About this service
Digital data storage is the daily routine of almost every organisation, yet legally it is one of the least considered processes: data is kept because „it was set up that way“, not because a purpose requires it. In Georgia the legal framework for data storage is defined by the Georgian law on personal data protection — its norms on principles, security, data protection by design and default, and records together create the rules under which digital data must be stored. This service is legal consultation built precisely on that framework: we analyse how and for how long your data is stored, how far this complies with the law, and what a properly constructed storage regime looks like.
The storage-limitation principle — data is kept until the purpose is achieved
Article 4 of the law establishes the principles of data processing, and for storage the decisive one is this: data may be stored only for the period necessary to achieve the corresponding legitimate purpose of processing. Once the purpose for which the data is processed has been achieved, the data must be deleted, destroyed or stored in depersonalised form — except where processing is determined by law or by a subordinate normative act issued in conformity with law, and storage is a necessary and proportionate measure. The same principles add that data must be accurate: inaccurate data must be corrected, erased or destroyed without unjustified delay. In practical terms this means concrete work: an organisation must know, for every category of data, what the storage purpose is, when the purpose is achieved, and what happens after that moment.
Security measures — what must be safeguarded during storage
Article 27 of the law regulates the security obligation: the controller must take appropriate technical and organisational measures to ensure that data is processed in conformity with the law and must be able to demonstrate that conformity. The measures significant for digital storage are named concretely: the controller and the processor must take organisational and technical measures corresponding to the possible and accompanying risks — including pseudonymisation of data, logging of access to data, and information-security mechanisms ensuring confidentiality, integrity and availability. The measures must be proportionate: account must be taken of the categories and volume of data, the purpose, form and means of processing, and the possible risks to the rights of data subjects, and the effectiveness of the measures must be assessed periodically. In a storage consultation we examine exactly these elements: is access logged, is backup appropriate, who can see what, and how the system protects data from loss and disclosure.
Data protection by design — minimisation as the automatically applied initial method
When digital systems are designed or updated, the requirement of Article 26 applies: taking into account new technologies, costs, the nature, scale, context and purposes of processing, and the expected risks to the rights of data subjects, the controller must adopt appropriate technical and organisational measures — including pseudonymisation — both when determining the means of processing and in the processing itself. The law concludes that in determining the quantity of data, the scale of processing, storage periods and access to data, measures must ensure that only the amount of data necessary for the specific purpose is processed automatically, and that before an alternative approach is chosen, access is automatically ensured only to the minimal volume. In plain terms: a new system must be configured from the outset to collect nothing superfluous — not to store everything and „clean it up later“.
Records — storage must exist on paper too
Article 28 requires written or electronic records of processing-related information: the controller and its special representative must ensure the recording of information such as the purposes of processing, the categories of data subjects and data, the categories of recipients, the storage periods — or, where a concrete period cannot be determined, the criteria for setting it — a description of the security measures taken, and information about incidents. These records are precisely the document in which the storage regime becomes visible — and under the law, upon the corresponding request, immediately but no later than 3 working days, the information must be provided to the State Audit Service. In other words, the records must be maintained so that they can be produced promptly when requested.
What the consultation covers
The consultation begins with an analysis of the current state: which systems store data, for what purposes, for what periods and with what access. We then identify compliance gaps — undefined periods, data remaining after the purpose is achieved, inadequate security measures, processes missing from the records — and give you concrete recommendations: which data must be deleted or depersonalised, how storage periods and criteria should be defined, and what must be entered in the records. The result is not general advice but a complete picture of your organisation's storage regime and a remediation plan.
How to start
Approach us with whatever material you have — a list of systems, existing policies, a description of purposes. At the first meeting we will assess the situation and plan the next steps. If data storage is already the subject of a dispute or an inspection, we will assess your position on the same framework and prepare the appropriate response. Remember: a properly constructed storage regime is not only compliance but also protection from loss — data kept excessively and purposelessly becomes a risk in itself.
