StartNewsNorth Macedonian Administrative Court Upholds Agency Decision on Unlawful Processing of Patient Health Data
07.10.2026Dr. Tobias Höllwarth

North Macedonian Administrative Court Upholds Agency Decision on Unlawful Processing of Patient Health Data

The Administrative Court of North Macedonia has upheld a decision of the Personal Data Protection Agency concerning the unlawful processing of a patient’s personal and health data within the national electronic healthcare system.

North Macedonian Administrative Court Upholds Agency Decision on Unlawful Processing of Patient Health Data

On 29 July 2026, the North Macedonian Personal Data Protection Agency (the “Agency”) announced that the Administrative Court had confirmed a decision of the Agency’s Misdemeanour Commission dated 21 January 2026. The decision followed a supervisory procedure conducted by the Agency and resulted in sanctions being imposed on the University Clinic for Gastroenterohepatology in Skopje, its acting director and a doctor.

Incorrect patient data entered into the national e-health system

The case concerned the national electronic healthcare system known as “Moj Termin” (“My Appointment”).

According to the Agency’s public statement, on 11 April 2025, a medical referral was issued in the name of a female patient who had not received healthcare services on that date. The referral contained health information relating to another individual.

The incorrectly issued referral was subsequently used to generate additional referrals and medical reports. Those documents contained the patient’s identifying information but associated it with inaccurate health data relating to another person.

The incident therefore extended beyond an isolated clerical error. Once the inaccurate information had been entered into the electronic system, it was reproduced in subsequent healthcare documentation. This created a risk to the integrity of the patient’s medical record and to any healthcare decisions that might have been made on the basis of that record.

The incident had already attracted media attention in April 2025, when a national television investigative programme reported that another individual may have received healthcare services using the affected patient’s identity. The report raised the possibility of misuse of both personal data and health insurance rights.

Legal basis of the decision

The Agency classified the conduct as unlawful processing under Article 111(1)(2), in conjunction with paragraphs (2) and (3), of the North Macedonian Law on Personal Data Protection. Article 111 regulates Category II misdemeanours, including failures by controllers or processors to ensure that personal data are processed lawfully in accordance with Article 10 of the Law. It also provides for the potential liability of the responsible person within a legal entity and of an official person involved in the infringement.

Article 10 reflects the GDPR framework on lawfulness of processing and requires each processing operation to be based on an applicable legal ground. The North Macedonian Law on Personal Data Protection is largely aligned with Regulation (EU) 2016/679.

Although the Agency’s public announcement formally refers to unlawful processing under Article 10, the facts of the case also highlight the importance of the accuracy principle under Article 9 of the Law ( Personal data must be accurate and, where necessary, kept up to date).

This requirement is particularly important in the healthcare sector, where inaccurate information may affect not only privacy rights but also medical diagnosis, treatment and continuity of care.

Sanctions

The Misdemeanour Commission imposed sanctions on the University Clinic for Gastroenterohepatology as the controller, on the acting director as the responsible person within the legal entity and on the doctor as an official person.

By confirming the Commission’s decision, the Administrative Court rendered the imposed sanctions final.

Practical implications for healthcare controllers

The decision demonstrates that data protection compliance in healthcare is not limited to preventing unauthorised access to, or disclosure of, medical information. The accuracy and correct attribution of information within electronic health records are equally important. Incorrectly linking one person’s identity to another person’s medical information can create risks not only for privacy, but also for diagnosis, treatment, continuity of care and the exercise of patients’ rights and public confidence in the healthcare system as well.

Article provided by INPLP member: Jasmina Brezovska (BONA FIDE Law Firm, North Macedonia)

Von Dr. Tobias Höllwarth← Alle News