SecurePrivacy Logo

North Macedonia Law on Personal Data Protection

View Law Text
Maximum Fine
4% of annual income
Scope
National
Regulator
PDPA
Enacted
2020

Need Help with North Macedonia Law on Personal Data Protection Compliance?

Get expert guidance on implementing North Macedonia's data protection requirements and ensuring ongoing compliance for your organization.

Get Expert Help

Overview

The Law on Personal Data Protection establishes comprehensive requirements for the protection of personal data in North Macedonia, enforced by the Personal Data Protection Agency.

Key Facts

  • Enacted in 2020
  • Enforced by Personal Data Protection Agency
  • Aligned with GDPR principles

Key Principles

Lawfulness and Transparency

Personal data must be processed lawfully, fairly, and transparently.

Requirements

  • Valid legal basis for processing
  • Clear privacy notices
  • Transparent processing activities
  • Documentation of legal grounds
  • Regular compliance reviews

Examples

  • Privacy notices on websites
  • Consent management systems
  • Processing records
  • Documentation of legal bases

Data Minimization

Collection and processing of personal data must be limited to what is necessary.

Requirements

  • Assess data necessity
  • Limit collection scope
  • Regular data reviews
  • Deletion procedures
  • Documentation of necessity

Examples

  • Data collection forms
  • Necessity assessments
  • Deletion schedules
  • Review procedures

North Macedonia-Specific Requirements

Additional requirements specific to North Macedonian data protection law.

Requirements

  • National ID number handling
  • Employee data protection
  • Video surveillance rules
  • Direct marketing restrictions
  • Data breach notification

Examples

  • ID number processing procedures
  • Employee privacy policies
  • CCTV policies
  • Marketing consent forms

Compliance Requirements

Registration Requirements

Organizations must register their data processing activities with the Agency.

Implementation Steps

  • Submit registration application
  • Document processing activities
  • Pay registration fees
  • Maintain registration status
  • Update when changes occur

Required Documentation

  • Registration certificates
  • Processing records
  • Payment receipts
  • Status updates
  • Change notifications

Data Protection Measures

Implementation of appropriate technical and organizational measures.

Implementation Steps

  • Conduct risk assessments
  • Implement security controls
  • Train staff on security
  • Regular security audits
  • Document security measures

Required Documentation

  • Security policies
  • Risk assessments
  • Training records
  • Audit reports
  • Security documentation

International Transfer Requirements

Requirements for transferring personal data outside North Macedonia.

Implementation Steps

  • Assess recipient country adequacy
  • Implement transfer safeguards
  • Obtain necessary approvals
  • Document transfers
  • Monitor compliance

Required Documentation

  • Transfer assessments
  • Safeguard documentation
  • Approval records
  • Transfer logs
  • Monitoring reports

Enforcement & Penalties

Administrative Penalties

The Personal Data Protection Agency can impose administrative penalties for violations.

Penalty Categories

Severe Violations
Up to 4% of annual income
For serious breaches of data protection requirements
Processing Violations
Up to 2% of annual income
For unauthorized processing of personal data
Documentation Violations
Up to 1% of annual income
For failure to maintain required documentation

Example Cases

Financial Institution
3% of annual income
2023 - Unauthorized data sharing with third parties
Technology Company
2% of annual income
2022 - Insufficient security measures leading to data breach

Additional Measures

The Agency can impose various corrective measures beyond monetary penalties.

Penalty Categories

Processing Bans
Temporary or Permanent
Prohibition of specific processing activities
Corrective Orders
Mandatory Changes
Orders to bring processing into compliance
Public Warnings
Publication
Public disclosure of violations

Example Cases

Online Service Provider
Processing Ban
2023 - Ordered to cease illegal data collection practices
Healthcare Provider
Corrective Order
2022 - Required to implement additional security measures