What Is Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti)?
Montenegro’s operative statute is the Law on Personal Data Protection, currently consolidated through amendments 79/2008, 70/2009, 44/2012, 22/2017, and 77/2024. The latest located amendment was published on 5 August 2024 and became effective on 13 August 2024. The original law was adopted on 17 December 2008, formally entered into force on 30 December 2008, and delayed application for six months to 30 June 2009. No replacement statute exists yet, but official 2026 government material confirms that a new personal-data-protection law remains under preparation. The Agency for Personal Data Protection and Free Access to Information (AZLP) is the regulator. The current framework provides access, correction, unlawful-processing deletion, objection, automated-decision safeguards, compensation, and multiple fixed procedural deadlines. Deletion is notably narrower than a general GDPR-style erasure right: no general “no longer necessary” ground was located, and deletion is tied specifically to unlawful processing. No Montenegro-specific data-broker complaint or deletion route was located, although AZLP announced a narrow July 2025 initiative concerning deletion of decisions identifying rehabilitated persons.
At a glance
- Full name
- Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti)
- Short code
- Law on Personal Data Protection
- Jurisdiction
- Montenegro
- Enacted
- 2008
- Last major update
- Current consolidated framework includes amendments 79/2008, 70/2009, 44/2012, 22/2017, and 77/2024; amendment 77/2024 was published 5 August 2024 and effective 13 August 2024; official 2026 material confirms a replacement law remains under preparation
- Regulator
- Agency for Personal Data Protection and Free Access to Information (AZLP)
- Private right of action
- Yes
Scope, who Law on Personal Data Protection covers
Protected data
Data subject rights
Protection regardless of nationality or residence
Right to withdraw consent at any time
Right to object to direct marketing before processing
Protection against specified automated decisions, with an opportunity to express a view
Right to information about direct and indirect collection
Right of access through a written, identity-verified request
Right to correction of incomplete or inaccurate data
Right to deletion specifically where processing is unlawful
Right to notification of the subject and relevant third parties after correction or deletion, normally within 8 days
Right to request protection from the AZLP
Right to compensation under general compensation rules
No separate statutory portability right was located
No general processing-restriction right was located
Notable features
Montenegro retains an older amended framework while a replacement law is under preparation. The law has a detailed deadline map, including 15-day controller response periods, 8-day correction or deletion notices, a 60-day AZLP rights-protection decision period, and an 8-day objection period for inspection records. A narrow July 2025 AZLP initiative concerning deletion of decisions identifying rehabilitated persons is a real institutional example, but not a general public-record or broker-removal system.
Enforcement & penalties
Regulator: Agency for Personal Data Protection and Free Access to Information (AZLP)
Penalties: Article 74 misdemeanor fines range from €500-€20,000 for a legal person, €150-€2,000 for a responsible person or natural person, and €150-€6,000 for an entrepreneur. The violations include unlawful processing, unlawful special-category or criminal-offence data processing, failure to delete unlawful data, inadequate security, unlawful video surveillance, failure to answer access, correction, or deletion requests, and non-compliance with Agency orders.
Private right of action: Article 48 provides compensation under general compensation rules. The framework also provides administrative-court challenge routes, including a 20-day filing period from service under the general Administrative Dispute Law; no separate fixed filing deadline for a civil compensation action was located.
Relevance to data brokers
No Montenegro-specific data-broker complaint or deletion route was located — no statutory provision or AZLP form addresses this specifically. No general public-record-specific complaint or deletion route was located either. Article 42(5) treats legally public registers as a transfer exception, and Article 27(2) exempts law-established public registers from the controller’s pre-notification obligation, but neither creates a general public-record deletion process.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Montenegro provide a general right to delete personal data?+
Not located. The reviewed law ties deletion specifically to unlawful processing, and no general GDPR-style “no longer necessary” erasure ground was located.
How long does the AZLP have to decide a rights-protection request?+
Article 47 provides a 60-day deadline for an AZLP rights-protection request decision. The report also identifies 15-day controller response periods and 8-day correction, deletion, and inspection-record stages.
Does Montenegro have a dedicated data-broker deletion route?+
Not located. The reviewed statute and AZLP forms do not address data brokers specifically. A July 2025 AZLP initiative concerning deletion of decisions identifying rehabilitated persons is a narrow institutional example, not a general broker or public-record removal route.
Official sources & citations
Other international privacy regimes
Law on Personal Data Protection sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
