Law / Georgia

Georgia

age

Georgia's SB 351 (2024) was enacted as a single act that both restricts minors' social media accounts, requiring parental consent under age 16, and requires age verification on websites publishing material harmful to minors, with both provisions effective July 1, 2025. The social media provisions were preliminarily enjoined in NetChoice v. Carr in June 2025 and remain unenforceable pending Georgia's appeal, argued at the Eleventh Circuit in March 2026.

The separate harmful to minors age verification provision is not part of that suit (the district court's opinion states the case challenges only Section 3-1 of the act, O.C.G.A. Secs. 39-6-1 to 39-6-5) and is currently in effect. Georgia has not enacted an app store age verification or design code law, though state senators have called for one.

privacy

Georgia has no comprehensive consumer-privacy statute. A genuine comprehensive bill, SB 111 (2026), titled the Georgia Consumer Privacy Protection Act, passed the Senate, but the House replaced its entire text with unrelated rural-hospital tax-credit provisions before Governor Kemp signed the substituted bill on May 11, 2026, so no privacy law was actually enacted under that number.

Georgia's operative privacy statute is the narrow Georgia Personal Identity Protection Act, O.C.G.A. Secs. 10-1-910 to 10-1-915, a breach notification and identity-theft statute whose personal information definition covers only a name combined with a Social Security number, driver's license or state ID number, or an account, credit card, or debit card number, with no biometric, genetic, or health category and no general data-subject rights; Georgia courts have held the Act creates no freestanding data-security duty.

The identity-theft statute itself creates no private right of action, but Georgia's general Fair Business Practices Act separately arms a person injured by a deceptive trade practice with an individual civil action for injunctive relief and damages.

The finding that biometric data is not a sensitive or restricted category under Georgia law cannot be pinned to an official-host quote of O.C.G.A. Sec. 10-1-911's definition: Georgia's own annotated code is a subscription LexisNexis product with no free public mirror (the state's designated free portal, http://www.lexisnexis.com/hottopics/gacode/, is a JavaScript application this crawl cannot render, and the Georgia General Assembly's own legislation search at legis.ga.gov is likewise a client-rendered application), and the Attorney General's Consumer Ed guidance page cited on the instrument below paraphrases the notification duty without quoting the definitions section.

The finding rests on the definition as excerpted from secondary legal-reference sources cross-checked against that guidance page's own description of covered data (a driver's license or credit card number), not on a pinned primary quote.

8 instruments named 4 researched in detail As of 2026-08-27

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Adult content age verification (AV)

SB 351 (2024), commercial entity age verification for material harmful to minors

cite O.C.G.A. Sec. 39-5-5 stage IN FORCE in force since 2025-07-01 source official Act text, Office of the Governor of Georgia

Requires a commercial entity that knowingly publishes a substantial portion (more than 33.33 percent) of material harmful to minors on a public website to perform reasonable age verification before granting access, using a digitized identification card, government issued identification, or a method meeting the NIST Identity Assurance Level 2 standard, with a bar on retaining identifying information after access is granted. Not challenged in NetChoice v. Carr, which covers only the act's social media provisions.

Note and primary source

Breach notification

Georgia Personal Identity Protection Act, notification of security breach

cite O.C.G.A. Sec. 10-1-912 stage IMMINENT commencement not set source official guidance quoting O.C.G.A. Sec. 10-1-912, Georgia Attorney General's Consumer Protection Division (Consumer Ed)

An information broker or data collector, including a government agency, that maintains computerized personal information on a Georgia resident must give notice of a breach of the security of the system in the most expedient time possible and without unreasonable delay, unless a law enforcement agency determines notification would compromise a criminal investigation.

A person or business maintaining data on behalf of an information broker or data collector must notify that broker or collector of a breach it discovers, and above a 10,000-resident notification threshold the notifying party must also notify nationwide consumer reporting agencies.

Georgia's operative personal information definition (O.C.G.A. Sec. 10-1-911, a companion definitions section not itself quoted on the page cited below) covers only a name combined with a Social Security number, driver's license or state ID number, or an account, credit card, or debit card number where it could be misused without more; biometric, genetic, and health data are absent from the definition entirely, so a breach of biometric data alone triggers no notice duty.

The Act has no direct notice duty running to a state regulator or the Attorney General, and Georgia courts have held the Act imposes no freestanding data-security standard of conduct in its own right.

What it asks of an app

Enforcement supervision

Georgia Fair Business Practices Act, civil action by individuals

cite O.C.G.A. Sec. 10-1-399 stage IMMINENT commencement not set source official Code of Georgia Annotated text, hosted by the Georgia Attorney General's Consumer Protection Division

Any person who suffers injury or damage from a consumer act or practice that violates the Georgia Fair Business Practices Act may bring an individual civil action, though not a class action, to obtain equitable injunctive relief and to recover general and exemplary damages, with exemplary damages available only for an intentional violation and the court awarding three times actual damages for an intentional violation.

A prevailing injured party is also entitled to reasonable attorneys' fees and expenses of litigation, though fees incurred after rejecting a reasonable written settlement offer within 30 days of the required pre-suit demand are excluded, and fees shift against a plaintiff who continues an action after such a rejection in bad faith or to harass.

This private right of action is separate from, and broader in subject matter than, the Personal Identity Protection Act's breach-notification duty, which itself creates no private right of action.

What it asks of an app

Social media and minors

SB 351 (2024), Protecting Georgia's Children on Social Media Act

cite O.C.G.A. Secs. 39-6-1 to 39-6-5 stage ENJOINED enforcement paused by a court effective 2025-07-01 source official Act text, Office of the Governor of Georgia

Requires social media platforms to use commercially reasonable age verification and to obtain parental consent before a minor under 16 may hold an account, and limits data collection and advertising directed at minors. A federal court preliminarily enjoined these provisions on June 26, 2025.

Note and primary source

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.