Armenia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Armenia lets personal data leave, but only to a country on an official approved list of 53 states, or with case-by-case permission from the privacy regulator. That regulator has had no boss since February 2026 and the largest fine it can impose is about 1,300 US dollars. The real constraints are elsewhere: government data sent to a foreign cloud must keep a backup copy inside Armenia, and banking and medical secrecy sit outside the privacy law entirely.
Eight questions about Armenia
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Armenia's rules apply to my company?
Probably not, if you have nothing in Armenia. The privacy law describes who it covers by naming Armenian public bodies, companies and individuals who process personal data. It contains no clause saying it follows Armenians' data abroad, and no rule requiring a foreign company to appoint someone inside Armenia. There is no size or revenue threshold either, so a one-person Armenian business is caught exactly like a bank.
Article 1(1) of the Law on Protection of Personal Data (HO-49-N) defines the subject matter as the processing of personal data by state administration or local self-government bodies, state or community institutions or organisations, and legal or natural persons, and state supervision over that processing. There is no equivalent of Article 3 of the EU General Data Protection Regulation. A full-text scan of the consolidated law on 18 August 2026 found no provision on extraterritorial application and no in-country representative duty. Article 1(2) carves out state, banking, notarial, advocate and insurance secrets, national security and defence processing, anti-money-laundering work, covert investigation and court proceedings — those are governed by their own statutes. Article 1(4) confirms other laws may set their own processing and supervision rules, and where another law names a supervisory body, the privacy regulator exercises its powers in the manner set by the privacy law.
Sources
- Official sourceARLIS — Legal Information System of the Republic of Armenia (Ministry of Justice)Law of the Republic of Armenia on Protection of Personal Data, HO-49-N of 18 May 2015, consolidated text, Article 1
arlis.am
“Սույն օրենքը կարգավորում է պետական կառավարման կամ տեղական ինքնակառավարման մարմինների, պետական կամ համայնքային հիմնարկների կամ կազմակերպությունների, իրավաբանական կամ ֆիզիկական անձանց կողմից անձնական տվյալները մշակելու, դրանց նկատմամբ պետական հսկողություն իրականացնելու կարգն ու պայմանները:”
Link checked 18 August 2026
Can I store my users' data outside Armenia?
Yes, with paperwork. Armenia runs an approved-country list: if the destination is on it, you can send data with no permission from anyone. The list is real and populated — 53 countries, including all of the European Union, the United Kingdom, Canada, Japan, South Korea, Israel, Georgia and Russia. Sending data anywhere else needs written permission from the privacy regulator first, and that regulator currently has nobody in the chair. Three sectors override this entirely: government, banking-type secrets, and health.
Article 27 of HO-49-N sets the structure. Article 27(1): a transfer abroad needs either the person's consent or a demonstrable link to the processing purpose. Article 27(2): no regulator permission is needed where the destination ensures an adequate level of protection, which is deemed satisfied if the transfer is made under an international treaty or the destination appears on the list published by the regulator. Article 27(3)-(4): to any other country, the sender must apply in writing before transferring, describing the destination, the recipient, the data, the purpose and the contract or draft contract; the regulator has 30 days to allow or refuse and must specify what contractual changes would make the guarantees sufficient. Article 27(6): personal data held by state bodies may go to foreign state bodies only under ratified international treaties. SECTOR OVERRIDES. (1) Government — a copy must stay in the country. Government decision N 884-L of 14 June 2024 ('Cloud First') requires state administration bodies that place state information systems, data or information in a cloud located outside Armenia to keep a backup copy in Armenia on minimum necessary server infrastructure, and permits only 'low' risk-rated, non-state-secret public information to be put in a cloud at all. (2) Banking, notarial, advocate and insurance secrecy — data can leave with the right paperwork but by a different route: Article 1(2) of the privacy law removes these from its scope, so the approved-country list gives no cover; the Law on Bank Secrecy of 7 October 1996 lists exhaustively who may receive bank secrets and foreign service providers are not among them. (3) Health — data can leave with the right paperwork; the anonymised database inside the national electronic health system is declared the property of the Republic of Armenia and managed under a government-set procedure, and disclosing medical secrets without written consent is a criminal offence. (4) Vital-sector operators (energy, transport, water, communications, post, financial services, health, information technology, space, database operation, public administration and others) are not restricted on where data sits, but are supervised by the new cybersecurity regulator. Telecoms: operators must keep customer data confidential and must give law-enforcement and national-security staff access to communications equipment including interception devices, which in practice keeps interception infrastructure in-country. No express telecom, insurance, securities, education, gaming or mapping localisation rule was found — checked 18 August 2026, medium confidence.
