Law on Personal Data Protection (Official Gazette No. 42/2020)
North Macedonia's Law on Personal Data Protection (Official Gazette No. 42/2020), effective February 2020, replaces the 2005 law and aligns with the EU GDPR. The Agency for Personal Data Protection oversees enforcement. The law incorporates GDPR principles, data subject rights, DPO requirements, data breach notification obligations (added by Law No. 12/2021), and increased administrative fines.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (25)
Assurance
| Code | Title |
|---|---|
| MKPDP-18 | Codes of Conduct and Certification |
Automated Processing
| Code | Title |
|---|---|
| MKPDP-14 | Automated Decision Making and Profiling |
Breach Management
| Code | Title |
|---|---|
| MKPDP-6 | Personal Data Breach Notification |
Chapter I - General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art.1 | Purpose of the Law |
| Art.2 | Scope |
| Art.3 | Definitions |
| Art.4 | Principles for Data Processing |
| Art.8 | Rights of Data Subjects |
| HUN-1 | Purpose and Scope |
| HUN-2 | Definitions |
| HUN-3 | Fundamental Rules |
| URY-1 | Fundamental Right (Article 1) |
| URY-2 | Scope and Definitions (Article 2-4) |
Chapter II - Principles and Lawfulness of Processing
| Code | Title |
|---|---|
| Art. 13 | Transparency and Provision of Information to Deployers |
| Art. 5 | Prohibited AI Practices |
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
| Art. 9 | Risk Management System |
Chapter III - Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 14 | Human Oversight |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 17 | Quality Management System |
| Art. 18 | Documentation Keeping |
| Art. 19 | Automatically Generated Logs |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 21 | Cooperation with Competent Authorities |
| Art. 23 | Transitional Provisions |
| Art. 25 | Criminal Penalties |
| URY-7 | Right of Access (Article 13) |
| URY-8 | Right of Rectification (Article 15) |
| URY-9 | Right of Deletion (Article 15) |
Chapter IV - Controller and Processor Obligations
| Code | Title |
|---|---|
| Art. 30 | Privacy Policy |
| Art. 35 | Right of Access |
| Art. 38 | Processing in Employment Context |
| Art. 40 | Establishment and Composition |
| Art. 42 | Processing for Archiving Purposes |
| Art. 45 | Data Protection Officer |
Chapter IX - Directorate for Personal Data Protection
| Code | Title |
|---|---|
| Art. 90 | Establishment and Competences |
| Art. 95 | Inspection Supervision |
Chapter V - Transfer of Personal Data
| Code | Title |
|---|---|
| Art. 29 | Application of a Conformity Assessment Body for Notification |
| Art. 30 | Privacy Policy |
| Art. 50 | Transparency Obligations for Providers and Deployers of Certain AI Systems |
| Art. 52 | Procedure |
Chapter X - Sanctions and Penalties
| Code | Title |
|---|---|
| Art. 110 | Administrative Fines - Minor Violations |
| Art. 111 | Administrative Fines - Serious Violations |
| Art. 112 | Administrative Fines - Categories |
Cross Border Transfer
| Code | Title |
|---|---|
| MKPDP-8 | International Transfers |
Data Lifecycle
| Code | Title |
|---|---|
| MKPDP-13 | Retention and Erasure |
Data Subject Rights
| Code | Title |
|---|---|
| MKPDP-2 | Data Subject Rights Handling |
Design
| Code | Title |
|---|---|
| MKPDP-12 | Privacy by Design and by Default |
Documentation
| Code | Title |
|---|---|
| MKPDP-4 | Records of Processing Activities |
Governance
| Code | Title |
|---|---|
| MKPDP-3 | Appointment of Data Protection Officer |
Lawfulness
| Code | Title |
|---|---|
| MKPDP-1 | Lawful Basis for Processing |
Marketing
| Code | Title |
|---|---|
| MKPDP-17 | Direct Marketing and Consent |
People
| Code | Title |
|---|---|
| MKPDP-15 | Training and Awareness |
Regulator Relations
| Code | Title |
|---|---|
| MKPDP-16 | Cooperation With the Agency |
Risk Assessment
| Code | Title |
|---|---|
| MKPDP-5 | Data Protection Impact Assessment |
Security
| Code | Title |
|---|---|
| MKPDP-10 | Security of Processing |
Sensitive Data
| Code | Title |
|---|---|
| MKPDP-11 | Special Categories of Data |
Third Party
| Code | Title |
|---|---|
| MKPDP-7 | Processor Contracts and Oversight |
Transparency
| Code | Title |
|---|---|
| MKPDP-9 | Transparency and Privacy Notices |
Your Compliance Coverage
If you comply with Law on Personal Data Protection (Official Gazette No. 42/2020), you already cover:
EU AI Act
35%
22 controls mapped
Compare →Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
35%
22 controls mapped
Compare →Digital Services Act (DSA) - Regulation (EU) 2022/2065
33%
21 controls mapped
Compare →+ 587 more: GDPR (33%), Chile Personal Data Protection Law (Law No. 21.719) (33%)
See all 590 mapped frameworks ↓Maps to 590 other frameworks
Frequently Asked Questions
What is Law on Personal Data Protection (Official Gazette No. 42/2020)?
Law on Personal Data Protection (Official Gazette No. 42/2020) is a compliance framework from North Macedonia with 25 domains and 65 controls. North Macedonia's Law on Personal Data Protection (Official Gazette No. 42/2020), effective February 2020, replaces the 2005 law and aligns with the EU GDPR. The Agency for Personal Data Protection oversees enforcement. The law incorporates GDPR principles, data subject rights, DPO requirements, data breach notification obligations (added by Law No. 12/2021), and increased administrative fines. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Law on Personal Data Protection (Official Gazette No. 42/2020) have?
Law on Personal Data Protection (Official Gazette No. 42/2020) has 65 controls organised across 25 domains. The largest domains are Chapter I - General Provisions (15 controls), Chapter III - Rights of Data Subjects (12 controls), Chapter IV - Controller and Processor Obligations (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Law on Personal Data Protection (Official Gazette No. 42/2020) map to?
Law on Personal Data Protection (Official Gazette No. 42/2020) maps to 590 other compliance frameworks. The top mapping partners are EU AI Act (35% coverage), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (35% coverage), Digital Services Act (DSA) - Regulation (EU) 2022/2065 (33% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Law on Personal Data Protection (Official Gazette No. 42/2020) compliance?
Start your Law on Personal Data Protection (Official Gazette No. 42/2020) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Law on Personal Data Protection (Official Gazette No. 42/2020) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 65 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 768 frameworks.
Get Started Free →Free forever — no credit card required