Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Artificial Intelligence Law
  4. Privacy in AI
  5. AI Data Processing Compliance

Loading...

Privacy in AI

AI Data Processing Compliance

Is there a separate data law for artificial intelligence?

No. The law contains no separate AI chapter — processing in such systems is assessed under the general principles, the legal bases, the automated-decision regime and the impact-assessment duty.

When is a solely automated decision prohibited?

Where it produces legal or similarly significant effects for the subject, it is permitted only on explicit consent, in connection with a contract or by law — and the subject may demand human intervention, express a view and contest the decision.

When is an impact assessment mandatory?

Where new technologies create a high probability of risk to rights, and additionally in cases of fully automated significant decisions, large volumes of special-category data and systematic large-scale monitoring. The assessment is a written document retained for at least 1 year after processing ceases.

What if the system uses data for a purpose other than collection?

The law deems further processing incompatible with the original purpose impermissible. Compatibility assessment must account for the connection between purposes, the nature of the relationship with the subject and the subject's reasonable expectations.

4 min·...

About this service

Artificial-intelligence systems live on data: they collect, analyse, classify and make decisions based on it. The Georgian law on personal data protection contains no separate chapter for artificial intelligence — and that is the first thing anyone working in this field must know. Processing within such systems is assessed under the law's general norms: the principles of processing, the legal bases, the special regime for automated decisions and the impact-assessment duty. This service builds the legal assessment of your system on precisely these four pillars — from product design to operation.

The principles — where every assessment begins

Article 4 of the law establishes the principles of processing, which extend fully to AI systems: data must be processed lawfully, fairly, transparently for the subject and without violating their dignity; data must be collected only for concrete, clearly defined and legitimate purposes, and further processing incompatible with the original purpose is impermissible; data must be processed only to the extent necessary for the purpose; and data must be accurate. For AI, concrete questions quickly arise here: how transparent is it that a model uses a subject's data; whether the use of training data is compatible with the purpose of collection; and whether the collected volume is genuinely necessary. The law also contemplates follow-on questions: in processing for another purpose, account must be taken of the connection between the original and the new purpose, the nature of the relationship between the controller and the subject, the subject's reasonable expectations and more.

Legal bases — why the processing is permitted

Under Article 5, processing is permitted where one of the bases exists: the subject's consent for one or several specific purposes; necessity for the performance of an obligation under a contract with the subject or for concluding one; provision by law; necessity for duties imposed by legislation; public availability of the data; protection of vital interests; significant public interest and others. In an AI system this question is no formality: the training corpus, the product's functioning and internal analytics often serve different purposes, and each may require a different basis. Choosing the basis and documenting it is precisely the work that must be done at the design stage of the system.

Automated decisions — the system's most sensitive point

Article 19 is critical exactly for AI systems: the data subject has the right not to be subjected to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects for them — except where the decision is based on the subject's explicit consent, is necessary for concluding or performing a contract, or is provided by law. Upon the subject's request, the controller must take measures to protect the subject's rights — including involving human intervention in the decision-making process and giving the possibility to express a view and to contest the decision. A system that leaves no route for human engagement is therefore in conflict with the law. The use of special-category data in such decisions is permitted only with additional safeguards.

Impact assessment — the precondition for high-risk processing

Article 31 imposes a prior-assessment duty: where, taking into account new technologies, the categories, volume, purposes and means of processing, there is a high probability of a risk of violating fundamental rights and freedoms, the controller must carry out a data-protection impact assessment in advance. Beyond that, the assessment is mandatory where the controller makes fully automated decisions with significant effect for the subject, processes special-category data of a large number of subjects, or conducts systematic and large-scale monitoring of subjects' behaviour. The assessment is fixed in a written document describing the categories of data, purposes, proportionality and risks together with the measures; on substantive change of the processing the document is updated, and on cessation of processing it is retained for at least 1 year. Where a high risk is identified, the controller must take all necessary measures and, where needed, consult the State Audit Service.

Practical scenarios

Examples make the conversation concrete. A chatbot that analyses customer correspondence to improve service — that is one purpose; building emotional profiles on the same texts to sell to third parties is an entirely different matter and will not pass the compatibility test. A CV-screening system that filters candidates automatically most likely falls under the automated-decision regime and demands a route for human review. Cameras in a workplace conducting large-scale monitoring are subject to impact assessment. In each such case the right question is not „is it forbidden“ but „which rule applies and what must be done to satisfy it“. We help convert these abstract norms into concrete requirements for your product — requirements that a development team can implement and an auditor can verify.

How we can help

Our specialists will assess your system on exactly these pillars: we define the purposes and bases of processing, identify risks of violating the principles (especially purpose incompatibility and excessive data), assess whether your product falls under the automated-decision regime, and plan the human-intervention mechanism. Where necessary we prepare the impact-assessment document. Contact us for a concrete assessment of how your system stands against the law's requirements.

Updated: ...

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer