An Enterprise Customer Sent a Security Questionnaire: The Armenian Supplier’s Checklist

Yerevan rooftops and cables at dusk with concrete apartment blocks against a fading violet sky

At a glance

  • Armenia is not on the European Commission’s GDPR adequacy list, so your EU customer needs its own Chapter V transfer mechanism, in practice the Commission’s standard contractual clauses under Article 46(2)(c).
  • Remote access by your engineers to an EU customer’s systems is a transfer under the European Data Protection Board’s three part test, even when no data is copied to Armenia.
  • Armenia’s Law on Personal Data Protection requires a written processing instruction between the parties (Article 14), and the instructing party keeps statutory responsibility for the other’s processing.
  • A named subprocessor register, one row per entity with access level and transfer basis, is the single most commonly requested document after the data processing agreement.
  • Armenia keeps its own adequate protection country list, updated by a decision of 18 June 2026. That list governs data you send onward out of Armenia.

Armenia is absent from the European Commission’s list of countries with an adequacy decision, and that single fact drives most of what an enterprise security questionnaire asks your company to produce. Your customer cannot move personal data to a supplier in a non-adequate country on trust. It needs a transfer mechanism under Chapter V of the GDPR, in practice the Commission’s standard contractual clauses adopted under Article 46(2)(c), and it needs a file showing that signing those clauses with you is defensible.

The questionnaire is that file. Every item in it maps to an obligation the customer carries, so an answer that reads as evasive stalls the deal inside procurement, before legal ever sees it.

Why enterprise customers send these questionnaires

Article 28 of the GDPR permits a controller to engage only processors that provide sufficient guarantees of appropriate technical and organisational measures. The controller must be able to demonstrate that it assessed those guarantees, and the completed questionnaire, with the evidence attached to it, is that demonstration. Auditors ask to see it, and so, occasionally, does a supervisory authority.

A supplier outside the EEA adds a second file. The customer must document the transfer, identify its Chapter V mechanism, and assess whether the law of the destination country undermines the protection those clauses promise. Your answers are the raw material for that assessment, which is why questions about government access requests and about who can reach the data sit alongside the routine security items.

Remote access counts. Under the European Data Protection Board’s three part test, and as set out in EDPB Opinion 22/2024, making personal data available to an entity in a third country is a transfer even when nothing is copied and the data stays on the customer’s servers. An Armenian engineer holding a support login to an EU customer’s production system triggers the same analysis as a database export.

What is different about an Armenian supplier

The Commission’s adequacy list covers Andorra, Argentina, Brazil, Canada for commercial organisations, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay, and participants in the EU to US Data Privacy Framework. Armenia does not appear on it. For background on how the two regimes diverge more generally, see our guide to GDPR and Armenian data protection law.

Standard contractual clauses are the practical route. Binding corporate rules under Article 47 are designed for intra-group transfers and are unavailable to an independent supplier. Article 46(2)(d) covers clauses that a supervisory authority adopts and the Commission approves, a separate instrument from the Commission’s own clauses under Article 46(2)(c). Procurement teams sometimes cite the two together; the paper you will be sent is the Commission’s.

The terminology inverts

Armenia’s Law on Personal Data Protection of 18 May 2015, as amended through 4 December 2025, calls the party that determines the purpose of processing the “processor” and the party that processes on instruction the “authorised person”. The GDPR uses those words the other way round, which produces confused questionnaire answers when a supplier maps the Armenian terms straight across. Article 14 requires a written instruction between the two, and the instructing party retains statutory responsibility for what the other does with the data. One well drafted data processing agreement can carry both the customer’s Article 28 requirement and the Armenian written instruction requirement, provided it is drafted to do so.

Onward transfers out of Armenia

Article 27 of the same law governs personal data leaving Armenia, which is the moment you route customer data to a subprocessor in a third country. The inbound direction, your EU customer sending data to you, is governed by the GDPR on the customer’s side. Suppliers running hosting, error monitoring or support tooling abroad hit Article 27 routinely without noticing.

Transfers to a state on Armenia’s official adequate protection list, or made under an international treaty, proceed without separate authorisation. Armenia maintains such a list, updated by a decision of 18 June 2026 and covering roughly 53 countries and entries, among them the EU and EEA states, Argentina, Canada, Israel, Japan, New Zealand, Singapore, South Korea, Uruguay and Russia, with an entry for United States organisations whose limits have not been spelled out in published guidance. For a destination outside the list, the transfer requires prior permission from the authorised body together with contractual safeguards that body has approved. The statutory review period is 30 days, and the list is republished annually.

The document checklist

Six documents answer most of what arrives. Assemble them once and the next questionnaire becomes an editing job.

  1. Data processing agreement. The customer sends its own paper. Read it against the Armenian written instruction requirement before signing, and check that its retention and deletion terms match what your systems actually do.
  2. Subprocessor register. One row per subprocessor: legal entity and country, purpose, categories of personal data reached, level of access, where processing and access physically occur, the transfer basis for that subprocessor, and confirmation that the customer authorised it. Append your vetting and offboarding process.
  3. Transfer paperwork. The executed standard contractual clauses with the correct module for the relationship, plus your written input into the customer’s transfer impact assessment, covering the access requests you could receive and your ability to challenge them.
  4. Security policy summary. Two to four pages on access control, encryption in transit and at rest, logging, change management and secure development. Customers rarely accept a flat refusal to share anything, and they rarely need your full internal policy set.
  5. Incident response summary. Who is notified internally, the trigger for telling the customer, the channel used, and the contractual notification window you are prepared to commit to.
  6. Certifications and test evidence. An ISO 27001 certificate with its statement of applicability, a SOC 2 Type II report if you hold one, and a summary of your most recent penetration test with remediation status. No GDPR certificate exists, and offering one marks the response as inexperienced.

Need help with an enterprise security questionnaire?

Tell us about your situation and we’ll respond within 1 business day.

Get a Free Consultation

Common questionnaire sections and how to answer them

Entity and ownership details

Questionnaires open with the registered name, registration number, legal address and ownership chain. Take these from your company registration record so the answers match the state register character for character. A mismatch here is what sends the form back before anyone reads the security content.

Data flows and hosting

Name the countries. An answer saying data is hosted securely in the cloud generates a follow up every time. State the hosting provider, the region, whether any replica or backup sits elsewhere, and whether staff outside that region can reach production. If your engineers in Armenia access an EU hosted environment, disclose it here; the customer’s transfer analysis depends on it, and discovering it later costs you credibility on every other answer you gave.

Subprocessors

Name every entity, including the ones that feel invisible: ticketing, error monitoring, transactional email, analytics, and payroll platforms that touch customer contact data. Article 28(2) of the GDPR requires the customer’s prior authorisation for engaging a new subprocessor, so the register needs a change notification commitment beside it, with a notice period and an objection right the customer can actually exercise.

Breach and incident notification

Your contract will carry a notification window running to the customer. Commit only to a window your on call rota can meet on a Saturday night, because the customer’s own 72 hour clock under GDPR Article 33 starts when it becomes aware, and it will push that pressure down the chain to you.

Armenian regulatory notification is a separate question, and the first thing to establish is your own size. Armenia’s Law on Cybersecurity, HO-442-N, is not confined to operators of critical infrastructure. Article 1(3)(1) catches a legal entity or individual entrepreneur that both works in one of the sectors listed in Article 16(4) and operates an information system or critical information infrastructure. Those are two limbs, not one. Information technology, expressly including digital infrastructure, is Article 16(4)(9); database management and operation is Article 16(4)(12). Neither point is limited to infrastructure operators, and there is no exemption for a supplier whose clients are all foreign. The common answer, that the company does not run critical infrastructure, therefore does not dispose of the question.

The exclusion that does dispose of it for many suppliers is Article 1(4). An entity meeting the micro or small enterprise criteria falls outside the law altogether, unless it operates critical information infrastructure. Under Article 2(1) of the Law on State Support to Small and Medium Entrepreneurship the small enterprise criteria are an average listed workforce of up to 50 and previous year revenue, or previous year end balance sheet assets, not exceeding AMD 500,000,000. A great many Armenian development and BPO companies sit inside that exclusion. It turns on your own headcount and accounts, so settle it before you answer the questionnaire.

If the exclusion does not cover you, the duties sit in Article 11. Notify the Autonomous Body, the Information Systems Regulation Commission, immediately on becoming aware and in any event within 24 hours, where the incident has significant impact or such impact can reasonably be presumed. Article 11(2) defines significant impact, so not every minor incident triggers a report. Updated information on severity and consequences follows within 72 hours of becoming aware. That clock runs from awareness, not from the first notification, which is a distinction worth getting right in the contract as well. Potentially affected persons are notified immediately, or within two days where immediate notice is impossible, and a final report is due within one month of the 72 hour submission.

Whether those duties bite today is contested. The law entered into force on 4 January 2026, but Article 25(1)(2) postpones the general notification obligation in Article 9(3)(5) until the corresponding secondary acts enter into force, and those acts have not been published. Article 11 is not expressly postponed, and nothing published resolves the tension. The Government has also still to adopt the service classifications under Article 16(5) that would tell a particular supplier whether it is caught. Prime Minister’s Decision N 117-A of 13 February 2026 schedules those classifications for 21 to 30 November 2026, with the list of identified critical infrastructure operators to follow in December. Those are scheduled dates, not adopted instruments.

Three things follow. Do not draft a contractual notification clause on the premise that no Armenian regulatory duty exists. Do not treat absence from the Commission’s register as a safe harbour, because on the better reading of Articles 1 and 3 the register kept under Article 7(4) records status rather than creates it. And diary the November classifications, because they are what will settle your position.

Retention and deletion

Give a schedule by data category, with the event that starts each clock. Then state what happens at termination: return in a named format, deletion within a stated number of days, and what remains in backups until the backup cycle overwrites it. Backup residue is the answer most suppliers get wrong, by promising immediate deletion their architecture cannot perform.

Access control and personnel

Cover role based access with named approvers, multi factor authentication on production systems and on the identity provider, joiner and leaver timing in working days, and the confidentiality undertakings in your employment contracts. Where a screening step the questionnaire assumes is not available to you, say so plainly. A customer can work with a documented constraint and cannot work with a vague answer.

Frequently asked questions

Does Armenia have an EU adequacy decision?
No. Armenia does not appear on the European Commission’s list of countries benefiting from an adequacy decision under GDPR Article 45. Personal data reaching an Armenian supplier from an EU customer therefore needs a Chapter V transfer tool, which in commercial practice means the Commission’s standard contractual clauses under Article 46(2)(c).
Where is the data stored, and does it leave the EEA?
Answer with named countries and named providers, covering primary hosting, replicas, backups and any location from which staff can reach production. Data that remains physically on EU servers still leaves the EEA in legal terms if personnel in Armenia can access it, so the honest answer usually involves both a storage location and an access location.
Does remote access by our engineers count as a transfer?
Yes. The European Data Protection Board’s three part test, reflected in Opinion 22/2024, treats making personal data available to an entity in a third country as a transfer. A support login held by an Armenian engineer into an EU customer’s environment falls inside that definition even though no file is downloaded.
Do we have to disclose every subprocessor by name?
Expect to. GDPR Article 28(2) gives the customer a prior authorisation right over subprocessors, which it cannot exercise against an unnamed list. Disclose the legal entity, its country, the purpose, the data categories reached, the level of access, and the transfer basis relied on for that subprocessor, then commit to notifying changes with a notice period.
What evidence should we offer instead of a GDPR certificate?
No GDPR certificate exists under EU law that a vendor can simply hand over. The evidence pack that satisfies procurement is a signed data processing agreement, executed standard contractual clauses, a named subprocessor register, an ISO 27001 certificate with its statement of applicability or a SOC 2 Type II report, and a penetration test summary with remediation status.
Must we report a security incident to an Armenian regulator?
Armenia’s Law on Cybersecurity places a 24 hour initial notification and a 72 hour update duty on service providers in designated sectors, reporting to the Autonomous Body, the Information Systems Regulation Commission. Information technology and database operation are among the designated sectors, so an ordinary outsourcing company cannot assume it falls outside the regime. The classification criteria that determine whether a specific supplier is covered have not been published in a form that settles individual cases, and the point requires a company specific assessment before any contractual commitment is made.
Can we send customer data from Armenia to a third country?
Article 27 of the Law on Personal Data Protection governs transfers out of Armenia. Destinations on Armenia’s official adequate protection list, updated by a decision of 18 June 2026, or covered by an international treaty, need no separate authorisation. Any other destination requires prior permission from the authorised body plus contractual safeguards it has approved, with a statutory review period of 30 days. Your customer’s contract will normally also require its own prior consent.
Is Armenian data protection law equivalent to the GDPR?
Armenia has its own statute, the Law on Personal Data Protection of 18 May 2015 as amended through 4 December 2025, and no EU body has found it equivalent. Compliance with Armenian law is a separate exercise from the GDPR obligations your customer carries, and a questionnaire answer claiming equivalence will be rejected. Describe what Armenian law requires of you and how the contract bridges the remainder.

Where to start

  1. Ask the customer which of its legal entities is the controller and which categories of personal data will actually reach you. Scope narrows the questionnaire before you answer a single item.
  2. Build the subprocessor register first. The data processing agreement, the transfer paperwork and the data flow answers all depend on it.
  3. Confirm with the customer which standard contractual clause module fits the relationship, which turns on whether the customer acts as controller or as processor for its own client.
  4. Have the data processing agreement reviewed against the Armenian written instruction requirement before signature, so one document carries both obligations.
  5. Settle your position on Armenian cybersecurity notification for your own operations before agreeing a contractual notification window.

Last updated: 21 September 2026


Trusted by Clients from 97 Countries

4.9★ average on Google Reviews

Y. Xu

Everything was great I really appreciate the high quality service of your firm. The outcome is desirable and I am pleased. All lawyers are professional and very helpful. Thank you very much for your services. I will give 5 star for everything.

Jackson C.

My family and I would like to express our highest appreciation to Arman and the team for the responsive and professional support along the journey. Although there was an unexpected situation, Arman helped follow our cases through and provide us regular updates. Thank you.

Simon C.

All was exactly as described. Practical, cost-effective, and trustworthy legal services for all and any legal work in the Republic of Armenia. My long-term experience with this team has been good, and I am happy to recommend them for personal legal services. They respond promptly to communications, and their English/Armenian language skills are of professional standard. I will be using the services again for any issue that I have.

Get a Free Consultation
Tell us about your situation and we'll respond within 1 business day with a clear next step.

Your information is protected. We never share your details with third parties.

>