Skip to content

Evidence request lists

Armenia Law on Protection of Personal Data (2015)

Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Accountability

AM-DPA-12
Records of Processing Activities

Maintain internal records of processing activities including purposes, categories, recipients, and safeguards.

Artefacts an auditor will ask for
  • Records of processing activities
Where this commonly fails
  • No records of processing

Automated Processing

AM-DPA-14
Automated Decision-Making Safeguards

Provide safeguards where decisions producing legal effects are based solely on automated processing, including human review on request.

Artefacts an auditor will ask for
  • Human-review / objection for solely-automated decisions
Where this commonly fails
  • Solely-automated decisions without safeguards

Consent

AM-DPA-02
Data Subject Consent

Obtain free, informed, specific, and unambiguous consent from the data subject before processing, and allow withdrawal at any time.

Artefacts an auditor will ask for
  • Consent records (free, informed)
Where this commonly fails
  • Processing without valid consent

Cross-Border

AM-DPA-06
Cross-Border Transfer Conditions

Transfer personal data outside Armenia only to jurisdictions with adequate protection or under contractual, consent, or PDPA-approved safeguards.

Artefacts an auditor will ask for
  • Transfer assessment (adequacy/safeguards/consent)
Where this commonly fails
  • Transfer without a lawful basis

Data Principles

AM-DPA-09
Data Minimisation and Purpose Limitation

Collect only data necessary for declared purposes and do not process for incompatible new purposes without further lawful basis.

Artefacts an auditor will ask for
  • Purpose specification & minimisation controls
Where this commonly fails
  • Excessive collection / purpose creep

Incident

AM-DPA-15
Breach Response and Notification

Detect, contain, and document personal data breaches, and notify PDPA and affected data subjects in line with regulator guidance.

Artefacts an auditor will ask for
  • Breach detection, recording & notification
Where this commonly fails
  • No breach response process

Lawfulness

AM-DPA-01
Lawful Basis for Processing

Process personal data only with a defined lawful basis under Armenian law, primarily data subject consent or statutory authority.

Artefacts an auditor will ask for
  • Lawful-basis register
Where this commonly fails
  • No legal ground for processing

Lifecycle

AM-DPA-10
Retention and Deletion

Define retention periods proportionate to purposes and delete or anonymise data when no longer needed.

Artefacts an auditor will ask for
  • Retention schedule & deletion process
Where this commonly fails
  • Indefinite retention

Marketing

AM-DPA-18
Direct Marketing Restrictions

Conduct direct marketing only with prior consent and provide a simple opt-out mechanism on every communication.

Artefacts an auditor will ask for
  • Marketing opt-out / consent
Where this commonly fails
  • Marketing without consent/opt-out

People

AM-DPA-16
Staff Training and Confidentiality

Train staff who process personal data and impose confidentiality obligations enforceable beyond employment.

Artefacts an auditor will ask for
  • Confidentiality undertakings & staff training
Where this commonly fails
  • Staff disclose / untrained

Regulator Engagement

AM-DPA-17
PDPA Inspections and Cooperation

Cooperate with Personal Data Protection Agency inspections, requests for information, and corrective orders within statutory timelines.

Artefacts an auditor will ask for
  • Cooperation with the authorized body's inspections
Where this commonly fails
  • Obstructing supervision

Regulator Notification

AM-DPA-05
Notification to Personal Data Protection Agency

Notify the Personal Data Protection Agency (PDPA) before processing where required, including describing purposes, categories, and recipients.

Artefacts an auditor will ask for
  • Notification/registration with the authorized body
Where this commonly fails
  • Processing without required notification

Rights

AM-DPA-04
Data Subject Rights Fulfilment

Provide data subjects with rights of access, rectification, deletion, restriction, and objection, with documented response procedures and timelines.

Artefacts an auditor will ask for
  • Rights-request handling procedure
Where this commonly fails
  • Rights requests not actioned

Security

AM-DPA-11
Security of Processing

Implement organisational and technical measures protecting personal data against unauthorised access, alteration, disclosure, or loss.

Artefacts an auditor will ask for
  • Technical & organisational security measures
Where this commonly fails
  • Inadequate security

Sensitive Data

AM-DPA-03
Special Category Data Restrictions

Apply heightened controls to special category data (health, biometrics, race, religion, political views) including explicit consent or statutory exception.

Artefacts an auditor will ask for
  • Special-category processing conditions
Where this commonly fails
  • Sensitive data without a lawful condition

Third Party

AM-DPA-07
Processor and Sub-Processor Oversight

Engage processors only under written contract specifying confidentiality, security measures, and processing instructions; control sub-processor chain.

Artefacts an auditor will ask for
  • Processor agreement restricting use
Where this commonly fails
  • Processor engaged without binding terms

Transparency

AM-DPA-08
Information to Data Subjects at Collection

Inform data subjects at the point of collection about the operator, purposes, recipients, retention period, and their rights.

Artefacts an auditor will ask for
  • Information notice at collection
Where this commonly fails
  • No notice to data subjects

Vulnerable Groups

AM-DPA-13
Children and Minors

Apply additional safeguards to processing of children's data, including parental consent where required by Armenian law.

Artefacts an auditor will ask for
  • Parental consent / age-appropriate safeguards
Where this commonly fails
  • Children's data without safeguards
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Armenia Law on Protection of Personal Data (2015) framework page.