Regulation Finder/North Macedonia

North Macedonia

Comprehensive

Law on Personal Data Protection (2020)

Authority: Agency for Personal Data Protection (APDP) | Enforcement: Active | Enacted: August 2020

Overview

North Macedonia enacted a new data protection law in 2020, closely aligned with the GDPR. The APDP is the supervisory authority. As an EU candidate country, North Macedonia has made data protection alignment a priority.

14-Topic Coverage

Data Protection Authority

Fully Addressed

APDP oversees compliance, handles complaints, and issues enforcement measures.

Data Subject Rights

Fully Addressed

Full GDPR-aligned rights: access, rectification, erasure, restriction, portability, objection.

Cross-Border Transfer

Fully Addressed

GDPR-aligned transfer mechanisms.

Breach Notification

Fully Addressed

Must notify APDP within 72 hours.

DPO Requirements

Fully Addressed

DPO required per GDPR-aligned criteria.

Children's Data

Fully Addressed

Parental consent for children under 14.

Penalties & Enforcement

Fully Addressed

Fines up to EUR 20,000 or 4% of annual turnover for certain categories.

Sector-Specific Rules

Fully Addressed

NBRM financial data rules, health data regulations.

AI & Automated Decisions

Fully Addressed

Right to not be subject to automated decisions.

Data Localisation

Not Addressed

No data localisation requirement.

Significant Data Fiduciary

Not Addressed

No equivalent concept.

Government Data

Fully Addressed

Law applies to government processing.

Coverage Summary

Fully Addressed11/14
Partially Addressed1/14
Not Addressed2/14
Pending0/14

Need Compliance Help?

Our data privacy team can help you navigate North Macedonia's regulations.

Book a Consultation