All posts

Data protection in Georgia: the State Audit Service took over in March 2026

Georgia’s data protection law has no market-place criterion, caps fines at 10,000 lari — and since 2 March 2026 has a different supervisory authority from the one every secondary source still names.

Georgia rewrote its data protection law in 2023 with the GDPR in view — but not everywhere. Three divergences decide whether a European company has anything to do in Georgia at all, and a fourth has made half the secondary literature wrong since March 2026.

The supervisory authority has changed

Anyone looking up the Georgian data protection authority today finds the Personal Data Protection Service. That is out of date. Under Law No. 1289 of 17 December 2025, in force since 2 March 2026, competence has passed to the State Audit Service, acting through the Auditor General. The former service’s organisational provisions have been repealed; in the consolidated text it survives only in a transitional provision.

That is not a formality. It changes four addresses at once:

  • Notification of data protection incidents
  • Notification of the data protection officer and their contact details
  • Registration of a foreign controller’s special representative
  • Prior authorisation for contract-based transfers to third countries

Sub-statutory acts issued by the former service remain in force for the time being — the power to amend or repeal them now sits with the Auditor General.

No market-place principle

The most consequential divergence from the GDPR sits in the scope provision. The Georgian statute covers processing on Georgian territory — and beyond that, processing by a controller registered outside Georgia where they use technical means located in Georgia for it. Mere transit through such means is excluded.

That is the older connecting factor of the 1995 European directive, not the GDPR’s market-place principle. A criterion attaching to offering goods or services to people in Georgia, or to monitoring their behaviour, does not appear in the statute.

The special representative — and who does not need one

Where scope is triggered, a duty follows that the GDPR does not have in this form. A controller or processor registered abroad using technical means in Georgia must, before processing begins, appoint a special representative in Georgia and register them with the authority. The statute puts the consequence sharply: the right to process data arises only after that registration.

Two paragraphs further on sits the exception that covers almost every European client: the duty does not apply to controllers and processors established in an EU member state and subject to its data protection rules — nor to those in a state the EU has recognised as adequate.

Transfers to the EU: unrestricted

On third-country transfers Georgia is more generous than the structure suggests. A transfer is permitted where the statute’s requirements are met and adequate safeguards exist in the recipient state. Alongside that sit further routes: an international treaty, a contract containing adequate safeguards between controller and recipient, specific statutory mandates, written consent after being informed of the absence of safeguards, and vital or substantial public interests.

Only the contractual route requires authorisation — prior authorisation from the supervisory authority.

The decisive question is therefore whether the destination is on the adequacy list. That list is not in the statute but in an order of the Auditor General, and it must be reviewed at least every three years. The version in force from 14 April 2026 names 49 states — including all 27 EU member states individually, plus Iceland, Liechtenstein and Norway, and among others the United Kingdom, Switzerland, Japan, Canada and Israel.

Scenario Georgia → EU/EEA Georgia → unlisted state
Basis adequate safeguards recognised contract with safeguards, or consent
Prior authorisation only on the contractual route
Onward transfer only for the same purpose only for the same purpose

The fine range tops out at 10,000 lari

Here Georgian law parts most clearly from the GDPR. It works not with a percentage of group turnover but with fixed amounts across two tiers, divided at 500,000 lari of annual turnover. Branches of foreign undertakings are expressly covered.

Breaching a processing principle costs 1,000 or 2,000 lari at the base tier, 1,500 or 3,000 with aggravating circumstances. Processing without a legal basis sits at the same level. The most expensive offence in the statute is failing to inform data subjects of an incident: 3,000 or 5,000 lari, rising to 10,000 lari with aggravating circumstances. That is the highest figure in the entire law — a low four-figure euro amount at current rates.

Two offences fall outside the pattern because they carry no fine at first: failing to appoint a data protection officer draws only a warning; a repeat within a year of the sanction costs 3,000 lari. For a missing special representative the repeat sits at 5,000 lari.

The counterpoint to the modest money sits in the powers. The authority may suspend or permanently prohibit processing, order erasure or destruction, and forbid transfers abroad. Its production orders expressly reach state, tax, banking, commercial and professional secrets, and it has a right of entry. Judging the exposure by the size of the fine measures the wrong end. Time, however, is tight: proceedings are barred four months after the act, or after discovery for a continuing breach.

Who needs a data protection officer

The duty is sector-based, and on that point wider than the GDPR: public institutions, insurers, commercial banks, microfinance organisations, credit bureaus, telecommunications undertakings, airlines, airports and medical institutions all need one — regardless of the volume or risk of their processing.

To that is added the familiar catch-all: processing the data of a large number of data subjects, or systematic large-scale monitoring of their behaviour. The statute names no figure for “large number”; it delegates the boundary to an act of the Auditor General.

An external provider is permitted, as is a shared officer across several controllers. Identity and contact details must be notified to the authority within ten working days and published on the website.

If you employ staff in Georgia and process employee data, the employment side is in Employment contracts in Georgia; who may advise you in Georgia is in Who may advise you in Georgia.

Georgian data protection — frequently asked

Who is the Georgian data protection authority?

Since 2 March 2026 the State Audit Service, acting through the Auditor General. Until then it was the Personal Data Protection Service, whose organisational provisions have been repealed. Sub-statutory acts issued by the former body remain in force for now; the power to amend them has passed over.

Does the law apply to my company abroad?

Only where you use technical means located in Georgia for the processing — mere transit does not count. The Georgian statute contains no equivalent of the GDPR’s market-place principle, which attaches to offering goods or services or to monitoring behaviour.

Do I need a representative in Georgia?

A controller registered abroad who uses technical means in Georgia must appoint and register a special representative before processing begins — the right to process arises only once that registration is done. Controllers established in an EU member state, and those in states the EU has recognised as adequate, are exempt.

May I transfer data from Georgia to the EU?

Yes, without prior authorisation. The Auditor General’s adequacy list names all 27 EU member states and the three EEA states individually. The authorisation requirement applies only to the contractual route into states that are not listed.

How high are the fines?

Considerably lower than under the GDPR. The statute works with fixed amounts across two turnover tiers, divided at 500,000 lari of annual turnover. The highest figure anywhere in the law is 10,000 lari — for failing to inform data subjects of an incident under aggravating circumstances.

This article is general information and does not constitute legal or tax advice. Sourced are the data protection law in its Georgian text (publication 9, consolidated 10 June 2026), amending Law No. 1289 and Auditor General order No. 007. The adequacy list is a sub-statutory act reviewed at least every three years — check the version then in force before any transfer. Whether and when the Auditor General replaces the former service’s remaining acts is open. As at August 2026.

Sources

Every legal statement in this article is backed by the primary source listed below.

  1. Law of Georgia on Personal Data Protection No. 3144, Arts. 2, 5, 33, 34, 37, 38, 51, 52, 65 to 87 — Georgian text, publication 9, consolidated 10 June 2026
  2. Law of Georgia No. 1289 of 17 December 2025 — transfer of supervision to the State Audit Service — in force from 2 March 2026
  3. Order No. 007 of the Auditor General of 14 April 2026 — list of states with adequate safeguards — 49 states, including every EU and EEA state individually