GDPR and personal data in Georgia
Georgian data protection law is close enough to the GDPR that operators assume compliance transfers, and different enough that the assumption is wrong in exactly the places that attract enforcement.
1. Two regimes, one operation
A Georgian company serving European customers is usually inside both regimes at once. The practical answer is not to run two compliance programmes but to build one to the higher standard and document where the local rule differs.
2. Where they align
Lawful basis, purpose limitation, data subject rights, breach notification and the requirement to appoint a responsible person all have recognisable counterparts. A team that has implemented the GDPR properly will recognise most of the architecture.
3. Where they diverge
Registration and filing duties, the treatment of biometric and video data, cross-border transfer mechanics and the powers of the supervisory authority differ in substance. So does the enforcement culture: inspections here tend to begin with documentation rather than with a complaint.
Video surveillance at the office is the single most common finding in Georgian inspections. Signage, retention period and the internal act authorising it are checked first.
4. What an operator should hold
A record of processing that matches the systems actually running, a retention schedule that someone enforces, processor agreements with every vendor touching personal data, and an incident procedure that has been rehearsed once. Four documents, kept current, answer most of an inspection.
Operating across both regimes? Book a data protection review with the technology team.
Book a consultation