Law / North Macedonia

Law on Personal Data Protection (LPDP)

Zakon za zastita na licnite podatoci (Law on Personal Data Protection) Official Gazette No. 42/2020, fully applicable 24 August 2021, arts. 1-11, 15, 28-47, 81-83, 85-87, 94-96 (general provisions, principles and controller obligations)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 24 August 2021.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • The general lawful-basis, consent, and controller and processor duties of Chapters II and IV, including data protection by design, records of processing, security measures, data protection impact assessments and appointing a data protection officer, are currently suspended under Article 122 until North Macedonia's accession to the European Union; only Article 12's child consent age rule and Articles 46 and 47's voluntary certification scheme currently bind.
  • Where a certification mechanism under Articles 46 and 47 is used, know that it is voluntary and does not by itself reduce responsibility for complying with the rest of this Law.
  • Get the Agency's prior approval before any systematic and extensive processing of a citizen's national identification number, and otherwise process it only with the data subject's prior consent or another case a law states.
  • Process personal data for direct marketing, including related profiling, only after the data subject has given explicit consent.
  • Apply appropriate safeguards, such as pseudonymisation or data minimisation, when processing personal data for archiving in the public interest, or for scientific, historical or statistical purposes.
  • Disclose personal data held in an official document only to fulfil a task in the public interest, reconciling public access to official documents with the right to data protection.

What it reaches

Obligation class

Governance, Disclosure, Consent

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Law on Personal Data Protection (LPDP), Official Gazette No. 42/2020, applies to processing personal data wholly or partly by automated means and to non-automated processing that forms part of a filing system, reaching a controller or processor established in North Macedonia and, for offering goods or monitoring behaviour there, a controller or processor established abroad.

Article 122 suspends Chapters II, III, IV and V and VIII until North Macedonia's accession to the European Union, so the general lawful basis, consent, and controller and processor duties those chapters state, including data protection by design, records of processing, security measures, data protection impact assessments and appointing a data protection officer, do not currently bind, and only Article 12's child consent rule and Articles 46 and 47's voluntary certification scheme survive from the suspended chapters.

The certification scheme is voluntary and available through a transparent process, and adherence to it does not reduce a controller's or processor's responsibility for complying with the Law. Chapter VII's specific processing rules are not suspended and bind today.

A controller may disclose personal data in official documents only to fulfil a task in the public interest, and may process a citizen's national identification number only with the data subject's consent, for a legally binding right or duty, or in another case a law states, needing the Agency's prior approval for systematic and extensive processing of it.

The state may set more specific employment context processing rules by law or collective agreement, provided they safeguard employees' human dignity, legitimate interests and fundamental rights. A controller processing personal data for archiving in the public interest, or for scientific, historical or statistical purposes, must apply appropriate safeguards such as pseudonymisation or data minimisation.

Processing personal data for direct marketing, including related profiling, is allowed only after the data subject has given explicit consent. Journalistic, academic, artistic or literary processing may depart from the Law's other chapters where necessary to reconcile personal data protection with freedom of expression and information.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach

Read the law

Base law text hosted by the Agency for Personal Data Protection (azlp.mk), read in full (202,535 characters, not truncated)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app