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Article 27 (transfer of personal data to other states)
arlis.am
“Առանց լիազոր մարմնի թույլտվության անձնական տվյալները կարող են փոխանցվել այլ պետություն, եթե այդ պետությունում ապահովված է անձնական տվյալների պաշտպանության բավարար մակարդակ:”
Link checked 18 August 2026
- Official sourcePersonal Data Protection Agency, Ministry of Justice (published on ARLIS)Decision of the Head of the Personal Data Protection Agency N ATPP-001/24 of 8 July 2024 establishing the list of states ensuring an adequate level of personal data protection
arlis.am
Link checked 18 August 2026
- Official sourceGovernment of the Republic of Armenia (published on ARLIS)Government decision N 884-L of 14 June 2024 on the development and introduction of the 'Cloud First' policy, point 1(3)
arlis.am
“պետական կառավարման համակարգի մարմիններն իրենց տնօրինության տակ գտնվող պետական տեղեկատվական համակարգերը, տվյալները և տեղեկատվությունը Հայաստանի Հանրապետությունից դուրս գտնվող ամպային տիրույթում տեղադրելիս Հայաստանի Հանրապետությունում պահպանում են դրանց պահուստային տարբերակը՝ նվազագույն անհրաժեշտ սերվերային ենթակառուցվածքների ներգրավմամբ.”
Link checked 18 August 2026
What do I need in place before data leaves Armenia?
The model is an approved list, and the list is full. Fifty-three countries were approved on 8 July 2024 and that decision has never been changed. If your destination is on it you need nothing — no standard contract, no filing, no fee. If it is not on it, you must write to the regulator before you send anything, attach the contract you plan to sign, and wait up to 30 days for a yes or a no.
The approved list (Decision N ATPP-001/24, in force 10 July 2024) covers: Albania, the United States (organisations only), Andorra, Austria, Argentina, Belgium, Bosnia and Herzegovina, Bulgaria, Germany, Denmark, Estonia, Iceland, Ireland, Italy, Spain, Israel, Latvia, Liechtenstein, Lithuania, Luxembourg, Poland, Croatia, Canada, Republic of Korea, Cyprus, North Macedonia, Greece, Hungary, Japan, Malta, the United Kingdom, Moldova, Monaco, Montenegro, the Netherlands, New Zealand, Norway, Sweden, Switzerland, Czechia, Portugal, Romania, the Russian Federation, San Marino, Serbia, Singapore, Slovakia, Slovenia, Georgia, Ukraine, Uruguay, Finland and France. Countries absent from the list and therefore requiring case-by-case permission include India, China, Australia, Brazil, Mexico, Turkey, the United Arab Emirates, Kazakhstan and Azerbaijan. The United States entry is qualified with the word 'organisations', which reads as a certified-organisation approach rather than blanket country approval; that qualification is not further defined in the decision. Two structural points. First, this is a single official's decision, not a statute or a government decree, so the head of the agency can add or remove a country — including Russia — with one signature and no consultation. Second, Article 27(5) obliges the regulator to review the list at least once a year and publish changes; no revision has appeared since July 2024, more than two years ago, so the annual review duty appears to be unmet.
Sources
- Official sourcePersonal Data Protection Agency, Ministry of Justice (published on ARLIS)Decision N ATPP-001/24 of 8 July 2024, Annex — list of 53 states ensuring an adequate level of protection
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Article 27(3)-(5) — permission procedure and annual review of the list
arlis.am
“Լիազոր մարմինը 30 օրվա ընթացքում պարտավոր է թույլատրել կամ մերժել հայտը:”
Link checked 18 August 2026
Who enforces the rules in Armenia, and what can they do?
On paper, the Personal Data Protection Agency inside the Ministry of Justice. In practice, nobody right now: its head resigned with effect from 24 February 2026 and no replacement appointment has been published. In more than eleven years the agency has published exactly one general decision — the approved-country list. Two other regulators are genuinely working: the Central Bank supervises banks, payment firms, insurers and securities, and a brand-new Information Systems Regulatory Commission was appointed in March and April 2026 to police cybersecurity and state computer systems.
Article 24 of HO-49-N gives the agency real powers: inspections on its own initiative, administrative penalties, orders to block, suspend or stop processing, orders to correct or destroy data, a register of processors, court applications, and an annual public report. Article 25 sets an unusual appointment route — the Prime Minister appoints the head for five years on the nomination of the Minister of Justice, chosen from a list of candidates jointly proposed by at least five human-rights non-governmental organisations, and nobody may serve two consecutive terms. The evidence on operation: Prime Minister's decision N 120-A of 13 February 2026 released Grigor Nersisyan from the post of Head of the Agency with effect from 24 February 2026, on his own written application. A search of the official legal database on 18 August 2026 found no subsequent appointment decision, although earlier appointments in 2015, 2018 and 2023 were all published there. Administrative fine decisions under Article 189.17 of the Code of Administrative Offences are not published in the legal database, so a low level of enforcement activity cannot be excluded, but no published enforcement decision or annual report was found. The Agency's own website could not be reached — the Ministry of Justice site blocks automated access — so this rating rests on the official acts database alone. By contrast, the Information Systems Regulatory Commission created by law HO-444-N of 4 December 2025 was actually stood up: the National Assembly appointed Nerses Yeritsyan as chairman and Nairi Adamyan and Srbuhi Hakobyan as members on 26 March 2026, and David Khachatryan on 16 April 2026. The law treats the Commission as formed once four members are appointed, so it has been constituted, and the 2026 state budget was amended to fund it.
Sources
- Official sourcePrime Minister of the Republic of Armenia (published on ARLIS)Prime Minister's decision N 120-A of 13 February 2026 releasing Grigor Nersisyan from the post of Head of the Personal Data Protection Agency of the Ministry of Justice
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Articles 24 and 25 — powers and appointment of the head of the authority
arlis.am
Link checked 18 August 2026
- Official sourceNational Assembly of the Republic of Armenia (published on ARLIS)National Assembly decision AZHO-117-A of 26 March 2026 appointing Nerses Yeritsyan chairman of the Information Systems Regulatory Commission
arlis.am
Link checked 18 August 2026
How long do I have to keep the data?
The floor is five years for anything that proves your tax position. The ceiling is not a number — it is a principle: you must destroy or block personal data as soon as you no longer need it for the purpose you collected it for. Two hard clocks sit inside that principle. If someone withdraws consent you have ten working days to destroy their data, then three more working days to tell them you did. If you spot unlawful processing you have three working days to fix it or destroy the data.
FLOOR. Article 56 of the Tax Code requires taxpayers to keep documents substantiating the tax base, income, expenses and taxes paid or withheld for not less than five years from the reporting period they relate to. Financial institutions reporting under the international common reporting standard must keep account documents and the contents of computer systems and electronic media for not less than five years. CEILING. Article 5(5) of HO-49-N requires personal data to be stored so that identification of the person is not possible for longer than needed for the pre-determined purpose. Article 19(1) requires the processor to destroy or block data not needed to achieve the lawful purpose. Article 21(5) requires processing to stop immediately once the purpose is achieved, unless another law says otherwise. Article 21(6) sets the ten-working-day destruction clock after a written or digitally signed consent withdrawal, and a three-working-day duty to confirm destruction to the person. Article 21(3) sets the three-working-day clock to cure unlawful processing, failing which the data must be destroyed immediately. CONFLICT. The law does not resolve floor-versus-ceiling with a general rule; it resolves it by exception. Article 21(5) and Article 21(6) both yield to 'unless otherwise provided by law', so a statutory retention duty such as the five-year tax rule overrides the deletion duty. Article 8 also makes processing lawful where it follows from a legal obligation.
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Articles 5, 19 and 21 — storage limitation, destruction and blocking
arlis.am
“մշակողը պարտավոր է դադարեցնել անձնական տվյալներ մշակելը և ոչնչացնել տվյալները հետկանչն ստանալու օրվան հաջորդող տասն աշխատանքային օրվա ընթացքում”
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaTax Code of the Republic of Armenia, HO-165-N — five-year duty to keep documents substantiating the tax base
arlis.am
“ապահովել հարկման բազայի հաշվարկման և հարկային հաշվարկների ներկայացման համար անհրաժեշտ փաստաթղթերի ... պահպանումը ոչ պակաս, քան հինգ տարի ժամկետում”
Link checked 18 August 2026
What happens if there is a breach?
Count three clocks. Under the privacy law, if data leaks out of your electronic systems you must immediately publish a public announcement about it and at the same time tell the Armenian police and the privacy regulator — there is no grace period and no threshold. If you run a system in a sector the state calls vital, you have 24 hours to tell the cybersecurity regulator, 72 hours to send an update, two days to warn the people affected, and one month to file a final report. Both sets of duties can bite at once.
Article 21(4) of HO-49-N is unusual and easy to miss: on a leak of personal data from electronic systems the processor must immediately publish a statement, simultaneously reporting the leak to the Police of the Republic of Armenia and to the privacy regulator. Notice what it does not say: there is no severity threshold, no risk test, and no option to notify the regulator quietly first. Public disclosure is the primary obligation. Article 11 of the Law on Cybersecurity HO-442-N (in force 4 January 2026) runs the second set of clocks for service providers in the fourteen vital sectors. Notification to the Autonomous Body immediately and no later than 24 hours after becoming aware, for any incident with a material effect on continuous, uninterrupted or secure operation — or where a material effect cannot yet be assessed but can reasonably be assumed. Updated information within 72 hours. Notification of potentially affected persons immediately, or within two days if that is not possible; if the provider fails, the regulator may notify those people or the public itself. Final report within one month of the 72-hour update, covering causes, remedies, severity, scale, time spent, money spent and preventive steps.
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Article 21(4) — leak from electronic systems
arlis.am
“Էլեկտրոնային համակարգերից անձնական տվյալների արտահոսքի դեպքում մշակողը պարտավոր է այդ մասին անհապաղ հրապարակել հայտարարություն՝ միաժամանակ արտահոսքի վերաբերյալ հայտնելով Հայաստանի Հանրապետության ոստիկանությանը և անձնական տվյալների պաշտպանության լիազոր մարմնին:”
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw of the Republic of Armenia on Cybersecurity, HO-442-N of 4 December 2025, Article 11 — cyber incident notification
arlis.am
“պարտավոր է կիբեռմիջադեպի մասին իրեն հայտնի դառնալուց հետո անհապաղ, բայց ոչ ուշ, քան 24 ժամվա ընթացքում, Ինքնավար մարմնին ծանուցել”
Link checked 18 August 2026
What trips people up in Armenia?
Five things that will ruin your week. One: a data leak must be announced publicly and reported to the police, not just to the regulator. Two: encryption is legally compulsory, not a best practice, and failing to use it is its own separate fine. Three: before you process biometric or sensitive data you must notify the regulator in advance and wait to be entered in its register. Four: to process a dead person's data you need the consent of all of their legal heirs. Five: a child is anyone under 16 here, not 13 and not 18.
1. PUBLIC ANNOUNCEMENT OF LEAKS. Article 21(4) requires the announcement to be published, with simultaneous reports to the police and the regulator. Most breach playbooks assume regulator-first and public-later; Armenia inverts that. 2. COMPULSORY ENCRYPTION. Article 19(2) obliges every processor to use encryption to protect information systems containing personal data. Article 189.17(5) of the Code of Administrative Offences makes not using encryption a standalone offence, fined at 100 times the statutory calculation base, about 100,000 drams (roughly 260 US dollars). 3. PRIOR NOTIFICATION FOR SENSITIVE AND BIOMETRIC DATA. Article 23(3) makes notification to the regulator compulsory before processing biometric or special-category data; Article 23(5) gives the regulator 30 days to enter the details in the register of processors; Article 23(8) requires updates within ten working days of any change. This is a registration duty in all but name, and it is currently owed to an authority with no head. 4. DEAD PEOPLE. Article 9(10) requires the consent of all legal heirs to process the personal data of someone who has died or been declared dead; where there are no heirs, consent comes from the head of the community where the succession opened. There is no time limit on this. 5. CHILDREN AT 16. Article 9(9) requires the legal representative's consent for anyone under 16, and for people lacking or with limited legal capacity. Armenia has no separate lower age of digital consent. 6. CRIMINAL LIABILITY ON INDIVIDUALS. Article 204 of the Criminal Code punishes using, selling or disclosing someone's personal or family secret without consent with up to one year in prison, rising to three years where it is spread through the media or online. Article 205 punishes a data processor who discloses medical secrets without written consent with up to two years, rising to three years where it is published, and higher again where the offender is a health worker. 7. THE FINES ARE TINY BUT THE SECRECY FINES ARE NOT. The maximum administrative fine for a data protection breach is 500 times the calculation base, about 500,000 drams (roughly 1,300 US dollars), and Article 189.17(8) lets an offender escape liability entirely by curing the breach within the deadline the regulator sets. Unlawful disclosure of bank secrecy, by contrast, carries a court-imposed fine of 2,000 to 10,000 times the base — roughly 5,200 to 26,000 US dollars — plus possible criminal liability and full compensation of the customer's loss.
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Articles 9(9)-(10), 19(2) and 23(3)
arlis.am
“Մշակողը մինչև կենսաչափական կամ հատուկ կատեգորիայի անձնական տվյալներ մշակելը պարտավոր է անձնական տվյալների պաշտպանության լիազոր մարմնին ծանուցել տվյալներ մշակելու մտադրության մասին:”
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaCode of Administrative Offences of the Republic of Armenia, Article 189.17 — penalties for breaches of the personal data legislation
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaCriminal Code of the Republic of Armenia, HO-199-N, Articles 204 and 205 — violation of private life and disclosure of medical secrets
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on the Minimum Monthly Wage, HO-66-N, Article 3 — the calculation base for fines in codes and laws is 1,000 drams
arlis.am
“Նշված ակտերում որպես հաշվարկային հիմք սահմանվում է 1000 դրամը:”
Link checked 18 August 2026
What is changing soon in Armenia?
