5.8
Law
Tooltip info. Law.
3.9
Practice
Tooltip info. Practice.
4.9
Overall
Tooltip info. Compared to previous year.
The right to privacy is protected by Armenian legislation, though there is a need for improvement taking into account modern technologies and related risks in relation to personal data management and security. In 2024, the Personal Data Protection Agency (PDPA) launched an online course on personal data protection for civil servants, aiming to address the issue of lack of awareness and knowledge. Some legal drafts published in 2024 did not comply with personal data protection principles, such as the draft amendments to the Law on Police allowing permanent police access to cameras owned by private establishments (see more information below). Among the legislative developments relevant for the area is the draft package of the Law on Public Information, which includes amendments to the Law on the Protection of Personal Data. These amendments revise the authorities of PDPA in terms of the data security oversight and oblige state oversight bodies to agree drafts that are relevant to personal data protection in advance with the PDPA. Lack of oversight of the lawfulness of surveillance activities provides grounds for distrust towards the ability of the government to protect the right to privacy in practice. In this context, the draft amendments to the Law on Police and related laws, mandating shops and other businesses with public access (such as cafes and restaurants) to install video surveillance systems at all sides of their premises, with 24/7 livestream access provided to police, raised a number of concerns. CSOs and international organisations have highlighted the disproportionality of such measures, the vague definition of data collection purposes, and the lack of guarantees for the proper and safe processing of data, among other issues. The government recalled the draft before its second reading in the National Assembly, citing the need for further discussions and a step-by-step introduction of surveillance measures. The scores in the area of Right to Privacy have not changed from 2023. The recommendations on more careful handling of data to protect the right to privacy, ensuring that the legislation on surveillance activities is designed and implemented in line with a human rights approach and transparent and accountable measures of oversight remain in place.

Standards

Everyone enjoys the right to privacy and data protection.
Armenian legislation guarantees the right to privacy and adequate protection against interference or attacks on privacy. The Constitution acknowledges the right of every person to the inviolability of their private and family life, honour, and reputation, which may be restricted only by law: for the purposes of state security, the economic welfare of the country, preventing or disclosing crimes, protecting public order, health and morals or the basic rights and freedoms of others. The Criminal Code sets out liability for the use, realisation or disclosure of information constituting personal or family secrets of a person without their consent, or acquisition or storage of that information with the aim of using, realising or disclosing that information in violation of the manner established by law. However, the Civil Code does not provide for compensation of non-material damage persons suffering from the violation of the right to privacy in private relationships. A separate provision in the Constitution mentions the right to the protection of personal data: the processing of personal data shall be carried out in good faith, for the purpose prescribed by law, with the consent of the person concerned or without such consent in case there is another legitimate ground prescribed by law. The Law on the Protection of Personal Data regulates the procedure and conditions for the handling of personal data and exercising state oversight of these data. According to the Law, the processing of personal data must pursue a legitimate aim, and the means to achieve this aim must be appropriate, necessary, and moderate. The Code on Administrative Offences sets out a number of administrative sanctions for violating the provisions of the Law on Personal Data Protection, including fines from 50,000 up to 500,000 AMD (around 120-1,200 EUR), in cases where the violation is not subject to criminal liability. The PDPA, established under the Ministry of Justice in 2015, is authorised to oversee the implementation of the legal requirements for the protection of personal data, maintain a registry of organisations processing personal data and provide protection of the relevant rights. The PDPA provides consultations, initiates administrative proceedings on the basis of citizens’ applications, provides opinions on the compatibility of laws and legal drafts on the principles of processing personal data, as well as organises trainings and awareness-raising events and publishes guides and information materials for citizens on how to protect their privacy. Although the Law on the Protection of Personal Data contains enabling provisions in line with international law, its enforcement and remedy mechanisms are weak, thus in practice these provisions are hardly met, and instances of violations take place. In May 2024, the PDPA launched an online course on personal data protection for civil servants, aiming to address the issue of lack of awareness and knowledge. All new legislative acts and amendments undergo examination by state bodies, including the PDPA. At the same time, several legal drafts published in 2024 did not comply with personal data protection principles, such as the draft amendments to the Law on Police allowing permanent police access to cameras owned by private establishments (see more information under Standard 2 below). One of the legislative developments in the area were the draft amendments to the Law on the Protection of Personal Data included in the draft package of the Law on Public Information (consulted on with CSOs at the beginning of 2024). According to these amendments, some of the PDPA’s responsibilities are delegated to the body responsible for overseeing data security, while the oversight bodies shall agree in advance with the PDPA the drafts or activities that are relevant to personal data protection. This provision may contribute to enforcing better compliance of further draft legislation and activities initiated by oversight bodies with personal data protection standards.
The state protects the right to privacy of CSOs and associated individuals.
The legislation complies with the right to privacy of CSOs; however, there are concerns with its implementation in practice. The reporting requirements for public organisations and foundations do not contain any provisions on disclosing the names of their staff, except for the executive head. The reporting form for foundations also requires the publication of the names of the founders and members of the Board of Trustees, if they received any assets and services from the foundation during the reporting year. The Law on Police sets out regulations on the use of surveillance technologies to ensure proper notification on the use of such equipment and the protection of personal information. Warning signs must be visible about stationary video and photo equipment placed in public places. When using mobile equipment, police officers must transport it in a visible manner, except in cases when surveillance is being conducted for special investigative purposes. The resulting videos or photos may be used to investigate crimes or violations of public order, to investigate complaints about officers’ actions, to promote the protection of individuals' rights and legitimate interests, or to publicise the case of disciplinary violation or its absence by a police officer after the completion of an investigation, without disclosing or only minimally identifying other persons’ identities. Use of videos or photos by the police for other purposes (including publishing) is prohibited. The list of police officers having access to the archive and the procedure for using the data is defined by the Order from the Chief of Police. Though the law prohibits using personal technical means by police officers, according to CSO reports, during the 12 June protest some police officers were filming the demonstrators with their mobile phones, which raises concerns about further possible unlawful processing of data and relevant accountability measures. Police officers can use facial recognition systems in real time to verify the similarity of a citizen to the person wanted for an alleged crime. At the same time, the law states that the image of the persons in the view of the equipment cannot be recorded, saved or processed in any other way. The Ministry of Internal Affairs presented draft amendments to the Law on Police, the Law on Electronic Communications, and related laws, aiming to combat street crime. The draft package requires shops, cafes, restaurants and other businesses to install high-quality video surveillance systems at the entrance and on all sides of their premises, with 24/7 livestream access provided to police. Despite its negative assessment by the PDPA and the Human Rights Defender of Armenia, the draft was approved by the government in April 2024 and passed on its first reading in the National Assembly in June 2024. CSOs have highlighted a number of issues related to the draft, including disproportionality, the vague definition of data collection purposes, and the lack of guarantees for the proper and safe processing of data, among others. In particular, permanent police access to cameras might enable video surveillance of CSO activists, tracking their everyday activities and business meetings, allowing disclosure of media information sources, as well as providing such information to third parties (as this possibility is provided for by the draft laws). Human Rights Watch has criticised the draft, stating that it is unjustified and interferes with privacy and other rights. Based on stakeholder concerns, the Ministry of Internal Affairs recalled the draft, noting that it was driven exclusively from considerations of public interest and security but, given the lack of a broad public consensus on the initiative, it would pursue a step-by-step approach with readiness for further discussions on the issues with stakeholders. In response, welcoming this development, CSOs have stated that it is important in such initiatives to conduct a proper study of relevant legislation and practices in the field and involve the public, civil society and the professional community in the process. Searches of the premises of CSOs or surveillance of their communications can only be carried out based on a court decision, except for in urgent cases when a delay may lead to actions of terrorism or threaten state security. In such cases, the National Security Service (NSS) can carry out surveillance within a 48-hour period before a court decision is secured. In practice, experts and CSOs are doubtful about the legitimate use of surveillance powers by the NSS and law enforcement bodies as there are no oversight and accountability mechanisms for surveillance activities, or transparent investigations of data leaks. There were no reported cases of law enforcement breaking into CSOs’ premises or accessing CSOs’ documents without due judicial authorisations during the reporting period.
4
Law
Tooltip info. Law.
2.8
Practice
Tooltip info. Practice.
3.4
Overall
Tooltip info. Compared to previous year.
Georgian legislation encompasses basic guarantees against interference or attacks on privacy, regardless of whether they are committed by state bodies, physical persons or legal entities, or whether they are carried out online or offline. However, these guarantees are still fragile and the practical implementation of the state’s duty to respect the right to privacy shows worrying trends, with leaked documents illustrating the illegal surveillance of CSOs and associated individuals. The implementation of the Law on Transparency of Foreign Influence introduces reporting requirements that significantly infringe on the privacy of CSO members, donors, board members, and employees. The overall score in this area decreased from 3.9 in 2023 to 3.4 in 2024, with decreases in the scores for Legislation (from 4.7 in 2023 to 4.0 in 2024) and Practice (from 3.0 in 2023 to 2.8 in 2024).

Standards

Everyone enjoys the right to privacy and data protection.
The Georgian Constitution and international treaties ratified by Georgia guarantee that everyone has the right to privacy and that there may be no arbitrary or unlawful interference with this right without court approval or legal necessity. The police are prohibited from searching a residence or conducting non-consensual electronic surveillance or monitoring operations without a warrant. Georgia’s Law on Personal Data Protection establishes the main legal framework for the state’s positive obligation to protect the right to privacy. Georgia also has an independent state authority, the State Inspector’s Service, that is responsible for monitoring the lawfulness of personal data processing, covert investigative actions and activities performed within the central databank of electronic communications identification data. Even with these legislative and institutional safeguards, Georgia is still far from meeting the necessary legislative threshold that would firmly guarantee the right to privacy, as was established in a study conducted in 2023 by IDFI which still applies. The main finding is that, while the right to privacy is constitutionally protected in Georgia, its implementation remains inconsistent and discriminatory. Individuals associated with CSOs or those critical of the government are particularly vulnerable to privacy infringements, largely due to the extensive use of covert surveillance measures. The study found that although Georgian law provides nominal guarantees against unauthorised interference or attacks on privacy, there are significant gaps in enforcement and judicial oversight. Agencies such as the State Security Service and its Operative–Technical Agency are granted broad surveillance powers, often executed without adequate judicial scrutiny. The approval rate for covert surveillance requests by courts exceeds 91.7 per cent, and these approvals are rarely accompanied by public justification, raising concerns about the impartiality and transparency of the process. Furthermore, the regulatory framework governing the collection, processing, and storage of personal data by government authorities is insufficient. The IDFI study highlights the State Security Service’s direct access to telecommunications networks, which allows for the collection of potentially invasive personal data without effective oversight. Judicial oversight in these matters is often inadequate, leading to a lack of accountability for abuses. The study also found a concerning absence of effective investigations or prosecutions of privacy violations committed by state authorities, resulting in a lack of recourse for those affected. These practices collectively undermine the fundamental right to privacy and highlight the need for stronger legal protections and more rigorous oversight mechanisms to prevent abuse. On 1 August 2024, the Minister of Justice of Georgia approved the Order on Approval of the Rules for Registration, Financial Declaration Submission, and Monitoring of Organisations Pursuing the Interests of Foreign Powers (Order No. 1019) in relation to the ‘foreign agents law’. Order No. 1019 introduces a detailed financial declaration form consisting of 12 sections, which organisations that will be registered as ‘entities of foreign influence’ are required to complete. The submitted information, containing extensive financial details, will be made publicly available in a registry intended to stigmatise and discredit these organisations, specifically media entities and CSOs. Additionally, the declaration form demands the disclosure of personal data, not only from the organisation's employees but also from individuals who have financial ties to the organisation. On 20 September 2024, Order No. 1019 was amended with an updated annex to the implementing rules. While these amendments were introduced swiftly, they did not substantially address the concerns raised by civil society and international observers. Key issues, such as the excessive scope of data collection and potential risks to privacy, remain unaddressed. The changes have been criticised for failing to align with international standards, particularly those concerning the proportionality and necessity of such measures.
The state protects the right to privacy of CSOs and associated individuals.
The law protects CSOs from state authorities entering their premises or accessing their documents without court approval or legal necessity and prohibits the conducting of non-consensual electronic surveillance or monitoring operations without a warrant. There have been no recorded cases of unlawful searching of CSOs’ offices or the seizing of documents. However, surveillance and unauthorised monitoring of CSO representatives remains a prevalent and concerning issue. The Law on Transparency of Foreign Influence and its implementing regulations have significant implications for the privacy of members, donors, board members, and employees of NNLEs. Under the requirements of the law, NNLEs must submit the aforementioned detailed financial declarations that include sensitive information such as identification data, financial transactions, and donor information. The regulation governing this process does not provide specific measures to ensure the confidentiality of this information, which is concerning for the privacy of individuals and organisations involved. While Georgian legislation, including the Constitution of Georgia and the Law on Personal Data Protection, aims to protect personal information, the requirements of the ‘foreign agents law’ directly contradict these protections. The related financial declarations and other information required by the law are publicly accessible, meaning personal data and commercially sensitive information could be exposed without appropriate safeguards. This lack of confidentiality effectively constitutes unauthorised interference with privacy, particularly since individuals are not given the opportunity to refuse consent or challenge the disclosure of their data. Public disclosure of such data could significantly discourage donors and organisations from participating in CSO activities, which undermines the principle of privacy protection for CSO members and associates. While Order No. 1019 does not explicitly mention any new provisions for accessing CSOs’ premises based on objective grounds and appropriate judicial authorisation. However, the general expansion of the National Agency of Public Registry’s authority to monitor and verify compliance with the law — including the ability to inspect financial and operational records — raises concerns about potential overreach into the operations of CSOs without proper legal oversight. It remains critical that any physical access to CSOs’ premises is based on transparent and objective criteria, supported by judicial authorisation, to avoid arbitrary interference in CSOs’ activities. The situation is severe since IDFI’s findings in this regard reveal an alarming absence of accountability for state violations of privacy. Despite numerous documented incidents of unlawful surveillance over the years, in 2024, state authorities still have not faced any repercussions and investigations rarely lead to prosecutions. Order No. 1019 grants broad monitoring powers to the National Agency of Public Registry, including requesting information from NNLEs and related individuals to verify compliance. This broad authority raises questions about the proportionality and legitimacy of surveillance activities, especially in the absence of judicial oversight. Order No. 1019 does not mention any requirement for preliminary authorisation issued by an independent judicial authority, which would be a critical safeguard to ensure that any surveillance activities are legitimate and proportionate. Order No. 1019 also grants the National Agency of Public Registry broad authority to monitor compliance with the law, which includes inspecting income, revenue, and assets of NNLEs. This authority is not limited by clearly defined criteria and lacks specific requirements for obtaining judicial authorisation before accessing sensitive documents or information. As such, there is an increased risk of unauthorised access to CSO offices or documentation without appropriate legal procedures, which would infringe on the operational independence of CSOs and potentially deter them from conducting their activities freely and effectively. This environment of impunity exacerbates the already existing challenges faced by CSOs, leading to self-censorship and a diminished capacity to fulfil their roles as watchdogs of government activities. CSOs lack adequate protection against the illegitimate collection, processing, and storage of their data, whether conducted online or offline

Recommendation

  • The Ministry of Finance provides the definition of ‘grant’ in accordance with best international practices and in consultation with CSOs, and does not treat grant projects or other non-profit activities as economic activities;
  • Law enforcement bodies carry out proper examination and transparent investigations and apply the relevant sanctions in cases where police officers have abused their power in the policing of assemblies, while at the same time the political leadership does not provide any assessment of police actions before the results of official investigations are known;
  • The National Assembly establishes mechanisms for mandatory public consultation on draft legislation produced by National Assembly members and for CSO engagement in both the early stages of legal drafts and during the final revision of the drafts received by the government (including through engagement at the level of Standing Committees);
  • The National Assembly makes the necessary legislative changes to expand the possibilities for CSOs to represent public interests in the courts on cases within the scope of their goals and ensures that they can use this right in practice through alleviating any excessive requirements and related bureaucratic procedures;
  • The government ensures that the legislative framework on surveillance activities is developed in accordance with international law and in consultation with CSOs, while its provisions are followed in practice, with transparent and accountable measures in case of non-compliance;
  • The state provides adequate protections for CSOs, including through: adopting anti-discrimination laws and establishing an anti-discrimination body, taking legislative and practical measures against SLAPPs in line with the Council of Europe’s recommendations adopted in April 2024; issuing public statements in support of CSOs that are targeted by third parties, and ensuring proper investigation of attacks against CSOs and activists within a reasonable timeframe; and
  • The government (particularly the Ministry of Finance) and the National Assembly create a more favourable tax environment to improve CSOs’ possibilities to seek funding and in-kind support from diverse sources, including individual and business donations and direct entrepreneurship activities.
  • Repeal all discriminatory and stigmatising legislation restricting freedom of expression and freedom of association for CSOs, media representatives, and vulnerable groups including the Law on Transparency of Foreign Influence. Once all discriminatory and stigmatising legislation restricting the freedoms of expression and association for CSOs, media representatives, and vulnerable groups is repealed:
  • Conduct a comprehensive revision of the Code of Administrative Offences to remove unjustified restrictions on the rights to freedom of peaceful assembly and expression (for example, detaining individuals to prevent their participation or imposing administrative imprisonment without proper safeguards);
  • Implement measures to protect CSOs and individuals associated with them from interference and attacks, ensuring accountability for any acts of violence or intimidation against them;
  • Strengthen the regulatory framework governing the collection, processing and storage of personal data by government authorities, ensuring it meets international standards for privacy protection;
  • Ensure that CSOs are free to seek, receive and use financial and material resources for the pursuit of their objectives, without undue restrictions and regardless of their source (domestic or foreign); and
  • The government should design and implement effective oversight mechanisms to ensure accountability and transparency in law enforcement agencies’ handling of digital rights and privacy.

Download reports