World Watch/Georgia/Data & Privacy

Data & Privacy · Georgia

Data protection & privacy laws in Georgia (2026)

Comprehensive lawLaw of Georgia on Personal Data Protection (No. 3144/2023); supervisory authority: Personal Data Protection Service (PDPS / pdps.ge)Country index 80 · B+

Georgia shaded by its data & privacy status

Georgia enacted a comprehensive GDPR-aligned personal data protection law (No. 3144/2023) on 14 June 2023, superseding the 2011 law. Core provisions entered force on 1 March 2024, with additional obligations (DPIAs, DPO requirements) phased in through June 2024 and January 2025–2027. The independent Personal Data Protection Service (PDPS) enforces the law, conducts inspections, and imposes fines.

Key points

Comprehensive GDPR-aligned law

Law No. 3144/2023, adopted 14 June 2023, establishes data-protection principles (lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity) closely mirroring the EU GDPR. It replaced the 2011 Personal Data Protection Law.

Phased implementation

Core provisions took effect 1 March 2024; Data Protection Impact Assessment and DPO obligations from 1 June 2024; further provisions being phased in from January 2025 through January 2027.

Data subject rights

Individuals hold rights of access, rectification, erasure, data portability, restriction of processing, and objection to direct marketing, mirroring GDPR Chapter III rights.

Mandatory DPO sectors

Appointing a Data Protection Officer is mandatory for government bodies, commercial banks, insurance firms, microfinance organisations, electronic communications companies, healthcare institutions, airlines/airports, credit bureaux, and entities processing data on more than 3% of Georgia's population or more than 1% of special-category data.

Supervisory authority and enforcement

The Personal Data Protection Service (PDPS) is an independent state authority empowered to conduct scheduled and unscheduled inspections, investigate complaints, and impose fines. In 2024 it conducted 265 inspections and received 1,662 data-subject applications. Fines range from GEL 1,000 to a maximum of GEL 20,000 per single inspection.

EU association alignment

The reform was driven in part by Georgia's EU Association Agreement and candidate-country aspirations; the law was developed with EU4Digital support and is explicitly modelled on the GDPR framework to harmonise Georgian data-protection standards with EU requirements.

Georgia - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →