



{"id":25201,"date":"2020-11-26T16:39:02","date_gmt":"2020-11-26T16:39:02","guid":{"rendered":"https:\/\/media.am\/?p=25201"},"modified":"2020-11-27T21:23:16","modified_gmt":"2020-11-27T21:23:16","slug":"personal-data-protection-in-armenia-where-are-we-heading","status":"publish","type":"post","link":"https:\/\/media.am\/en\/critique\/2020\/11\/26\/25201\/","title":{"rendered":"Personal Data Protection In Armenia: Where Are We Heading?"},"content":{"rendered":"<p><span style=\"font-weight: 400\">Years ago, the issue of personal data in Armenia was not of interest to the general public or the state. The situation is changing over time. Unfortunately, the positive changes towards a more serious approach to this issue are based on negative experiences. Leaks are only increasing and this is finally becoming a concern for people.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Let&#8217;s look at only a portion of the leaks during June-July 2020.<\/span><\/p>\n<p><span style=\"font-weight: 400\">June 2: The &#8220;Anvil&#8221; Facebook page published lists of people killed by the coronavirus.<\/span><\/p>\n<p><span style=\"font-weight: 400\">June 11: The Azerbaijani hacker group, which has been carrying out attacks on Armenian email and social media accounts for years, published more than 3,000 pieces of information on those infected with the coronavirus and those who have had contact with them. Names, birth numbers, addresses, telephone numbers and passport numbers were published.<\/span><\/p>\n<p><span style=\"font-weight: 400\">June 24-26: The same hacker group published data on about 2,000 Armenians. This time without passport data.<\/span><\/p>\n<p><span style=\"font-weight: 400\">July 6: Passport data of several hundred Armenians were published in the Azerbaijani hacker forum. Moreover, these are passport photos, and in some of them people were even photographed with passports. Such images are required, for example, credit or similar organizations, where identity must be verified to ensure that a person does not use another citizen&#8217;s passport.<\/span><\/p>\n<p><img decoding=\"async\" class=\"wp-image-25173 size-full\" src=\"http:\/\/media.am\/wp-content\/uploads\/2020\/11\/image1-sam.png\" alt=\"\" width=\"241\" height=\"320\" srcset=\"https:\/\/media.am\/wp-content\/uploads\/2020\/11\/image1-sam.png 241w, https:\/\/media.am\/wp-content\/uploads\/2020\/11\/image1-sam-226x300.png 226w\" sizes=\"(max-width: 241px) 100vw, 241px\" \/><\/p>\n<p><i><span style=\"font-weight: 400\">This is one of the examples of a leakage. The personal data section is covered<\/span><\/i><span style=\"font-weight: 400\">July 7: Azerbaijani hackers published leaflets on Facebook about the inventory of a military unit of the Artsakh Defense Army, which also included information about the car park.<\/span><\/p>\n<div id=\"attachment_25175\" style=\"width: 330px\" class=\"wp-caption alignnone\"><img decoding=\"async\" aria-describedby=\"caption-attachment-25175\" class=\"wp-image-25175 size-full\" src=\"http:\/\/media.am\/wp-content\/uploads\/2020\/11\/image2-sam.png\" alt=\"\" width=\"320\" height=\"179\" srcset=\"https:\/\/media.am\/wp-content\/uploads\/2020\/11\/image2-sam.png 320w, https:\/\/media.am\/wp-content\/uploads\/2020\/11\/image2-sam-300x168.png 300w\" sizes=\"(max-width: 320px) 100vw, 320px\" \/><p id=\"caption-attachment-25175\" class=\"wp-caption-text\"><i><span style=\"font-weight: 400\">This is one of the examples of a leakage. Some of the data in this picture has been deleted.<\/span><\/i><\/p><\/div>\n<p><span style=\"font-weight: 400\">July 30: Data of more than 6,000 Armenians was posted on the Internet including e-mail, telephone number, address, passport number. Most likely, the leak was from the database of one of the bonus cards.<\/span><\/p>\n<blockquote><p><span style=\"font-weight: 400\">Control and statistics<\/span><\/p><\/blockquote>\n<p><span style=\"font-weight: 400\">Armenia has taken an interesting path in terms of personal data. The <\/span><a href=\"https:\/\/www.arlis.am\/DocumentView.aspx?DocID=76781\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400\">Law on Personal Data<\/span><\/a><span style=\"font-weight: 400\"> was adopted in 2002 and entered into force in 2003. The adoption of the law and its future life remains far from the consciousness of society, as well as from the functions of the government. Without receiving flesh and blood, the given law remains on paper.