Skip to the content
Global Data RulesData governance rules, country by country

Armenia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Armenia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: MediumEnforcement: Dormant

You can send personal data out of Armenia. But it must go to one of 53 countries on an official approved list. For anywhere else you need permission from the privacy regulator, case by case. That regulator has had no head since February 2026. The largest fine it can impose is about 1,300 US dollars. The real limits sit elsewhere. Government data put in a foreign cloud must keep a backup copy inside Armenia. Banking and medical secrecy sit outside the privacy law completely.

Data governance in Armenia

The eight things that decide how you handle data about people in Armenia. Same eight on every country page, so you can compare.

Who has to follow these rules

Probably not, if you have nothing in Armenia. The privacy law describes who it covers by naming Armenian public bodies, companies and individuals who use personal data. It has no clause saying it follows Armenians' data abroad. It has no rule making a foreign company appoint someone inside Armenia. There is no size or revenue cut-off either. A one-person Armenian business is caught exactly like a bank.

Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

Yes, with paperwork. Armenia runs an approved-country list. If your destination is on it, you can send data with no permission from anyone. The list is real and full. It has 53 countries, including all of the European Union, the United Kingdom, Canada, Japan, South Korea, Israel, Georgia and Russia. Sending data anywhere else needs written permission from the privacy regulator first. That regulator currently has nobody in charge. Three industries override all of this: government, banking-type secrets, and health.

What to do: Plan for a database inside Armenia: this data is not allowed to leave.

Sending data out of the country

You can only send data to countries on an approved list, and the list is full. Fifty-three countries were approved on 8 July 2024, and that decision has never changed. If your destination is on the list you need nothing. No standard contract, no filing, no fee. If it is not on the list, you must write to the regulator before you send anything. You attach the contract you plan to sign, and wait up to 30 days for a yes or a no.

Ways to send data out:
Official 'this country is safe' decision · Government sign-off needed · Explicit consent

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

On paper, the Personal Data Protection Agency inside the Ministry of Justice. Right now, nobody. Its head resigned with effect from 24 February 2026, and no replacement has been announced. In more than eleven years the agency has published exactly one general decision. That is the approved-country list. Two other regulators are working. The Central Bank supervises banks, payment firms, insurers and securities. A brand-new Information Systems Regulatory Commission was appointed in March and April 2026. It covers cybersecurity and state computer systems.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

You must keep anything that proves your tax position for at least five years. There is no maximum number of years. Instead there is a rule. You must destroy or block personal data as soon as you no longer need it for the purpose you collected it for. Two firm deadlines sit inside that rule. If someone withdraws consent, you have ten working days to destroy their data. You then have three more working days to tell them you did it. If you spot data being used unlawfully, you have three working days to fix it or destroy the data.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Allowed because the law requires it

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count three deadlines. Under the privacy law, if data leaks out of your electronic systems, you must publish a public announcement about it immediately. At the same time you must tell the Armenian police and the privacy regulator. There is no grace period and no threshold. If you run a system in an industry the state calls vital, you have 24 hours to tell the cybersecurity regulator. You then have 72 hours to send an update, two days to warn the people affected, and one month to file a final report. Both sets of duties can apply at the same time.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. One: a data leak must be announced publicly and reported to the police, not just to the regulator. Two: encryption is required by law, not a best practice. Not using it is a separate fine on its own. Three: before you use biometric or sensitive data, you must tell the regulator first and wait to be entered in its register. Four: to use a dead person's data you need the consent of all their legal heirs. Five: a child here is anyone under 16, not 13 and not 18.

What you have to do here:
Secure the data · Register or notify · Get a parent's consent for children · Tell affected people
What it costs if you get it wrong:
Criminal liability

What's changing next

Armenia rewrote its digital rulebook in December 2025. The deadlines land through 2026, 2027 and 2028. Rules for cyber incidents and for state computer systems are already live. Detailed technical rules are due by January 2027. Internal cybersecurity policies and risk assessments are due by July 2027. Security certificates for critical systems are due by January 2028. The change most likely to catch you out is not a new law. One official can rewrite the approved-country list with a signature.

