Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Corporate & Commercial Law
  3. Business Compliance
  4. Regulatory Compliance
  5. EdTech Compliance

Loading...

Regulatory Compliance

EdTech Compliance

Whose consent is required for processing a pupil’s personal data?

From the age of 16 the pupil consents personally; below 16 the consent of a parent or legal representative is required, and special categories of data need written consent. The platform must take reasonable measures to verify the representative’s consent.

How must an educational platform secure pupil data?

Article 27 requires technical and organisational measures — pseudonymisation, access logging, information security mechanisms — and confidentiality obligations for staff that survive the end of employment.

What is the deadline for notifying a data incident?

The incident must be recorded and notified to the State Audit Service no later than 72 hours from discovery, with categories of data, measures taken and a contact person, unless significant harm is unlikely.

When is an impact assessment mandatory?

When processing children’s data using new technologies creates a high risk to fundamental rights. The document is kept for the whole processing period and at least 1 year after its termination.

5 min·...

Educational technology platforms process the personal data of minors every day: names, ages, contact details, learning results and behavioural statistics. In Georgian law this relationship is governed by the Law of Georgia on Personal Data Protection, which contains a dedicated regime for minors. This page examines what the statute requires of an educational platform — from the lawful basis of each operation to the 72-hour incident notification — and marks the deliberate boundary of the discussion: the status, authorisation and curriculum regulation of educational institutions form a separate legislative sphere whose norms we do not cite here.

Principles and Lawful Bases of Processing

Article 4 sets the principles binding every controller: data must be processed lawfully, fairly and transparently for the pupil and without violating their dignity; collected only for specific, clearly defined and legitimate purposes; processed only to the extent necessary; kept accurate; stored no longer than necessary; and protected by appropriate technical and organisational measures.

Article 5 requires every operation to rest on a lawful basis: consent, a contract with the pupil or steps at their request, a legal provision, a legal obligation, publicly available data, vital interests, a significant public interest or legitimate interests. For a platform this means every function — registration, analytics, communication — must be mapped in advance to its basis, and the burden of substantiation lies on the controller.

The Age of the Pupil and the Consent Regime

The central rule for minors is Article 7: processing of a minor’s data on the basis of consent is permitted if the minor has reached the age of 16, while data of a minor under 16 may be processed with the consent of a parent or other legal representative. The law also contemplates cases where the consent of both a minor between 16 and 18 and the representative is required.

The platform must take reasonable and adequate measures to verify that the consent of the parent or representative of a pupil under 16 exists. Special categories of a minor’s data may be processed only with the representative’s written consent. The controller must protect the best interests of the child, and consent is invalid where processing endangers or harms those interests.

Informing Pupils and Parents at Collection

Article 24 defines the minimum information to be given before or at collection: the controller’s identity and contacts, and where they exist its representative and data protection officer; the purposes and legal basis; whether provision is mandatory and the consequences of refusal; recipients; planned transfers abroad; storage periods or their criteria; and the data subject’s rights.

A distinct requirement concerns form: where the data subject is a minor, the information must be given in simple, understandable language. Upon written request it must nonetheless be provided within 10 working days, and in special cases extended, with justification, by no more than 10 further working days, of which the data subject is notified immediately.

Security, Incidents and Impact Assessment

Article 27 obliges the platform to take appropriate measures and to be able to demonstrate compliance: pseudonymisation, access logging, information security mechanisms, and records of every operation on electronic data, including incidents. Employees must not exceed their authorisation and must preserve confidentiality even after employment ends.

When an incident occurs, Article 29 requires the controller to record it, its consequences and the measures taken, and to notify the State Audit Service no later than 72 hours from discovery, unless significant harm is unlikely. The notification describes the circumstances, the categories and approximate volumes of data and subjects affected, measures taken or planned, and a contact person; incomplete information may be supplied in stages by agreement.

Finally, where processing children’s data with new technologies creates a high risk to fundamental rights, Article 31 makes an impact assessment mandatory: a written document on categories, purposes, proportionality, risks and safeguards. It must be updated when processing changes materially and retained at least 1 year after processing ends. A large number of data subjects means no less than 3 per cent of the population, and where the risk cannot be substantially reduced, the data must not be processed.

Frequently Asked Questions

Below are the questions educational platforms stumble over most often, answered from the precise norms of the Law of Georgia on Personal Data Protection.

Whose consent is needed for a pupil’s data?

A pupil who has reached 16 gives consent personally; for a pupil under 16 the consent of a parent or legal representative is required, and special categories of data may be processed only with written consent.

What must the platform’s information notice contain?

Under Article 24: the controller’s identity and contacts, purposes and legal basis, the mandatory nature of provision, recipients, transfers, storage periods and the pupil’s rights — in simple language a child can understand.

How quickly must an incident be reported?

No later than 72 hours from discovery, to the State Audit Service, in writing or electronically, unless significant harm is unlikely — that is the rule of Article 29.

Does this regime regulate the content of study programmes?

No. This page covers only the protection of pupils’ personal data. The status, authorisation and curriculum requirements of educational institutions are governed by separate legislation that is not cited here.

How We Help on Legal.ge

The lawyers of Legal.ge assemble the complete data-protection layer of an educational platform: we analyse the lawful basis of every operation, build the parental-consent workflow for pupils under 16, audit the information notice, draft the incident-response procedure and the impact-assessment document, and represent the platform before the State Audit Service. Contact us — and pupil data will be handled lawfully.

Updated: ...

Verified against current law: 09/07/2026

Legal basis:

  • უმაღლესი განათლების შესახებ
  • საავტორო და მომიჯნავე უფლებების შესახებ
  • ზოგადი განათლების შესახებ
  • პერსონალურ მონაცემთა დაცვის შესახებ

Find a Specialist

Professionals working in this field

Corporate & Commercial Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law Occupational health and safety specialistCorporate & Commercial Law Personal data protection officer