<\/span><\/p>\n<p><span style=\"font-weight: 400\">In 2015, the <\/span><a href=\"https:\/\/www.arlis.am\/documentview.aspx?docid=98338\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400\">Law on Personal Data Protection<\/span><\/a><span style=\"font-weight: 400\"> was adopted and entered into force. This was already a more or less conscious step by the state. A <\/span><a href=\"http:\/\/www.justice.am\/structures\/view\/structure\/32\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400\">Personal Data Protection Agency<\/span><\/a><span style=\"font-weight: 400\"> was established, which operates within the system of the Ministry of Justice. The principle of state-public cooperation, which is the basis of the agency, is interesting.<\/span><\/p>\n<p><span style=\"font-weight: 400\">According to the law, &#8220;the head of the authorized body for personal data protection is appointed for a term of five years&#8230; based on the joint proposals of at least five human rights NGOs.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400\">The agency is active, <\/span><a href=\"https:\/\/www.facebook.com\/PersonalDataArmenia\/\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400\">represented on social networks<\/span><\/a><span style=\"font-weight: 400\">, where it provides consultation to citizens.<\/span><\/p>\n<p><span style=\"font-weight: 400\">According to the <\/span><a href=\"http:\/\/www.justice.am\/storage\/uploads\/2019Annual-report-2019-ATPG.pdf\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400\">agency&#8217;s report<\/span><\/a><span style=\"font-weight: 400\">, in 2019, 83 administrative proceedings were initiated in the Personal Data Protection Agency on the basis of citizens&#8217; applications or on the initiative of the agency.<\/span><\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-25177 size-full\" src=\"http:\/\/media.am\/wp-content\/uploads\/2020\/11\/image3-sam.png\" alt=\"\" width=\"739\" height=\"346\" srcset=\"https:\/\/media.am\/wp-content\/uploads\/2020\/11\/image3-sam.png 739w, https:\/\/media.am\/wp-content\/uploads\/2020\/11\/image3-sam-300x140.png 300w\" sizes=\"(max-width: 739px) 100vw, 739px\" \/><\/p>\n<p><span style=\"font-weight: 400\">For comparison, since the establishment of the agency in 2015-2018, a total of 67 lawsuits have been initiated, 16 less than in 2019 alone. In 2015, 2 proceedings were initiated, in 2016 &#8211; 11 proceedings, in 2017 &#8211; 21 proceedings, in 2018 &#8211; 33 proceedings.<\/span><\/p>\n<blockquote><p><span style=\"font-weight: 400\">Crime and punishment<\/span><\/p><\/blockquote>\n<p><span style=\"font-weight: 400\">Although the number of proceedings is growing, the reality hardly changes. Here are some key reasons:<\/span><\/p>\n<p>a. The fines of 200-500 thousand AMD are very mild for personal data violations. For example, for a personal data processing company, from a purely financial point of view, leaving aside the responsibility of the business, it is theoretically more profitable to pay a fine once than to hire a specialist to pay the equivalent of a fine every month.<\/p>\n<p><span style=\"font-weight: 400\">b\u2024 Data protection in state institutions should be put on a stronger footing. The agency has created a <\/span><a href=\"http:\/\/www.moj.am\/storage\/uploads\/123Uxecuyc-cucumner.pdf?fbclid=IwAR2xM_xDVwhxA-nCSVYJGJuAM_grVpUwFq12JDSkrSAyEnbvfL2QzSmYu4k\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400\">guide for the processing of personal data by state bodies<\/span><\/a><span style=\"font-weight: 400\">, but only one guide does not solve the problem. The functions of the agency are not enough to correct the situation in the whole state system and adjacent structures. It is necessary to have a more comprehensive conceptual approach, which implies the introduction of processes at the government level, staff training and control.<\/span><\/p>\n<p><span style=\"font-weight: 400\">c\u2024 Public opinion about personal data, although changing, is doing so very slowly. Especially in this period, when the probability of leaks only increases. And there is mass ignorance about the data of minors. Improving public opinion without public awareness campaigns will be based mainly on negative experiences.<\/span><\/p>\n<p><span style=\"font-weight: 400\">d\u2024 Public awareness also means controlling specific cases, making them public, presenting comprehensible statistics. In addition, the cases that have already taken place are not further analyzed publicly, no conclusion is presented by the relevant bodies as to what was the cause of the leak, what was done to make an exception of it. The public never knows about the culprits, neither the relevant practical conclusions nor the steps aimed at correcting them (if, of course, these things take place).<\/span><\/p>\n<p><span style=\"font-weight: 400\">e\u2024 One of the biggest problems regarding public awareness about accidents is the lack of it. There are countries where the organization is obliged by law to make the incident public if there is a leak.<\/span><\/p>\n<p><span style=\"font-weight: 400\">The logic is very simple: People should be aware that their information is open to the public or in the hands of criminals. In such a case, a person has the opportunity to take measures.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Thus, during the summer alone, there was a leak of passport data of about twenty thousand citizens. But there is no mechanism to inform people about it. In other words, most of them are not even aware that other people can use their data. In recent years, there has been only one case when, after a major outflow, the organization has taken on the responsibility of raising public awareness through the press. It was the <\/span><a href=\"https:\/\/pastebin.com\/buigqM3m\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400\">leak of the passwords<\/span><\/a><span style=\"font-weight: 400\"> of the users of ABCDomain hosting, after which an <\/span><a href=\"https:\/\/itel.am\/am\/news\/5547\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400\">announcement was made by the organization<\/span><\/a><span style=\"font-weight: 400\">. This is a unique positive example.<\/span><\/p>\n<p><span style=\"font-weight: 400\">The simple conclusion of all this is one: If large-scale and multilateral actions are not taken, data leaks will only continue. Or rather, their volumes will increase.<\/span><\/p>\n<p style=\"text-align: right\"><b>Samvel Martirosyan<\/b><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Years ago, the issue of personal data in Armenia was not of interest to the general public or the state. The situation is changing over time. Unfortunately, the positive changes towards a more serious approach to this issue are based on negative experiences. Leaks are only increasing and this is finally becoming a concern for<a class=\"moretag\" href=\"https:\/\/media.am\/en\/critique\/2020\/11\/26\/25201\/\"> Read the full article&#8230;<\/a><\/p>\n","protected":false},"author":3,"featured_media":25172,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ngg_post_thumbnail":0,"footnotes":""},"categories":[16],"tags":[],"class_list":["post-25201","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-critique","author_posts-samvel-martirosyan"],"acf":[],"_links":{"self":[{"href":"https:\/\/media.am\/en\/wp-json\/wp\/v2\/posts\/25201","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/media.am\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/media.am\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/media.am\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/media.am\/en\/wp-json\/wp\/v2\/comments?post=25201"}],"version-history":[{"count":1,"href":"https:\/\/media.am\/en\/wp-json\/wp\/v2\/posts\/25201\/revisions"}],"predecessor-version":[{"id":25202,"href":"https:\/\/media.am\/en\/wp-json\/wp\/v2\/posts\/25201\/revisions\/25202"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/media.am\/en\/wp-json\/wp\/v2\/media\/25172"}],"wp:attachment":[{"href":"https:\/\/media.am\/en\/wp-json\/wp\/v2\/media?parent=25201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/media.am\/en\/wp-json\/wp\/v2\/categories?post=25201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/media.am\/en\/wp-json\/wp\/v2\/tags?post=25201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}