About this service
Artificial-intelligence systems live on data: they collect, analyse, classify and make decisions based on it. The Georgian law on personal data protection contains no separate chapter for artificial intelligence — and that is the first thing anyone working in this field must know. Processing within such systems is assessed under the law's general norms: the principles of processing, the legal bases, the special regime for automated decisions and the impact-assessment duty. This service builds the legal assessment of your system on precisely these four pillars — from product design to operation.
The principles — where every assessment begins
Article 4 of the law establishes the principles of processing, which extend fully to AI systems: data must be processed lawfully, fairly, transparently for the subject and without violating their dignity; data must be collected only for concrete, clearly defined and legitimate purposes, and further processing incompatible with the original purpose is impermissible; data must be processed only to the extent necessary for the purpose; and data must be accurate. For AI, concrete questions quickly arise here: how transparent is it that a model uses a subject's data; whether the use of training data is compatible with the purpose of collection; and whether the collected volume is genuinely necessary. The law also contemplates follow-on questions: in processing for another purpose, account must be taken of the connection between the original and the new purpose, the nature of the relationship between the controller and the subject, the subject's reasonable expectations and more.
Legal bases — why the processing is permitted
Under Article 5, processing is permitted where one of the bases exists: the subject's consent for one or several specific purposes; necessity for the performance of an obligation under a contract with the subject or for concluding one; provision by law; necessity for duties imposed by legislation; public availability of the data; protection of vital interests; significant public interest and others. In an AI system this question is no formality: the training corpus, the product's functioning and internal analytics often serve different purposes, and each may require a different basis. Choosing the basis and documenting it is precisely the work that must be done at the design stage of the system.
Automated decisions — the system's most sensitive point
Article 19 is critical exactly for AI systems: the data subject has the right not to be subjected to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects for them — except where the decision is based on the subject's explicit consent, is necessary for concluding or performing a contract, or is provided by law. Upon the subject's request, the controller must take measures to protect the subject's rights — including involving human intervention in the decision-making process and giving the possibility to express a view and to contest the decision. A system that leaves no route for human engagement is therefore in conflict with the law. The use of special-category data in such decisions is permitted only with additional safeguards.
Impact assessment — the precondition for high-risk processing
Article 31 imposes a prior-assessment duty: where, taking into account new technologies, the categories, volume, purposes and means of processing, there is a high probability of a risk of violating fundamental rights and freedoms, the controller must carry out a data-protection impact assessment in advance. Beyond that, the assessment is mandatory where the controller makes fully automated decisions with significant effect for the subject, processes special-category data of a large number of subjects, or conducts systematic and large-scale monitoring of subjects' behaviour. The assessment is fixed in a written document describing the categories of data, purposes, proportionality and risks together with the measures; on substantive change of the processing the document is updated, and on cessation of processing it is retained for at least 1 year. Where a high risk is identified, the controller must take all necessary measures and, where needed, consult the State Audit Service.
Practical scenarios
Examples make the conversation concrete. A chatbot that analyses customer correspondence to improve service — that is one purpose; building emotional profiles on the same texts to sell to third parties is an entirely different matter and will not pass the compatibility test. A CV-screening system that filters candidates automatically most likely falls under the automated-decision regime and demands a route for human review. Cameras in a workplace conducting large-scale monitoring are subject to impact assessment. In each such case the right question is not „is it forbidden“ but „which rule applies and what must be done to satisfy it“. We help convert these abstract norms into concrete requirements for your product — requirements that a development team can implement and an auditor can verify.
How we can help
Our specialists will assess your system on exactly these pillars: we define the purposes and bases of processing, identify risks of violating the principles (especially purpose incompatibility and excessive data), assess whether your product falls under the automated-decision regime, and plan the human-intervention mechanism. Where necessary we prepare the impact-assessment document. Contact us for a concrete assessment of how your system stands against the law's requirements.
