Why a data breach response plan is necessary
A data breach response plan is a document prepared in advance that defines who, when, within which deadlines and with which content responds to an incident. Unlike live response, which is the management of an event that has already happened, the plan is an ex-ante instrument: it is created when nothing has happened yet, so that decisions during a crisis are not the result of improvisation. The Georgian Law on Personal Data Protection does not separately require the existence of a plan, but every element of it rests on obligations established by law — and it is precisely the violation of those obligations that triggers the sanctions from which the plan protects.
The legal foundation of the plan rests on two pillars. The first is the security obligation: under the second paragraph of Article 27 of the law, the controller and the processor are obliged to adopt organisational and technical measures corresponding to the possible and accompanying risks, including pseudonymisation, logging of access and information-security mechanisms. The second is the set of incident-recording and notification obligations in Articles 29 and 30.
What the plan should reflect from the security baseline
The plan begins with a list of the measures established by Article 27 that will be activated during an incident: pseudonymisation of data, logging of access to data, and mechanisms of confidentiality, integrity and availability. The third paragraph of the same article requires the periodic assessment of the effectiveness of these measures — in the plan this should be reflected as an assessment schedule.
A separate emphasis falls on records. Under the fourth paragraph of Article 27, every action performed on data in electronic form, including information on incidents, is recorded. The plan defines who maintains the records during an incident and where the consequence that has occurred and the measures taken are fixed — because it is precisely this record that becomes the basis of the notification.
The 72-hour notification and its content
The central time parameter of the plan is 72 hours: under the first paragraph of Article 29, the controller is obliged to notify the State Audit Office of the incident in writing or electronically no later than 72 hours from its detection, except where significant damage or a significant threat to fundamental rights is unlikely. Fixing the moment of detection of the incident is therefore a separate procedure in the plan.
The plan shapes in advance the template of the notification with the content required by the third paragraph of Article 29: the circumstances, nature and time of the incident; the estimated categories and volume of damaged or disclosed data and the estimated circle of affected subjects; the estimated damage and the measures carried out or planned; the intention regarding informing the subjects; and the contact person. Where providing the information together is impossible, the plan provides for phased submission in agreement with the State Audit Office.
Where processing is carried out through a processor, the second paragraph of Article 29 requires immediate notification from it — this channel must be established in the contract as part of the plan.
The procedure for informing subjects
Under the first paragraph of Article 30, where the incident is highly likely to cause significant damage or threat, the subject must be informed at the first opportunity after detection, in simple and comprehensible language. The plan includes the template of this notification as well: a general description of the incident and the circumstances, the estimated damage and the measures, and the contact person's details.
The plan also reflects the two exceptions provided for by the third paragraph of Article 30: the duty to inform does not arise where informing would endanger the enumerated protected interests, or where security measures have averted the significant threat. Under the second paragraph, where individual notification is disproportionate, the information is disseminated publicly or in another effective form.
The sanctions from which the plan protects
Article 76 of the law resolves the failure to perform the security obligation as follows: a warning or a fine of 2 000 lari for persons with annual turnover up to 500 000 lari and a warning or a fine of 4 000 lari at higher turnover; with aggravating circumstances — 3 000 and 5 000 lari. Article 78 concerns the failure to perform the duty of notifying the State Audit Office: a warning or a fine of 2 000 lari at turnover up to 500 000 lari and a warning or a fine of 3 000 lari at higher turnover; with aggravating circumstances — 3 000 and 5 000 lari.
These figures are the economic justification of the plan: prepared procedures change not only the speed of response but also the risk that deadlines and formalities will be violated. The Legal.ge team will help you develop a data breach response plan — both at the level of the document and in shaping the process of updating and verifying it.
Frequently Asked Questions
The most frequent questions.
How quickly must the State Audit Service be notified?
Within 72 hours of discovery, in writing or electronically — unless significant harm or risk is unlikely.
When are data subjects informed?
Where significant harm or risk is likely — at the first opportunity, in plain language; where costs are disproportionate — by public communication; in certain cases the duty does not arise.
What sanctions apply?
A warning or a fine of 2 000 to 4 000 lari, with aggravation 3 000 to 5 000 lari; the missed 72-hour notification lies in the same frames.
How We Help on Legal.ge
A breach plan is a capability, not a document: a 72-hour calendar, templates and a sanctions map laid out in advance. The lawyers of Legal.ge will draft one for your organization and assist in a real incident.
