AI LAW RADAR · Daily Last verified 28 Aug 2026

Jurisdiction dossier

North Macedonia: AI regulation & deadlines

North Macedonia has no AI-specific statute in force and one binding automated-decision rule that has applied since 24 February 2020. Art. 26 of the Закон за заштита на личните податоци, published in «Службен весник на РСМ» бр. 42 of 16 February 2020 at page 95 and amended at 294/21 and 101/25, is GDPR art. 22 transposed almost word for word: the same solely-automated trigger with legal or similarly significant effects, the same three exits of contract, authorising law and explicit consent, the same safeguards clause naming human intervention by the controller, the right to express a personal view and the right to contest, and a special-categories bar in art. 26(4) that routes through art. 13(2) points 1) and 7) — explicit consent and substantial public interest — exactly where GDPR art. 22(4) routes through art. 9(2)(a) and (g). Unlike Serbia and Albania, the Act carries no Law Enforcement Directive part, so there is no police-side counterpart to Serbia's art. 39 or Albania's art. 53 in this statute. The divergence that bites is in the penalty: breach of art. 26 is a Category II offence under art. 111(1)(15), capped at 4% of the controller's total annual income, and art. 111 offers no €20 000 000 alternative of the kind GDPR art. 83(5) sets beside the percentage, so a low-revenue controller's exposure is bounded by its own income. Art. 119 gave controllers 18 months from entry into force to align, a window that closed on 24 August 2021. Art. 122 schedules chapters II (except art. 12), III, IV (except arts. 46 and 47), V and VIII — art. 26 among them — to cease applying on EU accession. 1 obligation tracked — 1 in force.

Binding — Binding sectoral Flagship law: ZZLP art. 26

North Macedonia has no AI-specific statute in force and one binding automated-decision rule that has applied since 24 February 2020. Art. 26 of the Закон за заштита на личните податоци, published in «Службен весник на РСМ» бр. 42 of 16 February 2020 at page 95 and amended at 294/21 and 101/25, is GDPR art. 22 transposed almost word for word: the same solely-automated trigger with legal or similarly significant effects, the same three exits of contract, authorising law and explicit consent, the same safeguards clause naming human intervention by the controller, the right to express a personal view and the right to contest, and a special-categories bar in art. 26(4) that routes through art. 13(2) points 1) and 7) — explicit consent and substantial public interest — exactly where GDPR art. 22(4) routes through art. 9(2)(a) and (g). Unlike Serbia and Albania, the Act carries no Law Enforcement Directive part, so there is no police-side counterpart to Serbia's art. 39 or Albania's art. 53 in this statute. The divergence that bites is in the penalty: breach of art. 26 is a Category II offence under art. 111(1)(15), capped at 4% of the controller's total annual income, and art. 111 offers no €20 000 000 alternative of the kind GDPR art. 83(5) sets beside the percentage, so a low-revenue controller's exposure is bounded by its own income. Art. 119 gave controllers 18 months from entry into force to align, a window that closed on 24 August 2021. Art. 122 schedules chapters II (except art. 12), III, IV (except arts. 46 and 47), V and VIII — art. 26 among them — to cease applying on EU accession.

checked 28 Aug 2026 primary source ↗

The Register

1 obligation
North Macedonia Binding

ZZLP art. 26 — GDPR art. 22 transposed almost word for word, in force since 24 February 2020, with a 4%-of-income fine and no euro alternative underneath it

