About this service
A data incident — a security failure as a result of which data is accidentally or unlawfully destroyed, lost, altered, disclosed or accessed — is for an organisation not only a technical but a legal event. The Georgian law on personal data protection obliges the controller to record incidents and to give notice of them. One circumstance should be stated early: under the current legislation, supervision in the field of data protection is exercised by the State Audit Service, and the notification is addressed precisely to it — the title „inspector“ is a legacy of the old institution. This service helps organisations with the legal response to an incident: determining the obligations, preparing the notification and managing sanction risk.
The notification duty — 72 hours
Article 29 of the law sets the basic rule: the controller is obliged to record the incident, its consequences and the measures taken, and to notify the State Audit Service in writing or electronically no later than 72 hours from the discovery of the incident — except where it is unlikely that the incident will cause significant damage or pose a significant threat to human fundamental rights and freedoms. The hours thus run from the moment of discovery, not from the completion of a full investigation — a distinction that is decisive in practice. Moreover, where it is impossible to provide all the required information at once, the controller may, in agreement with the State Audit Service, supply the information in stages within a reasonable period.
What the notification must contain
The law describes the content precisely. The notification must contain: information on the circumstances, nature and time of the incident; the approximate categories and quantities of data unlawfully disclosed, damaged, deleted, destroyed, obtained, lost or altered, and of the data subjects placed at risk; the likely damage caused by the incident and the measures carried out or planned to reduce or eliminate it; whether the controller plans to notify the data subjects and within what period; and the details of the data protection officer or other contact person. These five elements are the minimum without which a notification is considered incomplete.
The role of the processor
Where processing is carried out or assisted by another person — for example an external service provider — the law extends a clear requirement to it as well: the processor is obliged to inform the controller immediately about the incident. This means that the time of discovery and the chain of transmission must be arranged by contract so that the controller genuinely has 72 hours — even a single day contractually allotted can consume a third of that time in a serious incident.
Informing the data subject
The organisation's duties do not end with the authority. Under Article 30 of the law, where the incident is likely to cause significant damage or pose a significant threat to fundamental rights and freedoms, the controller is obliged, upon discovery, at the first opportunity and without unjustified delay, to notify the data subject and to provide, in simple and comprehensible language: a general description of the incident and related circumstances; the likely or actual damage and the measures carried out or planned to reduce or eliminate it; and contact details. Where individual notification would require disproportionately large costs, the information must be made public in a form that gives subjects a real opportunity to receive it. The law allows exceptions — for example where appropriate security measures have averted the significant threat of violation — but substantiating that assessment is the controller's burden.
Fines
Failure to perform the duty of notifying the State Audit Service entails administrative liability: a warning or a fine of 2 000 lari for those whose annual turnover does not exceed 500 000 lari, and a warning or a fine of 3 000 lari for those whose turnover exceeds 500 000 lari. In the presence of aggravating circumstances these amounts rise — to 3 000 and 5 000 lari respectively. A late or omitted notification therefore creates a precisely measured financial consequence.
One further detail matters: on the basis of the notification, the State Audit Service may also make public the information at its disposal about the incident if the controller fails to ensure the informing of data subjects — with defined state and public interests remaining an exception. A correct communication plan is therefore an integral part of the legal response to an incident.How we can help
Our specialists help qualify the incident legally — whether the event is an incident within the meaning of the law, whether it is subject to notification and which period applies; we prepare the notification to the State Audit Service in full compliance with the five statutory elements; and we assist in the decision on informing data subjects and in drafting that text. To prepare in advance, we draw a response plan that fixes deadlines, responsibilities and notification templates in the organisation at an early stage. Contact us for concrete steps for your situation.
