Law / North Macedonia

Law on Personal Data Protection (LPDP), personal data breach notification

Zakon za zastita na licnite podatoci, arts. 37-38 (personal data breach notification)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 24 August 2021.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Because Article 122 suspends Chapter IV until North Macedonia's accession to the European Union, no personal data breach notification duty currently binds under this Law.
  • Once Chapter IV takes effect, notify the Agency of a personal data breach within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons, and give reasons for any delay beyond that period.
  • Once Chapter IV takes effect, communicate a personal data breach to the affected data subject without undue delay wherever the breach is likely to result in a high risk to their rights and freedoms, unless an exception such as prior encryption, later mitigation, or disproportionate effort applies.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Articles 37 and 38 carry North Macedonia's personal data breach notification duties, but Article 122 suspends Chapter IV, where both articles sit, until North Macedonia's accession to the European Union, so no breach notification duty currently binds under this Law.

Article 37 would require a controller, without undue delay and where feasible not later than 72 hours after becoming aware of the breach, to notify the Agency, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons, giving reasons for any delay beyond that period.

Article 38 would require a controller to communicate the breach to the affected data subject without undue delay wherever it is likely to result in a high risk to their rights and freedoms, unless the affected data were already protected by measures such as encryption, later steps removed the high risk, or a public communication of equal effect substitutes for disproportionate individual effort.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach

Read the law

Base law text hosted by the Agency for Personal Data Protection (azlp.mk), read in full (202,535 characters, not truncated)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app