Law / North Macedonia

North Macedonia

12 of 13 named instruments researched to a stage, across four of the six areas of law we track: 12 in force. As of 19 September 2026.

  1. AI law 1
  2. Privacy law 7
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (181 words)

North Macedonia has no AI-transparency, AI-risk, or AI-training statute; the only binding provision reaching an AI system's own output is a criminal ban on realistic depictions of child sexual abuse that covers a synthetic or AI-generated image on the same terms as a photograph of a real child.

The Ministry of Digital Transformation's ICT Development Strategy: SMART/MK 2030, adopted around October 2025, names artificial intelligence as one of four policy pillars alongside infrastructure, digital skills, and e-government, framed as aligning with the EU Digital Decade 2030 and, over time, the EU AI Act, but it is a non-binding government strategy implemented through a future Action Plan and creates no directly enforceable right or obligation.

On 8 May 2026, North Macedonia's Justice Minister signed the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225) during a state visit by the Council of Europe Secretary General; the country has not ratified the Convention and no domestic implementing legislation has been introduced, so it creates no binding domestic obligation as of this review.

AI prohibited practices

Criminal Code, Production and Distribution of Child Pornography

Criminal Code, OG No. 37/1996, art. 193-aUnofficial consolidated text of the Criminal Code, hosted by the Public Prosecutor's Office of the Republic of North Macedonia (jorm.gov.mk)

In force. Binds public and private bodies.

What this law does

Article 122(24) defines child pornography, for the whole Criminal Code, as pornographic material that visually depicts explicit sexual acts with a minor or with an adult who looks like a minor, or that depicts a minor or an adult who looks like a minor in an explicit sexual position, and separately reaches realistic images depicting the same acts or positions, whether or not an actual minor was involved in producing them.

Article 193-a(1) punishes producing child pornography for the purpose of distributing it, or transmitting, offering or otherwise making it available, with imprisonment of at least five years; paragraph (2) punishes acquiring or possessing it with imprisonment of five to eight years; paragraph (3) raises the minimum to eight years where the offense is committed through a computer system or another mass-communication medium; paragraph (4) extends liability to a legal person, punishable by a fine.

Because the definition's realistic-image branch does not require a real child to have been depicted, an image an AI system generates that realistically depicts a minor, or a person who looks like a minor, in an explicit sexual act or position falls within it on the same terms as a photograph.

The consolidated text lists the many Official Gazette issues that have amended the Criminal Code as a whole without attributing this specific article to one of them, so no commencement date for this provision is confirmed here.

What it requires

Privacy law7 instruments, 7 in force

Research summary (188 words)

North Macedonia is not a General Data Protection Regulation (GDPR) jurisdiction. Its comprehensive personal data statute is the Law on Personal Data Protection (LPDP), Official Gazette No. 42/2020, in force 24 February 2020, amended by OG 294/2021. Article 122 suspends most of the Act's GDPR-style substance, Chapters II through V and VIII, until North Macedonia's accession to the European Union; only a narrow child's consent age rule (Art. 12) and a voluntary certification scheme (Arts. 46-47) survive from those chapters.

What is currently live is the Agency itself (Chapter VI), supervision and misdemeanour fines (Chapters IX-X), and Chapter VII's specific processing rules: an Article 84 rule requiring the Agency's prior approval before biometric, health, or genetic data may be processed at all, even under consent; a dedicated video surveillance regime (Arts. 89-93) covering notice, a 30-day retention cap, prohibited locations, and a 70% owner-consent rule for residential buildings; and narrower rules on employment-context processing, national identification numbers, archiving and research, churches, and deceased persons' data.

The GDPR-style data-subject-rights chapter, the cross-border transfer regime, and the private right to sue a controller or claim compensation are all suspended and not currently in force.

Breach notification

Law on Personal Data Protection (LPDP), personal data breach notification

Zakon za zastita na licnite podatoci, arts. 37-38 (personal data breach notification)Base law text hosted by the Agency for Personal Data Protection (azlp.mk), read in full (202,535 characters, not truncated)

In force since 24 August 2021. Binds public and private bodies.

What this law does

Articles 37 and 38 carry North Macedonia's personal data breach notification duties, but Article 122 suspends Chapter IV, where both articles sit, until North Macedonia's accession to the European Union, so no breach notification duty currently binds under this Law.

