Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Data Protection & Privacy
  4. Data Processing
  5. Data Processing Agreements

Loading...

Data Processing

Data Processing Agreements

Can data processing be entrusted by oral agreement?

No. Under Article 36, a processor processes data only under a legal act or a written agreement. Written form is a mandatory condition.

What must the contract necessarily contain?

Grounds and purposes of processing, data categories, processing term and the parties' rights and duties, plus five mandatory clauses: instruction-based processing, personnel confidentiality, security, deletion or transfer on termination, and information for monitoring.

May the mandate be transferred to another person?

Only with the controller's prior written consent — and that consent does not release the processor from its obligations.

What fine is provided?

Under Article 84: a warning or GEL 1 000 for persons with turnover up to GEL 500 000, a warning or GEL 2 000 above that; with aggravating circumstances — up to GEL 2 000 and GEL 4 000.

5 min·...

The legal basis — why a written agreement is mandatory

When an organization entrusts data processing to a third party — a service provider, a cloud, a contractor — Article 36 of the Law on Personal Data Protection strictly defines the form: a processor may process data only on the basis of a legal act or a written agreement concluded with the controller. The existence of a contract is not a matter of prudence — it is a statutory condition without which the processing is unlawful. That is why the data processing agreement is the legal rampart of every outsourcing relationship.

Under point 1 of Article 36, the agreement must define: the grounds and purposes of processing; the categories of data to be processed; the term of processing; and the rights and obligations of the controller and the processor. The agreement thus answers at minimum four questions — why, what, for how long, and who does what. If these elements are not defined, the agreement fails the law's requirement, though the parties remain free to add further terms.

Mandatory clauses — five duties the contract must carry

Point 2 of Article 36 regulates the processor's duties that must enter the agreement: first — data are processed only under the controller's documented instruction; second — the natural persons directly involved in processing bear a confidentiality duty; third — data security is ensured in accordance with the law; fourth — on termination or expiry of the agreement the data are deleted or handed over to the controller, copies included, unless storage is required by legislation; fifth — the controller receives appropriate information for compliance and is facilitated in monitoring the processing. These five points are the contract's minimum framework — without them the document is deficient.

The bounds of the mandate and sub-processors

The law actively protects the mandate's bounds: further processing for purposes different from those defined by the agreement or legal act is prohibited. Processing through a processor is permissible only where the processor takes appropriate organizational and technical measures to protect the subject's rights and the law's requirements; and where the processor's activity carries a high risk of non-purposeful processing or violation of rights, concluding the agreement is prohibited. The controller must request information in advance on law-compliant processing and monitor it. Transferring one's rights and duties to another person — a sub-processor — is possible only with the controller's prior written consent, and that consent does not release the processor from its obligations. On a dispute, processing stops immediately and the data are fully transferred to the controller; the same happens when the agreement ends.

Joint control and security

Article 35 regulates joint controllers: where more than one controller is involved in processing, they must determine in advance, in writing, each one's duties and responsibility — including the protection of the subject's rights and information duties; this information must be accessible to the subject, who may also apply to each controller individually. Article 27 binds both sides on security: the controller and the processor jointly take organizational-technical measures corresponding to possible and accompanying threats — pseudonymization, access logging and confidentiality-integrity-availability mechanisms included. Security liability cannot be shifted entirely onto one side by contract.

A contract does not end when signed once. The law considers its whole life: the agreement may provide for the processor's duty to assist the controller for the purposes of security and the protection of the subject's rights; and the processor must take appropriate organizational-technical measures to help the controller perform duties connected with the exercise of the subject's rights — for example, in responding to deletion, rectification or portability requests. Where the agreement is cancelled or expires, processing must stop and the processed data must be transferred to the controller immediately and in full. Where a dispute arises — at the very moment the parties' relationship sours — the law is unambiguous: processing stops immediately and the data are transferred in full. Data cannot be left "stranded" in a failing relationship by law.

A practical recommendation for organizations: existing outsourcing contracts deserve re-verification against these requirements — many are written in generic service language and do not reflect the elements the law demands. Auditing the contract is cheap; a fine and explanations before the State Audit Service are not.

Fines and why this matters

Article 84 attaches fines to non-performance of the duties under Articles 35 and 36: for persons with annual turnover up to GEL 500 000 — a warning or a fine of GEL 1 000; for legal persons above that turnover — a warning or GEL 2 000; with aggravating circumstances — GEL 2 000 and GEL 4 000 respectively. The Legal.ge team assists in drafting data processing agreements and bringing existing contracts into compliance.

Frequently Asked Questions

Below are frequently asked questions about processing contracts.

Can processing be entrusted by an oral agreement?

No — under Article 36, only a legal act or a written agreement suffices.

What fine is provided?

Under Article 84 — a warning or 1,000 GEL for turnover up to 500,000 GEL, and a warning or 2,000 GEL above that.

What must the contract contain?

The grounds and purposes of processing, data categories, time limits, the parties’ rights and duties, and the five mandatory conditions.

How We Help on Legal.ge

A well-drafted contract is dispute prevention. On Legal.ge you can consult a data-protection specialist who will check or prepare your agreement. Contact us.

Updated: ...

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer