Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Data Protection & Privacy
  4. Data Breach Management
  5. Breach Notification

Loading...

Data Breach Management

Breach Notification

To whom is the incident notification addressed?

The State Audit Service — under current legislation it exercises supervision in the field of data protection. The notification is given in writing or electronically no later than 72 hours from discovery, unless significant damage or threat is unlikely.

What must the notification contain?

Five elements: the circumstances, nature and time of the incident; the approximate categories and quantities of affected data and subjects; the likely damage and measures taken or planned; whether the organisation plans to inform the subjects and when; and contact details.

When must the data subject be informed?

Where the incident is likely to cause significant damage or threat to fundamental rights, the subject must be notified at the first opportunity without unjustified delay, in simple and comprehensible language. Where individual notification is disproportionate, public communication is possible.

What fine threatens for omission of the notification?

Failure to notify the State Audit Service entails a warning or a fine — up to 2 000 lari where annual turnover does not exceed 500 000 lari and up to 3 000 lari where it exceeds it; with aggravating circumstances — up to 3 000 and 5 000 lari respectively.

4 min·...

About this service

A data incident — a security failure as a result of which data is accidentally or unlawfully destroyed, lost, altered, disclosed or accessed — is for an organisation not only a technical but a legal event. The Georgian law on personal data protection obliges the controller to record incidents and to give notice of them. One circumstance should be stated early: under the current legislation, supervision in the field of data protection is exercised by the State Audit Service, and the notification is addressed precisely to it — the title „inspector“ is a legacy of the old institution. This service helps organisations with the legal response to an incident: determining the obligations, preparing the notification and managing sanction risk.

The notification duty — 72 hours

Article 29 of the law sets the basic rule: the controller is obliged to record the incident, its consequences and the measures taken, and to notify the State Audit Service in writing or electronically no later than 72 hours from the discovery of the incident — except where it is unlikely that the incident will cause significant damage or pose a significant threat to human fundamental rights and freedoms. The hours thus run from the moment of discovery, not from the completion of a full investigation — a distinction that is decisive in practice. Moreover, where it is impossible to provide all the required information at once, the controller may, in agreement with the State Audit Service, supply the information in stages within a reasonable period.

What the notification must contain

The law describes the content precisely. The notification must contain: information on the circumstances, nature and time of the incident; the approximate categories and quantities of data unlawfully disclosed, damaged, deleted, destroyed, obtained, lost or altered, and of the data subjects placed at risk; the likely damage caused by the incident and the measures carried out or planned to reduce or eliminate it; whether the controller plans to notify the data subjects and within what period; and the details of the data protection officer or other contact person. These five elements are the minimum without which a notification is considered incomplete.

The role of the processor

Where processing is carried out or assisted by another person — for example an external service provider — the law extends a clear requirement to it as well: the processor is obliged to inform the controller immediately about the incident. This means that the time of discovery and the chain of transmission must be arranged by contract so that the controller genuinely has 72 hours — even a single day contractually allotted can consume a third of that time in a serious incident.

Informing the data subject

The organisation's duties do not end with the authority. Under Article 30 of the law, where the incident is likely to cause significant damage or pose a significant threat to fundamental rights and freedoms, the controller is obliged, upon discovery, at the first opportunity and without unjustified delay, to notify the data subject and to provide, in simple and comprehensible language: a general description of the incident and related circumstances; the likely or actual damage and the measures carried out or planned to reduce or eliminate it; and contact details. Where individual notification would require disproportionately large costs, the information must be made public in a form that gives subjects a real opportunity to receive it. The law allows exceptions — for example where appropriate security measures have averted the significant threat of violation — but substantiating that assessment is the controller's burden.

Fines

Failure to perform the duty of notifying the State Audit Service entails administrative liability: a warning or a fine of 2 000 lari for those whose annual turnover does not exceed 500 000 lari, and a warning or a fine of 3 000 lari for those whose turnover exceeds 500 000 lari. In the presence of aggravating circumstances these amounts rise — to 3 000 and 5 000 lari respectively. A late or omitted notification therefore creates a precisely measured financial consequence.

One further detail matters: on the basis of the notification, the State Audit Service may also make public the information at its disposal about the incident if the controller fails to ensure the informing of data subjects — with defined state and public interests remaining an exception. A correct communication plan is therefore an integral part of the legal response to an incident.

How we can help

Our specialists help qualify the incident legally — whether the event is an incident within the meaning of the law, whether it is subject to notification and which period applies; we prepare the notification to the State Audit Service in full compliance with the five statutory elements; and we assist in the decision on informing data subjects and in drafting that text. To prepare in advance, we draw a response plan that fixes deadlines, responsibilities and notification templates in the organisation at an early stage. Contact us for concrete steps for your situation.

Updated: ...

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer