Software-as-a-service platforms that process customer data in the cloud usually frame compliance through international certification schemes. Georgian law knows no such certification statute: compliance here means fulfilling — and being able to demonstrate fulfilment of — the specific obligations of the Law of Georgia on Personal Data Protection. That statute builds the auditable framework on which a service provider stands: security measures, records of processing, incident notification, impact assessment and, where thresholds are met, the data protection officer. On this page the lawyers of Legal.ge explain each element of that framework, article by article, as it applies to a platform business.
Principles and Lawful Bases
Article 4 sets the principles: data must be processed lawfully, fairly and transparently; collected for specific, clearly defined purposes; processed only to the extent necessary; kept accurate; stored only as long as needed; and protected by technical and organisational measures. The controller is responsible for compliance with these principles and must be able to substantiate it.
Article 5 lists the lawful bases: the subject’s consent, performance of a contract or steps at the subject’s request, processing provided by law, legal obligations, publicly available data, vital interests, significant public interest and legitimate interests. For a platform this means each function — account creation, analytics, support — is mapped in advance to a specific basis, and that mapping is documented rather than assumed.
Security Measures and Records — the Auditable Core
Article 27 requires appropriate technical and organisational measures and the ability to demonstrate compliance: pseudonymisation, logging of access to data, information security mechanisms covering confidentiality, integrity and availability, records of every operation performed on electronic data, and staff confidentiality that survives the end of employment.
Article 28 adds the documentary layer that makes an audit meaningful: the controller and its representative record, in writing or electronically, identities and contacts, purposes of processing, categories of subjects and data, recipients, transfers to other states, retention periods, security measures and incidents. That information must be provided to the State Audit Service upon request immediately, but no later than 3 working days — a deadline that is practically impossible to meet without a maintained register. Preparing that register before the first request is therefore not diligence but basic risk management.
Incidents: the 72-Hour Rule and Informing Data Subjects
Upon discovering an incident, Article 29 requires recording it together with its consequences and the measures taken, and notifying the State Audit Service in writing or electronically no later than 72 hours from discovery, unless significant harm or risk is unlikely. The notification covers the circumstances, the categories and approximate volumes of data and subjects affected, measures taken or planned, and a contact person; where full information cannot be provided at once, it may be supplied in stages by agreement with the service.
Where the incident is likely to cause significant harm, Article 30 obliges the controller to inform the data subject at the first opportunity, without unjustified delay, in simple language: a general description, the likely damage, the measures taken and contact details. The duty does not arise where appropriate measures eliminated the significant risk or where protected interests apply, and where informing individuals would demand disproportionate effort the information may instead be published publicly.
Impact Assessment and the Data Protection Officer
Where large-scale processing with new technologies creates a high risk to fundamental rights, Article 31 makes a written impact assessment mandatory — covering categories, purposes, proportionality and risks — kept up to date and retained at least 1 year after processing ends. A large number of data subjects means no less than 3 per cent of the population, and where the risk cannot be substantially reduced by additional measures, the data must not be processed at all.
Article 33 completes the governance layer: defined categories of controllers — including those processing a large number of data subjects’ data or carrying out systematic and large-scale monitoring — must appoint a data protection officer accountable to the highest level of management; others may do so voluntarily. The officer’s appointment or change must be notified to the State Audit Service within 10 working days, and the identity and contacts published on the website.
Frequently Asked Questions
Below are the questions platform businesses ask us most often about compliance, answered from the norms of the Law of Georgia on Personal Data Protection.
Is there a Georgian compliance certification for platforms?
No. Compliance is achieved not by certificate but by fulfilling statutory obligations and being able to demonstrate it — security measures, records of processing and incident management.
How fast must an incident be notified?
To the State Audit Service — no later than 72 hours from discovery; to data subjects — at the first opportunity where significant harm is likely.
What must be recorded on an ongoing basis?
Processing-related information — purposes, categories, recipients, transfers, retention periods, security measures and incidents — provided to the State Audit Service upon request within no more than 3 working days.
Who is the data protection officer?
The person coordinating data protection inside the platform: informing staff, monitoring internal regulations and liaising with the State Audit Service. Appointment is mandatory for defined categories and voluntary for the rest.
How We Help on Legal.ge
The lawyers of Legal.ge build the complete compliance system of a platform: we analyse the lawful basis of every processing operation, create the records register, design an incident-response procedure with the 72-hour deadline under control, prepare the impact-assessment document and advise on the data protection officer. Contact us — and your platform’s compliance will be substantiated and inspectable.
