Skip to the content
Global Data RulesData governance rules, country by country

Armenia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: MediumEnforcement: Dormant

Armenia lets personal data leave, but only to a country on an official approved list of 53 states, or with case-by-case permission from the privacy regulator. That regulator has had no boss since February 2026 and the largest fine it can impose is about 1,300 US dollars. The real constraints are elsewhere: government data sent to a foreign cloud must keep a backup copy inside Armenia, and banking and medical secrecy sit outside the privacy law entirely.

Eight questions about Armenia

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Armenia's rules apply to my company?

Probably not, if you have nothing in Armenia. The privacy law describes who it covers by naming Armenian public bodies, companies and individuals who process personal data. It contains no clause saying it follows Armenians' data abroad, and no rule requiring a foreign company to appoint someone inside Armenia. There is no size or revenue threshold either, so a one-person Armenian business is caught exactly like a bank.

Medium confidenceNational rulesControllerProcessor

Can I store my users' data outside Armenia?

Yes, with paperwork. Armenia runs an approved-country list: if the destination is on it, you can send data with no permission from anyone. The list is real and populated — 53 countries, including all of the European Union, the United Kingdom, Canada, Japan, South Korea, Israel, Georgia and Russia. Sending data anywhere else needs written permission from the privacy regulator first, and that regulator currently has nobody in the chair. Three sectors override this entirely: government, banking-type secrets, and health.

High confidenceYes, with paperworkAllowlistA copy must stayGovernmentBankingHealth and social care

What do I need in place before data leaves Armenia?

The model is an approved list, and the list is full. Fifty-three countries were approved on 8 July 2024 and that decision has never been changed. If your destination is on it you need nothing — no standard contract, no filing, no fee. If it is not on it, you must write to the regulator before you send anything, attach the contract you plan to sign, and wait up to 30 days for a yes or a no.

High confidenceAllowlistOfficial 'this country is safe' decisionGovernment sign-off neededExplicit consent

Who enforces the rules in Armenia, and what can they do?

On paper, the Personal Data Protection Agency inside the Ministry of Justice. In practice, nobody right now: its head resigned with effect from 24 February 2026 and no replacement appointment has been published. In more than eleven years the agency has published exactly one general decision — the approved-country list. Two other regulators are genuinely working: the Central Bank supervises banks, payment firms, insurers and securities, and a brand-new Information Systems Regulatory Commission was appointed in March and April 2026 to police cybersecurity and state computer systems.

Medium confidenceDormantRegulator

How long do I have to keep the data?

The floor is five years for anything that proves your tax position. The ceiling is not a number — it is a principle: you must destroy or block personal data as soon as you no longer need it for the purpose you collected it for. Two hard clocks sit inside that principle. If someone withdraws consent you have ten working days to destroy their data, then three more working days to tell them you did. If you spot unlawful processing you have three working days to fix it or destroy the data.

High confidenceKeep data for a minimum periodDelete data after a periodAllowed because the law requires it

What happens if there is a breach?

Count three clocks. Under the privacy law, if data leaks out of your electronic systems you must immediately publish a public announcement about it and at the same time tell the Armenian police and the privacy regulator — there is no grace period and no threshold. If you run a system in a sector the state calls vital, you have 24 hours to tell the cybersecurity regulator, 72 hours to send an update, two days to warn the people affected, and one month to file a final report. Both sets of duties can bite at once.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Armenia?

Five things that will ruin your week. One: a data leak must be announced publicly and reported to the police, not just to the regulator. Two: encryption is legally compulsory, not a best practice, and failing to use it is its own separate fine. Three: before you process biometric or sensitive data you must notify the regulator in advance and wait to be entered in its register. Four: to process a dead person's data you need the consent of all of their legal heirs. Five: a child is anyone under 16 here, not 13 and not 18.

High confidenceSecure the dataRegister or notifyGet a parent's consent for childrenTell affected peopleCriminal liabilityBiometric dataSensitive personal data

What is changing soon in Armenia?

Armenia rewired its digital rulebook in December 2025 and the deadlines land through 2026, 2027 and 2028. Rules for cyber incidents and for state computer systems are already live. Detailed technical rules are due by January 2027, internal cybersecurity policies and risk assessments by July 2027, and security certificates for critical systems by January 2028. The change most likely to catch someone out is not a new law at all: the approved-country list can be rewritten by one official's signature.

High confidencePartly in forcePassed, not yet fully in forceGovernment policy document

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    2 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    5 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules2 rules

«Անձնական տվյալների պաշտպանության մասին» Հայաստանի Հանրապետության օրենք

Act of parliament · HO-49-N of 18 May 2015, as amended most recently by HO-447-N of 4 December 2025 and HO-191-N of 7 May 2026

In forceYes, with paperwork

Armenia's general privacy law. Personal data may leave the country freely to 53 approved states; anywhere else needs written permission from the regulator, decided within 30 days. Encryption is compulsory, sensitive and biometric processing must be notified in advance, and a leak must be announced publicly.

In force since 1 July 2015

Enforced by Personal Data Protection Agency of the Ministry of Justice — not yet operational

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent

High confidence

Անձնական տվյալների պաշտպանության գործակալության պետի որոշում՝ անձնական տվյալների պաշտպանության բավարար մակարդակն ապահովող պետությունների ցանկը սահմանելու մասին

Adequacy decision · Decision N ATPP-001/24 of the Head of the Personal Data Protection Agency, 8 July 2024

In forceYes, with paperwork

The list that makes the whole transfer regime work. Fifty-three countries are approved, including the whole European Union, the United Kingdom, Canada, Japan, South Korea, Israel, Georgia, Ukraine and the Russian Federation. It is a single official's decision, unchanged since July 2024 despite a legal duty to review it every year.

In force since 10 July 2024

Enforced by Personal Data Protection Agency of the Ministry of Justice — not yet operational

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision

High confidence

Industry rules5 rules

«Ամպայինն առաջինը» քաղաքականության մշակման և ներդրման մասին ՀՀ կառավարության որոշում

Government policy document · Government decision N 884-L of 14 June 2024, as amended by N 1445-L of 12 September 2024 · Government

Partly in forceA copy must stay

Armenia's only true localisation rule. Government bodies may move data to the cloud, and may use a cloud outside Armenia, but must keep a backup copy inside the country. Only low-risk, non-secret public information may go to a cloud at all.

In force since 15 June 2024

Transfer model: Approval each time · Accepted routes: Security review needed

High confidence

«Կիբեռանվտանգության մասին» Հայաստանի Հանրապետության օրենք

Act of parliament · HO-442-N of 4 December 2025

Partly in forceYes — store it anywhere

A new law covering anyone who runs an information system in fourteen vital sectors — energy, manufacturing, transport, water, communications, post, finance, health, information technology, waste, space, database operation, emergency response and public administration. Micro and small businesses are exempt unless they run critical infrastructure. The 24-hour incident clock is live now; the heavier duties phase in to 2028.

In force since 4 January 2026

Enforced by Information Systems Regulatory Commission

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

«Հանրային տեղեկությունների մասին» Հայաստանի Հանրապետության օրենք

Act of parliament · HO-443-N of 4 December 2025 · Government

Partly in forceYes, with paperwork

Rebuilds how the Armenian state holds data. Every government database must be registered, audited and connected through a single official data exchange layer, and copying state data through any other channel is banned. Cloud contracts must let the government leave for another cloud.

In force since 4 January 2026

Enforced by Information Systems Regulatory Commission

Transfer model: Approval each time · Accepted routes: Security review needed

High confidence

Who you would hear from

  • Հայաստանի Հանրապետության արդարադատության նախարարության անձնական տվյալների պաշտպանության գործակալություն

    The authorised body for the Law on Protection of Personal Data: inspections, administrative penalties, orders to block or stop processing, the register of processors, the approved-country list, and complaints from individuals.

    Headless since 24 February 2026. Prime Minister's decision N 120-A of 13 February 2026 released Grigor Nersisyan at his own request, and no appointment of a successor has been published in the official acts database as of 18 August 2026, although the 2015, 2018 and 2023 appointments all were. In eleven years the agency has published exactly one general decision — the July 2024 approved-country list — and it has not carried out the annual review of that list required by Article 27(5). The agency's own website could not be reached, because moj.am blocks automated access, so a low volume of unpublished individual fine decisions cannot be ruled out.

  • Տեղեկատվական համակարգերի կարգավորման հանձնաժողով

    The 'autonomous body' under the Law on Cybersecurity, the Law on Public Information and the Law on the Information Systems Regulatory Body: cyber incident reporting, critical information infrastructure, audits of state databases, the data exchange layer, and technical security requirements — including, since December 2025, technical requirements for processing personal data through information systems and for storing biometric data outside them.

    Newly constituted and still building. The National Assembly appointed the chairman, Nerses Yeritsyan, and members Nairi Adamyan and Srbuhi Hakobyan on 26 March 2026, and David Khachatryan on 16 April 2026 — four appointments, which is the threshold at which the founding law treats the Commission as formed. The 2026 state budget was amended to fund it. Its own implementing rules are due by 26 December 2026, so it has not yet issued substantive regulation. No public website for the Commission could be located on 18 August 2026; the link given is the official text of its founding law.

  • Հայաստանի Հանրապետության կենտրոնական բանկ

    Single supervisor for banks, credit organisations, payment and settlement systems and organisations, insurers and the securities market. It may demand information from operators of Armenian and foreign payment systems even where that information is a bank, commercial or other secret.

    A long-established, fully staffed supervisor with statutory on-site inspection and sanction powers. The bank-secrecy penalty it stands behind — a court-imposed fine of 2,000 to 10,000 times the calculation base — is roughly twenty times the maximum privacy fine.

  • Հանրային ծառայությունները կարգավորող հանձնաժողով

    Regulator for electronic communications, including the confidentiality duty owed by operators to their customers and the rules on disclosing customer location data to emergency services.

    Established regulator that issues binding decisions; its decisions are published in the official legal acts database.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That no new head of the Personal Data Protection Agency has been appointed since 24 February 2026.

    Based on the absence of a published appointment decision in the official legal acts database, where the 2015, 2018 and 2023 appointments were all published. The Ministry of Justice website, which would carry the agency's own staff page, returns 403 to automated requests, so this could not be cross-checked against the agency's own source.

  • That the Personal Data Protection Agency has issued no enforcement decisions.

    Individual administrative fine decisions under Article 189.17 of the Code of Administrative Offences are not published in the legal acts database, and the agency's own site was unreachable. What is verified is that only one general decision by the agency head has ever been published, and that no annual report was locatable. The enforcement rating of dormant rests on that, plus the vacancy, plus a maximum fine of about 1,300 US dollars.

  • That the approved-country list has not been amended since 8 July 2024.

    The official acts database shows Decision N ATPP-001/24 as the principal act still in force from 10 July 2024 with no amending act attached, and a search for other decisions of the agency head returned none. If a revision were published only in the official bulletin or on the agency's own website and not incorporated into the acts database, it would have been missed.

  • That there is no data localisation or data retention rule for telecoms, insurance, securities, education, gaming or mapping.

    No such rule was found in the Law on Electronic Communications, the Law on Payment and Settlement Systems and Payment and Settlement Organisations, or the Law on Spatial Data, checked 18 August 2026. Sub-statutory rules of the Public Services Regulatory Commission and the Central Bank were not exhaustively reviewed, and those are exactly where a retention period or a processing-location condition would normally sit. Treat as 'not found', not as 'does not exist'.

  • Whether a new, European-style data protection law is being drafted.

    Armenia ratified the modernising protocol to the Council of Europe data protection convention in November 2021, which usually precedes a rewrite, and the December 2025 package moved technical data-security powers to a new regulator. The public consultation portal e-draft.am was reachable but its search interface could not be queried, and the web search budget for this run was exhausted before any bill could be checked. No pending bill is asserted either way.

  • The exact scope of the 'organisations' qualifier next to the United States on the approved-country list.

    The decision lists 'United States of America (organisations)' with no definition, no cross-reference and no accompanying guidance. Whether this means certified participants in a specific framework, or something else, could not be established from the decision text and no guidance from the agency was locatable.

  • That the Law on Protection of Personal Data does not apply to foreign companies with no presence in Armenia.

    This is an inference from the absence of any extraterritoriality clause in the consolidated text, not from a positive statement in the law or from a regulator's or court's ruling. No case law or regulator guidance on the point was found.

  • Whether the Information Systems Regulatory Commission has begun issuing decisions.

    Four members were appointed in March and April 2026 and the founding law treats it as formed, but no decisions, no website and no register of its acts could be located on 18 August 2026. Its implementing rules are not due until 26 December 2026, so silence at this point is expected rather than surprising.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.