Law / United States / Georgia

Georgia Personal Identity Protection Act, notification of security breach

O.C.G.A. Sec. 10-1-912

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Commencement not set.

A breach notification rule binding public and private bodies.

As of 27 August 2026.

What it requires

  • Give notice of a breach of the security of a system containing a Georgia resident's personal information in the most expedient time possible and without unreasonable delay.
  • Notify the information broker or data collector you maintain data for, of any breach you discover, so that party can meet its own notice duty.
  • Notify all nationwide consumer reporting agencies if a breach requires notifying more than 10,000 Georgia residents at one time.
  • Do not rely on this statute to cover a breach of biometric, genetic, or health data alone. Georgia's personal information definition does not include any of those categories.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

An information broker or data collector, including a government agency, that maintains computerized personal information on a Georgia resident must give notice of a breach of the security of the system in the most expedient time possible and without unreasonable delay, unless a law enforcement agency determines notification would compromise a criminal investigation.

A person or business maintaining data on behalf of an information broker or data collector must notify that broker or collector of a breach it discovers, and above a 10,000-resident notification threshold the notifying party must also notify nationwide consumer reporting agencies.

Georgia's operative personal information definition (O.C.G.A. Sec. 10-1-911, a companion definitions section not itself quoted on the page cited below) covers only a name combined with a Social Security number, driver's license or state ID number, or an account, credit card, or debit card number where it could be misused without more; biometric, genetic, and health data are absent from the definition entirely, so a breach of biometric data alone triggers no notice duty.

The Act has no direct notice duty running to a state regulator or the Attorney General, and Georgia courts have held the Act imposes no freestanding data-security standard of conduct in its own right.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

official guidance quoting O.C.G.A. Sec. 10-1-912, Georgia Attorney General's Consumer Protection Division (Consumer Ed)
the definitions in Sec. 10-1-911 are not quoted in that guidance and could not be independently pinned to an official host, see the jurisdiction summary

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app