A draft amendment to the Law “On Personal Data Protection” of the Republic of Armenia introduces several new concepts and mechanisms that bring the Armenian framework closer to the EU’s General Data Protection Regulation (GDPR).

Meanwhile, the draft does not replicate the GDPR, and important differences remain.

Here are some key points:

1. Legal bases for processing

The draft provides three legal bases for processing personal data: 

  • consent; 
  • processing directly provided for by law; and 
  • data obtained from publicly available sources.

This differs significantly from Art. 6 GDPR, which provides six legal bases, including contract performance, legal obligations, vital interests, public interest and legitimate interests.

2. Distinction between controller and processor

The draft does not establish the GDPR’s distinction between data controller and data processor, and allocation of responsibilities and contractual requirements.

This is particularly relevant for businesses using cloud, IT, payroll, AI and other third-party service providers.

3. Data Protection Officer (DPO)

The draft introduces a DPO framework and requires state and local self-government authorities to appoint at least one DPO.

Unlike the GDPR, however, it does not impose mandatory DPO designation on certain private-sector organizations based on the nature, scale and risks of processing.

4. Data Protection Impact Assessment (DPIA)

The draft introduces DPIA for certain processing involving special-category or biometric data, processing that may present a high risk to individuals’ rights and freedoms, and other processing classified as high-risk by the competent authority.

This reflects the GDPR’s risk-based approach under Art. 35 GDPR.

5. Automated decision-making

The draft introduces safeguards for decisions based solely on automated processing, including rights to human intervention, to express a position, to receive an explanation and to challenge the decision.

In some respects, this approach aligns with Art. 22 of the GDPR and is particularly relevant as AI and automated decision-making tools become more widespread.

6. Consent

The draft adds “informed” to the requirements for consent.

However, unlike Art. 4(11) GDPR, the draft does not expressly require consent to be freely given, specific and unambiguous.

Thus, while the proposed regulation moves the Armenian framework closer to the GDPR standard, it does not establish an equivalent standard for valid consent.

7. Supervisory framework

The draft clarifies the role of the Personal Data Protection Commission as the competent supervisory authority, with its status and powers to be regulated under a separate law.

A move toward a more risk-based data framework

Overall, the draft is a significant development of Armenia’s personal data protection framework and incorporates several concepts influenced by the GDPR.

For businesses operating in Armenia, particularly technology, financial, healthcare and other organizations processing biometric or special-category data, the proposed changes may require a review of existing data protection policies, procedures and compliance practices.