Law note · Georgia

Law on Personal Data Protection, enforcement and penalties

cite Law of Georgia on Personal Data Protection, Law No. 3144-XI, Arts. 63-80 stage IN FORCE in force since 2024-03-01 kind Enforcement supervision binds public and private bodies reviewed 2026-08-29

What it requires

  • An app processing the personal data of a person in Georgia must be prepared to answer to the State Audit Office's administrative-penalty powers; no private right of action exists under this Act itself, though general Georgian civil or tort law was not researched for this document.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
Private right of action
No

What we found

The State Audit Office, in its personal-data-protection function (administratively headed by the Head of the Personal Data Protection Service under Art. 88's transitional provisions), is Georgia's supervisory authority, a distinctive institutional choice housing the DPA inside the state audit body rather than a standalone commission.

Administrative penalties (Arts. 66-80) are flat sums rather than a percentage-of-turnover model; Art. 66, for a violation of processing principles, sets GEL 1,000 to 4,000 depending on entity type, turnover, and aggravating circumstances.

No private-right-of-action or civil-compensation provision was found within this Act itself; enforcement reads as regulator-only through the State Audit Office's administrative-penalty powers, though general Georgian civil or tort law may separately provide a damages route outside this Act, which was not researched here.

← Back to the example  ·  Lint your app →