TrustlexGeorgia business setup
Назад к аналитике
Compliance

Outsourcing the Data Protection Officer Role in Georgia

The officer must be independent, reachable and free of conflict - three conditions that are hard to satisfy with an internal appointment in a small company. When outsourcing works, what it must include, and the two ways it is done badly.

Beka Shakulashvili · Основатель и управляющий партнёр 17 августа 2026 г. 10 мин чтения
Информационный перевод. Оригинал статьи составлен на английском языке; при расхождениях преимущество имеет английская версия. Материал носит общий характер и не является юридической или налоговой консультацией.

Once an organisation is caught by the officer duty, the practical question is who holds the role. In a company of fifteen people there is often nobody who can hold it properly: the candidates all run something the officer is supposed to monitor. That is the problem an external appointment solves, and the reason the role is commonly outsourced rather than filled internally.

The role can sit outside the organisation. The accountability cannot.

External

Appointment permitted

The officer need not be an employee

Independent

The binding condition

No instructions on how to perform the tasks

Named

A person, not a firm

Someone has to be identifiable and reachable

Why an internal appointment often fails

The officer monitors the organisation's compliance and reports to the top of it. That creates two conditions most small organisations cannot meet from inside. The first is independence: the officer must not be told how to reach conclusions. The second is absence of conflict: an officer who also decides how and why personal data is processed ends up monitoring their own decisions.

Law of Georgia on Personal Data Protection (2023)· Status of the personal data protection officer
The officer shall perform the assigned tasks independently and shall not receive instructions concerning their performance; the officer shall not be dismissed or penalised for performing those tasks, and may perform other duties provided that they do not give rise to a conflict of interest.
Stated in outline. The permissibility of an external appointment, and the treatment of conflicts, should be confirmed against the current Law and the acts of the Personal Data Protection Service.

In-house against outsourced

Internal appointmentExternal appointment
Conflict riskHigh in a small company - the candidates run the processingLow - no operational role to conflict with
IndependenceStructurally hard where the officer reports to the person they monitorBuilt in; the engagement letter can secure it
AvailabilityAbsorbed into another full-time jobDefined in the contract, with a response time
CostSalary, or a distraction from the role the person was hired forA monthly fee, sized to the organisation
ContinuityEnds when the person leavesContinues; the provider replaces the individual
What each model gives you, and what it costs.

Outsourcing moves the work, not the accountability. The controller remains responsible for compliance; the officer monitors and advises. Any provider who implies that appointing them transfers liability is selling something the law does not offer.

What an outsourced appointment has to include

  1. 1

    A named individual, identifiable and reachable, rather than a firm in the abstract.

  2. 2

    Published contact details, and the notification of the appointment required by the supervisory authority.

  3. 3

    A contractual guarantee of independence: no instruction on how to reach conclusions, and no penalty for reaching uncomfortable ones.

  4. 4

    A reporting line to the highest level of management, exercised in practice and not only on paper.

  5. 5

    Defined availability - a response time for data subject requests and for contact from the supervisory authority.

  6. 6

    Access: to the processing activities, the systems and the people, because an officer who cannot see the processing cannot monitor it.

Worked example

The head of IT who was appointed to save a salary

A company appoints its head of IT as data protection officer. He knows the systems better than anyone and the appointment costs nothing.

  1. 1He also chooses the systems, sets the retention periods and decides what is logged - that is, he determines how and why personal data is processed.
  2. 2The officer's task is to monitor exactly those decisions, so the appointment asks him to audit himself.
  3. 3When a supervisory contact arrives, the conflict is visible on the organisation chart before anyone reads a policy.
  4. 4The company now has two problems: the underlying data protection question, and an appointment that does not do what an appointment is for.

The cheapest appointment is the one most likely to be defective. Conflict of interest is assessed by what the person decides, not by how well they understand the technology.

Illustrative. Whether a particular role conflicts is assessed on the facts of what that person decides.

Worked example

The officer nobody could find

An organisation appoints an external officer, signs the contract, and files it. No contact details are published, the supervisory authority is not notified, and the appointment is not mentioned in the privacy notice.

  1. 1A data subject exercising their rights has no route to the officer and contacts the supervisory authority instead.
  2. 2The authority asks for the officer's details and the date of appointment, and the organisation produces a contract nobody outside it could have known about.
  3. 3The appointment existed, and every function that depends on the officer being reachable did not.
  4. 4The fix is administrative and takes an afternoon; the impression created by the enquiry lasts considerably longer.

An officer is a contact point. An appointment that has not been published and notified provides the cost of the role and none of its purpose.

Illustrative. Notification and publication requirements are set by the supervisory authority; confirm the current form.

How Trustlex does it

We hold the role as a named individual under a monthly engagement: appointment and notification, the contact point for data subjects and for the Personal Data Protection Service, an annual review of processing activities, and advice on higher-risk processing when it comes up. What we do not do is imply that appointing us makes the organisation compliant - the officer monitors compliance, and building the programme underneath is separate work we will quote for honestly.

General information, not legal advice. Whether your organisation must appoint an officer, and what the appointment must contain, depends on your processing and on the acts of the supervisory authority in force at the time.

Похожие статьи