Law note · Georgia

Law on Personal Data Protection, biometric data article

cite Law of Georgia on Personal Data Protection, Law No. 3144-XI, Art. 9; Art. 3(d) stage IN FORCE in force since 2024-03-01 kind Biometric privacy binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that captures or stores a facial image, voiceprint, or other biometric identifier from a person in Georgia must have a necessity-based purpose recognized by Art. 9 or the data subject's consent, and must determine in writing, before processing begins, the purpose, volume, storage period, and destruction procedure for that biometric data.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • trains_models
  • crawls_web
Excludes recording-derived identifiers
No

What we found

Art. 3(d) defines biometric data as data processed using technical means and related to the physical, physiological or behavioural characteristics of a data subject, such as facial images, voice characteristics or dactyloscopic data, which allow the unique identification or confirm the identity of that data subject, naming voice and face directly rather than leaving them implicit, the closest match to General Data Protection Regulation (GDPR) Art. 4(14)'s formulation in this batch.

Art. 9 is a dedicated biometric-data article, independent of the Art. 6 special-categories list: biometric data may be processed only for an enumerated list of necessity-based purposes (security or property protection where no less-intrusive means exists, identity-document issuance, border-crossing identification, migration control, international-protection implementation, crime prevention and investigation, detention or sentence enforcement, minor-welfare coordination, operative-investigative activity, information or cyber security, or another case a law directly provides for), and Art. 9(2) requires the controller to determine in writing, before processing begins, the purpose and volume of the biometric data to be processed, its storage period, and its storage and destruction procedure and conditions.

Art. 13 requires the data subject's consent as the default basis, subject to those necessity-based exceptions.

← Back to the example  ·  Lint your app →