Skip to content

Evidence request lists

Law on Personal Data Protection (Official Gazette No. 42/2020)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cross-Border + Articles 47-52 + MKPDP-8

MKPDP-Cross-Border-Transfers-MKPDP-8-Articles-47-52-Adequacy-SCC-BCR-EU-Schrems-Convention-108
North Macedonia PDPL Cross-Border + MKPDP-8 + Articles 47-52 + EU Adequacy

North Macedonia PDPL MKPDP-8 + Articles 47-52 Cross-Border Data Transfers. Transfer of personal data outside North Macedonia permitted only where: (1) destination jurisdiction provides adequate level of protection (Article 47) - AZLP follows EU adequacy decisions list + automatic recognition of EU/EEA + UK + Switzerland + Convention 108 parties (28 countries) + bilateral adequacy possible; (2) appropriate safeguards (Article 48) including AZLP-approved Binding Corporate Rules (Obvrzni vnatresni pravila) + Standard Contractual Clauses (Standardni dogovorni klauzuli - based on EU Commission 2021 SCCs Decision 2021/914) + AZLP-approved Codes of Conduct + AZLP-approved Certification Mechanisms + international agreements; (3) derogations (Article 50) - explicit informed consent + performance of contract with data subject or in data subject interest + public interest + legal claims + vital int

Artefacts an auditor will ask for
  • Cross-border transfer inventory
  • Adequacy reliance documentation (EU + Convention 108)
  • SCC 2021 executed copies
  • AZLP-approved BCRs
  • Transfer Impact Assessment per Schrems II
  • International agreement evidence
Where this commonly fails
  • Transfer without lawful basis
  • Old SCCs not refreshed to 2021
  • No TIA
  • No BCR approval procedure

Enforcement + Articles 110-112 + AZLP + Codes

MKPDP-Enforcement-Sanctions-Article-110-111-112-Administrative-Fines-AZLP-Cooperation-MKPDP-16-Codes-Certification-MKPDP-18
North Macedonia PDPL Enforcement + Articles 110-112 + AZLP + Codes + Certification

North Macedonia PDPL Articles 110-112 + MKPDP-13/14/16/18 Enforcement and Sanctions framework. Article 110 Administrative Fines - Minor Violations (procedural + administrative): MKD 50,000-500,000 + cumulative + reduced for small/medium enterprises. Article 111 Administrative Fines - Serious Violations (substantive data protection infringements): MKD 500,000-3,000,000 fine for legal entities + EUR 10M or 2% turnover (GDPR Article 83(4) level) for higher-tier offences + EUR 20M or 4% turnover (GDPR Article 83(5) level) for fundamental principles violations + sensitive data + Cross-Border + data subject rights + AZLP order non-compliance. Article 112 Categories of Fines - tiered by violation type + severity + intentional vs negligent + repeat + cooperation with AZLP + mitigation factors + GDPR Article 83(2) criteria adopted. AZLP investigative + corrective + authorisation + advisory powers

Artefacts an auditor will ask for
  • AZLP investigation response plan
  • Sanctions exposure register (MKD 50K-3M + EUR 10M-20M)
  • Cooperation with AZLP audit records
  • Retention schedule + secure erasure evidence
  • ISO 27701 or Europrivacy certification
  • Code of Conduct adoption
  • Automated decision opt-out programme
Where this commonly fails
  • No AZLP response plan
  • No sanctions exposure analysis
  • Retention non-compliance
  • No certification
  • No Code of Conduct
  • No automated-decision opt-out

Governance + DPO + ROPA + DPIA + PbD + Training

MKPDP-Governance-DPO-MKPDP-3-Records-of-Processing-MKPDP-4-DPIA-MKPDP-5-Privacy-by-Design-MKPDP-12-Training-MKPDP-15
North Macedonia PDPL Governance + DPO + ROPA + DPIA + Privacy by Design + Training

North Macedonia PDPL MKPDP-3 + 4 + 5 + 12 + 15 + Articles 35-46 Governance and Accountability. MKPDP-3 Data Protection Officer (DPO - Oficer za zastita na licnite podatoci) - mandatory designation under Article 41 where: (a) public authorities + bodies; (b) core activities consisting of systematic monitoring on large scale; (c) core activities involving processing of special categories on large scale. DPO must be designated on basis of professional qualities + expert knowledge of data protection law and practices + ability to fulfil tasks (Article 42) + may be employee or external + sufficient resources + reporting to highest management + independence + no conflict of interest + DPO notification to AZLP + DPO contact publication. MKPDP-4 Records of Processing Activities (ROPA - Evidencija za aktivnosti na obrabotka) - controllers and processors must maintain detailed records (Article 35)

Artefacts an auditor will ask for
  • DPO designation + AZLP notification
  • ROPA per processing operation
  • DPIA reports for high-risk
  • Privacy by Design embedded in SDLC
  • Annual training records + role-based
  • Prior consultation with AZLP for residual high-risk
Where this commonly fails
  • No DPO
  • ROPA incomplete
  • No DPIA for high-risk
  • No PbD in development
  • No annual training
  • No prior consultation

Lawful Basis + Consent + Notice + Direct Marketing

MKPDP-Lawful-Basis-Consent-Notice-Transparency-Privacy-Notices-MKPDP-1-9-Direct-Marketing-MKPDP-17
North Macedonia PDPL Lawful Basis + Consent + Notice + Transparency + Direct Marketing

North Macedonia PDPL Articles 10-13 + 19-21 Lawful Basis for Processing. MKPDP-1 Lawful Basis - all processing must rest on one of the six lawful bases: (1) consent of the data subject; (2) performance of contract; (3) compliance with legal obligation; (4) vital interests; (5) public interest task; (6) legitimate interests not overridden by data subject fundamental rights and freedoms. Consent must be freely given + specific + informed + unambiguous + given by clear affirmative action + withdrawable + verifiable for children below age 14 with parental consent (lower than GDPR default 16). MKPDP-9 Transparency and Privacy Notices - data subjects must receive transparent + concise + intelligible + easily accessible information at the point of collection (Articles 19-21) including identity + contact details of controller + DPO + purposes + legal basis + recipients + Cross-Border transfer de

Artefacts an auditor will ask for
  • Lawful basis register per processing
  • Consent records (granular + withdrawable)
  • Macedonian/Albanian privacy notices
  • Children parental consent verification (under 14)
  • Direct marketing opt-in evidence
  • Soft opt-in policy documentation
Where this commonly fails
  • Bundled consent
  • Notices not in Macedonian
  • No children verification
  • Marketing without opt-in
  • Soft opt-in misuse

Scope + Official Gazette 42/2020 + AZLP + GDPR

MKPDP-Scope-Application-North-Macedonia-Official-Gazette-42-2020-February-2020-Effective-24-August-2021-AZLP-GDPR-Alignment
North Macedonia PDPL Scope + Official Gazette 42/2020 + GDPR Alignment + AZLP

Republic of North Macedonia Law on Personal Data Protection (Zakon za zastita na licnite podatoci) published Official Gazette of the Republic of North Macedonia No. 42/2020 of 16 February 2020 + effective 24 August 2021 (18-month transition period) + Amendment Law No. 12/2021 published Official Gazette No. 12/2021 (breach notification clarifications). Replaces the 2005 Law on Personal Data Protection. Substantively aligned with EU GDPR Regulation 2016/679 as part of North Macedonia EU accession process (candidate status since 2005 + formal negotiations opened 19 July 2022). Constitutional anchor Constitution of North Macedonia Article 18 right to privacy + Article 25 inviolability of correspondence. Agency for Personal Data Protection (Agencija za zastita na licnite podatoci - AZLP) - independent supervisory authority + Skopje headquarters + Director appointed by Assembly (Sobranie) for

Artefacts an auditor will ask for
  • Applicability assessment
  • AZLP engagement records
  • Macedonian and Albanian privacy notices
  • Convention 108+ alignment memo
  • Constitution Articles 18 + 25 compliance
  • EU accession readiness gap analysis
Where this commonly fails
  • No AZLP engagement
  • Notices not in Macedonian/Albanian
  • No accession readiness
  • Treating Law same as GDPR without Macedonian provisions

Security + Processor + Breach Notification + Articles 30-37

MKPDP-Security-Processor-Breach-Notification-MKPDP-6-7-10-Articles-36-37-Personal-Data-Breach-72-Hour-AZLP
North Macedonia PDPL Security + Processor + Breach Notification + 72-Hour

North Macedonia PDPL MKPDP-6 + 7 + 10 + Articles 30-37 Security + Processor + Breach Notification. MKPDP-10 Security of Processing (Article 30) - controllers and processors must implement appropriate technical + organisational measures taking into account state-of-the-art + costs + nature + scope + context + purposes + risk including: (a) pseudonymisation + encryption; (b) confidentiality + integrity + availability + resilience of systems; (c) timely restoration of availability and access to data after incident; (d) regular testing + assessment + evaluation. MKPDP-7 Processor Contracts and Oversight (Article 31) - engagements with processors governed by written contract specifying subject-matter + duration + nature + purpose + categories + Controllers obligations + processor obligations including: process only on documented instructions + confidentiality + security + sub-processor author

Artefacts an auditor will ask for
  • Encryption + pseudonymisation evidence
  • Processor contracts (Article 31 compliant)
  • AZLP breach notification log + 72-hour evidence
  • Data subject breach notification when high-risk
  • MK-CIRT + GovCERT.MK coordination records
  • Incident response playbook
Where this commonly fails
  • No encryption
  • No processor contracts
  • Late AZLP notification
  • No data subject breach notification
  • No MK-CIRT liaison

Special Categories + Children Age 14 + Sensitive

MKPDP-Special-Categories-Sensitive-Children-MKPDP-11-Age-14-Parental-Consent-Health-Genetic-Biometric
North Macedonia PDPL Special Categories + Children + Age 14 + Parental Consent

North Macedonia PDPL MKPDP-11 + Articles 14-18 Special Categories of Personal Data. Prohibited categories (Article 14): racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union membership + genetic data + biometric data for unique identification + health data + sexual life + sexual orientation + criminal convictions. Processing of special categories prohibited except: (1) explicit consent of data subject; (2) employment + social security + social protection law (Article 15); (3) vital interests; (4) processing by non-profit body for members; (5) data manifestly made public by data subject; (6) legal claims; (7) substantial public interest authorised by law; (8) preventive or occupational medicine + medical diagnosis + healthcare + public health (with professional secrecy); (9) public interest in archiving + scientific or historical research + statis

Artefacts an auditor will ask for
  • Special categories inventory
  • Explicit consent records
  • Children parental consent + age verification (under 14)
  • EMBG processing legal-basis documentation
  • Healthcare data Health Insurance Fund coordination
  • DPIA for sensitive processing
Where this commonly fails
  • Special categories without explicit consent
  • Children without parental consent
  • EMBG processing without statutory basis
  • Healthcare without Health Insurance Fund coordination

Subject Rights + Articles 22-29 + MKPDP-2

MKPDP-Data-Subject-Rights-Access-Rectification-Erasure-Restriction-Portability-Object-Articles-22-25-MKPDP-2
North Macedonia PDPL Data Subject Rights + Access + Rectification + Erasure + Portability

North Macedonia PDPL Articles 22-25 + MKPDP-2 Data Subject Rights Handling. Article 22 Right of Access - data subject has the right to obtain confirmation of processing + access to personal data + supplementary information (purposes + categories + recipients + retention + ARCO rights + AZLP complaint avenue + source of data + automated decision-making). Article 23 Right to Rectification - to correct inaccurate + incomplete + outdated data + propagation to recipients. Article 24 Right to Erasure (Right to be Forgotten) - to delete personal data when no longer necessary + consent withdrawn + unlawful processing + legal obligation. Article 25 Right to Restriction of Processing - during accuracy verification + processing dispute + objection. Article 26 Right to Data Portability - structured + commonly-used + machine-readable format + transmission to another controller (where technically feas

Artefacts an auditor will ask for
  • Rights request SLAs (30-day) + log
  • Access response templates
  • Portability format documentation
  • Automated decision opt-out + human intervention
  • AZLP appeals procedure
  • Administrative Court review path
Where this commonly fails
  • Slow rights response
  • No portability format
  • No automated-decision opt-out
  • No identity verification
  • No appeals path
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.