Provider Rights and Core Obligations
A qualified trusted-services provider is entitled to provide one or more qualified or other trusted services defined by the law and to set the corresponding fee. At the same time the law imposes on it a strict block of obligations: it must draw up internal statutes and ensure their public availability for every service it provides.
The internal statutes must reflect: a description of the secure systems, means and procedures used; the grounds and scope of liability insurance, including compensation for damage caused by cessation of activity; the period and procedure for storing all necessary information; the procedure for cessation of activity and its transfer to another person; the amount of the fee, the payment procedure and the procedure for possible changes; and any other conditions established by the technical regulation. The provider notifies the supervisory organ and its consumers of any change in the statutes at least 14 calendar days in advance, and of an intended cessation of service at least 30 calendar days in advance — otherwise it is obliged to compensate the damage caused by non-notification.
The operational requirements are equally exact: the use of only secure systems, means and procedures ensuring reliability, data integrity, verification of authenticity and protection from forgery and unauthorised use; sufficient financial and technical resources and qualified personnel in accordance with the technical regulation; personal-data protection and information-security incident management; civil liability insurance (for an administrative organ — sufficient financial resources and guarantees); a service-continuity plan submitted to the organ; and notification of the organ of any breach of system security or data integrity within no more than 24 hours. Compensation of damage caused by non-observance of the requirements is obligatory, save for force-majeure circumstances.
Certificate-Related Service Obligations
A provider of certificate-related services must, beyond the basic requirements: identify the certificate holder in accordance with the technical regulation; ensure the reliability of the data recorded upon issuance; ensure immediate cancellation, suspension and reactivation of certificates where the law so provides; maintain and update a database of issued qualified-signature certificates; supply certificate-status information to interested persons via the internet on a continuous basis; and retain certificates and related data and facts for at least 6 years from cancellation, with exact indication of the time. The identification data of a holder registered under a pseudonym are likewise released in cases provided for by legislation.
Authorization at the Digital Governance Agency
A person wishing to become a qualified trusted-services provider must, in order to establish compliance of its activity with the law and the technical regulation, undergo authorization at the Digital Governance Agency — a public-law legal person operating within the governance area of the Ministry of Justice of Georgia. The applicant submits an application, an audit conclusion on compliance, documentation of sufficient financial resources and guarantees (or of civil liability insurance) and the internal statutes. Where necessary the Agency may request additional documentation to assess system security and continuity of activity.
Authorization may be refused if the applicant submitted the documentation incompletely or inaccurately, or if its activity does not conform to the law and the technical regulation; a deadline is set to cure the defect, failing which refusal follows — though the right to reapply remains. The authorization and supervision procedure is determined by an order of the Minister of Justice of Georgia — a delegation named expressly in the law.
Supervision and Sanctions
For supervision purposes the Digital Governance Agency: checks the provider's compliance as needed, but at least once every 2 years; reacts to violations discovered; suspends or revokes the authorization; and maintains and publishes the list of providers and the services they offer. This public list is an important instrument for consumers to verify status.
Recognition of Foreign Services
A qualified trusted service operating abroad or of international organisations has legal force equal to a qualified trusted service operating in Georgia if Georgia has concluded an appropriate international treaty on the recognition of qualified trusted services. The international treaty is named here as a separate condition, and its existence must always be verified.
Frequently Asked Questions
Where does a provider obtain authorization?
At the Digital Governance Agency within the justice system; an application, an audit conclusion, financial documentation or insurance and the internal statutes are required, and the procedure is settled by the Minister of Justice's order.
What are the notification deadlines for changes and cessation?
Statute changes — at least 14 calendar days in advance to the organ and consumers; cessation of service — at least 30 calendar days in advance; otherwise damage must be compensated.
How frequent are the inspections?
As needed, but at least once every 2 years, and the Agency reacts to violations even by suspending or revoking the authorization.
Are foreign services recognized?
Yes, if Georgia has an international treaty on the recognition of qualified trusted services — then the foreign service carries force equal to the Georgian one.
How We Help on Legal.ge
The Legal.ge team helps prepare the authorization process, draft the internal statutes and communicate with the Agency. Write to us — we will plan the lawful launch of your activity and continuous compliance monitoring.
