Law / United States / Georgia

Disposal of records containing personal information

O.C.G.A. Sec. 10-15-2

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A security baseline statutes rule binding private bodies.

As of 16 September 2026.

What it requires

  • This binds any 'business': a sole proprietorship, partnership, corporation, association, or other group, however organized and whether or not organized to operate at a profit, expressly including a financial institution and an entity that destroys records, that discards or disposes of a customer's record containing personal information.
  • Shred the record, erase the personal information, modify the record to make the personal information unreadable, or take other action you reasonably believe will ensure that no unauthorized person will have access to the personal information, before discarding or disposing of a customer's record. Personal information here is personally identifiable data about a customer's medical condition, account or credit balance, information supplied on opening an account or applying for credit, or a tax return, combined with an identifier such as a Social Security number, driver license number, or date of birth.
  • A bank or financial institution subject to the Gramm-Leach-Bliley Act's privacy and security provisions, a hospital or health care institution subject to HIPAA's privacy and security provisions, or any other entity governed by a federal law that itself requires disposal of such records in the same manner, is exempt from this duty.
  • Expect Attorney General enforcement, using the Fair Business Practices Act's investigative powers, with an administrative penalty of up to $500 per wrongfully discarded customer record, capped at $10,000 total per order; a business that shows it used due diligence in attempting to properly dispose of the record has an affirmative defense, and the statute creates no private right of action of its own.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

The $500.00 figure is per customer's record wrongfully disposed of or discarded, subject to a $10,000.00 total ceiling on the fine levied under any one Attorney General administrative order (O.C.G.A. Sec. 10-15-6(a)). A business that shows it used due diligence in its attempt to properly dispose of or discard the record has an affirmative defense to the violation.

Rule
Per violation only
As of
16 September 2026
Currency
USD
Fixed cap
10,000
Per violation unit
Violation
Per violation amount
500

Who enforces it

Enforcement body

The Attorney General, under O.C.G.A. Sec. 10-15-5(a), using the investigative powers of the Fair Business Practices Act of 1975 (O.C.G.A. Sec. 10-1-390 et seq., including the investigative-demand and subpoena powers of O.C.G.A. Secs. 10-1-403 and 10-1-404). A hearing and any administrative review proceed under the Georgia Administrative Procedure Act, per O.C.G.A. Sec. 10-15-6(c).

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A 'business' may not discard or dispose of a customer's record containing personal information unless it shreds the record, erases the personal information, modifies the record to make the personal information unreadable, or takes other action it reasonably believes will ensure that no unauthorized person will have access to the personal information for the period between disposal and destruction.

'Business' is defined broadly (sole proprietorship, partnership, corporation, association, or other group, organized for profit or not), expressly includes a financial institution and an entity that destroys records, and excludes a bank or financial institution subject to the Gramm-Leach-Bliley Act's privacy and security provisions, a hospital or health care institution subject to HIPAA's privacy and security provisions, and any other entity governed by a federal law that itself requires disposal of such records in the same manner.

'Personal information' is personally identifiable data about a customer's medical condition, account or credit balance or limit, data supplied when opening an account or applying for a loan or credit, or a federal, state, or local income tax return, where 'personally identifiable' requires the data to be combined with an identifier such as a Social Security number, driver license number, passport number, or date of birth; a name, address, or phone number alone is not personally identifiable data under this chapter.

The Attorney General enforces the duty using the Fair Business Practices Act's investigative powers, and may impose an administrative penalty of not more than $500.00 for each wrongfully discarded customer record, capped at $10,000.00 total per order, after notice and a hearing conducted under the Georgia Administrative Procedure Act; a business that shows it used due diligence in its attempt to properly dispose of the record has an affirmative defense.

The chapter states no private right of action for a violation of this duty. The commencement date of this specific Code section is not stated in the unannotated code text consulted here, though the same chapter's receipt-truncation section (O.C.G.A. Sec. 10-15-3(b)(1)) states that its own first phase-in was already in force by July 1, 2004, which places the whole chapter's enactment at or before that date.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

official statute text, Code of Georgia Annotated (unannotated), hosted by FindLaw

Back to the example  ·  Lint your app