What Is Law of Georgia on Personal Data Protection?
Georgia’s operative privacy statute is the Law of Georgia on Personal Data Protection, Law No. 3144, enacted on 14 June 2023. Core provisions took effect on 1 March 2024, while Articles 31, 33, 80, and 82 took effect on 1 June 2024. The current consolidated version shows eight amendments through 10 June 2026. On 2 March 2026, the State Audit Office of Georgia became the successor authority responsible for monitoring lawfulness, reviewing applications, conducting inspections, and imposing administrative penalties. The former Personal Data Protection Service handles only educational activities. This authority transition is a material currentness issue for any public-facing explanation. The law provides concrete rights-request and supervisory-review deadlines, including mostly 10-working-day controller responses and a two-month State Audit Office review period extendable by one month. Not located was a Georgia-specific data-broker route; the general rights and complaint mechanisms are the identified tools.
At a glance
- Full name
- Law of Georgia on Personal Data Protection
- Short code
- Law No. 3144
- Jurisdiction
- Georgia
- Enacted
- 2023
- Last major update
- The current consolidated version shows eight amendments through 10 June 2026; the State Audit Office became the successor supervisory authority on 2 March 2026
- Regulator
- State Audit Office of Georgia
- Private right of action
- Limited
- Statutory citation
- Law of Georgia on Personal Data Protection, Law No. 3144
Scope, who Law No. 3144 covers
Protected data
Data subject rights
Right to information and confirmation, generally within 10 working days with a possible 10-working-day extension
Right of access and to receive copies, generally within 10 working days with a possible 10-working-day extension
Right to rectification and updating within 10 working days
Right to termination, erasure, or destruction of processing within 10 working days
Right to blocking, with a decision or refusal notice no later than three working days
Right to data portability for consent- or contract-based automated processing
Protection against specified automated decisions and profiling
Right to object to direct marketing, no later than seven working days
For publicly available data, right to request restricted access, copy deletion, or internet-link removal
Right to appeal to the State Audit Office, a court, and/or a superior administrative body
Notable features
The law uses a processing-activity and Georgian-technical-means trigger rather than a GDPR-style offering or monitoring test. Foreign controllers using Georgian technical means generally must appoint and register a special representative in Georgia, subject to stated exemptions. The State Audit Office transition, mostly concrete 10-working-day rights deadlines, and two-month-plus-one-month supervisory review period are distinctive currentness points.
Enforcement & penalties
Regulator: State Audit Office of Georgia
Penalties: Penalties are fixed in GEL and vary by violation, offender type, annual turnover above or below GEL 500,000, and aggravating circumstances. Processing-principles and unlawful-processing violations range from GEL 1,000 to GEL 4,000; unlawful special-category processing from GEL 2,000 to GEL 5,000; direct-marketing violations from GEL 2,000 to GEL 6,000; data-subject-rights violations from GEL 1,000 to GEL 5,000; inadequate security from GEL 2,000 to GEL 5,000; unlawful international transfers from GEL 2,000 to GEL 6,000; incident-notification failures from GEL 2,000 to GEL 5,000 for regulator notification and GEL 3,000 to GEL 10,000 for subject notification. The multiple-offence cap is GEL 10,000 for the lower-turnover category or GEL 20,000 for the higher category, with specified mitigation reductions.
Private right of action: Article 22 provides appeal routes to the State Audit Office, a court, and/or a superior administrative body. An administrative-penalty decision may be appealed in court within one month after official notification. A general private damages action was not identified in the reviewed report.
Relevance to data brokers
Not located. The reviewed materials found no Georgia-specific data-broker route; the general access, rectification, termination, erasure, destruction, blocking, portability, objection, and complaint mechanisms are the only identified tools. For publicly available data, a person may request restricted access, copy deletion, or internet-link removal, subject to the statutory framework and exceptions.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Which authority currently supervises data protection in Georgia?+
On 2 March 2026, the State Audit Office of Georgia is the successor authority responsible for monitoring lawfulness, reviewing applications, conducting inspections, and imposing administrative penalties. The former Personal Data Protection Service handles only educational activities.
How quickly must a Georgian controller respond to an erasure request?+
Article 16 generally requires termination, erasure, or destruction within 10 working days. Refusal grounds include a continuing lawful basis, legal-claim necessity, expression or information necessity, or substantial impairment of archiving, research, or statistical purposes.
Does Georgia have a dedicated data-broker deletion route?+
Not located. The reviewed materials identify general rights and complaint mechanisms, plus specific requests concerning publicly available data such as restricted access, copy deletion, or internet-link removal.
Official sources & citations
Other international privacy regimes
Law No. 3144 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
