Georgia
SubstantialLaw on Personal Data Protection (2011, amended 2023)
Authority: State Inspector's Service / Personal Data Protection Service | Enforcement: Active | Enacted: May 2012
Overview
Georgia enacted data protection legislation in 2011, with significant amendments in 2023 to align with GDPR. The Personal Data Protection Service oversees compliance. Georgia has EU adequacy candidacy under the Association Agreement.
14-Topic Coverage
Data Protection Authority
Fully AddressedPersonal Data Protection Service oversees compliance and enforcement.
Consent Requirements
Fully AddressedConsent or other legitimate basis required. Consent must be free, specific, and informed.
Data Subject Rights
Fully AddressedRights to access, rectification, erasure, restriction, and objection.
Cross-Border Transfer
Fully AddressedTransfers to countries with adequate protection or with appropriate safeguards.
Breach Notification
Fully AddressedMust notify the Service of data breaches. 2023 amendments strengthened notification.
DPO Requirements
Partially AddressedRequired for public bodies. Private sector encouraged.
Children's Data
Partially AddressedGeneral provisions apply. Enhanced protections under 2023 amendments.
Penalties & Enforcement
Fully AddressedAdministrative fines significantly increased by 2023 amendments.
Sector-Specific Rules
Partially AddressedNBG financial data rules, health data regulations.
Cookie/Tracking
Partially AddressedGeneral consent requirements apply.
AI & Automated Decisions
Partially AddressedRight to not be subject to automated decisions under 2023 amendments.
Data Localisation
Not AddressedNo general data localisation requirement.
Significant Data Fiduciary
Not AddressedNo equivalent concept.
Government Data
Fully AddressedLaw applies to government processing with national security exemptions.
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Georgia's regulations.
Book a Consultation