Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Banking & Finance Law
  3. Fintech
  4. Digital Banking
  5. Mobile Banking Compliance

Loading...

Digital Banking

Mobile Banking Compliance

When is processing permitted?

When a statutory ground exists — consent, a transaction, law, an obligation or another established case.

What information may a consumer request?

Confirmation of processing, grounds and purposes, sources of collection and retention period — free of charge.

What is the 72-hour deadline?

Within that time from discovery the State Audit Service must receive written or electronic notification, unless harm is unlikely.

Does a bank need a protection officer?

Yes, a commercial bank is on the list and is obliged to appoint or designate a personal data protection officer.

Who substantiates the processing ground?

The bank — the person responsible for processing.

5 min·...

Grounds for Data Processing

Mobile banking means the continuous processing of personal data, and the law confines this processing to clear grounds: it is permitted where the data subject has given consent for one or several specific purposes; where processing is necessary for the performance of an obligation under a transaction concluded with the data subject or for concluding a transaction at the subject's request; where it is provided for by law; where it is necessary for the performance of duties imposed on the controller by the legislation; and in other cases provided for by law, including the protection of vital interests and significant public interest. Every function of the application — from creating a profile to analysing transactions — must be tied to these grounds; otherwise the processing becomes baseless. Where consent is the ground, it is particularly important that it refer to specific purposes and not be folded into a general formulation.

The Consumer's Right to Information

A data subject is entitled to request from the controller confirmation of whether data concerning the subject is being processed, whether the processing is justified, and to receive free of charge, in accordance with the request, information about the data being processed, the grounds and purposes of processing, the sources of collection and the retention period. On the screen of a banking application this right takes a practical form: the consumer must be able to obtain this information easily, not merely be told that it exists somewhere in the terms. Transparency here is not a formality but the foundation of trust, and the way an institution answers information requests often says more about its compliance than any policy document.

Technical and Organizational Security Measures

The controller is obliged to take appropriate technical and organizational measures to ensure that data are processed in accordance with the law and to be able to confirm this compliance. The measures must correspond to the possible and accompanying threats of processing and include such instruments as pseudonymisation of data and the logging of access to data. In the mobile banking context this means that security is not only a matter of servers: it embraces access management, logging, and processes that restrict even employees' unjustified contact with the data. A security architecture built this way simultaneously serves the regulator's expectations and the customer's peace of mind.

Incident-Related Obligations

Upon discovering an incident, the controller is obliged to record the incident, its consequence and the measures taken, and to notify the State Audit Service in writing or electronically no later than 72 hours from discovery, except where it is unlikely that the incident will cause significant harm. Where an incident is likely with high probability to cause significant harm or a significant threat to a person's fundamental rights, the data subject must be informed at the first opportunity, without unjustified delay, in simple and understandable language — with a general description of the incident, its possible consequences, the measures taken and contact information. An hourly deadline thus overturns the demands on internal procedures: an incident response plan must be written in advance, not improvised at the moment of crisis.

The Data Protection Officer

The law separately defines the circle of persons obliged to appoint or designate a data protection officer: among them are commercial banks, microfinance organisations, insurance organisations and electronic communication companies, as well as persons processing data of a large number of data subjects or conducting systematic and large-scale monitoring of their behaviour. Mobile banking operators almost always fall within this list, because an application directly contains the signs of behaviour monitoring. The appointment of an officer is therefore not a formality — it is the coordination point of the entire compliance system.

The law writes the grounds of processing as a closed list: the data subject's consent for one or several specific purposes; performance of an obligation under a contract with the subject or conclusion of a contract at the subject's request; processing provided by law; performance of duties imposed by legislation on the responsible person; publicly available data; protection of vital interests; significant public interest; legitimate interests — save where the subject's rights override; and processing necessary to consider the subject's application. The duty of substantiating the ground lies precisely with the bank as the person responsible for processing — this is the point from which a compliance programme begins. The second leg is the subject's informedness: the subject may demand confirmation of whether data about them are processed and receive information on the processing — the mobile application interface is the natural channel for exercising this right.

Frequently Asked Questions

What can be a ground for processing in an application?

Consent for a specific purpose, performance of a transaction, a case provided for by law, or the controller's lawful obligation.

Within what time is the service notified of an incident?

The State Audit Service — no later than 72 hours from discovery; the data subject, where significant harm is highly probable — at the first opportunity.

Who appoints a protection officer?

Commercial banks, microfinance organisations, electronic communication companies and persons of large-volume processing or large-scale monitoring.

What must the bank have as a ground for processing?

One of the grounds listed in the law — among them consent, a contractual obligation or legitimate interest; substantiation is the bank's duty.

How We Help on Legal.ge

Mobile banking compliance means managing three rings at once — grounds, security and incidents. Our team will help you determine the grounds of processing, plan security measures and prepare incident response procedures. Contact us for a compliance plan tailored to your service.

Updated: ...

Legal basis:

  • ინფორმაციული უსაფრთხოების შესახებ
  • პერსონალურ მონაცემთა დაცვის შესახებ

Find a Specialist

Professionals working in this field

Banking & Finance Law LawyerBanking & Finance Law AttorneyBanking & Finance Law Occupational health and safety specialist