Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Cybersecurity Law
  4. Crypto Cybersecurity
  5. Crypto Security Compliance

Loading...

Crypto Cybersecurity

Crypto Security Compliance

Is there a separate security statute for the crypto business?

No. There is no stand-alone regime; the binding requirements flow from accountable-person status — the virtual asset service provider is on the list of financial institutions and must implement a compliance control system.

What is the accompanying information for a convertible virtual asset transfer?

It is information materially connected with a transfer or receipt, whose composition is determined by the supervisory organ under an established procedure. The provider must ensure its accompaniment, and the receiving provider examines whether a reporting ground exists if the transfer lacks identification data.

What must the internal instruction contain?

The rights and duties of the responsible person or unit, staff selection rules, a continuing training programme and an independent audit function to check the system's effectiveness. The instruction is approved by the governing body or a person with managerial authority.

What is the penalty for non-compliance?

Failure to comply with the statutory requirements results in a warning, and a repeated act in a fine of 1 000 lari. A special, separate liability regime applies to accountable persons.

5 min·...

Crypto business security: which rules are binding

There is no separate cybersecurity statute for the crypto business in Georgia — not for exchanges and not for wallet-service providers. The binding legal frame that imposes security and control requirements on such a business flows from its status as an accountable person: by listing the virtual asset service provider among financial institutions, the Law of Georgia on the Prevention of Money Laundering and Terrorism Financing obliges it to implement a compliance control system and to ensure that transfers are accompanied by the required accompanying information. On this page we explain what this means in practice and what consequences a breach carries.

Accountable-person status and its circle

The law defines three groups of accountable persons: financial institutions, persons engaged in non-financial activity and public institutions. The virtual asset service provider is listed directly among financial institutions — alongside commercial banks, microfinance organizations, payment service providers and others. The crypto business thus receives its security standards not from a stand-alone act but from the common regime extended to the whole financial sector. Moreover, the law's requirements extend to other persons conditionally: an advocate or a notary, for example, becomes an accountable person where he or she serves a client in matters that include the management of money, securities or convertible virtual assets, management of a bank account, creation of a legal person or the purchase and sale of shares. Certain forms of professional activity — including the giving of legal advice and representation before a court — fall outside these requirements.

Convertible virtual asset transfers and accompanying information

The law separately defines the operation of a transfer of a convertible virtual asset: an operation performed by digital means, by or on the instruction or with the consent of the initiator, to make a convertible virtual asset available to a recipient; the initiator and the recipient may be one and the same person. Two direct requirements attach to these operations. First, the virtual asset service provider must ensure that a transfer or receipt of a convertible virtual asset is accompanied by accompanying information determined under the procedure established by the supervisory organ. Second, the provider of the recipient of a convertible virtual asset must examine whether a ground exists for submitting a report where the transfer does not fully contain the identification data of the initiator or the recipient in accordance with the established procedure. Technically this means that the transfer system must be built from the start so that accompanying data are recorded and retained — retrofitting this onto a running platform is far more expensive.

The compliance control system: the real security frame

The law obliges the accountable person to implement internal control policies, rules, systems and mechanisms that are proportionate to the character and volume of its activity and to the associated money laundering and terrorism financing risks. For the implementation an internal instruction is elaborated, approved by the governing body or a person with managerial authority. The instruction defines, among other matters, the rights and duties of the person or unit responsible for the functioning of the compliance control system; the rules for selecting employees of high qualification and reputation for employment; a continuing training programme; and an independent audit function to check the effectiveness of the system. The accountable person must supply the responsible persons with information effectively and in due time and grant them the right to take independent decisions. The position of the head of compliance must correspond to a senior management level, and a member of the governing body or a person with managerial authority is responsible for the system's effectiveness. These documents and roles — not a generic security certificate — are the crypto business security standard in Georgian law.

Liability and the real boundary

The law attaches a sanction for non-fulfilment of the requirements it establishes: failure by a person to comply results in a warning, and a repeated commission of the same act in a fine of 1 000 lari. Under this norm an accountable person within the article's list is not implied — a separate, special liability regime applies to it, placed in a separate chapter and outside the subject of this page. The real damage often lies not in the fine but in the restriction of activity and reputation: for a provider under supervision, a defect in the control system is directly reflected in client trust and partner relationships.

How we can help

We help the crypto business understand the mandatory regime: we determine whether your model falls within the definition of an accountable person, draft the internal instruction and the description of the compliance control system, and plan the legal requirements for embedding accompanying information into the platform. Contact us — we will assess your situation under the current legislation.

In practice the compliance control system in a crypto business consists of three layers: a documentary layer, meaning the approved instruction and policies; an organisational layer, meaning the responsible person or unit, its right to take independent decisions and its accountability to the top level; and a technical layer, meaning transfer monitoring, the recording of accompanying information and data retention. The proportionality requirement of the law means that the systems of a small provider and of a large platform will differ, yet all three layers are equally necessary for both: a defect in any one of them invalidates the whole system. In our experience it is usually the technical layer that remains neglected, with the instruction written but the platform unable to retain the accompanying data.

Updated: ...

Verified against current law: 09/07/2026

Legal basis:

  • საქართველოს სამოქალაქო კოდექსი

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer