Georgia DPL cross-border + breach + special-context regimes. CROSS-BORDER TRANSFERS (Art. 35-37 - GDPR Chapter V aligned): personal data may be transferred outside Georgia only where: (a) ADEQUACY - the destination country provides adequate level of protection (Minister of Justice determination + EU/EEA + Convention 108+ countries); (b) APPROPRIATE SAFEGUARDS - binding corporate rules + standard contractual clauses (SCCs) + approved code of conduct + approved certification + ad hoc clauses approved by PDPS; (c) DEROGATIONS - explicit consent + contract necessity + public interest + legal claims + vital interests + register access. BREACH NOTIFICATION (Art. 38 - 2023 NEW + GDPR Art. 33-34 aligned): controllers must notify the PDPS within 72 HOURS of becoming aware of a breach likely to result in risk to natural persons; without undue delay to data subjects if breach likely to result in HIGH RISK to rights and freedoms; documented incident records. VIDEO SURVEILLANCE (Art. 39 - SPECIFIC REGIME): permitted only for: (a) public-property protection; (b) safety/security; (c) statutorily mandated; (d) consent-based + with transparency notice including controller identity + purpose + retention; PROHIBITED in toilets + changing rooms + medical examination rooms + private dwellings + religious meeting places. PERSONAL DATA OF DEFENCE + INTELLIGENCE: separately regulated. DIRECT MARKETING (Art. 40): consent required for e-marketing + soft opt-in for similar products to existing customers + clear unsubscribe + suppression list maintenance.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.