Compliance Node Overview
Georgia's Law on Personal Data Protection (საქართველოს კანონი პერსონალური მონაცემების დაცვის შესახებ) - adopted by the Parliament of Georgia on 28 December 2011 and entering into force on 1 May 2012, subsequently amended multiple times most significantly in 2023 and 2024 to align with the European Union General Data Protection Regulation (GDPR) as part of Georgia's EU accession preparations - is Georgia's primary personal data protection legislation establishing a rights-based framework for the protection of personal data in Georgia. Georgia received EU candidate status in December 2023, and the progressive GDPR alignment of the Law reflects this EU integration trajectory under the EU-Georgia Association Agreement (in force since 2016). The supervisory authority is the Personal Data Protection Inspector (Პერსონალური მონაცემების დაცვის ინსპექტორი - PDPI), an independent institution established under the Law, whose mandate has expanded progressively to align with GDPR supervisory authority powers. Key features of Georgia's Law on Personal Data Protection: (1) Scope - applies to personal data processing by public institutions and private persons in Georgia; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation (proportionality); accuracy; storage limitation; security; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political views; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; and biometric data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to object; and right to complain to the PDPI; (6) Data processor oversight - controllers must implement written agreements with processors; (7) Breach notification - controllers must notify the PDPI of significant personal data security incidents; (8) Cross-border transfers - personal data transfers to third countries require adequate protection or approved safeguards; (9) PDPI enforcement - investigates complaints; conducts inspections; issues binding orders; initiates administrative proceedings; (10) EU alignment - amendments through 2023-2024 introduced GDPR-equivalent provisions including enhanced data subject rights, DPO obligations, DPIA requirements, and strengthened breach notification consistent with Georgia's EU candidacy obligations. Georgia's Constitution (Конституция) guarantees the right to privacy providing the constitutional basis for the Law.
Pillar: Cybersecurity · Authority: Personal Data Protection Inspector (PDPI, Georgia) · Version: 1.0.0 · Last updated:
Primary source: https://www.pdp.ge/
SHA-256 integrity: a2e696d0bdfbce0815fdfe0a478432eab926bcb94a1d0c56167cd1da9bce209a
Primary Citations — 7 traced to source
- Law on Personal Data Protection (Georgia) - adopted 28 December 2011; in force 1 May 2012; amended through 2023-2024 to align with GDPR as part of EU accession preparations; processing principles: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, security, accountability; sensitive personal data: racial/ethnic origin, political views, religious beliefs, trade union membership, health, sexual orientation, criminal convictions, biometric; data subject rights: access, rectification, erasure, objection; breach notification; cross-border transfer restrictions; DPO and DPIA requirements introduced through GDPR-aligned amendments
- Personal Data Protection Inspector (PDPI, Georgia) - independent supervisory authority established under the Law on Personal Data Protection; conducts inspections; investigates complaints; issues binding orders; initiates administrative proceedings; imposes sanctions; publishes guidance on Law compliance; PDPI has progressively strengthened its supervisory capacity in line with Georgia's EU accession objectives; pdp.ge is the official PDPI portal for notifications, guidance, and compliance resources
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.