Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Data Protection & Privacy
  4. Data Processing
  5. Data Processor Compliance

Loading...

Data Processing

Data Processor Compliance

Does the processor differ from an employee?

Yes. A natural person in an employment relationship with the controller is not a processor — the status concerns processing transferred to a third party.

Must the processor keep its own records?

Yes — under point 2 of Article 28: the parties' identities and contacts, types of processing, transfers and safeguards, security measures and incidents. Upon request it is submitted to the State Audit Service within 3 working days.

How is an incident communicated?

The processor notifies the controller immediately — the 72-hour period for notifying the State Audit Service starts precisely here.

May the mandate be transferred to another person?

Only with the controller's prior written consent — which does not release the processor from its obligations.

What happens on termination of the agreement?

Processing stops and the processed data are transferred to the controller immediately and in full.

5 min·...

Who is the processor

Under the definition of Article 3 of the Law on Personal Data Protection, the processor is a natural person, legal person or public institution that processes data for the controller or on its behalf. An important clarification: a natural person in an employment relationship with the controller is not considered a processor — the status concerns outsourcing, not one's own staff. International vocabulary often calls this role the "processor"; the Georgian statutory term is precisely the authorized person for processing, and that is the one used in legal analysis. The same article also defines an incident: a breach of data security that causes unlawful or accidental damage, loss, unauthorized disclosure, destruction, alteration, access to the data or other unauthorized processing.

The basis of operation, mandatory conditions and security

Under point 1 of Article 36, the processor processes data only on the basis of a legal act or a written agreement with the controller defining the grounds and purposes of processing, the categories of data to be processed, the term and the parties' rights and duties. The agreement must also contain five mandatory conditions: processing only under the controller's documented instruction; confidentiality for the persons directly participating in the processing; security in accordance with the law; deletion or transfer of the data to the controller on termination or cessation of the agreement — including copies, unless their retention is required by Georgian legislation; and provision of information to the controller with support for its monitoring.

Further processing beyond the defined purposes is prohibited. Processing through a processor is permissible only where the processor ensures appropriate organizational and technical measures to protect the subject's rights and the law's requirements; and where, in view of the processor's activity or aims, a high risk of non-purposeful processing or violation of the subject's rights exists, concluding the agreement is itself prohibited. Transferring rights and duties to another person is possible only with the controller's prior written consent, which does not release from obligations; on the arising of a dispute the processing stops immediately and the data are transferred in full, and on termination of the agreement or the legal act the processed data must be transferred to the controller immediately and in full.

The controller, for its part, must request information in advance about the processing in accordance with the data law and monitor the processor's processing. Under point 10 of Article 36, the processor must take appropriate organizational-technical measures to help the controller perform duties connected with the exercise of the subject's rights — a subject's request must not fall between the organizations. Therefore, in every outsourcing plan, the scenario of both roles should be played out before the contract: who keeps the records, who notifies and how the exit from the relationship works.

Own records and the State Audit Service

Point 2 of Article 28 obliges the processor to keep its own records: in writing or electronically, information must be ensured on the identity and contacts of the processor itself, the data protection officer, the controller, joint controllers and the special representative; the types of processing carried out for the controller or on its behalf; participation in international transfers, with the transfer and safeguards; a general description of security measures; and incidents. The duty extends to persons engaged in the processing under point 7 of Article 36. Upon request, this information is submitted to the State Audit Service immediately, but no later than 3 working days — just like the controller's records. The processor is thus a full-fledged participant in the law's eyes, not the controller's shadow.

The duty connected to incidents

Point 2 of Article 29 regulates incident communication: the processor is obliged to notify the controller of an incident immediately. This is a short but decisive norm: the 72-hour period within which the controller must notify the State Audit Service from the discovery of the incident begins precisely with the processor's immediate information. If the incident happened in the processor's own systems, delay stalls the whole chain — and increases the risk of a fine.

The processor's role is two-sided: it serves clients, but its own records, security measures and immediate notification are its personal sphere of responsibility — precisely the elements the State Audit Service examines.

Frequently Asked Questions

Below we answer questions about the status and duties of the processor.

Does the processor differ from an employee?

Yes. A natural person in an employment relationship with the controller is not a processor — the status concerns processing transferred to a third party.

How many mandatory conditions must the agreement contain?

Five: processing under instruction, confidentiality of personnel, security, deletion or transfer of data on termination, and information for monitoring.

Must the processor keep its own records?

Yes — under point 2 of Article 28: the parties' identities and contacts, types of processing, transfers and safeguards, security measures and incidents. Upon request it is submitted to the State Audit Service within 3 working days.

How is an incident communicated?

The processor notifies the controller immediately — the 72-hour period for notifying the State Audit Service starts precisely here.

May the mandate be transferred to another person?

Only with the controller's prior written consent — which does not release the processor from its obligations.

How We Help on Legal.ge

The Legal.ge team assists both in building the processor's duties properly and in the controller managing the chain: we draft the mandatory conditions of the agreement, describe the records and structure the incident-response procedure.

If your organization processes data for others or outsources processing, write to us on Legal.ge — we will assess your agreements against the law's requirements, review the records and prepare corrections so that every duty is performed on time and with justification.

Updated: ...

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer