Montenegro Law on Personal Data Protection (2023)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cross-Border Transfer - Montenegro PDPL
Govern cross-border transfers aligned with GDPR Chapter V + Convention 108+. Transfers permitted to: (a) EU/EEA member states (free transfers post-EU accession); (b) Convention 108+ states (free transfers); (c) countries with adequacy decision (UK + Switzerland + Japan + Korea + Canada commercial + Israel + Argentina + Uruguay + New Zealand + Andorra + Faroe Islands + Guernsey + Isle of Man + Jersey + EU-US Data Privacy Framework 2023); (d) Standard Contractual Clauses (SCC) approved by AZLP + EU 2021 SCC equivalent; (e) Binding Corporate Rules (BCR) approved by AZLP; (f) explicit consent + necessary for contract + vital interests + legal claims. Western Balkans Regional Data Protection Network (WBRDPN) bilateral arrangements with Serbia + North Macedonia + Bosnia and Herzegovina + Albania + Kosovo. Diaspora communities in Italy + Germany + Switzerland + Austria + USA + Canada + Australi
- Cross-border transfer register with GDPR Chapter V + Convention 108+ basis
- AZLP-approved SCC (or EU 2021 SCC equivalent)
- BCR documentation submitted to AZLP
- Western Balkans WBRDPN bilateral records (Serbia + Croatia + N Macedonia + BiH + Albania + Kosovo)
- Diaspora cross-border arrangements documentation
- Schrems II Transfer Impact Assessment for US transfers
- AZLP-approved SCC not in use (relying on EU SCC alone)
- Diaspora data flows not papered for cross-border
- Schrems II TIA not conducted
- Convention 108+ adequacy not leveraged
Data Subject Rights - Montenegro PDPL
Provide and operate channels for data subjects to exercise GDPR-aligned rights. Right to information and access (GDPR Articles 13-15) within 1 month extendable by 2 months for complex requests + free of charge first request per year + transparent information. Right to rectification (Article 16). Right to erasure / right to be forgotten (Article 17). Right to restriction (Article 18). Right to data portability (Article 20). Right to object (Article 21) including absolute right to direct marketing opt-out. Right not to be subject to solely automated decision-making with legal or similarly significant effects (Article 22) with safeguards including human intervention. AZLP complaint mechanism free of charge + investigation + finding + appeal to Administrative Court of Montenegro (Upravni sud Crne Gore) within 30 days + Supreme Court (Vrhovni sud Crne Gore) further appeal + Constitutional Cou
- Subject rights register with 1-month SLA evidence
- Identity authentication procedure
- Automated decision-making safeguards (human intervention)
- AZLP complaint preparedness + Administrative Court 30-day appeal preparedness
- Supreme Court + Constitutional Court escalation
- 1-month SLA not tracked
- Automated decision safeguards missing
- Administrative Court 30-day appeal SLA not anticipated
Enforcement Sanctions and Remedies - Montenegro PDPL
Manage AZLP enforcement under Montenegro PDPL. AZLP powers include investigation + on-site inspections + information notices + enforcement notices + variation orders + compliance orders + cease processing orders + warnings + reprimands + complaint mechanism free of charge. Penalties: administrative fines up to EUR 20,000 for individuals + EUR 40,000 for entities (significantly lower than GDPR EUR 20M / 4% turnover - pending review for EU accession harmonisation - expected uplift to GDPR level post-accession ~2028). Civil claim for material and non-material damage under Code of Obligations (Zakon o obligacionim odnosima). Administrative Court of Montenegro (Upravni sud Crne Gore) appeal within 30 days of AZLP decision. Supreme Court of Montenegro (Vrhovni sud Crne Gore) further appeal on points of law. Constitutional Court (Ustavni sud Crne Gore) constitutional review where applicable. Cr
- AZLP correspondence and notice tracking + remediation evidence
- Current penalty exposure (EUR 20K individual + EUR 40K entity) + post-EU-accession GDPR uplift preparedness
- Administrative Court of Montenegro 30-day appeal preparedness
- Supreme Court + Constitutional Court escalation plan
- Civil claim preparedness under Code of Obligations
- Western Balkans WBRDPN bilateral cooperation
- Convention 108+ Committee mutual assistance
- Penalty exposure assessment doesn't account for EU accession uplift (significant)
- Administrative Court 30-day SLA missed
- Bilateral cooperation with neighbouring DPAs not engaged
- Constitutional Court process for novel constitutional issues not mapped
Governance DPO ROPA DPIA - Montenegro PDPL
Operate Montenegro PDPL governance structure including DPO designation + ROPA + DPIA + Codes of Conduct + sub-regulations. DPO mandatory for public authorities + bodies whose core activities consist of large-scale regular and systematic monitoring + bodies whose core activities consist of large-scale processing of sensitive data + bodies whose processing likely to result in high risk (GDPR Article 37 alignment). DPO independent + reports to highest management + contact published + AZLP notification. ROPA under GDPR Article 30 alignment in Montenegrin or English covering controller and processor activities. DPIA under GDPR Article 35 for high-risk processing including large-scale sensitive + systematic monitoring of public areas + profiling presenting significant risk + AI/ML processing with significant individual impact + AZLP consultation under Article 36 for unmitigated high residual r
- DPO designation + AZLP notification (GDPR Article 37 alignment)
- ROPA Article 30 alignment
- DPIA register + AZLP consultation Article 36 records
- Codes of Conduct AZLP-registered adherence
- Certification via accredited certification body
