Skip to content
Personal Data Protection (GDPR) for Businesses in North Macedonia
Data Protection (GDPR)

Personal Data Protection (GDPR) for Businesses in North Macedonia

Martin BoshkoskiUpdated: 7 min read

Almost every business processes personal data — customer names and emails, employee records, CCTV footage, website analytics. In North Macedonia this is governed by the Law on Personal Data Protection, which closely mirrors the EU's GDPR. If you decide why and how personal data is processed, you are a controller and you carry legal obligations, enforced by the Agency for Personal Data Protection (AZLP), with fines that can reach a percentage of your annual income. This guide covers the essentials every business owner should know.

Does the law apply to you?

The law applies to any controller (the business that determines the purposes and means of processing) or processor (a party that processes data on the controller's behalf, such as an IT provider) established in North Macedonia — regardless of where the processing physically happens. It also reaches businesses not established in the country when they process the data of people in North Macedonia in connection with offering them goods or services or monitoring their behaviour. In practice: if you hold data about identifiable people, the law applies to you.

You need a lawful basis to process data

You cannot process personal data just because it is useful. Each processing activity needs a lawful basis, most commonly: the person's consent; the performance of a contract with them (e.g. fulfilling an order); a legal obligation (e.g. keeping tax records); protecting someone's vital interests; a public interest task; or your legitimate interests, where these are not overridden by the person's rights. Consent, when used, must be freely given, specific and clearly affirmative — pre-ticked boxes do not count.

The core principles

Processing must follow a set of principles: lawfulness, fairness and transparency; purpose limitation (collect data for specified purposes, don't repurpose it freely); data minimisation (only what you need); accuracy; storage limitation (don't keep it longer than necessary); and integrity and confidentiality (keep it secure). You must also be able to demonstrate compliance — accountability is itself an obligation.

People's rights

Individuals whose data you hold (data subjects) have rights you must be ready to honour: to be informed about your processing (usually via a privacy notice), and to access, rectify, erase, restrict, object to and port their data. As a rule you must respond without undue delay and within one month of a request. Build a simple internal process so requests do not catch you off guard.

Not sure how this applies to you?

Get a clear answer from a verified expert.

Security and data breaches

You must apply appropriate technical and organisational security measures. If a personal data breach occurs, you must notify the Agency without delay and no later than 72 hours after becoming aware of it; if you report later, you must explain the delay. Where the breach is likely to result in a high risk to the affected individuals, you must also inform them.

The Agency and penalties

The supervisory authority is the Agency for Personal Data Protection (AZLP), an independent state body that oversees compliance and handles complaints. Penalties are significant: depending on the violation, fines can reach up to 2% of a legal entity's total annual income, and for the most serious breaches up to 4%, alongside fixed fines for responsible persons. Beyond the fine, the reputational cost of mishandling customer data is often larger.

Two obligations deserve their own guides: whether you must appoint a Data Protection Officer, and the specific rules for video surveillance.

Frequently asked questions

Does North Macedonia's data protection law apply to my small business?
Yes, if you process personal data of identifiable people — customers, employees, visitors — you are a controller with obligations under the Law on Personal Data Protection, regardless of your size.
Do I always need consent to process personal data?
No. Consent is one of several lawful bases. Others include performing a contract, a legal obligation, vital or public interests, and legitimate interests. You need at least one valid basis for each processing activity.
How quickly must I report a data breach?
Without delay and no later than 72 hours after becoming aware of it, to the Agency for Personal Data Protection; a later report must be justified. Affected individuals must be told if the risk to them is high.
What are the fines for breaking the data protection law?
Depending on the violation, up to 2% of a legal entity's total annual income, and up to 4% for the most serious breaches, plus fixed fines for responsible individuals.
Who enforces data protection in North Macedonia?
The Agency for Personal Data Protection (AZLP), an independent supervisory authority that oversees compliance and handles complaints.
Verified Nexa network · anonymous

Need help with this?

Tell us a little about your situation and we will connect you with a verified expert from the Nexa network.

Your request is presented to the verified Nexa network anonymously — without your name. We share your contact only if a professional expresses interest, and you can withdraw at any time via info@nexa.mk. You have no financial obligation toward Nexa.

Related articles

Register a Company in North Macedonia: Complete 2026 Guide
Company Registration

Register a Company in North Macedonia: Complete 2026 Guide

You can register a company in North Macedonia in days. Most choose a DOO or DOOEL (EUR 5,000 capital, payable within a year). Foreigners can own 100% with no residency, and corporate profit tax is a flat 10%.

21 May 20268 min read
Read more
Do You Need a Data Protection Officer (DPO)?
Data Protection (GDPR)

Do You Need a Data Protection Officer (DPO)?

Not every business must appoint a Data Protection Officer. The law makes it mandatory in three situations — most often when your core activity involves large-scale, regular monitoring of people or large-scale processing of sensitive data.

22 September 20265 min read
Read more
Video Surveillance (CCTV) Rules for Businesses in North Macedonia
Data Protection (GDPR)

Video Surveillance (CCTV) Rules for Businesses in North Macedonia

If your business uses CCTV, you must adopt a formal act governing the surveillance, post a visible notice, and delete footage within 30 days. Video surveillance is regulated personal-data processing — here is what compliance requires.

22 September 20265 min read
Read more