Article 37 would require a controller, without undue delay and where feasible not later than 72 hours after becoming aware of the breach, to notify the Agency, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons, giving reasons for any delay beyond that period.

Article 38 would require a controller to communicate the breach to the affected data subject without undue delay wherever it is likely to result in a high risk to their rights and freedoms, unless the affected data were already protected by measures such as encryption, later steps removed the high risk, or a public communication of equal effect substitutes for disproportionate individual effort.

What it requires

Comprehensive regime

Law on Personal Data Protection (LPDP)

Zakon za zastita na licnite podatoci (Law on Personal Data Protection) Official Gazette No. 42/2020, fully applicable 24 August 2021, arts. 1-11, 15, 28-47, 81-83, 85-87, 94-96 (general provisions, principles and controller obligations)Base law text hosted by the Agency for Personal Data Protection (azlp.mk), read in full (202,535 characters, not truncated)

In force since 24 August 2021. Binds public and private bodies.

What this law does

The Law on Personal Data Protection (LPDP), Official Gazette No. 42/2020, applies to processing personal data wholly or partly by automated means and to non-automated processing that forms part of a filing system, reaching a controller or processor established in North Macedonia and, for offering goods or monitoring behaviour there, a controller or processor established abroad.

Article 122 suspends Chapters II, III, IV and V and VIII until North Macedonia's accession to the European Union, so the general lawful basis, consent, and controller and processor duties those chapters state, including data protection by design, records of processing, security measures, data protection impact assessments and appointing a data protection officer, do not currently bind, and only Article 12's child consent rule and Articles 46 and 47's voluntary certification scheme survive from the suspended chapters.

The certification scheme is voluntary and available through a transparent process, and adherence to it does not reduce a controller's or processor's responsibility for complying with the Law. Chapter VII's specific processing rules are not suspended and bind today.

A controller may disclose personal data in official documents only to fulfil a task in the public interest, and may process a citizen's national identification number only with the data subject's consent, for a legally binding right or duty, or in another case a law states, needing the Agency's prior approval for systematic and extensive processing of it.

The state may set more specific employment context processing rules by law or collective agreement, provided they safeguard employees' human dignity, legitimate interests and fundamental rights. A controller processing personal data for archiving in the public interest, or for scientific, historical or statistical purposes, must apply appropriate safeguards such as pseudonymisation or data minimisation.

Processing personal data for direct marketing, including related profiling, is allowed only after the data subject has given explicit consent. Journalistic, academic, artistic or literary processing may depart from the Law's other chapters where necessary to reconcile personal data protection with freedom of expression and information.

What it requires

Law on Personal Data Protection (LPDP), video surveillance

Zakon za zastita na licnite podatoci, arts. 89-93 (video surveillance, notice, retention and destruction)Base law text hosted by the Agency for Personal Data Protection (azlp.mk), read in full (202,535 characters, not truncated)

In force since 24 August 2021. Binds public and private bodies.

What this law does

Articles 89 to 93 hold North Macedonia's dedicated video surveillance regime, in force since Chapter VII is not among the chapters Article 122 suspends. A controller performing video surveillance must publish a clear, visible notice that it is in place, naming the controller and explaining how to learn the place and storage period of the recordings, and must notify employees of video surveillance on official or business premises.

Video surveillance may reach only the area sufficient for the goal it was installed for, and is prohibited outright in changing rooms, dressing rooms, toilets and similar rooms. Recordings may be stored for no longer than 30 days unless another law sets a longer period with its own safeguards, and the owner of a camera installed contrary to the Law must remove it at their own expense.

Introducing video surveillance in a single-unit or multi-unit residential building needs the written consent of at least 70% of the owners or tenants, its recordings may never be transmitted over cable television or the internet, and entrances to other individual apartments may never be recorded.

The controller must analyse the goal of a video surveillance system before installing it and reassess it every two years, covering the continuing need for it, its goals, and feasible technical alternatives.

What it requires

Cross border transfer

Law on Personal Data Protection (LPDP), transfer of personal data

Zakon za zastita na licnite podatoci, arts. 48-56 (transfer of personal data)Base law text hosted by the Agency for Personal Data Protection (azlp.mk), read in full (202,535 characters, not truncated)

In force since 24 August 2021. Binds public and private bodies.

What this law does

Chapter V, Articles 48 to 56, carries North Macedonia's cross-border transfer regime, but Article 122 suspends the whole chapter until North Macedonia's accession to the European Union, so no transfer safeguard is currently required under this Law.

