DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Europe · In force · Opt-in

🇲🇪 Montenegro Data Privacy Laws

Montenegro has operated a directive-era law since 2008 and adopted a GDPR-aligned replacement as part of its EU accession work; expect EU-style obligations as the new framework applies.

Updated September 28, 2026 · digitalprivacyregs.com
Status
In force
Consent model
Opt-in
Primary law
Law on Personal Data Protection (2008, as amended); GDPR-aligned replacement adopted on the EU accession track
Year
2008
Authority
AZLP
Marketing consent
Consent-first framework; GDPR alignment phasing in.
Transfers
Transfers abroad need an adequate destination or the authority's authorization.
Penalties
The authority can impose administrative fines.

The framework

Montenegro's framework rests on the Law on Personal Data Protection (2008, as amended), with the AZLP as the supervisory authority.

That puts Montenegro in the global opt-in majority, where permission comes before processing and marketing waits for consent.

Key instruments

Law on Personal Data Protection (2008, as amended); GDPR-aligned replacement adopted on the EU accession track

2008 · In force

Montenegro has operated a directive-era law since 2008 and adopted a GDPR-aligned replacement as part of its EU accession work; expect EU-style obligations as the new framework applies.

Marketing and advertising

Consent-first framework; GDPR alignment phasing in. That single sentence decides most channel plans here.

Cross-border transfers

Transfers abroad need an adequate destination or the authority's authorization.

Enforcement and penalties

The authority can impose administrative fines. Read the ceiling together with the authority's track record, which prices the risk.

Cite this page: "Montenegro Data Privacy Laws." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/montenegro.html. Accessed [date].