Connected device data and the Georgian law
Internet-connected devices — sensors, household appliances, wearable gadgets, industrial controllers — continuously collect information about owners and users: location, regime, habits, sometimes health indicators. Georgia has no separate sectoral statute for the confidentiality of connected devices, and this should be said plainly: data flows from connected devices run on the general regime — the Law of Georgia on Personal Data Protection. That law demands protection at the level of design, security measures, processing principles and incident response. Below we explain how these requirements extend to a connected-device product.
Processing principles — the starting frame
The law establishes principles to be observed in processing, and each of them bears directly on devices. Data must be processed lawfully, fairly, transparently for the subject and without violating dignity. Collection is admissible only for specific, clearly defined and legitimate purposes, and further processing incompatible with the original purpose is impermissible. Data must be processed only to the extent necessary for achieving the legitimate purpose and must be proportionate to it. Data must be authentic and accurate, and storage — only for the period necessary for the purpose: once the purpose is achieved, the data are deleted, destroyed or stored in depersonalised form. Finally, the security principle requires technical and organisational measures protecting the data from unauthorised or unlawful processing and accidental loss.
Protection at the level of design: minimisation as the initial method
The law defines an approach tied precisely to new products: taking into account new technologies, costs, the character, scale, context and purposes of processing, and the expected risks to the rights of subjects, the controller must adopt appropriate technical and organisational measures both when determining the means of processing and in the process itself — including pseudonymisation. Moreover, when determining the quantity of data, the scale of processing, storage periods and access, it must be ensured that only the volume necessary for the specific purpose is processed automatically. The measures must be applied so that, before an alternative approach is chosen, an indefinite circle of persons is automatically granted access only to the minimal volume of data. In the connected-device context this means: the device must be designed so that information transmitted from the sensor is processed only in the quantity and only for the period the function requires.
Security measures and logging
The law obliges the controller and the processor to adopt organisational and technical measures corresponding to possible and accompanying threats — including pseudonymisation of data, logging of access to data and information security mechanisms ensuring confidentiality, integrity and accessibility. The measures must correspond to the categories of data, their volume, the purpose and means of processing, and the possible threats of violating the rights of subjects, and their effectiveness must be periodically assessed. Logging is a separate requirement: every action towards data existing in electronic form — collection, alteration, access, disclosure, deletion — must be recorded. In a device ecosystem this entails retaining logs both at the device level and in the cloud part of the platform.
Incident: the 72-hour duty
When protection nevertheless fails and an incident occurs — a breach of data security causing unlawful or accidental damage, loss, unauthorised disclosure, alteration or access — the law imposes a strict duty: the controller must record the incident, its consequences and the measures taken, and no later than 72 hours from discovery notify the State Audit Service in writing or electronically, except where the incident is unlikely to cause significant harm. The notice must contain the circumstances, nature and time of the incident; the estimated categories and volumes of data disclosed, damaged, deleted, destroyed, obtained, lost or altered, and the categories and numbers of subjects affected; the estimated damage and the measures taken or planned; whether and when the subjects are to be informed; and contact details. The processor, for its part, must inform the controller immediately.
How we can help
We assist manufacturers of connected devices and service providers in assessing the data flows of a product: we determine which data are personal, how minimisation and pseudonymisation should be designed, what logging and security measures the platform needs, and how to build an incident response process observing the 72-hour term. Contact us — we will assess your device or platform under the current law.
A separate matter worth attention is the distinction between device owners and users: home sensors are often used by an entire family and workplace devices by employees, and the law treats each of them as a subject. This means that the data of one and the same device may contain information about several people, and the rights of each are protected independently. Designing a product therefore requires more than thinking about a single user account: it must be determined who else may appear in the role of source or recipient of data and how transparency is ensured for each. Our approach begins precisely with this analysis.
