Law / Montenegro

Law on Information Security, General Security Measures

Law on Information Security, Arts. 1 to 3, 7 to 15 and 18(1) to (3)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 5 December 2024.

A security baseline statutes rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • This binds you if you access or process data, or use and manage a network and information system, in Montenegro, whether you are a business, another legal entity or a natural person, and regardless of your sector or size (Article 2).
  • Adopt rules for handling data, log who has accessed it, and oversee the security of that data (Article 12).
  • Physically secure the premises, spaces and devices that house your network and information system (Article 14).
  • Protect the confidentiality, integrity and availability of the data you process, store or transmit through the planning, design, construction, use, maintenance and decommissioning of that system (Article 15).
  • Designate an employee to monitor your compliance with these measures (Article 18(3)).

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 70 frames a violation as an administrative misdemeanor (“prekršaj”) carrying only the fine described in penalty_structure, and creates no separate criminal offence. Montenegro's Criminal Code Article 353 (unauthorised use of a computer or computer network) is a distinct offence against a system committed by an intruder, already filed on this jurisdiction's scraping-topic row.

Penalty structure

Article 70(1) fines the legal entity 500 to 5,000 EUR for failing to apply the Article 11 to 15 measures or to designate a compliance-monitoring employee, and Article 70(1) fines the responsible individual within that entity 30 to 1,500 EUR for the same violation; a repeat violation can add a 3-to-6-month suspension of the entity's professional activity. An entity the Government has designated essential or important instead faces the higher fine tier this jurisdiction's companion row on essential and important entities describes (Articles 68 and 69).

Rule
Fixed only
As of
18 September 2026
Minimum
500
Currency
EUR
Fixed cap
5,000

Who enforces it

Enforcement body

The Cybersecurity Agency of Montenegro (Agencija za sajber bezbjednost) for every organ or other entity outside the state administration (Article 6); the Ministry of Public Administration, Digital Society and Media, through an inspector for information society services, for a state administration body (Articles 64 to 67).

Settledness

As of
18 September 2026
Guidance link
https://www.gov.me/en/mju
Guidance body
Ministarstvo javne uprave, digitalnog društva i medija (Ministry of Public Administration, Digital Society and Media)
Open questions
Does Article 18(3)'s duty to designate an employee to monitor compliance with these measures apply to a sole proprietor who falls within Article 2's scope but has no employee to designate?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 2 binds every state organ, ministry, local self-government body, legal entity exercising public authority, business company, other legal entity and natural person that accesses or processes data, or uses and manages a network and information system, in Montenegro.

Article 18(2) requires every such organ or entity that the Government has not designated an essential or important entity to apply the data-protection measures of Article 12 (rules for handling data, access logging, and security oversight), the physical-protection measures of Article 14, and the network-and-information-system-protection measures of Article 15 (protecting the confidentiality, integrity and availability of data through the planning, design, construction, use, maintenance and decommissioning of that system), and Article 18(3) requires every organ or entity, designated or not, to name an employee to monitor its own compliance with these measures.

An essential or important entity carries the same Article 12, 14 and 15 duties as part of the wider Article 11 to 16 measures this jurisdiction's companion row on essential and important entities describes.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official Gazette of Montenegro (“Službeni list Crne Gore”), No. 113/2024, 27 November 2024

Back to the example  ·  Lint your app