words)

Montenegro is not a General Data Protection Regulation (GDPR) jurisdiction, and which act currently governs is genuinely unresolved. Professional trackers disagree, sometimes within one source, between the 2008 Law on Personal Data Protection (Official Gazette Nos. 79/08, 70/09, 44/12, 22/17, and an August 2024 amendment, 77/24) and a separately reported 2023 replacement, Official Gazette No. 21/2023. A 70/09-consolidated English translation of the 2008 act is hosted by Montenegro's own supervisory authority.

The more specific and more recently dated sources weigh toward the 2008 act, as amended, being what currently governs, but that is not independently confirmed against the 2023 candidate or against the later 44/12, 22/17 and 77/24 amendments to the specific articles read. The 2008 act is recorded here as the operative regime on that working resolution, not as a settled fact.

The instrument below is recorded as enacted rather than in force: no specific promulgation, publication, or commencement date for the act or its amendments is established, from the consolidated text located or from any other source.

Biometric privacy

Law on Personal Data Protection, biometric measures

Law on Personal Data Protection, arts. 31-32 (biometric measures)70/09-consolidated English translation hosted by the Agency for Personal Data Protection and Free Access to Information (azlp.me)

Commencement not set. Binds public and private bodies.

What this law does

Article 31 permits the establishment and comparison of personal traits for the purpose of establishing and proving the identity of an individual, defined as biometric measures, to be performed in accordance with this law.

Article 32 confines biometric measures carried out by the public sector, meaning the state authority, public administration body, local self-government and local administration authority, commercial enterprise or other legal person and an entrepreneur exercising public authority, to the entry into business or official premises and the presence at work of employees, and only where provided for by law and necessary for the protection of individuals and property, the protection of secrecy of data or business secrets, discharging obligations under international treaties, or establishing the identity of individuals crossing state borders, where these aims cannot be achieved another way.

What it requires

Comprehensive regime

Law on Personal Data Protection

Official Gazette of Montenegro Nos. 79/08 70/09, 44/12, 22/17 and 77/24, as amended, arts. 1-10, 16-30 and 33-40 (general processing, security and registration)70/09-consolidated English translation hosted by the Agency for Personal Data Protection and Free Access to Information (azlp.me)

Commencement not set. Binds public and private bodies.

What this law does

This is the working resolution of a genuinely unresolved status question: whether the 2008 Law on Personal Data Protection, as amended through the August 2024 amendment (OG 77/24), or a separately reported 2023 replacement (OG No. 21/2023) currently governs, and it is recorded as enacted rather than in force because no promulgation, publication or commencement date for the act or any of its four amendments is available at primary source.

This law binds the state authority, public administration body, local self-government and local administration authority, commercial enterprise and other legal person, entrepreneur and natural person, with the seat or domicile in Montenegro, and a controller whose seat or domicile is outside Montenegro if the equipment used for processing personal data is situated in Montenegro, under Article 5.

Article 7 applies the law to processing personal data wholly or partly by automatic means, and to processing otherwise than by automatic means that forms part of, or is intended to form part of, a personal data filing system.

Article 10 permits processing with the data subject's prior consent, or without it where processing is necessary for one of five listed grounds running from performance of a legal obligation to a legitimate interest that does not override the data subject's rights and freedoms.

A processor of personal data may be entrusted specific processing activities only by way of a written contract under Article 16, and only where the processor is registered for carrying out the processing of personal data and can guarantee technical, personnel and organizational protection measures.

Article 24 requires the controller and the recipient of personal data to implement technical, personnel and organizational safeguards appropriate to the nature of the data processed, and Article 25 requires every officer and employee who processes personal data to keep it secret.

Article 26 requires the controller to keep records of every personal data filing system it establishes, and Articles 27 and 28 require the Agency's prior consent before establishing or materially altering one, with the Agency's silence for 30 days counting as consent.

Articles 33 to 40 let business and official premises keep entry and exit records and run video surveillance for safety and security purposes, subject to a public notice, a bar on recording residential interiors or apartment entrances, and a one year storage limit.

What it requires

Cross border transfer

Law on Personal Data Protection, transfer of personal data from Montenegro

Law on Personal Data Protection, arts. 41-42 (transfer of personal data from Montenegro)70/09-consolidated English translation hosted by the Agency for Personal Data Protection and Free Access to Information (azlp.me)

Commencement not set. Binds public and private bodies.

What this law does

Article 41 permits personal data to be transferred from Montenegro to another country, or given to an international organisation that implements the safeguards this law requires, only with the prior consent of the supervisory authority, with the adequacy of the protection assessed against the nature of the data, the purpose and duration of the processing, the countries of origin and destination, and the rules of law and security measures in force there.

Article 42 lists nine cases in which that consent is not mandatory, including a separate law or treaty providing for the transfer, the data subject's informed prior consent, performance of a contract, protecting the data subject's life, a transfer from a public register, an important public interest or legal claim, and a transfer to a Member State of the European Union or European Economic Area, or to a country on the European Union's adequacy list.

What it requires

Data subject rights

Law on Personal Data Protection, rights of the data subject

Law on Personal Data Protection, arts. 11, 20-21, 23, 43-46 (rights of the data subject)70/09-consolidated English translation hosted by the Agency for Personal Data Protection and Free Access to Information (azlp.me)

Commencement not set. Binds public and private bodies.

What this law does

Article 11 lets a data subject request erasure of personal data that was not obtained from him directly, and requires the controller to erase it within 30 days of the request.

Article 20 requires the controller or processor to give a data subject, from whom data are collected directly, information including the purpose of processing, the recipients or categories of recipients, and the existence of the rights of access and rectification, and Article 21 imposes the same duty, no later than when processing begins, where the data were not obtained from the data subject directly.

Article 23 lets a data subject request erasure of personal data whose processing does not comply with the law, and requires the controller to notify the data subject and any recipient of an alteration, supplementing or erasure within 8 days.

Article 43 requires the controller to notify a data subject, on written request, within 15 days of whether personal data concerning him are undergoing processing, the identity of the processor and recipient, the source, purpose and legal grounds, and the rights of access and rectification, and Article 44 requires the controller, within the same 15 days, to supplement, alter or erase inaccurate or incomplete personal data, or block the use of personal data whose use does not comply with the law.

Article 45 lets the rights set out in Articles 43 and 44 be restricted for defence, national and public security, the detection and prosecution of criminal offenders, or the protection of economic or financial interests or cultural assets of importance for the state, to the extent necessary and only under a separate law, and Article 46 puts the cost of an Article 43 or 44 proceeding on the controller.

What it requires

Enforcement supervision

Law on Personal Data Protection, agency, supervision and penal provisions

Law on Personal Data Protection, arts. 47-74 (agency, supervision and penal provisions)70/09-consolidated English translation hosted by the Agency for Personal Data Protection and Free Access to Information (azlp.me)

Commencement not set. Binds public and private bodies.

What this law does

Article 47 lets a person who alleges a breach of rights under this law submit a request for protection of rights to the Agency, which must decide within 60 days, and lets the Agency temporarily ban further processing on the applicant's written request while a likely breach is pending decision. Article 48 entitles a data subject to compensation from the controller for damage suffered from a breach of rights under this law, under the general rules on compensation of damage.

Article 49 sets up the Agency for Personal Data Protection as the supervisory authority, autonomous and independent, with legal personality, and Articles 65 to 73 give the Agency's controllers the right of access to filing systems, files and electronic processing means regardless of the level of data secrecy, and let the Agency, on finding unlawful activity, order that irregularities be eliminated, impose a temporary ban on unlawful processing, order the erasure of unlawfully collected data, and ban an unlawful transfer or entrusting of personal data.

Article 74 fines an authority, legal person or entrepreneur ten to three hundred times the minimum wage in Montenegro, and a responsible individual one to twenty times the minimum wage, for violating the duties this law imposes.

What it requires

Sensitive categories

Law on Personal Data Protection, special categories of data

Law on Personal Data Protection, arts. 9(7)-(9), 12-14 (special categories of data)70/09-consolidated English translation hosted by the Agency for Personal Data Protection and Free Access to Information (azlp.me)

Commencement not set. Binds public and private bodies.

What this law does

Article 9 defines special categories of data as personal data concerning racial or ethnic origin, political, religious or other beliefs, social origin, trade union membership, health, sex life or sexual orientation, biometric data, and data from registers of misdemeanour and criminal convictions, with biometric data itself defined generically, without enumerated examples, as data on physical or physiological features intrinsic to every natural person that are specific, unique and unchangeable and capable of revealing identity directly or indirectly.

Article 12 requires personal data concerning children to be processed in a manner that is in the best interest of the child.

Article 13 permits processing special categories of data only where the data subject has consented, where necessary for detecting, preventing or diagnosing illness or providing medical treatment by a health worker or another person under a professional secrecy duty, to protect the vital interests of the data subject or another person unable to consent, where the data subject has manifestly made the data public or processing is necessary to establish or protect a legal interest, or in the non-disclosed internal activities of a political, religious or other non-profit association, and requires special categories of data to be distinctively designated and protected against unauthorised access.

Article 14 confines the processing of personal data on criminal offences, criminal or misdemeanour penalties or security measures to the competent state authority or its supervision, with safeguards required by law.

What it requires

Scraping law2 instruments, 2 in force

Research summary (287 words)

Montenegro has no scraping-specific statute, so general law governs each dimension separately.

The Criminal Code's Article 353 criminalises unauthorised access to a computer system in whole or in part; its basic form is not conditioned on defeating a security measure, so a plain reading reaches an unauthenticated scraper who accesses a public page without the operator's consent, while violating a protection measure or accessing a system of state or local-government significance raises the maximum term, and using data obtained through unauthorised access, or intercepting non-public computer data during transmission, are separate offences under the same article.

No Montenegrin court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper was located.

The Law on Copyright and Related Rights confers a sui generis right on the maker of a database, protecting the entire contents, any qualitatively or quantitatively substantial part, and even an insubstantial part where extracted repeatedly and systematically in a way that conflicts with the database's normal exploitation, for 15 years from the database's making or first disclosure; its catalogue of exceptions (transient technical reproduction, private and internal-use copying, quotation, teaching, and official-proceedings use) names no text-and-data-mining or AI-training exception, and its private-use exception expressly excludes electronic databases from its own scope.

The Law on Personal Data Protection imposes no general exemption for personal data drawn from a publicly available source; Article 15 instead imposes a further consent requirement before personal data from a publicly available source may be processed for direct marketing, so scraped personal data remains subject to the Act's ordinary lawful-basis rules.

No Montenegrin statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or states an AI-training-specific rule.

Computer misuse

Criminal Code of Montenegro, Unauthorised Access to a Computer System

Criminal Code of Montenegro Art. 353 (Unauthorised Access to a Computer System), Official Gazette of the Republic of Montenegro Nos. 70/03, 13/04, 47/06 and Official Gazette of Montenegro Nos. 40/08, 25/10, 32/11, 64/11, 40/13, 56/13, 14/15, 42/15, 58/15, 44/17, 49/18Criminal Code of Montenegro, English translation (2018 consolidated version) hosted by the United Nations Office on Drugs and Crime (UNODC)

In force. Binds public and private bodies.

What this law does

Article 353(1) punishes unauthorised access to a computer system, in whole or in part, with a fine or imprisonment of up to one year; the basic offence does not require defeating a security measure. Article 353(2) raises the maximum to three years where the perpetrator violates a computer system's protection measures or accesses a system significant to a state authority, local-government authority, or another institution exercising public powers.

Article 353(3) applies the same three-year maximum to illegally intercepting non-public computer data during its transmission to, from, or within a computer system, including electromagnetic emissions. Article 353(4) punishes using data obtained through any of paragraphs 1 to 3 with a fine or up to three years, rising under Article 353(5) to a term of six months to five years where that use has grave consequences for another person.

What it requires

Cybersecurity law3 instruments, 3 in force

Research summary (703 words)

Montenegro's Law on Information Security (“Službeni list Crne Gore”, No. 113/2024, adopted by Parliament 19 November 2024 and in force since 5 December 2024) is a full transposition of the NIS2 Directive (Directive (EU) 2022/2555): the statute's own preamble footnote states it is harmonized with that Directive, and it repeals Montenegro's earlier Law on Information Security (“Službeni list CG”, Nos. 14/10, 40/16 and 67/21). It binds two overlapping classes on different terms.

First, a general baseline duty in Articles 11 to 15 and 18(1) to (3) reaches every organ of the state and every business, other legal entity or natural person that accesses or processes data, or uses and manages a network and information system, in Montenegro, with no sector or size gate: data-handling rules and access logging, physical security of the premises and devices holding the system, and protection of the confidentiality, integrity and availability of the data that system carries, plus a duty to name an employee to monitor compliance.

Second, an entity the Government designates an essential or important entity under Articles 4 and 19 to 27, sector lists tracking NIS2's own Annexes (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space for essential entities; postal and courier services, waste management, chemicals, food, manufacturing, online marketplace services and research for important entities), additionally carries the enhanced risk-management measures of Article 16 and, if an essential entity, must obtain and periodically renew a certificate of compliance with the Montenegrin standard MEST ISO/IEC 27001 from an accredited body within 30 months of the law's entry into force (Article 18(4) to (6) and Article 73).

Chapter IV (Articles 28 to 37) layers a tiered incident-reporting duty on top of both classes alike: a threat or incident with no effect on service continuity is reported monthly, one that could significantly affect continuity triggers a 24-hour initial notification, and the Cybersecurity Agency's own severity rating then sets a 72-hour or 24-hour ongoing-report clock and a 30-day final-report clock.

Of the sectors reaching a software or platform business, only the digital-infrastructure essential-entity category (an internet exchange point, a DNS or top-level-domain registry, a cloud computing, data centre, content delivery network or qualified trust service provider) and the online-marketplace important-entity category name a declarable digital service; the surrounding non-digital sectors, and the essential and important entity designation itself, are a role no activity in LexLint's current vocabulary expresses, and are recorded here rather than flagged on a guess.

The Cybersecurity Agency of Montenegro (Agencija za sajber bezbjednost), established under this law, enforces against every organ and other entity outside the state administration, and began its first supervision cycle in July 2026, issuing questionnaires to designated essential and important entities and completing an on-site inspection of at least one essential entity; the Ministry of Public Administration, Digital Society and Media enforces against state administration bodies through its own inspector and CIRT.

Every violation described here is an administrative misdemeanor (“prekršaj”) carrying a fine and never a criminal offence; Montenegro's Criminal Code Article 353 (unauthorised use of a computer or computer network), a distinct offence against a system committed by an intruder, is already this jurisdiction's scraping-topic row and is not restated here.

The law explicitly excludes the ministry responsible for defence, the Army of Montenegro, the Agency for National Security, the police unit of the interior ministry, Parliament, the Central Bank of Montenegro, and data whose security is governed by the classified-data law (Article 7); whether the Central Bank of Montenegro has issued separate binding cybersecurity or IT-risk directives for the banks it licenses is not confirmed in the primary text consulted here.

Personal data handled through a network or information system is carved out to Montenegro's Law on Personal Data Protection by this law's own Article 8, which is this jurisdiction's privacy-topic row and is not restated here.

Montenegro is a candidate for European Union accession rather than a member state, so the directly applicable Cyber Resilience Act (Regulation (EU) 2024/2847) does not reach Montenegro on its own force, and no Montenegrin instrument located here sets a security requirement a connected device or software product must meet to be placed on the market, independent of that Regulation.

Sector security regimes

Law on Information Security, Essential and Important Entities

Law on Information Security, Arts. 4, 16, 18(4) to (6), and 19 to 27Official Gazette of Montenegro (“Službeni list Crne Gore”), No. 113/2024, 27 November 2024

In force since 5 December 2024. Binds public and private bodies.

What this law does

Article 4 defines an essential entity as an organ or other entity that applies information and communication technology to deliver a service so significant to life, health, citizen safety or state functioning that its interruption or destruction would endanger them, and an important entity as one delivering a service whose interruption would only impair state functioning; both definitions apply regardless of the entity's size.

Article 19 places essential entities within eleven named sectors (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space) and important entities within seven others (postal and courier services, waste management, chemicals manufacture, food production, manufacturing of medical devices, electronics, electrical equipment, machinery or motor vehicles, online marketplace services, and research).

Articles 20 to 26 set the mechanics for the Government to adopt and maintain a Government-approved List of essential and important entities from sectoral proposals the competent ministries compile.

A designated entity carries the enhanced risk-management measures of Article 16 (a risk and security analysis, an incident-handling policy, a business-continuity and cyber-crisis plan, a supply-chain security act, system-governance acts, cryptographic protection where required, and an effectiveness assessment of these measures) on top of the general measures this jurisdiction's companion row describes, and, if designated an essential entity, must obtain a certificate of compliance with the Montenegrin standard MEST ISO/IEC 27001 from an accredited body within 30 months of the law's entry into force and request a periodic re-verification afterward (Article 18(4) to (6) and Article 73).

The Cybersecurity Agency launched its first supervision cycle in July 2026, sending questionnaires to designated essential and important entities and completing an on-site inspection of at least one essential entity, and reported that essential entities showed higher self-assessed compliance than important entities.

What it requires

Security baseline statutes

Law on Information Security, General Security Measures

Law on Information Security, Arts. 1 to 3, 7 to 15 and 18(1) to (3)Official Gazette of Montenegro (“Službeni list Crne Gore”), No. 113/2024, 27 November 2024

In force since 5 December 2024. Binds public and private bodies.

What this law does

Article 2 binds every state organ, ministry, local self-government body, legal entity exercising public authority, business company, other legal entity and natural person that accesses or processes data, or uses and manages a network and information system, in Montenegro.

Article 18(2) requires every such organ or entity that the Government has not designated an essential or important entity to apply the data-protection measures of Article 12 (rules for handling data, access logging, and security oversight), the physical-protection measures of Article 14, and the network-and-information-system-protection measures of Article 15 (protecting the confidentiality, integrity and availability of data through the planning, design, construction, use, maintenance and decommissioning of that system), and Article 18(3) requires every organ or entity, designated or not, to name an employee to monitor its own compliance with these measures.

An essential or important entity carries the same Article 12, 14 and 15 duties as part of the wider Article 11 to 16 measures this jurisdiction's companion row on essential and important entities describes.

What it requires

Vulnerability and incident reporting

Law on Information Security, Cyber Threat and Incident Reporting

Law on Information Security, Arts. 28 to 37Official Gazette of Montenegro (“Službeni list Crne Gore”), No. 113/2024, 27 November 2024

In force since 5 December 2024. Binds public and private bodies.

What this law does

Article 28 requires every organ and other entity to assess the impact of a cyber threat or incident on the continuity of the services it provides, by the number of users affected, the duration, and the geographic reach. Article 29 requires an assessment of no impact to be reported once a month to the Cybersecurity Agency, or to the Government CIRT for a state administration body.

Article 30 requires an assessment of possible significant impact to be reported within 24 hours of becoming aware of it, on a prescribed form; the Agency or CIRT then rates the incident low, medium or high under Article 31.

A medium-rated incident carries a 72-hour first report, further reports without delay on any new development, continuing reports every 72 hours while it lasts, and a final report within 30 days of resolution (Article 33); a high-rated incident carries the same sequence on continuing reports every 24 hours instead (Article 34), and a high-rated incident the Agency and CIRT cannot resolve within ten days can be escalated to a Government-declared cyber crisis under Article 35.

What it requires

Age gating law1 instrument, 1 in force

Research summary (138 words)

Montenegro's Law on Audiovisual Media Services (Official Gazette No. 54/2024, in force since 19 June 2024) requires a provider of an on-demand audiovisual media service and a video-sharing platform provider to shield minors from content that could impair their development, including a duty to use content categorisation and age-verification tools for merely harmful content and the highest level of technical protection, such as a special code or identity verification, for content including pornography or gratuitous violence; personal data collected through either measure may not be used for commercial purposes.

No separate app-store-level or general age-appropriate design-code statute was found, and no social-media-specific minor-access statute distinct from this Law was found. Whether Montenegro's Law on Games of Chance imposes a comparable age-verification duty on an operator of online games of chance is a question this review did not reach.

Adult content age verification (AV)

Law on Audiovisual Media Services, Protection of Minors

Law on Audiovisual Media Services, Arts. 59 and 130, Official Gazette of Montenegro No. 54/2024Text of the Law on Audiovisual Media Services published by the Ministry of Culture and Media on the Government of Montenegro document portal

In force since 19 June 2024. Binds public and private bodies.

What this law does

Article 59 requires a provider of an audiovisual media service on demand to make content that could impair a minor's physical, health-related, moral, mental, intellectual, emotional or social development available only in a way least likely for minors to ordinarily encounter it, using measures that include content categorisation and age-verification tools.

It requires content that could seriously impair that development, including pornography or gratuitous depiction of violence, to be made available only behind the highest level of technical protection, such as a special code or identity verification. Personal data of a minor collected through either measure may not be processed for commercial purposes such as direct marketing, profiling, or targeted behavioural advertising.

Article 130 imposes a parallel duty on a video-sharing platform provider to establish and apply an age-verification system for platform users in relation to content that could endanger a minor's psychological, physical or moral development, among the protective measures the Agency for Audiovisual Media Services oversees. The Law was published on 11 June 2024 and entered into force on 19 June 2024.

Article 187 fines a legal person 500 to 20,000 euros, and sets lower tiers for a responsible person in a legal entity, a natural person, or an entrepreneur, for failing to comply with either duty, as a misdemeanor rather than a criminal offense.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (312 words)

Montenegro has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Law on Copyright and Related Rights is the primary law reaching an aggregator's reproduction of news content.

Its Article 50 permits, without the rightholder's consent, reproducing works seen or heard while reporting a current event, preparing and reproducing summaries of disclosed newspaper and similar articles in the form of press reviews, and using political speeches or lecture extracts, to the extent justified by the purpose of information, though the author keeps the exclusive right to compile political speeches or lecture extracts into a collection; Article 53 separately permits quoting a disclosed work for criticism, recognition, or reference, in accordance with fair practice and to the extent the purpose requires, with no headline-length or short-extract cap distinct from that fair-practice test, and no reported Montenegrin decision applies either provision to a systematic news aggregator rather than an individual user.

The Act's Section E rights of publishers are narrower than the European Union's Digital Single Market Directive Article 15 neighbouring right: Article 137 gives the first lawful publisher of a previously unpublished public-domain work the author's economic rights for 25 years, and Article 138 gives a publisher a share of private-copying remuneration; neither reaches an online news publisher's own reporting, and Montenegro is a candidate for European Union membership rather than a member state, so no domestic transposition of Article 15 was expected or found.

No statute or reported case addresses whether a hyperlink is a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law was found. The Act's exception for transient or incidental technical reproduction (Article 49) covers processes such as network transmission but is not a machine-readable text-and-data-mining reservation, and no such opt-out mechanism exists in the text read.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.