Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Data Protection & Privacy
  4. DPO Services
  5. DPO Outsourcing

Loading...

DPO Services

DPO Outsourcing

Can the officer's function be outsourced?

Yes. Under the third paragraph of Article 33, the function may be performed by an employee or by another person on the basis of a services contract. Several organisations may also have a common officer.

Who is obliged to appoint an officer?

Public agencies, insurance organisations, commercial banks, microfinance organisations, credit bureaux, electronic communications companies, airlines, airports, medical facilities, as well as processors of large volumes of data and those conducting systematic large-scale monitoring.

Within what period is the State Audit Office notified?

Within 10 working days of the officer's appointment, designation or replacement, the identity and contact information are notified to the State Audit Office and published on the website.

What sanction is provided?

Under Article 82: a warning for a first violation; a repeat within 1 year of the imposition of an administrative penalty by the General Auditor — a fine of 3 000 lari.

5 min·...

The institution of the data protection officer under Georgian legislation

The data protection officer is the figure who personally ensures the lawfulness of data protection in an organisation. This institution is defined by Article 33 of the Georgian Law on Personal Data Protection, and it is precisely on that article that the outsourcing model rests as well — transferring the officer's function to an external person under a services contract. This page examines who is obliged to appoint an officer, what functions the officer has and how the outsourcing model works in accordance with the law.

An initial clarification is important: this is not a certification regime, and the law does not require formalities connected with special qualifications. The requirement is different: the officer must have appropriate knowledge in the field of data protection, must be accountable, taking into account the specific circumstances, before the highest possible level of governance, and his or her independence must be ensured.

Who is obliged to appoint an officer

Under the first paragraph of Article 33, the appointment or designation of a data protection officer is obligatory for: a public agency, an insurance organisation, a commercial bank, a microfinance organisation, a credit bureau, an electronic communications company, an airline, an airport, a medical facility, and also a controller or processor that processes data of a large number of data subjects or carries out systematic and large-scale monitoring of their behaviour.

Beyond the enumerated cases, other controllers have the right, at their own discretion, to appoint or designate an officer. The circle of persons who do not have this obligation is determined by a normative act of the General Auditor.

The officer's functions

The law regulates the officer's functions precisely. The officer ensures the informing and consultation of the controller, the processor and their employees on issues connected with data protection, including the adoption or amendment of regulatory legal norms; participates in the development of internal regulations and of the data protection impact assessment document; monitors the performance of Georgian legislation and internal organisational documents; analyses incoming applications and complaints and issues recommendations; receives consultations from the State Audit Office and represents the controller and the processor in relations with it; submits information and documents at its request; coordinates and monitors the performance of its assignments and recommendations; and, where a data subject applies, provides the subject with information on the processing processes and his or her rights.

These functions reflect that the officer is not merely a nominal position: it is a centre of knowledge, control and communication standing between the organisation and the supervisory authority.

The outsourcing model: how it is permitted

The third paragraph of Article 33 directly establishes the lawfulness of outsourcing: the officer's function may be performed by an employee of the controller or processor or by another person on the basis of a services contract. This means that a services contract concluded with an external partner is a fully lawful path — hiring an employee is not required.

The same paragraph also permits a combination of positions: the officer has the right to perform another function as well, provided this does not create a conflict of interests. Under the fourth paragraph, several controllers or processors may have a common officer, provided his or her full-fledged performance of the functions is ensured; for public agencies, the appointment of a common officer for several state agencies is also permitted.

The seventh paragraph defines the organisation's obligations: the officer's appropriate involvement in the process of making significant decisions must be ensured, along with provision with appropriate resources and independence in carrying out activities. In the event of temporary absence or termination of authority, another person must be vested with the officer's authority without unjustified delay.

Under the eighth paragraph of Article 33, the controller and the processor are obliged, within 10 working days of the officer's appointment or designation and also of his or her replacement, to notify the State Audit Office of the officer's identity and contact information, which the service publishes. At the same time, the officer's identity and contact information must be proactively published on the website, where one exists, or by another accessible means.

The officer's figure is also part of the records: the relevant subparagraph of the first paragraph of Article 28 directly includes the identity and contact information of the data protection officer in the records related to processing.

Liability for failure to perform the appointment obligation

Article 82 establishes the sanction in two stages. The failure to perform the obligation connected with the appointment of the officer provided for by the first paragraph of Article 33 entails a warning to the offender. The failure to perform the same obligation within 1 year of the imposition of an administrative penalty by the General Auditor entails a fine of 3 000 lari.

The Legal.ge team offers a data protection officer outsourcing service: full performance of the functions on the basis of a services contract, communication with the State Audit Office and the conduct of notifications within the 10-working-day deadlines, and the sharing of the common knowledge that ensures the quality of your organisation's compliance.

Frequently Asked Questions

Below are frequently asked questions about outsourcing.

Can the officer’s function be outsourced?

Yes — under paragraph 3 of Article 33 it may be performed by an employee or another person under a services contract; organisations may share one officer.

What fine is provided?

Under Article 82: a warning for a first breach; a repeat within 1 year — a fine of 3,000 GEL.

Within what period is the State Audit Service notified?

Within 10 working days of appointment, definition or change; the details are published on the website.

How We Help on Legal.ge

Deciding on DPO outsourcing requires assessing the obligation, the organisation of the function and the sanction risk. On Legal.ge you can consult a data-protection specialist.

Updated: ...

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer