Law note · Georgia
Law on Personal Data Protection, cross-border transfer
What it requires
- An app transferring the personal data of a person in Georgia to a recipient outside Georgia must rely on the destination being on the State Audit Office's adequacy list, a State Audit Office-permitted contractual safeguard, the data subject's informed written consent, or another Art. 37 statutory basis.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
What we found
Art. 37 permits cross-border transfer where the destination state or organization provides appropriate safeguards, through an international treaty, a controller-to-recipient agreement providing appropriate safeguards (which requires a State Audit Office permit under Art. 37(3)), specified statutory bases (criminal-procedure investigative cooperation, alien-status law, international law-enforcement cooperation, or anti-money-laundering and counter-terrorist-financing cooperation), the data subject's written consent after being informed of the destination's inadequate safeguards, vital-interest necessity, or a proportionate public-interest ground.
Art. 38 requires the State Audit Office to maintain and review, at least every three years, a published adequacy list assessed against the destination's international obligations, rights-protection guarantees, onward-transfer rules, and independent supervisory body. No data localization is compelled. Both articles were touched by Law No. 1289 of 17 December 2025; the specific amendment text was not independently read for this document.