Armenia Law on Protection of Personal Data (2015)
Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Accountability
Maintain internal records of processing activities including purposes, categories, recipients, and safeguards.
- Records of processing activities
- No records of processing
Automated Processing
Provide safeguards where decisions producing legal effects are based solely on automated processing, including human review on request.
- Human-review / objection for solely-automated decisions
- Solely-automated decisions without safeguards
Consent
Obtain free, informed, specific, and unambiguous consent from the data subject before processing, and allow withdrawal at any time.
- Consent records (free, informed)
- Processing without valid consent
Cross-Border
Transfer personal data outside Armenia only to jurisdictions with adequate protection or under contractual, consent, or PDPA-approved safeguards.
- Transfer assessment (adequacy/safeguards/consent)
- Transfer without a lawful basis
Data Principles
Collect only data necessary for declared purposes and do not process for incompatible new purposes without further lawful basis.
- Purpose specification & minimisation controls
- Excessive collection / purpose creep
Incident
Detect, contain, and document personal data breaches, and notify PDPA and affected data subjects in line with regulator guidance.
- Breach detection, recording & notification
- No breach response process
Lawfulness
Process personal data only with a defined lawful basis under Armenian law, primarily data subject consent or statutory authority.
- Lawful-basis register
- No legal ground for processing
Lifecycle
Define retention periods proportionate to purposes and delete or anonymise data when no longer needed.
- Retention schedule & deletion process
- Indefinite retention
Marketing
Conduct direct marketing only with prior consent and provide a simple opt-out mechanism on every communication.
- Marketing opt-out / consent
- Marketing without consent/opt-out
People
Train staff who process personal data and impose confidentiality obligations enforceable beyond employment.
- Confidentiality undertakings & staff training
- Staff disclose / untrained
Regulator Engagement
Cooperate with Personal Data Protection Agency inspections, requests for information, and corrective orders within statutory timelines.
- Cooperation with the authorized body's inspections
- Obstructing supervision
Regulator Notification
Notify the Personal Data Protection Agency (PDPA) before processing where required, including describing purposes, categories, and recipients.
- Notification/registration with the authorized body
- Processing without required notification
Rights
Provide data subjects with rights of access, rectification, deletion, restriction, and objection, with documented response procedures and timelines.
- Rights-request handling procedure
- Rights requests not actioned
Security
Implement organisational and technical measures protecting personal data against unauthorised access, alteration, disclosure, or loss.
- Technical & organisational security measures
- Inadequate security
Sensitive Data
Apply heightened controls to special category data (health, biometrics, race, religion, political views) including explicit consent or statutory exception.
- Special-category processing conditions
- Sensitive data without a lawful condition
Third Party
Engage processors only under written contract specifying confidentiality, security measures, and processing instructions; control sub-processor chain.
- Processor agreement restricting use
- Processor engaged without binding terms
Transparency
Inform data subjects at the point of collection about the operator, purposes, recipients, retention period, and their rights.
- Information notice at collection
- No notice to data subjects
Vulnerable Groups
Apply additional safeguards to processing of children's data, including parental consent where required by Armenian law.
- Parental consent / age-appropriate safeguards
- Children's data without safeguards
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Armenia Law on Protection of Personal Data (2015) framework page.