01.08.2026

Personal Data Protection in Georgia: Who Supervises Business Now and What Your Obligations Are

Since 2 March 2026, the supervisory authority for the lawfulness of personal data processing in Georgia is the State Audit Office. The Personal Data Protection Service was abolished and its functions transferred in full to the State Audit Office. Companies' substantive obligations, appointing a data protection officer, reporting incidents within 72 hours, transparency and impact assessment, remain unchanged.

A large part of Georgian business still treats personal data protection legislation the way it treats fire safety instructions: as a formality to be pinned to a wall and forgotten. Before 1 March 2024, that attitude was relatively safe. It no longer is.

The Law of Georgia on Personal Data Protection entered into force on 1 March 2024 and introduced into Georgian law, for the first time, institutions that had previously been discussed only in the context of the EU's GDPR: the data protection officer, mandatory breach notification within 72 hours, and the data processing impact assessment. On 2 March 2026, what changed was who verifies compliance with these obligations.

 

Who supervises personal data protection in Georgia from 2026?

 

Since 2 March 2026, the supervisory authority for the lawfulness of personal data processing in Georgia is the State Audit Office. The Personal Data Protection Service, as an independent legal entity of public law, was abolished on 2 March 2026 pursuant to legislative amendments adopted on 17 December 2025. From the same date, the State Audit Office also supervises covert investigative activities and activities carried out in the central bank of electronic communication identification data.

One point matters most for business here: the substantive obligations have not been relaxed. The part of the law that determines on what basis you may process employee or client data, within what deadline you must report an incident, and whom you must appoint as an officer, remains unchanged. What changed is the address to which notifications are sent, complaints are filed, and inspections are initiated.

In practice, this means that if your internal documents, your privacy policy, incident response rules, employee information forms, still refer to the "Personal Data Protection Service", those documents are out of date. This is the type of defect that surfaces in the first minutes of an inspection and shapes the impression formed about the organisation's general diligence.

 

Who is required to appoint a personal data protection officer?

 

Since 1 June 2024, appointing a personal data protection officer is required of companies that process data on a large scale or systematically process special categories of data: health data, biometric data, and data relating to criminal convictions. This obligation is established by Article 33 of the Law.

Based on L&L Consulting's practice, the organisations that most often fall within this definition are medical institutions and clinics, financial organisations, insurance companies and public bodies. Company management often sincerely believes that "we don't hold a large database" — until it counts how many candidate CVs, video recordings and client identification documents are stored on its servers.

Can the data protection officer be an external person? Yes. Under the Law, the function of the personal data protection officer may be performed by an external provider on the basis of a service agreement. For small and medium-sized businesses, an external officer is usually more rational than creating a dedicated in-house position.

Does the officer need a certificate? No. The Law does not require mandatory certification of the personal data protection officer and does not set specific qualification requirements, but it does require that the person have appropriate knowledge in the field of data protection. An officer appointed as a formality but lacking competence cannot be treated as fulfilment of the obligation.

Conflict of interest deserves separate attention. The data protection officer must not have a conflict of interest, which in the case of an internal appointment often becomes the problem precisely: an IT director or head of HR who personally determines processing operations cannot be an objective reviewer of their own decisions.

 

Within what deadline must a data security incident be reported?

 

A personal data security breach must be reported to the supervisory authority no later than 72 hours after it is discovered. In addition to notification, the organisation is obliged to record every data security breach incident, the consequences that occurred, and the measures taken.

Seventy-two hours is a short deadline when an organisation has no predetermined procedure: who takes the decision, who assesses the risk, who prepares the notification, who communicates with the supervisory authority. That procedure must exist before an incident, not after it.

It is worth noting that breach notification figures in Georgia fall sharply below those of EU member states. That gap points to fewer notifications rather than to fewer incidents.

 

Which obligations are breached most often?

 

Three personal data protection obligations are breached most often by Georgian companies: the transparency obligation, the incident response obligation, and the rules on video and audio monitoring.

Transparency. The Law requires that the data subject: employee, client, candidate be given comprehensible information at the moment the data is collected about who processes their data, for what purpose, on what legal basis and for how long, to whom it is transferred, and what rights the subject holds. A one-page privacy policy published on a website and copied from another site does not satisfy this obligation.

Video and audio monitoring. This is the area where breaches are most visible and most easily detected. The Law sets out where cameras may be placed, in what circumstances audio recording is permitted, how warning signage must be displayed, and how long recordings may be retained. Continuous video monitoring directed at employees in the workplace is no longer a matter for the employer's discretion, it requires separate justification.

 

Is a permit required to transfer data abroad?

 

Cross-border transfer of data is permitted where the receiving country ensures appropriate data protection safeguards, or where such safeguards are secured by an agreement concluded between the controller and the recipient. A transfer based on such an agreement requires a special permit from the supervisory authority.

This is an issue most Georgian companies fail to notice at all, because they do not subjectively perceive it as a "transfer". If your CRM sits on an American server, your HR system in a European cloud, and your accounting software in a third country, you are carrying out a cross-border transfer of data and this requires a separate legal basis. The permit procedure must be planned in advance, not once an inspection is already under way.

For companies applying for or already holding a VASP licence, this is a particularly sensitive matter: KYC/AML procedures involve processing identification data on a large scale, while the technological infrastructure is almost always located abroad. Complying with National Bank requirements does not substitute for data protection obligations, these are two parallel regimes.

 

When is an impact assessment mandatory?

 

A data processing impact assessment is mandatory where the processing, particularly through the use of new technologies, creates a high risk to the rights and freedoms of natural persons. In practice, an impact assessment applies to profiling, automated decision-making, biometric identification systems, large-scale video monitoring, and the deployment of artificial intelligence tools.

Over the past year, the pace at which Georgian businesses have adopted AI tools has increased noticeably. Most companies treat this as an IT or operational decision. In legal terms, however, this is often precisely the case where an impact assessment must be carried out in advance before deployment, not after.

 

Compliance requirements at a glance

 

The Law imposes five principal obligations on companies, each with a different addressee and a different deadline. In summary, the picture is as follows.

Appointing a personal data protection officer is required of organisations that process data on a large scale or systematically process special categories of data. This obligation is established by Article 33 of the Law and has applied since 1 June 2024. Unlike the other obligations, appointing an officer is selective; it does not apply to every company.

Reporting a data security incident, by contrast, applies to every controller without exception. The deadline is no later than 72 hours from discovery of the incident, and this is the only obligation measured in hours and therefore the only one that is practically impossible to meet without a procedure prepared in advance.

The transparency obligation also applies to every controller and is discharged at the moment data is collected: the subject must be informed then about the purpose, legal basis and retention period of the processing and about their own rights, rather than later and on request.

The data processing impact assessment applies only to high-risk processing: profiling, automated decision-making, biometric identification, large-scale video monitoring and the deployment of AI tools. Timing is critical here: the assessment must be carried out before processing begins, not afterwards.

A cross-border transfer permit is required where the transfer relies on safeguards secured by agreement. The permit must be obtained before the transfer begins. Where the receiving country ensures appropriate data protection safeguards, no separate permit is required.

For the precise normative wording, see the consolidated text of the Law on the Legislative Herald of Georgia.

 

How to prepare for an inspection: four stages

 

Achieving personal data protection compliance normally takes a medium-sized company two to three weeks and divides into four stages: a data audit, determining the legal basis, producing documentation, and designating an officer together with staff training.

Stage one — the data audit. Describing the real picture: what data you collect, where it is stored, who has access to it, which third parties receive it, and how long it is retained. This is often the most sobering stage, because it tends to emerge that five people still have access to the files of employees who left years ago.

Stage two — determining the legal basis for each processing operation. Consent is not a universal answer: in an employment relationship consent is often a weak basis because of the inequality between the parties, and replacing it with a statutory or contractual basis is more durable.

Stage three — creating or updating documentation: the privacy policy, employee information form, video monitoring rules, incident response procedure, data retention policy, and a compliance review of agreements concluded with processors, cloud providers, outsourced accountants, HR agencies.

Stage four — designating an officer, whether through internal or external resources, and training staff. Training must not become a formality: most breaches occur not through bad intent but because an employee does not know that forwarding a copy of a client's ID to a personal phone is a breach.


Frequently asked questions

 

Did companies' obligations change after the supervisory authority changed? No. What changed on 2 March 2026 was the supervisory authority, not companies' substantive obligations. All that needs changing is the name of the authority referenced in internal documents and the notification channels.

Is an LLC with 10 employees required to appoint a data protection officer? That depends on the nature of the processing, not on the number of employees. If a company systematically processes special categories of data or processes data on a large scale, the obligation arises regardless of a small headcount.

What happens if a company fails to appoint an officer? The law provides for administrative liability. A warning is stipulated for a first-time offense, whereas the failure by a data controller/authorized person to fulfill the obligation regarding the appointment of a Personal Data Protection Officer within one year from the imposition of an administrative penalty by the Auditor General shall result in a fine of GEL 3,000 on the offender.

Is GDPR compliance sufficient to meet the requirements of Georgian law? No. Georgian law is modelled on the GDPR but is not identical to it. Differences exist in the procedures for cross-border transfers, video monitoring, and dealings with the supervisory authority.

Which authority do I file a complaint with? Since 2 March 2026, the designated authority is the State Audit Office.


Conclusion

 

A change of supervisory authority is no reason to assume that oversight will weaken. Following an institutional transition period, supervisory activity generally intensifies, and the companies most exposed are those that have done nothing since 2024.

Personal data protection compliance is not a one-off project. It is a continuous process that must be updated as a company grows, as new systems are deployed, and as processes change.

L&L Consulting provides full legal support on personal data protection: data audits, preparation of compliance documentation, external data protection officer services, establishing the legal basis for cross-border transfers, and representation in dealings with the supervisory authority.

Contact us for an initial consultation →


About the author

Zurab Loria — Attorney at Law, Managing Partner at L&L Consulting.