Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Data Protection & Privacy
  4. Data Processing
  5. Data Processing Agreements

Loading...

Data Processing

Data Processing Agreements

What must a data processing agreement define?

Under Article 36: the grounds and purposes of processing, the categories of data, the term of processing and the rights and obligations of the parties. The processor processes data only under a written assignment, and changing the purpose is inadmissible.

May data be passed to a sub-processor?

Only with the controller's prior written consent. The consent does not release the processor from its obligations and liability.

What happens in a dispute or at the end of the agreement?

Upon a dispute the processor immediately ceases processing and transfers all data to the controller in full. Upon cancellation or termination, processing ceases and the data are transferred immediately and in full.

What fine is provided?

Under Article 84: a warning or a fine of 1 000 lari where turnover does not exceed 500 000 lari and a warning or a fine of 2 000 lari above that threshold; with aggravating circumstances, 2 000 and 4 000 lari.

5 min·...

The data processing agreement: what happens after signing

A data processing agreement shapes the legal link between the controller and the processor. Under the first paragraph of Article 36 of the Georgian Law on Personal Data Protection, a processor may process data only on the basis of a legal act or a written agreement which defines the grounds and purposes of processing, the categories of data to be processed, the term of processing and the rights and obligations of the parties. The focus of this page, however, is not the text of the agreement but its lifecycle: what obligations the parties bear while the agreement operates, in disputes and upon its termination.

The law distributes clear roles here. The processor processes data only in accordance with the controller's written assignment or instruction; it ensures that the natural person directly involved in processing has a duty of confidentiality; it ensures the security of data in accordance with the law; and upon cancellation or termination of the agreement it deletes the data or transfers them to the controller and deletes the copies, unless their retention is required by legislation. Further processing of the data for a purpose different from that defined by the agreement or legal act is inadmissible.

Preliminary verification and monitoring

Choosing a partner does not end at the moment of signing. Under the sixth paragraph of Article 36, the controller is obliged to demand from the processor, in advance, information on the processing of data in accordance with the law and to monitor the processing carried out by the processor. This means that the right and duty of control are continuous: they begin before the agreement and continue throughout its operation.

In addition, where the processor's activity or aims create a high risk of non-purpose processing of data or of violation of the rights of subjects, concluding an agreement with such a person is inadmissible at all. Managing the agreement therefore begins with a risk assessment: who the partner is, what it does and how far its activity corresponds to the purposes for which the data are transferred.

Sub-processors and the consent rule

The processing chain often does not stop at one processor. Under the seventh paragraph of Article 36, unless otherwise provided by Georgian legislation, it is inadmissible for the processor to transfer its rights and duties, in full or in part, to another person without the controller's prior written consent. An important addition: the controller's consent does not release the processor from the corresponding obligations and liability.

The practical effect is clear: consent is a formal permission for engaging a sub-processor and not a redistribution of responsibility. The controller remains answerable for the behaviour of the entire chain, which is why the list of sub-processors, verification of their compliance and the procedure for consenting to changes are indispensable parts of managing the agreement.

Disputes and the transfer of data

Where a dispute arises between the parties, the law halts the process: under the eighth paragraph of Article 36, the processor is obliged to cease processing immediately and to transfer to the controller in full all the data at its disposal. The ninth paragraph of the same article defines the consequence of the cancellation or termination of the agreement or legal act: processing must cease and the processed data must be transferred to the controller immediately and in full.

These norms rule out the widespread practice under which, after the end of cooperation, the data remain with the former partner in a kind of warehouse. The exit is either deletion or full transfer — a third option does not comply with the law. The processor is also obliged to take organisational and technical measures to assist the controller in performing obligations connected with the exercise of the rights of data subjects.

Security and immediate notification of incidents

The security obligation in the lifecycle of the agreement belongs to both parties. Under the second paragraph of Article 27 of the law, the controller and the processor are obliged to adopt organisational and technical measures corresponding to the possible and accompanying risks — including pseudonymisation of data, logging of access to data and information-security mechanisms. These measures must be assessed periodically and updated where necessary.

In the event of an incident, time is decisive. Under the second paragraph of Article 29, the processor is obliged to notify the controller of the incident immediately, since it is the latter that bears the duty to record the incident and to notify the State Audit Office no later than 72 hours from its detection. Accordingly, the agreement and internal procedures must provide for this transmission channel in advance.

Liability and fines

Article 84 of the law attaches a sanction to the failure to perform the obligations provided for by Articles 35 and 36. In the general case this act entails, for a natural person, a public agency, a non-commercial legal entity, a legal entity, a branch of an enterprise of a foreign country and an individual entrepreneur whose annual turnover does not exceed 500 000 lari, a warning or a fine of 1 000 lari; where the turnover exceeds 500 000 lari, a warning or a fine of 2 000 lari. With aggravating circumstances the fine rises to 2 000 and 4 000 lari respectively.

The Legal.ge team will help you manage the entire lifecycle of data processing agreements: from verifying the partner and structuring the agreement to documenting monitoring, sub-processor consents and exit procedures.

Updated: ...

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer