North Macedonia Law on Personal Data Protection (2020)
North Macedonia's Law on Personal Data Protection (Official Gazette No. 42/2020), effective February 2020, replaces the 2005 law and is fully aligned with the EU GDPR. The Personal Data Protection Agency (Directorate) oversees enforcement. The law incorporates GDPR principles, rights, DPO requirements, DPIA obligations, breach notification, and administrative fines. Enacted as part of North Macedonia's EU accession process and reflects the country's commitment to EU data protection standards.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (25)
Assurance
| Code | Title |
|---|---|
| MKPDP-18 | Codes of Conduct and Certification |
Automated Processing
| Code | Title |
|---|---|
| MKPDP-14 | Automated Decision Making and Profiling |
Breach Management
| Code | Title |
|---|---|
| MKPDP-6 | Personal Data Breach Notification |
Chapter I — General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art.1 | Purpose of the Law |
| Art.2 | Scope |
| Art.3 | Definitions |
| Art.4 | Principles for Data Processing |
| Art.8 | Rights of Data Subjects |
| HUN-1 | Purpose and Scope |
| HUN-2 | Definitions |
| HUN-3 | Fundamental Rules |
| URY-1 | Fundamental Right (Article 1) |
| URY-2 | Scope and Definitions (Article 2–4) |
Chapter II — Principles and Lawfulness of Processing
| Code | Title |
|---|---|
| Art. 13 | Transparency and Provision of Information to Deployers |
| Art. 5 | Prohibited AI Practices |
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
| Art. 9 | Risk Management System |
Chapter III — Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 14 | Human Oversight |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 17 | Quality Management System |
| Art. 18 | Documentation Keeping |
| Art. 19 | Automatically Generated Logs |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 21 | Cooperation with Competent Authorities |
| Art. 23 | Transitional Provisions |
| Art. 25 | Criminal Penalties |
| URY-7 | Right of Access (Article 13) |
| URY-8 | Right of Rectification (Article 15) |
| URY-9 | Right of Deletion (Article 15) |
Chapter IV — Controller and Processor Obligations
| Code | Title |
|---|---|
| Art. 30 | Privacy Policy |
| Art. 35 | Right of Access |
| Art. 38 | Processing in Employment Context |
| Art. 40 | Establishment and Composition |
| Art. 42 | Processing for Archiving Purposes |
| Art. 45 | Data Protection Officer |
Chapter IX — Directorate for Personal Data Protection
| Code | Title |
|---|---|
| Art. 90 | Establishment and Competences |
| Art. 95 | Inspection Supervision |
Chapter V — Transfer of Personal Data
| Code | Title |
|---|---|
| Art. 29 | Application of a Conformity Assessment Body for Notification |
| Art. 30 | Privacy Policy |
| Art. 50 | Transparency Obligations for Providers and Deployers of Certain AI Systems |
| Art. 52 | Procedure |
Chapter X — Sanctions and Penalties
| Code | Title |
|---|---|
| Art. 110 | Administrative Fines — Minor Violations |
| Art. 111 | Administrative Fines — Serious Violations |
| Art. 112 | Administrative Fines — Categories |
Cross Border Transfer
| Code | Title |
|---|---|
| MKPDP-8 | International Transfers |
Data Lifecycle
| Code | Title |
|---|---|
| MKPDP-13 | Retention and Erasure |
Data Subject Rights
| Code | Title |
|---|---|
| MKPDP-2 | Data Subject Rights Handling |
Design
| Code | Title |
|---|---|
| MKPDP-12 | Privacy by Design and by Default |
Documentation
| Code | Title |
|---|---|
| MKPDP-4 | Records of Processing Activities |
Governance
| Code | Title |
|---|---|
| MKPDP-3 | Appointment of Data Protection Officer |
Lawfulness
| Code | Title |
|---|---|
| MKPDP-1 | Lawful Basis for Processing |
Marketing
| Code | Title |
|---|---|
| MKPDP-17 | Direct Marketing and Consent |
People
| Code | Title |
|---|---|
| MKPDP-15 | Training and Awareness |
Regulator Relations
| Code | Title |
|---|---|
| MKPDP-16 | Cooperation With the Agency |
Risk Assessment
| Code | Title |
|---|---|
| MKPDP-5 | Data Protection Impact Assessment |
Security
| Code | Title |
|---|---|
| MKPDP-10 | Security of Processing |
Sensitive Data
| Code | Title |
|---|---|
| MKPDP-11 | Special Categories of Data |
Third Party
| Code | Title |
|---|---|
| MKPDP-7 | Processor Contracts and Oversight |
Transparency
| Code | Title |
|---|---|
| MKPDP-9 | Transparency and Privacy Notices |
Your Compliance Coverage
If you comply with North Macedonia Law on Personal Data Protection (2020), you already cover:
EU AI Act
35%
22 controls mapped
Compare →Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
35%
22 controls mapped
Compare →Digital Services Act (DSA) - Regulation (EU) 2022/2065
33%
21 controls mapped
Compare →+ 588 more: GDPR (33%), Chile Personal Data Protection Law (Law No. 21.719) (33%)
See all 591 mapped frameworks ↓Maps to 591 other frameworks
Frequently Asked Questions
What is North Macedonia Law on Personal Data Protection (2020)?
North Macedonia Law on Personal Data Protection (2020) is a compliance framework from North Macedonia with 25 domains and 65 controls. North Macedonia's Law on Personal Data Protection (Official Gazette No. 42/2020), effective February 2020, replaces the 2005 law and is fully aligned with the EU GDPR. The Personal Data Protection Agency (Directorate) oversees enforcement. The law incorporates GDPR principles, rights, DPO requirements, DPIA obligations, breach notification, and administrative fines. Enacted as part of North Macedonia's EU accession process and reflects the country's commitment to EU data protection standards. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does North Macedonia Law on Personal Data Protection (2020) have?
North Macedonia Law on Personal Data Protection (2020) has 65 controls organised across 25 domains. The largest domains are Chapter I — General Provisions (15 controls), Chapter III — Rights of Data Subjects (12 controls), Chapter IV — Controller and Processor Obligations (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does North Macedonia Law on Personal Data Protection (2020) map to?
North Macedonia Law on Personal Data Protection (2020) maps to 591 other compliance frameworks. The top mapping partners are EU AI Act (35% coverage), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (35% coverage), Digital Services Act (DSA) - Regulation (EU) 2022/2065 (33% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with North Macedonia Law on Personal Data Protection (2020) compliance?
Start your North Macedonia Law on Personal Data Protection (2020) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about North Macedonia Law on Personal Data Protection (2020) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 65 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required