Skip to content

Evidence request lists

Georgia Law on Personal Data Protection (2012)

Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Georgia DPL: Controller + Processor Obligations, DPO, RoPA, DPIA and Security

GeDPL-Controller-Processor-DPO-RoPA-DPIA
Controller + Processor Obligations + DPO + RoPA + DPIA + Security

Georgia DPL Controller + Processor + Security obligations. CONTROLLER ACCOUNTABILITY (Art. 27): demonstrate compliance through documented policies + records + impact assessments + reviews. PROCESSOR REQUIREMENTS (Art. 28 - GDPR Art. 28 aligned): written contract + processing scope + duration + categories + sub-processor authorisation + return/deletion + audit cooperation. RECORDS OF PROCESSING ACTIVITIES (RoPA, Art. 29 - GDPR Art. 30 aligned): controllers + processors maintain RoPA including categories + purposes + recipients + cross-border + retention + technical/organisational measures. DATA PROTECTION OFFICER (DPO, Art. 30 - 2023 NEW MANDATORY): for (a) public authorities + bodies; (b) controllers/processors whose core activities require regular + systematic monitoring on large scale; (c) controllers/processors processing special-category data on large scale + criminal data on large s

Artefacts an auditor will ask for
  • RoPA + DPIA records
  • DPO appointment + notification + qualifications
  • Processor agreement template
  • Security measure inventory + testing
Where this commonly fails
  • RoPA missing or incomplete
  • DPO not mandated when required
  • Processor agreement weak
  • Security measures not state-of-the-art

Georgia DPL: Cross-Border Transfers, Breach Notification (72-Hour) and Special Provisions

GeDPL-CrossBorder-Breach-Surveillance-Marketing
Cross-Border Transfers, 72-Hour Breach Notification, Video Surveillance and Marketing

Georgia DPL cross-border + breach + special-context regimes. CROSS-BORDER TRANSFERS (Art. 35-37 - GDPR Chapter V aligned): personal data may be transferred outside Georgia only where: (a) ADEQUACY - the destination country provides adequate level of protection (Minister of Justice determination + EU/EEA + Convention 108+ countries); (b) APPROPRIATE SAFEGUARDS - binding corporate rules + standard contractual clauses (SCCs) + approved code of conduct + approved certification + ad hoc clauses approved by PDPS; (c) DEROGATIONS - explicit consent + contract necessity + public interest + legal claims + vital interests + register access. BREACH NOTIFICATION (Art. 38 - 2023 NEW + GDPR Art. 33-34 aligned): controllers must notify the PDPS within 72 HOURS of becoming aware of a breach likely to result in risk to natural persons; without undue delay to data subjects if breach likely to result in HI

Artefacts an auditor will ask for
  • Cross-border DPIA + transfer mechanism
  • Breach response procedure + 72-hour SLA
  • Video surveillance policy + signage
  • E-marketing consent + soft opt-in
Where this commonly fails
  • Transfers without adequacy/safeguards
  • 72-hour SLA missed
  • Video surveillance in prohibited zones
  • E-marketing without consent or soft opt-in

Georgia DPL: Data Subject Rights (Access, Rectification, Erasure, Portability, Objection, ADM)

GeDPL-DataSubjectRights
Data Subject Rights (Access, Rectification, Erasure, Restriction, Portability, Objection, ADM)

Georgia DPL Data Subject Rights (Articles 21-26 - GDPR Chapter III aligned post-2023). RIGHTS: (1) RIGHT TO INFORMATION + TRANSPARENCY (Art. 21) - clear + accessible + at-collection notice; (2) RIGHT OF ACCESS (Art. 22) - confirmation + copy + purposes + categories + recipients + retention + rights information + cross-border transfers; (3) RIGHT TO RECTIFICATION (Art. 23) - correction of inaccurate or incomplete data; (4) RIGHT TO ERASURE / BE FORGOTTEN (Art. 24) - deletion when data no longer necessary + consent withdrawn + objection sustained + unlawful processing + legal obligation + child consent; (5) RIGHT TO RESTRICT PROCESSING (Art. 25) - limiting processing during accuracy dispute + pending objection + unlawful processing + retention for legal claims; (6) RIGHT TO DATA PORTABILITY (Art. 26 - 2023 NEW) - receive personal data provided + structured + commonly-used + machine-readabl

Artefacts an auditor will ask for
  • Rights request log + 30-day tracking
  • ADM policy + human review + opt-out
  • Identity verification policy
Where this commonly fails
  • Rights gaps post-2023
  • 30-day SLA missed
  • ADM protections not implemented
  • Identity verification too weak/strong

Georgia DPL: Lawful Basis, Consent, Special Categories and Children

GeDPL-LawfulBasis-Consent-Sensitive-Children
Lawful Basis, Consent, Special Categories and Children (Age 16)

Georgia DPL lawful basis + consent + special categories + children. LAWFUL BASIS (Art. 5 - GDPR Art. 6 aligned): (a) CONSENT of the data subject; (b) CONTRACT performance + pre-contractual measures; (c) LEGAL OBLIGATION of the controller; (d) VITAL INTERESTS of the data subject or another natural person; (e) PUBLIC INTEREST + official authority; (f) LEGITIMATE INTERESTS of the controller or third party balanced against data subject rights. CONSENT (Art. 6): must be FREELY GIVEN + SPECIFIC + INFORMED + UNAMBIGUOUS + WITHDRAWABLE at any time (and as easy to withdraw as to give); EXPLICIT CONSENT required for special categories; PARENTAL CONSENT required for processing personal data of children UNDER 16 in information-society services context; presumed-consent + pre-ticked-boxes + opt-out PROHIBITED. SPECIAL CATEGORIES (Art. 7 + 8 - GDPR Art. 9 aligned): race + ethnicity + political opinion

Artefacts an auditor will ask for
  • Lawful basis register
  • Consent records + withdrawal mechanism
  • Special-category lawful basis + DPIA
  • Age-of-consent verification + parental consent for children
Where this commonly fails
  • Lawful basis ambiguous
  • Implied/pre-ticked consent
  • Special-category processed without explicit consent
  • Age verification weak

Georgia DPL: Personal Data Protection Service (PDPS), Enforcement and Sanctions

GeDPL-PDPS-Enforcement-Sanctions
Personal Data Protection Service (PDPS), Enforcement Powers and Sanctions

Personal Data Protection Service (PDPS - Sakartvelos Personalur Monatsemta Datsvis Sammartveloba) - the Georgian supervisory authority established by the 2012 Law + significantly strengthened by the 2023 amendments. INDEPENDENCE (Art. 40-9): the PDPS is an independent body + the Head is elected by Parliament for a 5-year term + may be re-elected once; financial + functional + structural independence. POWERS (Art. 40-2 + 40-11 + 40-13): (a) MONITORING + INVESTIGATION + COMPLAINT-HANDLING; (b) INSPECTION powers including premises entry + records access + interviews + IT systems inspection; (c) GUIDANCE + RECOMMENDATIONS + standards; (d) ENFORCEMENT through INSTRUCTIONS + administrative + criminal referrals; (e) ADMINISTRATIVE FINES (Art. 40-13): per-violation civil penalties up to GEL 20,000 (2023 amendments substantially increased from earlier GEL 200-1,000; the 2023 reform aimed at GDPR-

Artefacts an auditor will ask for
  • PDPS-contact-point + cooperation playbook
  • Penalty risk assessment
  • Appeals procedure
Where this commonly fails
  • PDPS engagement reactive only
  • Penalty risk under-assessed
  • Appeals unfamiliar

Georgia DPL: Scope, Applicability, Definitions and 2023 GDPR-Alignment Amendments

GeDPL-Scope-Defs-2023Amendments
Scope, Applicability, Definitions and 2023 GDPR-Alignment Amendments

Georgia DPL Scope + applicability + 2023 GDPR-aligned amendments. SCOPE: applies to natural-person personal data processing in Georgia + (post-2023 amendments) EXTRATERRITORIAL APPLICATION to processing related to offering of goods or services to data subjects in Georgia or monitoring of behaviour in Georgia (GDPR Art. 3(2) aligned). APPLICABILITY: controllers + processors operating in Georgia + foreign entities with Georgia-targeted activities; public authorities + private sector + non-profits. DEFINITIONS: PERSONAL DATA = information relating to an identified or identifiable natural person (GDPR-aligned); CONTROLLER + PROCESSOR (GDPR-aligned roles); CONSENT (freely given + specific + informed + unambiguous); SENSITIVE DATA (Art. 9 GDPR special categories); CHILD = under 16 (Georgia age of digital consent); BIOMETRIC + GENETIC DATA per GDPR. 2023 AMENDMENTS (Law No. 3144-RS of 2 June 20

Artefacts an auditor will ask for
  • Applicability assessment incl extraterritorial
  • 2023 amendment readiness + implementation
  • Definitions glossary + GDPR mapping
Where this commonly fails
  • Pre-2023 framework still applied
  • Extraterritorial scope underestimated
  • Definitions not GDPR-aligned

Georgia DPL: Sectoral Coordination, EU-Accession + CoE Convention 108+ and 2024-2025 Status

GeDPL-Crosswalk-GDPR-CoE108-NIS2
Crosswalk to GDPR, Council of Europe Convention 108+, EU AI Act and NIS2

Georgia DPL crosswalk to major DP regimes. EU GDPR (Regulation (EU) 2016/679): post-2023 amendments substantially aligned + most GDPR concepts (extraterritorial scope + 7 lawful bases + 8 special-category bases + 7 data subject rights + DPO + DPIA + 72-hour breach + cross-border SCC/BCR + administrative fines) are now in Georgia DPL with some local adaptations; ADEQUACY DECISION not yet granted but pursued via EU accession. EU LAW ENFORCEMENT DIRECTIVE (EU) 2016/680: Georgia has separate regime for personal data processing by competent authorities for criminal-offence purposes + coordinated with DPL. EU AI ACT (Regulation (EU) 2024/1689): Georgia may align via EU accession; high-risk AI systems + biometric identification + emotion recognition + automated decision-making + EU AI Act competent authorities likely include PDPS. EU NIS2 (Directive (EU) 2022/2555): Cybersecurity Act 2025 antic

Artefacts an auditor will ask for
  • GDPR + Convention 108+ + EU AI Act alignment evidence
  • Bilateral DP cooperation engagement
  • Multi-regime compliance program
Where this commonly fails
  • GDPR alignment partial
  • Convention 108+ not ratified
  • Bilateral cooperation absent
GeDPL-EU-CoE-Status-2024-2025
EU-Accession Status, CoE Convention 108+ and 2024-2025 Pipeline

Georgia DPL EU + Council of Europe context + 2024-2025 pipeline. EU CANDIDATE STATUS: Georgia granted EU CANDIDATE COUNTRY status December 2023 (subject to ongoing reforms + political conditions including democratic backsliding concerns 2024-2025); EU Acquis approximation includes GDPR + the Law Enforcement Directive (EU) 2016/680 + EU eIDAS + ePrivacy + NIS2 + AI Act. The 2023 DPL AMENDMENTS were part of EU Acquis approximation + brought Georgia DPL substantially closer to GDPR alignment. COE CONVENTION 108+ (modernised Council of Europe Convention 108): Georgia is signatory to Convention 108 + the 2018 Protocol amending Convention 108 (Convention 108+); ratification of Convention 108+ anticipated 2025-2026; Convention 108+ provides global DP framework + interoperability + 55+ state parties. EU GDPR ADEQUACY DECISION: NOT YET GRANTED for Georgia + may be sought as part of EU accession n

Artefacts an auditor will ask for
  • EU Acquis approximation tracking
  • Convention 108+ readiness
  • Adequacy decision pursuit
  • Political/legislative monitoring
Where this commonly fails
  • Pre-2023 framework persisting
  • Convention 108+ ratification delayed
  • Adequacy pursuit not aligned
  • Political instability impact unclear
GeDPL-Implementation-Roadmap
Implementation Roadmap - Organizational Roles, Training and PDPS Coordination

Georgia DPL compliance program implementation roadmap. ORGANIZATIONAL ROLES: (a) PRIVACY COUNSEL / DPO (mandatory per 2023 amendments for public + large-scale + special-category processing); (b) PDPS COORDINATOR - PDPS-contact-point + audit cooperation + breach notification + complaint response; (c) CYBERSECURITY LEAD - 72-hour breach + Cybersecurity Act 2025 readiness; (d) INTERNATIONAL TRANSFERS LEAD - SCCs + BCRs + Adequacy + Convention 108+ readiness; (e) RECORDS MANAGER - RoPA + DPIA + retention; (f) TRAINING COORDINATOR - awareness + role-specific. OPERATIONAL CONTROLS: (a) RoPA + DPIA registers + risk assessment; (b) data subject rights portal + 30-day SLA; (c) consent management + age-of-consent + parental verification; (d) breach detection + 72-hour notification procedure; (e) cross-border transfer assessment + safeguards; (f) DPO appointment + PDPS notification; (g) sectoral-sp

Artefacts an auditor will ask for
  • Organizational roles + RACI
  • Operational controls + metrics
  • Multi-language + sectoral evidence
  • 2023 amendment implementation evidence
Where this commonly fails
  • DPO not appointed when required
  • Operational controls partial
  • Multi-language gaps
  • 2023 amendments delayed
GeDPL-Sectoral-Coordination
Sectoral Coordination - Cybersecurity, Banking, Healthcare, Employment and Telecommunications

Georgia DPL sectoral coordination. CONSTITUTION ARTICLE 15: fundamental right to privacy + personal data protection + foundational anchor. CRIMINAL CODE Articles 157 + 158: criminal sanctions for unauthorised personal data disclosure + collection + use + up to 3 years imprisonment + fine. LAW OF GEORGIA ON INFORMATION SECURITY (Law No. 6391-Is of 5 June 2012 + amendments): information security in public + critical-infrastructure entities + integrated with DPL. LAW OF GEORGIA ON CYBERSECURITY (anticipated 2025 + EU NIS2 transposition): essential + important entity registration + risk management + incident reporting; coordinates with DPL for personal-data-related incidents. LAW OF GEORGIA ON ELECTRONIC COMMUNICATIONS: telecommunications operators DP obligations + lawful intercept regime + electronic-marketing rules + coordinates with SVTSL-equivalent + EU ePrivacy Directive alignment. BANK

Artefacts an auditor will ask for
  • Sectoral compliance program per industry
  • Cybersecurity Act readiness if applicable
  • Sector-specific privacy guidance
Where this commonly fails
  • Sectoral coordination ad-hoc
  • Cybersecurity Act not anticipated
  • Employment + healthcare not addressed
GeDPL-Status-2024-2025
Implementation Status, PDPS Enforcement and 2024-2025 Pipeline

Georgia DPL implementation status + PDPS enforcement + 2024-2025 pipeline. STATUS: Law No. 5550-IS of 28 December 2011 in force since 1 May 2012; substantial 2023 amendments (Law No. 3144-RS of 2 June 2023) effective from 1 March 2024 + delayed elements 1 May 2024 + 1 September 2024; ongoing post-2024 implementation + PDPS guidance + enforcement maturation. PDPS ENFORCEMENT: 2024-2025 active complaint-handling + investigations + administrative fines + sectoral guidance; specific enforcement priorities include (a) employment data + workplace monitoring; (b) telemarketing + e-marketing without consent; (c) video surveillance in prohibited zones; (d) cross-border transfer compliance; (e) child online protection; (f) breach notification timeliness. 2024-2025 PIPELINE: (a) further alignment with EU Acquis as accession process matures; (b) Convention 108+ ratification anticipated; (c) Cybersec

Artefacts an auditor will ask for
  • 2023 amendment evidence
  • PDPS engagement + enforcement readiness
  • 2024-2025 readiness plan
  • Political risk monitoring
Where this commonly fails
  • 2023 amendments incomplete
  • PDPS engagement reactive
  • 2024-2025 priorities not addressed
  • Political risk ignored
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Georgia Law on Personal Data Protection (2012) framework page.