Montenegro's Law on Personal Data Protection, a 106-article statute adopted by the parliament in Podgorica on 4 September 2026 and signed into law by President Jakov Milatović on 8 September, entered into force on 19 September 2026. It becomes applicable on 19 March 2027, replacing a 2008 act and extending obligations to companies anywhere in the world that sell to people in Montenegro or track their behaviour there.

In Short

Montenegro, a Balkan country that is trying to join the European Union, has passed a new privacy law that copies most of Europe's rules on personal data. It matters to any website, app or advertising company that tracks people in Montenegro, even one based somewhere else, because breaking the rules can cost up to 2 million euros or 4% of a company's worldwide sales. The rules start to bite on 19 March 2027, and a few of the rules for sending data abroad stay switched off until Montenegro actually becomes an EU member.

From adoption to application

The text was passed by the 28th convocation of the Skupština Crne Gore, the Montenegrin parliament, at a sitting of its sixth extraordinary session on 4 September 2026, under the parliamentary reference 23-3/26-12/11 and EPA 1164 XXVIII. The promulgation decree, numbered 01-009/26-1569/2 and dated 8 September 2026 in Podgorica, carries the signature of President Jakov Milatović. Andrija Mandić signed the adopted text as president of the parliament.

Timing is governed by Article 106. The law enters into force on the eighth day after publication in the Official Gazette of Montenegro and applies six months after that. The attached copy of the law does not show the gazette publication date. According to Luis Alberto Montezuma, who shared the full 45-page text on LinkedIn, the entry-into-force date is 19 September 2026 and the application date is 19 March 2027. Counting back eight days from 19 September places publication on 11 September, although that date is derived rather than stated in either source document.

Montezuma summarised the structural point in his post: "It has 106 articles and replaces the 2008 Act rather than amending it." The predecessor, the Law on Personal Data Protection published in the Official Gazette of Montenegro No. 79/08, was amended four times, in 2009, 2012, 2017 and 2024, according to the gazette references listed in Articles 98, 99, 101 and 105 of the new text.

Several intermediate deadlines fall between the two headline dates. Article 102 requires other Montenegrin laws touching personal data to be aligned with the new statute by 1 December 2026, more than three months before the new rules themselves apply. Article 103 gives the supervisory authority 90 days from entry into force to align its own statute, which works out to 18 December 2026. Article 64 requires the authority to set and publish certification criteria, and the design of its seals and marks, within six months of entry into force. Article 100 gives it one year from entry into force to review transfer approvals granted under the old regime.

Territorial reach mirrors the European model

The ten chapters follow the architecture of the GDPR closely, in some places clause for clause, running from principles and rights through controller duties, transfers, the supervisory authority and fines to transitional provisions.

Article 3 sets the scope, and it is the provision most relevant to international advertising. The law applies to processing in the context of the activities of a controller or processor established in Montenegro, whether or not the processing itself happens there. It also applies to controllers and processors with no establishment in Montenegro when their processing relates to offering goods or services to people in Montenegro, irrespective of whether payment is required, or to monitoring the behaviour of those people insofar as the behaviour takes place on Montenegrin territory. A third limb covers controllers located where Montenegrin law applies by virtue of public international law.

Monitoring behaviour is precisely what audience segmentation, retargeting and cross-site measurement do. A platform with no office in Podgorica that builds interest profiles of Montenegrin browsers falls inside the text on its plain wording.

Article 5 carries 22 definitions. Personal data covers any information relating to an identified or identifiable natural person, and the list of identifiers explicitly includes location data and an online identifier. Profiling is defined as any form of automated processing used to evaluate personal aspects, in particular to analyse or predict performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movement. Pseudonymisation, consent, the information society service and binding corporate rules are all defined in terms that track the European regulation.

Article 6 lists six processing principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity and confidentiality. A seventh obligation, accountability, places the burden on the controller to demonstrate compliance with all six.

Article 7 sets six lawful bases. Processing is lawful only where the data subject has consented for one or more specific purposes, where it is necessary for a contract or pre-contractual steps, for a legal obligation, to protect vital interests, for a task in the public interest, or for legitimate interests pursued by the controller or a third party. The legitimate interest basis gives way where the interests or fundamental rights of the data subject override it, particularly where the data subject is a child, according to Article 7, and public authorities cannot rely on it at all when performing their tasks.

Consent carries the demanding European definition. Article 5 requires it to be freely given, specific, informed and unambiguous, expressed by a statement or clear affirmative action. Article 8 puts the burden of proof on the controller, requires a consent request embedded in a written declaration to be clearly distinguishable from other matters, and makes any non-compliant part of such a declaration non-binding. Withdrawal must be as easy as giving consent. When assessing whether consent was freely given, utmost account is to be taken of whether performance of a contract, including provision of a service, was made conditional on consent to processing not necessary for that contract. That is the clause European regulators have used against consent walls and bundled terms.

Article 9 fixes the age for a child's own consent to information society services at 16. Below that age, processing based on consent is lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility. The controller must make reasonable efforts to verify that authorisation, taking into account available technology.

Sensitive data, profiling and impact assessments

Article 10 prohibits processing of special category data, meaning data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, together with genetic data, biometric data processed to uniquely identify a person, health data, and data concerning sex life or sexual orientation. Ten exceptions follow, beginning with explicit consent for one or more specified purposes. Article 11 limits processing of criminal conviction data to processing under official authority or authorised by law.

Automated decision-making sits in Article 23. A data subject has the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them. Three exceptions apply: contractual necessity, authorisation by law, and explicit consent. Where the contractual or consent exceptions are used, the controller must at least offer human intervention, the ability to express a point of view and the right to contest the decision. Such decisions cannot rest on special category data unless explicit consent or substantial public interest applies and safeguards are in place.

Article 36 makes a data protection impact assessment compulsory before processing that is likely to result in a high risk, especially when using new technologies. Three situations trigger it automatically: systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based; large-scale processing of special category or criminal data; and systematic monitoring of a publicly accessible area on a large scale. The supervisory authority must publish a list of processing types requiring an assessment and may publish a list of types that do not.

Where an assessment shows high residual risk, Article 37 requires prior consultation with the authority. The authority has up to eight weeks from receipt of the request to deliver written advice, extendable by six weeks for complex processing. It must notify any extension within one month, and the clock can be suspended while it waits for information it has requested.

Rights and response times

Chapter III gives data subjects the full set of European rights: transparent information at collection (Article 14) and when data is obtained from third parties (Article 15), access (Article 16), rectification (Article 17), erasure (Article 18, which the text labels "pravo na zaborav", the right to be forgotten), restriction (Article 19), notification of recipients (Article 20), portability in a structured, commonly used and machine-readable format (Article 21), objection (Article 22) and protection from solely automated decisions (Article 23).

Article 13 sets the clock. Controllers must respond without undue delay and in any event within one month of receiving a request. The period may be extended by two further months where necessary, given the complexity and number of requests, and the data subject must be told of the extension and the reasons within the first month. Requests are free by default. Manifestly unfounded or excessive requests, particularly repetitive ones, may be refused or charged a reasonable fee, with the burden of proof on the controller. Information may be provided alongside standardised icons, which must be machine-readable when presented electronically.

Where data comes from a third party, Article 15 requires notice within one month at the latest, including the source of the data and, where profiling drives automated decisions, meaningful information about the logic involved.

Direct marketing objections are absolute

Article 22 contains the provision with the most direct commercial bite. Where personal data is processed for direct marketing, the data subject may object at any time, and that right extends to profiling to the extent it is related to direct marketing. Once the objection is made, the data may no longer be processed for those purposes. There is no balancing test and no compelling-grounds exception, unlike objections to other processing based on public interest or legitimate interest, where the controller can continue if it demonstrates compelling legitimate grounds.

The right must be explicitly brought to the attention of the data subject at the latest at the time of first communication, and presented clearly and separately from any other information.

Objection by technical signal

The same article adds a sentence that has drawn considerable attention in European policy circles. In the context of information society services, and notwithstanding the rules on electronic communications, the data subject may exercise the right to object by automated means using technical specifications.

This language is inherited from the European regulation rather than invented in Podgorica. It nonetheless sits at the centre of a live dispute. In Brussels, the proposed Article 88b of the Digital Omnibus would have obliged controllers to respect consent or refusal transmitted automatically by a browser or operating system. The Council removed it on 18 June 2026, and a coalition of 19 organisations published a letter on 10 September 2026 asking EU institutions to put it back. Browser signals such as Global Privacy Control are the obvious candidates for the "technical specifications" the Montenegrin text refers to, but the law names no standard, and the supervisory authority has not issued guidance on which signals it would treat as a valid objection.

Controller and processor obligations

Design, joint control and processors

Article 26 imports data protection by design and by default. Controllers must implement measures such as pseudonymisation both when determining the means of processing and at the time of processing. By default, only personal data necessary for each specific purpose may be processed, an obligation that covers the amount collected, the extent of processing, the retention period and accessibility. Personal data must not be made accessible by default to an indefinite number of people without the individual's intervention.

Article 27 lets individuals exercise rights against each joint controller, whatever their internal arrangement. Article 29 sets the processor contract terms familiar from European data processing agreements: documented instructions, confidentiality, security, prior written authorisation for sub-processors, assistance with rights requests, deletion or return at the end of the service, and audit cooperation. The initial processor remains fully liable to the controller for a sub-processor's failures. A processor that determines purposes and means in breach of the law is treated as a controller for that processing.

A representative in Montenegro

Article 28 obliges any controller or processor caught by the extraterritorial limb of Article 3 to designate, in writing, a representative in Montenegro. Article 5 defines the representative as a natural or legal person with its business seat in Montenegro. The obligation does not apply to processing that is occasional, does not include large-scale processing of special category or criminal data, and is unlikely to result in a risk to individuals, nor to public authorities. Continuous tracking of users for advertising is difficult to describe as occasional. The representative must be mandated to be addressed by the supervisory authority and data subjects on all processing issues, and designating one does not shield the controller or processor from legal action.

Records and the 250-employee threshold

Article 31 requires controllers and processors to keep written records of processing activities, in electronic form where appropriate, and to make them available to the authority on request. Controller records must list purposes, categories of data subjects and data, categories of recipients including those in third countries, transfers, envisaged erasure time limits and a general description of security measures. Organisations with fewer than 250 employees are exempt unless their processing is likely to result in a risk, is not occasional, or includes special category or criminal data. As in the European model, the exemption is narrower than its headline suggests.

Data protection officers

Article 38 makes appointment of a data protection officer mandatory in three cases: processing by a public authority or body other than courts acting in their judicial capacity; core activities consisting of processing operations that require regular and systematic monitoring of data subjects on a large scale; and core activities consisting of large-scale processing of special category or criminal data. A group of undertakings may appoint a single officer provided the officer is easily accessible from each establishment. Article 39 bars the organisation from instructing, dismissing or penalising the officer for performing the role and requires a direct reporting line to the highest management level.

Breach notification within 72 hours

Article 34 requires a controller to notify the supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk. Late notifications must be accompanied by reasons for the delay. Processors must inform the controller without undue delay. The notice must cover the nature and approximate scale of the breach, likely consequences and remedial measures, and may be delivered in phases. Article 35 adds notification to affected individuals where the breach is likely to result in a high risk, with exemptions where the data was rendered unintelligible, for example by encryption, where subsequent measures removed the high risk, or where individual notice would require disproportionate effort, in which case a public communication substitutes.

Transfers: EU clauses wait for accession

Chapter V reproduces the European transfer structure with one significant difference in who decides, and one in timing.

Under Article 46, adequacy decisions are taken not by the supervisory authority but by the Government of Montenegro, after obtaining the prior opinion of the authority. The Government must weigh the rule of law, human rights, public authority access to data, the existence of an independent supervisory authority in the destination, and international commitments. Each decision must provide for periodic review at least every four years, define its territorial and sectoral scope and, where a decision is repealed, operate without retroactive effect. Adequacy decisions adopted before the new law entered into force remain valid until amended, replaced or repealed. The law itself does not list which destinations currently benefit.

Article 47 lists the appropriate safeguards that can be used without specific authorisation from the supervisory authority: a legally binding instrument between public bodies; binding corporate rules approved under Article 48; standard data protection clauses adopted by the European Commission; standard clauses adopted by the Montenegrin authority and approved by the Commission; an approved code of conduct with binding commitments by the importer; and an approved certification mechanism with binding commitments.

Article 104 then defers two of those six tools. Points 3 and 4 of Article 47, paragraph 2, covering both routes that depend on the European Commission, apply only from the date of Montenegro's accession to the European Union. The same deferral covers the authority's power to adopt standard clauses for Commission approval under Article 64 and Article 65, and the requirement under Article 72 for its annual report to include data on cooperation with EU supervisory authorities and the European Data Protection Board.

The practical consequence is that the European Commission's standard contractual clauses, the default transfer tool for most advertising technology vendors under European law, cannot be used in Montenegro as a pre-approved safeguard before accession. Until then, an exporter can rely on binding corporate rules approved by the authority, an approved code or certification, or contractual clauses individually authorised by the authority under Article 47, paragraph 3. Certification criteria do not yet exist: Article 64 gives the authority until six months after entry into force to publish them, and Article 43 caps any certificate at three years. Certification bodies, once accredited under Article 44, hold accreditation for a maximum of five years.

Article 50 provides the derogations: explicit consent after being informed of the risks, contract performance, important public interest recognised by law, legal claims, vital interests, and transfers from public registers. A residual route permits a transfer that is not repetitive, concerns only a limited number of data subjects and is necessary for compelling legitimate interests not overridden by the individual's rights, subject to notifying the authority. None of these is designed for the continuous data flows of an ad server or a demand-side platform.

Article 49 adds that any foreign court judgment or administrative decision requiring a controller to transfer or disclose personal data can be recognised or enforced only if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting country and Montenegro.

A transitional provision completes the picture. Article 100 obliges the authority to review, within one year of entry into force, the transfer approvals it granted under the old law, and to amend, replace or revoke after accession any approval that does not comply with directly applicable EU data protection law.

The Agency and its powers

Supervision stays with the Agencija za zaštitu ličnih podataka i slobodan pristup informacijama, the Agency for Personal Data Protection and Free Access to Information, headquartered in Podgorica. Article 52 declares it independent, with full institutional, functional, organisational and operational independence. Article 54 funds it from the state budget and states that financial control must not be used to restrict its statutory powers.

The Agency is run by a council and a director. Article 56 sets the council at a president and two members, appointed and dismissed by parliament on a proposal from the competent working body for five-year terms, renewable only once. Candidates need at least level VII1 education and seven years of experience at that level, and Article 58 bars members of parliament, government members and political party officials, among others. A dismissal procedure can be opened on a reasoned proposal by one third of members of parliament.

The director is appointed by the council after a public competition for a five-year term, under Article 60, and must have five years of experience at level VII1, of which three in management. Existing council members and the director continue until the end of their mandates under Article 101.

Article 65 lists 27 powers. They include ordering access to all personal data and premises, issuing warnings and reprimands, ordering compliance within a set deadline, imposing temporary or definitive processing bans, ordering suspension of data flows to a recipient in a third country, withdrawing certificates and imposing administrative fines. Article 72 requires an annual report to parliament by 31 March covering the previous year, including the number and types of measures imposed and misdemeanour and court proceedings initiated.

Inspections are conducted by officials called kontrolori. Article 73 requires them to hold level VII1 education, five years of work experience and a passed state professional examination, and states that they act independently. Article 81 gives them access to personal data regardless of its classification level.

Procedural clocks

Chapter VII gives individuals the right to file a request for protection of rights with the Agency, which must inform the applicant of progress and the outcome within 90 days under Article 76. If it fails to act within that period, Article 77 opens a route to administrative court. Article 80 allows a non-profit organisation active in data protection to file requests and claim compensation on an individual's behalf.

Article 84 requires the inspector to produce a written record within 30 days of completing an inspection, or immediately and no later than 15 days from filing where the inspection follows a request for protection of rights. The inspected party and the complainant have eight days from receipt to object to the council. Article 82 requires controllers and processors to establish mechanisms for confidential reporting of violations and protects good-faith reporters from retaliation.

Fines: European percentages, lower fixed ceilings

Chapter VIII sets two fine tiers that copy the European percentage structure while scaling the fixed amounts down tenfold.

Under Article 88, paragraph 1, violations of the obligations on children's consent (Article 9), processing not requiring identification (Article 12), controller and processor duties (Articles 26 to 40), certification body obligations (Articles 43 and 44) and failures to cooperate during supervision carry a fine of up to 1,000,000 euros or, for a company, up to 2% of its total worldwide annual revenue in the preceding financial year, whichever is higher.

Under paragraph 2, violations of the basic principles and conditions for consent (Articles 6, 7 and 8), of data subject rights (Articles 13 to 23) and of the transfer rules (Articles 46 to 50) carry a fine of up to 2,000,000 euros or up to 4% of worldwide annual revenue, whichever is higher. Paragraph 3 applies the same upper tier to failure to comply with an Agency order, a temporary or definitive processing limitation, or an order to suspend data flows.

For comparison, the European regulation's fixed ceilings are 10 million and 20 million euros; the upper figure appears in PPC Land's coverage of TikTok's challenge to a 530 million euro Irish fine. For a small domestic business, the Montenegrin fixed caps are the relevant number. For a multinational platform, the percentage is what matters, and on that measure the exposure is identical to the European one.

One drafting point may become contested. The Montenegrin text attaches the percentage to a "privredno društvo", a commercial company, and speaks of its worldwide annual sales. It does not expressly say whether the calculation runs at the level of the local subsidiary, the contracting entity or the whole group, even though Article 5 separately defines a group of undertakings. How the Agency reads that phrase will determine the real ceiling for international platforms.

Article 87 lists eleven factors the Agency must weigh, including the nature, gravity and duration of the violation, intent or negligence, mitigation steps, previous violations, the degree of cooperation, the categories of data affected, whether the controller self-reported, adherence to codes or certification, and any financial benefit gained or loss avoided. Where several provisions are breached through the same or linked processing, the total may not exceed the ceiling for the gravest violation. Article 88 exempts state bodies, public administration, local government and public institutions from administrative fines entirely. Article 90 routes all fine revenue to the state budget and gives fined parties recourse to administrative court.

A parallel misdemeanour regime

Article 89 runs alongside. A legal entity is liable to a misdemeanour fine of 150 to 2,000 euros for failing to notify a breach within 72 hours, breaching professional secrecy, denying an inspector access to data, premises or documents, or failing to establish a confidential reporting mechanism. The responsible individual within the entity risks 20 to 200 euros, an entrepreneur 50 to 400 euros and a natural person 20 to 200 euros. The Agency can issue a misdemeanour order itself.

Here the two regimes overlap. A late breach notification violates Article 34, which falls in the 1,000,000-euro tier, and also triggers the Article 89 misdemeanour. Article 89 resolves the conflict by providing that an administrative fine and a misdemeanour sanction cannot both be imposed for the same violation, which leaves the Agency to choose between a maximum of 2,000 euros and a ceiling of 1,000,000 euros or 2% for the same conduct. The text does not say how that choice is made.

Special situations

Chapter IX covers the areas where the European regulation leaves room for national law. Article 91 allows derogations for journalistic, academic, artistic and literary purposes, to be read restrictively, while Articles 93 to 97 deal with the unique master citizen number, employment, research and archiving, professional secrecy and the existing data protection rules of churches and religious communities.

Transitional provisions and a cross-reference that does not fit

Article 98 provides that proceedings not concluded with final effect by the application date will be completed under the old law. Article 99 abolishes the register of personal data collections kept under the 2008 act from the application date, with its contents handled under archival rules. Article 105 repeals the old law on the application date, with one exception: Articles 35 to 40a, which govern video surveillance, stay in force until a separate law on video surveillance takes effect.

Article 104 contains an apparent drafting error. It defers provisions it describes as relating to European Union law and the law of member states until accession and lists, among them, Article 99, paragraph 2. That paragraph concerns the archival treatment of the abolished register and makes no reference to EU law. The provision that does deal with accession is Article 100, paragraph 2, on the Agency's review of transfer approvals once Montenegro joins. The cross-reference in Article 104 may therefore have been intended for Article 100. A similar mismatch appears in Articles 67 and 85, which refer to measures under Article 79 when Article 79 deals with compensation for damage and the list of corrective measures sits in Article 86. Neither source document addresses these references, and the official text as promulgated is the version that governs.

Why this matters for the marketing community

Montenegro is a small advertising market. The significance of the law lies less in its size than in what it demonstrates about the spread of European-style rules, and in the specific friction points it creates for vendors whose compliance stacks were built for the EU.

The first is scope. Any platform that monitors behaviour of people in Montenegro, from a demand-side platform building segments to a measurement vendor running cross-site attribution, falls within Article 3. The representative obligation under Article 28 follows from that, alongside records, impact assessments for large-scale profiling and a probable duty to appoint a data protection officer for organisations whose core activity is large-scale systematic monitoring.

The second is transfers. Many of the industry's European data flows to the United States now run on the EU-US Data Privacy Framework, with standard contractual clauses as the fallback, and PPC Land reported in August that the European Data Protection Board had cast doubt on that framework's footing after the FTC's commissioners lost their protection from removal. Neither tool transfers automatically to Montenegro. The framework is an EU instrument that says nothing about Montenegrin exports, and Article 104 withholds the Commission's clauses until accession. The alternatives written into the law, including certification schemes of the kind the EDPB approved when it recognised the Europrivacy seal as a transfer tool in April, depend on criteria the Montenegrin Agency has not yet published.

The third is marketing consent. The absolute right to object to direct marketing, the ban on conditioning a service on unnecessary consent and the provision for objection by technical signal together reproduce the pressures that have shaped every consent management platform deployed in the EU. Whether the Agency will treat browser signals as a valid objection is an open question, and it is the same question Brussels has not resolved.

The fourth is enforcement durability. European experience is a caution against reading headline ceilings as outcomes. PPC Land's analysis of the European record found that close to 40% of the 7.1 billion euros in announced fines had been annulled or were under active challenge by May 2026. A three-person council, a single director and an inspectorate that must build a caseload from a starting point will produce a record of its own, and the misdemeanour overlap in Article 89 hands the Agency a low-cost alternative to the headline fines.

Montenegro also joins a queue of jurisdictions with application dates clustered in early 2027. Indonesia signed a 225-article implementing regulation on 16 July 2026 that sets fines of up to 2% of revenue from January 2027. India published rules with registered consent managers in November 2025, and Vietnam issued its implementing decree on the final day of 2025. Each uses a different transfer mechanism and a different regulator timetable. For a buyer running campaigns across several of them, the spread of deadlines matters as much as the similarity of the texts.

Is Montenegro's version simply a GDPR copy? In most articles, yes. In the transfer chapter, the governmental adequacy power, the deferred clauses and the fixed fine ceilings, it is a distinct regime with its own timetable, and one that will change again on the day the country joins the European Union.

Timeline

Summary

Who: The Parliament of Montenegro (28th convocation), which adopted the law; President Jakov Milatović, who promulgated it; Andrija Mandić, president of the parliament, who signed the adopted text; and the Agency for Personal Data Protection and Free Access to Information, which enforces it. The obligations apply to controllers and processors established in Montenegro and to foreign companies that offer goods or services to people in Montenegro or monitor their behaviour there. Luis Alberto Montezuma shared the text and its key dates on LinkedIn.

What: A new 106-article Law on Personal Data Protection that replaces the 2008 act. It imports the GDPR's principles, six lawful bases, consent standard, data subject rights, 72-hour breach notification, impact assessments, data protection officers and transfer rules. Fines reach 1,000,000 euros or 2% of worldwide annual revenue for one tier and 2,000,000 euros or 4% for the other. The Commission-linked standard contractual clauses and related provisions are deferred until EU accession, and adequacy decisions sit with the Government.

When: Adopted on 4 September 2026, promulgated on 8 September 2026, in force from 19 September 2026 and applicable from 19 March 2027. Other laws must be aligned by 1 December 2026; transfer approvals must be reviewed by 19 September 2027; the deferred transfer provisions apply from the date of accession.

Where: Montenegro, with extraterritorial reach to processing anywhere that targets or monitors people located in Montenegro.

Why: The law aligns Montenegro's framework with the European Union's as part of its path towards membership, while holding back provisions that only make sense inside the Union. For advertisers, publishers and ad tech vendors, it creates representative, profiling, marketing-objection and transfer obligations whose practical shape depends on guidance and certification criteria the Agency has yet to publish.