Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
What it requires →
Art. 3(13) defines biometric personal data only as information characterizing a person's physical, physiological and biological characteristics, a bare, generic definition with no processing-method qualifier, no unique-identification qualifier, and no named modality such as voice or face.
Art. 13 requires the data subject's consent as the default basis for processing biometric data, except where a law-defined purpose can only be achieved through that processing; no modality-specific variation exists.
Art. 19(4) and (6) defer retention and destruction specifics to a government resolution not read for this document, requiring only that physical-media storage of biometric data outside information systems be protected from unauthorized access, use, destruction, alteration, blocking, copying, and distribution. Art. 23(3) additionally requires the processor to notify the authorized body before processing biometric or special-category data of its intent to do so, a pre-processing notification duty.
Because the Art. 3(13) definition has no derivation or identification qualifier at all, whether it includes or excludes an identifier derived from a photo, video, or audio recording is not addressed by the statute's text.
Comprehensive regime
What it requires →
Armenia's Law on Protection of Personal Data, Law No. HO-49-N, took effect 1 July 2015 (Art. 28), replacing a 2002-era law on the same date. Two derived corpus candidates conflict on the exact adoption date, 18 May versus 8 May 2015; this document does not resolve that conflict and records only the confirmed in-force date.
General principles at Arts. 4-8 cover legality, proportionality, accuracy, minimal subject involvement, and lawfulness-of-processing grounds, across 29 articles total, considerably shorter and less elaborated than several of this jurisdiction's regional peers. All translations of Armenian-language text in this document are the researcher's own working translations, not an official translation.
Cross border transfer
What it requires →
Art. 27 permits cross-border transfer with the data subject's consent, or where the transfer follows from or is necessary for the purposes of processing. Absent authorized-body permission, transfer to a state providing an adequate level of protection is permitted where adequacy follows an international treaty or the destination is on the authorized body's officially published list, reviewed at least annually.
Transfer to a non-adequate state requires the authorized body's prior written permission, granted only where a contract provides safeguards the body has itself approved as adequate; the processor must apply in writing before transfer, naming the destination country, recipient, data description, purpose, and the contract or draft contract, and the authority must approve or reject within 30 days. No standardized model-contract template mechanism exists, and no data localization is compelled.
Data subject rights
What it requires →
Art. 15 gives a data subject the right to receive information about their own data. Art. 16 gives a right regarding decisions made on the basis of processing; its relationship to specifically automated processing, versus any decision based on processing at all, needs a closer read before it is treated as an automated-decision-objection right in the General Data Protection Regulation (GDPR) Art. 22 sense. Art. 17 gives a right to appeal a processor's action or inaction.
No dedicated deletion or portability article was found beyond what falls out of Art. 19's general duty to destroy data when it is no longer needed.
Enforcement supervision
What it requires →
Art. 24 creates an independent Authorized Body for Personal Data Protection, structured by government resolution, with powers to audit compliance, apply administrative-liability measures established by law, demand suspension or cessation of unlawful processing, demand rectification, blocking, or destruction, block processing following review of a pre-processing notification, maintain a processor registry, certify adequate-security electronic systems, inspect devices and documents, apply to court, investigate individual complaints, publish an annual public report, and provide guidance.
No compensation or damages term was found anywhere in the Act; specific fine amounts live in the separate RA Code on Administrative Offences, which was not read for this document, so no figures are stated here. Individual recourse runs through the Art. 17 appeal right or the authority's own court-application power, not a dedicated statutory civil-damages provision inside this Act; general Civil Code tort provisions might independently support a damages claim but were not researched here.
Sensitive categories
What it requires →
Art. 12 sets a single, general condition for special-category processing: processing without the data subject's consent is prohibited except where it is directly provided for by law, and processing must stop immediately once its legal basis or purpose lapses. This is a single ground, consent or a legal provision, considerably thinner than a multi-ground special-category structure.
The statute was not read for this document to enumerate which specific categories Art. 12 governs beyond this general rule, and biometric data is instead addressed by a separate, dedicated article (Art. 13), not folded into this general special-category rule.