Georgia DPL: Personal Data Protection Service (PDPS), Enforcement and Sanctions
Georgia Law on Personal Data Protection (2012) GeDPL-PDPS-Enforcement-Sanctions: Personal Data Protection Service (PDPS), Enforcement Powers and Sanctions
Personal Data Protection Service (PDPS - Sakartvelos Personalur Monatsemta Datsvis Sammartveloba) - the Georgian supervisory authority established by the 2012 Law + significantly strengthened by the 2023 amendments. INDEPENDENCE (Art. 40-9): the PDPS is an independent body + the Head is elected by Parliament for a 5-year term + may be re-elected once; financial + functional + structural independence. POWERS (Art. 40-2 + 40-11 + 40-13): (a) MONITORING + INVESTIGATION + COMPLAINT-HANDLING; (b) INSPECTION powers including premises entry + records access + interviews + IT systems inspection; (c) GUIDANCE + RECOMMENDATIONS + standards; (d) ENFORCEMENT through INSTRUCTIONS + administrative + criminal referrals; (e) ADMINISTRATIVE FINES (Art. 40-13): per-violation civil penalties up to GEL 20,000 (2023 amendments substantially increased from earlier GEL 200-1,000; the 2023 reform aimed at GDPR-comparable deterrence + further increases anticipated); REPEAT + SERIOUS violations may attract higher penalties; CRIMINAL SANCTIONS per Criminal Code Article 157 for unauthorised disclosure of personal data + Article 158 for unlawful collection or use + up to 3 years imprisonment + fine. APPEALS (Art. 40-13): to PDPS + administrative court + cassation. INTERNATIONAL COOPERATION (Art. 40-2): PDPS engages with EU EDPB + Council of Europe Convention 108 Consultative Committee + Berlin Group International Working Group on Data Protection in Technology + bilateral DP authorities cooperation. ENGAGEMENT: organizations should maintain PDPS-CONTACT-POINT + procedure for cooperating with audits + complaints + notifications + DPO-PDPS-coordination.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 40 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
ItalyCodice-ePrivacy-Cookies-ElectronicCommunications-Telemarketing-PublicOpposition-TrafficDataRetention-Art121-122-130-132 Italy Codice ePrivacy - Article 121 Electronic Communications + Article 122 Cookies and Tracking + Article 130 Unsolicited Direct Marketing + Article 132 Traffic Data Retention + Italian Public Opposition Register (Registro delle Opposizioni)