Georgia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Georgia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Data can leave Georgia, but only in three ways. The destination country has been approved by the regulator. Or you get a permit. Or a narrow exception applies. Georgia copied the European model in 2023. No general rule forces data to stay in the country. The big change is who is in charge. On 2 March 2026 the independent privacy watchdog was replaced by the State Audit Office. We could not verify that it has issued a single decision since.
Data governance in Georgia
The eight things that decide how you handle data about people in Georgia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law catches a company with no office in Georgia if it uses equipment located in Georgia to handle people's data. There is no revenue or headcount limit to duck under. It gets worse. A foreign company in that position must appoint a representative in Georgia. It must register that person with the regulator before it starts handling data. The only escape is being based in the European Union, or in a country the European Union has already approved.
- What you have to do here:
- Appoint a representative · Register or notify
Article 2 applies the Law to data handled wholly or partly by automated means within Georgia. It also applies to a company outside Georgia that uses equipment available in Georgia. Article 34 makes such a company appoint or designate a special representative in Georgia before it starts. That duty does not apply to bodies founded in EU member states. It also does not apply to bodies in states the European Union recognises as giving good enough protection. Order No 20 of 28 February 2024 sets the registration steps. You file identity and corporate documents, the written appointment agreement, and a description of the equipment used. Checks take 10 working days, with a further 5 or 10 working days for corrections. Companies that already had a representative when the Law started had until 1 April 2024 to register. That order was amended by Order No 004 of the Auditor General of the State Audit Service, published 31 March 2026.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, No 3144-XIms-Xmp, Articles 2 and 34 (consolidated text of 10 June 2026)
matsne.gov.ge
“the controller/processor is obliged to appoint or designate a special representative in Georgia before data processing”
Link checked 18 August 2026
- Official sourcePersonal Data Protection Service of Georgia, via Legislative HeraldOrder No 20 of 28 February 2024 on the Approval of the Procedure for Registering a Special Representative
matsne.gov.ge
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork. Data may go abroad in three ways. The destination country has been judged to give good enough protection. Or the regulator grants a permit for the contract you have signed. Or a narrow exception applies, such as the person's written consent after being told the risks. Nothing in the general law forces data to stay in Georgia. The one place data really does stay is telecoms. A copy of who called whom, and when, sits in a state-run database inside the country.
- Ways to send data out:
- Official 'this country is safe' decision · Government sign-off needed
Article 37(1) allows a transfer where the Law's requirements are met and the destination has proper safeguards. Article 37(2) adds other routes. One is an international treaty. One is an agreement between companies with proper safeguards, plus a permit from the regulator. Others are criminal procedure grounds, and the written consent of the person after being told the risks. The last two are vital interests, and a narrow proportionate public interest ground. Article 38 makes the regulator assess whether a country or international organisation gives good enough protection. It must set that out in a formal act and review it at least once every three years. Industry by industry, checked on 18 August 2026. BANKING, PAYMENTS, INSURANCE AND SECURITIES. We found no rule forcing data to stay in Georgia in the National Bank of Georgia's published acts. Its acts portal is not machine-readable, so we record this as unconfirmed. HEALTH. We found no rule forcing data to stay in Georgia. But medical institutions are on the list of bodies that must appoint a data protection officer. TELECOM. The content of communications must be destroyed immediately. Connection identification data may be copied by the state into a central database held in Georgia. GOVERNMENT AND CRITICAL INFRASTRUCTURE. The Information Security Law sets security duties. It says nothing about where you store data. EDUCATION, GAMING, MAPPING AND DEFENCE. We found no rule forcing data to stay in Georgia.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, Articles 37 and 38 (transfer to another state and assessment of adequate safeguards)
matsne.gov.ge
“The transfer of data to another state and international organisation shall be allowed if the requirements for data processing provided for by this Law and appropriate safeguards in the relevant state or international organisation are in place for ensuring data protection and the protection of data subjects' rights.”
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Electronic Communications, No 1514, Articles 8 and 8-3
matsne.gov.ge
“copy the databases of the electronic communication identification data and store them at the central bank of the electronic communication identification data”
Link checked 18 August 2026
- Official sourceNational Bank of GeorgiaNational Bank of Georgia — Legal Acts portal (checked for banking, payments and IT rules on 18 August 2026)
nbg.gov.ge
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Georgia.
Sending data out of the country
You can only send data to countries the regulator has approved. A permit is the back-up route. The regulator decides which countries offer good enough protection and publishes that decision as a formal act. If your destination is not on the list, you need a permit for your contract. Or you fall back on a narrow exception such as written consent. We could not find the current published list. So we cannot tell you today which countries are on it. Treat that as the single biggest open question in this record.
- Ways to send data out:
- Official 'this country is safe' decision · Government sign-off needed · Explicit consent · To save someone’s life · Important public interest
Article 38(1) makes the regulator assess whether a destination gives good enough protection. It looks at the destination's international commitments and its data protection laws. It looks at the guarantees for people's rights, including real ways to complain. It also looks at the onward-transfer rules and whether the destination has an independent regulator. The list must be reviewed at least every three years. It must be revised when a destination no longer qualifies. Since 2 March 2026 the assessing body named in the Law is the State Audit Office, and the Auditor General issues the formal act. We could not find any published list on an official Georgian website.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, Article 38 (assessment of adequate safeguards and the list of states)
matsne.gov.ge
“The existence of adequate safeguards for data protection in another state and/or international organisation shall be assessed by the State Audit Office on the basis of international obligations and regulatory legislation relating to data protection, guarantees for the protection of the rights and freedoms of data subjects (including effective legal protection mechanisms), rules for further international data transfer, and the analysis of the existence, powers and activities of an independent data protection supervisory body.”
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
This is where Georgia surprises people. Until 1 March 2026 the job belonged to the Personal Data Protection Service, an independent watchdog. From 2 March 2026 the law hands the same job to the State Audit Office. That is the body that audits government spending. Its head, the Auditor General, now signs the privacy rules. We can prove the handover happened. The Auditor General reissued two of the privacy rulebooks at the end of March 2026. We could not find a single enforcement decision published since the handover.
The text of the Law dated 17 December 2025 carries the swap in brackets, marked to take effect on 2 March 2026. Every reference to the Personal Data Protection Service becomes the State Audit Office of Georgia. The original 2023 text named the Personal Data Protection Service in the same articles. That rules out a translation error. The subordinate rules back this up. Order No 22 on data protection officers was amended by Order No 005 of the Auditor General of the State Audit Service on 30 March 2026. Order No 20 on registering foreign companies' representatives was amended by Order No 004. Both were published 31 March 2026. Rating: waking, not active. The rule-making machine is running. But we could not verify any published decisions, fines or inspection results from the new regulator on an official website. Industry regulators are separately working. They are the National Bank of Georgia and the Georgian National Communications Commission. The Digital Governance Agency also runs the national computer emergency response team.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, version of 17 December 2025 (Law No 1289) showing the substitution of the State Audit Office with effect from 2 March 2026
matsne.gov.ge
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, original text published 3 July 2023, Articles 29 and 38 naming the Personal Data Protection Service
matsne.gov.ge
“A controller is obliged to register an incident, its resulting outcome, the measures taken, and to notify the Personal Data Protection Service about the incident, not later than 72 hours after the identification of the incident”
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaOrder No 22 of 28 February 2024 on data protection officers, as amended by Order No 005 of the Auditor General of the State Audit Service, 30 March 2026
matsne.gov.ge
Link checked 18 August 2026
- Official sourceState Audit Office of GeorgiaState Audit Office of Georgia — official site (no data protection section visible on 18 August 2026)
sao.ge
Link checked 18 August 2026
How long you must keep it — and when to delete it
The maximum is clear. Keep personal data only as long as you need it for the purpose you collected it for. Then erase it, destroy it, or strip out the identifying parts. That is unless another law tells you to keep it. The minimum keeping times are scattered across tax, accounting and industry laws that we could not open on an official site today. In telecoms the direction is reversed. The content of a call or message must be destroyed at once. The record of who contacted whom can be copied into a state database. It is then kept for a period set by a separate law.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period
Article 4(1)(e) of the Law on Personal Data Protection sets the maximum. You may store data only for the period needed to achieve the legitimate purpose. Then you must erase, destroy or de-identify it, unless a law requires you to keep it. Article 8(5) of the Law on Electronic Communications requires the content of a user's communication to be destroyed immediately and automatically. Article 8-3 of the same law lets the authorised body copy operators' databases of electronic communication identification data into a central bank of that data. The keeping period is fixed by Article 15(1) of the Law on the Legal Entity under Public Law called Operative and Technical Agency of Georgia. We could not open that law. Where a specific keeping law clashes with the general delete-when-done duty, the specific law wins. Article 4 expressly excludes retention that legislation requires.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, Article 4(1)(e) (storage limitation)
matsne.gov.ge
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Electronic Communications, Article 8(5) and Article 8-3
matsne.gov.ge
“Information on the content of the communication made by a user via an electronic communication network shall be immediately and automatically destroyed.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There are two clocks. If personal data is lost, leaked or wrongly handled, you have 72 hours from spotting it to tell the regulator. You must also keep your own record of the incident and what you did about it. If you run a system the government has listed as critical to the country, you must tell the national computer emergency response team immediately. There is no fixed number of hours, which means the same day. If both apply to you, both run at once.
- What you have to do here:
- Report breaches to the regulator · Report cyber incidents · Secure the data
Article 29(1) of the Law on Personal Data Protection sets the 72-hour clock. You must also record the incident, its consequences and the steps you took. There is an exception where significant damage or a significant threat to fundamental rights is least expected. Order No 19 of 28 February 2024, in force from 1 March 2024, sets out how to judge that. It looks at the type of data. It looks at whether children or disabled people are affected. It looks at how easily people can be identified, and at the scale. It requires you to notify where the likelihood of significant damage is medium or high. You can report in stages where you cannot finish the assessment within 72 hours. A supplier handling data on your behalf must tell you immediately. Separately, Article 10 of the Law on Information Security requires you to notify the national computer emergency response team immediately of an identified computer incident. You must also preserve the evidence.
Sources
- Official sourcePersonal Data Protection Service of Georgia, via Legislative HeraldOrder No 19 of 28 February 2024 on criteria for incidents posing a significant threat and the procedure for notifying the supervisory body
matsne.gov.ge
“A controller shall be obliged to notify the Service of an incident within 72 hours after its detection”
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Information Security, No 6391-Is, Article 10 (notification of computer incidents)
matsne.gov.ge
“CERT shall be immediately notified of the identified computer incident”
Link checked 18 August 2026
What to do: Your breach process has to reach Georgia's regulator inside the deadline above.
What catches people out
Five things. First, the regulator changed identity on 2 March 2026. A privacy notice or contract naming the Personal Data Protection Service now points at a body the law no longer mentions. Second, a foreign company must register a representative in Georgia before it starts, not after. Third, a child is anyone under 16. A European sign-up flow tuned to 13 will be wrong here. Fourth, direct marketing always needs consent, even if you bought the list lawfully. Fifth, the same State Audit Office that now polices privacy also runs the public register of foreign-funded organisations. Those organisations must publish detailed information about themselves.
- What you have to do here:
- Appoint a representative · Appoint a data protection officer · Get a parent's consent for children · Get consent · Register or notify
1) The English text of the Law on the government's own site now reads 'State Audit Office' in the articles on breach notification and international transfer. The 2023 original read 'Personal Data Protection Service' there. Anyone comparing an old summary with the current text will think they are reading two different laws. 2) Article 34 and Order No 20: register first, handle data second. The exemption covers only bodies established in the European Union, and bodies in countries the European Union treats as giving good enough protection. 3) Article 7(1): a person aged 16 or over may consent for themselves. Under 16 needs a parent or guardian, unless a specific law says otherwise. 4) Article 12(1): you may use data for direct marketing only with the person's consent. It does not matter how you originally collected the data. 5) Under the Foreign Agents Registration Act, in force 31 May 2025, anyone acting for a foreign principal must file details within 10 days. That means identity, address, employment, contract, funding and spending. They must update every six months. The filings go into a publicly searchable, downloadable database. Enforcement moved from the Anti-Corruption Bureau to the State Audit Office in March 2026. 6) A quieter one. Banks, insurers, microfinance organisations, credit bureaus, telecoms companies, airlines, airports, medical institutions and all public bodies must appoint a data protection officer. Size does not matter.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, Articles 7, 12, 33 and 34
matsne.gov.ge
“Data may only be processed for direct marketing purposes with the consent of the data subject”
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaLaw of Georgia Foreign Agents Registration Act, No 399-IIms-XImp, 1 April 2025
matsne.gov.ge
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaOrder No 22 of 28 February 2024 — which controllers need not appoint a data protection officer
matsne.gov.ge
“3% of the population of Georgia”
Link checked 18 August 2026
What's changing next
Nothing new is scheduled to start in the privacy law itself. We checked the current text on 18 August 2026 and found no parts waiting on a future date. The live story is the handover. The Auditor General is reissuing the four rulebooks inherited from the old watchdog. Two of the four were reissued in March 2026. The rest of the risk sits in things the government can already change without a new law.
THINGS THAT CAN CHANGE WITH NO CONSULTATION. First, the list of approved destination countries. The regulator sets it by its own formal act. It must review the list at least every three years. It may revise it whenever a destination stops qualifying. A country can be removed with no consultation and no step through parliament. Second, the permit route for transfers is discretionary. So the bar can be raised without changing the text of the law. Third, the government approves the list of critical information system subjects by ordinance. So an ordinary private company can be pulled into the security rules overnight. Fourth, the two remaining 2024 orders can be rewritten by the Auditor General alone. Those cover data protection impact assessments and incident notification. Also worth watching, but not a date. Georgia's regulator is no longer a dedicated independent body. That sits awkwardly with the independence expected by the Council of Europe data protection convention, and by European Union accession. Any outside assessment of Georgia's protection level could shift because of it.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection, consolidated text of 10 June 2026 (checked for future-dated provisions)
matsne.gov.ge
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaOrder No 20 of 2024 as amended by Order No 004 of the Auditor General, published 31 March 2026
matsne.gov.ge
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries2 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms data needs a copy kept in the country
Official name: საქართველოს კანონი ელექტრონული კომუნიკაციების შესახებ · Law of Georgia on Electronic Communications, No 1514, Articles 8, 8-2 and 8-3 · Act of parliament
Telecoms data is the one place Georgia keeps a state copy at home. What was said must be destroyed at once. But the record of who contacted whom can be copied by the state into a central database inside Georgia. Every hand-over to a state body has to be logged.
Enforced by Georgian National Communications Commission
How this country controls where data goes: Approval each time
What you have to do
- Keep the data in the countryNot a ban on foreign hosting. The authorised state agency may copy operators' identification-data databases into a central state-held database in Georgia.
- Delete data after a periodContent of communications must be immediately and automatically destroyed.
- Keep records of how you use dataOperators must log every time identification data is handed to a state body. They must report it to the regulator named in the law.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Electronic Communications, Articles 8 and 8-3
matsne.gov.ge
“Information on the content of the communication made by a user via an electronic communication network shall be immediately and automatically destroyed.”
Link checked 18 August 2026
- Official sourceGeorgian National Communications CommissionGeorgian National Communications Commission — resolutions, including the 2010 rules on services and consumer rights protection in electronic communications
comcom.ge
Link checked 18 August 2026
Breach reporting rules
Official name: საქართველოს კანონი ინფორმაციული უსაფრთხოების შესახებ · Law of Georgia on Information Security, No 6391-Is; last amended by Law No 803-IIms-XImp of 26 June 2025 · Act of parliament
This applies to organisations the government has listed as critical to national defence or economic security. That includes private companies. It demands a security policy, a named security manager, audits and immediate incident reporting. It says nothing about where systems or data must sit.
Enforced by Digital Governance Agency
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidentsThe national computer emergency response team must be notified immediately of an identified computer incident, and evidence preserved.
- Secure the dataAn information security policy meeting recognised international standards must be adopted.
- Appoint a data protection officerA security manager, not a privacy officer: a named person responsible for day-to-day compliance.
- Independent auditCompatibility assessment against minimum information security standards.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Information Security, Articles 3, 4, 6, 7 and 10
matsne.gov.ge
“CERT shall be immediately notified of the identified computer incident”
Link checked 18 August 2026
- Official sourceDigital Governance Agency of GeorgiaDigital Governance Agency — national computer emergency response team, government cloud and data centre services
dga.gov.ge
Link checked 18 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: საქართველოს კანონი პერსონალურ მონაცემთა დაცვის შესახებ · No 3144-XIms-Xmp, published 3 July 2023, consolidated text of 10 June 2026 · Act of parliament
This is Georgia's general privacy law, closely modelled on the European Union's rules. Data may leave the country to an approved destination, under a permit, or by a narrow exception. It reaches foreign companies that use equipment in Georgia. It makes them register a local representative before they start.
Enforced by State Audit Office of Georgia
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, To save someone’s life, Important public interest, Legal claims
What you have to do
- Get consentAlways required for direct marketing, however the data was originally collected.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Secure the data
- Report breaches to the regulator — within 72 hoursFrom identification of the incident. Exempt only where significant damage is least expected.
- Delete data after a periodStore only as long as the purpose needs, then erase, destroy or de-identify, unless a law requires retention.
- Appoint a data protection officer — applies at: Public bodies, insurers, banks, microfinance organisations, credit bureaus, telecoms, airlines, airports, medical institutions, plus anyone processing data of a significant number of people or doing systematic large-scale monitoring
- Appoint a representativeThis covers foreign companies and their suppliers that use equipment in Georgia. You are exempt if you are established in the European Union, or in a country the European Union treats as safe enough.
- Register or notifyYou must register the special representative with the regulator before you start handling data.
- Assess high-risk projects
- Get a parent's consent for children — applies at: under 16
- Put a transfer safeguard in place
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia on Personal Data Protection (consolidated text of 10 June 2026)
matsne.gov.ge
“The transfer of data to another state and international organisation shall be allowed if the requirements for data processing provided for by this Law and appropriate safeguards in the relevant state or international organisation are in place”
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaOriginal text as published 3 July 2023
matsne.gov.ge
Link checked 18 August 2026
General data protection law (2026)
Official name: საქართველოს 2025 წლის 17 დეკემბრის კანონი №1289 (ცვლილება პერსონალურ მონაცემთა დაცვის შესახებ კანონში) · Law of Georgia No 1289 of 17 December 2025, published 23 December 2025 · Act of parliament
From 2 March 2026 the law's references to the independent Personal Data Protection Service are replaced by the State Audit Office of Georgia. The Auditor General now issues the privacy rulebooks. Every duty stayed the same. The body you owe it to changed.
Enforced by State Audit Office of Georgia
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed
What you have to do
- Report breaches to the regulator — within 72 hours, from 2 March 2026Same clock, different recipient: notifications now go to the State Audit Office.
Sources
- Official sourceLegislative Herald of GeorgiaLaw on Personal Data Protection, version of 17 December 2025, showing the substitution effective 2 March 2026
matsne.gov.ge
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaOrder No 22 of 2024 amended by Order No 005 of the Auditor General of the State Audit Service, 30 March 2026
matsne.gov.ge
Link checked 18 August 2026
Data rules
Official name: ბრძანება №20 — სპეციალური წარმომადგენლის რეგისტრაციის წესი · Order No 20 of 28 February 2024, amended by Order No 004 of the Auditor General published 31 March 2026 · Government rules
This is the procedure a foreign company must follow to put a representative on the Georgian register. You must do it before you handle data using equipment in Georgia. Companies established in the European Union are exempt. So are companies in a country the European Union has approved.
Enforced by State Audit Office of Georgia
How this country controls where data goes: Only approved countries
What you have to do
- Appoint a representativeAppointment must be in writing and evidenced by an agreement filed with the supervisor.
- Register or notify — from 1 April 2024Verification within 10 working days; corrections within 5 working days, extendable once. Companies that already had a representative had to register by 1 April 2024.
Sources
- Official sourceLegislative Herald of GeorgiaOrder No 20 of 28 February 2024 on the Approval of the Procedure for Registering a Special Representative
matsne.gov.ge
Link checked 18 August 2026
Children's data rules
Official name: ბრძანება №19 — ინციდენტის შესახებ შეტყობინების წესი · Order No 19 of 28 February 2024 · Government rules
Sets out when a data incident counts as serious enough to report and how to report it within 72 hours. Factors include the type of data, whether children or disabled people are affected, and how easily people can be identified.
Enforced by State Audit Office of Georgia
What you have to do
- Report breaches to the regulator — within 72 hoursRequired where the likelihood of significant damage is medium or high. Staged reporting allowed if the assessment cannot be completed in time.
- Tell affected peopleWhere the incident is likely to cause significant damage to the person.
- Keep records of how you use dataThe incident, its consequences and the measures taken must be registered internally.
Sources
- Official sourceLegislative Herald of GeorgiaOrder No 19 of 28 February 2024 on criteria for incidents posing a significant threat to fundamental rights
matsne.gov.ge
“A controller shall be obliged to notify the Service of an incident within 72 hours after its detection”
Link checked 18 August 2026
Government data rules
Official name: საქართველოს კანონი უცხოელი აგენტების რეგისტრაციის შესახებ · Foreign Agents Registration Act, No 399-IIms-XImp, 1 April 2025; amended by Law No 1292 of 17 December 2025 · Act of parliament
This is not a data protection law. But it moves personal and financial information into a public, searchable, downloadable government database. Anyone acting for a foreign government, party or organisation must register and keep filing. Enforcement moved to the State Audit Office in March 2026. That is the same body that now supervises privacy.
Enforced by State Audit Office of Georgia
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notifyWithin 10 days of becoming an agent of a foreign principal; updates every six months.
- Keep records of how you use dataIdentity, addresses, employment, the written agreement with the foreign principal, funding sources for the preceding 60 days and spending records.
Sources
- Official sourceLegislative Herald of GeorgiaLaw of Georgia Foreign Agents Registration Act
matsne.gov.ge
Link checked 18 August 2026
- Official sourceLegislative Herald of GeorgiaOrder No 10 of 31 May 2025 on the Procedure for Administration and Enforcement of the Foreign Agents Registration Act
matsne.gov.ge
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Which countries are currently on Georgia's list of destinations with adequate safeguards
We could not confirm which countries are approved. The law requires the regulator to publish the list as a formal act. We found no published list on an official Georgian website. The Legislative Herald's search box ignores the query, and the regulator's website did not return readable pages. Until this list is found, treat every transfer as needing a permit or an exception.
Whether the State Audit Office has issued any data protection decision, fine or inspection result since taking over on 2 March 2026
We could not confirm any enforcement activity. We found no register of decisions. Rule-making activity is proven; enforcement is not. That is why enforcement is rated waking rather than active or dormant.
The exact fate of the Personal Data Protection Service as an institution, and the fine levels in the privacy law
We could not confirm the final chapters of the law. The Legislative Herald cuts long documents short when fetched. So we could not read the regulator's status, its powers, or the penalty amounts in Georgian lari. The Georgian text is cut even earlier than the English.
Any data storage or outsourcing rule for banks, payment providers, insurers or securities firms
We could not confirm this against the National Bank of Georgia's legal acts, which sit in a database we could not query. We found no rule as at 18 August 2026. If you work in banking, check before you rely on it.
How long telecoms identification data is kept in the state-held central database
We could not confirm how long this data is kept. The Law on Electronic Communications passes the period to Article 15(1) of the Law on the Operative and Technical Agency. We could not open that law on an official website.
Whether any health, education, gaming, mapping or defence rule imposes keeping data in the country
We found nothing, checked 18 August 2026. We covered these industries using the general statutes we could open, not a regulator-by-regulator sweep. Search on the official gazette is unusable. Check with your own regulator before you rely on this.
That the English text on the Legislative Herald accurately reflects the Georgian original in naming the State Audit Office
We could not confirm this against the Georgian text, because the Georgian page is cut short at Article 14. We compared the 2023 original with the December 2025 version. We also have two 2026 orders signed by the Auditor General. That makes a translation glitch very unlikely.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.