Data Protection in Georgia

Security in Georgia

Under Georgian law, the data controller is obliged to implement appropriate organizational and technical measures to ensure that personal data is processed in accordance with the law and to demonstrate compliance with these requirements.¹

The controller and the processor must take measures to address potential and incidental risks associated with data processing, including pseudonymization, access logging, and information security mechanisms (confidentiality, integrity, availability), to protect data against loss, unlawful processing, destruction, alteration, disclosure, or misuse.²

When determining the necessary organizational and technical measures, the controller and processor must consider the categories and volume of data, processing purposes, form and means of processing, and potential risks to the data subject’s rights. They must periodically assess the effectiveness of the measures and update or implement additional safeguards if necessary.³

The controller and processor are required to maintain records of all actions performed on electronically stored data, including incidents, collection, modification, access, disclosure (transfer), linking, and deletion. For non-electronic data, records must be kept for all disclosures or alterations, including incident reports.

All personnel involved in processing or with access to data must act within their assigned authority, maintain confidentiality, and protect data, including after the termination of their employment.

The controller and processor must define employee access rights according to their role and implement adequate measures to prevent, detect, and stop unauthorized processing by staff, including raising awareness on data security obligations.

Footnotes

[1] See Article 27, para. 1, Law of Georgia on Personal Data Protection.
[2] See Article 27, para. 2, Law of Georgia on Personal Data Protection.
[3] See Article 27, para. 3, Law of Georgia on Personal Data Protection.
[4] See Article 27, para. 4, Law of Georgia on Personal Data Protection.
[5] See Article 27, para. 5, Law of Georgia on Personal Data Protection.
[6] See Article 27, para. 6, Law of Georgia on Personal Data Protection.

Continue reading

  • no results

Previous topic
Back to top