- No DPO despite triggers
- DPIA not conducted for AI/ML
- Codes of Conduct claimed but not AZLP-registered
- Sub-regulations and bylaws not monitored for new requirements
Scope and Authority - Montenegro PDPL
Establish the legal foundation of Montenegro Law on Personal Data Protection (Zakon o zastiti podataka o licnosti) 2023 + adopted by Skupstina + signed by President Jakov Milatovic + Official Gazette publication + replaced 2008 Law (insufficient for EU accession) + EU GDPR Regulation 2016/679 alignment + Convention 108+ + EU accession candidate Chapter 23 + 24 alignment. Constitution of Montenegro Article 41 protection of personal data + Article 43 data abuse protection + Article 51 access to information anchors. Agency for Personal Data Protection and Access to Information (Agencija za zastitu licnih podataka i pristup informacijama - AZLP) Podgorica + dual function for data protection AND access to information + Council 5 members + Director appointed by Skupstina + reports to Parliament + EDPB observer + Convention 108+ Committee. Geographic scope Republic of Montenegro (Crna Gora) 13,
- Montenegro PDPL 2023 applicability assessment
- Constitution Article 41 + 43 + 51 anchor documentation
- AZLP correspondence records + dual function (data protection + access to information)
- EU accession Chapter 23 + 24 progress alignment evidence
- Sectoral coordination (CBCG + EKIP + Securities + Police)
- EU accession Chapter 23 alignment not assessed
- Dual AZLP function (data + access) confusion in operations
- Western Balkans WBRDPN cooperation not engaged
Security and Breach Notification - Montenegro PDPL
Implement technical and organisational security measures + breach notification process aligned with GDPR Articles 32-34 + Montenegro National Cyber Security Strategy + CIRT-MNE. Security measures appropriate to risk including encryption + access controls + activity logging + secure development + supplier security + business continuity + workforce training. AZLP Security Guidelines providing baseline. Breach notification within 72 hours to AZLP + concurrent affected data subject notification without undue delay where high risk + breach register maintenance + breach response plan + post-incident review. Coordination with CIRT-MNE (Computer Incident Response Team Montenegro) under Ministry of Public Administration Digital Society and Media + Cybercrime Convention (Budapest Convention) signatory + Council of Europe Convention 108+ + national Cyber Security Strategy 2018-2021 + 2022-2026 (in
- AZLP Security Guidelines adoption evidence
- GDPR Article 32 security measures
- 72-hour AZLP breach notification procedure + breach register + response plan
- CIRT-MNE coordination protocol for critical infrastructure
- Cybersecurity Act 2018 + NIS2 transposition preparation
- CBCG Cybersecurity Guidelines (banking) compliance
- No 72-hour notification capability
- CIRT-MNE dual notification not mapped for critical infrastructure
- NIS2 transposition readiness gap
Sensitive Data and Children - Montenegro PDPL
Process sensitive personal data and children data under enhanced conditions aligned with GDPR Article 9 + Article 8. Sensitive Personal Data categories: racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union membership + genetic data + biometric data uniquely identifying natural person + health data + data concerning sex life or sexual orientation + criminal convictions and offences. Processing prohibited unless explicit consent or one of the lawful conditions (employment + vital interests + non-profit body + manifestly public + legal claims + substantial public interest + healthcare professional + public health + archiving/research). Children digital consent age 16 (GDPR default + may be lowered to 13 by sub-regulation aligned with GDPR Article 8(1)). Parental consent for under 16 (or under 13 if lowered) + age verification + reasonable efforts.
- Sensitive data inventory with GDPR Article 9 lawful condition mapping
- Children under 16 parental consent (or 13 if lowered)
- AZLP guidance on biometric + genetic + health processing
- Centre for Social Work coordination for minor processing
- Children age verification weak
- Biometric and genetic processing without specific AZLP guidance compliance
- Sub-regulation lowering to 13 not monitored
Seven Data Protection Principles - Montenegro PDPL
Implement the seven foundational Data Protection Principles aligned with EU GDPR Article 5. (1) Lawfulness fairness and transparency. (2) Purpose limitation. (3) Data minimisation. (4) Accuracy. (5) Storage limitation. (6) Integrity and confidentiality. (7) Accountability. Lawful basis aligned with GDPR Article 6 (consent + contract + legal obligation + vital interests + public task + legitimate interests). Privacy notices in Montenegrin (Cyrillic and Latin scripts) and minority languages where reasonably required (Serbian + Bosnian + Albanian + Croatian). AZLP guidance issued for sectoral implementation. ROPA under GDPR Article 30 alignment with Montenegrin and English where applicable. Data Protection by Design and by Default (GDPR Article 25 alignment). Accountability principle requires demonstrable compliance through policies + procedures + training + records + audits + measures.
- Seven GDPR-aligned principles implementation matrix
- Lawful basis register per processing
- Bilingual privacy notices (Montenegrin Cyrillic + Latin + minority languages where required)
- ROPA in Montenegrin or English
- AZLP guidance adoption evidence
- English-only notices despite Montenegrin (both scripts) requirement
- Minority language notices missing (Serbian + Bosnian + Albanian + Croatian)
- ROPA incomplete
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.