The Personal Data Protection Agency adopted the new Law on Personal Data Protection, as well as the bylaws related to this area. With these changes, Macedonian regulation is being harmonized with European regulation.
What is new in the law?
The deadline for harmonizing the operations of controllers and processors of personal data begins on August 24, 2021, meaning that all companies that perform any processing of personal data must implement the new changes in their operations.
In this context, a controller is considered to be any person, whether natural person, legal entity, state authority, agency or other body, which independently or jointly with others determines the purposes and manner of processing personal data. A processor of a personal data collection is a person, whether natural person, legal entity, state authority, agency or other body, that processes personal data on behalf of the controller.
| Role | What it means | Practical note |
|---|---|---|
| Controller | A person who independently or jointly with others determines the purposes and manner of processing personal data. | purpose and manner |
| Processor | A person who processes personal data on behalf of the controller. | on behalf of controller |
| Company | Controllers and processors of data also include every company that performs any processing of data. | data processing |
The controller is obliged to apply appropriate measures to ensure that only the necessary personal data is processed. At the same time, the controller may also be a processor, or may engage a processor on its behalf.
Controllers and processors of data also include every company that performs any processing of data.
Personal Data Protection Officer
The controller and the processor are obliged to appoint an authorized person for personal data protection, or an officer, who is involved in all matters related to data protection.
To appoint an officer, a “Decision for appointing a personal data protection officer” must be completed. Among other things, the officer’s obligations include:
- informing the controller/processor, as well as employees who perform processing, about their obligations;
- monitoring compliance with the law and with other laws related to this area;
- preparing internal acts for personal data protection.
Restrictions and protection when processing personal data
Under the new law, the processing of personal data will have certain restrictions, such as: purposes of processing, legal periods during which the data may be used, measures for correcting or deleting data, as well as appropriate protection against unauthorized or unlawful processing.
This law enables protection of the data of every natural person, with guaranteed protection without any discrimination based on personal characteristics.
What must be done?
Every processor of personal data must register with the Personal Data Protection Agency in the section “Records of high-risk collections”.
Read the new Law on Personal Data Protection in more detail.
Frequently asked questions about the Law on Personal Data Protection
When does the deadline for harmonization begin?
The deadline for harmonizing the operations of controllers and processors of personal data begins on August 24, 2021.
Who is considered a controller?
A controller is a person who independently or jointly with others determines the purposes and manner of processing personal data.
Who is considered a processor?
A processor is a person who processes personal data on behalf of the controller.
Can the company manager be the officer?
No. The officer may not be the company manager and must be a person with higher education.
Do you need help?
Do you need professional consultations and assistance for your clients regarding the implementation of the new Law on Personal Data Protection? The accounting office Aleksandar.AK is available for you.
Request support for administrative, accounting and consulting alignment with your company’s obligations.