The Constitution of the Republic of Armenia sets forth the right to protection of personal data. In Armenia, the relations regarding personal data are primarily regulated by the Law “On Protection of Personal Data” of the Republic of Armenia.
Why Does Data Protection Matter for Businesses?
Privacy and data protection have become essential legal considerations for businesses, technology companies, data centers and other organizations that process personal data.
For example, a company may process personal data when it:
- provides products and services to customers;
- maintains customer or client databases;
- operates a website or mobile application;
- sends marketing communications;
- uses cloud-based software; processes payments;
- uses customer relationship management (CRM) or human resources (HR) systems;
- records visitors or uses CCTV; conducts customer due diligence;
- receives CVs, hires employees and manages employment relationships;
- transfers information to affiliates, contractors or other third parties.
Data protection should therefore be integrated into a company's ordinary legal, operational and business processes.
A well-designed privacy compliance framework can help an organization identify what personal data it processes, the purposes and legal grounds for processing, where the data are stored, who has access to them, how long they are retained, and whether processing, any disclosures or international transfers comply with applicable legal requirements.
GDPR Compliance for Businesses in Armenia
The EU General Data Protection Regulation (GDPR) may also apply to organizations, incorporated in Armenia, depending on the nature of their activities or to whom they offer the goods or services.
The GDPR is particularly relevant to those businesses, incorporated in Armenia, that offer goods or services to individuals in the European Union or monitor the behavior of individuals within the EU.
Whereas the extraterritorial application of GDPR, the fact of being incorporated in Armenia does not automatically place an Armenian organization outside the GDPR, rather an Armenian organization should assess whether the GDPR applies to its specific activities.
Where the GDPR applies, a business may need to address requirements concerning lawful processing, transparency, data subject rights, data security, contractual arrangements, international transfers and, where applicable, the appointment of an EU representative or a Data Protection Officer (DPO).
International Transfers of Personal Data
International data transfers are particularly relevant to technology companies and businesses that use cloud servers, software platforms or other service providers located outside Armenia.
The Law “On Protection of Personal Data” of the Republic of Armenia establishes specific requirements for transferring personal data to other states. Depending on the circumstances, a transfer may be permitted on the basis of the data subject's consent, or other conditions established by law. The law also addresses transfers to countries that provide an adequate level of protection and circumstances requiring authorization and contractual safeguards.
Businesses should identify where personal data are stored, where they are accessed, which third parties receive them, and whether any international transfers comply with the applicable legal requirements.
Data Processing Agreements
When a company engages another organization to process personal data on its behalf, the relationship should be reviewed from a data protection perspective.
Depending on the applicable legislation and the parties' respective roles, a Data Processing Agreement (DPA) may be required.
Such agreements may address the scope and purpose of processing, the parties' responsibilities, confidentiality, security measures, the engagement of subprocessors, assistance with data subject requests, data breach notification and the deletion of personal data.
Privacy and Artificial Intelligence
The growing use of artificial intelligence (AI) creates new privacy and data protection considerations for businesses.
AI governance should therefore be considered together with privacy, confidentiality, cybersecurity and contractual risk.
Organizations using AI tools should assess:
- What personal data are entered into AI systems;
- Whether employee, customer personal data or confidential information is being processed;
- Where the data is stored or transferred;
- Whether an AI provider uses submitted data for additional purposes;
- What contractual protections and data processing terms apply;
- Who can access AI-generated or AI-processed information;
- How long personal data are retained and when they are deleted;
- Data protection by design and data protection by default, where GDPR is applicable;
- Whether the proposed processing is compatible with applicable privacy and data protection legislative requirements.
Data Protection Compliance for Startups and Technology Companies
Privacy considerations should ideally be addressed at an early stage of a company's development.
For startups and technology companies, data protection issues may arise during:
- Product development;
- User registration and account management;
- Customer onboarding and identity verification;
- Implementation of analytics and advertising technologies;
- Integration of third-party APIs and software;
- Use of AI tools and automated systems.
Integrating privacy requirements into products, contracts and internal processes from the outset ensure compliance with legislative requirements and reduces necessity of costly restructuring as a business grows.
Privacy and Data Protection Services
LY Law Firm provides legal advice on privacy and personal data protection matters based on Armenian Law and GDPR.
LY Law Firm, whose managing partner is a certified information privacy professional in Europe (CIPP/E), supportս businesses in assessing GDPR-related obligations and addressing privacy and data protection requirements in connection with their operations in Armenia and international business activities.
In particualr, our services include:
- Privacy & Data Protection Legal Due Diligence;
- Data Protection Compliance Advice;
- Drafting and reviewing privacy policies and internal documentation;
- Reviewing, drafting and negotiating agreements relating to privacy and personal data protection, including data transfer agreements;
- Cross-border data transfers;
- legal support for conducting Data Protection Impact Assessments (DPIAs).
Frequently Asked Questions
What is personal data?
Personal data is any information relating to a natural person that allows, or may allow, either directly or indirectly to identify the person.
Personal data can be a person's first name, surname, identification number, email address, phone number, etc. For example, in its judgment in Breyer v Bundesrepublik Deutschland (Case C-582/14), the Court of Justice of the European Union (CJEU) held that dynamic IP address registered by an online media services provider when a person accesses a website that the provider makes accessible to the public constitutes personal data.
What is pseudonymous data?
Pseudonymous data is personal data that has been processed so that it can no longer be attributed to a specific individual without the use of additional information. However, pseudonymised data is not fully anonymous is still personal data and subject to applicable data protection legislation.
Pseudonymisation involves separating identifying information from the data, while retaining the possibility of re-identifying the individual using additional information. It is commonly used as a security measure to reduce the risks associated with processing personal data.
What is the difference between Law “On Protection of Personal Data” of the Republic of Armenia and GDPR?
Law “On Protection of Personal Data” of the Republic of Armenia and the General Data Protection Regulation (GDPR) define important principles concerning the lawful processing and protection of personal data. However, they are not identical regulatory frameworks and all issues are not regulated identically.
Differences may arise in areas such as legal grounds for processing, the appointment of a Data Protection Officer (DPO), organizational obligations and documentation requirements, international data transfers, and relations with regulatory authority.
Businesses subject to both legislation of the Republic of Armenia and GDPR should assess their obligations under each framework separately. Compliance with one regulation does not in itself mean that the business automatically meets the requirements of another.
Does a company in Armenia need a privacy policy?
A privacy policy is an important part of a company's data protection framework, particularly when the business collects personal data through its website, applications and online services.
In the meantime, a privacy policy alone does not ensure compliance with data protection laws. Businesses should also assess their data processing activities, legal grounds for processing, data retention terms, internal procedures, employee access to personal data, contracts with service providers and third parties, security measures, data transfers, and other applicable requirements.
Does a company need to designate a Data Protection Officer (DPO)?
The Law “On Protection of Personal Data” of the Republic of Armenia does not establish a general requirement for organizations to designate a Data Protection Officer (DPO).
For businesses subject to the GDPR, the specific criteria for mandatory DPO designation should be assessed, taking into account the nature, scope, and purposes of their data processing core activities, as well as types of processed personal data, and other applicable criteria.
Can personal data be transferred outside Armenia?
Cross-border transfers of personal data require legal assessment. The Law “On Protection of Personal Data” of the Republic of Armenia establishes requirements for transferring personal data to other countries, including requirements relating to an adequate level of protection and circumstances in which transfers may be permitted. Such cases may arise, for example, when data is transferred to a foreign cloud service provider.
Where an organization is also subject to the GDPR, its separate requirements for international data transfers must be assessed.