Armenia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Armenia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send personal data out of Armenia. But it must go to one of 53 countries on an official approved list. For anywhere else you need permission from the privacy regulator, case by case. That regulator has had no head since February 2026. The largest fine it can impose is about 1,300 US dollars. The real limits sit elsewhere. Government data put in a foreign cloud must keep a backup copy inside Armenia. Banking and medical secrecy sit outside the privacy law completely.
Data governance in Armenia
The eight things that decide how you handle data about people in Armenia. Same eight on every country page, so you can compare.
Who has to follow these rules
Probably not, if you have nothing in Armenia. The privacy law describes who it covers by naming Armenian public bodies, companies and individuals who use personal data. It has no clause saying it follows Armenians' data abroad. It has no rule making a foreign company appoint someone inside Armenia. There is no size or revenue cut-off either. A one-person Armenian business is caught exactly like a bank.
Article 1(1) of the Law on Protection of Personal Data (HO-49-N) says what the law is about. It covers the use of personal data by state or local government bodies, by state or community bodies, and by companies and individuals. It also covers state supervision of that work. There is nothing like Article 3 of the European General Data Protection Regulation. We read the whole consolidated law on 18 August 2026. It has no rule applying it to companies outside Armenia. It has no rule making you appoint a local representative. Article 1(2) leaves out state, banking, notary, lawyer and insurance secrets. It also leaves out national security and defence work, anti-money-laundering work, covert investigation and court proceedings. Those are governed by their own laws. Article 1(4) confirms that other laws may set their own rules on using data and on supervision. Where another law names a supervisory body, the privacy regulator uses its powers in the way the privacy law sets out.
Sources
- Official sourceARLIS — Legal Information System of the Republic of Armenia (Ministry of Justice)Law of the Republic of Armenia on Protection of Personal Data, HO-49-N of 18 May 2015, consolidated text, Article 1
arlis.am
“Սույն օրենքը կարգավորում է պետական կառավարման կամ տեղական ինքնակառավարման մարմինների, պետական կամ համայնքային հիմնարկների կամ կազմակերպությունների, իրավաբանական կամ ֆիզիկական անձանց կողմից անձնական տվյալները մշակելու, դրանց նկատմամբ պետական հսկողություն իրականացնելու կարգն ու պայմանները:”
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork. Armenia runs an approved-country list. If your destination is on it, you can send data with no permission from anyone. The list is real and full. It has 53 countries, including all of the European Union, the United Kingdom, Canada, Japan, South Korea, Israel, Georgia and Russia. Sending data anywhere else needs written permission from the privacy regulator first. That regulator currently has nobody in charge. Three industries override all of this: government, banking-type secrets, and health.
Article 27 of HO-49-N sets the structure. Article 27(1): to send data abroad you need either the person's consent or a clear link to the purpose you are using the data for. Article 27(2): you need no permission from the regulator if the destination gives enough protection. That test is met if the transfer runs under an international treaty, or if the destination is on the list the regulator publishes. Article 27(3) and 27(4): for any other country, you must apply in writing before you send anything. You must describe the destination, the recipient, the data, the purpose and the contract or draft contract. The regulator has 30 days to allow or refuse. It must say what contract changes would make the guarantees good enough. Article 27(6): personal data held by state bodies may go to foreign state bodies only under ratified international treaties. INDUSTRY OVERRIDES. (1) Government. Government decision N 884-L of 14 June 2024, called 'Cloud First', covers state bodies. If they put state information systems, data or information in a cloud outside Armenia, they must keep a backup copy in Armenia. That backup must sit on the minimum server capacity needed. Only public information rated 'low' risk, and not a state secret, may go into a cloud at all. (2) Banking, notary, lawyer and insurance secrecy. These are conditional, but by a different route. Article 1(2) of the privacy law removes them from its reach, so the approved-country list gives no cover. The Law on Bank Secrecy of 7 October 1996 lists exactly who may receive bank secrets, and foreign service providers are not on that list. (3) Health. Conditional. The anonymised database inside the national electronic health system is declared the property of the Republic of Armenia. It is managed under a procedure the government sets. Sharing medical secrets without written consent is a crime. (4) Vital-sector operators. These cover energy, transport, water, communications, post, financial services, health, information technology, space, database operation, public administration and others. There is no rule on where their data sits, but the new cybersecurity regulator supervises them. Telecoms: operators must keep customer data confidential. They must also give law-enforcement and national-security staff access to communications equipment, including interception devices. That keeps interception equipment inside the country. We found no express rule requiring telecom, insurance, securities, education, gaming or mapping data to stay in Armenia. Checked 18 August 2026, medium confidence.
