Legal.geLegal.ge
SpecialistsLibraryPricing
More
AboutBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Download on the App StoreLegal.ge for iPhone

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Data Protection & Privacy
  4. Data Breach Management
  5. Breach Remediation

Services

0 services available

Loading...

Data Breach Management

Breach Remediation

Within what period must the Service be notified?

No later than 72 hours from discovery — in writing or electronically, unless significant damage or risk is unlikely. The processor notifies the controller immediately.

What must the notification to subjects contain?

In plain language — a general description of the incident, the estimated or incurred damage and the measures taken or planned, plus the DPO's contact details. It is issued at the first opportunity, without unjustified delay.

What fine threatens non-informing of subjects?

A warning or GEL 3 000 for turnover up to GEL 500 000; a warning or GEL 5 000 above it; with aggravating circumstances — up to GEL 5 000 and GEL 10 000.

When does the duty to inform not arise?

Where notification threatens a protected interest — state or public security, investigation and so on — or where security measures taken have prevented the significant risk of violating fundamental rights.

5 min·8 Feb 2026

A data security breach arrives in three waves: the incident itself, the subsequent remediation, and legal liability. The Law on Personal Data Protection regulates all three: the incident is recorded and reported to the State Audit Service, the data subject is informed, and for the violation the Service applies measures and fines. This page is about the second and third waves — how an organization restores its position and what threatens it if it cannot.

Recording the incident and the 72-hour notification

Under Article 29 of the law, the controller must record the incident, its consequences and the measures taken, and no later than 72 hours from its discovery notify the State Audit Service in writing or electronically — except where the incident is unlikely to cause significant damage or a significant risk to fundamental rights. The processor immediately notifies the controller of the incident. The notification must contain the circumstances, nature and time of the incident; the estimated categories and quantities of affected data and subjects; the estimated damage and the measures taken or planned; the plan and timing for informing subjects; and the DPO's contact details. Where full information cannot be provided at once, it is submitted in phases by agreement with the Service; and if the controller fails to inform the subjects, the State Audit Service is itself empowered to make the information public.

Informing the subject

Under Article 30, where the incident is likely to cause significant damage or a significant risk to fundamental rights, the controller must, at the first opportunity after discovery and without unjustified delay, notify the subject and provide in plain language: a general description of the incident and its circumstances; the estimated or incurred damage and the measures taken or planned to reduce or eliminate it; and the contact details of the DPO or other person. Where informing requires disproportionately large costs, the information is disseminated publicly. The duty to inform does not arise if notification would threaten state or public security, investigation or another protected interest, or if the security measures taken have prevented the significant risk of violating fundamental rights.

The State Audit Service's measures

Article 52 gives the Service a full arsenal for eliminating violations: demanding correction of the violation and deficiencies in a specified form and period; demanding temporary or permanent cessation of processing where security measures do not meet legislative requirements; demanding cessation, blocking, deletion, destruction or depersonalization of data processed in breach of legislation; demanding cessation of transfers to another state; issuing written advice for minor violations; and imposing administrative liability. The controller must fulfil the demands within the set period and report; on failure, the Service applies to a court, a law-enforcement organ or a regulator. The Service's decision is mandatory and appealable only in court.

Remediation measures — what they must cover

Notifications are only the first step; the law demands recovery as well. In the notification submitted to the State Audit Service, the controller indicates the measures taken or planned to reduce or eliminate the damage — and this planning must be real, because the measures the Service applies are aimed precisely at correcting those deficiencies. A remediation package usually covers eliminating the source of the flaw, identifying and restoring affected data, reviewing access, and informing staff. In addition, the law contemplates that the criteria for defining an incident significant to fundamental rights are set by a normative act of the General Auditor — so an organization should know that the boundaries are spelled out administratively as well.

The second important circumstance is the risk to transparency: if the controller does not inform the subjects, the State Audit Service is itself empowered to publicize the information at its disposal. Concealing information thus harms the organization twice over: the fine grows and publicity can no longer be managed by the organization itself. A properly built process — recording, the 72-hour notification, informing subjects and executing the planned measures — is the only way an incident stays a short episode instead of growing into a prolonged legal problem.

Fines for failing to inform subjects

Article 79 attaches rather heavy fines to non-performance of the duty to inform subjects: for persons with annual turnover up to GEL 500 000 — a warning or a fine of GEL 3 000; above that turnover — a warning or GEL 5 000; with aggravating circumstances — GEL 5 000 and GEL 10 000 respectively. Concealing a required notification thus doubles the price. The Legal.ge team assists in post-incident procedures — from preparing the 72-hour notification to communicating with subjects and the State Audit Service.

Frequently Asked Questions

Below are the most frequent questions about data breaches.

Within what period is the Service notified of an incident?

Within no later than 72 hours of discovery, in writing or electronically — unless significant damage or threat is unlikely.

What must the notification to subjects contain?

A general description of the incident and circumstances, the probable/incurred damage and measures, and the contact details of the data-protection officer — in simple and understandable language.

When does the duty to inform not arise?

Where notification would endanger state security or other protected interests, or where security measures taken have averted a significant threat to fundamental rights.

May the incident be made public?

Yes — where the controller fails to inform subjects, the State Audit Service may publicise the information at its disposal, save for legally protected cases.

How We Help on Legal.ge

Every step after a data breach — recording, the 72-hour notification, informing subjects and remediation — requires precise documentary fixation. The lawyers of Legal.ge will help you through this process and assess the risk of a fine. Contact us immediately upon discovery of an incident.

Updated: 9 Aug 2026

Verified against current law: 9 Jul 2026

Legal basis:

  • საქართველოს შრომის კოდექსი
  • საქართველოს სამოქალაქო კოდექსი

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer