Georgia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Georgia copied the European model in 2023: data can leave the country, but only to a destination the supervisor has approved, or with a permit, or under a narrow exception. There is no general rule forcing data to stay. The big change is who is in charge — on 2 March 2026 the independent privacy watchdog was replaced by the State Audit Office, and we could not verify that it has issued a single decision since.
Eight questions about Georgia
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Georgia's rules apply to my company?
Yes. The law catches a company with no office in Georgia if it uses technical means located in Georgia to handle people's data. There is no revenue or headcount threshold to duck under. Worse, a foreign company in that position must appoint a representative in Georgia and register that person with the supervisor BEFORE it starts processing — the only escape is being based in the European Union or in a country the European Union has already approved.
Article 2 applies the Law to processing carried out wholly or partly by automated means within Georgia, and to a controller not established in Georgia that uses technical means available in Georgia. Article 34 requires such a controller or processor to appoint or designate a special representative in Georgia before processing begins; the obligation does not apply to entities founded in EU member states or in states recognised by the EU as providing adequate protection. Order No 20 of 28 February 2024 sets the registration procedure: identity and corporate documents, the written appointment agreement, and a description of the technical means used, verified within 10 working days, with a further 5 or 10 working days for corrections. Controllers that already had a representative when the Law started had until 1 April 2024 to register. That order was amended by Order No 004 of the Auditor General of the State Audit Service, published 31 March 2026.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, No 3144-XIms-Xmp, Articles 2 and 34 (consolidated text of 10 June 2026)
matsne.gov.ge
“the controller/processor is obliged to appoint or designate a special representative in Georgia before data processing”
Link checked 18 August 2026
- Official sourcePersonal Data Protection Service of Georgia, via Legislative HeraldOrder No 20 of 28 February 2024 on the Approval of the Procedure for Registering a Special Representative
matsne.gov.ge
Link checked 18 August 2026
Can I store my users' data outside Georgia?
Yes, with paperwork. Data may go abroad if the destination country has been judged to give good enough protection, or if the supervisor grants a permit for the contract you have signed, or under a short list of narrow exceptions such as the person's written consent after being told the risks. Nothing in the general law forces data to stay in Georgia. The one place data really does stay is telecoms: a copy of who called whom, and when, sits in a state-run database inside the country.
Article 37(1) allows transfer where the Law's processing requirements and appropriate safeguards in the destination are in place. Article 37(2) adds alternatives: an international treaty, an agreement between controllers containing appropriate safeguards together with a permit from the supervisory body, criminal-procedure grounds, the written consent of the person after disclosure of the risks, vital interests, and a narrow proportionate public-interest ground. Article 38 makes the supervisory body assess adequacy of a state or international organisation and set it out in a normative act, reviewed at least once every three years. Sector by sector as checked on 18 August 2026: banking, payments, insurance and securities — no localisation rule found in the National Bank of Georgia's published acts, though its acts portal is not machine-readable and this is recorded as unconfirmed; health — no localisation rule found, but medical institutions are on the list of bodies that must appoint a data protection officer; telecom — content of communications must be destroyed immediately, while connection identification data may be copied by the state into a central database held in Georgia; government and critical infrastructure — the Information Security Law imposes security duties but no storage location; education, gaming, mapping and defence — no localisation rule found.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, Articles 37 and 38 (transfer to another state and assessment of adequate safeguards)
matsne.gov.ge
“The transfer of data to another state and international organisation shall be allowed if the requirements for data processing provided for by this Law and appropriate safeguards in the relevant state or international organisation are in place for ensuring data protection and the protection of data subjects' rights.”
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Electronic Communications, No 1514, Articles 8 and 8-3
matsne.gov.ge
“copy the databases of the electronic communication identification data and store them at the central bank of the electronic communication identification data”
Link checked 18 August 2026
- Official sourceNational Bank of GeorgiaNational Bank of Georgia — Legal Acts portal (checked for banking, payments and IT rules on 18 August 2026)
nbg.gov.ge
Link checked 18 August 2026
What do I need in place before data leaves Georgia?
The model is an approved-destinations list, with a permit as the back-up. The supervisor decides which countries offer good enough protection and publishes that decision as a formal act; if your destination is not on it, you need a permit for your contract, or you fall back on a narrow exception such as written consent. We could not find the current published list, so we cannot tell you today which countries are on it — treat that as the single biggest open question in this record.
Article 38(1) requires the supervisory body to assess adequacy by looking at the destination's international obligations, its data protection legislation, the guarantees for people's rights including effective remedies, its onward-transfer rules, and whether it has an independent supervisory authority. The list must be reviewed at least every three years and revised when a destination no longer qualifies. Since 2 March 2026 the assessing body named in the Law is the State Audit Office, and the normative act is issued by the Auditor General. No published adequacy list was locatable on an official Georgian domain during this run.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, Article 38 (assessment of adequate safeguards and the list of states)
matsne.gov.ge
“The existence of adequate safeguards for data protection in another state and/or international organisation shall be assessed by the State Audit Office on the basis of international obligations and regulatory legislation relating to data protection, guarantees for the protection of the rights and freedoms of data subjects (including effective legal protection mechanisms), rules for further international data transfer, and the analysis of the existence, powers and activities of an independent data protection supervisory body.”
Link checked 18 August 2026
Who enforces the rules in Georgia, and what can they do?
This is where Georgia surprises people. Until 1 March 2026 the job belonged to the Personal Data Protection Service, an independent watchdog. From 2 March 2026 the law hands the same job to the State Audit Office — the body that audits government spending — and its head, the Auditor General, now signs the privacy rules. We can prove the handover happened, because the Auditor General reissued two of the privacy rulebooks at the end of March 2026. We could not find a single enforcement decision published since the handover.
The text of the Law dated 17 December 2025 carries the substitution in brackets marked to take effect on 2 March 2026: every reference to the Personal Data Protection Service becomes the State Audit Office of Georgia. The original 2023 text named the Personal Data Protection Service in the same articles, which rules out a translation error. Corroboration comes from the subordinate rules: Order No 22 on data protection officers was amended by Order No 005 of the Auditor General of the State Audit Service on 30 March 2026, and Order No 20 on registering foreign companies' representatives by Order No 004, both published 31 March 2026. Rating: waking, not active — the rule-making machine is running, but no published decisions, fines or inspection results from the new supervisor could be verified on an official domain during this run. Sector regulators are separately operational: the National Bank of Georgia, the Georgian National Communications Commission and the Digital Governance Agency, which runs the national computer emergency response team.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, version of 17 December 2025 (Law No 1289) showing the substitution of the State Audit Office with effect from 2 March 2026
matsne.gov.ge
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, original text published 3 July 2023, Articles 29 and 38 naming the Personal Data Protection Service
matsne.gov.ge
“A controller is obliged to register an incident, its resulting outcome, the measures taken, and to notify the Personal Data Protection Service about the incident, not later than 72 hours after the identification of the incident”
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaOrder No 22 of 28 February 2024 on data protection officers, as amended by Order No 005 of the Auditor General of the State Audit Service, 30 March 2026
matsne.gov.ge
Link checked 18 August 2026
- Official sourceState Audit Office of GeorgiaState Audit Office of Georgia — official site (no data protection section visible on 18 August 2026)
sao.ge
Link checked 18 August 2026
How long do I have to keep the data?
The ceiling is clear: keep personal data only as long as you need it for the purpose you collected it for, then erase, destroy or strip out the identifying parts, unless another law tells you to keep it. The floors are scattered across tax, accounting and sector laws that we could not open on an official site today. In telecoms the direction is reversed — the content of a call or message must be destroyed at once, while the record of who contacted whom can be copied into a state database and kept for a period set by a separate law.
Article 4(1)(e) of the Law on Personal Data Protection sets the ceiling: data may be stored only for the period necessary to achieve the legitimate purpose, and must then be erased, destroyed or de-identified unless retention is required by law. Article 8(5) of the Law on Electronic Communications requires that the content of a user's communication be immediately and automatically destroyed. Article 8-3 of the same law lets the authorised body copy the databases of electronic communication identification data into a central bank of that data; the retention period is fixed by Article 15(1) of the Law on the Legal Entity under Public Law called Operative and Technical Agency of Georgia, which we could not open during this run. Where a specific retention law conflicts with the general delete-when-done duty, the specific law wins, because Article 4 expressly carves out retention required by legislation.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, Article 4(1)(e) (storage limitation)
matsne.gov.ge
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Electronic Communications, Article 8(5) and Article 8-3
matsne.gov.ge
“Information on the content of the communication made by a user via an electronic communication network shall be immediately and automatically destroyed.”
Link checked 18 August 2026
What happens if there is a breach?
Two clocks. If personal data is lost, leaked or wrongly handled, you have 72 hours from spotting it to tell the supervisor, and you must keep your own record of the incident and what you did about it. If you run a system the government has listed as critical to the country, you must tell the national computer emergency response team immediately — no fixed number of hours, which in practice means the same day. If both apply to you, both run at once.
Article 29(1) of the Law on Personal Data Protection sets the 72-hour clock and requires the incident, its consequences and the measures taken to be registered. There is a carve-out where it is least expected that the incident would cause significant damage or a significant threat to fundamental rights. Order No 19 of 28 February 2024, in force from 1 March 2024, sets out how to judge that: it looks at the type of data, whether children or disabled people are affected, how easily people can be identified, and the scale, and it requires notification where the likelihood of significant damage is medium or high. Staged reporting is allowed where a full assessment is impossible within 72 hours. A processor must tell its controller immediately. Separately, Article 10 of the Law on Information Security requires that the national computer emergency response team be notified immediately of an identified computer incident and that evidence be preserved.
Sources
- Official sourcePersonal Data Protection Service of Georgia, via Legislative HeraldOrder No 19 of 28 February 2024 on criteria for incidents posing a significant threat and the procedure for notifying the supervisory body
matsne.gov.ge
“A controller shall be obliged to notify the Service of an incident within 72 hours after its detection”
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Information Security, No 6391-Is, Article 10 (notification of computer incidents)
matsne.gov.ge
“CERT shall be immediately notified of the identified computer incident”
Link checked 18 August 2026
What trips people up in Georgia?
Five. First, the regulator changed identity on 2 March 2026, so a privacy notice or contract naming the Personal Data Protection Service now points at a body the law no longer mentions. Second, a foreign company must register a representative in Georgia before it starts, not after. Third, a child is anyone under 16, so a European sign-up flow tuned to 13 will be wrong here. Fourth, direct marketing always needs consent, even if you bought the list lawfully. Fifth, the same State Audit Office that now polices privacy also runs the public register of foreign-funded organisations, which must publish detailed information about themselves.
1) The English text of the Law on the government's own site now reads 'State Audit Office' in the articles on breach notification and international transfer, where the 2023 original read 'Personal Data Protection Service'. Anyone comparing an old summary with the current text will think they are reading two different laws. 2) Article 34 and Order No 20: registration first, processing second; the exemption covers only EU-established entities and entities in EU-recognised adequate countries. 3) Article 7(1): a person aged 16 or over may consent for themselves; under 16 needs a parent or guardian, unless a specific law says otherwise. 4) Article 12(1): data may be processed for direct marketing only with the person's consent, irrespective of how the data was originally collected. 5) Under the Foreign Agents Registration Act, in force 31 May 2025, persons acting for a foreign principal must file identity, address, employment, contract, funding and spending details within 10 days and update every six months, and the filings go into a publicly searchable, downloadable database; enforcement moved from the Anti-Corruption Bureau to the State Audit Office in March 2026. 6) A quieter one: banks, insurers, microfinance organisations, credit bureaus, telecoms companies, airlines, airports, medical institutions and all public bodies must appoint a data protection officer regardless of size.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, Articles 7, 12, 33 and 34
matsne.gov.ge
“Data may only be processed for direct marketing purposes with the consent of the data subject”
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaLaw of Georgia Foreign Agents Registration Act, No 399-IIms-XImp, 1 April 2025
matsne.gov.ge
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaOrder No 22 of 28 February 2024 — which controllers need not appoint a data protection officer
matsne.gov.ge
“3% of the population of Georgia”
Link checked 18 August 2026
What is changing soon in Georgia?
Nothing new is scheduled to start in the privacy law itself — we checked the current text on 18 August 2026 and found no provisions waiting on a future date. The live story is the handover: the Auditor General is reissuing the four rulebooks inherited from the old watchdog, and two of the four were reissued in March 2026. The rest of the risk sits in switches the government can already flip without a new law.
Dormant switches to watch. First, the list of approved destination countries: the supervisory body sets it by its own normative act, must review it at least every three years, and may revise it whenever a destination stops qualifying — a country can be removed with no consultation and no parliamentary step. Second, the permit route for transfers is discretionary, so the practical bar can be raised without changing the text. Third, the government approves the list of critical information system subjects by ordinance, so an ordinary private company can be pulled into the security regime overnight. Fourth, the two remaining 2024 orders, on data protection impact assessments and on incident notification, can be rewritten by the Auditor General alone. Also worth watching, but not a date: Georgia's supervisory authority is no longer a dedicated independent body, which is in tension with the independence expectations of the Council of Europe data protection convention and of European Union accession — any external assessment of Georgia's protection level could shift because of it.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, consolidated text of 10 June 2026 (checked for future-dated provisions)
matsne.gov.ge
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaOrder No 20 of 2024 as amended by Order No 004 of the Auditor General, published 31 March 2026
matsne.gov.ge
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
5 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
2 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules5 rules
საქართველოს კანონი პერსონალურ მონაცემთა დაცვის შესახებ
Act of parliament · No 3144-XIms-Xmp, published 3 July 2023, consolidated text of 10 June 2026
Georgia's general privacy law, closely modelled on the European Union's rules. Data may leave the country to an approved destination, under a permit, or by a narrow exception. It reaches foreign companies that use technical means in Georgia, and makes them register a local representative before they start.
Enforced by State Audit Office of Georgia
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Someone's life is at risk, Important public interest, Legal claims
What it makes you do
- Get consentAlways required for direct marketing, however the data was originally collected.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Secure the data
- Report breaches to the regulator — within 72 hoursFrom identification of the incident. Exempt only where significant damage is least expected.
- Delete data after a periodStore only as long as the purpose needs, then erase, destroy or de-identify, unless a law requires retention.
- Appoint a data protection officer — applies at: Public bodies, insurers, banks, microfinance organisations, credit bureaus, telecoms, airlines, airports, medical institutions, plus anyone processing data of a significant number of people or doing systematic large-scale monitoring
- Appoint a local representativeForeign controllers and processors using technical means in Georgia, unless established in the EU or an EU-adequate country.
- Register or notifyThe special representative must be registered with the supervisory body before processing starts.
- Assess high-risk projects
- Get a parent's consent for children — applies at: under 16
- Put a transfer safeguard in place
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection (consolidated text of 10 June 2026)
matsne.gov.ge
“The transfer of data to another state and international organisation shall be allowed if the requirements for data processing provided for by this Law and appropriate safeguards in the relevant state or international organisation are in place”
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaOriginal text as published 3 July 2023
matsne.gov.ge
Link checked 18 August 2026
საქართველოს 2025 წლის 17 დეკემბრის კანონი №1289 (ცვლილება პერსონალურ მონაცემთა დაცვის შესახებ კანონში)
Act of parliament · Law of Georgia No 1289 of 17 December 2025, published 23 December 2025
From 2 March 2026 the law's references to the independent Personal Data Protection Service are replaced by the State Audit Office of Georgia, and the Auditor General now issues the privacy rulebooks. Every duty stayed the same; the body you owe it to changed.
Enforced by State Audit Office of Georgia
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed
What it makes you do
- Report breaches to the regulator — within 72 hours, from 2 March 2026Same clock, different recipient: notifications now go to the State Audit Office.
Sources
- Official sourceLegislative Herald of GeorgiaLaw on Personal Data Protection, version of 17 December 2025, showing the substitution effective 2 March 2026
matsne.gov.ge
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaOrder No 22 of 2024 amended by Order No 005 of the Auditor General of the State Audit Service, 30 March 2026
matsne.gov.ge
Link checked 18 August 2026
ბრძანება №20 — სპეციალური წარმომადგენლის რეგისტრაციის წესი
Government rules · Order No 20 of 28 February 2024, amended by Order No 004 of the Auditor General published 31 March 2026
The procedure a foreign company must follow to put a representative on the Georgian register before it processes data using technical means in Georgia. Companies established in the European Union, or in a country the European Union has approved, are exempt.
Enforced by State Audit Office of Georgia
Transfer model: Allowlist
What it makes you do
- Appoint a local representativeAppointment must be in writing and evidenced by an agreement filed with the supervisor.
- Register or notify — from 1 April 2024Verification within 10 working days; corrections within 5 working days, extendable once. Companies that already had a representative had to register by 1 April 2024.
Sources
- Official sourceLegislative Herald of GeorgiaOrder No 20 of 28 February 2024 on the Approval of the Procedure for Registering a Special Representative
matsne.gov.ge
Link checked 18 August 2026
ბრძანება №19 — ინციდენტის შესახებ შეტყობინების წესი
Government rules · Order No 19 of 28 February 2024
Sets out when a data incident counts as serious enough to report and how to report it within 72 hours. Factors include the type of data, whether children or disabled people are affected, and how easily people can be identified.
Enforced by State Audit Office of Georgia
What it makes you do
- Report breaches to the regulator — within 72 hoursRequired where the likelihood of significant damage is medium or high. Staged reporting allowed if the assessment cannot be completed in time.
- Tell affected peopleWhere the incident is likely to cause significant damage to the person.
- Keep records of processingThe incident, its consequences and the measures taken must be registered internally.
Sources
- Official sourceLegislative Herald of GeorgiaOrder No 19 of 28 February 2024 on criteria for incidents posing a significant threat to fundamental rights
matsne.gov.ge
“A controller shall be obliged to notify the Service of an incident within 72 hours after its detection”
Link checked 18 August 2026
საქართველოს კანონი უცხოელი აგენტების რეგისტრაციის შესახებ
Act of parliament · Foreign Agents Registration Act, No 399-IIms-XImp, 1 April 2025; amended by Law No 1292 of 17 December 2025
Not a data protection law, but it moves personal and financial information into a public, searchable, downloadable government database. Anyone acting for a foreign government, party or organisation must register and keep filing. Enforcement moved to the State Audit Office in March 2026 — the same body that now supervises privacy.
Enforced by State Audit Office of Georgia
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notifyWithin 10 days of becoming an agent of a foreign principal; updates every six months.
- Keep records of processingIdentity, addresses, employment, the written agreement with the foreign principal, funding sources for the preceding 60 days and spending records.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia Foreign Agents Registration Act
matsne.gov.ge
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaOrder No 10 of 31 May 2025 on the Procedure for Administration and Enforcement of the Foreign Agents Registration Act
matsne.gov.ge
Industry rules2 rules
საქართველოს კანონი ელექტრონული კომუნიკაციების შესახებ
Act of parliament · Law of Georgia on Electronic Communications, No 1514, Articles 8, 8-2 and 8-3 · Telecoms
Telecoms data is the one place Georgia keeps a state copy at home. What was said must be destroyed at once, but the record of who contacted whom can be copied by the state into a central database inside Georgia, and every hand-over to a state body has to be logged.
Enforced by Georgian National Communications Commission
Transfer model: Approval each time
What it makes you do
- Keep the data in the countryNot a ban on foreign hosting. The authorised state agency may copy operators' identification-data databases into a central state-held database in Georgia.
- Delete data after a periodContent of communications must be immediately and automatically destroyed.
- Keep records of processingOperators must log every occasion on which identification data is handed to a state body and report it to the supervisory body named in the law.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Electronic Communications, Articles 8 and 8-3
matsne.gov.ge
“Information on the content of the communication made by a user via an electronic communication network shall be immediately and automatically destroyed.”
Link checked 18 August 2026
- Official sourceGeorgian National Communications CommissionGeorgian National Communications Commission — resolutions, including the 2010 rules on services and consumer rights protection in electronic communications
comcom.ge
Link checked 18 August 2026
საქართველოს კანონი ინფორმაციული უსაფრთხოების შესახებ
Act of parliament · Law of Georgia on Information Security, No 6391-Is; last amended by Law No 803-IIms-XImp of 26 June 2025 · Government
Applies to organisations the government has listed as critical to national defence or economic security, including private companies. It demands a security policy, a named security manager, audits and immediate incident reporting — but says nothing about where systems or data must sit.
Enforced by Digital Governance Agency
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidentsThe national computer emergency response team must be notified immediately of an identified computer incident, and evidence preserved.
- Secure the dataAn information security policy meeting recognised international standards must be adopted.
- Appoint a data protection officerA security manager, not a privacy officer: a named person responsible for day-to-day compliance.
- Independent auditCompatibility assessment against minimum information security standards.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Information Security, Articles 3, 4, 6, 7 and 10
matsne.gov.ge
“CERT shall be immediately notified of the identified computer incident”
Link checked 18 August 2026
- Official sourceDigital Governance Agency of GeorgiaDigital Governance Agency — national computer emergency response team, government cloud and data centre services
dga.gov.ge
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Which countries are currently on Georgia's list of destinations with adequate safeguards
The law requires the supervisor to publish the list as a normative act, but we could not locate any published list on an official Georgian domain during this run. The Legislative Herald's search box ignores the query, and the supervisor's website did not return machine-readable pages. Until this is found, treat every transfer as needing a permit or a derogation.
Whether the State Audit Office has issued any data protection decision, fine or inspection result since taking over on 2 March 2026
No decisions register was locatable. Rule-making activity is proven; enforcement activity is not. This is why enforcement is rated waking rather than active or dormant.
The exact fate of the Personal Data Protection Service as an institution, and the fine levels in the privacy law
The Legislative Herald truncates long documents when fetched, so the final chapters of the law — the supervisory body's status, its powers and the penalty amounts in Georgian lari — could not be read. The Georgian text truncates even earlier than the English.
Any data storage or outsourcing rule for banks, payment providers, insurers or securities firms
The National Bank of Georgia's legal acts are served from a database our tooling could not query. No rule found as at 18 August 2026, but absence of evidence here is weak evidence of absence.
How long telecoms identification data is kept in the state-held central database
The Law on Electronic Communications delegates the period to Article 15(1) of the Law on the Operative and Technical Agency, which we could not open on an official domain during this run.
Whether any health, education, gaming, mapping or defence rule imposes data localisation
Nothing found, checked 18 August 2026. Coverage of these sectors relied on the general statutes we could open rather than on a sector-by-sector regulator sweep, because search on the official gazette is unusable.
That the English text on the Legislative Herald accurately reflects the Georgian original in naming the State Audit Office
We confirmed the substitution by comparing the 2023 original with the December 2025 version and by two 2026 orders signed by the Auditor General, which makes a translation glitch very unlikely. But we could not read the Georgian text of the relevant articles directly, because the Georgian page truncates at Article 14.
30-day cadence. Georgia's supervisory authority changed hands five months ago and its inherited rulebooks are being reissued one by one; the approved-destinations list is unlocated and can be rewritten by the Auditor General alone. A record asserting a stable picture here would go wrong quickly.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Compare with
- Georgia versus Argentina
- Georgia versus Armenia
- Georgia versus Australia
- Georgia versus Austria
- Georgia versus Azerbaijan
- Georgia versus Brazil
- Georgia versus Bulgaria
- Georgia versus Cambodia
- Georgia versus Canada
- Georgia versus China
- Georgia versus Croatia
- Georgia versus Cyprus
- Georgia versus Estonia
- Georgia versus France
- Georgia versus Germany
- Georgia versus Greece
- Georgia versus Hong Kong SAR
- Georgia versus Hungary
- Georgia versus Iceland
- Georgia versus India
- Georgia versus Indonesia
- Georgia versus Ireland
- Georgia versus Israel
- Georgia versus Italy
- Georgia versus Japan
- Georgia versus Latvia
- Georgia versus Lithuania
- Georgia versus Luxembourg
- Georgia versus Malta
- Georgia versus Mexico
- Georgia versus Mongolia
- Georgia versus Nepal
- Georgia versus Netherlands
- Georgia versus Poland
- Georgia versus Russia
- Georgia versus Saudi Arabia
- Georgia versus Serbia
- Georgia versus Singapore
- Georgia versus Slovakia
- Georgia versus Slovenia
- Georgia versus South Korea
- Georgia versus Spain
- Georgia versus Sri Lanka
- Georgia versus Sweden
- Georgia versus Switzerland
- Georgia versus Taiwan
- Georgia versus Thailand
- Georgia versus Turkey
- Georgia versus Ukraine
- Georgia versus United Arab Emirates
- Georgia versus United Kingdom
- Georgia versus United States
- Georgia versus Uzbekistan