TrustlexGeorgia business setup
Назад к аналитике
Compliance

Who Must Appoint a Data Protection Officer in Georgia

The 2023 data protection law created a statutory officer role that many companies still have not filled. Which sectors must appoint one, the population thresholds that catch everyone else, and the tasks the role carries once it exists.

Beka Shakulashvili · Основатель и управляющий партнёр 17 августа 2026 г. 11 мин чтения
Информационный перевод. Оригинал статьи составлен на английском языке; при расхождениях преимущество имеет английская версия. Материал носит общий характер и не является юридической или налоговой консультацией.

Georgia rewrote its data protection law in 2023, and one of the changes is easy to miss because it creates a person rather than a policy: certain organisations must appoint a data protection officer. It is a statutory role with defined tasks and a required degree of independence, not a line in a job description, and a year after it took effect a large number of companies that fall inside it still have nobody appointed.

The officer is a role the law creates, not a policy you write once.

1 Mar 2024

Main provisions in force

Law adopted 14 June 2023

1 Jun 2024

Officer role effective

The appointment duty starts here

3% / 1%

Population thresholds

Ordinary data / special category data

Where the duty comes from

The Law of Georgia on Personal Data Protection was adopted on 14 June 2023, with its main provisions in force from 1 March 2024. The officer provisions took effect from 1 June 2024. Enforcement sits with the Personal Data Protection Service, which is a supervisory authority with inspection powers rather than an advisory body.

Law of Georgia on Personal Data Protection (2023)· Personal data protection officer
A data controller and a data processor shall, in the cases established by law, appoint a personal data protection officer, who shall act independently in the performance of the tasks assigned, shall not receive instructions on how to perform them, and shall report to the highest level of management of the organisation.
Stated in outline. The categories of organisation, the exemption thresholds and the officer's precise tasks are set by the Law and by acts of the Personal Data Protection Service, and have been amended since adoption. Confirm the current position before relying on it.

Who must appoint one

Two routes lead to the obligation. The first is the sector you operate in: the law names categories where the appointment is required regardless of size. The second is scale, which catches organisations in any sector once they process enough data or monitor behaviour systematically.

RouteWho it catchesTest
By sectorPublic institutions, commercial banks, microfinance organisations, credit bureaus, insurance organisations, electronic communication companies, airlines and airports, medical institutionsNamed category - size is not the question
By scaleAny organisation processing large volumes of personal dataAbove the population thresholds set by the supervisory authority
By activityAny organisation carrying out systematic and large-scale monitoring of behaviourThe nature of the processing, not the sector
The two routes into the obligation.

The thresholds that decide the second route

  • Processing the personal data of fewer than 3 percent of the population of Georgia points away from the obligation.
  • Processing special category data of fewer than 1 percent of the population points the same way.
  • No systematic and large-scale monitoring of data subject behaviour is the third limb.
  • These are stated as the conditions under which the appointment duty does not arise, so they are read together rather than as a menu - and they are set by the supervisory authority, which means they can change without the Law itself changing.

Note which sectors are named: commercial banks and microfinance organisations are on the list. If you hold a financial-services authorisation in Georgia, the officer question is almost certainly already yours, and it is separate from every AML obligation you already run.

What the officer actually has to do

  • Monitor the organisation's compliance with data protection law and its own internal policies.
  • Advise on data protection impact assessments and on processing that carries higher risk.
  • Act as the contact point for the Personal Data Protection Service and cooperate with it.
  • Act as the contact point for data subjects exercising their rights.
  • Do all of this independently, without instructions on how to reach conclusions, reporting to the top of the organisation.
Worked example

The microfinance organisation that thought it was too small

A small MFO with a few thousand borrowers reads the population thresholds, calculates that it processes far fewer than 3 percent of Georgians, and concludes it has no obligation.

  1. 1The threshold route is not the only route. Microfinance organisations are a named category, where the appointment is required because of what the organisation is rather than how much data it holds.
  2. 2The calculation was correct and irrelevant - it answered the scale question for an organisation that never needed to reach it.
  3. 3The gap surfaces at a supervisory contact, where the first question is who the appointed officer is and when the appointment was made.
  4. 4The organisation appoints someone retrospectively, which fixes the position going forward and does nothing about the period it was required and had nobody.

Read the sector list before doing the arithmetic. For named categories the thresholds are simply not the test, and a correct calculation of the wrong question is the most convincing way to get this wrong.

Illustrative. Confirm the current list of named categories, which has been amended since the Law was adopted.

Worked example

The product company that was monitoring without calling it monitoring

A Georgian software company builds analytics into its product: session recording, behavioural scoring, and profiles used to target in-app offers. It is not in any named sector and has modest user numbers.

  1. 1The sector route does not apply and the volume route looks comfortable, so the company assumes the duty does not arise.
  2. 2The third limb is systematic and large-scale monitoring of behaviour, which is a description of what the analytics stack does rather than a category of company.
  3. 3Session recording plus behavioural profiling plus automated targeting is the textbook example of the activity the limb exists to catch.
  4. 4The assessment turns on what the processing does, so it has to be documented as an assessment rather than assumed as an answer.

Companies rarely describe their own analytics as monitoring, which is exactly why this limb is missed. The safer habit is to write down why the duty does not apply, because that document is what a supervisor asks for.

Illustrative. Whether particular processing is systematic and large-scale monitoring is assessed on the facts.

What this article does not decide

Whether your organisation is caught, and by which route, depends on what you actually process and on the current acts of the Personal Data Protection Service. Nor does appointing an officer make an organisation compliant: the officer monitors compliance, and an officer appointed over a programme that does not exist simply has a better view of the gap.

General information, not legal advice. The categories, thresholds and tasks are set by the Law of Georgia on Personal Data Protection and by acts of the supervisory authority, and change.

Похожие статьи