North Macedonia
ComprehensiveLaw on Personal Data Protection (2020)
Authority: Agency for Personal Data Protection (APDP) | Enforcement: Active | Enacted: August 2020
Overview
North Macedonia enacted a new data protection law in 2020, closely aligned with the GDPR. The APDP is the supervisory authority. As an EU candidate country, North Macedonia has made data protection alignment a priority.
14-Topic Coverage
Data Protection Authority
Fully AddressedAPDP oversees compliance, handles complaints, and issues enforcement measures.
Consent Requirements
Fully AddressedGDPR-aligned consent requirements.
Data Subject Rights
Fully AddressedFull GDPR-aligned rights: access, rectification, erasure, restriction, portability, objection.
Cross-Border Transfer
Fully AddressedGDPR-aligned transfer mechanisms.
Breach Notification
Fully AddressedMust notify APDP within 72 hours.
DPO Requirements
Fully AddressedDPO required per GDPR-aligned criteria.
Children's Data
Fully AddressedParental consent for children under 14.
Penalties & Enforcement
Fully AddressedFines up to EUR 20,000 or 4% of annual turnover for certain categories.
Sector-Specific Rules
Fully AddressedNBRM financial data rules, health data regulations.
Cookie/Tracking
Partially AddressedE-communications provisions.
AI & Automated Decisions
Fully AddressedRight to not be subject to automated decisions.
Data Localisation
Not AddressedNo data localisation requirement.
Significant Data Fiduciary
Not AddressedNo equivalent concept.
Government Data
Fully AddressedLaw applies to government processing.
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate North Macedonia's regulations.
Book a Consultation