Law / Georgia

Georgia

12 of 13 named instruments researched to a stage, across four of the six areas of law we track: 11 in force and 1 proposed. As of 15 September 2026.

When they take effect10 of 12 carry a date, 2 do not. Earlier is before 2014.
Before 2014: 3 instruments (3 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 7 instruments (7 in force) 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 7
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 proposed

Research summary (104 words)

Georgia has no enacted AI-transparency, output-labelling, risk-obligation, training-data, prohibited-practice, governance, or sector-specific AI statute in force. Georgia signed the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225) on 5 September 2024, the day it opened for signature in Vilnius, but has not deposited an instrument of ratification, so the Convention binds Georgia to nothing yet.

The Law of Georgia on Personal Data Protection's automated-decision-making and profiling duties attach to personal data rather than to an AI system as such, and are a privacy-topic finding for this jurisdiction rather than an ai one.

AI risk obligations

Council of Europe Framework Convention on AI, Georgia's signature

Council of Europe Framework Convention on Artificial Intelligence and Human Rights Democracy and the Rule of Law, CETS No. 225, opened for signature 5 September 2024; signed by Georgia 5 September 2024Council of Europe, Framework Convention on Artificial Intelligence, official treaty portal and signatory tracker

Proposed: draft date not recorded. Signed, with consent not yet expressed, dated 5 September 2024, as of 12 September 2026. Binds public and private bodies.

What this law does

This measure is signed but not ratified and binds nobody in Georgia yet; what follows is what it would require if it is ratified in this form. The Convention covers the use of AI systems by public authorities, including private actors acting on their behalf, and by private actors generally.

It requires that activities within an AI system's lifecycle comply with fundamental principles including human dignity and individual autonomy, equality and non-discrimination, respect for privacy and personal data protection, transparency and oversight, accountability and responsibility, reliability, and safe innovation.

It requires documenting information about an AI system and its usage and making that information available to affected persons, sufficient to let them challenge a decision made through or substantially based on the system, and it requires an effective route to lodge a complaint with a competent authority.

It requires carrying out iterative risk and impact assessments of an AI system's actual and potential impacts on human rights, democracy, and the rule of law, with sufficient prevention and mitigation measures, and it lets a Party ban or impose a moratorium on certain AI applications. The Council of Europe's own tracker lists Georgia among the Convention's signatories rather than among the states that have ratified it.

What it requires

Privacy law7 instruments, 7 in force

Research summary (198 words)

Georgia's Law on Personal Data Protection, Law No. 3144-XI, adopted 14 June 2023, replaced the 2011 law outright and commenced in stages: most substantive articles entered into force 1 March 2024, with the data-protection-impact-assessment and Data Protection Officer articles following on 1 June 2024, and later amendments, most recently Law No. 1694 of 10 June 2026, have continued to touch core provisions, so this jurisdiction is fast-moving.

Art. 9 is a dedicated biometric-data article, independent of the Art. 6 special-categories list, permitting biometric processing only for an enumerated list of necessity-based purposes and requiring the controller to fix, in writing before processing begins, the purpose, volume, storage period, and destruction procedure; Art. 3(d) names facial images and voice characteristics directly as biometric-data examples, the closest match in this batch to General Data Protection Regulation (GDPR) Art. 4(14)'s formulation.

Cross-border transfer (Arts. 37-38) runs on an adequacy list the State Audit Office reviews at least every three years, an authority-permit route for contractual safeguards, and consent, a real and conditioned regime. No private right of action was found within this Act itself; enforcement is regulator-only through the State Audit Office's administrative-penalty schedule, with penalties set as flat sums rather than a percentage-of-turnover model.

Biometric privacy

Law on Personal Data Protection, biometric data article

Law of Georgia on Personal Data Protection, Law No. 3144-XI, Art. 9; Art. 3(d)official statute text, Legislative Herald of Georgia (Matsne)

In force since 1 March 2024. Binds public and private bodies.

What this law does

Art. 3(d) defines biometric data as data processed using technical means and related to the physical, physiological or behavioural characteristics of a data subject, such as facial images, voice characteristics or dactyloscopic data, which allow the unique identification or confirm the identity of that data subject, naming voice and face directly rather than leaving them implicit, the closest match to General Data Protection Regulation (GDPR) Art. 4(14)'s formulation in this batch.

Art. 9 is a dedicated biometric-data article, independent of the Art. 6 special-categories list: biometric data may be processed only for an enumerated list of necessity-based purposes (security or property protection where no less-intrusive means exists, identity-document issuance, border-crossing identification, migration control, international-protection implementation, crime prevention and investigation, detention or sentence enforcement, minor-welfare coordination, operative-investigative activity, information or cyber security, or another case a law directly provides for), and Art. 9(2) requires the controller to determine in writing, before processing begins, the purpose and volume of the biometric data to be processed, its storage period, and its storage and destruction procedure and conditions.

Art. 13 requires the data subject's consent as the default basis, subject to those necessity-based exceptions.

