Legal.geLegal.ge
SpecialistsLibraryPricing
More
AboutBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal platform.

Download on the App StoreLegal.ge for iPhone

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Data Protection & Privacy
  4. GDPR/Privacy Compliance
  5. GDPR Compliance

Services

0 services available

Loading...

GDPR/Privacy Compliance

GDPR Compliance

Which law applies in Georgia?

The Georgian Law on Personal Data Protection; the EU regulation matters when you serve European users.

What is the response deadline?

10 working days, extendable once by up to 10 working days with immediate notice.

Processing without consent?

Pick a lawful ground — contract, legal obligation, legitimate interest, public interest — and document it.

Where can consumers complain?

To the State Audit Service, the courts or a superior administrative organ; blocking may be requested pending review.

6 min·8 Feb 2026

European Standard and Georgian Law: What Compliance Actually Targets

The European Union's General Data Protection Regulation does not apply directly in Georgia — the operative law for the Georgian market is the Georgian Law on Personal Data Protection. At the same time, many Georgian companies serve European consumers and transfer data to European partners, so a compliance programme must answer to both regimes. The practical route is this: internal documents and processes are built on the specific requirements of the Georgian law, while the equivalent European level of protection is secured where both regimes demand the same thing — lawful grounds, transparency, data-subject rights and security measures.

Notably, the Georgian law's core blocks mirror the European regulation's architecture: processing principles, lawful bases, the rights of data subjects to information, rectification and erasure, and the right to complain. The differences lie in the details — deadlines, the supervisory authority and the sanctions regime. That is why a compliance audit runs in two layers: first a check of the obligations defined by the Georgian law, then a clarification of the grounds for transferring data to European partners.

Processing Principles: Lawfulness, Proportionality, Storage Limits

Article 4 of the Georgian law lays down the processing principles. Data must be processed lawfully, fairly, transparently for the data subject and without violating their dignity. Data must be collected only for specific, clearly defined and legitimate purposes, and further processing for a purpose incompatible with the original purpose is impermissible. Data must be processed only to the extent necessary to achieve the relevant legitimate purpose and must be proportionate to that purpose. Data must be accurate and, where necessary, kept up to date — inaccurate data must be corrected, deleted or destroyed without unjustifiable delay.

The same article provides that data may be stored only for the period necessary to achieve the relevant purpose; once the purpose is achieved, the data must be deleted, destroyed or stored in depersonalised form, except in cases defined by law. For security, technical and organisational measures must be taken that adequately ensure the protection of data, including from unauthorised or unlawful processing, accidental loss, destruction or damage. The controller is responsible for compliance with these principles and must be able to demonstrate compliance — this is precisely the requirement that makes a documented compliance programme indispensable.

Lawful Bases: What Your Processes Stand On

Article 5 defines the permissible grounds for processing: the data subject's consent for one or several specific purposes; performance of an obligation under a contract with the data subject or conclusion of a contract at the subject's request; processing provided for by law; performance of duties imposed on the controller by Georgian legislation; data made publicly available by law or by the subject; protection of the vital interests of the subject or another person, including monitoring the spread of epidemics, managing humanitarian crises and disasters; protection of a significant public interest; performance of tasks in the sphere of public interest defined by Georgian legislation; protection of the legitimate interests of the controller or a third party, unless the overriding interest of the data subject's rights prevails; and consideration of the data subject's application. Each process needs a chosen and recorded ground, because the burden of demonstrating the legal basis lies on the controller.

Data-Subject Rights and the 10-Working-Day Regime

Article 13 grants the data subject the right to information. On request and free of charge, the subject must receive information about the data being processed, the basis and purpose of processing, the source of collection, the storage period or the criteria for determining it, the subject's rights, and the basis, purposes and recipients of any transfers. This information must be provided no later than 10 working days after the request; in special cases, with proper justification, the period may be extended by no more than 10 working days, of which the subject must be notified immediately.

Article 15 secures the right to rectification, updating and completion: the subject may demand the correction of erroneous, inaccurate or incomplete data, and within 10 working days of the request the data must be corrected or the subject notified of the grounds for refusal together with an explanation of the appeal procedure. Article 16 governs the right to cessation of processing, deletion or destruction: within 10 working days of the request, processing must cease or data be deleted or destroyed, or the subject must be told the grounds for refusal and how to appeal it. Refusal is possible only in cases allowed by law — for example, where a lawful ground exists, where data are processed for substantiating or defending legal claims, where processing is necessary for the exercise of freedom of expression or information, or where processing serves archiving, scientific, historical or statistical purposes and honouring the request would make achieving those purposes impossible. In every refusal the burden of substantiating the ground lies on the controller.

Complaints and Supervision

Article 22 describes the right to complain: where rights or established rules under the law are violated, the data subject may apply to the State Audit Service of Georgia, the courts and/or a superior administrative organ. The subject may also request that the State Audit Service decide to block the data before it completes the review of the application, and the Service's decision may be appealed to court under Georgian legislation. For an organisation, this means the process and deadlines for answering subject requests must be established in documents, because every unanswered request becomes the seed of a complaint.

Frequently Asked Questions

Which law applies in Georgia?

The operative law is the Georgian Law on Personal Data Protection; the European regulation does not apply directly, but its requirements must be taken into account when serving European consumers.

How quickly must we answer a data subject?

Information, rectification and cessation requests are handled within 10 working days; in special cases the period may be extended once by no more than 10 working days with immediate notice to the subject.

When can we refuse deletion?

Only in cases allowed by law — an existing lawful ground, substantiation of legal claims, freedom of expression, or archiving and research purposes. Every refusal must be substantiated and the appeal route explained.

Where does a consumer complain?

To the State Audit Service of Georgia, the courts or a superior administrative organ; the subject may also request blocking of the data pending review.

How We Help on Legal.ge

Lawyers on Legal.ge conduct compliance audits, build processing registers, prepare internal policies and request-handling procedures for data-subject rights. We assess the lawful grounds of your processes, determine the grounds for transfers to European partners and deliver a remediation plan. Contact us to build a compliance programme around your business processes.

Updated: 29 Sep 2026

Legal basis:

  • პერსონალურ მონაცემთა დაცვის შესახებ