Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Data Protection & Privacy
  4. Data Breach Management
  5. Data Breach Response Planning

Loading...

Data Breach Management

Data Breach Response Planning

What is a data breach response plan?

A document prepared in advance defining the roles, deadlines and notification templates for responding to an incident. It rests on the security obligations and the rules of incident recording and notification.

Which deadline is the most critical?

72 hours from detection of the incident — the deadline for written or electronic notification to the State Audit Office, unless significant damage or threat is unlikely. Subjects are informed at the first opportunity where the threat is high.

What fines are provided?

Failure to perform the security obligation — a warning or a fine of 2 000/4 000 lari depending on turnover; with aggravating circumstances, 3 000/5 000 lari. Failure to notify — a warning or a fine of 2 000/3 000 lari; with aggravating circumstances, 3 000/5 000 lari.

What should the plan contain?

A list of security measures, a detection-fixing procedure, a distribution of roles, notification templates with the content established by law, an information channel with the processor and a schedule of periodic checks.

5 min·...

Why a data breach response plan is necessary

A data breach response plan is a document prepared in advance that defines who, when, within which deadlines and with which content responds to an incident. Unlike live response, which is the management of an event that has already happened, the plan is an ex-ante instrument: it is created when nothing has happened yet, so that decisions during a crisis are not the result of improvisation. The Georgian Law on Personal Data Protection does not separately require the existence of a plan, but every element of it rests on obligations established by law — and it is precisely the violation of those obligations that triggers the sanctions from which the plan protects.

The legal foundation of the plan rests on two pillars. The first is the security obligation: under the second paragraph of Article 27 of the law, the controller and the processor are obliged to adopt organisational and technical measures corresponding to the possible and accompanying risks, including pseudonymisation, logging of access and information-security mechanisms. The second is the set of incident-recording and notification obligations in Articles 29 and 30.

What the plan should reflect from the security baseline

The plan begins with a list of the measures established by Article 27 that will be activated during an incident: pseudonymisation of data, logging of access to data, and mechanisms of confidentiality, integrity and availability. The third paragraph of the same article requires the periodic assessment of the effectiveness of these measures — in the plan this should be reflected as an assessment schedule.

A separate emphasis falls on records. Under the fourth paragraph of Article 27, every action performed on data in electronic form, including information on incidents, is recorded. The plan defines who maintains the records during an incident and where the consequence that has occurred and the measures taken are fixed — because it is precisely this record that becomes the basis of the notification.

The 72-hour notification and its content

The central time parameter of the plan is 72 hours: under the first paragraph of Article 29, the controller is obliged to notify the State Audit Office of the incident in writing or electronically no later than 72 hours from its detection, except where significant damage or a significant threat to fundamental rights is unlikely. Fixing the moment of detection of the incident is therefore a separate procedure in the plan.

The plan shapes in advance the template of the notification with the content required by the third paragraph of Article 29: the circumstances, nature and time of the incident; the estimated categories and volume of damaged or disclosed data and the estimated circle of affected subjects; the estimated damage and the measures carried out or planned; the intention regarding informing the subjects; and the contact person. Where providing the information together is impossible, the plan provides for phased submission in agreement with the State Audit Office.

Where processing is carried out through a processor, the second paragraph of Article 29 requires immediate notification from it — this channel must be established in the contract as part of the plan.

The procedure for informing subjects

Under the first paragraph of Article 30, where the incident is highly likely to cause significant damage or threat, the subject must be informed at the first opportunity after detection, in simple and comprehensible language. The plan includes the template of this notification as well: a general description of the incident and the circumstances, the estimated damage and the measures, and the contact person's details.

The plan also reflects the two exceptions provided for by the third paragraph of Article 30: the duty to inform does not arise where informing would endanger the enumerated protected interests, or where security measures have averted the significant threat. Under the second paragraph, where individual notification is disproportionate, the information is disseminated publicly or in another effective form.

The sanctions from which the plan protects

Article 76 of the law resolves the failure to perform the security obligation as follows: a warning or a fine of 2 000 lari for persons with annual turnover up to 500 000 lari and a warning or a fine of 4 000 lari at higher turnover; with aggravating circumstances — 3 000 and 5 000 lari. Article 78 concerns the failure to perform the duty of notifying the State Audit Office: a warning or a fine of 2 000 lari at turnover up to 500 000 lari and a warning or a fine of 3 000 lari at higher turnover; with aggravating circumstances — 3 000 and 5 000 lari.

These figures are the economic justification of the plan: prepared procedures change not only the speed of response but also the risk that deadlines and formalities will be violated. The Legal.ge team will help you develop a data breach response plan — both at the level of the document and in shaping the process of updating and verifying it.

Frequently Asked Questions

The most frequent questions.

How quickly must the State Audit Service be notified?

Within 72 hours of discovery, in writing or electronically — unless significant harm or risk is unlikely.

When are data subjects informed?

Where significant harm or risk is likely — at the first opportunity, in plain language; where costs are disproportionate — by public communication; in certain cases the duty does not arise.

What sanctions apply?

A warning or a fine of 2 000 to 4 000 lari, with aggravation 3 000 to 5 000 lari; the missed 72-hour notification lies in the same frames.

How We Help on Legal.ge

A breach plan is a capability, not a document: a 72-hour calendar, templates and a sanctions map laid out in advance. The lawyers of Legal.ge will draft one for your organization and assist in a real incident.

Updated: ...

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer