+ 389 2 320 8090 contact@lblaw.com.mk

Personal Data Protection Law in North Macedonia – 2025 Update

KEY TAKEAWAYS

  • The 2025 amendment (OG No. 101/2025, 21 May 2025) added NATO member states to the special transfer regime in Articles 48 and 56.
  • Transfers from North Macedonia to an EU, NATO or EEA member state require notification to the Personal Data Protection Agency — not a full adequacy or safeguards assessment.
  • Transfers to other third countries and international organizations remain subject to Articles 49 to 53 of the Law.
  • The 2025 amendment does not remove the controller’s general duties: lawful processing, transparency, security, accountability and data subject rights all remain fully applicable.
  • Security breaches must be notified to the Agency immediately and no later than 72 hours after the controller becomes aware.
  • Fines: up to 2% of total annual revenue for Category I infringements; up to 4% for Category II infringements.

The Law on Personal Data Protection regulates the protection of personal data and the right to privacy in connection with personal data processing in North Macedonia. It applies to controllers and processors established in North Macedonia and, in the circumstances specified by the Law, to certain controllers and processors established abroad. The Law is aligned with the EU’s General Data Protection Regulation framework. A targeted amendment in May 2025 extended the favorable transfer regime to NATO member states. This page explains the current compliance framework. This page is part of our practice in business and corporate law. For related compliance matters, see our guide on 7 compliance risks for managers in North Macedonia. For official information from the supervisory authority, see the Personal Data Protection Agency.

What Changed in May 2025

The Law Supplementing the Law on Personal Data Protection was adopted on 14 May 2025, published in Official Gazette No. 101/2025 on 21 May 2025 and entered into force on the date of publication. It amended Articles 48 and 56 and required the relevant implementing act to be adopted within 15 days after entry into force.

Under amended Article 48, the provisions in Chapter V on transfers to third countries and international organizations do not apply to a transfer from North Macedonia to an EU member state, a NATO member state or a member state of the European Economic Area. For such a transfer, the controller or processor must notify the Personal Data Protection Agency.

Amended Article 56 extends the Agency director’s rulemaking authority to the method of notification and the forms and records concerning transfers to NATO member states. The 2025 amendment changes the destination-based transfer procedure for NATO states — it does not create a general exemption from the remainder of the Law.

Core Processing Principles

Article 9 requires personal data to be processed lawfully, fairly and transparently; collected for specified, explicit and legitimate purposes; adequate, relevant and limited to what is necessary; accurate and kept up to date; retained no longer than necessary; and processed with appropriate integrity and confidentiality.

The controller is responsible for compliance and must be able to demonstrate it. This accountability requirement should be reflected in documented legal bases, retention periods, access controls, internal procedures and evidence that the organization follows them in practice.

Legal Basis and Consent

Processing is lawful only when at least one basis in Article 10 applies — including consent, performance of a contract, compliance with a legal obligation, protection of vital interests, a task in the public interest or exercise of official authority, or a legitimate interest that is not overridden by the interests or fundamental rights and freedoms of the data subject.

Where consent is used, the controller must be able to demonstrate it. Consent must be distinguishable from other matters, expressed in clear and plain language, and capable of being withdrawn as easily as it was given. Special categories of personal data are subject to the prohibition and exceptions in Article 13.

Transparency and Data Subject Rights

Information must be concise, transparent, intelligible and easily accessible, using clear and plain language. Controllers should maintain privacy notices appropriate to employees, customers, website users, job applicants and other categories of data subjects.

The Law provides rights of access, rectification, erasure, restriction, data portability, objection and safeguards concerning automated individual decision-making including profiling. A controller must respond without undue delay and in any event within one month. That period may be extended by two additional months where necessary because of the complexity and number of requests, provided the data subject is informed within the initial month.

Controllers, Processors and Processing Records

Controllers must implement appropriate technical and organizational measures and data protection by design and by default. A processor may be engaged only under the conditions of Article 32, including a binding written arrangement that defines the processing and the processor’s duties.

Article 34 requires controllers and processors to maintain records of processing activities. The exemption for an organization with fewer than 50 employees does not apply when processing is likely to present a risk to rights and freedoms, is not occasional, or includes special categories of personal data or data concerning criminal convictions and offences.

Security and Personal Data Breaches

Article 36 requires security appropriate to the risk, taking account of the state of the art, implementation costs and the nature, scope, context and purposes of processing. Depending on the risk, measures may include pseudonymisation, encryption, resilience, restoration capability and regular testing of security controls.

A controller must notify the Agency immediately and no later than 72 hours after becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. A processor must notify the controller immediately after becoming aware of a breach. Where a breach is likely to result in a high risk, the controller must also inform the affected data subject without delay, subject to the statutory exceptions.

Impact Assessments and Data Protection Officer

A data protection impact assessment is required before processing that is likely to result in a high risk — particularly for specified forms of automated evaluation, large-scale processing of special categories or criminal offence data, and systematic large-scale monitoring of publicly accessible areas.

A controller or processor must appoint a data protection officer in the cases listed in Article 41, including large-scale regular and systematic monitoring or large-scale processing of special categories of data or criminal offence data. The officer must be involved in a timely manner, receive appropriate resources, act independently in performing statutory tasks and report directly to the highest management level.

International Transfers After the 2025 Amendment

Before transferring personal data abroad, an organization should identify the recipient, destination, purpose, categories of data, onward transfer arrangements and the applicable legal route.

For an EU, NATO or EEA destination, the amended Article 48 requires notification to the Personal Data Protection Agency — a streamlined procedure that replaces the full adequacy or safeguards assessment that would otherwise apply under Chapter V.

For other destinations, the organization must assess the mechanisms in Articles 49 to 53, including an adequacy decision, appropriate safeguards, binding corporate rules or a specific statutory derogation. The 2025 amendment does not convert every international transfer into a notification-only procedure.

Supervision and Fines

The Personal Data Protection Agency supervises compliance and may exercise investigative and corrective powers. Category I infringements may lead to a fine of up to 2% of the legal person’s total annual revenue, while Category II infringements may lead to a fine of up to 4%, together with the separate sanctions prescribed for responsible persons and other offenders.

Practical Checklist

For controllers and processors subject to the Law on Personal Data Protection in North Macedonia: (1) Map processing activities — document data categories, purposes, recipients, retention periods and international transfers. (2) Legal basis — identify and document the legal basis under Article 10 for each material processing activity. (3) Privacy notices — update privacy notices for employees, customers, website users and other data subjects; establish a procedure for responding to data subject requests within one month. (4) Processor agreements — review processor and sub-processor arrangements under Article 32; ensure binding written arrangements are in place. (5) Processing records — maintain records of processing activities where Article 34 applies, including organizations with fewer than 50 employees where processing carries risk, is not occasional or involves special categories. (6) Security and breach response — review technical and organizational security measures and ensure the 72-hour breach notification workflow to the Agency is operational. (7) Impact assessments and DPO — assess whether a data protection impact assessment or data protection officer appointment is required under Articles 38 and 41. (8) International transfers — for EU, NATO and EEA destinations, complete the notification required by Article 48; for other international transfers, document the applicable mechanism under Articles 49 to 53. 

Frequently Asked Questions

What is the principal change introduced by the 2025 amendment?

NATO member states were added to Articles 48 and 56. Transfers from North Macedonia to EU, NATO or EEA member states are now subject to notification to the Personal Data Protection Agency under the amended regime, rather than the full Chapter V requirements that apply to other third countries.

Does the 2025 amendment permit every international transfer based only on notification?

No. The notification-only rule concerns EU, NATO and EEA destinations. Transfers to other third countries or international organisations remain subject to Articles 49 to 53 of the Law, which require an adequacy decision, appropriate safeguards, binding corporate rules or a specific derogation.

Does the amendment remove the general duties of controllers and processors?

No. The processing principles, legal basis requirements, transparency duties, data subject rights, security rules, accountability measures and breach obligations remain fully applicable following the 2025 amendment.

How quickly must a controller respond to a data subject request?

The controller must act without undue delay and within one month of receiving the request. The period may be extended by two additional months where justified by the complexity and the number of requests, provided the data subject is informed within the first month.

When must the Personal Data Protection Agency be notified of a security breach?

Immediately and no later than 72 hours after the controller becomes aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. A processor must notify the controller immediately upon becoming aware of a breach.

Are organizations with fewer than 50 employees exempt from all record-keeping obligations?

No. The Article 34 exemption for organizations with fewer than 50 employees does not apply where processing is likely to create a risk to rights and freedoms, is not occasional, or includes special categories of personal data or data concerning criminal convictions and offences.

What fines can be imposed for non-compliance?

Category I infringements may result in a fine of up to 2% of the legal person’s total annual revenue. Category II infringements — which include the most serious breaches of the Law’s core principles, legal basis requirements and data subject rights — may result in a fine of up to 4% of total annual revenue, plus separate sanctions for responsible persons.

ABOUT THE AUTHOR

Angela Andonova

Attorney at Law | Lalicic & Partners, Skopje, North Macedonia

Practice areas: Business and corporate law, Regulatory compliance

Note: The above does not constitute legal advice and in no way can be accepted or understood as an instruction to act in a specific case. Each legal situation has its own characteristics that should be reviewed at separately, and for that reason we recommend that you contact a professional – a lawyer – for legal advice.