Document destruction as a form of data processing
Document destruction is often perceived as a mere technical operation — passing paper through a shredder or deleting a file. Under Georgian law this is not so: the concept of processing defined in Article 3 of the Law on Personal Data Protection directly includes deletion and destruction, just as it includes collection, storage, alteration, use and disclosure. Destruction is therefore full-fledged processing: it must be lawful, planned and documented.
The same article defines the concept of depersonalisation — such processing of data as a result of which linking them to a specific person becomes impossible. Depersonalisation is an alternative to destruction in those cases where the anonymous form of the data is still needed for statistics or analytics, but the link to the person is not.
When destruction becomes mandatory
The relevant subparagraph of the first paragraph of Article 4 of the law regulates the principle of storage limitation: data may be stored only for the period necessary to achieve the corresponding legitimate purpose. Once the purpose has been achieved, they must be deleted, destroyed or stored in depersonalised form — except where the processing is determined by a law or a subordinate normative act and storage is a necessary and proportionate measure.
This means that a destruction plan begins with purposes: for each category of document it must be known which purpose it serves, when that purpose is deemed achieved and what happens next — deletion, destruction or depersonalisation. After a lawful storage period expires, keeping a document is no longer a neutral act: it is a violation of the principle.
The subject's request and deadlines
Under the first paragraph of Article 16, the data subject has the right to demand from the controller the cessation, deletion or destruction of the processing of data concerning him or her, including profiling. The response deadline is clear: no later than 10 working days, the processing must cease or the data be deleted or destroyed, or the subject must be notified of the ground for refusal with an explanation of the appeal procedure.
The destruction process here too does not stay within the boundaries of the organisation. Under the relevant paragraphs of Article 16, the controller is obliged to notify all recipients of the data and all persons to whom it transferred the data of the cessation of processing or the deletion or destruction of the data — except where this is impossible due to the number of persons or disproportionate costs. Upon receiving the information, those persons are obliged to cease processing and to delete or destroy their own copies.
The role of the processor
Where data are processed by an external partner, the destruction rule is established by contract. Under the relevant subparagraph of the second paragraph of Article 36, the written agreement must provide for the processor's obligation — upon cancellation or termination of the agreement — to delete the data or transfer them to the controller and delete the copies, unless their retention is required by legislation.
At the end of a contract this norm acquires practical significance: every copy, backup specimen and production archive must either be destroyed or transferred to the client in full. Partial retention "just in case" requires a lawful ground — and none exists unless the law directly requires storage.
How to build the destruction process
The practical steps are as follows. First: inventorying and categorising documents — which data each type contains. Second: defining the storage period or criterion for each category according to its purpose. Third: separating the storage periods established by law — that part is exempt from the deletion obligation. Fourth: selecting destruction methods — different for paper and for electronic data. Fifth: keeping a record — what was destroyed, when and by whom. Sixth: a procedure for responding to subjects' requests within 10 working days.
What the supervisory authority pays attention to
When checking the lawfulness of destruction, the key questions are three. First: whether a ground for destruction existed — expiry of the purpose, a subject's request or the end of a contract. Second: whether the deadline was observed — especially the 10-working-day rule for statutory requests. Third: whether the result is evidenced — a record, a log or another document confirming the fact of destruction. Positive answers to these three questions mean that the destruction was not unlawful processing but the result of a procedure established by law.
Experience shows that it is precisely the third stage that is the weakest: organisations destroy documents excellently but cannot confirm it years later, when a check takes place. The Legal.ge team will help you develop a destruction policy and document its application, so that in the case of every destroyed document it is possible to confirm lawfulness.