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Article 27 (transfer of personal data to other states)
arlis.am
“Առանց լիազոր մարմնի թույլտվության անձնական տվյալները կարող են փոխանցվել այլ պետություն, եթե այդ պետությունում ապահովված է անձնական տվյալների պաշտպանության բավարար մակարդակ:”
Link checked 18 August 2026
- Official sourcePersonal Data Protection Agency, Ministry of Justice (published on ARLIS)Decision of the Head of the Personal Data Protection Agency N ATPP-001/24 of 8 July 2024 establishing the list of states ensuring an adequate level of personal data protection
arlis.am
Link checked 18 August 2026
- Official sourceGovernment of the Republic of Armenia (published on ARLIS)Government decision N 884-L of 14 June 2024 on the development and introduction of the 'Cloud First' policy, point 1(3)
arlis.am
“պետական կառավարման համակարգի մարմիններն իրենց տնօրինության տակ գտնվող պետական տեղեկատվական համակարգերը, տվյալները և տեղեկատվությունը Հայաստանի Հանրապետությունից դուրս գտնվող ամպային տիրույթում տեղադրելիս Հայաստանի Հանրապետությունում պահպանում են դրանց պահուստային տարբերակը՝ նվազագույն անհրաժեշտ սերվերային ենթակառուցվածքների ներգրավմամբ.”
Link checked 18 August 2026
What to do: Plan for a database inside Armenia: this data is not allowed to leave.
Sending data out of the country
You can only send data to countries on an approved list, and the list is full. Fifty-three countries were approved on 8 July 2024, and that decision has never changed. If your destination is on the list you need nothing. No standard contract, no filing, no fee. If it is not on the list, you must write to the regulator before you send anything. You attach the contract you plan to sign, and wait up to 30 days for a yes or a no.
- Ways to send data out:
- Official 'this country is safe' decision · Government sign-off needed · Explicit consent
The approved list is Decision N ATPP-001/24, in force 10 July 2024. It covers: Albania, the United States (organisations only), Andorra, Austria, Argentina, Belgium, Bosnia and Herzegovina, Bulgaria, Germany, Denmark, Estonia, Iceland, Ireland, Italy, Spain, Israel, Latvia, Liechtenstein, Lithuania, Luxembourg, Poland, Croatia, Canada, Republic of Korea, Cyprus, North Macedonia, Greece, Hungary, Japan, Malta, the United Kingdom, Moldova, Monaco, Montenegro, the Netherlands, New Zealand, Norway, Sweden, Switzerland, Czechia, Portugal, Romania, the Russian Federation, San Marino, Serbia, Singapore, Slovakia, Slovenia, Georgia, Ukraine, Uruguay, Finland and France. Countries missing from the list need permission case by case. They include India, China, Australia, Brazil, Mexico, Turkey, the United Arab Emirates, Kazakhstan and Azerbaijan. The United States entry carries the word 'organisations'. That reads as approval for certified companies rather than for the whole country. The decision does not define the word any further. Two points about how this works. First, this is one official's decision, not a law or a government decree. The head of the agency can add or remove a country, including Russia, with one signature and no consultation. Second, Article 27(5) makes the regulator review the list at least once a year and publish changes. No revision has appeared since July 2024, more than two years ago. So the yearly review duty looks unmet.
Sources
- Official sourcePersonal Data Protection Agency, Ministry of Justice (published on ARLIS)Decision N ATPP-001/24 of 8 July 2024, Annex — list of 53 states ensuring an adequate level of protection
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Article 27(3)-(5) — permission procedure and annual review of the list
arlis.am
“Լիազոր մարմինը 30 օրվա ընթացքում պարտավոր է թույլատրել կամ մերժել հայտը:”
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
On paper, the Personal Data Protection Agency inside the Ministry of Justice. Right now, nobody. Its head resigned with effect from 24 February 2026, and no replacement has been announced. In more than eleven years the agency has published exactly one general decision. That is the approved-country list. Two other regulators are working. The Central Bank supervises banks, payment firms, insurers and securities. A brand-new Information Systems Regulatory Commission was appointed in March and April 2026. It covers cybersecurity and state computer systems.
Article 24 of HO-49-N gives the agency real powers. It can inspect on its own initiative, impose administrative penalties, and order you to block, suspend or stop using data. It can order you to correct or destroy data. It keeps a register, applies to court, and publishes a yearly report. Article 25 sets an unusual appointment route. The Prime Minister appoints the head for five years, on the nomination of the Minister of Justice. The candidate comes from a list proposed jointly by at least five human-rights non-governmental organisations. Nobody may serve two terms in a row. What we can see about how it operates. Prime Minister's decision N 120-A of 13 February 2026 released Grigor Nersisyan as Head of the Agency from 24 February 2026. He asked to go in writing. We searched the official legal database on 18 August 2026 and found no later appointment decision. The 2015, 2018 and 2023 appointments were all published there. Fine decisions under Article 189.17 of the Code of Administrative Offences are not published in the legal database. So we cannot rule out a small amount of enforcement work. We found no published enforcement decision and no yearly report. We could not reach the agency's own website, because the Ministry of Justice site blocks automated access. So this rating rests on the official acts database alone. The Information Systems Regulatory Commission is different. It was created by law HO-444-N of 4 December 2025 and was actually set up. The National Assembly appointed Nerses Yeritsyan as chairman on 26 March 2026. It appointed Nairi Adamyan and Srbuhi Hakobyan on the same day, and David Khachatryan on 16 April 2026. The law treats the Commission as formed once four members are appointed, so it now exists. The 2026 state budget was changed to fund it.
Sources
- Official sourcePrime Minister of the Republic of Armenia (published on ARLIS)Prime Minister's decision N 120-A of 13 February 2026 releasing Grigor Nersisyan from the post of Head of the Personal Data Protection Agency of the Ministry of Justice
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Articles 24 and 25 — powers and appointment of the head of the authority
arlis.am
Link checked 18 August 2026
- Official sourceNational Assembly of the Republic of Armenia (published on ARLIS)National Assembly decision AZHO-117-A of 26 March 2026 appointing Nerses Yeritsyan chairman of the Information Systems Regulatory Commission
arlis.am
Link checked 18 August 2026
How long you must keep it — and when to delete it
You must keep anything that proves your tax position for at least five years. There is no maximum number of years. Instead there is a rule. You must destroy or block personal data as soon as you no longer need it for the purpose you collected it for. Two firm deadlines sit inside that rule. If someone withdraws consent, you have ten working days to destroy their data. You then have three more working days to tell them you did it. If you spot data being used unlawfully, you have three working days to fix it or destroy the data.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Allowed because the law requires it
MINIMUM KEEP-TIMES. Article 56 of the Tax Code makes taxpayers keep documents that back up the tax base, income, expenses and taxes paid or withheld. The period is not less than five years from the reporting period they relate to. Financial firms reporting under the international common reporting standard have the same five-year minimum. It covers account documents and the contents of computer systems and electronic media. MAXIMUM KEEP-TIMES. Article 5(5) of HO-49-N says personal data must be stored so that the person cannot be identified for longer than the stated purpose needs. Article 19(1) makes you destroy or block data you do not need for the lawful purpose. Article 21(5) makes you stop using data immediately once the purpose is met, unless another law says otherwise. Article 21(6) sets the ten-working-day deadline to destroy data after a written or digitally signed consent withdrawal. It then gives you three working days to confirm the destruction to the person. Article 21(3) sets the three-working-day deadline to put unlawful use right. If you do not, the data must be destroyed at once. CLASHES. The law does not settle minimum against maximum with a general rule. It settles it by exception. Article 21(5) and Article 21(6) both give way where another law says otherwise. So a legal duty to keep data, such as the five-year tax rule, beats the duty to delete. Article 8 also makes using data lawful where a legal duty requires it.
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Articles 5, 19 and 21 — storage limitation, destruction and blocking
arlis.am
“մշակողը պարտավոր է դադարեցնել անձնական տվյալներ մշակելը և ոչնչացնել տվյալները հետկանչն ստանալու օրվան հաջորդող տասն աշխատանքային օրվա ընթացքում”
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaTax Code of the Republic of Armenia, HO-165-N — five-year duty to keep documents substantiating the tax base
arlis.am
“ապահովել հարկման բազայի հաշվարկման և հարկային հաշվարկների ներկայացման համար անհրաժեշտ փաստաթղթերի ... պահպանումը ոչ պակաս, քան հինգ տարի ժամկետում”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count three deadlines. Under the privacy law, if data leaks out of your electronic systems, you must publish a public announcement about it immediately. At the same time you must tell the Armenian police and the privacy regulator. There is no grace period and no threshold. If you run a system in an industry the state calls vital, you have 24 hours to tell the cybersecurity regulator. You then have 72 hours to send an update, two days to warn the people affected, and one month to file a final report. Both sets of duties can apply at the same time.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Article 21(4) of HO-49-N is unusual and easy to miss. If personal data leaks from electronic systems, you must publish a statement immediately. At the same time you must report the leak to the Police of the Republic of Armenia and to the privacy regulator. Look at what it does not say. There is no severity threshold, no risk test, and no option to tell the regulator quietly first. Telling the public is the main duty. Article 11 of the Law on Cybersecurity HO-442-N, in force 4 January 2026, runs the second set of deadlines. It applies to service providers in the fourteen vital industries. You must tell the Autonomous Body immediately, and no later than 24 hours after you learn of the incident. That applies to any incident with a real effect on continuous, uninterrupted or secure operation. It also applies where you cannot yet judge the effect but can reasonably assume there is one. You must send updated information within 72 hours. You must tell the people who may be affected immediately, or within two days if that is not possible. If you do not, the regulator may tell those people or the public itself. You must file a final report within one month of the 72-hour update. It must cover causes, fixes, severity, scale, time spent, money spent and steps to prevent a repeat.
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Article 21(4) — leak from electronic systems
arlis.am
“Էլեկտրոնային համակարգերից անձնական տվյալների արտահոսքի դեպքում մշակողը պարտավոր է այդ մասին անհապաղ հրապարակել հայտարարություն՝ միաժամանակ արտահոսքի վերաբերյալ հայտնելով Հայաստանի Հանրապետության ոստիկանությանը և անձնական տվյալների պաշտպանության լիազոր մարմնին:”
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw of the Republic of Armenia on Cybersecurity, HO-442-N of 4 December 2025, Article 11 — cyber incident notification
arlis.am
“պարտավոր է կիբեռմիջադեպի մասին իրեն հայտնի դառնալուց հետո անհապաղ, բայց ոչ ուշ, քան 24 ժամվա ընթացքում, Ինքնավար մարմնին ծանուցել”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. One: a data leak must be announced publicly and reported to the police, not just to the regulator. Two: encryption is required by law, not a best practice. Not using it is a separate fine on its own. Three: before you use biometric or sensitive data, you must tell the regulator first and wait to be entered in its register. Four: to use a dead person's data you need the consent of all their legal heirs. Five: a child here is anyone under 16, not 13 and not 18.
- What you have to do here:
- Secure the data · Register or notify · Get a parent's consent for children · Tell affected people
- What it costs if you get it wrong:
- Criminal liability
1. PUBLIC ANNOUNCEMENT OF LEAKS. Article 21(4) makes you publish the announcement. You report to the police and the regulator at the same time. Most breach plans assume you tell the regulator first and the public later. Armenia reverses that. 2. ENCRYPTION IS COMPULSORY. Article 19(2) makes everyone use encryption to protect information systems holding personal data. Article 189.17(5) of the Code of Administrative Offences makes not using encryption an offence on its own. The fine is 100 times the statutory calculation base, about 100,000 drams (roughly 260 US dollars). 3. TELL THE REGULATOR FIRST FOR SENSITIVE AND BIOMETRIC DATA. Article 23(3) makes you notify the regulator before you use biometric or special-category data. Article 23(5) gives the regulator 30 days to enter the details in its register. Article 23(8) makes you send updates within ten working days of any change. This is a registration duty in all but name. Today it is owed to an authority with no head. 4. DEAD PEOPLE. Article 9(10) makes you get the consent of all legal heirs to use the personal data of someone who has died. The same applies to someone declared dead. Where there are no heirs, consent comes from the head of the community where the succession opened. There is no time limit on this. 5. CHILDREN AT 16. Article 9(9) makes you get the legal representative's consent for anyone under 16. The same applies to people who lack legal capacity or whose capacity is limited. Armenia has no separate, lower age for digital consent. 6. INDIVIDUALS CAN GO TO PRISON. Article 204 of the Criminal Code covers using, selling or disclosing someone's personal or family secret without consent. The penalty is up to one year in prison. It rises to three years where the secret is spread through the media or online. Article 205 covers disclosing medical secrets without written consent. The penalty is up to two years, rising to three years where it is published, and higher again where a health worker did it. 7. THE PRIVACY FINES ARE TINY, THE SECRECY FINES ARE NOT. The largest administrative fine for a data protection breach is 500 times the calculation base. That is about 500,000 drams (roughly 1,300 US dollars). Article 189.17(8) also lets you escape liability altogether if you fix the breach by the deadline the regulator sets. Unlawful disclosure of bank secrecy is different. A court can fine you 2,000 to 10,000 times the base, roughly 5,200 to 26,000 US dollars. You may also face criminal charges and have to cover the customer's full loss.
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Articles 9(9)-(10), 19(2) and 23(3)
arlis.am
“Մշակողը մինչև կենսաչափական կամ հատուկ կատեգորիայի անձնական տվյալներ մշակելը պարտավոր է անձնական տվյալների պաշտպանության լիազոր մարմնին ծանուցել տվյալներ մշակելու մտադրության մասին:”
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaCode of Administrative Offences of the Republic of Armenia, Article 189.17 — penalties for breaches of the personal data legislation
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaCriminal Code of the Republic of Armenia, HO-199-N, Articles 204 and 205 — violation of private life and disclosure of medical secrets
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on the Minimum Monthly Wage, HO-66-N, Article 3 — the calculation base for fines in codes and laws is 1,000 drams
arlis.am
“Նշված ակտերում որպես հաշվարկային հիմք սահմանվում է 1000 դրամը:”
Link checked 18 August 2026
What's changing next
Armenia rewrote its digital rulebook in December 2025. The deadlines land through 2026, 2027 and 2028. Rules for cyber incidents and for state computer systems are already live. Detailed technical rules are due by January 2027. Internal cybersecurity policies and risk assessments are due by July 2027. Security certificates for critical systems are due by January 2028. The change most likely to catch you out is not a new law. One official can rewrite the approved-country list with a signature.
ALREADY HAPPENED. Law HO-191-N was adopted on 7 May 2026 and came into force on 15 August 2026. That was three days before this record was written. It deletes the rule that the head of the privacy regulator must leave at 65. So there is no longer an age limit for the job. DATED AND COMING. Article 25 of the Law on Cybersecurity covers the detailed rules and the national cybersecurity standard. They are due within twelve months of 4 January 2026, so by 4 January 2027. Service providers must adopt internal cybersecurity rules within eighteen months, so by 4 July 2027. They must also complete risk assessments and incident-prevention programmes by that date. Operators of critical information infrastructure and cybersecurity service providers must produce a certificate within twenty-four months. It must show they meet an international or national cybersecurity standard, so it is due by 4 January 2028. Cybersecurity service providers then face an audit one year after certification. Article 61 of law HO-444-N covers the Information Systems Regulatory Commission's own rules. They are due within one year of 26 December 2025, so by 26 December 2026. A package on state fees is due on the same timetable. POWERS ALREADY HELD. These matter more than the pending laws. (1) The approved-country list is one official's decision. Adding or removing a country, including the Russian Federation or the United States, takes one signature. It takes effect the day after publication, with no consultation. The post is vacant, so the power sits with whoever the Prime Minister appoints next. (2) The Government has not yet approved the criteria for identifying critical information infrastructure. It has not approved the list of identified infrastructures either, nor the state bodies that supervise them. That is Article 16(1) and 16(2) of the Law on Cybersecurity. When it does, named companies pick up the full set of cybersecurity duties overnight. Article 16(6) also lets the regulator name a single system as critical infrastructure by notice, temporarily. It then has four months to make that permanent. (3) Article 8 of the Law on Cybersecurity covers control of information systems and critical infrastructure in emergencies, martial law or a state of emergency. It has been passed but is not yet in force. It starts only when the government act that implements it starts. (4) The government may extend the 'Cloud First' backup-in-Armenia rule further. The policy already invites autonomous and independent state bodies to follow it voluntarily. That is usually how such rules become compulsory later.
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw HO-191-N of 7 May 2026 amending the Law on Protection of Personal Data, in force 15 August 2026
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Cybersecurity, HO-442-N, Articles 8, 16 and 25 — deferred commencement, critical infrastructure designation and transitional deadlines
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on the Information Systems Regulatory Body, HO-444-N, Article 61 — transitional provisions and one-year deadline for implementing acts
arlis.am
Link checked 18 August 2026
What to do: Diarise 4 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data needs a copy kept in the country
Official name: «Ամպայինն առաջինը» քաղաքականության մշակման և ներդրման մասին ՀՀ կառավարության որոշում · Government decision N 884-L of 14 June 2024, as amended by N 1445-L of 12 September 2024 · Government policy document
This is Armenia's only true rule about where data must sit. Government bodies may move data to the cloud, and may use a cloud outside Armenia. But they must keep a backup copy inside the country. Only low-risk public information that is not secret may go into a cloud at all.
How this country controls where data goes: Approval each time · Accepted routes: Security review needed
What you have to do
- Keep the data in the countryYou must keep a backup copy inside Armenia whenever state information systems, data or information go into a cloud outside Armenia. It must sit on the minimum server capacity needed.
- Hold a security certificateData put in a cloud must meet at least the information security requirements of government decision N 1521-N of 26 December 2013.
- Assess high-risk projectsBefore deciding to move public information to a cloud, the holder must assess and classify all of it.
Sources
- Official sourceGovernment of the Republic of Armenia (published on ARLIS)Government decision N 884-L of 14 June 2024 on the 'Cloud First' policy, point 1
arlis.am
Link checked 18 August 2026
Health data rules
Official name: «Կիբեռանվտանգության մասին» Հայաստանի Հանրապետության օրենք · HO-442-N of 4 December 2025 · Act of parliament
A new law covering anyone who runs an information system in fourteen vital industries. They are energy, manufacturing, transport, water, communications, post, finance, health, information technology, waste, space, database operation, emergency response and public administration. Micro and small businesses are exempt unless they run critical infrastructure. The 24-hour incident deadline is live now. The heavier duties phase in up to 2028.
Enforced by Information Systems Regulatory Commission
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 24 hours, from 4 January 2026Then an update within 72 hours and a final report within one month.
- Tell affected people — within 48 hours, from 4 January 2026Tell them immediately, or within two days if that is impossible. If you do not, the regulator may tell the public itself.
- Secure the data — from 4 July 2027Internal cybersecurity rules, a risk assessment and an incident-prevention programme. Due 18 months after the law starts.
- Hold a security certificate — applies at: Operators of critical information infrastructure and cybersecurity service providers, from 4 January 2028A certificate showing you meet an international or national cybersecurity standard. Due 24 months after the law starts.
- Independent audit — applies at: Cybersecurity service providers, from 4 January 2029A cybersecurity audit one year after you get the certificate.
What it costs if you get it wrong
- Criminal liabilityBreach of the law gives rise to administrative or criminal liability under other statutes
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Cybersecurity, HO-442-N of 4 December 2025, Articles 1, 11, 16 and 25
arlis.am
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: «Հանրային տեղեկությունների մասին» Հայաստանի Հանրապետության օրենք · HO-443-N of 4 December 2025 · Act of parliament
This law rebuilds how the Armenian state holds data. Every government database must be registered, audited and connected through one official data exchange layer. Copying state data through any other channel is banned. Cloud contracts must let the government move to another cloud.
Enforced by Information Systems Regulatory Commission
How this country controls where data goes: Approval each time · Accepted routes: Security review needed
What you have to do
- Make switching cloud provider possibleArticle 21(6): a cloud service contract must not contain terms that would block moving public information or official websites to another cloud.
- Register or notifyA database must be registered in the management system of the state information system. First it must pass an information-technology audit, including a vulnerability assessment and penetration testing.
- Independent auditThe Information Systems Regulatory Commission organises and carries out the audit.
- Keep logsArticle 12(3): the state information system must be able to show who was given which personal data, or was sent it. It must be able to show this at any time, along with when, why and how.
What it costs if you get it wrong
- Fixed maximum fine: AMD 600,000 — about $2 thousandBreaching information-system security requirements where it leads to a leak of personal data
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Public Information, HO-443-N of 4 December 2025, Articles 12, 20 and 21
arlis.am
“Ամպային հաշվողական ծառայությունների մատուցման պայմանագրերում չպետք է նշվեն սահմանափակումներ, որոնք կխոչընդոտեն հանրային տեղեկությունների կամ պաշտոնական կայքէջերի միգրացիան դեպի այլ ամպային տիրույթ:”
Link checked 18 August 2026
Cloud and outsourcing rules (Banking)
Official name: «Բանկային գաղտնիքի մասին» Հայաստանի Հանրապետության օրենք · HO-80 of 7 October 1996, as amended · Act of parliament
Bank secrecy is left out of the privacy law and sits in its own 1996 law. That law names exactly who may see it. The list is courts, prosecutors with a court order, and tax and customs authorities in set cases. It also covers the financial intelligence unit, the credit bureau, and foreign securities regulators. Foreign cloud and outsourcing suppliers are not on that list. The fine for getting it wrong is roughly twenty times the largest privacy fine.
