Bidda Sovereign Intelligence · 10,090 Verified Nodes · 39 Sovereign Pillars

Armenia Law on Protection of Personal Data 2015 - Data Protection Agency

Armenia's Law on Protection of Personal Data (Հայաստանի Հանրապետության «Անձնական տվյալների պաշտպանության մասին» օրենք, Law No. HO-49-N) - adopted on 18…

What Armenia Law on Protection of Personal Data 2015 - Data Protection Agency requires

Armenia's Law on Protection of Personal Data (Հայաստանի Հանրապետության «Անձնական տվյալների պաշտպանության մասին» օրենք, Law No. HO-49-N) - adopted on 18 May 2015 and entering into force on 1 July 2016 - is Armenia's primary personal data protection legislation, replacing the earlier 2002 law and establishing a more comprehensive rights-based framework aligned with European data protection standards. The law was enacted in the context of Armenia's membership in the Eurasian Economic Union (EAEU) and the EU-Armenia Comprehensive and Enhanced Partnership Agreement (CEPA, in force 2021), which includes obligations for progressive alignment with EU standards including data protection. The supervisory authority is the Agency for Personal Data Protection of the Republic of Armenia (Հայաստանի Հանրապետության Անձնական Տվյալների Պաշտպանության Գործակալություն - PDPA), established as an independent body under the Ministry of Justice framework. Key features of Armenia's Law on Protection of Personal Data 2015: (1) Scope - applies to personal data processing by state bodies, local self-governing bodies, legal entities, and individuals in Armenia; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; proportionality; accuracy; storage limitation; security; and confidentiality; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political views; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; and biometric data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to object; and right to complain to the PDPA; (6) Operator obligations - operators (data controllers) must notify the PDPA before commencing processing; implement security measures; and designate a responsible person; (7) Breach notification - operators must notify the PDPA of significant personal data security incidents; (8) Cross-border transfers - personal data transfers outside Armenia require adequate protection or PDPA-approved safeguards; (9) PDPA enforcement - investigates complaints; conducts inspections; issues binding orders; initiates administrative proceedings; (10) EU alignment - Armenia's CEPA obligations drive progressive alignment with GDPR standards; Council of Europe Convention 108+ ratification confirms Armenia's commitment to European data protection standards. Armenia's Law positions the country as a data-secure jurisdiction in the South Caucasus, supporting Armenia's significant IT services export sector which processes significant personal data of international clients.

Pillar: Cybersecurity · Authority: Agency for Personal Data Protection of the Republic of Armenia (PDPA) · Version: 1.1.0 · Last updated:

Primary source: https://www.moj.am/storage/uploads/Personal_data_protection_law_ENG_OFFICIAL.pdf

SHA-256 integrity: c29db714be95165c10d5680886eda57f768b84bb48a079403dcafb3708a49d02

Primary Citations — 7 traced to source

  • Law on Protection of Personal Data (Law No. HO-49-N, adopted 18 May 2015, in force 1 July 2016, Armenia) - replaces the 2002 personal data law; processing principles: lawfulness, purpose limitation, proportionality, accuracy, storage limitation, security, confidentiality; sensitive personal data: racial/ethnic origin, political views, religious beliefs, trade union membership, health, sexual orientation, criminal convictions, biometric; data subject rights: access, rectification, erasure, objection, appeal to PDPA; PDPA notification mandatory; cross-border transfer restrictions; responsible person designation required
  • Agency for Personal Data Protection of the Republic of Armenia (PDPA) - independent supervisory authority under the Ministry of Justice framework; maintains the register of personal data operators; investigates complaints; conducts inspections; issues binding orders; initiates administrative proceedings; imposes sanctions; issues compliance guidance; participates in Council of Europe data protection authority consultations

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.