What it requires

Breach notification

Law on Personal Data Protection, breach notification

Law of Georgia on Personal Data Protection, Law No. 3144-XI, Arts. 29-30, as amended by Law No. 1289 (17 December 2025)official statute text, Legislative Herald of Georgia (Matsne)

In force since 1 March 2024. Binds public and private bodies.

What this law does

Art. 29 requires a controller to notify the State Audit Office of an incident within 72 hours of identification, in writing or electronically, with a defined content list covering the circumstances, type, and time; affected data categories, volume, and subject count; mitigation measures; planned data-subject notification timing; and DPO or contact details, unless it is least expected the incident would cause significant damage or pose a significant threat to fundamental rights.

Art. 30 requires notifying affected data subjects immediately or without unreasonable delay, in plain language, where there is a high probability of significant damage or a significant threat to fundamental rights, subject to narrower exceptions for state-security or public-safety categories, or where the controller already took measures preventing significant risk. This closely tracks General Data Protection Regulation (GDPR) Arts. 33-34's 72-hour authority-notification, risk-based subject-notification structure. Both articles were touched by Law No. 1289 of 17 December 2025; the specific amendment text is not established here.

What it requires

Comprehensive regime

Law on Personal Data Protection, comprehensive regime and lawful basis

Law of Georgia on Personal Data Protection, Law No. 3144-XI, adopted 14 June 2023, Arts. 1-5, 7-8official statute text, Legislative Herald of Georgia (Matsne), fully consolidated text with inline amendment-history footer

In force since 1 March 2024. Binds public and private bodies.

What this law does

The Law of Georgia on Personal Data Protection, Law No. 3144-XI, adopted 14 June 2023, replaced the 2011 Law on Personal Data Protection outright: Art. 89 declares the 2011 law invalid. Commencement was staged under Art. 90: non-substantive provisions took effect on promulgation in June 2023, while the bulk of substantive articles, including Arts. 1-5, 7-30, 32, 34-79, 81, and 83-89, entered into force 1 March 2024.

Lawful bases sit at Art. 5, which is not set out article-by-article here; Art. 6's special-category grounds are read in full and recorded in a separate instrument.

What it requires

Cross border transfer

Law on Personal Data Protection, cross-border transfer

Law of Georgia on Personal Data Protection, Law No. 3144-XI, Arts. 37-38, as amended by Law No. 1289 (17 December 2025)official statute text, Legislative Herald of Georgia (Matsne)

In force since 1 March 2024. Binds public and private bodies.

What this law does

Art. 37 permits cross-border transfer where the destination state or organization provides appropriate safeguards, through an international treaty, a controller-to-recipient agreement providing appropriate safeguards (which requires a State Audit Office permit under Art. 37(3)), specified statutory bases (criminal-procedure investigative cooperation, alien-status law, international law-enforcement cooperation, or anti-money-laundering and counter-terrorist-financing cooperation), the data subject's written consent after being informed of the destination's inadequate safeguards, vital-interest necessity, or a proportionate public-interest ground.

Art. 38 requires the State Audit Office to maintain and review, at least every three years, a published adequacy list assessed against the destination's international obligations, rights-protection guarantees, onward-transfer rules, and independent supervisory body. No data localization is compelled. Both articles were touched by Law No. 1289 of 17 December 2025; the specific amendment text is not established here.

What it requires

Data subject rights

Law on Personal Data Protection, data subject rights

Law of Georgia on Personal Data Protection, Law No. 3144-XI, Chapter III (Arts. 10-23)official statute text, Legislative Herald of Georgia (Matsne), chapter structure and penalty-schedule cross-references

In force since 1 March 2024. Binds public and private bodies.

What this law does

Chapter III of the Act grants a data subject's rights; the penalty schedule (Arts. 72-75) confirms the chapter covers rights whose violation is separately sanctioned, including a right to withdraw consent (Art. 20), a right to appeal (Art. 22), and an obligation on the controller to protect data-subject rights on request (Art. 23).

The individual right-articles within Chapter III (Arts. 10-19) are not set out here, only the chapter's structure and its penalty cross-references, so the specific access, rectification, deletion, portability, and objection rights it grants are not established.

What it requires

Enforcement supervision

Law on Personal Data Protection, enforcement and penalties

Law of Georgia on Personal Data Protection, Law No. 3144-XI, Arts. 63-79official statute text, Legislative Herald of Georgia (Matsne)

In force since 1 March 2024. Binds public and private bodies.

What this law does

The State Audit Office, in its personal-data-protection function (administratively headed by the Head of the Personal Data Protection Service under Art. 88's transitional provisions), is Georgia's supervisory authority, a distinctive institutional choice housing the DPA inside the state audit body rather than a standalone commission.

Administrative penalties (Arts. 66-79) are flat sums rather than a percentage-of-turnover model; Art. 66, for a violation of processing principles, sets GEL 1,000 to 4,000 depending on entity type, turnover, and aggravating circumstances.

No private-right-of-action or civil-compensation provision was found within this Act itself; enforcement reads as regulator-only through the State Audit Office's administrative-penalty powers, though general Georgian civil or tort law may separately provide a damages route outside this Act, which is not addressed here.

