AI LAW RADAR · Daily Last verified 28 Aug 2026

Jurisdiction dossier

Montenegro: AI regulation & deadlines

Montenegro has no AI-specific statute in force and one binding automated-decision rule, and it is the first in the atlas from the pre-GDPR generation. Art. 15a of the Zakon o zaštiti podataka o ličnosti («Službeni list Crne Gore» br. 79/08, 70/09, 44/12, 22/17, 77/24) is drafted on Directive 95/46 art. 15 rather than on GDPR art. 22, and the differences run in the restrictive direction on the trigger and in the permissive direction on everything else. It is a prohibition addressed to the decision-maker, not a right the data subject has to invoke: decisions on a person's rights, obligations and interests, and the assessment of their personal characteristics and abilities — the statute names work performance, reliability, creditworthiness and conduct — may not rest solely on automatic data processing. There is no concept of profiling in the Act, and no ‘legal effects or similarly significantly affects’ threshold: the trigger is the subject-matter of the decision. Art. 15a(2) allows only two exits, contract and authorising law, so unlike GDPR art. 22(2)(c), Serbia's art. 38 and North Macedonia's art. 26 there is no explicit-consent route out. There is no special-categories bar of the GDPR art. 22(4) kind. The safeguards are folded into the contract exit rather than standing alone, and they name only the possibility for the person to express a view — no express right to human intervention and no right to contest the decision. The transparency limb is reactive: art. 43(2)(7) requires the controller to disclose the manner of the automated processing in an art. 15a case, but only in the written reply to a written access request within 15 days. Art. 74 is where the asymmetry bites — its 21 misdemeanour items do not include art. 15a, so the prohibition itself carries no fine, while failure to answer the art. 43(1) request in time is item 18 at €500–€20,000 for a legal person. Like North Macedonia and unlike Serbia and Albania, Montenegro has no Law Enforcement Directive act, so there is no police-side counterpart. Both gaps are the subject of two Government bills tabled in the Skupština on 7 August 2026 — a full GDPR-style Zakon o zaštiti podataka o ličnosti whose art. 22 is a GDPR art. 22 transposition, and a separate LED-style act for competent authorities — both still ‘u proceduri’. 1 obligation tracked — 1 in force.

Binding — Binding sectoral Flagship law: ZZPL art. 15a

Montenegro has no AI-specific statute in force and one binding automated-decision rule, and it is the first in the atlas from the pre-GDPR generation. Art. 15a of the Zakon o zaštiti podataka o ličnosti («Službeni list Crne Gore» br. 79/08, 70/09, 44/12, 22/17, 77/24) is drafted on Directive 95/46 art. 15 rather than on GDPR art. 22, and the differences run in the restrictive direction on the trigger and in the permissive direction on everything else. It is a prohibition addressed to the decision-maker, not a right the data subject has to invoke: decisions on a person's rights, obligations and interests, and the assessment of their personal characteristics and abilities — the statute names work performance, reliability, creditworthiness and conduct — may not rest solely on automatic data processing. There is no concept of profiling in the Act, and no ‘legal effects or similarly significantly affects’ threshold: the trigger is the subject-matter of the decision. Art. 15a(2) allows only two exits, contract and authorising law, so unlike GDPR art. 22(2)(c), Serbia's art. 38 and North Macedonia's art. 26 there is no explicit-consent route out. There is no special-categories bar of the GDPR art. 22(4) kind. The safeguards are folded into the contract exit rather than standing alone, and they name only the possibility for the person to express a view — no express right to human intervention and no right to contest the decision. The transparency limb is reactive: art. 43(2)(7) requires the controller to disclose the manner of the automated processing in an art. 15a case, but only in the written reply to a written access request within 15 days. Art. 74 is where the asymmetry bites — its 21 misdemeanour items do not include art. 15a, so the prohibition itself carries no fine, while failure to answer the art. 43(1) request in time is item 18 at €500–€20,000 for a legal person. Like North Macedonia and unlike Serbia and Albania, Montenegro has no Law Enforcement Directive act, so there is no police-side counterpart. Both gaps are the subject of two Government bills tabled in the Skupština on 7 August 2026 — a full GDPR-style Zakon o zaštiti podataka o ličnosti whose art. 22 is a GDPR art. 22 transposition, and a separate LED-style act for competent authorities — both still ‘u proceduri’.

checked 28 Aug 2026 primary source ↗

The Register

1 obligation
Montenegro Binding

ZZPL art. 15a — a Directive 95/46 art. 15 prohibition, not a GDPR art. 22 right: no consent exit, no human-intervention safeguard, and no fine attached to the prohibition itself

Binds Controllers of personal data filing systems and their processors, public and private alike. Art. 7 applies the Act to processing of personal data carried out automatically, in whole or in part, or otherwise, where the data form or will form part of a filing system. Art. 8 carves out processing for defence and national security purposes (except the supervision provisions) unless another law provides otherwise, and processing by a natural person for their own needs. Art. 15a binds whoever takes the decision — the deployer of the system, not its vendor — and reaches state authorities, state administration bodies, local self-government and local administration bodies, companies, other legal persons, entrepreneurs and natural persons alike, which is the same list art. 74 uses when it sets the fine bands.. Art. 15a of the Zakon o zaštiti podataka o ličnosti («Službeni list Crne Gore» br. 79/08 of 23.12.2008, 70/09, 44/12, 22/17, 77/24) is Montenegro's automated-decision rule, and it is the first entry in the atlas drafted from Directive 95/46 art. 15 rather than from GDPR art. 22. Art. 15a(1): «Prilikom odlučivanja o pravima, obavezama i interesima lica, procjenjivanje njegovih ličnih svojstava i sposobnosti (rezultati rada na radnom mjestu, pouzdanost, kreditna sposobnost, ponašanje i sl.), koji su od značaja za odlučivanje, ne mogu se zasnivati isključivo na automatskoj obradi podataka.» Four structural differences from the GDPR generation follow. First, the form: this is a prohibition binding whoever takes the decision, not a right the data subject must invoke, so nothing turns on the person objecting. Second, the trigger: there is no definition of profiling anywhere in the Act and no ‘legal effects or similarly significantly affects’ threshold — what brings a decision inside art. 15a is its subject-matter (rights, obligations and interests) and the fact that it evaluates personal characteristics and abilities, with an illustrative list that reads as workplace, credit and conduct scoring. Third, the exits: art. 15a(2) admits only two, and neither is consent. «1) u toku zaključivanja ili izvršavanja ugovora uvažen zahtjev lica čiji se podaci obrađuju ili postoje odgovarajuće mjere zaštite njegovih zakonitih interesa (mogućnost da lice izrazi svoje mišljenje i sl.); 2) to zakonom propisano, pod uslovom da su propisane mjere zaštite zakonitih interesa lica.» Where GDPR art. 22(2)(c), Serbia's art. 38(2)(3) and North Macedonia's art. 26(2)(в) all let explicit consent license a solely-automated decision, Montenegro does not — the prohibition is narrower in its trigger but harder to contract out of. Fourth, the safeguards: they are not a free-standing paragraph as in GDPR art. 22(3) but a condition inside the contract exit, and the only one named is the possibility for the person to express an opinion. There is no express right to obtain human intervention from the controller and no right to contest the decision. Nor is there a special-categories bar of the GDPR art. 22(4) kind. The transparency limb is reactive only. Art. 43(1) obliges the controller, on a written request and after verifying identity, to reply within 15 days on whether it processes the person's data, and art. 43(2)(7) adds to that reply the «načinu automatske obrade ličnih podataka u slučaju iz člana 15a ovog zakona» — the manner of the automated processing in an art. 15a case. Nothing requires the controller to volunteer the existence of automated decision-making, so there is no analogue to GDPR arts. 13(2)(f) and 14(2)(g); a person who does not ask is not told. In the same reactive posture, art. 26 requires the controller to keep a record of its filing systems, art. 27 to notify the Agency before establishing an automatic filing system, and art. 28 to obtain the Agency's prior consent for automatic processing presenting a special risk — which expressly includes processing «koji se odnose na procjenu ličnosti, sposobnosti ili ponašanje», the same evaluative processing art. 15a is about. Art. 28 is the closest thing in the Act to a DPIA, and it is a licensing step rather than an assessment. Like North Macedonia's ZZLP and unlike Serbia's ZZPL and Albania's Law 124/2024, this Act has no Law Enforcement Directive part, so there is no police-side counterpart to Serbia's art. 39 or Albania's art. 53.

In force since 17 August 2012 and unamended since. Art. 15a was not in the Act as adopted: the supervisory authority's own official English translation of the consolidation at «Sl. list CG» 79/08 and 70/09 runs straight from Article 15 to Article 16 with nothing in between. It was inserted by the Zakon o izmjenama i dopunama Zakona o zaštiti podataka o ličnosti at «Sl. list CG» 44/12 of 09.08.2012, which the Official Gazette's own register records as having entered into force on 17.08.2012, and the Agency's consolidated text stamped for 79/08, 70/09 and 44/12 — archived before the next amendment — already carries art. 15a in the wording in force today. Neither later amendment touches it. The 2017 amendment (22/17 of 03.04.2017) is four articles long and, on the Government's own bill as tabled in the Skupština, changes only art. 28(1) (adding Agency consent for video surveillance of public areas), art. 37(3) (cutting footage retention from one year to six months), art. 40 and a new art. 40a. The 2024 amendment (77/24 of 05.08.2024, in force 13.08.2024) is a ‘Zakon o izmjeni’ — a single change — and art. 15a reads identically in the Agency's post-77/24 consolidated text. The Official Gazette records the Act's status as ‘Važeći’ and lists no successor. SUPERSESSION WATCH: on 7 August 2026 the Government tabled two bills that would replace this regime wholesale — the Predlog zakona o zaštiti podataka o ličnosti (EPA 1164 XXVIII, act no. 23-3/26-12), whose član 22 ‘Automatizovano donošenje pojedinačnih odluka, uključujući profilisanje’ is a GDPR art. 22 transposition with a defined profilisanje, a DPIA trigger for systematic evaluation and the full art. 13–14 disclosure duties; and the Predlog zakona o zaštiti podataka o ličnosti koje obrađuju nadležni organi u svrhu sprečavanja, istraživanja, otkrivanja ili gonjenja krivičnih djela ili izvršenja krivičnih sankcija (EPA 1165 XXVIII, act no. 23-3/26-13), which would give Montenegro the LED-side act it currently lacks. Both were still ‘u proceduri’ as of 28 August 2026, with committee opinions filed on 24 August 2026 and no adoption vote and no Official Gazette publication. Art. 15a governs until they are enacted and their transitional provisions bite.

Stated maximum penalty — None for the prohibition itself; €500–€20,000 for a legal person that fails the transparency limb attached to it. Art. 74(1) lists 21 misdemeanours and art. 15a is not among them, so a controller that bases a decision solely on automatic processing outside the two art. 15a(2) exits commits no offence under this Act. What is fineable is the reply: art. 74(1)(18) covers failure to deliver the art. 43(1) notification — which by art. 43(2)(7) must describe the manner of the automated processing in an art. 15a case — within 15 days of the request. The bands under art. 74 are €500–€20,000 for a legal person, €150–€6,000 for an entrepreneur, and €150–€2,000 for the responsible person in a legal entity, in a state authority, in a state administration body, in a local administration or local self-government body, and for a natural person. Two neighbouring items reach the same evaluative processing from the other side: art. 74(1)(9) fines failure to notify the Agency before establishing an automatic filing system (art. 27(1)), and art. 28 makes the Agency's prior consent a precondition for automatic processing that assesses personality, ability or conduct. The Agency's own supervisory route is art. 71 — an order or prohibition, whose breach is art. 74(1)(21) — which is how a solely-automated decision would in practice be stopped, since the prohibition carries no fine of its own. This is the same structural gap as Serbia's art. 39(3) and Albania's art. 53(3), but reached from the opposite direction: there the enumeration is drawn entirely from the GDPR Part and omits the LED rule; here there is only one Part and the enumeration simply skips art. 15a.

In force · 17 Aug 2012 checked 28 Aug 2026 ZZPL art. 15a ↗ high confidence

Questions & answers

From the data

When does ZZPL art. 15a take effect in Montenegro?

ZZPL art. 15a is already in force, with obligations live since August 17, 2012. Montenegro has no AI-specific statute in force and one binding automated-decision rule, and it is the first in the atlas from the pre-GDPR generation. Art. 15a of the Zakon o zaštiti podataka o ličnosti («Službeni list Crne Gore» br. 79/08, 70/09, 44/12, 22/17, 77/24) is drafted on Directive 95/46 art. 15 rather than on GDPR art. 22, and the differences run in the restrictive direction on the trigger and in the permissive direction on everything else. It is a prohibition addressed to the decision-maker, not a right the data subject has to invoke: decisions on a person's rights, obligations and interests, and the assessment of their personal characteristics and abilities — the statute names work performance, reliability, creditworthiness and conduct — may not rest solely on automatic data processing. There is no concept of profiling in the Act, and no ‘legal effects or similarly significantly affects’ threshold: the trigger is the subject-matter of the decision. Art. 15a(2) allows only two exits, contract and authorising law, so unlike GDPR art. 22(2)(c), Serbia's art. 38 and North Macedonia's art. 26 there is no explicit-consent route out. There is no special-categories bar of the GDPR art. 22(4) kind. The safeguards are folded into the contract exit rather than standing alone, and they name only the possibility for the person to express a view — no express right to human intervention and no right to contest the decision. The transparency limb is reactive: art. 43(2)(7) requires the controller to disclose the manner of the automated processing in an art. 15a case, but only in the written reply to a written access request within 15 days. Art. 74 is where the asymmetry bites — its 21 misdemeanour items do not include art. 15a, so the prohibition itself carries no fine, while failure to answer the art. 43(1) request in time is item 18 at €500–€20,000 for a legal person. Like North Macedonia and unlike Serbia and Albania, Montenegro has no Law Enforcement Directive act, so there is no police-side counterpart. Both gaps are the subject of two Government bills tabled in the Skupština on 7 August 2026 — a full GDPR-style Zakon o zaštiti podataka o ličnosti whose art. 22 is a GDPR art. 22 transposition, and a separate LED-style act for competent authorities — both still ‘u proceduri’.

Who must comply with AI rules in Montenegro?

Current obligations bind, among others, Controllers of personal data filing systems and their processors, public and private alike. Art. 7 applies the Act to processing of personal data carried out automatically, in whole or in part, or otherwise, where the data form or will form part of a filing system. Art. 8 carves out processing for defence and national security purposes (except the supervision provisions) unless another law provides otherwise, and processing by a natural person for their own needs. Art. 15a binds whoever takes the decision — the deployer of the system, not its vendor — and reaches state authorities, state administration bodies, local self-government and local administration bodies, companies, other legal persons, entrepreneurs and natural persons alike, which is the same list art. 74 uses when it sets the fine bands.. Scope and thresholds vary per instrument — see each row's source for the legal text.