DPIA

High-Risk Personal Data Processing

Organizations process special category, biometric and other personal data in digital services, artificial intelligence, healthcare, financial services and other activities.

Where processing may present a high risk to individuals' rights and freedoms, a Data Protection Impact Assessment may be required under the proposed amendments to the Law “On Personal Data Protection” of the Republic of Armenia.

A DPIA is a structured process for identifying and assessing the potential impact of a proposed or existing processing activity on individuals' rights and freedoms, as well as determining appropriate measures to mitigate identified risks and ensure protection of personal data.

DPIAs are particularly relevant where an organization processes special categories of personal data, biometric data, or personal data in other circumstances that may create a high risk to individuals' rights and freedoms.

Whether a DPIA is required depends on the nature, scope, context and purposes of the processing and the level of risk that the processing may present to individuals' rights and freedoms.

Organizations should consider DPIA requirements when introducing new processing activities or significantly changing existing ones, in the following circumstances:

  • the processing involves special categories of personal data; 
  • the processing involves biometric personal data; 
  • the processing of personal data is prescribed by law and, taking into account the nature, scope, purposes, or technologies used, may result in a high risk to the rights and freedoms of natural persons; or 
  • the processing is considered high-risk based on criteria established by the authorized body responsible for personal data protection.

The Commission for the Protection of Personal Data will establish the criteria for determining whether a data processing activity is considered high-risk.

Where a Data Protection Impact Assessment indicates that processing operations may result in a high risk that cannot be mitigated through appropriate technical, organizational, or legal measures, prior consultation with the Commission for the Protection of Personal Data is required.

Legal Support for Data Protection Impact Assessments

LY Law Firm provides legal support for DPIAs, helping organizations identify and address the legal and data protection risks associated with their processing activities.

We help organizations understand and address their obligations under Armenian personal data protection legislation and, where relevant, the EU General Data Protection Regulation (GDPR).

LY Law Firm provides legal support throughout the DPIA process, with a focus on the legal and regulatory aspects of personal data processing.

Our legal support include:

  • assessing whether a proposed or existing processing activity requires a DPIA; 
  • analyzing the purposes and legal basis for processing; 
  • assessing the nature, scope, context and methods of processing; 
  • assessing necessity and proportionality of the processing; 
  • identifying and analyzing risks to the rights and freedoms of data subjects; 
  • assessing international transfers of personal data; reviewing relevant contractual, organizational and legal safeguards; 
  • recommending measures to mitigate identified data protection risks; and 
  • reviewing existing DPIAs and advising on necessary updates.

Where a DPIA involves technical, information security or other specialist assessments, we can work with the organization's internal teams or relevant external specialists to ensure that the legal aspects are appropriately addressed.

For organizations that are subject to the GDPR, or that seek to align their activities with international data protection standards, LY Law Firm can provide legal support based on the GDPR.

Our DPIA legal services may be relevant to:

technology and software companies; financial institutions and fintech companies; healthcare organizations; telecommunications and digital service providers; organizations using biometric identification systems; organizations using artificial intelligence or automated decision-making; organizations conducting profiling or monitoring; organizations processing biometric or special-category personal data; and organizations preparing for GDPR compliance.

If you are unsure whether your organization needs to conduct a DPIA, LY Law Firm can first assess the relevant processing activity and advise whether a DPIA is required.

Frequently Asked Questions

What constitutes special categories of personal data?

Under the Law "On Personal Data Protection" of the Republic of Armenia, special categories of personal data include information regarding a person's racial, national, or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health status, and sex life.

The GDPR does not expressly include national origin as special category of personal data. At the same time, the GDPR defines special categories of personal data more broadly, by adding genetic data, biometric data for the purpose of uniquely identifying a natural person, and data concerning a person's sexual orientation. 

What is biometric personal data?

Under the Law "On Personal Data Protection" of the Republic of Armenia, biometric personal data refers to information characterizing a person's physical, physiological, and biological characteristics.

The GDPR defines biometric data as personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that person, such as facial images or dactyloscopic data.

In which cases is the processing of personal data considered high-risk?

The Personal Data Protection Commission of the Republic of Armenia will establish criteria for determining whether a particular processing operation presents a high risk.

Within the framework of GDPR, the Article 29 Working Party’s Guidelines (WP248) identify nine criteria that should be considered when determining whether processing operations are likely to result in a high risk and therefore require a Data Protection Impact Assessment (DPIA).

These nine criteria are:

  1. Evaluation or scoring - including profiling and predicting, based on a person’s financial situation, health, behavior, preferences, or other personal characteristics.
  2. Automated-decision making with legal or similar significant effect – automated processing that produces legal effects or similarly significantly affects individuals, such as decisions that may result in exclusion or discrimination. Processing that has little or no effect on individuals does not fall under this criterion.
  3. Systematic monitoring – processing used to regularly observe, monitor, or control individuals, including monitoring in publicly accessible areas.
  4. Sensitive data or data of a highly personal nature – processing special categories of personal data, criminal records, or other highly private information, such as health, financial, location, communications, or personal-document data, which may pose significant risks to individuals.
  5. Data processed on a large scale – processing involving a large number of individuals or a significant volume of data. The scale can be assessed based on the number of individuals, amount and types of data, duration of processing, and geographical scope.
  6. Matching or combining datasets – combining personal data from different sources or for different purposes in ways that may exceed the reasonable expectations of the individuals concerned.
  7. Data concerning vulnerable data subjects processing involving individuals who may be in a position of dependency or where an imbalance between the data subject and the controller may exist, limiting their ability to freely consent, object to processing, or exercise their rights. Examples may include children, employees, elderly persons, or asylum seekers.
  8. Innovative use or applying new technological or organisational solutions - processing involving new technologies or organisational approaches that may create new or significant risks to individuals’ rights and freedoms, such as biometric identification or access-control systems and Internet of Things (IoT) applications.
  9. Processing that prevents individuals from exercising a right or accessing a service or contract – processing that, by its nature, prevents data subjects from exercising a right or accessing a service or entering into a contract. An example is a bank screening a customer against a credit-reference database to determine whether to offer the customer a loan.

It is important to note that the criteria developed by the Article 29 Working Party are not binding on the Personal Data Protection Agency of the Republic of Armenia. Nevertheless, they can serve as a useful guideline for assessing the risk associated with personal data processing and determining the necessity of conducting a DPIA.