Law note · Georgia

Law on Personal Data Protection, cross-border transfer

cite Law of Georgia on Personal Data Protection, Law No. 3144-XI, Arts. 37-38, as amended by Law No. 1289 (17 December 2025) stage IN FORCE in force since 2024-03-01 kind Cross border transfer binds public and private bodies reviewed 2026-08-29

What it requires

  • An app transferring the personal data of a person in Georgia to a recipient outside Georgia must rely on the destination being on the State Audit Office's adequacy list, a State Audit Office-permitted contractual safeguard, the data subject's informed written consent, or another Art. 37 statutory basis.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

Art. 37 permits cross-border transfer where the destination state or organization provides appropriate safeguards, through an international treaty, a controller-to-recipient agreement providing appropriate safeguards (which requires a State Audit Office permit under Art. 37(3)), specified statutory bases (criminal-procedure investigative cooperation, alien-status law, international law-enforcement cooperation, or anti-money-laundering and counter-terrorist-financing cooperation), the data subject's written consent after being informed of the destination's inadequate safeguards, vital-interest necessity, or a proportionate public-interest ground.

Art. 38 requires the State Audit Office to maintain and review, at least every three years, a published adequacy list assessed against the destination's international obligations, rights-protection guarantees, onward-transfer rules, and independent supervisory body. No data localization is compelled. Both articles were touched by Law No. 1289 of 17 December 2025; the specific amendment text was not independently read for this document.

← Back to the example  ·  Lint your app →