Law note · Georgia
Law on Personal Data Protection, enforcement and penalties
What it requires
- An app processing the personal data of a person in Georgia must be prepared to answer to the State Audit Office's administrative-penalty powers; no private right of action exists under this Act itself, though general Georgian civil or tort law was not researched for this document.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
- Private right of action
- No
What we found
The State Audit Office, in its personal-data-protection function (administratively headed by the Head of the Personal Data Protection Service under Art. 88's transitional provisions), is Georgia's supervisory authority, a distinctive institutional choice housing the DPA inside the state audit body rather than a standalone commission.
Administrative penalties (Arts. 66-80) are flat sums rather than a percentage-of-turnover model; Art. 66, for a violation of processing principles, sets GEL 1,000 to 4,000 depending on entity type, turnover, and aggravating circumstances.
No private-right-of-action or civil-compensation provision was found within this Act itself; enforcement reads as regulator-only through the State Audit Office's administrative-penalty powers, though general Georgian civil or tort law may separately provide a damages route outside this Act, which was not researched here.