Armenia rewired its digital rulebook in December 2025 and the deadlines land through 2026, 2027 and 2028. Rules for cyber incidents and for state computer systems are already live. Detailed technical rules are due by January 2027, internal cybersecurity policies and risk assessments by July 2027, and security certificates for critical systems by January 2028. The change most likely to catch someone out is not a new law at all: the approved-country list can be rewritten by one official's signature.
ALREADY LANDED. Law HO-191-N, adopted 7 May 2026, came into force on 15 August 2026 — three days before this record was written. It deletes the rule that the head of the privacy regulator must leave at 65, removing an age ceiling from the appointment regime. DATED AND COMING. Under Article 25 of the Law on Cybersecurity, the sub-statutory acts and the national cybersecurity standard are due within twelve months of 4 January 2026, so by 4 January 2027. Service providers must adopt internal cybersecurity regulations and complete risk assessments and incident-prevention programmes within eighteen months, so by 4 July 2027. Operators of critical information infrastructure and cybersecurity service providers must produce a document certifying conformity with an international or national cybersecurity standard within twenty-four months, so by 4 January 2028; cybersecurity service providers then face an audit one year after certification. Under Article 61 of law HO-444-N the Information Systems Regulatory Commission's own implementing acts are due within one year of 26 December 2025, so by 26 December 2026, and a package on state fees is due on the same timetable. DORMANT SWITCHES — these matter more than the pending legislation. (1) The approved-country list is a decision of a single official. Adding or removing a country, including the Russian Federation or the United States, needs one signature, takes effect the day after publication, and involves no consultation. The post is currently vacant, which means the switch is held by whoever the Prime Minister next appoints. (2) The Government has not yet approved the criteria for identifying critical information infrastructure, nor the list of identified infrastructures and the state bodies responsible for supervising them, under Article 16(1)-(2) of the Law on Cybersecurity. When it does, named companies will acquire the full cybersecurity duty set overnight. Separately, Article 16(6) lets the regulator temporarily designate an individual system as critical infrastructure by notice, with a four-month window to make it permanent. (3) Article 8 of the Law on Cybersecurity, on control of information systems and critical infrastructure during emergencies, martial law or a state of emergency, has been passed but is not yet in force — it commences only when the implementing government act commences. It is a switch waiting for a lever. (4) The government may extend the 'Cloud First' backup-in-Armenia rule further; the policy expressly invites autonomous and independent state bodies to follow it voluntarily, which is how such rules usually become mandatory later.
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw HO-191-N of 7 May 2026 amending the Law on Protection of Personal Data, in force 15 August 2026
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Cybersecurity, HO-442-N, Articles 8, 16 and 25 — deferred commencement, critical infrastructure designation and transitional deadlines
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on the Information Systems Regulatory Body, HO-444-N, Article 61 — transitional provisions and one-year deadline for implementing acts
arlis.am
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
2 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
5 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules2 rules
«Անձնական տվյալների պաշտպանության մասին» Հայաստանի Հանրապետության օրենք
Act of parliament · HO-49-N of 18 May 2015, as amended most recently by HO-447-N of 4 December 2025 and HO-191-N of 7 May 2026
Armenia's general privacy law. Personal data may leave the country freely to 53 approved states; anywhere else needs written permission from the regulator, decided within 30 days. Encryption is compulsory, sensitive and biometric processing must be notified in advance, and a leak must be announced publicly.
Enforced by Personal Data Protection Agency of the Ministry of Justice — not yet operational
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent
What it makes you do
- Get consentConsent is the default basis. A legal representative consents for anyone under 16 or lacking legal capacity; all legal heirs consent for a deceased person.
- Allowed because the law requires it
- Tell people what you doArticle 10: the person must be told the processor's identity, the purpose, the data, the recipients and their rights before consent is taken.
- Let people see their data
- Let people correct their data
- Let people delete their dataDestruction within ten working days of a written or digitally signed consent withdrawal, with confirmation to the person within three further working days.
- Limit automated decisionsArticle 16: rights where a decision is taken on the basis of automated processing.
- Secure the dataArticle 19(2): use of encryption is compulsory, not optional.
- Register or notify — applies at: Compulsory before processing biometric or special-category data; voluntary otherwise; compulsory on the regulator's demandRegulator enters the details in the register of processors within 30 days; changes must be notified within ten working days.
- Report breaches to the regulatorImmediately, and simultaneously to the Police of Armenia, on any leak from electronic systems.
- Tell affected peopleBy way of an immediately published public announcement.
- Delete data after a periodDestroy or block data no longer needed for the lawful purpose; stop processing immediately once the purpose is achieved.
- Put a transfer safeguard in placeNo safeguard needed for the 53 listed countries; a regulator-approved contract and written permission for anywhere else.
- Get a parent's consent for children — applies at: under 16
- Written vendor contractArticle 14: an authorised person may process only on the processor's instruction, under law or contract.
What it costs if you get it wrong
- Fixed maximum fine: AMD 500,000 (500 times the 1,000-dram statutory calculation base) — about $1 thousandUnlawful processing, or unlawful destruction or blocking of personal data, under Article 189.17(1)-(2) of the Code of Administrative Offences
- Fixed maximum fine: AMD 100,000 — about $260Failure to use encryption while processing personal data
- Fixed maximum fine: AMD 100,000 — about $260Failure to notify the regulator, or breach of the notification procedure
- Criminal liability: Up to 3 years' imprisonmentUsing, selling or disclosing a personal or family secret without consent (Criminal Code Article 204)
- Order to stopThe regulator may demand that unlawful processing be blocked, suspended or stopped (Article 24(3)(3))
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N of 18 May 2015, consolidated official text
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaCode of Administrative Offences, Article 189.17
arlis.am
Link checked 18 August 2026
Անձնական տվյալների պաշտպանության գործակալության պետի որոշում՝ անձնական տվյալների պաշտպանության բավարար մակարդակն ապահովող պետությունների ցանկը սահմանելու մասին
Adequacy decision · Decision N ATPP-001/24 of the Head of the Personal Data Protection Agency, 8 July 2024
The list that makes the whole transfer regime work. Fifty-three countries are approved, including the whole European Union, the United Kingdom, Canada, Japan, South Korea, Israel, Georgia, Ukraine and the Russian Federation. It is a single official's decision, unchanged since July 2024 despite a legal duty to review it every year.
Enforced by Personal Data Protection Agency of the Ministry of Justice — not yet operational
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision
What it makes you do
- Put a transfer safeguard in placeNothing to do if the destination is one of the 53 listed states. The United States is listed only for 'organisations', which is not further defined.
Sources
- Official sourcePersonal Data Protection Agency, Ministry of Justice (published on ARLIS)Decision N ATPP-001/24 of 8 July 2024 and its Annex listing the 53 approved states
arlis.am
Link checked 18 August 2026
Industry rules5 rules
«Ամպայինն առաջինը» քաղաքականության մշակման և ներդրման մասին ՀՀ կառավարության որոշում
Government policy document · Government decision N 884-L of 14 June 2024, as amended by N 1445-L of 12 September 2024 · Government
Armenia's only true localisation rule. Government bodies may move data to the cloud, and may use a cloud outside Armenia, but must keep a backup copy inside the country. Only low-risk, non-secret public information may go to a cloud at all.
Transfer model: Approval each time · Accepted routes: Security review needed
What it makes you do
- Keep the data in the countryA backup copy must be kept inside Armenia, on minimum necessary server infrastructure, whenever state information systems, data or information are placed in a cloud outside Armenia.
- Hold a security certificateData put in a cloud must meet at least the information security requirements of government decision N 1521-N of 26 December 2013.
- Assess high-risk projectsThe holder must assess and classify its stock of public information before deciding to move it to a cloud.
Sources
- Official sourceGovernment of the Republic of Armenia (published on ARLIS)Government decision N 884-L of 14 June 2024 on the 'Cloud First' policy, point 1
arlis.am
Link checked 18 August 2026
«Կիբեռանվտանգության մասին» Հայաստանի Հանրապետության օրենք
Act of parliament · HO-442-N of 4 December 2025
A new law covering anyone who runs an information system in fourteen vital sectors — energy, manufacturing, transport, water, communications, post, finance, health, information technology, waste, space, database operation, emergency response and public administration. Micro and small businesses are exempt unless they run critical infrastructure. The 24-hour incident clock is live now; the heavier duties phase in to 2028.
Enforced by Information Systems Regulatory Commission
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 24 hours, from 4 January 2026Then an update within 72 hours and a final report within one month.
- Tell affected people — within 48 hours, from 4 January 2026Immediately, or within two days where immediate notice is impossible. If you do not, the regulator may tell the public itself.
- Secure the data — from 4 July 2027Internal cybersecurity regulations, risk assessment and an incident-prevention programme, due 18 months after commencement.
- Hold a security certificate — applies at: Operators of critical information infrastructure and cybersecurity service providers, from 4 January 2028A document certifying conformity with an international or national cybersecurity standard, due 24 months after commencement.
- Independent audit — applies at: Cybersecurity service providers, from 4 January 2029Cybersecurity audit one year after obtaining the conformity certificate.
What it costs if you get it wrong
- Criminal liabilityBreach of the law gives rise to administrative or criminal liability under other statutes
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Cybersecurity, HO-442-N of 4 December 2025, Articles 1, 11, 16 and 25
arlis.am
Link checked 18 August 2026
«Հանրային տեղեկությունների մասին» Հայաստանի Հանրապետության օրենք
Act of parliament · HO-443-N of 4 December 2025 · Government
Rebuilds how the Armenian state holds data. Every government database must be registered, audited and connected through a single official data exchange layer, and copying state data through any other channel is banned. Cloud contracts must let the government leave for another cloud.
Enforced by Information Systems Regulatory Commission
Transfer model: Approval each time · Accepted routes: Security review needed
What it makes you do
- Make switching cloud provider possibleArticle 21(6): cloud service contracts must not contain terms that would obstruct migrating public information or official websites to another cloud.
- Register or notifyA database must be registered in the management system of the state information system, and must first pass an information-technology audit including vulnerability assessment and penetration testing.
- Independent auditThe audit is organised and carried out by the Information Systems Regulatory Commission.
- Keep logsArticle 12(3): the state information system must be able to show at any time who was given access to, or was sent, which personal data, when, why and how.
What it costs if you get it wrong
- Fixed maximum fine: AMD 600,000 — about $2 thousandBreaching information-system security requirements where it leads to a leak of personal data
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Public Information, HO-443-N of 4 December 2025, Articles 12, 20 and 21
arlis.am
“Ամպային հաշվողական ծառայությունների մատուցման պայմանագրերում չպետք է նշվեն սահմանափակումներ, որոնք կխոչընդոտեն հանրային տեղեկությունների կամ պաշտոնական կայքէջերի միգրացիան դեպի այլ ամպային տիրույթ:”
Link checked 18 August 2026
«Բանկային գաղտնիքի մասին» Հայաստանի Հանրապետության օրենք
Act of parliament · HO-80 of 7 October 1996, as amended · Banking
Bank secrecy is carved out of the privacy law and lives in its own 1996 statute, which names exhaustively who may see it — courts, prosecutors on a court order, tax and customs authorities in defined cases, the financial intelligence unit, the credit bureau, and foreign securities regulators. Foreign cloud and outsourcing vendors are not on that list, and the fine for getting it wrong is roughly twenty times the maximum privacy fine.
Enforced by Central Bank of Armenia
Transfer model: Approval each time · Accepted routes: Legal claims
What it makes you do
- Extra vendor secrecy termsA standard data processing agreement does not make a foreign supplier a lawful recipient of bank secrecy. The statute lists who may receive it and foreign service providers are not on the list.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: AMD 2,000,000 to AMD 10,000,000 — about $26 thousandUnlawful disclosure of bank secrecy; imposed by a court, alongside full compensation of the customer's loss
- Criminal liabilityUnlawful disclosure of bank secrecy may also give rise to criminal liability
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Bank Secrecy, HO-80 of 7 October 1996, Articles 3, 10, 13, 13.1-13.3 and the penalty provision
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Article 1(2) — bank, notarial, advocate and insurance secrets are governed by other laws
arlis.am
Link checked 18 August 2026
«Բնակչության բժշկական օգնության և սպասարկման մասին» Հայաստանի Հանրապետության օրենք
Act of parliament · HO-42 of 4 March 1996, as amended; read with Criminal Code Article 205 · Health and social care
Health data is doubly protected. Medical secrecy sits outside the privacy law, needs written consent to be shared, and disclosing it is a crime that lands on a named individual. The anonymised database inside the national electronic health system belongs to the Armenian state.
Transfer model: Approval each time · Accepted routes: Explicit consent, Someone's life is at risk
What it makes you do
- Get consentMedical secrets may be passed on only with the patient's, or their legal representative's, written consent, apart from the exceptions in the statute.
- Secure the data
- Extra vendor secrecy termsThe national electronic health system runs through a single operator; the anonymised database inside it is declared the property of the Republic of Armenia and is managed under a government-set procedure.
