Georgia DPL crosswalk to major DP regimes. EU GDPR (Regulation (EU) 2016/679): post-2023 amendments substantially aligned + most GDPR concepts (extraterritorial scope + 7 lawful bases + 8 special-category bases + 7 data subject rights + DPO + DPIA + 72-hour breach + cross-border SCC/BCR + administrative fines) are now in Georgia DPL with some local adaptations; ADEQUACY DECISION not yet granted but pursued via EU accession. EU LAW ENFORCEMENT DIRECTIVE (EU) 2016/680: Georgia has separate regime for personal data processing by competent authorities for criminal-offence purposes + coordinated with DPL. EU AI ACT (Regulation (EU) 2024/1689): Georgia may align via EU accession; high-risk AI systems + biometric identification + emotion recognition + automated decision-making + EU AI Act competent authorities likely include PDPS. EU NIS2 (Directive (EU) 2022/2555): Cybersecurity Act 2025 anticipated to transpose + essential + important entity registration + incident reporting. COE CONVENTION 108+: Georgia signatory + ratification anticipated 2025-2026 + Convention 108+ provides global DP framework + 55+ state parties + interoperability with non-EU jurisdictions. CONVENTION ON CYBERCRIME (Budapest Convention): Georgia signatory + criminalises unauthorised personal data access + interception. INTERPOL + EUROPOL cooperation: separate data protection agreements with international policing organisations. BILATERAL ARRANGEMENTS: with EU/EEA + US + UK + Israel + Turkey + Armenia + Azerbaijan + Russia - varying DP cooperation levels.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.