North Macedonia Law on Personal Data Protection (2020)
North Macedonia's Law on Personal Data Protection (Official Gazette No. 42/2020), effective February 2020, replaces the 2005 law and is fully aligned with the EU GDPR. The Personal Data Protection Agency (Directorate) oversees enforcement. The law incorporates GDPR principles, rights, DPO requirements, DPIA obligations, breach notification, and administrative fines. Enacted as part of North Macedonia's EU accession process and reflects the country's commitment to EU data protection standards.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Chapter I — General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Legal Recognition of Data Messages |
| Art.1 | Purpose |
| Art.2 | Definitions |
| Art.3 | Cybersecurity Policy |
| Art.4 | Credit Information Business Licensing |
| Art.8 | Prohibited Acts |
| HUN-1 | Purpose and Scope |
| HUN-2 | Definitions |
| HUN-3 | Fundamental Rules |
| URY-1 | Fundamental Right (Article 1) |
| URY-2 | Scope and Definitions (Article 2–4) |
Chapter II — Principles and Lawfulness of Processing
| Code | Title |
|---|---|
| Art. 13 | Data Security and Privacy |
| Art. 5 | Legal Recognition of Data Messages |
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
| Art. 9 | Free Data Sharing |
Chapter III — Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 14 | Direct Data Flows |
| Art. 16 | Data Quality |
| Art. 17 | Governance Structure |
| Art. 18 | Central Bank Supervision |
| Art. 19 | Consent Management Controls |
| Art. 20 | Executive Accountability |
| Art. 21 | Administrative Sanctions |
| Art. 23 | Transitional Provisions |
| Art. 25 | Criminal Penalties |
| URY-7 | Right of Access (Article 13) |
| URY-8 | Right of Rectification (Article 15) |
| URY-9 | Right of Deletion (Article 15) |
Chapter IV — Controller and Processor Obligations
| Code | Title |
|---|---|
| Art. 30 | Privacy Policy |
| Art. 35 | Right of Access |
| Art. 38 | Processing in Employment Context |
| Art. 40 | Establishment and Composition |
| Art. 42 | Processing for Archiving Purposes |
| Art. 45 | Data Protection Officer |
Chapter IX — Directorate for Personal Data Protection
| Code | Title |
|---|---|
| Art. 90 | Establishment and Competences |
| Art. 95 | Inspection Supervision |
Chapter V — Transfer of Personal Data
| Code | Title |
|---|---|
| Art. 29 | Safety Measures |
| Art. 30 | Privacy Policy |
| Art. 50 | Right to Compensation |
| Art. 52 | Appropriate Safeguards |
Chapter X — Sanctions and Penalties
| Code | Title |
|---|---|
| Art. 110 | Administrative Fines — Minor Violations |
| Art. 111 | Administrative Fines — Serious Violations |
| Art. 112 | Administrative Fines — Categories |
Maps to 566 other frameworks
Frequently Asked Questions
What is North Macedonia Law on Personal Data Protection (2020)?
North Macedonia Law on Personal Data Protection (2020) is a compliance framework from North Macedonia with 7 domains and 47 controls. North Macedonia's Law on Personal Data Protection (Official Gazette No. 42/2020), effective February 2020, replaces the 2005 law and is fully aligned with the EU GDPR. The Personal Data Protection Agency (Directorate) oversees enforcement. The law incorporates GDPR principles, rights, DPO requirements, DPIA obligations, breach notification, and administrative fines. Enacted as part of North Macedonia's EU accession process and reflects the country's commitment to EU data protection standards. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does North Macedonia Law on Personal Data Protection (2020) have?
North Macedonia Law on Personal Data Protection (2020) has 47 controls organised across 7 domains. The largest domains are Chapter I — General Provisions (15 controls), Chapter III — Rights of Data Subjects (12 controls), Chapter IV — Controller and Processor Obligations (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does North Macedonia Law on Personal Data Protection (2020) map to?
North Macedonia Law on Personal Data Protection (2020) maps to 566 other compliance frameworks. The top mapping partners are EU Digital Services Act — Minors Protection Provisions (Regulation 2022/2065) (47% coverage), Chile Personal Data Protection Law (Law No. 21.719) (47% coverage), EU Network Code on Cybersecurity for the Electricity Sector (47% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with North Macedonia Law on Personal Data Protection (2020) compliance?
Start your North Macedonia Law on Personal Data Protection (2020) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about North Macedonia Law on Personal Data Protection (2020) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 47 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required