Skip to the content
Global Data RulesData governance rules, country by country

Georgia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Georgia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Waking up

Data can leave Georgia, but only in three ways. The destination country has been approved by the regulator. Or you get a permit. Or a narrow exception applies. Georgia copied the European model in 2023. No general rule forces data to stay in the country. The big change is who is in charge. On 2 March 2026 the independent privacy watchdog was replaced by the State Audit Office. We could not verify that it has issued a single decision since.

Data governance in Georgia

The eight things that decide how you handle data about people in Georgia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law catches a company with no office in Georgia if it uses equipment located in Georgia to handle people's data. There is no revenue or headcount limit to duck under. It gets worse. A foreign company in that position must appoint a representative in Georgia. It must register that person with the regulator before it starts handling data. The only escape is being based in the European Union, or in a country the European Union has already approved.

What you have to do here:
Appoint a representative · Register or notify

Where the data is allowed to live

Yes, with paperwork. Data may go abroad in three ways. The destination country has been judged to give good enough protection. Or the regulator grants a permit for the contract you have signed. Or a narrow exception applies, such as the person's written consent after being told the risks. Nothing in the general law forces data to stay in Georgia. The one place data really does stay is telecoms. A copy of who called whom, and when, sits in a state-run database inside the country.

Ways to send data out:
Official 'this country is safe' decision · Government sign-off needed

What to do: Get the paperwork for one of the routes below signed before any data leaves Georgia.

Sending data out of the country

You can only send data to countries the regulator has approved. A permit is the back-up route. The regulator decides which countries offer good enough protection and publishes that decision as a formal act. If your destination is not on the list, you need a permit for your contract. Or you fall back on a narrow exception such as written consent. We could not find the current published list. So we cannot tell you today which countries are on it. Treat that as the single biggest open question in this record.

Ways to send data out:
Official 'this country is safe' decision · Government sign-off needed · Explicit consent · To save someone’s life · Important public interest

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

This is where Georgia surprises people. Until 1 March 2026 the job belonged to the Personal Data Protection Service, an independent watchdog. From 2 March 2026 the law hands the same job to the State Audit Office. That is the body that audits government spending. Its head, the Auditor General, now signs the privacy rules. We can prove the handover happened. The Auditor General reissued two of the privacy rulebooks at the end of March 2026. We could not find a single enforcement decision published since the handover.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

The maximum is clear. Keep personal data only as long as you need it for the purpose you collected it for. Then erase it, destroy it, or strip out the identifying parts. That is unless another law tells you to keep it. The minimum keeping times are scattered across tax, accounting and industry laws that we could not open on an official site today. In telecoms the direction is reversed. The content of a call or message must be destroyed at once. The record of who contacted whom can be copied into a state database. It is then kept for a period set by a separate law.

What you have to do here:
Delete data after a period · Keep data for a minimum period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There are two clocks. If personal data is lost, leaked or wrongly handled, you have 72 hours from spotting it to tell the regulator. You must also keep your own record of the incident and what you did about it. If you run a system the government has listed as critical to the country, you must tell the national computer emergency response team immediately. There is no fixed number of hours, which means the same day. If both apply to you, both run at once.

What you have to do here:
Report breaches to the regulator · Report cyber incidents · Secure the data

What to do: Your breach process has to reach Georgia's regulator inside the deadline above.

What catches people out

Five things. First, the regulator changed identity on 2 March 2026. A privacy notice or contract naming the Personal Data Protection Service now points at a body the law no longer mentions. Second, a foreign company must register a representative in Georgia before it starts, not after. Third, a child is anyone under 16. A European sign-up flow tuned to 13 will be wrong here. Fourth, direct marketing always needs consent, even if you bought the list lawfully. Fifth, the same State Audit Office that now polices privacy also runs the public register of foreign-funded organisations. Those organisations must publish detailed information about themselves.

What you have to do here:
Appoint a representative · Appoint a data protection officer · Get a parent's consent for children · Get consent · Register or notify
Not fully verified — see “What we're not sure about” below.

What's changing next

Nothing new is scheduled to start in the privacy law itself. We checked the current text on 18 August 2026 and found no parts waiting on a future date. The live story is the handover. The Auditor General is reissuing the four rulebooks inherited from the old watchdog. Two of the four were reissued in March 2026. The rest of the risk sits in things the government can already change without a new law.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms data needs a copy kept in the country

Official name: საქართველოს კანონი ელექტრონული კომუნიკაციების შესახებ · Law of Georgia on Electronic Communications, No 1514, Articles 8, 8-2 and 8-3 · Act of parliament

In forceA copy must stay

Telecoms data is the one place Georgia keeps a state copy at home. What was said must be destroyed at once. But the record of who contacted whom can be copied by the state into a central database inside Georgia. Every hand-over to a state body has to be logged.

In force since 6 June 2005

Enforced by Georgian National Communications Commission

How this country controls where data goes: Approval each time

Not fully verified — see “What we're not sure about” below.
Government

Breach reporting rules

Official name: საქართველოს კანონი ინფორმაციული უსაფრთხოების შესახებ · Law of Georgia on Information Security, No 6391-Is; last amended by Law No 803-IIms-XImp of 26 June 2025 · Act of parliament

In forceYes — store it anywhere

This applies to organisations the government has listed as critical to national defence or economic security. That includes private companies. It demands a security policy, a named security manager, audits and immediate incident reporting. It says nothing about where systems or data must sit.

In force since 1 July 2012

Enforced by Digital Governance Agency

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: საქართველოს კანონი პერსონალურ მონაცემთა დაცვის შესახებ · No 3144-XIms-Xmp, published 3 July 2023, consolidated text of 10 June 2026 · Act of parliament

In forceYes, with paperwork

This is Georgia's general privacy law, closely modelled on the European Union's rules. Data may leave the country to an approved destination, under a permit, or by a narrow exception. It reaches foreign companies that use equipment in Georgia. It makes them register a local representative before they start.

In force since 1 March 2024

Enforced by State Audit Office of Georgia

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, To save someone’s life, Important public interest, Legal claims

General data protection law (2026)

Official name: საქართველოს 2025 წლის 17 დეკემბრის კანონი №1289 (ცვლილება პერსონალურ მონაცემთა დაცვის შესახებ კანონში) · Law of Georgia No 1289 of 17 December 2025, published 23 December 2025 · Act of parliament

In forceYes, with paperwork

From 2 March 2026 the law's references to the independent Personal Data Protection Service are replaced by the State Audit Office of Georgia. The Auditor General now issues the privacy rulebooks. Every duty stayed the same. The body you owe it to changed.

In force since 2 March 2026

Enforced by State Audit Office of Georgia

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Data rules

Official name: ბრძანება №20 — სპეციალური წარმომადგენლის რეგისტრაციის წესი · Order No 20 of 28 February 2024, amended by Order No 004 of the Auditor General published 31 March 2026 · Government rules

In forceYes, with paperwork

This is the procedure a foreign company must follow to put a representative on the Georgian register. You must do it before you handle data using equipment in Georgia. Companies established in the European Union are exempt. So are companies in a country the European Union has approved.

In force since 1 March 2024Enforced from 1 April 2024

Enforced by State Audit Office of Georgia

How this country controls where data goes: Only approved countries

Who you would hear from

  • სახელმწიფო აუდიტის სამსახური

    Data protection supervision since 2 March 2026; also public-sector audit and the foreign agents register

    Rule-making is clearly live. The Auditor General issued Orders No 004 and No 005 on 30-31 March 2026, amending the inherited data protection rulebooks. We found no published data protection decision, fine or inspection result on an official website as at 18 August 2026. The site shows no dedicated data protection section. Treat enforcement as unproven rather than absent.

  • პერსონალურ მონაცემთა დაცვის სამსახური

    Former independent data protection authority, named in the law until 1 March 2026

    The law's references to this Service were replaced by the State Audit Office from 2 March 2026. Its 2024 orders are now being amended by the Auditor General. But the content we could retrieve carried no dates. So we cannot say what, if anything, the body still does.

  • ციფრული მმართველობის სააგენტო

    Information security standards for critical systems, national computer emergency response team, government cloud and data centre

    Successor to the Data Exchange Agency, which is still the name used in the text of the Information Security Law.

  • საქართველოს კომუნიკაციების ეროვნული კომისია

    Electronic communications and media regulation

  • საქართველოს ეროვნული ბანკი

    Banking, payments, insurance and securities supervision

    It publishes its legal acts through a database we could not read on 18 August 2026. So we may have missed a banking storage rule.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Which countries are currently on Georgia's list of destinations with adequate safeguards

    We could not confirm which countries are approved. The law requires the regulator to publish the list as a formal act. We found no published list on an official Georgian website. The Legislative Herald's search box ignores the query, and the regulator's website did not return readable pages. Until this list is found, treat every transfer as needing a permit or an exception.

  • Whether the State Audit Office has issued any data protection decision, fine or inspection result since taking over on 2 March 2026

    We could not confirm any enforcement activity. We found no register of decisions. Rule-making activity is proven; enforcement is not. That is why enforcement is rated waking rather than active or dormant.

  • The exact fate of the Personal Data Protection Service as an institution, and the fine levels in the privacy law

    We could not confirm the final chapters of the law. The Legislative Herald cuts long documents short when fetched. So we could not read the regulator's status, its powers, or the penalty amounts in Georgian lari. The Georgian text is cut even earlier than the English.

  • Any data storage or outsourcing rule for banks, payment providers, insurers or securities firms

    We could not confirm this against the National Bank of Georgia's legal acts, which sit in a database we could not query. We found no rule as at 18 August 2026. If you work in banking, check before you rely on it.

  • How long telecoms identification data is kept in the state-held central database

    We could not confirm how long this data is kept. The Law on Electronic Communications passes the period to Article 15(1) of the Law on the Operative and Technical Agency. We could not open that law on an official website.

  • Whether any health, education, gaming, mapping or defence rule imposes keeping data in the country

    We found nothing, checked 18 August 2026. We covered these industries using the general statutes we could open, not a regulator-by-regulator sweep. Search on the official gazette is unusable. Check with your own regulator before you rely on this.

  • That the English text on the Legislative Herald accurately reflects the Georgian original in naming the State Audit Office

    We could not confirm this against the Georgian text, because the Georgian page is cut short at Article 14. We compared the 2023 original with the December 2025 version. We also have two 2026 orders signed by the Auditor General. That makes a translation glitch very unlikely.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.