What it costs if you get it wrong
- Criminal liability: Up to 3 years' imprisonment; higher where the offender is a health workerA data processor disclosing medical secrets without the person's written consent (Criminal Code Article 205)
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Medical Assistance and Services to the Population, HO-42, Articles 3, 10 and 11 — medical secrecy and the electronic health system
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaCriminal Code, HO-199-N, Article 205 — disclosure of medical secrets
arlis.am
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That no new head of the Personal Data Protection Agency has been appointed since 24 February 2026.
Based on the absence of a published appointment decision in the official legal acts database, where the 2015, 2018 and 2023 appointments were all published. The Ministry of Justice website, which would carry the agency's own staff page, returns 403 to automated requests, so this could not be cross-checked against the agency's own source.
That the Personal Data Protection Agency has issued no enforcement decisions.
Individual administrative fine decisions under Article 189.17 of the Code of Administrative Offences are not published in the legal acts database, and the agency's own site was unreachable. What is verified is that only one general decision by the agency head has ever been published, and that no annual report was locatable. The enforcement rating of dormant rests on that, plus the vacancy, plus a maximum fine of about 1,300 US dollars.
That the approved-country list has not been amended since 8 July 2024.
The official acts database shows Decision N ATPP-001/24 as the principal act still in force from 10 July 2024 with no amending act attached, and a search for other decisions of the agency head returned none. If a revision were published only in the official bulletin or on the agency's own website and not incorporated into the acts database, it would have been missed.
That there is no data localisation or data retention rule for telecoms, insurance, securities, education, gaming or mapping.
No such rule was found in the Law on Electronic Communications, the Law on Payment and Settlement Systems and Payment and Settlement Organisations, or the Law on Spatial Data, checked 18 August 2026. Sub-statutory rules of the Public Services Regulatory Commission and the Central Bank were not exhaustively reviewed, and those are exactly where a retention period or a processing-location condition would normally sit. Treat as 'not found', not as 'does not exist'.
Whether a new, European-style data protection law is being drafted.
Armenia ratified the modernising protocol to the Council of Europe data protection convention in November 2021, which usually precedes a rewrite, and the December 2025 package moved technical data-security powers to a new regulator. The public consultation portal e-draft.am was reachable but its search interface could not be queried, and the web search budget for this run was exhausted before any bill could be checked. No pending bill is asserted either way.
The exact scope of the 'organisations' qualifier next to the United States on the approved-country list.
The decision lists 'United States of America (organisations)' with no definition, no cross-reference and no accompanying guidance. Whether this means certified participants in a specific framework, or something else, could not be established from the decision text and no guidance from the agency was locatable.
That the Law on Protection of Personal Data does not apply to foreign companies with no presence in Armenia.
This is an inference from the absence of any extraterritoriality clause in the consolidated text, not from a positive statement in the law or from a regulator's or court's ruling. No case law or regulator guidance on the point was found.
Whether the Information Systems Regulatory Commission has begun issuing decisions.
Four members were appointed in March and April 2026 and the founding law treats it as formed, but no decisions, no website and no register of its acts could be located on 18 August 2026. Its implementing rules are not due until 26 December 2026, so silence at this point is expected rather than surprising.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Armenia versus Argentina
- Armenia versus Australia
- Armenia versus Austria
- Armenia versus Azerbaijan
- Armenia versus Brazil
- Armenia versus Bulgaria
- Armenia versus Cambodia
- Armenia versus Canada
- Armenia versus China
- Armenia versus Croatia
- Armenia versus Cyprus
- Armenia versus Estonia
- Armenia versus France
- Armenia versus Georgia
- Armenia versus Germany
- Armenia versus Greece
- Armenia versus Hong Kong SAR
- Armenia versus Hungary
- Armenia versus Iceland
- Armenia versus India
- Armenia versus Indonesia
- Armenia versus Ireland
- Armenia versus Israel
- Armenia versus Italy
- Armenia versus Japan
- Armenia versus Latvia
- Armenia versus Lithuania
- Armenia versus Luxembourg
- Armenia versus Malta
- Armenia versus Mexico
- Armenia versus Mongolia
- Armenia versus Nepal
- Armenia versus Netherlands
- Armenia versus Poland
- Armenia versus Russia
- Armenia versus Saudi Arabia
- Armenia versus Serbia
- Armenia versus Singapore
- Armenia versus Slovakia
- Armenia versus Slovenia
- Armenia versus South Korea
- Armenia versus Spain
- Armenia versus Sri Lanka
- Armenia versus Sweden
- Armenia versus Switzerland
- Armenia versus Taiwan
- Armenia versus Thailand
- Armenia versus Turkey
- Armenia versus Ukraine
- Armenia versus United Arab Emirates
- Armenia versus United Kingdom
- Armenia versus United States
- Armenia versus Uzbekistan