About this service
A personal-data protection audit is the work that puts an organisation on its feet before an inspection arrives. In Georgia, supervision in the field of data protection is exercised by the State Audit Service — the supervisory authority designated by the current legislation, which may inspect you either on its own initiative or on the basis of an interested person's application, with the decision on conducting an inspection taken by the General Auditor. An inspection is no formality: its results may include an order to remedy violations, cessation of processing, blocking, deletion, destruction or depersonalisation of data, and administrative liability. This service is built on exactly that reality: we prepare your organisation by checking the same points the State Audit Service examines.
What the State Audit Service inspects
The law defines the content of an inspection precisely. An inspection comprises: establishing compliance with the principles of data processing and the existence of lawful grounds for processing; checking the conformity of the organisational and technical measures and procedures implemented for data security with the requirements established by legislation; checking the legality of transfers of data to another state or an international organisation; and checking compliance with the rules and requirements established by this and other normative acts for data protection. During an inspection the Service may demand a document or information from any institution, natural person or legal person — including information containing state, tax, banking, commercial or professional secrets — and may enter any institution and examine any document regardless of its content and storage form.
Deadlines for providing information
An inspection comes with strict deadlines. The records-related information on data processing must be provided to the State Audit Service immediately upon the corresponding request, but no later than 3 working days. And where the requested material must be collected in another institution or unit, or the information is of significant volume, the controller or processor must supply the material immediately, but no later than 10 working days; on the basis of a reasoned request this period may be extended by no more than 10 working days. In audit preparation we check precisely this: whether your organisation could assemble the documents within these deadlines, or whether the records are not arranged so that they can be produced promptly on request.
What records and security require
The subject of an inspection is also the documentary foundation the organisation must hold. Records of processing-related information must exist in written or electronic form and cover: the identity and contact details of the controller, its special representative and the data protection officer; the purposes of processing; information on categories of data subjects and data; categories of recipients; information on transfers to another state or international organisation and the appropriate safeguards, including the Service's permission where it exists; storage periods or the criteria for setting them; a general description of security measures; and information on incidents. On the security side, the law requires measures proportionate to the possible risks — including pseudonymisation, access logging, and confidentiality, integrity and availability mechanisms — together with periodic assessment of their effectiveness.
What measures the Service may apply
Where the State Audit Service detects a violation, it may apply one or several measures: demand that the violation and the related deficiencies be remedied in the form and within the period it indicates; demand temporary or permanent cessation of processing where the security measures do not meet the requirements; demand cessation of processing, blocking, deletion, destruction or depersonalisation of data where processing is carried out in violation of the law; demand cessation of transfers to another state or international organisation; issue written advice in the case of a minor violation; or impose administrative liability. The demands must be met within the set period and the Service notified thereof; persistent non-compliance leads the Service to apply to a court, a law-enforcement organ or the sector regulator. The Service's decision is binding and may be appealed only in court.
Fines for obstruction
The law imposes administrative liability for obstructing an inspection and for violating the procedure for providing information or providing false information. Violating the submission procedure or providing false information entails a warning or a fine: for persons whose annual turnover does not exceed 500 000 lari — 1 000 lari, and for legal persons whose turnover exceeds 500 000 lari — 2 000 lari. Repetition of the same act within one year raises the fine to 3 000 and 5 000 lari respectively. Any form of obstruction of the inspection is fined up to 2 000 lari, or up to 4 000 lari for large-turnover entities, and on repetition — up to 4 000 and 6 000 lari respectively. That is the price a single mistake can cost an unprepared organisation.
How we can help
Our audit aims to have all of the above balanced before an inspection begins: we review the principles and grounds of processing, security measures and international transfers; we assess the completeness of your records and the speed with which they can be produced; we identify deficiencies and give you a remediation plan with exact deadlines. If an inspection is already under way, we help prepare and deliver the materials within the deadlines and respond correctly to the Service's demands. Contact us for a concrete assessment of where your organisation stands in relation to a possible inspection.
