ZZLP art. 26 — GDPR art. 22 transposed almost word for word, in force since 24 February 2020, with a 4%-of-income fine and no euro alternative underneath it
Binds Controllers and processors, public and private alike. Art. 2(1) applies the Act to wholly or partly automated processing of personal data and to non-automated processing of data forming part of, or intended to form part of, a filing system, with the household exemption in art. 2(2). Art. 3 gives it the GDPR's reach: establishment in North Macedonia regardless of where the processing happens (art. 3(1)); a controller or processor not established in North Macedonia whose processing relates to offering goods or services to data subjects in North Macedonia — payment or no payment — or to monitoring their behaviour where that behaviour takes place in North Macedonia (art. 3(2)); and a controller established where the law of North Macedonia applies by virtue of international law (art. 3(3)). The duty in art. 26 falls on whoever takes the decision, so the deployer of the system rather than its vendor.. Art. 26 of the Закон за заштита на личните податоци («Службен весник на РСМ» бр. 42/20, 294/21, 101/25) is North Macedonia's automated-decision rule and it tracks GDPR art. 22 closely enough that the differences are worth naming precisely. Art. 26(1): «Субјектот на личните податоци има право да не биде предмет на одлука заснована единствено на автоматизирана обработка, вклучувајќи го и профилирањето што предизвикува правни последици за него или на сличен начин значително влијае на него.» Same trigger as the GDPR — a decision resting solely on automated processing, profiling included, producing legal effects or similarly significantly affecting the person — and, unlike Albania's «pasoja të ngjashme të rënda», no re-drafting of the effects threshold. Art. 26(2) carries the three exits verbatim: (а) necessary for concluding or performing a contract between the data subject and the controller; (б) permitted by a law applying to the controller that itself provides suitable measures safeguarding rights, freedoms and legitimate interests; (в) based on the data subject's explicit consent. Art. 26(3) attaches the safeguards to exits (а) and (в) only, again as in GDPR art. 22(3), and spells out the minimum content: «право на обезбедување на човечка интервенција од страна на контролорот, право на изразување на личен став и право на оспорување на таквата одлука» — human intervention by the controller, the right to express a personal view, the right to contest the decision. Art. 26(4) bars such decisions from resting on special categories of personal data unless art. 13(2) point 1) or point 7) applies, with safeguards in place; art. 13(2)(1) is explicit consent and art. 13(2)(7) is substantial public interest on the basis of law, so the cross-reference lands exactly where GDPR art. 22(4) does via art. 9(2)(a) and (g). Art. 26 does not stand alone: arts. 17(1)(6), 18(1)(7) and 19(1)(8) each require the controller to disclose «постоењето на автоматизиран процес на одлучување, вклучувајќи го и профилирањето како што е наведено во членот 26 ставови (1) и (4)», together with meaningful information about the logic involved and the significance and envisaged consequences, and art. 39(3)(а) makes a systematic and extensive automated evaluation feeding such decisions a trigger for a data-protection impact assessment. There is no law-enforcement counterpart in this Act — the ZZLP has eleven chapters and none of them is a Law Enforcement Directive part, so North Macedonia has no analogue to Serbia's art. 39 or Albania's art. 53 inside this statute.
In force since 24 February 2020, and binding on every controller without transitional relief since 24 August 2021. Art. 124: «Овој закон влегува во сила осмиот ден од денот на објавувањето во ‘Службен весник на Република Северна Македонија’.» Publication was in issue 42 of 16 February 2020 at page 95 — the date is stamped on every page of the Agency's own copy of the Act and the issue-and-page citation is confirmed independently by the publisher's Хронолошки регистар за 2020, entry 813 — so the eighth day is 24 February 2020. Art. 119 then gave controllers and processors 18 months from entry into force to bring their operations into line, which ended on 24 August 2021; that period was a grace window for compliance, not a suspension of the Act, and it has been closed for five years. Both amendments were checked against art. 26 and neither touches it. The Закон за изменување и дополнување на ЗЗЛП at 294/21 (Хронолошки регистар за 2021, entry 627, issue 294 page 34) is not reflected in art. 26, whose text is identical in the original 42/20 gazette copy and in the consolidated text. The Закон за дополнување на ЗЗЛП of 14 May 2025 («Службен весник на РСМ» бр. 101 од 21 мај 2025) amends only arts. 48 and 56, inserting NATO member states alongside EU member states in the international-transfer rules, and enters into force on the day of publication. Art. 122 is a supersession trigger written into the Act: the provisions of chapters II (except art. 12), III, IV (except arts. 46 and 47), V and VIII cease to apply upon North Macedonia's accession to the European Union. Art. 26 sits in chapter III, «Права на субјектот на личните податоци», so it is scheduled to fall away in favour of the GDPR itself on accession — the same construction as art. 100 of Albania's Law 124/2024.
Stated maximum penalty — Up to 4% of total annual income, and — this is the divergence from the GDPR that matters — with no euro floor underneath the percentage. Breach of art. 26 is listed at art. 111(1)(15) («не ги исполнува обврските за регулирање на автоматското донесување на поединечни одлуки, вклучувајќи го и профилирањето според одредбите на членот 26 од овој закон»), which places it in the second of the Act's two offence categories: art. 110 is Category I at up to 2% and art. 111 is Category II at up to 4%. The Category II ceiling is «глоба во износ до 4% од вкупниот годишен приход на контролорот или обработувачот - правно лице, (изразена во апсолутен износ)» for the business year preceding the year of the offence, or for the shorter period since the entity began operating. Where GDPR art. 83(5) sets €20 000 000 or 4% of worldwide annual turnover, whichever is higher, art. 111(1) offers only the percentage, so the exposure of a low-revenue controller is bounded by its own income rather than by a fixed statutory sum. The accompanying personal fines are small and fixed: art. 111(2) €300–500 in denar equivalent for the responsible person in the legal entity, art. 111(3) €100–500 for an official in a state authority, art. 111(4) €100–250 for a natural-person controller or processor. Art. 113 lists the mitigating and aggravating factors that set the amount within the band.