Skip to the content
Global Data RulesData governance rules, country by country

Georgia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Waking up

Georgia copied the European model in 2023: data can leave the country, but only to a destination the supervisor has approved, or with a permit, or under a narrow exception. There is no general rule forcing data to stay. The big change is who is in charge — on 2 March 2026 the independent privacy watchdog was replaced by the State Audit Office, and we could not verify that it has issued a single decision since.

Eight questions about Georgia

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Georgia's rules apply to my company?

Yes. The law catches a company with no office in Georgia if it uses technical means located in Georgia to handle people's data. There is no revenue or headcount threshold to duck under. Worse, a foreign company in that position must appoint a representative in Georgia and register that person with the supervisor BEFORE it starts processing — the only escape is being based in the European Union or in a country the European Union has already approved.

High confidenceNational rulesAppoint a local representativeRegister or notify

Can I store my users' data outside Georgia?

Yes, with paperwork. Data may go abroad if the destination country has been judged to give good enough protection, or if the supervisor grants a permit for the contract you have signed, or under a short list of narrow exceptions such as the person's written consent after being told the risks. Nothing in the general law forces data to stay in Georgia. The one place data really does stay is telecoms: a copy of who called whom, and when, sits in a state-run database inside the country.

High confidenceYes, with paperworkAllowlistOfficial 'this country is safe' decisionGovernment sign-off needed

What do I need in place before data leaves Georgia?

The model is an approved-destinations list, with a permit as the back-up. The supervisor decides which countries offer good enough protection and publishes that decision as a formal act; if your destination is not on it, you need a permit for your contract, or you fall back on a narrow exception such as written consent. We could not find the current published list, so we cannot tell you today which countries are on it — treat that as the single biggest open question in this record.

Medium confidenceAllowlistOfficial 'this country is safe' decisionGovernment sign-off neededExplicit consentSomeone's life is at riskImportant public interest

Who enforces the rules in Georgia, and what can they do?

This is where Georgia surprises people. Until 1 March 2026 the job belonged to the Personal Data Protection Service, an independent watchdog. From 2 March 2026 the law hands the same job to the State Audit Office — the body that audits government spending — and its head, the Auditor General, now signs the privacy rules. We can prove the handover happened, because the Auditor General reissued two of the privacy rulebooks at the end of March 2026. We could not find a single enforcement decision published since the handover.

Medium confidenceWaking up

How long do I have to keep the data?

The ceiling is clear: keep personal data only as long as you need it for the purpose you collected it for, then erase, destroy or strip out the identifying parts, unless another law tells you to keep it. The floors are scattered across tax, accounting and sector laws that we could not open on an official site today. In telecoms the direction is reversed — the content of a call or message must be destroyed at once, while the record of who contacted whom can be copied into a state database and kept for a period set by a separate law.

Medium confidenceDelete data after a periodKeep data for a minimum period

What happens if there is a breach?

Two clocks. If personal data is lost, leaked or wrongly handled, you have 72 hours from spotting it to tell the supervisor, and you must keep your own record of the incident and what you did about it. If you run a system the government has listed as critical to the country, you must tell the national computer emergency response team immediately — no fixed number of hours, which in practice means the same day. If both apply to you, both run at once.

High confidenceReport breaches to the regulatorReport cyber incidentsSecure the data

What trips people up in Georgia?

Five. First, the regulator changed identity on 2 March 2026, so a privacy notice or contract naming the Personal Data Protection Service now points at a body the law no longer mentions. Second, a foreign company must register a representative in Georgia before it starts, not after. Third, a child is anyone under 16, so a European sign-up flow tuned to 13 will be wrong here. Fourth, direct marketing always needs consent, even if you bought the list lawfully. Fifth, the same State Audit Office that now polices privacy also runs the public register of foreign-funded organisations, which must publish detailed information about themselves.

Medium confidenceAppoint a local representativeAppoint a data protection officerGet a parent's consent for childrenGet consentRegister or notify

What is changing soon in Georgia?

Nothing new is scheduled to start in the privacy law itself — we checked the current text on 18 August 2026 and found no provisions waiting on a future date. The live story is the handover: the Auditor General is reissuing the four rulebooks inherited from the old watchdog, and two of the four were reissued in March 2026. The rest of the risk sits in switches the government can already flip without a new law.

Medium confidenceIn force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    5 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    2 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules5 rules

საქართველოს კანონი პერსონალურ მონაცემთა დაცვის შესახებ

Act of parliament · No 3144-XIms-Xmp, published 3 July 2023, consolidated text of 10 June 2026

In forceYes, with paperwork

Georgia's general privacy law, closely modelled on the European Union's rules. Data may leave the country to an approved destination, under a permit, or by a narrow exception. It reaches foreign companies that use technical means in Georgia, and makes them register a local representative before they start.

In force since 1 March 2024

Enforced by State Audit Office of Georgia

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Someone's life is at risk, Important public interest, Legal claims

High confidence

საქართველოს 2025 წლის 17 დეკემბრის კანონი №1289 (ცვლილება პერსონალურ მონაცემთა დაცვის შესახებ კანონში)

Act of parliament · Law of Georgia No 1289 of 17 December 2025, published 23 December 2025

In forceYes, with paperwork

From 2 March 2026 the law's references to the independent Personal Data Protection Service are replaced by the State Audit Office of Georgia, and the Auditor General now issues the privacy rulebooks. Every duty stayed the same; the body you owe it to changed.

In force since 2 March 2026

Enforced by State Audit Office of Georgia

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed

Medium confidence

ბრძანება №20 — სპეციალური წარმომადგენლის რეგისტრაციის წესი

Government rules · Order No 20 of 28 February 2024, amended by Order No 004 of the Auditor General published 31 March 2026

In forceYes, with paperwork

The procedure a foreign company must follow to put a representative on the Georgian register before it processes data using technical means in Georgia. Companies established in the European Union, or in a country the European Union has approved, are exempt.

In force since 1 March 2024But only enforceable from 1 April 2024

Enforced by State Audit Office of Georgia

Transfer model: Allowlist

High confidence

Industry rules2 rules

საქართველოს კანონი ელექტრონული კომუნიკაციების შესახებ

Act of parliament · Law of Georgia on Electronic Communications, No 1514, Articles 8, 8-2 and 8-3 · Telecoms

In forceA copy must stay

Telecoms data is the one place Georgia keeps a state copy at home. What was said must be destroyed at once, but the record of who contacted whom can be copied by the state into a central database inside Georgia, and every hand-over to a state body has to be logged.

In force since 6 June 2005

Enforced by Georgian National Communications Commission

Transfer model: Approval each time

Medium confidence

საქართველოს კანონი ინფორმაციული უსაფრთხოების შესახებ

Act of parliament · Law of Georgia on Information Security, No 6391-Is; last amended by Law No 803-IIms-XImp of 26 June 2025 · Government

In forceYes — store it anywhere

Applies to organisations the government has listed as critical to national defence or economic security, including private companies. It demands a security policy, a named security manager, audits and immediate incident reporting — but says nothing about where systems or data must sit.

In force since 1 July 2012

Enforced by Digital Governance Agency

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • სახელმწიფო აუდიტის სამსახური

    Data protection supervision since 2 March 2026; also public-sector audit and the foreign agents register

    Rule-making is demonstrably live: the Auditor General issued Orders No 004 and No 005 on 30-31 March 2026 amending the inherited data protection rulebooks. No published data protection decision, fine or inspection result could be found on an official domain as at 18 August 2026, and the site shows no dedicated data protection section. Treat enforcement as unproven rather than absent.

  • პერსონალურ მონაცემთა დაცვის სამსახური

    Former independent data protection authority, named in the law until 1 March 2026

    The law's references to this Service were replaced by the State Audit Office with effect from 2 March 2026, and its 2024 orders are now being amended by the Auditor General. Its website was still reachable on 18 August 2026 but the content we could retrieve carried no dates, so we cannot say what, if anything, the body still does.

  • ციფრული მმართველობის სააგენტო

    Information security standards for critical systems, national computer emergency response team, government cloud and data centre

    Successor to the Data Exchange Agency, which is still the name used in the text of the Information Security Law.

  • საქართველოს კომუნიკაციების ეროვნული კომისია

    Electronic communications and media regulation

  • საქართველოს ეროვნული ბანკი

    Banking, payments, insurance and securities supervision

    Publishes its legal acts through a database that our tooling could not read on 18 August 2026, so any banking storage rule may have been missed.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Which countries are currently on Georgia's list of destinations with adequate safeguards

    The law requires the supervisor to publish the list as a normative act, but we could not locate any published list on an official Georgian domain during this run. The Legislative Herald's search box ignores the query, and the supervisor's website did not return machine-readable pages. Until this is found, treat every transfer as needing a permit or a derogation.

  • Whether the State Audit Office has issued any data protection decision, fine or inspection result since taking over on 2 March 2026

    No decisions register was locatable. Rule-making activity is proven; enforcement activity is not. This is why enforcement is rated waking rather than active or dormant.

  • The exact fate of the Personal Data Protection Service as an institution, and the fine levels in the privacy law

    The Legislative Herald truncates long documents when fetched, so the final chapters of the law — the supervisory body's status, its powers and the penalty amounts in Georgian lari — could not be read. The Georgian text truncates even earlier than the English.

  • Any data storage or outsourcing rule for banks, payment providers, insurers or securities firms

    The National Bank of Georgia's legal acts are served from a database our tooling could not query. No rule found as at 18 August 2026, but absence of evidence here is weak evidence of absence.

  • How long telecoms identification data is kept in the state-held central database

    The Law on Electronic Communications delegates the period to Article 15(1) of the Law on the Operative and Technical Agency, which we could not open on an official domain during this run.

  • Whether any health, education, gaming, mapping or defence rule imposes data localisation

    Nothing found, checked 18 August 2026. Coverage of these sectors relied on the general statutes we could open rather than on a sector-by-sector regulator sweep, because search on the official gazette is unusable.

  • That the English text on the Legislative Herald accurately reflects the Georgian original in naming the State Audit Office

    We confirmed the substitution by comparing the 2023 original with the December 2025 version and by two 2026 orders signed by the Auditor General, which makes a translation glitch very unlikely. But we could not read the Georgian text of the relevant articles directly, because the Georgian page truncates at Article 14.

30-day cadence. Georgia's supervisory authority changed hands five months ago and its inherited rulebooks are being reissued one by one; the approved-destinations list is unlocated and can be rewritten by the Auditor General alone. A record asserting a stable picture here would go wrong quickly.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.