What North Macedonia Law on Personal Data Protection 2020 - DZLP requires
North Macedonia's Law on Personal Data Protection (Закон за заштита на личните податоци - ZZLP) - adopted by the Assembly of the Republic of North Macedonia in early 2020 and published in the Official Gazette of the Republic of North Macedonia No. 42 of 16 February 2020, entering into force on 25 February 2020 - is North Macedonia's primary personal data protection legislation, explicitly modelled on and substantively aligned with the European Union General Data Protection Regulation (GDPR - Regulation (EU) 2016/679). The law was enacted as a central component of North Macedonia's EU accession preparations, with North Macedonia having held EU candidate status since 2005 and formally opening EU accession negotiations in 2022. The 2020 ZZLP replaced the previous Law on Personal Data Protection of 2005 and introduced full GDPR-equivalent provisions including the controller-processor framework, DPO requirements, Data Protection Impact Assessments, 72-hour breach notification, data subject rights, and the Supervisory Authority enforcement model. The supervisory authority is the Directorate for Personal Data Protection (Дирекција за заштита на личните податоци - DZLP), an independent state body established under the Law responsible for receiving notifications, investigating complaints, conducting inspections, and enforcing the ZZLP. Key features of North Macedonia's Law on Personal Data Protection 2020: (1) Scope - applies to processing of personal data of natural persons in North Macedonia by controllers and processors established in North Macedonia or processing data of North Macedonian data subjects regardless of establishment; (2) Data processing principles - lawfulness, fairness, and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability - mirroring GDPR; (3) Sensitive personal data - same categories as GDPR: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; genetic data; biometric data; health data; sex life or sexual orientation; and criminal conviction data; (4) Lawful processing conditions - GDPR-equivalent: consent; contract; legal obligation; vital interests; public interest; legitimate interests; (5) Data subject rights - full GDPR-equivalent rights: access; rectification; erasure; restriction; portability; objection; automated decision-making rights; (6) Data Protection Officer - mandatory for public authorities, controllers conducting large-scale systematic monitoring, and controllers processing sensitive data on a large scale; (7) Breach notification - 72-hour notification to DZLP; data subject notification for high-risk breaches; (8) Data Protection Impact Assessment - mandatory for high-risk processing; (9) Cross-border transfers - GDPR-equivalent transfer framework: adequacy decisions; standard contractual clauses; binding corporate rules; codes of conduct; certification; (10) Penalties - administrative fines graduated by violation severity up to EUR 20,000 or EUR 100,000 (not GDPR-scale but significant for North Macedonia's economy). North Macedonia's ZZLP 2020 is the most GDPR-aligned data protection law in the Western Balkans region.
Pillar: Data Protection & Privacy · Authority: Directorate for Personal Data Protection (DZLP, North Macedonia) · Version: 1.0.0 · Last updated:
Primary source: https://www.dzlp.mk/
SHA-256 integrity: 9c6a14e203f5221a7c7ea92ebc476be2335431a09cde7e5e99da206d33b3d728
Primary Citations — 7 traced to source
- Law on Personal Data Protection (ZZLP - Official Gazette of North Macedonia No. 42/2020) - in force 25 February 2020; GDPR-aligned; processing principles: lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, accountability; sensitive personal data: racial/ethnic origin, political opinions, religious beliefs, trade union membership, genetic, biometric, health, sexual orientation, criminal convictions - identical to GDPR categories; data subject rights: access, rectification, erasure, restriction, portability, objection, automated decision-making protection; DPO mandatory; 72-hour DZLP breach notification; DPIA required; GDPR-equivalent transfer framework
- Directorate for Personal Data Protection (Дирекција за заштита на личните податоци - DZLP, North Macedonia) - independent supervisory authority established under the ZZLP 2020; registers DPO notifications; receives breach notifications within 72 hours; investigates complaints; conducts inspections; issues binding orders; imposes administrative fines; publishes guidance on ZZLP compliance; participates in Council of Europe data protection authority consultations and EU accession alignment activities; dzlp.mk is the official DZLP portal
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mk-pdpa-2020.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mk-pdpa-2020.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mk-pdpa-2020
- Back to registry: Browse all 10,090 compliance nodes