What counts as an incident under Georgian legislation
Data breach response in Georgia rests on the norms of the Law on Personal Data Protection, and the first question to answer is the definition of an incident. The relevant subparagraph of Article 3 of the law defines an incident as a violation of data security which entails the unlawful or accidental damage or loss of data, as well as unauthorised disclosure, destruction, alteration, access to them, their collection or other unauthorised processing. This definition is broad: it is not limited to a hacker attack and covers cases such as accidental deletion, a file sent to the wrong address or unauthorised access to a database.
When such an event occurs, the law prescribes for the controller a clear sequence of legal actions: the baseline of security measures, the recording of the incident, notification to the State Audit Office and, where necessary, informing the data subjects. Each of these stages is examined in detail below.
Security measures as the starting position
Response to an incident is assessed in the context of the measures the organisation has under Article 27 of the law. The controller and the processor are obliged to adopt organisational and technical measures corresponding to the possible and accompanying risks — including pseudonymisation of data, logging of access to data and information-security mechanisms — which ensure protection against loss and unlawful processing. The effectiveness of the measures is assessed periodically.
Article 27 also requires the recording of every action performed on data in electronic form — information on incidents, collection, alteration, access, disclosure, combination and deletion. When an incident occurs, it is precisely this record that becomes the source of the evidence used by the notification and the internal analysis.
Notification to the State Audit Office: deadline and content
Under the first paragraph of Article 29, the controller is obliged to record the incident, its consequence and the measures taken, and to notify the State Audit Office in writing or electronically no later than 72 hours from the detection of the incident. The only exception is where it is unlikely that the incident will cause significant damage or pose a significant threat to human fundamental rights and freedoms.
The content of the notification is defined by law: the circumstances, nature and time of the incident; the estimated categories and volume of data damaged, disclosed or lost, and the estimated circle of affected subjects; the estimated damage and the measures carried out or planned; the intention regarding informing the subjects; and the contact person's details. Where providing the information together and in full is impossible, it may be submitted in stages in agreement with the State Audit Office. Where processing is carried out through a processor, the latter is obliged to notify the controller of the incident immediately.
The publicity aspect should also be noted: where the controller fails to inform the subjects, the State Audit Office is entitled to make the information about the incident public — except where publication would endanger state security, cybersecurity, investigation or other legally protected interests, or where the institution requests non-disclosure on a legally established ground.
Informing data subjects
Under the first paragraph of Article 30, where the incident is highly likely to cause significant damage or pose a significant threat to human fundamental rights and freedoms, the controller is obliged, at the first opportunity after detection and without unjustified delay, to notify the data subject of the incident and to provide in simple language information containing a general description of the incident and the related circumstances, the estimated damage and the measures carried out or planned, and the contact person.
The duty to inform does not arise in two cases: where informing would endanger state secrets, security, investigation or other enumerated interests, and where the controller has adopted security measures such that the significant threat of violation of fundamental rights has been averted. Where informing each subject individually involves disproportionate costs, the information is disseminated publicly or in another form that gives the subjects a real possibility of receiving it.
Records and documentation
Information on incidents is part of the records related to processing. The relevant subparagraph of the first paragraph of Article 28 directly includes information on incidents in these records, where it exists. Under the third paragraph of the same article, the recorded information must be provided to the State Audit Office immediately upon request, but no later than 3 working days.
The criteria for an incident containing a significant threat, as well as the notification procedure, are established by a normative act of the General Auditor. The response procedure must therefore be reconciled with those acts.
Frequently Asked Questions
What counts as a data protection incident?
A breach of data security causing unlawful or accidental damage to or loss of data, as well as unauthorised disclosure, destruction, alteration, access to, collection/obtaining of or other unauthorised processing of them.
Who is notified of an incident and how?
The State Audit Office — in writing or electronically, no later than 72 hours from discovery of the incident; the data subject — at the first opportunity, without undue delay and in simple, understandable language.
What must the notice contain?
For the Audit Office — the nature of the incident; for the subject — a general description of the incident and related circumstances, the likely/incurred damage, measures taken or planned, and contact details.
How We Help on Legal.ge
The practical sequence is as follows: fixing the incident and assessing the damage; activating security measures to stop the spread; maintaining records; where necessary, receiving immediate information from the processor; preparing and sending the notification to the State Audit Office within 72 hours; informing the subjects where the threat is significant; documenting the consequences and measures established. The Legal.ge team will help you go through this process and assess the incident legally, so that deadlines and formalities are observed precisely.
