The Page Bears the EU AI Act Name — The Norms Are Georgian
In international practice, the central instrument of artificial-intelligence regulation is the EU AI Act, and for Georgian companies operating on the EU market its requirements apply directly. On Georgia's internal market, however, the use of AI systems is governed by the Georgian law on personal data protection, which regulates automated decision-making, data minimisation and impact assessment. This page explains precisely the Georgian norms, with the EU AI Act referenced as context.
Three provisions form the cornerstones of this regime: the rule on automated individual decision-making and the related rights, the priority of data minimisation, and the obligation of data protection impact assessment. Together they create the compliance frame within which every AI system must be placed.
Automated Decisions and Profiling
A data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning him. Only three exceptions exist: the decision is based on explicit consent; it is necessary for entering into or performing a contract; or it is provided by law. Outside these, a purely automated significant decision is unlawful.
Upon the data subject's request, the controller must take measures to protect his rights, freedoms and legitimate interests — including involving human resources in the decision-making process, and giving the possibility to express a view and to contest the decision. The use of special categories of data in such decisions is admissible only in defined cases where appropriate safeguards exist.
The Priority of Data Minimisation
When creating a new product or service, the controller — both when determining the means and in the processing itself — must take appropriate technical and organisational measures, including pseudonymisation. These measures must ensure the effective implementation of processing principles and the integration of safeguards protecting the rights of data subjects.
In determining the quantity of data, the scale of processing, storage periods and access, measures must ensure that only the amount necessary for the specific purpose is processed automatically. The measures must be applied so that, before an alternative approach is chosen, access for an indefinite circle of persons is limited to the minimal amount of data. For AI systems this means: minimisation must be embedded at the design level.
Impact Assessment
Where processing using new technologies, taking into account the category, volume, purposes and means of processing, is likely to result in a high risk to fundamental rights and freedoms, the controller is obliged to carry out a prior data protection impact assessment.
The assessment is also mandatory where the controller takes a fully automated decision producing legal, financial or other significant effects; processes special categories of data of a large number of subjects; or carries out systematic and large-scale monitoring of behaviour in publicly accessible places. The written document created at assessment is the evidence of compliance — it shows the risk was minimised.
Practical Compliance Steps
Whether your AI system serves the Georgian market or the EU one, three actions are needed: classification of the decisions (is the effect significant, is the process automated); embedding minimisation in the architecture; and documenting the impact assessment. For the EU market, the EU AI Act's risk-tier analysis with its certification requirements is added on top.
Breach of each of these norms leads to sanctions and reputational harm, so compliance is not a formality — it is a business process accompanying the product life cycle throughout.
No less important is the governance side: how data flows to third parties are managed, who receives access to the model's outputs, and how the decision logic is recorded. The answers must be reflected in the impact assessment document in detail, because they show how far the system's architecture matches the law's requirements.
Documentation here is as important as the technical solution: measures that are not recorded do not exist in the regulator's eyes. The compliance file — from classification to assessment — must therefore be prepared in advance and kept updatable.
Frequently Asked Questions
Are automated decisions prohibited?
No, but the data subject has the right not to be subject to a solely automated significant decision unless consent, contractual necessity or law exists.
What is data minimisation?
The requirement that data be processed automatically only to the necessary minimum, with minimal access ensured before an alternative approach is chosen — at design level.
When is impact assessment mandatory?
At high risk — with new technologies threatening rights, fully automated significant decisions, large-scale special-category processing, and behaviour monitoring.
How do we start compliance?
With decision classification, minimisation architecture and the impact assessment document; for the EU market, add the EU AI Act risk analysis.
How We Help on Legal.ge
The Legal.ge team conducts legal audits of AI systems: classification, verification of minimisation and preparation of impact assessments, in the context of Georgian legislation and the EU AI Act. Contact us already at the design stage of your system — this way the compliance frame is embedded in the architecture from the start and no costly rebuild follows.

