What a privacy impact assessment is under Georgian law
A privacy impact assessment is a systematic analysis that determines what effect a planned or ongoing processing of data has on the rights and freedoms of data subjects and which technical or organisational measures are needed to manage the risks. It is important to understand that in Georgia there is no separate statute bearing this specific name: the assessment duty and its methodology rest on the Georgian Law on Personal Data Protection, above all on its Articles 4, 26, 27 and 31. This page explains, on the basis of exactly those provisions, how an organisation should build a risk-oriented approach to protecting confidentiality.
International terminology often refers to this process by the name of the European model, yet in the Georgian legal context the decisive norms are those of the Georgian law: the European regulation is only a comparative framework towards which the Georgian law is oriented. Accordingly, any internal document — whether a confidentiality assessment report or a risk register — must be tied to the precise articles of this law and not to foreign standards alone.
Processing principles as the measuring framework of the assessment
The starting point of the assessment is the set of processing principles defined in Article 4 of the law. Under its first paragraph, data must be processed lawfully, fairly, transparently for the data subject and without violating his or her dignity. Data are collected only for specific, clearly defined and legitimate purposes, and further processing incompatible with the original purpose is inadmissible. The same paragraph establishes the requirement to process only the necessary volume of data and to keep it proportionate to the purpose, the requirement of authenticity, accuracy and, where necessary, updating, the limitation of storage periods, and the security principle, under which technical and organisational measures must be taken that adequately ensure protection against unauthorised or unlawful processing, accidental loss, destruction or damage.
The seventh paragraph of Article 4 creates the foundation of the assessment's accountability: the controller is responsible for compliance with these principles and must be able to substantiate that compliance. This means that the assessment is not merely desirable practice — it is the instrument for substantiating compliance with the principles, without which an organisation struggles to demonstrate lawfulness.
The second paragraph of Article 4 deserves separate mention, as it establishes a compatibility test for processing for a different purpose: the controller must consider whether there is a connection between the original and the further purpose; the character of the relationship between the controller and the data subject at the time of collection; whether the subject has a reasonable expectation of further processing; whether special-category data are being processed; the possible consequences; and the existence of security measures. These six factors are precisely the questions that a privacy impact assessment must answer.
Privacy by design and by default
Article 26 of the law constitutes the engineering dimension of the assessment. Under its first paragraph, taking into account new technologies, the costs of implementation, the nature, scale, context and purposes of processing, as well as the risks expected for the rights and freedoms of data subjects, the controller must adopt appropriate technical and organisational measures both when determining the means of processing and directly in the processing itself, including pseudonymisation. The adoption of these measures must ensure the effective implementation of the processing principles and the integration of protection mechanisms into the processing operation.
The second paragraph governs protection by default: when determining the quantity of data, the scale of processing, retention periods and access to data, measures must be adopted so that only the volume of data necessary for the specific purpose is processed automatically. The measures must be applied in such a way that, before an alternative approach is chosen, an indefinite circle of persons is automatically granted access only to the minimal volume of data. A privacy impact assessment checks compliance with precisely these requirements each time a new product or service is created.
Security measures and the logging of actions
Article 27 forms the technical block of the assessment. Under its first paragraph, the controller is obliged to adopt appropriate technical and organisational measures to ensure processing in accordance with the law and to be able to confirm that compliance. The second paragraph requires correspondence to the possible and accompanying risks of processing: measures — including pseudonymisation of data, logging of access to data and information-security mechanisms of confidentiality, integrity and availability — must ensure protection against loss of data and unlawful processing, including destruction, deletion, alteration, disclosure or use.
The third paragraph requires that, when determining the measures, the categories and volume of data, the purpose, form and means of processing, and the possible risks of violating the rights of the subject be taken into account, and that the effectiveness of the adopted measures be periodically assessed. The fourth paragraph establishes logging: every action performed on data in electronic form — information on incidents, collection, alteration, access, disclosure, combination and deletion — must be recorded, while for non-electronic data all actions connected with disclosure or alteration are recorded.
The human dimension matters as well. Under the fifth paragraph, every employee who participates in processing or has access to data is obliged not to exceed the limits of the authority granted, to protect the secrecy and confidentiality of the data, including after the termination of official authority. The sixth paragraph obliges the organisation to define the scope of access according to employees' powers and to take measures to prevent, detect and suppress facts of unlawful processing by employees.
When the assessment turns into a mandatory formal document
General assessment practice converts into a mandatory form when the risk is high. Under the first paragraph of Article 31 of the law, where, in the course of processing, taking into account new technologies, the category of data, the volume, the purposes and the means of processing, there is a high probability of a risk of violation of human fundamental rights and freedoms, the controller is obliged to carry out in advance a data protection impact assessment. In addition, the assessment is unconditionally mandatory in three situations: for fully automated decisions, including those based on profiling; for processing special categories of data of a large number of subjects; and for systematic and large-scale monitoring in public gathering places. A large number means not less than 3 percent of the population of Georgia, calculated according to the final results of the census.
At this level the assessment takes the form of a written document containing a description of the data category, the purposes of processing, proportionality, the process and the grounds, as well as an assessment of the possible risks and a description of the organisational and technical security measures. The document is updated upon a substantial change in the processing process and is kept throughout the entire period of processing, and upon cessation of processing for at least 1 year. If the risk cannot be substantially reduced through additional measures, the data must not be processed, and where necessary the State Audit Office is consulted.
How to build the assessment process in an organisation
The practical sequence is as follows. At the first stage, existing and planned processing operations are described: categories of data, purposes, grounds and means. At the second stage, each operation is checked against the principles of Article 4 — lawfulness, purpose limitation, volume minimisation, accuracy, storage limitation and security. At the third stage, the means of pseudonymisation and minimisation are determined according to the design logic established by Article 26. At the fourth stage, the logging and access management required by Article 27 are verified. Finally, where the risk is high, the process culminates in the duty established by Article 31.
The Legal.ge team will help you solve the privacy impact assessment task: from describing processing operations and identifying risks to selecting measures and preparing documentation, so that your organisation's approach rests on the precise requirements of Georgian legislation and not merely on international practice.
