Law / North Macedonia

Law on Personal Data Protection (LPDP), rights of the data subject

Zakon za zastita na licnite podatoci, arts. 16-27 (rights of the data subject)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 24 August 2021.

A data subject rights rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Because Article 122 suspends Chapter III until North Macedonia's accession to the European Union, none of the data subject rights it lists, access, rectification, erasure, restriction, portability, objection, and protection from a solely automated decision, currently bind a controller under this Law.
  • Once Chapter III takes effect, answer a data subject's access request under Article 19 with confirmation of processing, a copy of the personal data, and the processing's purposes, recipients, retention period and source.
  • Once Chapter III takes effect, rectify inaccurate personal data within 15 days of a request under Article 20.
  • Once Chapter III takes effect, erase personal data within 30 days of a request under Article 21 wherever one of its listed grounds applies.
  • Once Chapter III takes effect, give a data subject the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them, under Article 26.

What it reaches

Obligation class

Data subject rights, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Chapter III, Articles 16 to 27, carries the data subject rights the LPDP models on the General Data Protection Regulation (GDPR), but Article 122 suspends the whole chapter until North Macedonia's accession to the European Union, so none of it currently binds a controller. Article 19 would give a data subject the right to obtain confirmation of whether their personal data are being processed and, where so, a copy of the data along with the purposes, recipients, retention period and source of the processing.

Article 20 would give a right to have inaccurate personal data rectified within 15 days of a request. Article 21 would give a right to erasure, the right to be forgotten, within 30 days of a request, where a listed ground applies such as withdrawal of consent, unlawful processing or the data no longer being necessary.

Article 22 would give a right to restrict processing, Article 24 a right to receive and transmit personal data in a structured, machine readable format, and Article 25 a right to object to processing, including to direct marketing outright. Article 26 would give a data subject the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions

Read the law

Base law text hosted by the Agency for Personal Data Protection (azlp.mk), read in full (202,535 characters, not truncated)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app