Law / Montenegro

Montenegro

privacy

Montenegro is not a General Data Protection Regulation (GDPR) jurisdiction, and which act currently governs is genuinely unresolved. Professional trackers disagree, sometimes within one source, between the 2008 Law on Personal Data Protection (Official Gazette Nos. 79/08, 70/09, 44/12, 22/17, and an August 2024 amendment, 77/24) and a separately reported 2023 replacement, Official Gazette No. 21/2023.

This research read a 70/09-consolidated English translation of the 2008 act directly through crawler infrastructure and confirmed it is real and hosted by Montenegro's own supervisory authority, and weighed the more specific and more recently dated sources toward the 2008 act, as amended, being what currently governs, but could not independently confirm this against the 2023 candidate or against the later 44/12, 22/17 and 77/24 amendments to the specific articles read.

This document records the 2008 act as the operative regime on that working resolution, not as a settled fact. The instrument below is recorded as enacted rather than in_effect: neither this research nor the consolidated text located could establish a specific promulgation, publication, or commencement date for the act or its amendments.

6 instruments named 1 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

Law on Personal Data Protection

cite Official Gazette of Montenegro Nos. 79/08, 70/09, 44/12, 22/17 and 77/24, as amended stage Enacted source 70/09-consolidated English translation hosted by the Agency for Personal Data Protection and Free Access to Information (azlp.me), read through crawler infrastructure (54,193 characters, not truncated)

This is the working resolution of a genuinely unresolved status question: whether the 2008 Law on Personal Data Protection, as amended through the August 2024 amendment (OG 77/24), or a separately reported 2023 replacement (OG No. 21/2023) currently governs.

This document records the 2008 act as enacted rather than in_effect: this research could not source a specific promulgation, publication, or commencement date for the 2008 act or any of its four amendments from a primary source, only the general year 2008 and the amendment year 2024, so no effective_date is recorded.

Primary text, read through a 70/09-consolidated English translation hosted by AZLP, confirms biometric data as a special category under a generic definition with no enumerated examples, distinct in kind from the enumerated-example definitions found elsewhere in this batch, plus a dedicated Biometric Measures chapter (Articles 31-32) scoped narrowly to workplace access control and presence recording, not a general commercial biometric-capture regime.

It also confirms a civil damages right under Article 48 and a cross-border transfer regime under Article 41 requiring the prior consent of the supervisory authority. This text is not confirmed unchanged by the 44/12, 22/17 or 77/24 amendments, and whether it remains the operative law at all, rather than having been superseded by a 2023 replacement, was not resolved in this research.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.