What a data protection impact assessment is and which law governs it in Georgia
A data protection impact assessment is a prior, documented analysis through which the controller identifies, before launching a processing operation, what risks the planned processing creates for the fundamental rights and freedoms of individuals and what organisational and technical measures are needed to avoid or substantially reduce those risks. In Georgia this instrument exists not as a voluntary standard or a contractual practice but as a direct statutory duty: Article 31 of the Georgian Law on Personal Data Protection defines when, how and in which form the assessment must be carried out. That article is the anchor of your organisation's compliance position and of its administrative liability exposure.
In international practice this instrument is widely known by an abbreviation that spread from the European Union's general data protection regulation. It is important to keep the distinction clear: the operative norm in Georgian law is the Georgian Law on Personal Data Protection, which follows the European approach, while the EU regulation serves only as the comparative framework the Georgian law aligns with. Article 31 of the same law directly names the State Audit Office as the public body to be consulted where necessary, and the criteria for establishing the circumstances that trigger the assessment duty are set by a normative act of the General Auditor.
When the assessment becomes mandatory
Under the first paragraph of Article 31, where taking into account new technologies, the category of data, the volume, the purposes and the means of processing there is a high probability of a risk of violation of fundamental rights and freedoms, the controller is obliged to carry out a data protection impact assessment in advance. The assessment therefore precedes the planned processing; it is not a remedial exercise conducted after a breach has already occurred.
Beyond this general criterion, the second paragraph of Article 31 lists three situations in which the assessment is mandatory without any additional interpretation. First, where the controller makes a decision with legal, financial or other significantly important consequences for the data subject in a fully automated manner, including on the basis of profiling. Second, where it processes special categories of data of a large number of data subjects. Third, where it carries out systematic and large-scale monitoring of the behaviour of data subjects in public gathering places.
To prevent the notion of a large number from becoming a matter of subjective interpretation, the seventh paragraph of Article 31 sets a quantitative threshold: a large number of data subjects means not less than 3 percent of the population of Georgia, calculated according to the final results of the last census. In practical terms, if your processing touches special-category data at that scale, the assessment is mandatory. The criteria for establishing the circumstances giving rise to the assessment duty and the procedure for conducting it are established in detail by a normative act of the General Auditor, so the document must be reconciled with those acts before it is finalised.
Required content of the assessment document and its retention
A data protection impact assessment is not merely a technical conclusion or an internal memorandum. Under the third paragraph of Article 31 the controller is obliged to create a written document containing two closely connected blocks. The first is a description of the category of data, the purposes of their processing, proportionality, the process and the grounds. The second is an assessment of the possible risks of violation of fundamental rights and freedoms and a description of the organisational and technical measures envisaged for data security. The document thus answers simultaneously what you process, why, and with which risks.
The document also has a legally significant retention rule. Under the fourth paragraph of Article 31, where the processing process changes substantially the controller is obliged to update the assessment document, and the retention rule sets a clear orientation: the document is kept throughout the entire period of processing, and where processing ceases, for at least 1 year. This means that producing the document at the request of the supervisory authority cannot become a problem even for processing operations that have already been completed.
High residual risk: additional measures, consultation and the prohibition of processing
Where the assessment reveals a high risk of violation of fundamental rights and freedoms, the fifth paragraph of Article 31 prescribes a legally defined sequence of actions. First, all necessary measures must be taken to substantially reduce the risks and, where necessary, the State Audit Office must be consulted for that purpose. If, through additional organisational and technical measures, it remains impossible to reduce the risk substantially, the law is categorical: the data must not be processed. This prohibition is one of the strictest consequences of the assessment institution and it does not allow for any supplementary arrangement.
Where the State Audit Office is addressed, the sixth paragraph of Article 31 defines the information to be submitted: information on the powers of the controller, joint controllers and the processor; information on the purposes and means of the planned processing; information on the security measures defined to protect the rights and freedoms of data subjects; the contact information of the data protection officer, where one exists; the data protection impact assessment itself; and other additional information where the service requests it.
A separate point concerns the confidentiality of the document. Under the eighth paragraph of Article 31 the document is not subject to publication where publication could threaten state security, information security and cybersecurity or defence interests, public safety interests, the prevention of crime, operational-search activities, investigation, criminal prosecution, the administration of justice and other enumerated interests. Detailed technical information used in preparing the assessment therefore does not reduce the obligation to present it to the supervisory authority.
Privacy by design as the complementary duty
The assessment does not exist in a vacuum. Article 26 of the law governs the priority of more extensive masking of data as the automatically applied initial method before the choice of an alternative approach when creating a new product or service. Specifically, taking into account new technologies, the costs of implementation, the nature, scale, context and purposes of processing, as well as the expected risks to the rights and freedoms of data subjects, the controller must adopt appropriate technical and organisational measures both when determining the means of processing and directly in the processing itself, including pseudonymisation.
The second paragraph of the same article requires that when determining the quantity of data, the scale of processing, the retention periods and access to the data, measures be adopted so that only the volume of data necessary for the specific purpose is processed automatically. The risks and measures described in the assessment document must be tied to these requirements, because both institutions serve the same logic: protection must not be added afterwards, it must be designed in from the start.
Administrative liability for failing to carry out the assessment
Article 80 of the law attaches an administrative sanction to the failure to perform the assessment duty provided for by Article 31. In the general case this act entails, for a natural person, a public agency, a non-commercial legal entity, a legal entity, a branch of an enterprise of a foreign country and an individual entrepreneur whose annual turnover does not exceed 500 000 lari, a warning or a fine of 2 000 lari. Under the same paragraph, for a legal entity, a branch of an enterprise of a foreign country and an individual entrepreneur whose annual turnover exceeds 500 000 lari, a warning or a fine of 3 000 lari is prescribed. The warning and the fine are alternative sanctions here, and the choice depends on the circumstances.
The same act committed in the presence of aggravating circumstances leads to a stricter outcome: a fine of 3 000 lari for those whose annual turnover does not exceed 500 000 lari, and a fine of 5 000 lari where the turnover exceeds that threshold. In reality, a delayed or superficial assessment is not only a sanction risk; it also weakens the lawfulness of the very processing whose protection the assessment was designed to secure.
Transitional rules and practical recommendations
Article 88 of the law contains transitional provisions. Among them is the rule under which the controller is released from the duty under Article 26 with respect to software used for data processing that was created before 1 March 2024, except where that software was significantly updated after 1 March 2024 and the performance of the duty does not require unjustified expenditure. It is also established that the normative act on the criteria for establishing the circumstances giving rise to the assessment duty and on the assessment procedure was to be issued before 1 March 2024.
A practical plan for an organisation consists of the following stages: describing and classifying processing operations; checking the triggers listed in the second paragraph of Article 31; where high risk is established, preparing the document in accordance with the third paragraph; consulting the State Audit Office where necessary with the content defined by the sixth paragraph; updating the document upon every substantial change and retaining it for the required periods. The Legal.ge team will help you go through this process so that the assessment is not a formal document but a genuine risk management instrument.
