About this service
Cloud services — the storage, processing and delivery of data and applications on remote infrastructure — are a standard business tool. Legally, however, this relationship stands at the intersection of two different regimes: on the one hand, a cloud service is a contractual relationship between a service provider and a recipient; on the other, where the provider stores or transmits information, it acquires the status of an intermediary service provider, which creates its own legal regime. Georgian law has no separate statute for cloud services; they are governed by the intermediary-services chapter of the law on electronic commerce together with the general norms of contract. This service builds the drafting and review of cloud agreements on precisely the correct connection of those two regimes.
Cloud service without a licence
Article 3 of the law on electronic commerce provides that the supply of information-society services is not subject to licensing, permission or authorisation. Offering a cloud service as such therefore requires no state permit — market entry is free. This rule does not, however, extend to activities that other legislative acts place under licensing, permission or authorisation regimes: where a cloud solution touches such a sphere, the corresponding regime must be analysed separately. The absence of a licence requirement does not mean a legal vacuum — on the contrary, the quality and terms of the service are shaped entirely by the contract.
Hosting — the cloud provider's principal regime
The exemption from liability is drawn most clearly in the hosting norm: when storing a recipient of services' information, an intermediary service provider is not responsible for the stored information provided one of the following conditions exists: it has no actual knowledge of unlawful activity or information — and where a claim for damages is brought, it does not know the facts or circumstances from which the unlawful activity or information becomes apparent; or, upon obtaining actual knowledge of unlawful activity or information, it immediately removes the unlawful information or restricts access to it. For a cloud provider this is the basic legal framework of the business: responsibility for stored client content arises only where the provider knows of the illegality and fails to react. The exemption does not extend to cases where the recipient of the intermediary service acts in the name of the service provider, or where the provider manages the recipient.
Caching — temporary intermediate storage in transmission
Cloud architecture frequently employs temporary intermediate storage — caching. Here too the law exempts the provider from liability, but under strict conditions: the information must be stored for the purpose of making its delivery to other recipients more efficient and rapid, and the provider must not modify the information, must not interfere with its lawful availability conditions, must comply with industry update rules, must not obstruct lawfully used technologies, and — most practically — must immediately delete the stored information or restrict its accessibility upon learning that it has been removed from the primary source or that its accessibility has been restricted. The comfort of caching thus comes at the price of constant vigilance: the provider must have a working reaction mechanism in place.
There is no monitoring obligation
Cloud agreements often raise the question whether the provider is obliged itself to inspect client data for illegality. The law answers categorically: it is prohibited to impose on an intermediary service provider an obligation to monitor the information it transmits or stores, or an obligation to undertake active measures to detect unlawful actions. This rule matters to both sides: the client may not hope that the provider will analyse its content, and the provider is free of a general surveillance duty. At the same time, upon the request of an authorised organ the provider may be charged with supplying identifying information about the recipient of services for detection, prevention and avoidance — general monitoring is prohibited, but compliance with a concrete request is mandatory.
Protection mechanisms for the recipient of services
The client's position is protected too: where the law's obligations are breached, the recipient of services is entitled to apply to the agency. The existence of this right does not deprive the recipient of the right to apply to a court or arbitration, or to resolve the dispute through mediation. Practically, this means that in a cloud-services agreement the final instance for dispute resolution remains the court and not the provider's internal procedure — something to account for when drafting.
How we can help
Our specialists will draft a cloud-services agreement that positions the provider correctly within the intermediary regime: defining the scope of the service, how knowledge of unlawful content is recorded and what happens after notification, and how the data-return procedure operates on termination. For clients, we analyse the terms offered — especially liability limitations and data-access issues. One more practical note: cloud agreements typically live as a bundle — a master agreement, service descriptions, data-processing terms and acceptance documents. The bundle only works if each layer refers to the others expressly, because the statutory exemptions of the intermediary regime apply to the provider as such, not to every document it signs. We tie the bundle together so that the hosting regime, the data-return procedure and the dispute-resolution clause do not contradict one another. Contact us for a concrete assessment or a draft agreement.
