Almost every business processes personal data — customer names and emails, employee records, CCTV footage, website analytics. In North Macedonia this is governed by the Law on Personal Data Protection, which closely mirrors the EU's GDPR. If you decide why and how personal data is processed, you are a controller and you carry legal obligations, enforced by the Agency for Personal Data Protection (AZLP), with fines that can reach a percentage of your annual income. This guide covers the essentials every business owner should know.
Does the law apply to you?
The law applies to any controller (the business that determines the purposes and means of processing) or processor (a party that processes data on the controller's behalf, such as an IT provider) established in North Macedonia — regardless of where the processing physically happens. It also reaches businesses not established in the country when they process the data of people in North Macedonia in connection with offering them goods or services or monitoring their behaviour. In practice: if you hold data about identifiable people, the law applies to you.
You need a lawful basis to process data
You cannot process personal data just because it is useful. Each processing activity needs a lawful basis, most commonly: the person's consent; the performance of a contract with them (e.g. fulfilling an order); a legal obligation (e.g. keeping tax records); protecting someone's vital interests; a public interest task; or your legitimate interests, where these are not overridden by the person's rights. Consent, when used, must be freely given, specific and clearly affirmative — pre-ticked boxes do not count.
The core principles
Processing must follow a set of principles: lawfulness, fairness and transparency; purpose limitation (collect data for specified purposes, don't repurpose it freely); data minimisation (only what you need); accuracy; storage limitation (don't keep it longer than necessary); and integrity and confidentiality (keep it secure). You must also be able to demonstrate compliance — accountability is itself an obligation.
People's rights
Individuals whose data you hold (data subjects) have rights you must be ready to honour: to be informed about your processing (usually via a privacy notice), and to access, rectify, erase, restrict, object to and port their data. As a rule you must respond without undue delay and within one month of a request. Build a simple internal process so requests do not catch you off guard.
Not sure how this applies to you?
Get a clear answer from a verified expert.
Security and data breaches
You must apply appropriate technical and organisational security measures. If a personal data breach occurs, you must notify the Agency without delay and no later than 72 hours after becoming aware of it; if you report later, you must explain the delay. Where the breach is likely to result in a high risk to the affected individuals, you must also inform them.
The Agency and penalties
The supervisory authority is the Agency for Personal Data Protection (AZLP), an independent state body that oversees compliance and handles complaints. Penalties are significant: depending on the violation, fines can reach up to 2% of a legal entity's total annual income, and for the most serious breaches up to 4%, alongside fixed fines for responsible persons. Beyond the fine, the reputational cost of mishandling customer data is often larger.
Two obligations deserve their own guides: whether you must appoint a Data Protection Officer, and the specific rules for video surveillance.


