Law / North Macedonia

North Macedonia

privacy

North Macedonia is not a General Data Protection Regulation (GDPR) jurisdiction. Its comprehensive personal data statute is the Law on Personal Data Protection (LPDP), Official Gazette No. 42/2020, in force 24 February 2020 and fully applicable from 24 August 2021 after an 18-month grace period, amended by OG 294/2021.

Primary text confirms biometric data as a special category under a GDPR Article 4(14)-style definition and, more consequentially, an Article 84 rule requiring the Agency's prior approval before biometric, health, or genetic data may be processed at all, even under consent, a stricter regime than GDPR's own DPIA-based approach. Primary text also confirms a GDPR Chapter V-style cross-border transfer regime and a standalone civil damages right. Publicly-available-data treatment and breach notification were not independently confirmed in this research.

5 instruments named 1 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

Law on Personal Data Protection (LPDP)

cite Zakon za zastita na licnite podatoci (Law on Personal Data Protection), Official Gazette No. 42/2020, fully applicable 24 August 2021 stage In effect since 2021-08-24 source Base law text hosted by the Agency for Personal Data Protection (azlp.mk), read in full through crawler infrastructure (202,535 characters, not truncated)

The LPDP transposes General Data Protection Regulation (GDPR) structure and principles per the Agency's own guidance and CMS commentary, though the lawful-basis and controller and processor articles were not independently confirmed against primary text in this pass.

Primary text confirms biometric data as a special category under a functional, GDPR Article 4(14)-style definition with no enumerated examples such as face or voice, and confirms Article 84's prior-approval regime: processing of health data, genetic data, or biometric data requires the Agency's approval before it may occur at all, including where the processing rests on the data subject's own explicit consent under Article 84(2).

Primary text also confirms a cross-border transfer regime using third-country, international-organisation, binding-corporate-rule, and adequacy-adjacent safeguard language across Articles 50, 51 and 53, and a civil damages right under Article 101 that a citizen association may also bring on a data subject's mandate under Article 100.

The 2021 amendment's own content, a further amendment reported as OG 101/25, publicly-available-data treatment, and breach notification were not confirmed in this research.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.