What it requires

Sensitive categories

Law on Personal Data Protection, special categories of data

Law of Georgia on Personal Data Protection, Law No. 3144-XI, Art. 6official statute text, Legislative Herald of Georgia (Matsne)

In force since 1 March 2024. Binds public and private bodies.

What this law does

Art. 6 lists special categories of data as race or ethnicity, political, religious, or philosophical belief, professional-union membership, health, sexual life, criminal-proceeding status, conviction or criminal record, trafficking or domestic-violence-victim status, and detention, plus biometric and genetic data processed to allow unique identification of a natural person, with 20 lawful grounds (a through t) for processing such data, far more elaborate than a bare consent-only rule; two of those twenty, Art. 6(1)(r) and Art. 6(1)(s), are not yet in force, each carrying its own later commencement date fixed by Article 90 of this Law, distinct from the 1 March 2024 date the rest of Art. 6 took effect on.

One of those grounds, Art. 6(1)(i), permits processing where the data subject has made the data publicly available without explicit prohibition of its use. Georgia's biometric-specific Art. 9 regime applies independently on top of any Art. 6 basis, so a biometric identifier is never governed by Art. 6 alone.

What it requires

Scraping law3 instruments, 3 in force

Research summary (245 words)

Georgia has no scraping-specific statute, so general law governs each dimension separately. The Criminal Code of Georgia's cybercrime chapter criminalises unauthorised access to a computer system and unauthorised interference with computer data or systems, but the offence turns on whether access or interference is unauthorised rather than on defeating a technical security measure, and no reported Georgian case addresses whether reading a public, unauthenticated page falls within it.

No Georgian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Law of Georgia on Copyright and Related Rights confers a sui generis database producer right against unauthorised extraction or re-use of a database's contents, but carries no text-and-data-mining exception of the kind the EU's Digital Single Market Directive introduced, so training a model on scraped Georgian-hosted copyrighted content rests only on the Act's general, purpose-limited exceptions such as its quotation provision.

The Law of Georgia on Personal Data Protection (Law No. 3144-XI, 2023), already researched under this jurisdiction's privacy-topic document, applies to personal data without a general carve-out for information the data subject has made publicly available, so scraping personal data from a public Georgian website remains subject to that Act's lawful-basis, purpose-limitation, and cross-border-transfer duties; the seam rule files that duty under the privacy topic rather than restating it here.

No Georgian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Criminal Code, unauthorised access and interference with computer data and systems

Criminal Code of Georgia, Chapter XXXV (Cybercrime), Arts. 284-286Criminal Code of Georgia, official consolidated text, Legislative Herald of Georgia (Matsne)

In force since 1 June 2000. Binds public and private bodies.

What this law does

Article 284 punishes unauthorised access to a computer system by a fine or corrective labour of up to two years, or imprisonment for the same term, rising to imprisonment of two to five years for access committed by a group, using an official position, repeatedly, or resulting in substantial damage (over GEL 2,000), and to imprisonment of three to six years where the target is a critical information system subject.

Article 285 punishes unauthorised making, purchase, storage, sale, or dissemination of software, a password, an access code, or similar data for the purpose of committing a Chapter XXXV offence, by a fine or corrective labour of up to two years and/or imprisonment of up to three years, rising to three to six years for the aggravating circumstances listed above and to four to seven years against a critical information system subject.

Article 286 punishes unauthorised damage, deletion, modification, or concealment of computer data by a fine or corrective labour of up to two years and/or imprisonment for the same term, rising through the same aggravating tiers to three to five years and, against a critical information system subject, four to seven years.

The chapter's own note defines 'unauthorised' as illegal access or use, including where the right holder has not directly or indirectly transferred the right, without requiring that a technical security measure be defeated; because of that, and because no reported Georgian case addresses the point, whether reading a public, unauthenticated page without registration or login falls within these offences is unsettled rather than settled either way.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (250 words)

Georgia has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Law of Georgia on Copyright and Related Rights (1999, as amended) is the only law reaching an aggregator's reproduction of news content.

Its quotation exception permits, without the author's consent and without paying royalties but with compulsory acknowledgement of the author and source, quoting a published work for scientific, research, polemic, critical or information purposes, including reproduction of excerpts from newspapers and magazines for a printed survey, and separately permits reproducing articles or publicly transmitted works on current economic, political, social or religious issues through periodicals unless the author has specially prohibited it.

Neither provision carries a headline-length or short-extract cap distinct from its own purpose-and-extent test, and no reported Georgian decision applies either to a systematic news aggregator as opposed to an individual quoting a published work.

The Act's related-rights chapter protects performers, phonogram and videogram producers, and broadcasting organisations, not a print or online news publisher's own reporting, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates.

No statute or case law located addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law was found. The Act's text carries no machine-readable text-and-data-mining reservation or opt-out mechanism of the kind the scraping topic's copyright_tdm finding for this jurisdiction addresses.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.