Law on Personal Data Protection (Official Gazette No. 42/2020)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cross-Border + Articles 47-52 + MKPDP-8
North Macedonia PDPL MKPDP-8 + Articles 47-52 Cross-Border Data Transfers. Transfer of personal data outside North Macedonia permitted only where: (1) destination jurisdiction provides adequate level of protection (Article 47) - AZLP follows EU adequacy decisions list + automatic recognition of EU/EEA + UK + Switzerland + Convention 108 parties (28 countries) + bilateral adequacy possible; (2) appropriate safeguards (Article 48) including AZLP-approved Binding Corporate Rules (Obvrzni vnatresni pravila) + Standard Contractual Clauses (Standardni dogovorni klauzuli - based on EU Commission 2021 SCCs Decision 2021/914) + AZLP-approved Codes of Conduct + AZLP-approved Certification Mechanisms + international agreements; (3) derogations (Article 50) - explicit informed consent + performance of contract with data subject or in data subject interest + public interest + legal claims + vital int
- Cross-border transfer inventory
- Adequacy reliance documentation (EU + Convention 108)
- SCC 2021 executed copies
- AZLP-approved BCRs
- Transfer Impact Assessment per Schrems II
- International agreement evidence
- Transfer without lawful basis
- Old SCCs not refreshed to 2021
- No TIA
- No BCR approval procedure
Enforcement + Articles 110-112 + AZLP + Codes
North Macedonia PDPL Articles 110-112 + MKPDP-13/14/16/18 Enforcement and Sanctions framework. Article 110 Administrative Fines - Minor Violations (procedural + administrative): MKD 50,000-500,000 + cumulative + reduced for small/medium enterprises. Article 111 Administrative Fines - Serious Violations (substantive data protection infringements): MKD 500,000-3,000,000 fine for legal entities + EUR 10M or 2% turnover (GDPR Article 83(4) level) for higher-tier offences + EUR 20M or 4% turnover (GDPR Article 83(5) level) for fundamental principles violations + sensitive data + Cross-Border + data subject rights + AZLP order non-compliance. Article 112 Categories of Fines - tiered by violation type + severity + intentional vs negligent + repeat + cooperation with AZLP + mitigation factors + GDPR Article 83(2) criteria adopted. AZLP investigative + corrective + authorisation + advisory powers
- AZLP investigation response plan
- Sanctions exposure register (MKD 50K-3M + EUR 10M-20M)
- Cooperation with AZLP audit records
- Retention schedule + secure erasure evidence
- ISO 27701 or Europrivacy certification
- Code of Conduct adoption
- Automated decision opt-out programme
- No AZLP response plan
- No sanctions exposure analysis
- Retention non-compliance
- No certification
- No Code of Conduct
- No automated-decision opt-out
Governance + DPO + ROPA + DPIA + PbD + Training
North Macedonia PDPL MKPDP-3 + 4 + 5 + 12 + 15 + Articles 35-46 Governance and Accountability. MKPDP-3 Data Protection Officer (DPO - Oficer za zastita na licnite podatoci) - mandatory designation under Article 41 where: (a) public authorities + bodies; (b) core activities consisting of systematic monitoring on large scale; (c) core activities involving processing of special categories on large scale. DPO must be designated on basis of professional qualities + expert knowledge of data protection law and practices + ability to fulfil tasks (Article 42) + may be employee or external + sufficient resources + reporting to highest management + independence + no conflict of interest + DPO notification to AZLP + DPO contact publication. MKPDP-4 Records of Processing Activities (ROPA - Evidencija za aktivnosti na obrabotka) - controllers and processors must maintain detailed records (Article 35)
- DPO designation + AZLP notification
- ROPA per processing operation
- DPIA reports for high-risk
- Privacy by Design embedded in SDLC
- Annual training records + role-based
- Prior consultation with AZLP for residual high-risk
- No DPO
- ROPA incomplete
- No DPIA for high-risk
- No PbD in development
- No annual training
- No prior consultation
Lawful Basis + Consent + Notice + Direct Marketing
North Macedonia PDPL Articles 10-13 + 19-21 Lawful Basis for Processing. MKPDP-1 Lawful Basis - all processing must rest on one of the six lawful bases: (1) consent of the data subject; (2) performance of contract; (3) compliance with legal obligation; (4) vital interests; (5) public interest task; (6) legitimate interests not overridden by data subject fundamental rights and freedoms. Consent must be freely given + specific + informed + unambiguous + given by clear affirmative action + withdrawable + verifiable for children below age 14 with parental consent (lower than GDPR default 16). MKPDP-9 Transparency and Privacy Notices - data subjects must receive transparent + concise + intelligible + easily accessible information at the point of collection (Articles 19-21) including identity + contact details of controller + DPO + purposes + legal basis + recipients + Cross-Border transfer de
- Lawful basis register per processing
- Consent records (granular + withdrawable)
- Macedonian/Albanian privacy notices
- Children parental consent verification (under 14)
- Direct marketing opt-in evidence
- Soft opt-in policy documentation
- Bundled consent
- Notices not in Macedonian
- No children verification
- Marketing without opt-in
- Soft opt-in misuse
Scope + Official Gazette 42/2020 + AZLP + GDPR
Republic of North Macedonia Law on Personal Data Protection (Zakon za zastita na licnite podatoci) published Official Gazette of the Republic of North Macedonia No. 42/2020 of 16 February 2020 + effective 24 August 2021 (18-month transition period) + Amendment Law No. 12/2021 published Official Gazette No. 12/2021 (breach notification clarifications). Replaces the 2005 Law on Personal Data Protection. Substantively aligned with EU GDPR Regulation 2016/679 as part of North Macedonia EU accession process (candidate status since 2005 + formal negotiations opened 19 July 2022). Constitutional anchor Constitution of North Macedonia Article 18 right to privacy + Article 25 inviolability of correspondence. Agency for Personal Data Protection (Agencija za zastita na licnite podatoci - AZLP) - independent supervisory authority + Skopje headquarters + Director appointed by Assembly (Sobranie) for
- Applicability assessment
- AZLP engagement records
- Macedonian and Albanian privacy notices
- Convention 108+ alignment memo
- Constitution Articles 18 + 25 compliance
- EU accession readiness gap analysis
- No AZLP engagement
- Notices not in Macedonian/Albanian
- No accession readiness
- Treating Law same as GDPR without Macedonian provisions
Security + Processor + Breach Notification + Articles 30-37
North Macedonia PDPL MKPDP-6 + 7 + 10 + Articles 30-37 Security + Processor + Breach Notification. MKPDP-10 Security of Processing (Article 30) - controllers and processors must implement appropriate technical + organisational measures taking into account state-of-the-art + costs + nature + scope + context + purposes + risk including: (a) pseudonymisation + encryption; (b) confidentiality + integrity + availability + resilience of systems; (c) timely restoration of availability and access to data after incident; (d) regular testing + assessment + evaluation. MKPDP-7 Processor Contracts and Oversight (Article 31) - engagements with processors governed by written contract specifying subject-matter + duration + nature + purpose + categories + Controllers obligations + processor obligations including: process only on documented instructions + confidentiality + security + sub-processor author
- Encryption + pseudonymisation evidence
- Processor contracts (Article 31 compliant)
- AZLP breach notification log + 72-hour evidence
- Data subject breach notification when high-risk
- MK-CIRT + GovCERT.MK coordination records
- Incident response playbook
- No encryption
- No processor contracts
- Late AZLP notification
- No data subject breach notification
- No MK-CIRT liaison
Special Categories + Children Age 14 + Sensitive
North Macedonia PDPL MKPDP-11 + Articles 14-18 Special Categories of Personal Data. Prohibited categories (Article 14): racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union membership + genetic data + biometric data for unique identification + health data + sexual life + sexual orientation + criminal convictions. Processing of special categories prohibited except: (1) explicit consent of data subject; (2) employment + social security + social protection law (Article 15); (3) vital interests; (4) processing by non-profit body for members; (5) data manifestly made public by data subject; (6) legal claims; (7) substantial public interest authorised by law; (8) preventive or occupational medicine + medical diagnosis + healthcare + public health (with professional secrecy); (9) public interest in archiving + scientific or historical research + statis
- Special categories inventory
- Explicit consent records
- Children parental consent + age verification (under 14)
- EMBG processing legal-basis documentation
- Healthcare data Health Insurance Fund coordination
- DPIA for sensitive processing
- Special categories without explicit consent
- Children without parental consent
- EMBG processing without statutory basis
- Healthcare without Health Insurance Fund coordination
Subject Rights + Articles 22-29 + MKPDP-2
North Macedonia PDPL Articles 22-25 + MKPDP-2 Data Subject Rights Handling. Article 22 Right of Access - data subject has the right to obtain confirmation of processing + access to personal data + supplementary information (purposes + categories + recipients + retention + ARCO rights + AZLP complaint avenue + source of data + automated decision-making). Article 23 Right to Rectification - to correct inaccurate + incomplete + outdated data + propagation to recipients. Article 24 Right to Erasure (Right to be Forgotten) - to delete personal data when no longer necessary + consent withdrawn + unlawful processing + legal obligation. Article 25 Right to Restriction of Processing - during accuracy verification + processing dispute + objection. Article 26 Right to Data Portability - structured + commonly-used + machine-readable format + transmission to another controller (where technically feas
- Rights request SLAs (30-day) + log
- Access response templates
- Portability format documentation
- Automated decision opt-out + human intervention
- AZLP appeals procedure
- Administrative Court review path
- Slow rights response
- No portability format
- No automated-decision opt-out
- No identity verification
- No appeals path
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.