Law on Personal Data Protection (LPDP), the Agency, supervision and misdemeanour provisions
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 24 August 2021.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Cooperate with the Personal Data Protection Agency's supervisors during a regular, irregular or control supervision, including granting access to premises, documents and equipment relevant to personal data processing.
- Because Article 122 suspends Chapter VIII until North Macedonia's accession to the European Union, a data subject currently has no right under this Law to file a request with the Agency over a suspected infringement, to seek judicial review of an Agency decision, to sue a controller or processor directly, or to claim compensation for damage an infringement caused.
- Expect a misdemeanour fine of up to 2% of the controller or processor's total annual turnover for violating a Category I obligation Article 110 lists, or up to 4% for a Category II obligation Article 111 lists, alongside small fixed fines against the responsible individual.
- Expect a misdemeanour fine of 1,000 to 10,000 euros in denar equivalent against a controller that performs video surveillance, or processes personal data through one, contrary to Articles 89 to 92.
- Expect the Agency to bring a misdemeanour procedure only within two years of the day the violation was committed, since the statute of limitations runs from that day.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
Article 111 sets the higher misdemeanour tier at up to 4% of a controller or processor legal entity's total annual turnover for the preceding business year (or preceding revenue if newer), for violations that include Articles 9, 10, 11, 13 and 16 to 26 (Chapters II-III, currently suspended) and Articles 48 to 53 (Chapter V, currently suspended), alongside currently effective Articles 66, 83, 84, 86 and 88. Article 110 sets a lower tier at up to 2% of turnover, covering obligations that include Articles 29 to 43 (Chapter IV, currently suspended) alongside currently effective Articles 12, 94, 96 and 106. Article 112 separately fixes a 1,000 to 10,000 euro fine, independent of turnover, against a controller for a video surveillance violation of Articles 89 to 92, all currently effective. Articles 110 and 111 each additionally fix small fines, denominated in euros but payable in denar equivalent, against the responsible individual: 300 to 500 euros for the responsible person at a legal entity, 100 to 500 euros for an official at a state administration body, and 100 to 250 euros for a natural person acting as controller or processor; Article 112's own individual fines run 100 to 500 euros throughout.
- Rule
- Turnover pct only
- As of
- 19 September 2026
- Currency
- EUR
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Personal Data Protection Agency, North Macedonia's independent supervisory authority.
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Personal Data Protection Agency, established by Chapter VI, is an independent and autonomous state administration body responsible for monitoring the lawfulness of personal data processing and protecting individuals' fundamental rights and freedoms in relation to it, and Chapter VI is not among the chapters Article 122 suspends.
Chapter IX lets the Agency's supervisors conduct regular, irregular and control supervision of a controller or processor, including reviewing records and premises and requesting explanations, and the controller or processor must make that supervision fully available.
Article 122 suspends Chapter VIII until North Macedonia's accession to the European Union, so a data subject currently has no right under this Law to file a request with the Agency over a suspected infringement, to seek judicial review of an Agency decision, to sue a controller or processor directly, or to claim compensation for damage an infringement caused.
Article 111 sets North Macedonia's higher misdemeanour tier at up to 4% of a controller or processor's total annual turnover, covering violations that include several currently suspended articles alongside currently effective Articles 66, 83, 84, 86 and 88, while Article 110 sets a lower tier at up to 2% of turnover.
Article 112 separately fixes a misdemeanour fine of 1,000 to 10,000 euros in denar equivalent against a controller for a video surveillance violation of Articles 89 to 92, all currently effective. A misdemeanour procedure cannot be initiated or conducted once two years have passed from the day the violation was committed.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsis_listed_company
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.