Article 48 would confine a transfer of personal data undergoing or intended for processing after transfer to a third country or an international organisation to the conditions this chapter lays down, though it would not reach a transfer to a European Union member state or a member of the European Economic Area. Article 49 would let a transfer proceed where the Agency has decided the destination country or organisation ensures an adequate level of protection.

Article 50 would, absent an adequacy decision, let a transfer proceed only where the controller or processor has provided appropriate safeguards, such as binding corporate rules or standard data protection clauses, and enforceable data subject rights and effective legal remedies remain available. Article 53 would, absent an adequacy decision or appropriate safeguards, still allow a transfer on a listed ground such as the data subject's informed explicit consent, or necessity for a contract.

What it requires

Data subject rights

Law on Personal Data Protection (LPDP), rights of the data subject

Zakon za zastita na licnite podatoci, arts. 16-27 (rights of the data subject)Base law text hosted by the Agency for Personal Data Protection (azlp.mk), read in full (202,535 characters, not truncated)

In force since 24 August 2021. Binds public and private bodies.

What this law does

Chapter III, Articles 16 to 27, carries the data subject rights the LPDP models on the General Data Protection Regulation (GDPR), but Article 122 suspends the whole chapter until North Macedonia's accession to the European Union, so none of it currently binds a controller. Article 19 would give a data subject the right to obtain confirmation of whether their personal data are being processed and, where so, a copy of the data along with the purposes, recipients, retention period and source of the processing.

Article 20 would give a right to have inaccurate personal data rectified within 15 days of a request. Article 21 would give a right to erasure, the right to be forgotten, within 30 days of a request, where a listed ground applies such as withdrawal of consent, unlawful processing or the data no longer being necessary.

Article 22 would give a right to restrict processing, Article 24 a right to receive and transmit personal data in a structured, machine readable format, and Article 25 a right to object to processing, including to direct marketing outright. Article 26 would give a data subject the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them.

What it requires

Enforcement supervision

Law on Personal Data Protection (LPDP), the Agency, supervision and misdemeanour provisions

Zakon za zastita na licnite podatoci, arts. 57-80, 97-116 (the Agency, supervision and misdemeanour provisions)Base law text hosted by the Agency for Personal Data Protection (azlp.mk), read in full (202,535 characters, not truncated)

In force since 24 August 2021. Binds public and private bodies.

What this law does

The Personal Data Protection Agency, established by Chapter VI, is an independent and autonomous state administration body responsible for monitoring the lawfulness of personal data processing and protecting individuals' fundamental rights and freedoms in relation to it, and Chapter VI is not among the chapters Article 122 suspends.

Chapter IX lets the Agency's supervisors conduct regular, irregular and control supervision of a controller or processor, including reviewing records and premises and requesting explanations, and the controller or processor must make that supervision fully available.

Article 122 suspends Chapter VIII until North Macedonia's accession to the European Union, so a data subject currently has no right under this Law to file a request with the Agency over a suspected infringement, to seek judicial review of an Agency decision, to sue a controller or processor directly, or to claim compensation for damage an infringement caused.

Article 111 sets North Macedonia's higher misdemeanour tier at up to 4% of a controller or processor's total annual turnover, covering violations that include several currently suspended articles alongside currently effective Articles 66, 83, 84, 86 and 88, while Article 110 sets a lower tier at up to 2% of turnover.

Article 112 separately fixes a misdemeanour fine of 1,000 to 10,000 euros in denar equivalent against a controller for a video surveillance violation of Articles 89 to 92, all currently effective. A misdemeanour procedure cannot be initiated or conducted once two years have passed from the day the violation was committed.

What it requires

Sensitive categories

Law on Personal Data Protection (LPDP), special categories, a child's consent and biometric, health and genetic data

Zakon za zastita na licnite podatoci, arts. 12-14, 84 (special categories, a child's consent and biometric, health and genetic data)Base law text hosted by the Agency for Personal Data Protection (azlp.mk), read in full (202,535 characters, not truncated)

In force since 24 August 2021. Binds public and private bodies.

What this law does

Article 12 makes the processing of a child's personal data for an information society service offered directly to the child lawful only where the child is at least 14 years old, or, if younger, only where a parent or another holder of parental responsibility has given or authorised the consent, and requires the controller to make reasonable efforts to verify that parental consent given the available technology.

Article 84 requires the Agency's prior approval before processing health data, genetic data or biometric data of a person in North Macedonia, including where the processing rests on the data subject's own explicit consent, unless the processing is determined by a law that itself provides safeguards, or the genetic data is processed by experts for preventive medicine, diagnostics or treatment.

Article 122 suspends Chapter II except Article 12 until North Macedonia's accession to the European Union, so Article 13's general prohibition on processing special categories of personal data and its list of lawful exceptions, and Article 14's rule confining criminal conviction data to official control, do not currently bind.

Article 13 would otherwise prohibit processing special categories of personal data absent a listed exception, such as the data subject's explicit consent, a necessity ground tied to employment or social security law, vital interests, the legitimate activities of a non-profit body, or an important public interest with suitable safeguards.

Article 14 would otherwise confine processing personal data relating to criminal convictions and offences to processing under the control of an official authority, or under a law providing appropriate safeguards.

What it requires

Scraping law3 instruments, 3 in force

Research summary (220 words)

North Macedonia has no scraping-specific statute, so general law governs each dimension separately.

The Criminal Code's article 251 criminalizes unauthorized deletion, alteration, damage, concealment or interception of computer data, a program or a computer system, so a scraper that defeats a technical access control or intercepts a non-public data transmission falls within it, while reading a public, unauthenticated page without defeating any such measure does not fit a plain reading of the provision.

The Law on Copyright and Related Rights confers a sui generis right on a database maker over the extraction and re-utilization of the whole or a substantial part of a database's content, and separately permits quotation, teaching, scientific research, criticism and review uses of a work within the extent the purpose justifies and with the author's name and source credited, but carries no text-and-data-mining-specific exception or opt-out mechanism.

The Law on Personal Data Protection applies to processing of personal data, including data collected by scraping, subject to the suspension of its general lawful-basis and controller duties described in the privacy topic's own record for this jurisdiction.

No North Macedonian statute or reported court decision assigns legal weight to a robots.txt directive, imposes an AI-training-specific rule, addresses the enforceability of a website's browsewrap or clickwrap terms against a scraper, or establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine.

Computer misuse

Criminal Code, Damage and Unauthorized Entry into a Computer System

Criminal Code, OG No. 37/1996, art. 251Unofficial consolidated text of the Criminal Code, hosted by the Public Prosecutor's Office of the Republic of North Macedonia (jorm.gov.mk)

In force. Binds public and private bodies.

What this law does

Article 251(1) punishes a person who, without authorization, deletes, alters, damages, conceals or otherwise renders unusable computer data, a program, or a device for maintaining an information system, or disables or hinders the use of a computer system, data, program or computer communication, with a fine or imprisonment of up to three years.

Paragraph (2) applies the same penalty to unauthorized entry into another's computer or system with intent to exploit its data or programs for unlawful gain or to cause damage, or to transmit data reached without authorization. Paragraph (3) separately punishes unauthorized interception, by technical means, of a non-public transmission of computer data to, from or within a computer system.

Paragraph (4) raises the penalty to one to five years' imprisonment where the act targets a system protected by special security measures, one used by a state body, public enterprise or public institution, or in international communications, or is committed by a member of an organized group; paragraphs (5) and (6) raise it further where the act produced a greater unlawful gain or damage.

Paragraph (7) separately punishes the unauthorized manufacture, acquisition, sale, possession or distribution of a device, password, access code or program suited for committing the offense, and paragraph (9) extends liability to a legal person, punishable by a fine. The consolidated text lists the many Official Gazette issues that have amended the Criminal Code as a whole without attributing this specific article to one of them, so no commencement date for this provision is confirmed here.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (212 words)

North Macedonia has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Law on Copyright and Related Rights is the only law reaching an aggregator's reproduction of news content.

Article 52(1)(6) permits reproducing and publicly communicating articles, notes and similar works on current economic, political, religious or similar topics, without the author's permission or payment, to the extent the purpose of informing the public justifies, with the author's name and source credited, unless the author has specifically prohibited it.

Article 52(3) extends the same free-of-charge treatment to publicly communicating the headline of such a work where it is republished in an electronic publication from another electronic publication or other source for the purpose of informing the public. Neither provision carries a headline-length or short-extract cap distinct from this purpose test, and no reported North Macedonian decision applies either to a systematic news aggregator as opposed to an individual republisher.

No statute or case law addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law was found. The Law predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.