
Data Protection for Businesses Operating in Georgia
A business should map its personal-data processing, identify purpose and legal basis, give accurate notices, allocate controller and processor roles, control vendors and transfers, set retention, and prepare for rights requests and incidents under Georgia's current Personal Data Protection Law.
Why this issue changes business decisions
The inventory should follow systems rather than departments. A customer-support platform may contain customer, employee and vendor information, be hosted abroad, be accessed by a group company and use subprocessors. Each purpose, role, recipient and retention rule must be understood before a notice or contract is drafted.
Georgian law and the EU GDPR are separate scope questions. A Georgian company may be subject to GDPR because of its EU establishment or activities, but not merely because GDPR is a well-known standard. The company should document which regime applies to which processing and avoid both overclaiming and under-compliance.
What the official Georgian sources show
The current primary source is the Law of Georgia on Personal Data Protection at Matsne document 5827307. Older pages and policies may still link to superseded legislation, so source references and templates should be updated. Official source
From 2 March 2026, the State Audit Office became the legal successor to the former Personal Data Protection Service for supervision of the lawfulness of personal-data processing. Businesses should use the current consolidated law and the successor authority's channels when checking supervisory procedure. Official source
Controller and processor labels should match decision-making and operation. A contract cannot make a party a processor if it independently determines purposes, while a service provider following documented instructions requires appropriate confidentiality, security, assistance and return or deletion terms. Official source
Rights and incident procedures need operational owners. Customer support, HR, security and management should know how to recognise a request or event, preserve evidence, verify identity, assess deadlines and obtain legal input.
Decisions to record before the company acts
Create a data map covering purpose, role, system, recipient, access location and retention.
Update notices and consent language to match actual processing.
Review vendor, cloud and intra-group data terms and subprocessing.
Test a rights request, deletion request and security-incident escalation.
Issues counsel should connect
Data mapping
Document categories, subjects, purposes, systems, recipients, locations, retention and security owners.
Lawful processing
Assess legal basis, proportionality, transparency and special-category or high-risk issues.
Notices and records
Prepare customer, employee, website and applicant notices and internal processing records.
Vendor and group terms
Allocate controller/processor roles, instructions, confidentiality, security, assistance, return and audit.
Rights and incidents
Create intake, identity, assessment, response, evidence and escalation procedures.
High-risk change
Review new products, monitoring, AI, profiling, biometrics, large-scale processing and transfers before deployment.
A practical sequence for this matter
- 1
Interview business and technical owners and inventory systems and vendors.
- 2
Map purposes, legal roles, bases, disclosures, retention and transfers.
- 3
Prioritise high-risk gaps and any immediate rights or incident issue.
- 4
Prepare documents, contract amendments, registers and staff procedures.
- 5
Train responsible roles and test a sample request, deletion and incident scenario.
Documents and evidence
- processing and system inventory
- privacy notices and consent language
- employee and recruitment documents
- vendor and intra-group data terms
- retention and deletion schedule
- rights-request register
- incident response and breach record
- impact and transfer assessments where required
Risks to test
- notice and practice diverge
- consent is used where it is not appropriate
- controller/processor roles are misclassified
- vendor contract omits assistance or deletion
- data is retained without a purpose
- rights or incidents are not recognised and escalated
Official public sources used
This publication cites only legislation, registries and regulators. It does not rely on other law firms or competitor commentary as authority.