Educational technology platforms process the personal data of minors every day: names, ages, contact details, learning results and behavioural statistics. In Georgian law this relationship is governed by the Law of Georgia on Personal Data Protection, which contains a dedicated regime for minors. This page examines what the statute requires of an educational platform — from the lawful basis of each operation to the 72-hour incident notification — and marks the deliberate boundary of the discussion: the status, authorisation and curriculum regulation of educational institutions form a separate legislative sphere whose norms we do not cite here.
Principles and Lawful Bases of Processing
Article 4 sets the principles binding every controller: data must be processed lawfully, fairly and transparently for the pupil and without violating their dignity; collected only for specific, clearly defined and legitimate purposes; processed only to the extent necessary; kept accurate; stored no longer than necessary; and protected by appropriate technical and organisational measures.
Article 5 requires every operation to rest on a lawful basis: consent, a contract with the pupil or steps at their request, a legal provision, a legal obligation, publicly available data, vital interests, a significant public interest or legitimate interests. For a platform this means every function — registration, analytics, communication — must be mapped in advance to its basis, and the burden of substantiation lies on the controller.
The Age of the Pupil and the Consent Regime
The central rule for minors is Article 7: processing of a minor’s data on the basis of consent is permitted if the minor has reached the age of 16, while data of a minor under 16 may be processed with the consent of a parent or other legal representative. The law also contemplates cases where the consent of both a minor between 16 and 18 and the representative is required.
The platform must take reasonable and adequate measures to verify that the consent of the parent or representative of a pupil under 16 exists. Special categories of a minor’s data may be processed only with the representative’s written consent. The controller must protect the best interests of the child, and consent is invalid where processing endangers or harms those interests.
Informing Pupils and Parents at Collection
Article 24 defines the minimum information to be given before or at collection: the controller’s identity and contacts, and where they exist its representative and data protection officer; the purposes and legal basis; whether provision is mandatory and the consequences of refusal; recipients; planned transfers abroad; storage periods or their criteria; and the data subject’s rights.
A distinct requirement concerns form: where the data subject is a minor, the information must be given in simple, understandable language. Upon written request it must nonetheless be provided within 10 working days, and in special cases extended, with justification, by no more than 10 further working days, of which the data subject is notified immediately.
Security, Incidents and Impact Assessment
Article 27 obliges the platform to take appropriate measures and to be able to demonstrate compliance: pseudonymisation, access logging, information security mechanisms, and records of every operation on electronic data, including incidents. Employees must not exceed their authorisation and must preserve confidentiality even after employment ends.
When an incident occurs, Article 29 requires the controller to record it, its consequences and the measures taken, and to notify the State Audit Service no later than 72 hours from discovery, unless significant harm is unlikely. The notification describes the circumstances, the categories and approximate volumes of data and subjects affected, measures taken or planned, and a contact person; incomplete information may be supplied in stages by agreement.
Finally, where processing children’s data with new technologies creates a high risk to fundamental rights, Article 31 makes an impact assessment mandatory: a written document on categories, purposes, proportionality, risks and safeguards. It must be updated when processing changes materially and retained at least 1 year after processing ends. A large number of data subjects means no less than 3 per cent of the population, and where the risk cannot be substantially reduced, the data must not be processed.
Frequently Asked Questions
Below are the questions educational platforms stumble over most often, answered from the precise norms of the Law of Georgia on Personal Data Protection.
Whose consent is needed for a pupil’s data?
A pupil who has reached 16 gives consent personally; for a pupil under 16 the consent of a parent or legal representative is required, and special categories of data may be processed only with written consent.
What must the platform’s information notice contain?
Under Article 24: the controller’s identity and contacts, purposes and legal basis, the mandatory nature of provision, recipients, transfers, storage periods and the pupil’s rights — in simple language a child can understand.
How quickly must an incident be reported?
No later than 72 hours from discovery, to the State Audit Service, in writing or electronically, unless significant harm is unlikely — that is the rule of Article 29.
Does this regime regulate the content of study programmes?
No. This page covers only the protection of pupils’ personal data. The status, authorisation and curriculum requirements of educational institutions are governed by separate legislation that is not cited here.
How We Help on Legal.ge
The lawyers of Legal.ge assemble the complete data-protection layer of an educational platform: we analyse the lawful basis of every operation, build the parental-consent workflow for pupils under 16, audit the information notice, draft the incident-response procedure and the impact-assessment document, and represent the platform before the State Audit Service. Contact us — and pupil data will be handled lawfully.
