What Montenegro Law on Personal Data Protection No. 79/2017 - AZLP ME requires
Montenegro's Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti), adopted by the Parliament of Montenegro in 2017 as Official Gazette of Montenegro No. 79/2017 and significantly amended in 2021 (Official Gazette of Montenegro No. 86/2021) to align comprehensively with the EU General Data Protection Regulation, is Montenegro's primary personal data protection legislation establishing a GDPR-equivalent rights-based framework. Montenegro received EU candidate status in 2010 and has been among the most advanced Western Balkans EU accession candidates, with accession negotiations opened in 2012 and data protection reform forming part of the EU accession obligations covering Judiciary and Fundamental Rights. The supervisory authority is the Agency for Personal Data Protection and Free Access to Information (Agencija za zaštitu podataka o ličnosti i slobodan pristup informacijama - AZLP ME), an independent institution whose mandate covers both personal data protection and freedom of information in Montenegro. Key features of Montenegro's Law on Personal Data Protection as amended: (1) Scope - applies to personal data processing by public authorities, legal entities, and individuals established in Montenegro or processing data of individuals located in Montenegro regardless of establishment location; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right not to be subject to solely automated decisions; and right to data portability; (6) Data Protection Officer - required for public authorities, organisations conducting large-scale systematic monitoring, and organisations processing sensitive personal data on a large scale; (7) Breach notification - controllers must notify the AZLP ME within 72 hours of becoming aware of a personal data breach likely to result in risk to data subjects; high-risk breaches require data subject notification; (8) Data Protection Impact Assessment - required for high-risk processing aligned with GDPR standards; (9) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or using AZLP ME-approved safeguards; and (10) Administrative fines - graduated fines for violations. Montenegro's Law is among the most GDPR-aligned data protection frameworks in the Western Balkans, positioning Montenegro strongly in its EU accession trajectory and supporting its growing digital economy and tourism sector.
Pillar: Data Protection & Privacy · Authority: Agency for Personal Data Protection and Free Access to Information - AZLP ME (Montenegro) · Version: 1.0.0 · Last updated:
Primary source: https://www.azlp.me/
SHA-256 integrity: 74e35537dee62979cc463aacfd5722f0575db8e94a58c447d2aa01977f02b068
Primary Citations — 7 traced to source
- Law on Personal Data Protection (Official Gazette of Montenegro No. 79/2017, amended Official Gazette of Montenegro No. 86/2021) - processing principles: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, security, accountability; sensitive personal data: racial/ethnic origin, political opinions, religious beliefs, trade union membership, health, sexual orientation, criminal convictions, biometric, genetic; data subject rights: access, rectification, erasure, restriction, portability, objection, automated decision-making protection; DPO mandatory; 72-hour AZLP ME breach notification; DPIA required; GDPR-equivalent transfer framework
- Agency for Personal Data Protection and Free Access to Information - AZLP ME (Agencija za zaštitu podataka o ličnosti i slobodan pristup informacijama, Montenegro) - independent supervisory authority whose mandate covers both personal data protection and freedom of information; registers DPO notifications; receives breach notifications; investigates complaints; conducts inspections; issues binding orders; imposes administrative fines; publishes compliance guidance aligned with EU EDPB standards; participates in Council of Europe data protection consultations; azlp.me is the official AZLP ME portal
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/me-pdpa-2017.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/me-pdpa-2017.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/me-pdpa-2017
- Back to registry: Browse all 10,090 compliance nodes