Law / Armenia

Armenia

10 of 13 named instruments researched to a stage, across four of the six areas of law we track: 9 in force and 1 proposed. As of 18 September 2026.

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 proposed

Research summary (258 words)

Armenia has no domestic statute imposing AI-transparency or output-labelling duties, AI-risk obligations, training-data duties, prohibited-practices bans, governance duties, or sector-specific AI rules.

Its notable development is signing, alongside roughly a dozen other Council of Europe member and observer states, the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225); the Council of Europe's own overview page lists Armenia among the treaty's signatories and lists only the European Union among the parties that have ratified it, so the Convention does not yet bind an app operating in Armenia.

On 6 January 2026 the Armenian Government approved a Doctrine of Economic and Institutional Transformation that names the development of artificial intelligence technologies as an economic priority and envisages a future national AI policy framework; this is a strategic policy document rather than binding legislation or regulation, and it creates no enforceable behavioural obligation for an AI system, so it is described here rather than recorded as an instrument.

The Law on State Support of the High-Technology Sector, Law No. HO-498-N (2024), is an industrial-policy payroll-tax incentive programme for the high-technology sector generally, researched under this jurisdiction's compute-topic document; it imposes no disclosure, transparency or accountability duty on an AI system and is not recorded here.

The Law on Protection of Personal Data's right concerning decisions made on the basis of processing (Art. 16) attaches to the processing of personal data rather than to an AI system as such, and is researched under this jurisdiction's privacy-topic document rather than here.

AI governance

Council of Europe Framework Convention on Artificial Intelligence, signed by Armenia

Council of Europe Framework Convention on Artificial Intelligence and Human Rights Democracy and the Rule of Law, Council of Europe Treaty Series No. 225, opened for signature 5 September 2024; signed by Armenia, not yet ratifiedOfficial description of the Framework Convention on Artificial Intelligence and its list of signatories and parties

Proposed: draft date not recorded. Signed, with consent not yet expressed, dated 27 January 2026, as of 12 September 2026. Binds public and private bodies.

What this law does

The Council of Europe's own list of signatories to the Framework Convention on Artificial Intelligence names Armenia as a signatory, and its list of parties that have ratified the Convention names only the European Union, so the treaty has not been ratified or given effect in Armenian domestic law and does not currently bind an app operating in Armenia.

As drafted, it would require activities within the lifecycle of an artificial intelligence system to be consistent with human dignity, equality and non-discrimination, privacy, transparency and accountability, including carrying out iterative risk and impact assessments on human rights, democracy and the rule of law and establishing prevention and mitigation measures.

It covers use of an AI system by a public authority, including a private actor acting on the authority's behalf, and by a private actor generally, and it would require giving notice that a person is interacting with an AI system rather than a human being, and providing an effective means to challenge a decision made through, or substantially based on, such a system.

What it requires

Privacy law6 instruments, 6 in force

Research summary (244 words)

Armenia's Law on Protection of Personal Data, Law No. HO-49-N, in force since 1 July 2015, replaced a 2002-era law and is a Convention 108-family statute, not a General Data Protection Regulation (GDPR) transposition: it is markedly thinner than this batch's other jurisdictions on modern GDPR-specific features, most notably that no breach-notification duty appears anywhere in its 29 articles, confirmed by a full reading of the Act's security article (Art. 19) and a full article-by-article map rather than inferred from the Act's brevity.

Art. 13 gives biometric data a dedicated, if minimal, processing article requiring the data subject's consent except where a law-defined purpose can only be achieved through that processing, distinct from the general special-category rule at Art. 12; Art. 3(13)'s biometric-data definition is bare, with no processing-method or unique-identification qualifier and no named modality, so whether an identifier derived from a recording is included or excluded is not addressed by the statute's text.

Cross-border transfer (Art. 27) runs on an adequacy-list mechanism, consent, or the authorized body's written permission for a contract it has approved as providing adequate safeguards, a real and conditioned regime, more developed than the rest of the Act's brevity would predict.

Armenia ratified the Council of Europe's Convention 108+ modernizing protocol in 2022, one of the first roughly 16 states to do so, recorded here as context for the domestic statute rather than as a separate instrument. All quotations of Armenian-language text here are working translations, not an official or certified translation.

Biometric privacy

Law on Protection of Personal Data, biometric data provisions

Law of the Republic of Armenia on Protection of Personal Data, Law No. HO-49-N, Arts. 3(13), 13, 19(4), 19(6), 23(3)official primary text, Armenian Legal Information System (ARLIS), translated by the researcher

In force since 1 July 2015. Binds public and private bodies.

What this law does

Art. 3(13) defines biometric personal data only as information characterizing a person's physical, physiological and biological characteristics, a bare, generic definition with no processing-method qualifier, no unique-identification qualifier, and no named modality such as voice or face.

Art. 13 requires the data subject's consent as the default basis for processing biometric data, except where a law-defined purpose can only be achieved through that processing; no modality-specific variation exists.

Art. 19(4) and (6) defer retention and destruction specifics to a separate government resolution, not covered here, requiring only that physical-media storage of biometric data outside information systems be protected from unauthorized access, use, destruction, alteration, blocking, copying, and distribution. Art. 23(3) additionally requires the processor to notify the authorized body before processing biometric or special-category data of its intent to do so, a pre-processing notification duty.

Because the Art. 3(13) definition has no derivation or identification qualifier at all, whether it includes or excludes an identifier derived from a photo, video, or audio recording is not addressed by the statute's text.

What it requires

Comprehensive regime

Law on Protection of Personal Data, comprehensive regime

Law of the Republic of Armenia on Protection of Personal Data, Law No. HO-49-N (2015), Arts. 1, 3-8official primary text, Armenian Legal Information System (ARLIS), consolidated Armenian-language text, translated by the researcher

In force since 1 July 2015. Binds public and private bodies.

What this law does

Armenia's Law on Protection of Personal Data, Law No. HO-49-N, took effect 1 July 2015 (Art. 28), replacing a 2002-era law on the same date. Secondary sources give the adoption date as 18 May or 8 May 2015; only the confirmed in-force date is recorded.

General principles at Arts. 4-8 cover legality, proportionality, accuracy, minimal subject involvement, and lawfulness-of-processing grounds, across 29 articles total, considerably shorter and less elaborated than several of this jurisdiction's regional peers. All translations of Armenian-language text here are working translations, not an official translation.

What it requires

Cross border transfer

Law on Protection of Personal Data, cross-border transfer

Law of the Republic of Armenia on Protection of Personal Data, Law No. HO-49-N, Art. 27official primary text, Armenian Legal Information System (ARLIS), translated by the researcher

In force since 1 July 2015. Binds public and private bodies.

What this law does

Art. 27 permits cross-border transfer with the data subject's consent, or where the transfer follows from or is necessary for the purposes of processing. Absent authorized-body permission, transfer to a state providing an adequate level of protection is permitted where adequacy follows an international treaty or the destination is on the authorized body's officially published list, reviewed at least annually.

Transfer to a non-adequate state requires the authorized body's prior written permission, granted only where a contract provides safeguards the body has itself approved as adequate; the processor must apply in writing before transfer, naming the destination country, recipient, data description, purpose, and the contract or draft contract, and the authority must approve or reject within 30 days. No standardized model-contract template mechanism exists, and no data localization is compelled.

What it requires

Data subject rights

Law on Protection of Personal Data, data subject rights

Law of the Republic of Armenia on Protection of Personal Data, Law No. HO-49-N, Arts. 15-17official primary text, Armenian Legal Information System (ARLIS), translated by the researcher

In force since 1 July 2015. Binds public and private bodies.

What this law does

Art. 15 gives a data subject the right to receive information about their own data. Art. 16 gives a right regarding decisions made on the basis of processing; its relationship to specifically automated processing, versus any decision based on processing at all, needs a closer read before it is treated as an automated-decision-objection right in the General Data Protection Regulation (GDPR) Art. 22 sense. Art. 17 gives a right to appeal a processor's action or inaction.

No dedicated deletion or portability article was found beyond what falls out of Art. 19's general duty to destroy data when it is no longer needed.

What it requires

Enforcement supervision

Law on Protection of Personal Data, enforcement

Law of the Republic of Armenia on Protection of Personal Data, Law No. HO-49-N, Art. 24official primary text, Armenian Legal Information System (ARLIS), translated by the researcher

In force since 1 July 2015. Binds public and private bodies.

What this law does

Art. 24 creates an independent Authorized Body for Personal Data Protection, structured by government resolution, with powers to audit compliance, apply administrative-liability measures established by law, demand suspension or cessation of unlawful processing, demand rectification, blocking, or destruction, block processing following review of a pre-processing notification, maintain a processor registry, certify adequate-security electronic systems, inspect devices and documents, apply to court, investigate individual complaints, publish an annual public report, and provide guidance.

No compensation or damages term was found anywhere in the Act; specific fine amounts live in the separate RA Code on Administrative Offences, which is not covered here, so no figures are stated. Individual recourse runs through the Art. 17 appeal right or the authority's own court-application power, not a dedicated statutory civil-damages provision inside this Act; general Civil Code tort provisions might independently support a damages claim but are not addressed here.

What it requires

Sensitive categories

Law on Protection of Personal Data, special category data

Law of the Republic of Armenia on Protection of Personal Data, Law No. HO-49-N, Art. 12official primary text, Armenian Legal Information System (ARLIS), translated by the researcher

In force since 1 July 2015. Binds public and private bodies.

What this law does

Art. 12 sets a single, general condition for special-category processing: processing without the data subject's consent is prohibited except where it is directly provided for by law, and processing must stop immediately once its legal basis or purpose lapses. This is a single ground, consent or a legal provision, considerably thinner than a multi-ground special-category structure.

Which specific categories Art. 12 governs beyond this general rule is not enumerated here, and biometric data is instead addressed by a separate, dedicated article (Art. 13), not folded into this general special-category rule.

What it requires

Scraping law2 instruments, 2 in force

Research summary (512 words)

Armenia has no scraping-specific statute, so general law governs each dimension separately.

The current Criminal Code of the Republic of Armenia, Law No. HO-199-N (adopted 2021, in force since 1 July 2022), Chapter 38, criminalises penetrating a computer, computer system or computer network without permission under an authorisation test framed by law, contract or other legitimate basis (Art. 359), and separately criminalises intercepting or appropriating data not intended for general use without such permission, done for the purpose of using it or making it available to others (Art. 362).

Reading a public, unauthenticated page carries no obvious element of penetrating a protected system or appropriating data withheld from general use, so a plain reading of both articles leaves open-web crawling of a public page outside their reach, though no reported Armenian case has tested the point. The 2021 Code replaced a 2003-era Criminal Code whose Arts. 253 and 254 addressed similar conduct under different numbers; that earlier code is no longer in force.

No Armenian court has ruled on the enforceability of a browsewrap or clickwrap terms of service against a scraper, though Art. 359's authorisation test rests on law, contract, or other legitimate basis as three independent grounds for a right of access, a textual hook a scraper's breach of a website's terms could in principle engage even without technical circumvention; this reading is untested.

The Law on Copyright and Related Rights, Law No. AL-142 (2006, as amended), permits free use of a lawfully published work for quotation, criticism, research or informational purposes, including reproduction of newspaper and magazine extracts in the form of a press summary (Art. 22(2)(a)), but Armenia has not enacted a text-and-data-mining exception distinct from that general, attribution-conditioned, purpose-limited ground, a materially narrower basis for training a model on scraped text than a dedicated text and data mining (TDM) exception would provide.

The same Law confers a sui generis right on the maker of a database to prohibit extraction or re-utilisation of the whole or a substantial part of a database's contents (Arts. 58-59), a genuine database right on the EU model, researched here as its own instrument.

Armenia's Law on Protection of Personal Data, Law No. HO-49-N (2015), researched as this jurisdiction's privacy-topic document, applies to personal data with only a narrow, subject's-own-act publicity ground (Art. 11) rather than a general carve-out for publicly accessible information, and conditions cross-border transfer on an adequacy list, consent, or the data protection authority's approval of a contract (Art. 27); scraping personal data from a public Armenian website therefore remains subject to that Act's lawful-basis and cross-border-transfer duties.

No Armenian statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

The Copyright Law's anti-circumvention provision (Art. 67) attaches copyright-infringement-level liability to circumventing a technological measure protecting copyrighted content, which could reach defeating a paywall or access control to scrape gated content, but no reported case applies it to scraping specifically. All quotations of Armenian-language text here are the researcher's own working translations, not an official or certified translation.

Computer misuse

Criminal Code, unauthorised computer access and illegal appropriation of data

Criminal Code of the Republic of Armenia, Law No. HO-199-N (2021), Arts. 359, 362official consolidated Armenian-language text, Armenian Legal Information System (ARLIS)

In force since 1 July 2022. Binds public and private bodies.

What this law does

Article 359 criminalises penetrating a computer, computer system or computer network by gaining access without permission, where the person has no such right under law, contract or other legitimate basis, and the act negligently causes destruction, alteration, damage, distortion, blocking, copying of data, or other material harm (base tier, up to one year's imprisonment); an aggravated tier applies where the act circumvents a protective system, uses special technical means, official position, group commission, targets data protected by law, or negligently causes especially large damage (up to two years).

Article 362 separately criminalises intercepting or appropriating data stored on a computer, system, network or other computer equipment that is not intended for general use, without permission under law, contract or other legitimate basis, done for the purpose of using that data or making it available to others (base tier, up to two years' imprisonment), with aggravated tiers up to five years where the act is also accompanied by unauthorised penetration, targets legally protected data, is done for mercenary motive, or intercepts data in transit, and up to six years where committed by a criminal organisation or causing especially large damage.

Because Art. 362's base offence is scoped to data 'not intended for general use', appropriating data a website makes available to the general public sits outside a plain reading of the provision.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (293 words)

Armenia has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Law on Copyright and Related Rights, Law No. AL-142 (2006, as amended), is the only law reaching an aggregator's reproduction of news content.

Its free-use provision permits, without the author's consent, quotation of a lawfully published extract for scientific, research, polemic, critical or informational purposes, including reproduction of newspaper and magazine extracts in the form of a press summary (Art. 22(2)(a)), and separately permits the press and broadcasters to reproduce lawfully published articles on current economic, political, social or religious issues unless the author has prohibited that use beforehand (Art. 22(2)(c)); both grounds require mention of the author's name and the work's origin and are conditioned on not prejudicing the author's normal exploitation of the work, with no reported Armenian decision applying either to a systematic news aggregator as opposed to an individual quoting a published work.

Article 55 gives a publisher an exclusive right over the typographical arrangement of its editions, that is, the printed layout, but this is not a neighbouring right over the substance of the reported content of the kind the European Union's Digital Single Market Directive Article 15 creates, so no press-publisher right of that kind exists here.

No statute or reported case addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law was located. The Law predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

All quotations of Armenian-language and English-translated text here are the researcher's own working translations except where quoted from the Intellectual Property Agency's own official English translation.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.