Georgia's private-sector security-topic footprint is narrow: one enacted state statute imposes a genuine record-disposal duty distinct from breach notification, no enacted state law sets market-entry security requirements for a connected device or software product, no state law creates a general private-sector duty to report a vulnerability or a security incident to an authority, and no state regime was located adopting the newer NAIC Insurance Data Security Model Law.
O.C.G.A. Sec. 10-15-2 (Title 10, Commerce and Trade), part of a chapter (O.C.G.A. Secs. 10-15-1 to 10-15-7) that already had at least one provision in force by July 1, 2004 (the same chapter's receipt-truncation section, O.C.G.A. Sec. 10-15-3(b)(1), states that date for its own first phase-in; the disposal duty's own commencement date is not stated in the unannotated code text consulted here), requires a 'business,' defined broadly to include a sole proprietorship, partnership, corporation, association, or other group organized for profit or not, and expressly including a financial institution and an entity that destroys records, to shred, erase, modify to make unreadable, or otherwise take reasonable action to prevent unauthorized access to a customer's record before discarding it, where that record combines personally identifiable data with a customer's medical condition, an account or credit balance, information supplied when opening an account or applying for a loan or credit, or a federal, state, or local income tax return.
The duty carves out a bank or financial institution subject to the Gramm-Leach-Bliley Act's privacy and security provisions, a hospital or health care institution subject to Health Insurance Portability and Accountability Act (HIPAA)'s privacy and security provisions, and any other entity governed by a federal law that itself requires disposal of such records in the same manner.
The same chapter's O.C.G.A. Sec. 10-15-3 requires a merchant accepting a payment card to truncate the account number and omit the expiration date on a printed receipt, phased in from July 1, 2004 for machines first used on or after that date to July 1, 2006 for all machines; because that duty binds a merchant printing a payment receipt rather than a duty over a software product's security posture or a business's general handling of covered information, and because it substantially overlaps the federal Fair and Accurate Credit Transactions Act's own truncation requirement, it is named here rather than filed as its own instrument.
The same chapter's O.C.G.A. Sec. 10-15-4, which makes it a crime for a person to use a scanning device or reencoder to capture or transfer payment-card magnetic-strip data with intent to defraud, and O.C.G.A. Sec. 10-15-7's felony penalties for that offense (one to three years' imprisonment or a fine of up to $10,000.00 for a first offense, three to ten years or up to $50,000.00 for a second or subsequent offense), bind the intruder who captures the data rather than the system's operator or manufacturer, so both sit with the scraping topic's computer-misuse family rather than here.
O.C.G.A. Sec. 10-15-5 authorizes the Attorney General to enforce the chapter using the Fair Business Practices Act's investigative powers, and O.C.G.A. Sec. 10-15-6 caps an administrative penalty for a violation of the disposal duty at $500.00 per wrongfully discarded customer record with a $10,000.00 total ceiling per order, subject to an affirmative due-diligence defense, with hearings and judicial review under the Georgia Administrative Procedure Act; the chapter states no private right of action of its own.
No enacted Georgia statute was located that sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act, and no enacted Georgia statute creates a general private-sector duty to report an exploited vulnerability or a security incident to a state authority; both are researched absences rather than gaps in coverage.
Georgia's Insurance Code, Title 33, carries a chapter on insurers' collection, use, and disclosure of information (O.C.G.A. Secs. 33-39-1 et seq., the older NAIC Insurance Information and Privacy Protection Act model, itself a privacy-topic matter), but the full Title 33 chapter listing read here, dated by its publisher to March 28, 2024 and running from Chapter 1 through Chapter 65, carries no chapter addressing an insurer's or insurance licensee's information-security program, a cybersecurity event, or a data-security duty comparable to the newer NAIC Insurance Data Security Model Law already adopted in South Carolina, Hawaii, Alaska, Arizona, and Wisconsin, and the Georgia Department of Insurance and Safety Fire Commissioner's own website carries no reference to a data-security or cybersecurity regulatory program either.
A 2025 or 2026 session enactment of the newer model law is not confirmed in the primary text consulted here: the Georgia General Assembly's own legislation-search site, www.legis.ga.gov, serves only a JavaScript application that returned no readable statute text, so a very recent adoption cannot be fully ruled out from the sources read here.
The Georgia Technology Authority (O.C.G.A. Title 50, Chapter 25) has the statutory power 'to establish technology security policies, standards, and services to be used by all agencies' (O.C.G.A. Sec. 50-25-4(a)(20)); nothing in the section read here extends that duty to a vendor or contractor doing business with the state, so it is a government's own information-security programme rather than a duty this topic tracks, and it is not filed as an instrument here.
Georgia's breach-notification statute, the Georgia Personal Identity Protection Act (O.C.G.A. Secs. 10-1-910 to 10-1-915), is already this jurisdiction's privacy-topic row rather than repeated here, and the Georgia Computer Systems Protection Act's hacking, computer theft, trespass, invasion-of-privacy, forgery, and password-disclosure offenses (O.C.G.A. Sec. 16-9-90 et seq.) bind an intruder rather than a system's operator and belong to the scraping topic.