Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
What it requires →
Art. 3(d) defines biometric data as data processed using technical means and related to the physical, physiological or behavioural characteristics of a data subject, such as facial images, voice characteristics or dactyloscopic data, which allow the unique identification or confirm the identity of that data subject, naming voice and face directly rather than leaving them implicit, the closest match to General Data Protection Regulation (GDPR) Art. 4(14)'s formulation in this batch.
Art. 9 is a dedicated biometric-data article, independent of the Art. 6 special-categories list: biometric data may be processed only for an enumerated list of necessity-based purposes (security or property protection where no less-intrusive means exists, identity-document issuance, border-crossing identification, migration control, international-protection implementation, crime prevention and investigation, detention or sentence enforcement, minor-welfare coordination, operative-investigative activity, information or cyber security, or another case a law directly provides for), and Art. 9(2) requires the controller to determine in writing, before processing begins, the purpose and volume of the biometric data to be processed, its storage period, and its storage and destruction procedure and conditions.
Art. 13 requires the data subject's consent as the default basis, subject to those necessity-based exceptions.
Breach notification
What it requires →
Art. 29 requires a controller to notify the State Audit Office of an incident within 72 hours of identification, in writing or electronically, with a defined content list covering the circumstances, type, and time; affected data categories, volume, and subject count; mitigation measures; planned data-subject notification timing; and DPO or contact details, unless it is least expected the incident would cause significant damage or pose a significant threat to fundamental rights.
Art. 30 requires notifying affected data subjects immediately or without unreasonable delay, in plain language, where there is a high probability of significant damage or a significant threat to fundamental rights, subject to narrower exceptions for state-security or public-safety categories, or where the controller already took measures preventing significant risk. This closely tracks General Data Protection Regulation (GDPR) Arts. 33-34's 72-hour authority-notification, risk-based subject-notification structure.
Both articles were touched by Law No. 1289 of 17 December 2025; the specific amendment text was not independently read for this document.
Comprehensive regime
What it requires →
The Law of Georgia on Personal Data Protection, Law No. 3144-XI, adopted 14 June 2023, replaced the 2011 Law on Personal Data Protection outright: Art. 89 declares the 2011 law invalid. Commencement was staged under Art. 90: non-substantive provisions took effect on promulgation in June 2023, while the bulk of substantive articles, including Arts. 1-5, 7-30, 32, 34-79, 81, and 83-89, entered into force 1 March 2024.
Lawful bases sit at Art. 5, which was not read article-by-article for this document; Art. 6's special-category grounds were read in full and are recorded in a separate instrument.
Cross border transfer
What it requires →
Art. 37 permits cross-border transfer where the destination state or organization provides appropriate safeguards, through an international treaty, a controller-to-recipient agreement providing appropriate safeguards (which requires a State Audit Office permit under Art. 37(3)), specified statutory bases (criminal-procedure investigative cooperation, alien-status law, international law-enforcement cooperation, or anti-money-laundering and counter-terrorist-financing cooperation), the data subject's written consent after being informed of the destination's inadequate safeguards, vital-interest necessity, or a proportionate public-interest ground.
Art. 38 requires the State Audit Office to maintain and review, at least every three years, a published adequacy list assessed against the destination's international obligations, rights-protection guarantees, onward-transfer rules, and independent supervisory body. No data localization is compelled. Both articles were touched by Law No. 1289 of 17 December 2025; the specific amendment text was not independently read for this document.
Data subject rights
What it requires →
Chapter III of the Act grants a data subject's rights; the penalty schedule (Arts. 72-75) confirms the chapter covers rights whose violation is separately sanctioned, including a right to withdraw consent (Art. 20), a right to appeal (Art. 22), and an obligation on the controller to protect data-subject rights on request (Art. 23).
The individual right-articles within Chapter III (Arts. 10-19) were not read article-by-article for this document, only the chapter's structure and its penalty cross-references; the specific access, rectification, deletion, portability, and objection rights this chapter grants should be confirmed directly before this instrument is treated as a complete account.
Enforcement supervision
What it requires →
The State Audit Office, in its personal-data-protection function (administratively headed by the Head of the Personal Data Protection Service under Art. 88's transitional provisions), is Georgia's supervisory authority, a distinctive institutional choice housing the DPA inside the state audit body rather than a standalone commission.
Administrative penalties (Arts. 66-80) are flat sums rather than a percentage-of-turnover model; Art. 66, for a violation of processing principles, sets GEL 1,000 to 4,000 depending on entity type, turnover, and aggravating circumstances.
No private-right-of-action or civil-compensation provision was found within this Act itself; enforcement reads as regulator-only through the State Audit Office's administrative-penalty powers, though general Georgian civil or tort law may separately provide a damages route outside this Act, which was not researched here.
Sensitive categories
What it requires →
Art. 6 lists special categories of data as race or ethnicity, political, religious, or philosophical belief, professional-union membership, health, sexual life, criminal-proceeding status, conviction or criminal record, trafficking or domestic-violence-victim status, and detention, plus biometric and genetic data processed to allow unique identification of a natural person, with 20 lawful grounds (a through t) for processing such data, far more elaborate than a bare consent-only rule.
One of those grounds, Art. 6(1)(i), permits processing where the data subject has made the data publicly available without explicit prohibition of its use. Georgia's biometric-specific Art. 9 regime applies independently on top of any Art. 6 basis, so a biometric identifier is never governed by Art. 6 alone.