fbpx

Legislation Update: Montenegro

GDPR Comes to Montenegro: Is Your Business Ready?

Montenegro has adopted a new Personal Data Protection Law (the “New Law”), bringing a long-awaited overhaul of its data protection framework. The New Law entered into force on 19 September 2026 but will apply from 19 March 2027, following a six-month transition period.

The reform is notable not only because it replaces a framework largely dating back to 2008, but also because it brings Montenegrin data protection rules much closer to the EU’s GDPR, on which it is modelled. For businesses, this means a major shift towards a more developed compliance framework, coupled with materially higher enforcement exposure and important changes in areas such as extraterritorial reach, personal data breaches, international transfers and accountability.

However, multinational companies should not assume their existing GDPR compliance programme can simply be rolled out in Montenegro. Certain features of the Montenegrin regime, such as its data transfer rules and local transitional requirements, require separate consideration.

Against this background, we highlight several aspects of the New Law which are likely to be particularly relevant for businesses preparing for its application.

Significantly Increased Fines

One of the most notable changes under the New Law is the dramatic increase in potential fines.

Under the existing law, the maximum fine is EUR 20,000, whereas the New Law follows the GDPR’s two-tier model, raising the cap to EUR 2 million or 4% of total worldwide annual turnover, whichever is higher, for more serious infringements, namely breaches of the fundamental processing principles, data subject rights and international data transfer requirements. Other infringements may attract fines of up to EUR 1 million or 2% of total worldwide annual turnover, whichever is higher.

The fine amount will depend on the circumstances of the infringement, including, among other things, its nature and seriousness, the level of fault, previous similar infringements, and cooperation with the Montenegrin data protection authority (the “Authority”).

Extraterritorial Scope and Local Representative Appointment

The New Law considerably expands the territorial reach of Montenegro’s data protection rules. While the existing law primarily focuses on processing carried out in Montenegro, the New Law introduces a GDPR-style extraterritorial scope.

This means it will also apply to controllers and processors without an establishment in Montenegro where their processing relates to offering goods or services to individuals in Montenegro or monitoring their behaviour in Montenegro.

Foreign businesses subject to these rules will, generally, also be required to appoint a representative in Montenegro. Businesses active in the Montenegrin market should therefore assess whether the New Law applies to them even in the absence of a local establishment and whether a local representative must be appointed.

International Data Transfers: EU Adequacy and SCCs Not Yet Available

The New Law substantially reshapes Montenegro’s international data transfer regime and creates a critical transitional issue for businesses that will need to address when transferring personal data abroad.

Under the existing law, the Authority’s prior approval is not required for a large portion of transfers, including transfers to EU and EEA member states and to countries recognised by the European Commission as providing an adequate level of data protection, as well as to processors in third countries in cases where EU standard contractual clauses (SCCs) are used as a safeguard. The New Law, however, does not recognise either the EU’s list of adequate countries or its SCCs until Montenegro joins the EU. Until then, the Authority also cannot adopt its own SCCs, since these would require approval by the European Commission, which is only possible once Montenegro is a member state.

In the meantime, unless the Montenegrin Government adopts its own adequacy decision(s), companies will need to rely on the remaining transfer tools: a transfer approval from the Authority, binding corporate rules, codes of conduct or certification mechanisms approved locally or the derogations for specific situations. None of these is a straightforward substitute for EU adequacy or SCCs. Transfer approvals, as well as the locally approved tools, will depend on the capacity of the competent Montenegrin authorities and forthcoming practice, and the derogations are designed for occasional rather than routine transfers.

Businesses transferring personal data from Montenegro should therefore reassess their existing transfer arrangements before the New Law becomes applicable, particularly where they currently rely on EU/EEA adequacy or EU SCCs.

Data Breach Notification

Unlike the existing law, the New Law introduces a general GDPR-style personal data breach notification regime. Controllers will generally be required to notify the Authority without undue delay and, where feasible, no later than 72 hours after becoming aware of a breach, unless it is unlikely to result in a risk to individuals. Affected individuals must also be notified if the breach is likely to result in a high risk to their rights and freedoms. Processors must notify the relevant controllers of the breach without undue delay after becoming aware of it.

Businesses should therefore ensure that appropriate internal breach-response and escalation procedures are in place before the New Law becomes applicable.

Preparing for March 2027

The six-month transition period gives businesses a much-needed opportunity to review their existing data protection framework and address the gaps before the New Law becomes applicable.

For companies already operating under the GDPR, much of the required compliance framework should already be familiar and, in many cases, existing documentation and processes can be adapted for Montenegro rather than developed from scratch. The main exercise will be to identify and address those areas where the New Law introduces specific local or transitional requirements.

In particular, businesses should consider:

  • reviewing processing activities and records, including the shift from registering filing systems with the Authority to keeping internal records of processing activities;
  • reassessing DPO requirements against the New Law’s GDPR-style appointment criteria;
  • mapping international data flows and reviewing transfer mechanisms, particularly in light of the major transfer issues outlined above;
  • updating key data protection documentation, including privacy notices, consent forms and controller-processor agreements, to match the much stricter new requirements;
  • introducing or updating personal data breach procedures to ensure that incidents can be promptly identified, escalated, assessed, and documented; and
  • reviewing internal policies and technical and organisational measures to ensure that compliance with the New Law can be demonstrated.

Ultimately, the New Law gives the Authority sharp teeth, and that alone should be enough to push businesses towards compliance. How hard, and how soon, those teeth will bite remains to be seen: further regulatory developments and the Authority’s guidance will be key to clarifying how the New Law operates in practice. But businesses that wait to find out are taking an avoidable risk. The time to prepare is now, not in March 2027.

 

 

The information in this document does not constitute legal advice on any particular matter and is provided for general informational purposes only.