Law / North Macedonia

Law on Personal Data Protection (LPDP), transfer of personal data

Zakon za zastita na licnite podatoci, arts. 48-56 (transfer of personal data)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 24 August 2021.

A cross border transfer rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Because Article 122 suspends Chapter V until North Macedonia's accession to the European Union, no cross-border transfer safeguard, adequacy decision, standard contractual clause or binding corporate rule, is currently required under this Law before transferring personal data outside North Macedonia.
  • Once Chapter V takes effect, transfer personal data to a third country or an international organisation only where the Agency has decided it ensures an adequate level of protection, or under an appropriate safeguard such as binding corporate rules or standard data protection clauses.
  • Once Chapter V takes effect, know that its transfer conditions will not reach a transfer from North Macedonia to a European Union member state or a member of the European Economic Area, though the controller or processor must still notify the Agency of it.
  • Once Chapter V takes effect, absent an adequacy decision or appropriate safeguards, transfer personal data to a third country only on a listed ground such as the data subject's informed explicit consent, or necessity for the performance of a contract.

What it reaches

Obligation class

Transfer

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Chapter V, Articles 48 to 56, carries North Macedonia's cross-border transfer regime, but Article 122 suspends the whole chapter until North Macedonia's accession to the European Union, so no transfer safeguard is currently required under this Law.

Article 48 would confine a transfer of personal data undergoing or intended for processing after transfer to a third country or an international organisation to the conditions this chapter lays down, though it would not reach a transfer to a European Union member state or a member of the European Economic Area. Article 49 would let a transfer proceed where the Agency has decided the destination country or organisation ensures an adequate level of protection.

Article 50 would, absent an adequacy decision, let a transfer proceed only where the controller or processor has provided appropriate safeguards, such as binding corporate rules or standard data protection clauses, and enforceable data subject rights and effective legal remedies remain available. Article 53 would, absent an adequacy decision or appropriate safeguards, still allow a transfer on a listed ground such as the data subject's informed explicit consent, or necessity for a contract.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach

Read the law

Base law text hosted by the Agency for Personal Data Protection (azlp.mk), read in full (202,535 characters, not truncated)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app