Law note · Armenia

Law on Protection of Personal Data, cross-border transfer

cite Law of the Republic of Armenia on Protection of Personal Data, Law No. HO-49-N, Art. 27 stage IN FORCE in force since 2015-07-01 kind Cross border transfer binds public and private bodies reviewed 2026-08-29

What it requires

  • An app transferring the personal data of a person in Armenia to a recipient outside Armenia must obtain the data subject's consent, rely on the destination being on the authorized body's published adequacy list or covered by an applicable treaty, or obtain the authorized body's prior written permission for a contract it has approved as providing adequate safeguards.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

Art. 27 permits cross-border transfer with the data subject's consent, or where the transfer follows from or is necessary for the purposes of processing. Absent authorized-body permission, transfer to a state providing an adequate level of protection is permitted where adequacy follows an international treaty or the destination is on the authorized body's officially published list, reviewed at least annually.

Transfer to a non-adequate state requires the authorized body's prior written permission, granted only where a contract provides safeguards the body has itself approved as adequate; the processor must apply in writing before transfer, naming the destination country, recipient, data description, purpose, and the contract or draft contract, and the authority must approve or reject within 30 days. No standardized model-contract template mechanism exists, and no data localization is compelled.

← Back to the example  ·  Lint your app →