Law on Personal Data Protection, biometric data article
Law of Georgia on Personal Data Protection, Law No. 3144-XI, Art. 9; Art. 3(d)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 March 2024.
A biometric privacy rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app that captures or stores a facial image, voiceprint, or other biometric identifier from a person in Georgia must have a necessity-based purpose recognized by Art. 9 or the data subject's consent, and must determine in writing, before processing begins, the purpose, volume, storage period, and destruction procedure for that biometric data.
What it reaches
Excludes recording-derived identifiersNo
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Art. 3(d) defines biometric data as data processed using technical means and related to the physical, physiological or behavioural characteristics of a data subject, such as facial images, voice characteristics or dactyloscopic data, which allow the unique identification or confirm the identity of that data subject, naming voice and face directly rather than leaving them implicit, the closest match to General Data Protection Regulation (GDPR) Art. 4(14)'s formulation in this batch.
Art. 9 is a dedicated biometric-data article, independent of the Art. 6 special-categories list: biometric data may be processed only for an enumerated list of necessity-based purposes (security or property protection where no less-intrusive means exists, identity-document issuance, border-crossing identification, migration control, international-protection implementation, crime prevention and investigation, detention or sentence enforcement, minor-welfare coordination, operative-investigative activity, information or cyber security, or another case a law directly provides for), and Art. 9(2) requires the controller to determine in writing, before processing begins, the purpose and volume of the biometric data to be processed, its storage period, and its storage and destruction procedure and conditions.
Art. 13 requires the data subject's consent as the default basis, subject to those necessity-based exceptions.
When LexLint raises it
processes_biometricsprocesses_voicetrains_modelscrawls_web
Read the law
official statute text, Legislative Herald of Georgia (Matsne)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.