Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Data Protection & Privacy
  4. GDPR/Privacy Compliance
  5. Privacy Compliance Audits

Loading...

GDPR/Privacy Compliance

Privacy Compliance Audits

Who inspects personal data protection in Georgia?

Supervision in the field of data protection is exercised by the State Audit Service, and the decision to conduct an inspection is taken by the General Auditor. An inspection is possible both on the Service's own initiative and on the basis of an interested person's application.

How much time do you have to provide requested material?

Records-related information — immediately upon request, but no later than 3 working days. Other material — immediately, but no later than 10 working days where collection occurs in another unit or the volume is significant; on a reasoned request this may be extended by a further 10 working days.

What can happen when a violation is found?

The State Audit Service may demand remediation of deficiencies, temporary or permanent cessation of processing, blocking, deletion, destruction or depersonalisation of data, cessation of transfers, issue written advice or impose administrative liability. The decision is binding and appealable only in court.

What fines exist for obstruction?

Violating the information-submission procedure or providing false information entails a warning or a fine — up to 1 000 lari for smaller entities and up to 2 000 lari where turnover exceeds 500 000 lari; on repetition these rise to 3 000 and 5 000 lari. Obstruction of an inspection is fined from 2 000 to 4 000 lari, and on repetition from 4 000 to 6 000 lari.

4 min·...

About this service

A personal-data protection audit is the work that puts an organisation on its feet before an inspection arrives. In Georgia, supervision in the field of data protection is exercised by the State Audit Service — the supervisory authority designated by the current legislation, which may inspect you either on its own initiative or on the basis of an interested person's application, with the decision on conducting an inspection taken by the General Auditor. An inspection is no formality: its results may include an order to remedy violations, cessation of processing, blocking, deletion, destruction or depersonalisation of data, and administrative liability. This service is built on exactly that reality: we prepare your organisation by checking the same points the State Audit Service examines.

What the State Audit Service inspects

The law defines the content of an inspection precisely. An inspection comprises: establishing compliance with the principles of data processing and the existence of lawful grounds for processing; checking the conformity of the organisational and technical measures and procedures implemented for data security with the requirements established by legislation; checking the legality of transfers of data to another state or an international organisation; and checking compliance with the rules and requirements established by this and other normative acts for data protection. During an inspection the Service may demand a document or information from any institution, natural person or legal person — including information containing state, tax, banking, commercial or professional secrets — and may enter any institution and examine any document regardless of its content and storage form.

Deadlines for providing information

An inspection comes with strict deadlines. The records-related information on data processing must be provided to the State Audit Service immediately upon the corresponding request, but no later than 3 working days. And where the requested material must be collected in another institution or unit, or the information is of significant volume, the controller or processor must supply the material immediately, but no later than 10 working days; on the basis of a reasoned request this period may be extended by no more than 10 working days. In audit preparation we check precisely this: whether your organisation could assemble the documents within these deadlines, or whether the records are not arranged so that they can be produced promptly on request.

What records and security require

The subject of an inspection is also the documentary foundation the organisation must hold. Records of processing-related information must exist in written or electronic form and cover: the identity and contact details of the controller, its special representative and the data protection officer; the purposes of processing; information on categories of data subjects and data; categories of recipients; information on transfers to another state or international organisation and the appropriate safeguards, including the Service's permission where it exists; storage periods or the criteria for setting them; a general description of security measures; and information on incidents. On the security side, the law requires measures proportionate to the possible risks — including pseudonymisation, access logging, and confidentiality, integrity and availability mechanisms — together with periodic assessment of their effectiveness.

What measures the Service may apply

Where the State Audit Service detects a violation, it may apply one or several measures: demand that the violation and the related deficiencies be remedied in the form and within the period it indicates; demand temporary or permanent cessation of processing where the security measures do not meet the requirements; demand cessation of processing, blocking, deletion, destruction or depersonalisation of data where processing is carried out in violation of the law; demand cessation of transfers to another state or international organisation; issue written advice in the case of a minor violation; or impose administrative liability. The demands must be met within the set period and the Service notified thereof; persistent non-compliance leads the Service to apply to a court, a law-enforcement organ or the sector regulator. The Service's decision is binding and may be appealed only in court.

Fines for obstruction

The law imposes administrative liability for obstructing an inspection and for violating the procedure for providing information or providing false information. Violating the submission procedure or providing false information entails a warning or a fine: for persons whose annual turnover does not exceed 500 000 lari — 1 000 lari, and for legal persons whose turnover exceeds 500 000 lari — 2 000 lari. Repetition of the same act within one year raises the fine to 3 000 and 5 000 lari respectively. Any form of obstruction of the inspection is fined up to 2 000 lari, or up to 4 000 lari for large-turnover entities, and on repetition — up to 4 000 and 6 000 lari respectively. That is the price a single mistake can cost an unprepared organisation.

How we can help

Our audit aims to have all of the above balanced before an inspection begins: we review the principles and grounds of processing, security measures and international transfers; we assess the completeness of your records and the speed with which they can be produced; we identify deficiencies and give you a remediation plan with exact deadlines. If an inspection is already under way, we help prepare and deliver the materials within the deadlines and respond correctly to the Service's demands. Contact us for a concrete assessment of where your organisation stands in relation to a possible inspection.

Updated: ...

Legal basis:

  • პერსონალურ მონაცემთა დაცვის შესახებ

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer