Law note · Georgia

Law on Personal Data Protection, breach notification

cite Law of Georgia on Personal Data Protection, Law No. 3144-XI, Arts. 29-30, as amended by Law No. 1289 (17 December 2025) stage IN FORCE in force since 2024-03-01 kind Breach notification binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that suffers an incident affecting the personal data of a person in Georgia must notify the State Audit Office within 72 hours of identification, and must notify affected data subjects immediately or without unreasonable delay where there is a high probability of significant damage or a significant threat to their fundamental rights.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

What we found

Art. 29 requires a controller to notify the State Audit Office of an incident within 72 hours of identification, in writing or electronically, with a defined content list covering the circumstances, type, and time; affected data categories, volume, and subject count; mitigation measures; planned data-subject notification timing; and DPO or contact details, unless it is least expected the incident would cause significant damage or pose a significant threat to fundamental rights.

Art. 30 requires notifying affected data subjects immediately or without unreasonable delay, in plain language, where there is a high probability of significant damage or a significant threat to fundamental rights, subject to narrower exceptions for state-security or public-safety categories, or where the controller already took measures preventing significant risk. This closely tracks General Data Protection Regulation (GDPR) Arts. 33-34's 72-hour authority-notification, risk-based subject-notification structure.

Both articles were touched by Law No. 1289 of 17 December 2025; the specific amendment text was not independently read for this document.

← Back to the example  ·  Lint your app →