Georgia Law on Personal Data Protection (2012)
Georgia DPL: Personal Data Protection Service (PDPS), Enforcement and Sanctions

Georgia Law on Personal Data Protection (2012) GeDPL-PDPS-Enforcement-Sanctions: Personal Data Protection Service (PDPS), Enforcement Powers and Sanctions

Personal Data Protection Service (PDPS - Sakartvelos Personalur Monatsemta Datsvis Sammartveloba) - the Georgian supervisory authority established by the 2012 Law + significantly strengthened by the 2023 amendments. INDEPENDENCE (Art. 40-9): the PDPS is an independent body + the Head is elected by Parliament for a 5-year term + may be re-elected once; financial + functional + structural independence. POWERS (Art. 40-2 + 40-11 + 40-13): (a) MONITORING + INVESTIGATION + COMPLAINT-HANDLING; (b) INSPECTION powers including premises entry + records access + interviews + IT systems inspection; (c) GUIDANCE + RECOMMENDATIONS + standards; (d) ENFORCEMENT through INSTRUCTIONS + administrative + criminal referrals; (e) ADMINISTRATIVE FINES (Art. 40-13): per-violation civil penalties up to GEL 20,000 (2023 amendments substantially increased from earlier GEL 200-1,000; the 2023 reform aimed at GDPR-comparable deterrence + further increases anticipated); REPEAT + SERIOUS violations may attract higher penalties; CRIMINAL SANCTIONS per Criminal Code Article 157 for unauthorised disclosure of personal data + Article 158 for unlawful collection or use + up to 3 years imprisonment + fine. APPEALS (Art. 40-13): to PDPS + administrative court + cassation. INTERNATIONAL COOPERATION (Art. 40-2): PDPS engages with EU EDPB + Council of Europe Convention 108 Consultative Committee + Berlin Group International Working Group on Data Protection in Technology + bilateral DP authorities cooperation. ENGAGEMENT: organizations should maintain PDPS-CONTACT-POINT + procedure for cooperating with audits + complaints + notifications + DPO-PDPS-coordination.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 40 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

FDA 21 CFR Part 11 · 3 controls

  • Part11.30 Controls for open systems (21 CFR §11.30)
  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
  • Part11.RecordRetention Record protection + retention + readiness for inspection (21 CFR §11.10(b) + (c))

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.6 Data protection and backup
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)

ISO/IEC 27400:2022 · 2 controls

  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion
  • ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
  • ItalyCodice-ePrivacy-Cookies-ElectronicCommunications-Telemarketing-PublicOpposition-TrafficDataRetention-Art121-122-130-132 Italy Codice ePrivacy - Article 121 Electronic Communications + Article 122 Cookies and Tracking + Article 130 Unsolicited Direct Marketing + Article 132 Traffic Data Retention + Italian Public Opposition Register (Registro delle Opposizioni)
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • ASD37-27 Outbound data loss prevention (Very Good)
  • AL-DPA-14 Direct Marketing
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • RUSPD-4 Special Categories, Biometric Data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 40 it maps to, and the evidence behind each claim, over MCP and REST.