Law note · Georgia
Law on Personal Data Protection, breach notification
What it requires
- An app that suffers an incident affecting the personal data of a person in Georgia must notify the State Audit Office within 72 hours of identification, and must notify affected data subjects immediately or without unreasonable delay where there is a high probability of significant damage or a significant threat to their fundamental rights.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
What we found
Art. 29 requires a controller to notify the State Audit Office of an incident within 72 hours of identification, in writing or electronically, with a defined content list covering the circumstances, type, and time; affected data categories, volume, and subject count; mitigation measures; planned data-subject notification timing; and DPO or contact details, unless it is least expected the incident would cause significant damage or pose a significant threat to fundamental rights.
Art. 30 requires notifying affected data subjects immediately or without unreasonable delay, in plain language, where there is a high probability of significant damage or a significant threat to fundamental rights, subject to narrower exceptions for state-security or public-safety categories, or where the controller already took measures preventing significant risk. This closely tracks General Data Protection Regulation (GDPR) Arts. 33-34's 72-hour authority-notification, risk-based subject-notification structure.
Both articles were touched by Law No. 1289 of 17 December 2025; the specific amendment text was not independently read for this document.