The legal framework of information governance in Georgia
Information governance means a system of managing data within an organization that ensures lawful collection, accuracy, security, and the ability to demonstrate all of it. Georgia has no separate sectoral statute for this field — the legal framework of information governance is built on the Georgian Law on Personal Data Protection, which shares the approaches of the European Union's General Data Protection Regulation, but it is precisely this law that creates the binding rules for Georgian organizations. In practice the framework consists of four pillars: the principles of processing together with accountability, protection by design, processing records together with the data protection officer institution, and security measures. Each is examined in detail below.
Principles of data processing and accountability
Point 1 of Article 4 of the law names the principles that must be respected in any processing: data must be processed lawfully, fairly, transparently for the subject and without violating their dignity; data is collected only for specific, clearly defined and legitimate purposes, and further processing for a purpose incompatible with the original one is impermissible; data is processed only to the extent necessary for achieving the legitimate purpose; data must be genuine and accurate, and inaccurate data must be corrected, deleted or destroyed without unjustified delay; data is stored only for the period necessary to achieve the purpose, after which it is deleted, destroyed or stored in depersonalized form; and finally, appropriate technical and organizational measures must be taken for security purposes.
Especially important is point 7 of the same article: the controller is responsible for compliance with these principles during processing and must be able to demonstrate their observance. This is the accountability principle — lawfulness must not only exist, it must be demonstrable. Where data is processed for a purpose different from the initial one, and this is not done with the subject's consent or on a legal basis, the controller must weigh the connection between the original and the new purpose, the character of its relationship with the subject, the subject's reasonable expectations, whether special categories of data are processed, the possible consequences, and the existing security measures.
Protection by design and by default
Article 26 of the law requires that, when creating a new product or service, the controller adopt appropriate technical and organizational measures — pseudonymization included — both when determining the means of processing and within the processing itself. These measures must secure the effective implementation of the processing principles and the integration of protective mechanisms to safeguard the subject's rights. Point 2 of the same article fixes the default rule: when determining the quantity, scale, storage periods and access to data, it must be ensured that only the volume of data necessary for the specific purpose is processed automatically, and that before an alternative approach is chosen, an indefinite circle of persons is automatically granted access only to minimal data. In terms of information governance, this means system design must begin precisely from data minimization.
Processing records and submission to the State Audit Office
Under point 1 of Article 28, the controller and its special representative must ensure, in writing or electronically, the recording of information related to processing: the identity and contacts of the controller, the special representative, the data protection officer, joint controllers and the processor; the purposes of processing; the categories of subjects and of data; the categories of recipients, including those in other states; transfers to another state or an international organization together with the corresponding safeguards, permission included; storage periods or the criteria for determining them; a general description of the organizational-technical security measures; and information on incidents. A similar record-keeping duty rests on the processor. Upon request, this information must be submitted to the State Audit Office immediately, but no later than 3 working days. The same article also regulates special cases: an electronic communications company must notify the State Audit Office about a transfer of identifying data to a law-enforcement body within 24 hours of the transfer, and a prosecutor's decree on an urgent covert investigative action is submitted in material form no later than 12 hours from the start time indicated in it.
The data protection officer
Under point 1 of Article 33 of the law, a public institution, an insurance organization, a commercial bank, a microfinance organization, a credit bureau, an electronic communications company, an airline, an airport and a medical institution — as well as any controller processing the data of a large number of subjects or carrying out systematic and large-scale monitoring of their behavior — must appoint or designate a data protection officer. The officer ensures the informing and consultation of staff, participates in developing internal regulations and the data protection impact assessment document, monitors compliance with legislation and internal documents, analyzes applications and complaints, represents the organization before the State Audit Office, and provides subjects with information about processing and their rights. Importantly, the officer's function may be performed by an employee or by another person under a service contract — outsourcing of the function is allowed — and several entities may share a common officer. The officer must be accountable to the highest level of governance, possess appropriate knowledge, be involved in significant decisions, and act independently. Within 10 working days of appointment or replacement, the officer's identity and contact details are communicated to the State Audit Office, which publishes them, and the same information is proactively published on the organization's website.
Data security measures
Article 27 of the law completes the security block: the controller must take appropriate technical and organizational measures to ensure compliance with the law and be able to confirm that compliance. The measures must correspond to possible and accompanying risks and include, among others, pseudonymization, logging of access to data, and information security mechanisms — confidentiality, integrity and availability. In defining the measures, account is taken of the categories and volume of data, the purpose, form and means of processing, and the possible threats of violating subjects' rights, while their effectiveness is assessed periodically and updated when necessary. Every action performed on data in electronic form is recorded — collection, modification, access, disclosure, linking and deletion, incidents included; employees must protect the secrecy and confidentiality of data even after the termination of their authority, and access scopes are defined according to their authorization. It is precisely these records and measures that create the technical foundation without which demonstrating accountability is impossible.
The Legal.ge team assists in building an information governance system — from maintaining processing records to appointing a protection officer and documenting security measures.
