Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Corporate & Commercial Law
  3. Business Compliance
  4. Regulatory Compliance
  5. SaaS Compliance

Loading...

Regulatory Compliance

SaaS Compliance

How does a platform demonstrate compliance without a certificate?

By implementing the statutory technical and organisational measures and being able to prove it: security mechanisms, records of operations and a processing register produced to the State Audit Service within 3 working days of a request.

What happens upon a data incident?

The incident is recorded and notified to the State Audit Service no later than 72 hours from discovery; where significant harm is likely, data subjects are informed without unjustified delay.

When is an impact assessment mandatory?

When new-technology processing creates a high risk to fundamental rights. The document is retained for the whole processing period and at least 1 year after termination.

Is appointing a data protection officer required?

For controllers processing large volumes of data or conducting systematic monitoring it is mandatory; for others voluntary — but it strengthens governance and regulator relations.

5 min·...

Software-as-a-service platforms that process customer data in the cloud usually frame compliance through international certification schemes. Georgian law knows no such certification statute: compliance here means fulfilling — and being able to demonstrate fulfilment of — the specific obligations of the Law of Georgia on Personal Data Protection. That statute builds the auditable framework on which a service provider stands: security measures, records of processing, incident notification, impact assessment and, where thresholds are met, the data protection officer. On this page the lawyers of Legal.ge explain each element of that framework, article by article, as it applies to a platform business.

Principles and Lawful Bases

Article 4 sets the principles: data must be processed lawfully, fairly and transparently; collected for specific, clearly defined purposes; processed only to the extent necessary; kept accurate; stored only as long as needed; and protected by technical and organisational measures. The controller is responsible for compliance with these principles and must be able to substantiate it.

Article 5 lists the lawful bases: the subject’s consent, performance of a contract or steps at the subject’s request, processing provided by law, legal obligations, publicly available data, vital interests, significant public interest and legitimate interests. For a platform this means each function — account creation, analytics, support — is mapped in advance to a specific basis, and that mapping is documented rather than assumed.

Security Measures and Records — the Auditable Core

Article 27 requires appropriate technical and organisational measures and the ability to demonstrate compliance: pseudonymisation, logging of access to data, information security mechanisms covering confidentiality, integrity and availability, records of every operation performed on electronic data, and staff confidentiality that survives the end of employment.

Article 28 adds the documentary layer that makes an audit meaningful: the controller and its representative record, in writing or electronically, identities and contacts, purposes of processing, categories of subjects and data, recipients, transfers to other states, retention periods, security measures and incidents. That information must be provided to the State Audit Service upon request immediately, but no later than 3 working days — a deadline that is practically impossible to meet without a maintained register. Preparing that register before the first request is therefore not diligence but basic risk management.

Incidents: the 72-Hour Rule and Informing Data Subjects

Upon discovering an incident, Article 29 requires recording it together with its consequences and the measures taken, and notifying the State Audit Service in writing or electronically no later than 72 hours from discovery, unless significant harm or risk is unlikely. The notification covers the circumstances, the categories and approximate volumes of data and subjects affected, measures taken or planned, and a contact person; where full information cannot be provided at once, it may be supplied in stages by agreement with the service.

Where the incident is likely to cause significant harm, Article 30 obliges the controller to inform the data subject at the first opportunity, without unjustified delay, in simple language: a general description, the likely damage, the measures taken and contact details. The duty does not arise where appropriate measures eliminated the significant risk or where protected interests apply, and where informing individuals would demand disproportionate effort the information may instead be published publicly.

Impact Assessment and the Data Protection Officer

Where large-scale processing with new technologies creates a high risk to fundamental rights, Article 31 makes a written impact assessment mandatory — covering categories, purposes, proportionality and risks — kept up to date and retained at least 1 year after processing ends. A large number of data subjects means no less than 3 per cent of the population, and where the risk cannot be substantially reduced by additional measures, the data must not be processed at all.

Article 33 completes the governance layer: defined categories of controllers — including those processing a large number of data subjects’ data or carrying out systematic and large-scale monitoring — must appoint a data protection officer accountable to the highest level of management; others may do so voluntarily. The officer’s appointment or change must be notified to the State Audit Service within 10 working days, and the identity and contacts published on the website.

Frequently Asked Questions

Below are the questions platform businesses ask us most often about compliance, answered from the norms of the Law of Georgia on Personal Data Protection.

Is there a Georgian compliance certification for platforms?

No. Compliance is achieved not by certificate but by fulfilling statutory obligations and being able to demonstrate it — security measures, records of processing and incident management.

How fast must an incident be notified?

To the State Audit Service — no later than 72 hours from discovery; to data subjects — at the first opportunity where significant harm is likely.

What must be recorded on an ongoing basis?

Processing-related information — purposes, categories, recipients, transfers, retention periods, security measures and incidents — provided to the State Audit Service upon request within no more than 3 working days.

Who is the data protection officer?

The person coordinating data protection inside the platform: informing staff, monitoring internal regulations and liaising with the State Audit Service. Appointment is mandatory for defined categories and voluntary for the rest.

How We Help on Legal.ge

The lawyers of Legal.ge build the complete compliance system of a platform: we analyse the lawful basis of every processing operation, create the records register, design an incident-response procedure with the 72-hour deadline under control, prepare the impact-assessment document and advise on the data protection officer. Contact us — and your platform’s compliance will be substantiated and inspectable.

Updated: ...

Verified against current law: 09/07/2026

Legal basis:

  • საქართველოს საგადასახადო კოდექსი
  • საქართველოს სამოქალაქო კოდექსი
  • საავტორო და მომიჯნავე უფლებების შესახებ
  • პერსონალურ მონაცემთა დაცვის შესახებ

Find a Specialist

Professionals working in this field

Corporate & Commercial Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law Occupational health and safety specialistCorporate & Commercial Law Personal data protection officer