What Is Law of the Republic of Armenia on Protection of Personal Data?
Armenia’s operative statute is the Law of the Republic of Armenia on Protection of Personal Data, HO-49-N, adopted in 2015 and effective from 1 July 2015, with Article 7 having a delayed commencement. The current consolidated text and amendment history identify amendments through HO-191-N, adopted on 7 May 2026 and effective on 15 August 2026; no amendment later than 21 August 2026 was located. The law does not reproduce the GDPR rights framework. Armenia uses “destruction” rather than “erasure,” provides blocking as a temporary suspension of processing, and includes consent withdrawal, access, correction, complaints, judicial review, and compensation routes. No standalone general objection right or express portability right was located. The current Armenian statutory text also marks the former Article 1(3) journalism, literary, and artistic exception as repealed, while older English translations still contain that language.
At a glance
- Full name
- Law of the Republic of Armenia on Protection of Personal Data
- Short code
- HO-49-N
- Jurisdiction
- Armenia
- Enacted
- 2015
- Last major update
- Latest located amendment HO-191-N adopted 7 May 2026 and effective 15 August 2026; no amendment later than 21 August 2026 was located
- Regulator
- Personal Data Protection Agency
- Private right of action
- Limited
- Statutory citation
- Law of the Republic of Armenia on Protection of Personal Data, HO-49-N
Scope, who HO-49-N covers
Protected data
Data subject rights
Right to information and access
Right to rectification and updating
Right to destruction of personal data, using Armenia’s statutory terminology rather than “erasure”
Right to blocking or temporary suspension of processing
Right to withdraw consent, after which processing must generally cease and data be destroyed within 10 working days
Narrow protection against specified automated decisions under Article 16
Right to complain to the Personal Data Protection Agency
Right to judicial review and compensation through the Agency or courts
No standalone general objection right was located
No express portability right was located
Notable features
Armenia’s framework is narrower than GDPR in important respects: no standalone general objection or express portability right was located, and automated-decision protection is narrower than GDPR’s broader profiling safeguards. The current Armenian text controls over older English translations, particularly because the former Article 1(3) journalism, literary, and artistic exception is marked repealed. Transfers to inadequate destinations require Agency permission, and the EAEU framework does not displace the domestic statute based on the reviewed materials.
Enforcement & penalties
Regulator: Personal Data Protection Agency
Penalties: Administrative Offences Code Article 189.17 provides penalties of 200-500 times the minimum salary for unlawful collection, recording, organization, storage, use, alteration, restoration, or transfer; 300-500 times for failure to abolish or block required data; 100-200 times for failure to provide legally required information; 50-100 times for failure to notify the authorized body; 100 times for failure to use required encryption; 100-200 times for information-system security or biometric-storage violations; and 200-300 times for confidentiality violations. An exemption applies where the violation is cured within the Agency-specified period or before a decision is adopted with supporting evidence. Figures are reported as stated in the official instrument and are not converted to AMD.
Private right of action: Article 17 provides complaint, judicial-review, and compensation routes through the Agency or courts. No fixed Personal Data Protection Law deadline was located for judicial appeal; the general Administrative Procedure Law route gives two months for an administrative act, one month for an action, and two months for inaction.
Relevance to data brokers
No dedicated data-broker route was located across the reviewed ARLIS, Personal Data Protection Agency, and Ministry materials. A narrow adjacent mechanism exists for public-source data: names, birth and death details, and consciously public data are treated as publicly available, with removal available through request or judicial procedure under Article 11. No GDPR-style foreign-site targeting or monitoring rule was located, so the statute should not be expanded into a claim that every foreign people-search site is automatically subject to Armenian law.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Armenia provide a GDPR-style right to portability?+
No express portability right was located in the reviewed Armenian law. The law does provide information, access, correction, destruction, blocking, consent withdrawal, complaint, judicial-review, and compensation routes.
What does Armenia call the right to erase data?+
The Armenian law uses “destruction” rather than “erasure.” Processing must generally cease and data be destroyed within 10 working days after consent is withdrawn.
Can public-source data be removed in Armenia?+
Article 11 treats specified public-source data as publicly available and provides a removal route through request or judicial procedure. No dedicated data-broker route was located.
Official sources & citations
Other international privacy regimes
HO-49-N sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