Binds Controllers and processors, public and private alike. Art. 2(1) applies the Act to wholly or partly automated processing of personal data and to non-automated processing of data forming part of, or intended to form part of, a filing system, with the household exemption in art. 2(2). Art. 3 gives it the GDPR's reach: establishment in North Macedonia regardless of where the processing happens (art. 3(1)); a controller or processor not established in North Macedonia whose processing relates to offering goods or services to data subjects in North Macedonia — payment or no payment — or to monitoring their behaviour where that behaviour takes place in North Macedonia (art. 3(2)); and a controller established where the law of North Macedonia applies by virtue of international law (art. 3(3)). The duty in art. 26 falls on whoever takes the decision, so the deployer of the system rather than its vendor.. Art. 26 of the Закон за заштита на личните податоци («Службен весник на РСМ» бр. 42/20, 294/21, 101/25) is North Macedonia's automated-decision rule and it tracks GDPR art. 22 closely enough that the differences are worth naming precisely. Art. 26(1): «Субјектот на личните податоци има право да не биде предмет на одлука заснована единствено на автоматизирана обработка, вклучувајќи го и профилирањето што предизвикува правни последици за него или на сличен начин значително влијае на него.» Same trigger as the GDPR — a decision resting solely on automated processing, profiling included, producing legal effects or similarly significantly affecting the person — and, unlike Albania's «pasoja të ngjashme të rënda», no re-drafting of the effects threshold. Art. 26(2) carries the three exits verbatim: (а) necessary for concluding or performing a contract between the data subject and the controller; (б) permitted by a law applying to the controller that itself provides suitable measures safeguarding rights, freedoms and legitimate interests; (в) based on the data subject's explicit consent. Art. 26(3) attaches the safeguards to exits (а) and (в) only, again as in GDPR art. 22(3), and spells out the minimum content: «право на обезбедување на човечка интервенција од страна на контролорот, право на изразување на личен став и право на оспорување на таквата одлука» — human intervention by the controller, the right to express a personal view, the right to contest the decision. Art. 26(4) bars such decisions from resting on special categories of personal data unless art. 13(2) point 1) or point 7) applies, with safeguards in place; art. 13(2)(1) is explicit consent and art. 13(2)(7) is substantial public interest on the basis of law, so the cross-reference lands exactly where GDPR art. 22(4) does via art. 9(2)(a) and (g). Art. 26 does not stand alone: arts. 17(1)(6), 18(1)(7) and 19(1)(8) each require the controller to disclose «постоењето на автоматизиран процес на одлучување, вклучувајќи го и профилирањето како што е наведено во членот 26 ставови (1) и (4)», together with meaningful information about the logic involved and the significance and envisaged consequences, and art. 39(3)(а) makes a systematic and extensive automated evaluation feeding such decisions a trigger for a data-protection impact assessment. There is no law-enforcement counterpart in this Act — the ZZLP has eleven chapters and none of them is a Law Enforcement Directive part, so North Macedonia has no analogue to Serbia's art. 39 or Albania's art. 53 inside this statute.

In force since 24 February 2020, and binding on every controller without transitional relief since 24 August 2021. Art. 124: «Овој закон влегува во сила осмиот ден од денот на објавувањето во ‘Службен весник на Република Северна Македонија’.» Publication was in issue 42 of 16 February 2020 at page 95 — the date is stamped on every page of the Agency's own copy of the Act and the issue-and-page citation is confirmed independently by the publisher's Хронолошки регистар за 2020, entry 813 — so the eighth day is 24 February 2020. Art. 119 then gave controllers and processors 18 months from entry into force to bring their operations into line, which ended on 24 August 2021; that period was a grace window for compliance, not a suspension of the Act, and it has been closed for five years. Both amendments were checked against art. 26 and neither touches it. The Закон за изменување и дополнување на ЗЗЛП at 294/21 (Хронолошки регистар за 2021, entry 627, issue 294 page 34) is not reflected in art. 26, whose text is identical in the original 42/20 gazette copy and in the consolidated text. The Закон за дополнување на ЗЗЛП of 14 May 2025 («Службен весник на РСМ» бр. 101 од 21 мај 2025) amends only arts. 48 and 56, inserting NATO member states alongside EU member states in the international-transfer rules, and enters into force on the day of publication. Art. 122 is a supersession trigger written into the Act: the provisions of chapters II (except art. 12), III, IV (except arts. 46 and 47), V and VIII cease to apply upon North Macedonia's accession to the European Union. Art. 26 sits in chapter III, «Права на субјектот на личните податоци», so it is scheduled to fall away in favour of the GDPR itself on accession — the same construction as art. 100 of Albania's Law 124/2024.

Stated maximum penalty — Up to 4% of total annual income, and — this is the divergence from the GDPR that matters — with no euro floor underneath the percentage. Breach of art. 26 is listed at art. 111(1)(15) («не ги исполнува обврските за регулирање на автоматското донесување на поединечни одлуки, вклучувајќи го и профилирањето според одредбите на членот 26 од овој закон»), which places it in the second of the Act's two offence categories: art. 110 is Category I at up to 2% and art. 111 is Category II at up to 4%. The Category II ceiling is «глоба во износ до 4% од вкупниот годишен приход на контролорот или обработувачот - правно лице, (изразена во апсолутен износ)» for the business year preceding the year of the offence, or for the shorter period since the entity began operating. Where GDPR art. 83(5) sets €20 000 000 or 4% of worldwide annual turnover, whichever is higher, art. 111(1) offers only the percentage, so the exposure of a low-revenue controller is bounded by its own income rather than by a fixed statutory sum. The accompanying personal fines are small and fixed: art. 111(2) €300–500 in denar equivalent for the responsible person in the legal entity, art. 111(3) €100–500 for an official in a state authority, art. 111(4) €100–250 for a natural-person controller or processor. Art. 113 lists the mitigating and aggravating factors that set the amount within the band.

