A data security breach arrives in three waves: the incident itself, the subsequent remediation, and legal liability. The Law on Personal Data Protection regulates all three: the incident is recorded and reported to the State Audit Service, the data subject is informed, and for the violation the Service applies measures and fines. This page is about the second and third waves — how an organization restores its position and what threatens it if it cannot.
Recording the incident and the 72-hour notification
Under Article 29 of the law, the controller must record the incident, its consequences and the measures taken, and no later than 72 hours from its discovery notify the State Audit Service in writing or electronically — except where the incident is unlikely to cause significant damage or a significant risk to fundamental rights. The processor immediately notifies the controller of the incident. The notification must contain the circumstances, nature and time of the incident; the estimated categories and quantities of affected data and subjects; the estimated damage and the measures taken or planned; the plan and timing for informing subjects; and the DPO's contact details. Where full information cannot be provided at once, it is submitted in phases by agreement with the Service; and if the controller fails to inform the subjects, the State Audit Service is itself empowered to make the information public.
Informing the subject
Under Article 30, where the incident is likely to cause significant damage or a significant risk to fundamental rights, the controller must, at the first opportunity after discovery and without unjustified delay, notify the subject and provide in plain language: a general description of the incident and its circumstances; the estimated or incurred damage and the measures taken or planned to reduce or eliminate it; and the contact details of the DPO or other person. Where informing requires disproportionately large costs, the information is disseminated publicly. The duty to inform does not arise if notification would threaten state or public security, investigation or another protected interest, or if the security measures taken have prevented the significant risk of violating fundamental rights.
The State Audit Service's measures
Article 52 gives the Service a full arsenal for eliminating violations: demanding correction of the violation and deficiencies in a specified form and period; demanding temporary or permanent cessation of processing where security measures do not meet legislative requirements; demanding cessation, blocking, deletion, destruction or depersonalization of data processed in breach of legislation; demanding cessation of transfers to another state; issuing written advice for minor violations; and imposing administrative liability. The controller must fulfil the demands within the set period and report; on failure, the Service applies to a court, a law-enforcement organ or a regulator. The Service's decision is mandatory and appealable only in court.
Remediation measures — what they must cover
Notifications are only the first step; the law demands recovery as well. In the notification submitted to the State Audit Service, the controller indicates the measures taken or planned to reduce or eliminate the damage — and this planning must be real, because the measures the Service applies are aimed precisely at correcting those deficiencies. A remediation package usually covers eliminating the source of the flaw, identifying and restoring affected data, reviewing access, and informing staff. In addition, the law contemplates that the criteria for defining an incident significant to fundamental rights are set by a normative act of the General Auditor — so an organization should know that the boundaries are spelled out administratively as well.
The second important circumstance is the risk to transparency: if the controller does not inform the subjects, the State Audit Service is itself empowered to publicize the information at its disposal. Concealing information thus harms the organization twice over: the fine grows and publicity can no longer be managed by the organization itself. A properly built process — recording, the 72-hour notification, informing subjects and executing the planned measures — is the only way an incident stays a short episode instead of growing into a prolonged legal problem.
Fines for failing to inform subjects
Article 79 attaches rather heavy fines to non-performance of the duty to inform subjects: for persons with annual turnover up to GEL 500 000 — a warning or a fine of GEL 3 000; above that turnover — a warning or GEL 5 000; with aggravating circumstances — GEL 5 000 and GEL 10 000 respectively. Concealing a required notification thus doubles the price. The Legal.ge team assists in post-incident procedures — from preparing the 72-hour notification to communicating with subjects and the State Audit Service.
Frequently Asked Questions
Below are the most frequent questions about data breaches.
Within what period is the Service notified of an incident?
Within no later than 72 hours of discovery, in writing or electronically — unless significant damage or threat is unlikely.
What must the notification to subjects contain?
A general description of the incident and circumstances, the probable/incurred damage and measures, and the contact details of the data-protection officer — in simple and understandable language.
When does the duty to inform not arise?
Where notification would endanger state security or other protected interests, or where security measures taken have averted a significant threat to fundamental rights.
May the incident be made public?
Yes — where the controller fails to inform subjects, the State Audit Service may publicise the information at its disposal, save for legally protected cases.
How We Help on Legal.ge
Every step after a data breach — recording, the 72-hour notification, informing subjects and remediation — requires precise documentary fixation. The lawyers of Legal.ge will help you through this process and assess the risk of a fine. Contact us immediately upon discovery of an incident.
