Georgia Law on Personal Data Protection (2012)
Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Georgia DPL: Controller + Processor Obligations, DPO, RoPA, DPIA and Security
Georgia DPL Controller + Processor + Security obligations. CONTROLLER ACCOUNTABILITY (Art. 27): demonstrate compliance through documented policies + records + impact assessments + reviews. PROCESSOR REQUIREMENTS (Art. 28 - GDPR Art. 28 aligned): written contract + processing scope + duration + categories + sub-processor authorisation + return/deletion + audit cooperation. RECORDS OF PROCESSING ACTIVITIES (RoPA, Art. 29 - GDPR Art. 30 aligned): controllers + processors maintain RoPA including categories + purposes + recipients + cross-border + retention + technical/organisational measures. DATA PROTECTION OFFICER (DPO, Art. 30 - 2023 NEW MANDATORY): for (a) public authorities + bodies; (b) controllers/processors whose core activities require regular + systematic monitoring on large scale; (c) controllers/processors processing special-category data on large scale + criminal data on large s
- RoPA + DPIA records
- DPO appointment + notification + qualifications
- Processor agreement template
- Security measure inventory + testing
- RoPA missing or incomplete
- DPO not mandated when required
- Processor agreement weak
- Security measures not state-of-the-art
Georgia DPL: Cross-Border Transfers, Breach Notification (72-Hour) and Special Provisions
Georgia DPL cross-border + breach + special-context regimes. CROSS-BORDER TRANSFERS (Art. 35-37 - GDPR Chapter V aligned): personal data may be transferred outside Georgia only where: (a) ADEQUACY - the destination country provides adequate level of protection (Minister of Justice determination + EU/EEA + Convention 108+ countries); (b) APPROPRIATE SAFEGUARDS - binding corporate rules + standard contractual clauses (SCCs) + approved code of conduct + approved certification + ad hoc clauses approved by PDPS; (c) DEROGATIONS - explicit consent + contract necessity + public interest + legal claims + vital interests + register access. BREACH NOTIFICATION (Art. 38 - 2023 NEW + GDPR Art. 33-34 aligned): controllers must notify the PDPS within 72 HOURS of becoming aware of a breach likely to result in risk to natural persons; without undue delay to data subjects if breach likely to result in HI
- Cross-border DPIA + transfer mechanism
- Breach response procedure + 72-hour SLA
- Video surveillance policy + signage
- E-marketing consent + soft opt-in
- Transfers without adequacy/safeguards
- 72-hour SLA missed
- Video surveillance in prohibited zones
- E-marketing without consent or soft opt-in
Georgia DPL: Data Subject Rights (Access, Rectification, Erasure, Portability, Objection, ADM)
Georgia DPL Data Subject Rights (Articles 21-26 - GDPR Chapter III aligned post-2023). RIGHTS: (1) RIGHT TO INFORMATION + TRANSPARENCY (Art. 21) - clear + accessible + at-collection notice; (2) RIGHT OF ACCESS (Art. 22) - confirmation + copy + purposes + categories + recipients + retention + rights information + cross-border transfers; (3) RIGHT TO RECTIFICATION (Art. 23) - correction of inaccurate or incomplete data; (4) RIGHT TO ERASURE / BE FORGOTTEN (Art. 24) - deletion when data no longer necessary + consent withdrawn + objection sustained + unlawful processing + legal obligation + child consent; (5) RIGHT TO RESTRICT PROCESSING (Art. 25) - limiting processing during accuracy dispute + pending objection + unlawful processing + retention for legal claims; (6) RIGHT TO DATA PORTABILITY (Art. 26 - 2023 NEW) - receive personal data provided + structured + commonly-used + machine-readabl
- Rights request log + 30-day tracking
- ADM policy + human review + opt-out
- Identity verification policy
- Rights gaps post-2023
- 30-day SLA missed
- ADM protections not implemented
- Identity verification too weak/strong
Georgia DPL: Lawful Basis, Consent, Special Categories and Children
Georgia DPL lawful basis + consent + special categories + children. LAWFUL BASIS (Art. 5 - GDPR Art. 6 aligned): (a) CONSENT of the data subject; (b) CONTRACT performance + pre-contractual measures; (c) LEGAL OBLIGATION of the controller; (d) VITAL INTERESTS of the data subject or another natural person; (e) PUBLIC INTEREST + official authority; (f) LEGITIMATE INTERESTS of the controller or third party balanced against data subject rights. CONSENT (Art. 6): must be FREELY GIVEN + SPECIFIC + INFORMED + UNAMBIGUOUS + WITHDRAWABLE at any time (and as easy to withdraw as to give); EXPLICIT CONSENT required for special categories; PARENTAL CONSENT required for processing personal data of children UNDER 16 in information-society services context; presumed-consent + pre-ticked-boxes + opt-out PROHIBITED. SPECIAL CATEGORIES (Art. 7 + 8 - GDPR Art. 9 aligned): race + ethnicity + political opinion
- Lawful basis register
- Consent records + withdrawal mechanism
- Special-category lawful basis + DPIA
- Age-of-consent verification + parental consent for children
- Lawful basis ambiguous
- Implied/pre-ticked consent
- Special-category processed without explicit consent
- Age verification weak
Georgia DPL: Personal Data Protection Service (PDPS), Enforcement and Sanctions
Personal Data Protection Service (PDPS - Sakartvelos Personalur Monatsemta Datsvis Sammartveloba) - the Georgian supervisory authority established by the 2012 Law + significantly strengthened by the 2023 amendments. INDEPENDENCE (Art. 40-9): the PDPS is an independent body + the Head is elected by Parliament for a 5-year term + may be re-elected once; financial + functional + structural independence. POWERS (Art. 40-2 + 40-11 + 40-13): (a) MONITORING + INVESTIGATION + COMPLAINT-HANDLING; (b) INSPECTION powers including premises entry + records access + interviews + IT systems inspection; (c) GUIDANCE + RECOMMENDATIONS + standards; (d) ENFORCEMENT through INSTRUCTIONS + administrative + criminal referrals; (e) ADMINISTRATIVE FINES (Art. 40-13): per-violation civil penalties up to GEL 20,000 (2023 amendments substantially increased from earlier GEL 200-1,000; the 2023 reform aimed at GDPR-
- PDPS-contact-point + cooperation playbook
- Penalty risk assessment
- Appeals procedure
- PDPS engagement reactive only
- Penalty risk under-assessed
- Appeals unfamiliar
Georgia DPL: Scope, Applicability, Definitions and 2023 GDPR-Alignment Amendments
Georgia DPL Scope + applicability + 2023 GDPR-aligned amendments. SCOPE: applies to natural-person personal data processing in Georgia + (post-2023 amendments) EXTRATERRITORIAL APPLICATION to processing related to offering of goods or services to data subjects in Georgia or monitoring of behaviour in Georgia (GDPR Art. 3(2) aligned). APPLICABILITY: controllers + processors operating in Georgia + foreign entities with Georgia-targeted activities; public authorities + private sector + non-profits. DEFINITIONS: PERSONAL DATA = information relating to an identified or identifiable natural person (GDPR-aligned); CONTROLLER + PROCESSOR (GDPR-aligned roles); CONSENT (freely given + specific + informed + unambiguous); SENSITIVE DATA (Art. 9 GDPR special categories); CHILD = under 16 (Georgia age of digital consent); BIOMETRIC + GENETIC DATA per GDPR. 2023 AMENDMENTS (Law No. 3144-RS of 2 June 20
- Applicability assessment incl extraterritorial
- 2023 amendment readiness + implementation
- Definitions glossary + GDPR mapping
- Pre-2023 framework still applied
- Extraterritorial scope underestimated
- Definitions not GDPR-aligned
Georgia DPL: Sectoral Coordination, EU-Accession + CoE Convention 108+ and 2024-2025 Status
Georgia DPL crosswalk to major DP regimes. EU GDPR (Regulation (EU) 2016/679): post-2023 amendments substantially aligned + most GDPR concepts (extraterritorial scope + 7 lawful bases + 8 special-category bases + 7 data subject rights + DPO + DPIA + 72-hour breach + cross-border SCC/BCR + administrative fines) are now in Georgia DPL with some local adaptations; ADEQUACY DECISION not yet granted but pursued via EU accession. EU LAW ENFORCEMENT DIRECTIVE (EU) 2016/680: Georgia has separate regime for personal data processing by competent authorities for criminal-offence purposes + coordinated with DPL. EU AI ACT (Regulation (EU) 2024/1689): Georgia may align via EU accession; high-risk AI systems + biometric identification + emotion recognition + automated decision-making + EU AI Act competent authorities likely include PDPS. EU NIS2 (Directive (EU) 2022/2555): Cybersecurity Act 2025 antic
- GDPR + Convention 108+ + EU AI Act alignment evidence
- Bilateral DP cooperation engagement
- Multi-regime compliance program
- GDPR alignment partial
- Convention 108+ not ratified
- Bilateral cooperation absent
Georgia DPL EU + Council of Europe context + 2024-2025 pipeline. EU CANDIDATE STATUS: Georgia granted EU CANDIDATE COUNTRY status December 2023 (subject to ongoing reforms + political conditions including democratic backsliding concerns 2024-2025); EU Acquis approximation includes GDPR + the Law Enforcement Directive (EU) 2016/680 + EU eIDAS + ePrivacy + NIS2 + AI Act. The 2023 DPL AMENDMENTS were part of EU Acquis approximation + brought Georgia DPL substantially closer to GDPR alignment. COE CONVENTION 108+ (modernised Council of Europe Convention 108): Georgia is signatory to Convention 108 + the 2018 Protocol amending Convention 108 (Convention 108+); ratification of Convention 108+ anticipated 2025-2026; Convention 108+ provides global DP framework + interoperability + 55+ state parties. EU GDPR ADEQUACY DECISION: NOT YET GRANTED for Georgia + may be sought as part of EU accession n
- EU Acquis approximation tracking
- Convention 108+ readiness
- Adequacy decision pursuit
- Political/legislative monitoring
- Pre-2023 framework persisting
- Convention 108+ ratification delayed
- Adequacy pursuit not aligned
- Political instability impact unclear
Georgia DPL compliance program implementation roadmap. ORGANIZATIONAL ROLES: (a) PRIVACY COUNSEL / DPO (mandatory per 2023 amendments for public + large-scale + special-category processing); (b) PDPS COORDINATOR - PDPS-contact-point + audit cooperation + breach notification + complaint response; (c) CYBERSECURITY LEAD - 72-hour breach + Cybersecurity Act 2025 readiness; (d) INTERNATIONAL TRANSFERS LEAD - SCCs + BCRs + Adequacy + Convention 108+ readiness; (e) RECORDS MANAGER - RoPA + DPIA + retention; (f) TRAINING COORDINATOR - awareness + role-specific. OPERATIONAL CONTROLS: (a) RoPA + DPIA registers + risk assessment; (b) data subject rights portal + 30-day SLA; (c) consent management + age-of-consent + parental verification; (d) breach detection + 72-hour notification procedure; (e) cross-border transfer assessment + safeguards; (f) DPO appointment + PDPS notification; (g) sectoral-sp
- Organizational roles + RACI
- Operational controls + metrics
- Multi-language + sectoral evidence
- 2023 amendment implementation evidence
- DPO not appointed when required
- Operational controls partial
- Multi-language gaps
- 2023 amendments delayed
Georgia DPL sectoral coordination. CONSTITUTION ARTICLE 15: fundamental right to privacy + personal data protection + foundational anchor. CRIMINAL CODE Articles 157 + 158: criminal sanctions for unauthorised personal data disclosure + collection + use + up to 3 years imprisonment + fine. LAW OF GEORGIA ON INFORMATION SECURITY (Law No. 6391-Is of 5 June 2012 + amendments): information security in public + critical-infrastructure entities + integrated with DPL. LAW OF GEORGIA ON CYBERSECURITY (anticipated 2025 + EU NIS2 transposition): essential + important entity registration + risk management + incident reporting; coordinates with DPL for personal-data-related incidents. LAW OF GEORGIA ON ELECTRONIC COMMUNICATIONS: telecommunications operators DP obligations + lawful intercept regime + electronic-marketing rules + coordinates with SVTSL-equivalent + EU ePrivacy Directive alignment. BANK
- Sectoral compliance program per industry
- Cybersecurity Act readiness if applicable
- Sector-specific privacy guidance
- Sectoral coordination ad-hoc
- Cybersecurity Act not anticipated
- Employment + healthcare not addressed
Georgia DPL implementation status + PDPS enforcement + 2024-2025 pipeline. STATUS: Law No. 5550-IS of 28 December 2011 in force since 1 May 2012; substantial 2023 amendments (Law No. 3144-RS of 2 June 2023) effective from 1 March 2024 + delayed elements 1 May 2024 + 1 September 2024; ongoing post-2024 implementation + PDPS guidance + enforcement maturation. PDPS ENFORCEMENT: 2024-2025 active complaint-handling + investigations + administrative fines + sectoral guidance; specific enforcement priorities include (a) employment data + workplace monitoring; (b) telemarketing + e-marketing without consent; (c) video surveillance in prohibited zones; (d) cross-border transfer compliance; (e) child online protection; (f) breach notification timeliness. 2024-2025 PIPELINE: (a) further alignment with EU Acquis as accession process matures; (b) Convention 108+ ratification anticipated; (c) Cybersec
- 2023 amendment evidence
- PDPS engagement + enforcement readiness
- 2024-2025 readiness plan
- Political risk monitoring
- 2023 amendments incomplete
- PDPS engagement reactive
- 2024-2025 priorities not addressed
- Political risk ignored
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Georgia Law on Personal Data Protection (2012) framework page.