Law note · Armenia
Law on Protection of Personal Data, biometric data provisions
What it requires
- An app that captures or stores a voiceprint, faceprint, or other biometric identifier from a person in Armenia must obtain the data subject's consent, unless a law-defined purpose can only be achieved through that processing, and must notify the authorized body before beginning to process biometric data, since Armenia's biometric-data definition does not distinguish by modality or by whether the identifier was derived from a recording.
When LexLint raises it
processes_biometricsprocesses_voice
What we found
Art. 3(13) defines biometric personal data only as information characterizing a person's physical, physiological and biological characteristics, a bare, generic definition with no processing-method qualifier, no unique-identification qualifier, and no named modality such as voice or face.
Art. 13 requires the data subject's consent as the default basis for processing biometric data, except where a law-defined purpose can only be achieved through that processing; no modality-specific variation exists.
Art. 19(4) and (6) defer retention and destruction specifics to a government resolution not read for this document, requiring only that physical-media storage of biometric data outside information systems be protected from unauthorized access, use, destruction, alteration, blocking, copying, and distribution. Art. 23(3) additionally requires the processor to notify the authorized body before processing biometric or special-category data of its intent to do so, a pre-processing notification duty.
Because the Art. 3(13) definition has no derivation or identification qualifier at all, whether it includes or excludes an identifier derived from a photo, video, or audio recording is not addressed by the statute's text.