Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Education Law
  3. Education Compliance
  4. EdTech
  5. Student Data Privacy

Loading...

EdTech

Student Data Privacy

Can personal information be demanded?

No — private life is inviolable.

How is academic progress stored?

Separately from disciplinary data.

What is stored in EMIS?

Data of institutions, programmes, personnel and enrolled persons.

Does FERPA apply?

No — protection is determined by Georgian norms.

4 min·...

The Inviolability of Private Life

The legal basis of pupil data confidentiality at school level is Article 17 of the Law on General Education. Under this norm, the private life of the pupil, the parent and the teacher is inviolable — they may not be required to disclose information about their private life. This general guarantee extends to the EdTech context as well: any processing of pupil data collected in a system must be assessed through the prism of this inviolability.

The limits should also be noted: the school has the right to require a pupil and a teacher to undergo medical screening for diseases, alcohol and drugs, but is obliged to ensure the accessibility of such screening; and the arbitrary restriction of the inviolability of private life, private communication, or property in the school's ownership but transferred for personal use is impermissible.

The Collection and Storage of Data

Under paragraph 2 of Article 17, in collecting and storing the personal data of the pupil, the parent and the teacher, the school is obliged to be guided by the requirements of this law and the General Administrative Code of Georgia. The processing must therefore be read through both the constitutional guarantee and the specific statutory rules at once.

For digital systems this means that an EdTech platform is not a legal vacuum: the data entered into it is protected by the same rules as paper records — and the school is responsible for ensuring that its technological partner also satisfies these requirements. The choice of a technology provider is thus a legal decision as much as a commercial one.

The Separation of Academic and Disciplinary Data

A direct norm of the law: information on the pupil's academic progress must be stored separately from disciplinary data. This is the lawful expression of the principles of minimisation and delineation: data of different purposes must be separated from one another.

For an EdTech solution this is a technical requirement: mixing academic and disciplinary records in a single profile is a violation of the law, and the system architecture must provide for this separation from the outset.

EMIS — the Centralised Information System

The second layer is the education management information system. Article 52-1 of the law provides that this system reflects information on general education institutions, educational programmes, the implementing personnel, and the personal data of persons entitled to or enrolled in an educational programme — including, in cases provided by legislation, data on their state of health.

The collection, storage, processing, analysis and administration of the data is ensured by the education management information system in compliance with the requirements of the Law of Georgia on Personal Data Protection, and it is authorised to receive and use personal data existing in other public law entities within the ministry's system.

The EdTech Context and Honest Boundaries

The American FERPA and COPPA data regimes are non-Georgian and cannot be transplanted — the Georgian page is carried by Article 17 of the Law on General Education, Article 52-1 and the law on personal data protection. For an EdTech provider this means three practical requirements: demanding information about the pupil's private life is impermissible; academic and disciplinary data are stored separately; and integration with the centralised system takes place in compliance with the personal data protection law.

Precisely these three conditions should be reflected in the contract — international certification is additional security, not a legal substitute. Encryption and hosting arrangements do not replace the consent and purpose-limitation rules; they only reinforce them.

Frequently Asked Questions

Below we answer the questions most frequently raised about student data confidentiality. The answers address all three circles — the school, the student and the technology partner.

Can personal information be demanded from a pupil?

No — private life is inviolable and disclosure of information cannot be required of a pupil, parent or teacher.

How should academic progress be stored?

Separately from disciplinary data — a direct requirement of the law. The absence of separation is itself a violation rather than a subject of justification.

What is stored in EMIS?

Personal data of institutions, programmes, personnel and enrolled persons — including health data in specified cases.

Which law protects the data?

The Law on General Education, the General Administrative Code and the law on personal data protection.

Does FERPA apply?

No — FERPA and COPPA are non-Georgian regulation; protection is determined by Georgian norms. A foreign provider’s contract must likewise be read through Georgian requirements before any data leaves the system.

How We Help on Legal.ge

The Legal.ge team will check an EdTech system against the Georgian data protection requirements, help formulate the terms of the contract with the provider and prepare a description of the data processing rules. That description separates the roles of the school and of the technology partner and fixes responsibility for each stage.

Contact us on Legal.ge — protecting pupil data is the responsibility of both the school and its technology partner.

Updated: ...

Verified against current law: 27/06/2026

Legal basis:

  • საქართველოს ზოგადი ადმინისტრაციული კოდექსი
  • ზოგადი განათლების შესახებ
  • პერსონალურ მონაცემთა დაცვის შესახებ

Find a Specialist

Professionals working in this field

Education Law LawyerEducation Law Attorney