In force · 24 Feb 2020 checked 28 Aug 2026 ZZLP art. 26 ↗ high confidence

Questions & answers

From the data

When does ZZLP art. 26 take effect in North Macedonia?

ZZLP art. 26 is already in force, with obligations live since February 24, 2020. North Macedonia has no AI-specific statute in force and one binding automated-decision rule that has applied since 24 February 2020. Art. 26 of the Закон за заштита на личните податоци, published in «Службен весник на РСМ» бр. 42 of 16 February 2020 at page 95 and amended at 294/21 and 101/25, is GDPR art. 22 transposed almost word for word: the same solely-automated trigger with legal or similarly significant effects, the same three exits of contract, authorising law and explicit consent, the same safeguards clause naming human intervention by the controller, the right to express a personal view and the right to contest, and a special-categories bar in art. 26(4) that routes through art. 13(2) points 1) and 7) — explicit consent and substantial public interest — exactly where GDPR art. 22(4) routes through art. 9(2)(a) and (g). Unlike Serbia and Albania, the Act carries no Law Enforcement Directive part, so there is no police-side counterpart to Serbia's art. 39 or Albania's art. 53 in this statute. The divergence that bites is in the penalty: breach of art. 26 is a Category II offence under art. 111(1)(15), capped at 4% of the controller's total annual income, and art. 111 offers no €20 000 000 alternative of the kind GDPR art. 83(5) sets beside the percentage, so a low-revenue controller's exposure is bounded by its own income. Art. 119 gave controllers 18 months from entry into force to align, a window that closed on 24 August 2021. Art. 122 schedules chapters II (except art. 12), III, IV (except arts. 46 and 47), V and VIII — art. 26 among them — to cease applying on EU accession.

Who must comply with AI rules in North Macedonia?

Current obligations bind, among others, Controllers and processors, public and private alike. Art. 2(1) applies the Act to wholly or partly automated processing of personal data and to non-automated processing of data forming part of, or intended to form part of, a filing system, with the household exemption in art. 2(2). Art. 3 gives it the GDPR's reach: establishment in North Macedonia regardless of where the processing happens (art. 3(1)); a controller or processor not established in North Macedonia whose processing relates to offering goods or services to data subjects in North Macedonia — payment or no payment — or to monitoring their behaviour where that behaviour takes place in North Macedonia (art. 3(2)); and a controller established where the law of North Macedonia applies by virtue of international law (art. 3(3)). The duty in art. 26 falls on whoever takes the decision, so the deployer of the system rather than its vendor.. Scope and thresholds vary per instrument — see each row's source for the legal text.

What are the penalties for AI non-compliance in North Macedonia?

Stated statutory maxima include: ZZLP art. 26 — Up to 4% of total annual income, and — this is the divergence from the GDPR that matters — with no euro floor underneath the percentage. Breach of art. 26 is listed at art. 111(1)(15) («не ги исполнува обврските за регулирање на автоматското донесување на поединечни одлуки, вклучувајќи го и профилирањето според одредбите на членот 26 од овој закон»), which places it in the second of the Act's two offence categories: art. 110 is Category I at up to 2% and art. 111 is Category II at up to 4%. The Category II ceiling is «глоба во износ до 4% од вкупниот годишен приход на контролорот или обработувачот - правно лице, (изразена во апсолутен износ)» for the business year preceding the year of the offence, or for the shorter period since the entity began operating. Where GDPR art. 83(5) sets €20 000 000 or 4% of worldwide annual turnover, whichever is higher, art. 111(1) offers only the percentage, so the exposure of a low-revenue controller is bounded by its own income rather than by a fixed statutory sum. The accompanying personal fines are small and fixed: art. 111(2) €300–500 in denar equivalent for the responsible person in the legal entity, art. 111(3) €100–500 for an official in a state authority, art. 111(4) €100–250 for a natural-person controller or processor. Art. 113 lists the mitigating and aggravating factors that set the amount within the band.. These are the maximum amounts in the instruments; actual enforcement is at the regulator's discretion.