The legal framework of international data transfers International data transfer unites two different but closely connected questions: first, when the transfer of data to another state or international
Cross-Border DataDoes the institution of standard contractual clauses exist in Georgia In international practice, standard contractual clauses are known as a European mechanism for data transfers — a set of pre-approv
Cross-Border DataWhat cross-border data transfer means under Georgian law Cross-border data transfer means the transfer of data to another state or to an international organisation, and this process is governed by Art
DPO ServicesData Protection Officer (DPO) Advisory and Support Services The new Law of Georgia on Personal Data Protection significantly increases the responsibilities of organizations, making the appointment of
DPO ServicesThe institution of the data protection officer under Georgian legislation The data protection officer is the figure who personally ensures the lawfulness of data protection in an organisation. This in
Data Breach ManagementWhy a data breach response plan is necessary A data breach response plan is a document prepared in advance that defines who, when, within which deadlines and with which content responds to an incident
Data Breach ManagementWhat counts as an incident under Georgian legislation Data breach response in Georgia rests on the norms of the Law on Personal Data Protection, and the first question to answer is the definition of a
Data Breach ManagementAbout this service A data incident — a security failure as a result of which data is accidentally or unlawfully destroyed, lost, altered, disclosed or accessed — is for an organisation not only a tech
Data Breach ManagementThe stage after the incident — remediation and liability A data security breach arrives in three waves: the incident itself, the subsequent remediation, and legal liability. The Law on Personal Data P
Data ProcessingDocument destruction as a form of data processing Document destruction is often perceived as a mere technical operation — passing paper through a shredder or deleting a file. Under Georgian law this i
Data ProcessingWho is the processor Under the definition of Article 3 of the Law on Personal Data Protection, the processor is a natural person, legal person or public institution that processes data for the control
Data ProcessingThe data processing agreement: what happens after signing A data processing agreement shapes the legal link between the controller and the processor. Under the first paragraph of Article 36 of the Geo
Data ProcessingThe legal basis — why a written agreement is mandatory When an organization entrusts data processing to a third party — a service provider, a cloud, a contractor — Article 36 of the Law on Personal Da
Data ProcessingWhat a data retention policy is and why it is needed A data retention policy is an internal document that defines, for each category of data, for how long the data are stored, by which criterion the p
Data ProcessingWhat a legal hold obligation is and why deletion is not an absolute right A legal hold obligation means the systematic management of those situations in which an organisation must retain data even tho
Data Subject RightsData subject rights — the full catalogue Chapter three of the Law on Personal Data Protection grants the data subject eight rights, each answering a specific practical need: how to learn about process
Data Subject RightsWhat the right to data portability is The right to data portability lets the subject take their own data along when moving from one service to another. Under Article 18 of the Law on Personal Data Pro
Data Subject RightsThe right to request information: the Georgian legal frame The institution of a data subject's information request is often labelled with a foreign abbreviation, but in Georgia the right is defined by