Armenia is preparing to change the system of identity documents for its citizens

Pasport

It is planned to issue new biometric passports from the fall of 2026, and in parallel with this, a new infrastructure is being introduced in the country, which should also enable the use of automated border crossing systems, e-gates. According to the official presentation, this is not just a story about a new passport. We are talking about a change in the state identification infrastructure, the center of which is a person’s identity, and with it, one of the most sensitive personal data – biometrics.

Will Bayraktar control the new biometric passports of Armenian citizens?

But just on the eve of the introduction of this system, a story appeared in the public domain that linked this technological project with the 2020 war, the Turkish Bayraktar drones, the American Advent International investment company and the French IDEMIA technology group. On June 26, 2026, “Hraparak” published an article titled “The partner of “Bayraktar” was recognized as the winner of the RA government competition.” The article claimed that components manufactured by American companies were found in the wreckage of Bayraktar TB2 drones shot down by the Armenian side during the 2020 war, and that story was linked to Advent International. The article then moved on to Armenia’s new biometric system, noting that IDEMIA was included in the consortium that won the government tender, and that the majority of IDEMIA’s shares, according to the publication, belong to Advent International. By connecting these two nodes, the publication put forward the most serious assumption: that the biometric data of Armenian citizens could become available to states that are not friendly or hostile to Armenia.

This presentation of the story very quickly took on not only a technological, but also a national security tone. On one side is Bayraktar, one of the symbols of the 2020 war, and on the other, biometric data, which is linked to the identity of each citizen. The combination of the two almost immediately leads the reader to one conclusion. But it is at this point that the real work of journalistic investigation begins. Not to say right away whether this is true or false, but to restore the order of facts, clarify the real relationships of the companies, and separate the part that is proven from the part that is a claim of the source or is still a question.

The Ministry of Internal Affairs of Armenia after the publication came up with an official clarification. The Ministry characterized the article as disinformation and misleading. The key provision of the official response was as follows: Advent International was not a member of the consortium selected as a result of the tender announced by the Government of the Republic of Armenia. The Ministry recalled that on April 25, 2025, the public-private partnership agreement was signed with the “HayPass” Closed Joint-Stock Company, the founder of which is the “IN Smart Identity France SAS & ACI Technology S.à.rl” consortium. That is, Advent International is not a member of the winning consortium in the contractual chain.

This clarification is important, but it does not close the whole story. It answers one specific question: was Advent International a member of the winning consortium of the Armenian tender? The official answer is no. However, a separate question is what kind of corporate or investment relations existed between Advent and IDEMIA during this period. And another question: does this relationship in any way relate to the access to data of Armenian citizens? The three issues should be kept separate from each other, because the contracting party, the shareholder, the investor and the technological partner do not have the same legal status.

The official description of the competition for the biometric system in Armenia is quite clear. The winner was the French consortium “IDEMIA Identity Security France and ACI Technology S.à.rl”. On April 25, 2025, in the presence of Deputy Prime Minister Mher Grigoryan, Minister of Internal Affairs Arpine Sargsyan and the Executive Director of “HAYPASS” CJSC, founded by the consortium, Regis Bouchier, signed a public-private partnership agreement. The agreement concerns the issuance and provision of identity documents, as well as the infrastructure for the operation and maintenance of the means used in this process. As part of the project, HAYPASS should introduce a new infrastructure by the second half of 2026, with new solutions for collecting biometric data, a new geographical network and offices with modern technical equipment. Standardization of the building conditions, server infrastructure, and printing equipment of the service’s headquarters is also planned. According to the official description, the goal is to provide Armenian citizens and persons with other legal status in Armenia with secure and high-quality identification documents and to protect personal data and the legal identity of a person establishing a new threshold of protection.

It is also important that not all functions of the passport system are transferred to a private partner. According to the official presentation, the Ministry of Internal Affairs will continue to carry out status determination, identity verification, and the administration and maintenance of the state population register through the Migration and Citizenship Service. The private partner is responsible for collecting biometric data, printing documents, and delivering them to beneficiaries.

This distinction is important because during public discussions, the formulation “a private company is implementing the biometric system” can be perceived as a transfer of complete control of citizens’ data from the state to a private company. The official document does not describe such a complete transfer. It describes a separation of state and private functions. However, the next question immediately arises from this: if a private partner collects biometric data, to what extent can it have access to that data. Where is the data stored, who has technical access, who controls that access, how are backup copies stored, are there subprocessors or third-party technology services, and does the data leave the territory of Armenia at any stage? These questions are not in themselves evidence of a threat. They are questions that need to be answered in order to assess the security of the system.

On May 21, 2026, the Ministry of Internal Affairs announced that the printing of new types of biometric passports has already begun in the Netherlands, and they will be available to Armenian citizens from the fall of 2026. The Ministry also announced that a special security solution has been developed for Armenia, including fibers with the Armenian tricolor in the composition of the passport paper. One of the most important formulations of the same statement was that biometric data will be stored exclusively under the control of the Republic of Armenia.

According to the official position, data management will be carried out by a special unit of the Migration and Citizenship Service of the Ministry of Internal Affairs, and the private partner will use the data only within the framework of service provision and under state supervision. Armenia will be guided by high European standards in the field of data protection, including the requirements of the Council of Europe Convention 108+. Within the framework of the same system Automated border crossing solutions, e-gates, are also being introduced, which should allow passengers with the appropriate documents to cross the border in an automated manner, without the direct intervention of a border guard. According to the state presentation, the system is also an important step in the process of visa liberalization with the European Union.

Thus, the story presented by the state is about technological modernization. But to understand this story, one must also study IDEMIA’s corporate path. IDEMIA Group, according to its official presentation, operates in the fields of biometrics and cryptography, payments, secure travel, access and identity solutions. The group presents three main directions: IDEMIA Secure Transactions, IDEMIA Public Security and IDEMIA Smart Identity. The last direction is particularly important for this story, because it is related to physical and digital identity solutions. According to the company’s presentation, IDEMIA cooperates with more than 600 state organizations and more than 2,400 enterprises in more than 180 countries, and the number of employees of the entire group is about 15 thousand.

However, IDEMIA has also undergone a corporate restructuring in recent years. In September 2024, Le Monde reported that French state-owned IN Groupe had entered into exclusive negotiations to acquire IDEMIA’s Smart Identity division. This division specialized in the production of national identification cards, passports and other secure identity documents. According to the publication, the deal was to significantly increase the size of IN Groupe. Smart Identity at that time had a turnover of around 430 million euros and around 1,700 employees, 250 of whom were in France. Two of its production centers were located in the Netherlands and the Czech Republic. The deal was also presented as an opportunity for IN Groupe to expand internationally. The company’s management spoke of strengthening its positions in Europe, Africa, Latin America and Asia and participating in larger international competitions. Smart Identity’s technological expertise was to complement IN Groupe’s capabilities, especially in a context where identity documents are rapidly becoming digital.

IDEMIA was formed in 2016 through the merger of Safran’s former Morpho division and Oberthur Technologies. This history shows that the corporate structure around IDEMIA is not simple and immutable. The business lines were separated, divisions were sold, and the ownership and management structure of the company changed at different times.

In 2025, IDEMIA announced the completion of the sale of Smart Identity. According to the company’s official statement, the transaction was an important stage in the strategic restructuring that began in February 2024. IDEMIA Group focused on Secure Transactions and Public Security, while Smart Identity became part of IN Groupe. The transaction was finally completed on July 1, 2025.

Here, the chronology becomes important. The agreement between Armenia and HAYPASS was signed on April 25, 2025, and the completion of the sale of Smart Identity took place after that. Therefore, any claims about the ownership or control of the companies must be linked to a specific date. The structure of 2024 cannot be automatically presented as the structure of 2026, and the relationships operating after July 2025 cannot describe the situation in April of the same year without clarification.

It is in this corporate story that the Advent International issue becomes important. In the materials provided, Advent is presented in the context of an investment story related to IDEMIA. But even if such a corporate relationship exists, it must be distinguished from the contractual relationship in the Armenian tender. Advent could have an investment or ownership relationship with IDEMIA and at the same time not be a member of the winning consortium in the Armenian tender. These two facts do not contradict each other.

Here, one word, “partner,” can completely change the meaning of the story. Partner can mean a contractual party, an investor, a shareholder, a parent or subsidiary company, a technology provider, or part of the same corporate group. The legal meanings of these words are not the same. If they are mixed in a journalistic story, the reader may perceive the different types of relationships as one complete connection.

The same problem exists in the Bayraktar story. In the submission, ANCA claims that evidence collected on the battlefield showed that equipment manufactured by Advent International subsidiary Cobham PLC/Comant was found in Turkish Bayraktar drones used by Azerbaijan. On this basis, ANCA called on Advent International to cease the sale of military or dual-use technology to Turkey and Azerbaijan, and appealed to the US authorities to implement appropriate export restrictions and studies.

This information is important as a published source claim. But the materials provided do not present a full independent technical examination alongside ANCA’s claim regarding Bayraktar components. Therefore, the correct journalistic formulation is “ANCA claims that…”, not to present this claim as a fully independently verified fact. This may seem like a small difference in formulation, but in fact it is this difference that determines the quality of journalism. When it comes to national security, war, and personal data, turning a source’s claim into a fact can lead the reader to a conclusion that the source does not independently prove.

The most important chain of this story is right there. There is an ANCA claim regarding some of the Bayraktar components. There is a corporate history between Advent International and IDEMIA that needs to be considered in specific periods. The winner of the Armenian government’s tender was the IDEMIA Identity Security France and ACI Technology consortium. That consortium was founded by HAYPASS. HAYPASS has signed a PPP contract with Armenia. Armenia is implementing a biometric system.

But the totality of these facts does not automatically prove that the data of Armenian citizens is accessible to Turkey or any other hostile state. For that last conclusion, another, very specific evidentiary link is needed: the mechanism of access to the data.

That mechanism must be able to be described. Which legal entity has access? By what contractual provision? Where is the database located? Who has administrative access? Who can export the data? Where are the backup copies stored? Are foreign cloud or other technological services used? Are there subprocessors? How is access recorded? Who controls these activities? The answers to these questions can actually show whether the danger that the publication speaks of exists.

The Law of Armenia “On the Protection of Personal Data” creates a legal framework for these issues. The law considers personal data to be any information relating to a natural person that allows or may allow the direct or indirect identification of the person. Processing is considered to be the collection, recording, input, systematization, storage, use, transfer, rectification, blocking, destruction and other actions. Biometric data is defined by law as information characterizing the physical, physiological and biological characteristics of a person.

The law requires that the data be processed lawfully and for specific purposes. Without the consent of the data subject, they cannot be used for other purposes, except in cases provided for by law. The processing must pursue a legitimate aim, and the means must be appropriate, necessary and proportionate. The amount of data processed must be the minimum necessary to achieve the legitimate aim. The law also prohibits the processing of excessive data if the same aim can be achieved in a depersonalized manner.

These principles mean that the security of a biometric system is not just a matter of the company name. It is also important for what purpose the data is collected, how long it is stored, who is the processor, who is the authorized person, what actions can be performed and to whom the data can be transferred.

The law has a special place in the concept of an authorized person. This may be a legal or natural person, a state or local authority, which has been entrusted by the data processor, in cases specified by law or by contract, to collect, enter, systematize or otherwise process personal data. In other words, the involvement of a private partner does not in itself mean that the state loses legal control over the data. Instead, there should be a clear contractual and technical limitation.

The law provides that in the case of delegation of data processing, the purpose of the processing, the scope of the data, the activities, the scope of the data subjects and the security measures must be defined. This is important in the case of the new system in Armenia, since the private partner is officially involved in the process of collecting biometric data and producing documents.

The law provides for special requirements for biometric data. The basis for processing must be a basis provided for by law or appropriate consent, depending on the situation. The data subject must be informed of the legal basis for processing, the purpose, the list of data to be processed, the possible scope of data transfer and the validity period of the consent.

The law also provides for the rights of citizens. A citizen can obtain information about the processing of his/her personal data, to get acquainted with his/her data and, in cases provided for by law, to request their correction, completion, blocking or destruction. If he/she believes that the processing of his/her data violates his/her rights, he/she may apply to the authorized body for personal data protection or to the court.

In the event of a leak, the law also establishes a specific obligation. In the event of a leak of personal data from electronic systems, the processor is obliged to immediately publish a statement and notify the relevant state bodies and the authorized body for personal data protection. In the event of detection of illegal actions, the processor is obliged to eliminate the violations, and in cases provided for by law, to destroy the data.

The authorized body is an independent structure by law. It may verify the compliance of the processing of personal data with the law, apply administrative liability measures, request the blocking, suspension or termination of data processing, request the correction or destruction of data, maintain a register of data processors and inspect the devices, documents and computer programs used for data processing. The processor of biometric or special category data is obliged to notify the authorized body of the intention to process the data before processing such data. The notification must include the data of the processor or authorized person, the purpose and legal basis of the processing, the scope of the data, the subjects, the scope of the operations performed, a description of the security measures and the terms of the processing.

The law also limits the transfer of data to third parties and other states. Transfer to another country is permissible on the grounds provided for by law, and in the absence of an adequate level of protection, additional guarantees and permission from the authorized body may be required. This provision is important in the event of an allegation that the data may become accessible to foreign states. The foreign origin of the technology and the transfer of data abroad are not the same legal act. But if there is a transfer, it must have a legal and contractual basis.

For this reason, the most important next step in the public discussion is not a new title, but an examination of the documents. It must be possible to understand the flow of data from the citizen’s application to the printing of the document and the storage of data in the system. It must be clear at what stage what data is used, who is the data processor at that moment, and on what legal basis it is transferred to the next level.

There are still questions in this story that are not fully answered by the materials provided. For example, the complete technical architecture, the final list of third-party subprocessors, the location of data backups, the limits of each type of administrative access, and the results of an independent security audit. Their absence does not in itself prove a threat, but this information is necessary for the public to independently assess the security of the system.

This story also shows how disinformation can be formed from a mixture of real facts. The entire story does not have to be made up. A causal relationship can be created between real facts that the original sources do not confirm. ANCA’s claim about Bayraktar may be a real published fact. Advent and IDEMIA’s corporate history may be real. The result of the Armenian government tender is real. The creation of HAYPASS and the PPP contract are real. The implementation of the new biometric system is real. But the sum of these facts does not yet amount to the claim that the data of Armenian citizens is accessible to Turkey.

The same logic applies to state denial. The Ministry of Internal Affairs’ statement that Advent was not a member of the winning consortium is an important fact. But that does not mean that all questions about the companies’ corporate history have disappeared. To build stronger public trust, it is necessary not only to deny the false connection, but also to explain the legal nature of the real connections.

Public trust is especially important because a citizen does not choose which technological system the state will use to manage his identity. He simply uses that system. His biometric data cannot be replaced, just as a password can be replaced. If the data is leaked, the problem will not be limited to reissuing a single document. Therefore, the security of the system must be not only technological, but also managerial and legal.

In the fall of 2026, when new biometric passports will be available to citizens, this story will no longer be just a media dispute. It will become a functioning state infrastructure. From that moment on, every new passport will be linked not only to a person’s photo and biometric data, but also to the question of how much a citizen trusts the system that stores and processes their identity data.

The documented part of this story allows us to say that Armenia is implementing a new biometric system, that a French consortium won the tender, that HAYPASS has signed a PPP contract, that the state declares Armenia’s control over the data, and that the legislation establishes specific rules for the protection of biometric data.

At the same time, there are the ANCA’s published allegations about Bayraktar’s components and IDEMIA’s corporate history, the different stages of which should be considered with specific dates.

What still requires additional documentary verification is the actual technical flow of data, the role of all subprocessors, the possible involvement of foreign technology services, the full range of administrative inputs, and the results of an independent security audit.

Therefore, the most important question in this story, ultimately, is not “who is Bayraktar’s partner”, but a much simpler and more measurable question: who, on what legal basis and with what technical capabilities, can have access to the biometric data of Armenian citizens. If this access is limited, it should be clear why and how. If data is not transferred outside Armenia, it should be possible to verify this. If a private partner only has access necessary for the provision of the service, this limit should be visible in contracts and technical control mechanisms.

The answer to these questions can be much more important than any political statement. Because in the case of data protection, trust is not built only by the formulation “trust us”. It is built with a verifiable system where it is possible to find out who has accessed the data, for what purpose, on what legal basis and within what limits.

When it comes to human identity, the most dangerous mistake is not just transferring the wrong data. The most dangerous mistake is blurring the line between fact, source assertion, assumption and proof.

SOURCES USED

“Hraparak”, “”Bayraktar’s” partner recognized as the winner of the RA government tender”, June 26, 2026.

RA Ministry of Internal Affairs, “A public-private partnership agreement for the introduction of a biometric system was signed”, April 25, 2025.

Ministry of Internal Affairs of the Republic of Armenia, “Clarification: The company mentioned in the article has no participation in the consortium that won the tender announced by the Government of the Republic of Armenia”, 26 June 2026.

Ministry of Internal Affairs of the Republic of Armenia, “Work is underway to introduce automated border crossing (e-gates) systems in parallel with the biometric system”, 21 May 2026.

IDEMIA Group, Official announcements on the sale of IDEMIA Smart Identity to IN Groupe.

Le Monde, “IN Groupe, ex-Imprimerie nationale, rachète un de ses competitors français spécialisé dans les titres d’identité”, 19 September 2024.

ANCA, “Tell Advent: Selling Drone Equipment to Turkey Kills Armenian Civilians”.

Relevant provisions of the RA Law “On the Protection of Personal Data”.

The material was prepared within the framework of the Disinformation Flows Monitoring Program.

Journalist: Sargis Asatryan

#CivilSocietyCooperation #ishrarmenia #ishrfactcheck

Logo opr amt

The project is implemented with the financial support of the Federal Ministry for Foreign Affairs of the Federal Republic of Germany.

ISHR Armenia is solely responsible for the content of the materials.