What to do: Diarise 4 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data needs a copy kept in the country

Official name: «Ամպայինն առաջինը» քաղաքականության մշակման և ներդրման մասին ՀՀ կառավարության որոշում · Government decision N 884-L of 14 June 2024, as amended by N 1445-L of 12 September 2024 · Government policy document

Partly in forceA copy must stay

This is Armenia's only true rule about where data must sit. Government bodies may move data to the cloud, and may use a cloud outside Armenia. But they must keep a backup copy inside the country. Only low-risk public information that is not secret may go into a cloud at all.

In force since 15 June 2024

How this country controls where data goes: Approval each time · Accepted routes: Security review needed

Health data rules

Official name: «Կիբեռանվտանգության մասին» Հայաստանի Հանրապետության օրենք · HO-442-N of 4 December 2025 · Act of parliament

Partly in forceYes — store it anywhere

A new law covering anyone who runs an information system in fourteen vital industries. They are energy, manufacturing, transport, water, communications, post, finance, health, information technology, waste, space, database operation, emergency response and public administration. Micro and small businesses are exempt unless they run critical infrastructure. The 24-hour incident deadline is live now. The heavier duties phase in up to 2028.

In force since 4 January 2026

Enforced by Information Systems Regulatory Commission

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Government

Cloud and outsourcing rules

Official name: «Հանրային տեղեկությունների մասին» Հայաստանի Հանրապետության օրենք · HO-443-N of 4 December 2025 · Act of parliament

Partly in forceYes, with paperwork

This law rebuilds how the Armenian state holds data. Every government database must be registered, audited and connected through one official data exchange layer. Copying state data through any other channel is banned. Cloud contracts must let the government move to another cloud.

In force since 4 January 2026

Enforced by Information Systems Regulatory Commission

How this country controls where data goes: Approval each time · Accepted routes: Security review needed

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Biometric data rules

Official name: «Անձնական տվյալների պաշտպանության մասին» Հայաստանի Հանրապետության օրենք · HO-49-N of 18 May 2015, as amended most recently by HO-447-N of 4 December 2025 and HO-191-N of 7 May 2026 · Act of parliament

In forceYes, with paperwork

Armenia's general privacy law. Personal data may go freely to 53 approved countries. Anywhere else needs written permission from the regulator, decided within 30 days. Encryption is compulsory. You must tell the regulator before you use sensitive or biometric data. A leak must be announced publicly.

In force since 1 July 2015

Enforced by Personal Data Protection Agency of the Ministry of Justice — not yet operational

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent

Paperwork before personal data leaves

Official name: Անձնական տվյալների պաշտպանության գործակալության պետի որոշում՝ անձնական տվյալների պաշտպանության բավարար մակարդակն ապահովող պետությունների ցանկը սահմանելու մասին · Decision N ATPP-001/24 of the Head of the Personal Data Protection Agency, 8 July 2024 · Official “this country is safe” decision

In forceYes, with paperwork

This list is what makes sending data abroad work. Fifty-three countries are approved. They include the whole European Union, the United Kingdom, Canada, Japan, South Korea, Israel, Georgia, Ukraine and the Russian Federation. It is one official's decision. It has not changed since July 2024, despite a legal duty to review it every year.

In force since 10 July 2024

Enforced by Personal Data Protection Agency of the Ministry of Justice — not yet operational

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision

Who you would hear from

  • Հայաստանի Հանրապետության արդարադատության նախարարության անձնական տվյալների պաշտպանության գործակալություն

    The authorised body for the Law on Protection of Personal Data: inspections, administrative penalties, orders to block or stop processing, the register of processors, the approved-country list, and complaints from individuals.

    It has had no head since 24 February 2026. Prime Minister's decision N 120-A of 13 February 2026 released Grigor Nersisyan at his own request. No successor has been announced in the official acts database as of 18 August 2026. The 2015, 2018 and 2023 appointments were all published there. In eleven years the agency has published exactly one general decision, the July 2024 approved-country list. It has not carried out the yearly review of that list required by Article 27(5). We could not reach the agency's own website, because moj.am blocks automated access. So we cannot rule out a small number of unpublished fine decisions.

  • Տեղեկատվական համակարգերի կարգավորման հանձնաժողով

    The 'autonomous body' under the Law on Cybersecurity, the Law on Public Information and the Law on the Information Systems Regulatory Body: cyber incident reporting, critical information infrastructure, audits of state databases, the data exchange layer, and technical security requirements — including, since December 2025, technical requirements for processing personal data through information systems and for storing biometric data outside them.

    Newly formed and still building. The National Assembly appointed the chairman, Nerses Yeritsyan, on 26 March 2026. It appointed members Nairi Adamyan and Srbuhi Hakobyan on the same day, and David Khachatryan on 16 April 2026. That is four appointments, which is the point at which its founding law treats it as formed. The 2026 state budget was changed to fund it. Its own rules are due by 26 December 2026, so it has not yet issued real regulation. We could not find a public website for it on 18 August 2026. The link given is the official text of its founding law.

  • Հայաստանի Հանրապետության կենտրոնական բանկ

    Single supervisor for banks, credit organisations, payment and settlement systems and organisations, insurers and the securities market. It may demand information from operators of Armenian and foreign payment systems even where that information is a bank, commercial or other secret.

    A long-established, fully staffed supervisor. It can inspect on site and impose sanctions under its own law. It stands behind the bank-secrecy penalty, a court-imposed fine of 2,000 to 10,000 times the calculation base. That is roughly twenty times the largest privacy fine.

  • Հանրային ծառայությունները կարգավորող հանձնաժողով

    Regulator for electronic communications, including the confidentiality duty owed by operators to their customers and the rules on disclosing customer location data to emergency services.

    An established regulator that issues binding decisions. Its decisions appear in the official legal acts database.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That no new head of the Personal Data Protection Agency has been appointed since 24 February 2026.

    We found no published appointment decision in the official legal acts database. The 2015, 2018 and 2023 appointments were all published there. The Ministry of Justice website, which carries the agency's staff page, refuses automated requests. So we could not check this against the agency's own source. Confirm with the ministry before you rely on it.

  • That the Personal Data Protection Agency has issued no enforcement decisions.

    Individual fine decisions under Article 189.17 of the Code of Administrative Offences are not published in the legal acts database. We also could not reach the agency's own site. What we can show is that only one general decision by the agency head has ever been published, and that we found no yearly report. Our low enforcement rating rests on that, plus the vacant post, plus a largest fine of about 1,300 US dollars.

  • That the approved-country list has not been amended since 8 July 2024.

    The official acts database shows Decision N ATPP-001/24 still in force from 10 July 2024, with no amending act attached. A search for other decisions by the agency head returned none. If a revision appeared only in the official bulletin or on the agency's own website, we would have missed it. Check the list itself before you send data.

  • That there is no rule forcing data to stay in the country or data retention rule for telecoms, insurance, securities, education, gaming or mapping.

    We checked three laws on 18 August 2026 and found no such rule. They were the Law on Electronic Communications, the Law on Payment and Settlement Systems and Payment and Settlement Organisations, and the Law on Spatial Data. We did not review every detailed rule of the Public Services Regulatory Commission or the Central Bank. Those are exactly where a keep-time or a storage-location condition normally sits. If you work in these industries, check with your regulator before you rely on this.

  • Whether a new, European-style data protection law is being drafted.

    Armenia ratified the updating protocol to the Council of Europe data protection convention in November 2021, which usually comes before a rewrite. The December 2025 package also moved technical data-security powers to a new regulator. We could not search the public consultation portal e-draft.am, so we could not check for a bill. We do not say a bill is pending, and we do not say one is not.

  • The exact scope of the 'organisations' qualifier next to the United States on the approved-country list.

    The decision lists 'United States of America (organisations)' with no definition, no cross-reference and no guidance. We could not establish whether this means companies certified under a specific scheme, or something else. We found no guidance from the agency. Ask the agency before you send data to a United States recipient.

  • That the Law on Protection of Personal Data does not apply to foreign companies with no presence in Armenia.

    This is our reading, based on the law having no clause that applies it to companies outside Armenia. It is not based on a positive statement in the law, or on a ruling by a court or the regulator. We found no case law or regulator guidance on the point. Take advice if you have no presence in Armenia.

  • Whether the Information Systems Regulatory Commission has begun issuing decisions.

    Four members were appointed in March and April 2026, and the founding law treats the Commission as formed. We found no decisions, no website and no register of its acts on 18 August 2026. Its own rules are not due until 26 December 2026, so silence at this point is expected.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.