Enforced by Central Bank of Armenia
How this country controls where data goes: Approval each time · Accepted routes: Legal claims
What you have to do
- Extra vendor secrecy termsA standard data protection contract does not make a foreign supplier a lawful recipient of bank secrets. The law lists who may receive them, and foreign service providers are not on the list.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: AMD 2,000,000 to AMD 10,000,000 — about $26 thousandUnlawful disclosure of bank secrecy; imposed by a court, alongside full compensation of the customer's loss
- Criminal liabilityUnlawful disclosure of bank secrecy may also give rise to criminal liability
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Bank Secrecy, HO-80 of 7 October 1996, Articles 3, 10, 13, 13.1-13.3 and the penalty provision
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N, Article 1(2) — bank, notarial, advocate and insurance secrets are governed by other laws
arlis.am
Link checked 18 August 2026
Health data rules (Health and social care)
Official name: «Բնակչության բժշկական օգնության և սպասարկման մասին» Հայաստանի Հանրապետության օրենք · HO-42 of 4 March 1996, as amended; read with Criminal Code Article 205 · Act of parliament
Health data has two layers of protection. Medical secrecy sits outside the privacy law. You need written consent to share it. Disclosing it is a crime, and the charge lands on a named person. The anonymised database inside the national electronic health system belongs to the Armenian state.
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent, To save someone’s life
What you have to do
- Get consentYou may pass on medical secrets only with the patient's written consent, or their legal representative's. The only exceptions are those listed in the law.
- Secure the data
- Extra vendor secrecy termsThe national electronic health system runs through a single operator. The anonymised database inside it is declared the property of the Republic of Armenia. It is managed under a procedure the government sets.
What it costs if you get it wrong
- Criminal liability: Up to 3 years' imprisonment; higher where the offender is a health workerA data processor disclosing medical secrets without the person's written consent (Criminal Code Article 205)
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Medical Assistance and Services to the Population, HO-42, Articles 3, 10 and 11 — medical secrecy and the electronic health system
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaCriminal Code, HO-199-N, Article 205 — disclosure of medical secrets
arlis.am
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Biometric data rules
Official name: «Անձնական տվյալների պաշտպանության մասին» Հայաստանի Հանրապետության օրենք · HO-49-N of 18 May 2015, as amended most recently by HO-447-N of 4 December 2025 and HO-191-N of 7 May 2026 · Act of parliament
Armenia's general privacy law. Personal data may go freely to 53 approved countries. Anywhere else needs written permission from the regulator, decided within 30 days. Encryption is compulsory. You must tell the regulator before you use sensitive or biometric data. A leak must be announced publicly.
Enforced by Personal Data Protection Agency of the Ministry of Justice — not yet operational
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent
What you have to do
- Get consentConsent is the normal basis. A legal representative consents for anyone under 16 or lacking legal capacity. All legal heirs consent for someone who has died.
- Allowed because the law requires it
- Tell people what you doArticle 10: tell the person these things before you take consent. Who you are, why you want the data, and what data you want. Who will receive it, and what rights they have.
- Let people see their data
- Let people correct their data
- Let people delete their dataDestroy the data within ten working days of a written or digitally signed consent withdrawal. Confirm to the person within three more working days.
- Limit automated decisionsArticle 16: rights where a decision is made by computer with no human involved.
- Secure the dataArticle 19(2): you must use encryption. It is not optional.
- Register or notify — applies at: Compulsory before processing biometric or special-category data; voluntary otherwise; compulsory on the regulator's demandThe regulator enters your details in its register within 30 days. You must report any change within ten working days.
- Report breaches to the regulatorReport immediately, and at the same time to the Police of Armenia, on any leak from electronic systems.
- Tell affected peopleYou tell people by publishing a public announcement immediately.
- Delete data after a periodDestroy or block data you no longer need for the lawful purpose. Stop using it immediately once the purpose is met.
- Put a transfer safeguard in placeYou need nothing extra for the 53 listed countries. For anywhere else you need a contract the regulator approves, plus written permission.
- Get a parent's consent for children — applies at: under 16
- Written vendor contractArticle 14: someone you authorise may use the data only on your instruction, or under a law or contract.
What it costs if you get it wrong
- Fixed maximum fine: AMD 500,000 (500 times the 1,000-dram statutory calculation base) — about $1 thousandUnlawful processing, or unlawful destruction or blocking of personal data, under Article 189.17(1)-(2) of the Code of Administrative Offences
- Fixed maximum fine: AMD 100,000 — about $260Failure to use encryption while processing personal data
- Fixed maximum fine: AMD 100,000 — about $260Failure to notify the regulator, or breach of the notification procedure
- Criminal liability: Up to 3 years' imprisonmentUsing, selling or disclosing a personal or family secret without consent (Criminal Code Article 204)
- Order to stopThe regulator may demand that unlawful processing be blocked, suspended or stopped (Article 24(3)(3))
Sources
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaLaw on Protection of Personal Data, HO-49-N of 18 May 2015, consolidated official text
arlis.am
Link checked 18 August 2026
- Official sourceARLIS — Legal Information System of the Republic of ArmeniaCode of Administrative Offences, Article 189.17
arlis.am
Link checked 18 August 2026
Paperwork before personal data leaves
Official name: Անձնական տվյալների պաշտպանության գործակալության պետի որոշում՝ անձնական տվյալների պաշտպանության բավարար մակարդակն ապահովող պետությունների ցանկը սահմանելու մասին · Decision N ATPP-001/24 of the Head of the Personal Data Protection Agency, 8 July 2024 · Official “this country is safe” decision
This list is what makes sending data abroad work. Fifty-three countries are approved. They include the whole European Union, the United Kingdom, Canada, Japan, South Korea, Israel, Georgia, Ukraine and the Russian Federation. It is one official's decision. It has not changed since July 2024, despite a legal duty to review it every year.
Enforced by Personal Data Protection Agency of the Ministry of Justice — not yet operational
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision
What you have to do
- Put a transfer safeguard in placeNothing to do if the destination is one of the 53 listed countries. The United States is listed only for 'organisations', which is not defined anywhere.
Sources
- Official sourcePersonal Data Protection Agency, Ministry of Justice (published on ARLIS)Decision N ATPP-001/24 of 8 July 2024 and its Annex listing the 53 approved states
arlis.am
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That no new head of the Personal Data Protection Agency has been appointed since 24 February 2026.
We found no published appointment decision in the official legal acts database. The 2015, 2018 and 2023 appointments were all published there. The Ministry of Justice website, which carries the agency's staff page, refuses automated requests. So we could not check this against the agency's own source. Confirm with the ministry before you rely on it.
That the Personal Data Protection Agency has issued no enforcement decisions.
Individual fine decisions under Article 189.17 of the Code of Administrative Offences are not published in the legal acts database. We also could not reach the agency's own site. What we can show is that only one general decision by the agency head has ever been published, and that we found no yearly report. Our low enforcement rating rests on that, plus the vacant post, plus a largest fine of about 1,300 US dollars.
That the approved-country list has not been amended since 8 July 2024.
The official acts database shows Decision N ATPP-001/24 still in force from 10 July 2024, with no amending act attached. A search for other decisions by the agency head returned none. If a revision appeared only in the official bulletin or on the agency's own website, we would have missed it. Check the list itself before you send data.
That there is no rule forcing data to stay in the country or data retention rule for telecoms, insurance, securities, education, gaming or mapping.
We checked three laws on 18 August 2026 and found no such rule. They were the Law on Electronic Communications, the Law on Payment and Settlement Systems and Payment and Settlement Organisations, and the Law on Spatial Data. We did not review every detailed rule of the Public Services Regulatory Commission or the Central Bank. Those are exactly where a keep-time or a storage-location condition normally sits. If you work in these industries, check with your regulator before you rely on this.
Whether a new, European-style data protection law is being drafted.
Armenia ratified the updating protocol to the Council of Europe data protection convention in November 2021, which usually comes before a rewrite. The December 2025 package also moved technical data-security powers to a new regulator. We could not search the public consultation portal e-draft.am, so we could not check for a bill. We do not say a bill is pending, and we do not say one is not.
The exact scope of the 'organisations' qualifier next to the United States on the approved-country list.
The decision lists 'United States of America (organisations)' with no definition, no cross-reference and no guidance. We could not establish whether this means companies certified under a specific scheme, or something else. We found no guidance from the agency. Ask the agency before you send data to a United States recipient.
That the Law on Protection of Personal Data does not apply to foreign companies with no presence in Armenia.
This is our reading, based on the law having no clause that applies it to companies outside Armenia. It is not based on a positive statement in the law, or on a ruling by a court or the regulator. We found no case law or regulator guidance on the point. Take advice if you have no presence in Armenia.
Whether the Information Systems Regulatory Commission has begun issuing decisions.
Four members were appointed in March and April 2026, and the founding law treats the Commission as formed. We found no decisions, no website and no register of its acts on 18 August 2026. Its own rules are not due until 26 December 2026, so silence at this point is expected.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.