What Is Law on Personal Data Protection, Official Gazette No. 42/2020?
North Macedonia’s operative privacy statute is the Law on Personal Data Protection, Official Gazette No. 42/2020, adopted on 16 February 2020 and in force from 24 February 2020. It is domestic legislation harmonized with EU Regulation 2016/679; it is not itself the EU GDPR. The statute was amended by Official Gazette No. 294/2021 and by Official Gazette No. 101/2025, which added NATO-member countries to specified transfer provisions. The law provides a broad GDPR-style rights framework, including access, rectification, erasure, restriction, portability, objection, automated-decision safeguards, complaints to AZLP, judicial remedies, and compensation. No fixed final AZLP-decision or complaint-filing deadline was located. No North Macedonia-specific data-broker complaint, opt-out, suppression, or deletion route was located, although Article 94 requires deletion after the necessary-use period for certain disclosed official-document data.
At a glance
- Full name
- Law on Personal Data Protection, Official Gazette No. 42/2020
- Short code
- Law 42/2020
- Jurisdiction
- North Macedonia
- Enacted
- 2020
- Last major update
- Amended by Official Gazette No. 294/2021 and Official Gazette No. 101/2025; the 2025 amendment added NATO-member countries to Articles 48 and 56 transfer provisions
- Regulator
- Agency for Personal Data Protection (AZLP)
- Private right of action
- Yes
Scope, who Law 42/2020 covers
Protected data
Data subject rights
Right to transparent information and facilitation, generally with a 1-month response period extendable by 2 months for complexity or volume
Right of access, with the first copy free of charge
Right to rectification within 15 days
Right to erasure within 30 days on enumerated grounds and subject to exceptions
Right to be forgotten after public disclosure, including reasonable technical measures to notify other controllers holding links, copies, or reproductions
Right to restriction of processing
Right to data portability for consent- or contract-based automated processing, with direct transmission where feasible
Right to object to public-interest or legitimate-interest processing and an absolute right to object to direct marketing at any time
Safeguards against qualifying solely automated decisions, including human intervention and the ability to challenge
Right to complain to AZLP and pursue judicial remedies against AZLP decisions, inaction, controllers, or processors
Right to compensation for material and non-material damage
Notable features
The statute is a domestic GDPR-harmonized law rather than direct EU GDPR application. Its 2025 amendment extended the transfer-chapter exclusion to NATO-member countries while retaining a statutory notification framework. Article 94 requires deletion after the necessary-use period for personal data disclosed to authorized users unless another law provides otherwise.
Enforcement & penalties
Regulator: Agency for Personal Data Protection (AZLP)
Penalties: Category I violations may expose a legal entity to up to 2% of preceding annual turnover; Category II violations may expose it to up to 4% of preceding annual turnover. Responsible officers may be fined €300-€500 in denar equivalent, state officials €100-€500, and individual controllers or processors €100-€250. Video-surveillance violations may attract €1,000-€10,000 for a legal entity, €100-€500 for a responsible officer or state official, and €100-€250 for an individual controller or processor.
Private right of action: Articles 98-99 provide judicial remedies against AZLP decisions or inaction and directly against controllers or processors. Article 101 provides compensation for material and non-material damage before a competent court. No fixed deadline was located in Article 99 itself for a direct court action against a controller or processor.
Relevance to data brokers
No North Macedonia-specific data-broker complaint, opt-out, suppression, or deletion route was located. The general route is to exercise rights against the broker as controller, complain to AZLP under Article 97, or pursue judicial remedies under Articles 98-101. Article 94 is an adjacent public-record mechanism for certain data disclosed by public bodies, not a dedicated data-subject public-record deletion portal.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is the EU GDPR directly applicable in North Macedonia?+
No. The Law on Personal Data Protection is domestic legislation harmonized with EU Regulation 2016/679; it is not itself the EU GDPR.
Does North Macedonia have a dedicated data-broker deletion route?+
Not located. The available route is the general exercise of rights against the broker as controller, a complaint to AZLP, or judicial remedies. Article 94 provides a separate deletion-after-necessary-use rule for certain disclosed official-document data.
How long does AZLP have to issue a final decision?+
No fixed final AZLP-decision deadline was located. The law provides a 3-month progress or outcome threshold that can trigger judicial remedies, but that is not a guaranteed final-decision deadline.
Official sources & citations
Other international privacy regimes
Law 42/2020 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
