Skip to content
Video Surveillance (CCTV) Rules for Businesses in North Macedonia
Data Protection (GDPR)

Video Surveillance (CCTV) Rules for Businesses in North Macedonia

Martin BoshkoskiUpdated: 5 min read

CCTV footage of identifiable people is personal data, so running cameras in your shop, office or premises is regulated processing under the Law on Personal Data Protection and its dedicated rulebook. You cannot simply install cameras — you must document why and how, tell people they are being filmed, and delete recordings on time. Here is what a compliant setup looks like.

Adopt an act on video surveillance

The controller must adopt a formal internal act on the manner of performing video surveillance. It sets out the legal basis, the purpose(s) of the surveillance, the categories of personal data captured, a description of the surveillance system, the retention period, the notice to individuals, a privacy statement, the technical specification of the equipment (number of cameras, resolution, workstations that access the system), and a plan showing where the system is installed. In short, the act is the documented justification and design of your CCTV.

Post a visible notice

You must display, in a visible and clear place, a notice informing people that video surveillance is being carried out. This is a hard requirement — people must know they are being filmed before they enter the monitored area. The rulebook provides a template for this notice, and it forms part of your video surveillance act, together with a privacy statement explaining how individuals can exercise their rights.

Keep footage no longer than 30 days

Recordings are kept only as long as needed to fulfil their purpose, and in principle no longer than 30 days, after which they are automatically deleted from the storage medium. Longer retention is allowed only where another law requires it, or where it is genuinely necessary for the controller's legitimate interest in pursuing a legal procedure — in which case you must set internal rules for how such footage is stored and deleted. Keep an access log recording who received a copy of any footage and when.

Not sure how this applies to you?

Get a clear answer from a verified expert.

Respect people's rights

Individuals captured by your cameras keep their data-protection rights — including the right to be informed and, subject to conditions, to access footage of themselves. Your video surveillance act must describe how people can exercise these rights, and you must define the technical specification of the equipment used. Getting the paperwork right is what turns a set of cameras into lawful surveillance.

Frequently asked questions

Can my business install CCTV cameras freely?
No. CCTV of identifiable people is regulated processing. You must adopt a formal act on video surveillance, post a visible notice, limit retention, and respect people's rights.
How long can I keep CCTV footage?
In principle no longer than 30 days, after which it is automatically deleted, unless another law requires longer or it is genuinely necessary for a legal procedure under documented internal rules.
Do I have to tell people they are being filmed?
Yes. You must display a clear, visible notice that video surveillance is being carried out, before people enter the monitored area, together with a privacy statement.
Verified Nexa network · anonymous

Need help with this?

Tell us a little about your situation and we will connect you with a verified expert from the Nexa network.

Your request is presented to the verified Nexa network anonymously — without your name. We share your contact only if a professional expresses interest, and you can withdraw at any time via info@nexa.mk. You have no financial obligation toward Nexa.

Related articles

Personal Data Protection (GDPR) for Businesses in North Macedonia
Data Protection (GDPR)

Personal Data Protection (GDPR) for Businesses in North Macedonia

If your business handles personal data — of customers, employees or website visitors — the Law on Personal Data Protection applies. It mirrors the EU GDPR: lawful bases, data-subject rights, breach notification within 72 hours, and fines of up to 4% of annual income.

22 September 20267 min read
Read more
Do You Need a Data Protection Officer (DPO)?
Data Protection (GDPR)

Do You Need a Data Protection Officer (DPO)?

Not every business must appoint a Data Protection Officer. The law makes it mandatory in three situations — most often when your core activity involves large-scale, regular monitoring of people or large-scale processing of sensitive data.

22 September 20265 min read
Read more