Market-leading Company

A full-scope Data Protection Officer service for your organization

700+ locationsacross Georgia
GEL 2.5B+annual turnover of our partner organizations
Since 2024, having a DPO has been required by law- we make legal compliance simpler for your organization
What we do

Services for Private and Public Organizations

We provide your organization with every component of data protection support — from personal data protection audits to employee training.

DPO ოფისი

Full Performance of the Data Protection Officer Function

A certified Data Protection Officer will perform the DPO functions for your organization.

Personal Data Processing Audit and Recommendations

We assess personal data processing activities, review documentation, examine infrastructure and information technology processes, develop specific recommendations, and support their implementation.

Preparation of Personal Data Protection and Processing Regulations

We prepare and update policies, protocols, guidelines, instructions, internal rules, document templates, and other materials tailored to your organization’s activities.

Employee Consultation and Training

We provide ongoing awareness-raising and practical training for employees on personal data protection matters, including updates on legal and regulatory developments.

Incident Response

We support the identification, assessment, registration, and management of incidents, help minimize potential harm, and coordinate communication with data subjects and the supervisory authority.

Representation Before the Supervisory Authority

We represent and support your organization in communications with the Personal Data Protection Service, including coordination and implementation of its instructions and requirements.

Guarantee

Financial responsibility for the services provided

We assume financial responsibility for the services we provide. Your interests are protected not only through our professionalism, but also through a contractual guarantee of compensation for potential damage.

Company

About Us

Data Protection Officer LLC helps private and public organizations process personal data lawfully and securely.

DPO ოფისი

Our service covers the performance of the Data Protection Officer function, audits of data-processing activities and risk assessments, preparation of the necessary documentation, and support with implementing recommendations.

Our team of certified Data Protection Officers provides partner organizations with ongoing advice, compliance monitoring, and employee training. Our goal is to establish a well-functioning data protection system that complies with Georgian law and works effectively in practice.

Management

Our Team

Dr. Nika Asvanua

Dr. Nika Asvanua

CEO
LinkedIn profile →
Dr. George Mirianashvili

Dr. George Mirianashvili

COO
LinkedIn profile →
Blog

Latest News

Partnership

Our Partners

Trusted by organizations from every sector.

FAQ

Answers to the most common questions about personal data protection and Data Protection Officer (DPO) services.

What is personal data?

Personal data is any information through which a person can be identified, directly or indirectly.

Examples include a person’s first and last name, personal identification number, telephone number, email address, address, photograph, video recording, information about a person’s health, banking information, place of employment, and information about online activity.

Who is required to appoint a Data Protection Officer?

The appointment or designation of a Data Protection Officer is mandatory for:

  • Public institutions
  • Insurance organizations
  • Commercial banks
  • Microfinance organizations
  • Credit bureaus
  • Electronic communications companies
  • Airlines and airports
  • Medical institutions

It is also mandatory for any organization that:

  • Processes the personal data of no more than 3% of Georgia’s population
  • Processes special categories of personal data relating to no more than 1% of Georgia’s population
  • Carries out systematic and large-scale monitoring of people’s behaviour

What is meant by systematic and large-scale monitoring of people’s behaviour?

Systematic and large-scale monitoring includes, among other activities:

  • Tracking the online activity of registered users
  • Profiling individuals or assigning scores to them for risk-assessment purposes
  • Monitoring the behaviour of children, pupils, students, and trainees by kindergartens, schools, vocational education institutions, and higher education institutions
  • Behavioural advertising based on personal data

When assessing other activities, consideration is given to how frequently and for how long the monitoring is carried out, how many people it covers, the volume and types of data processed, and the extent of its geographical coverage.

Ordinary video surveillance used solely to protect an office, workplace, or supporting infrastructure is not regarded as systematic and large-scale monitoring for this purpose. An exception applies to the use of “smart cameras” where the system automatically analyses individuals or their behaviour.

What does a Data Protection Officer do?

A Data Protection Officer helps an organization process personal data lawfully and securely. The Data Protection Officer’s main functions include:

  • Advising the organization and its employees
  • Providing information about legislative changes in the field of data protection
  • Assessing data-processing activities and related risks
  • Participating in the preparation of internal policies, rules, and other documents
  • Monitoring compliance with the law and the organization’s internal rules
  • Reviewing individuals’ requests and complaints
  • Participating in the data protection impact assessment process
  • Assisting with the management of security incidents
  • Training employees
  • Communicating with the State Audit Office of Georgia and representing the organization

A Data Protection Officer helps the organization identify problems at an early stage and prevent infringements.

Must the Data Protection Officer be an employee of the organization?

No. The Data Protection Officer function may be performed by a company that provides the service under a contract.

The Data Protection Officer must have appropriate professional expertise, operate independently, and be free from conflicts of interest. The organization must involve the Data Protection Officer in a timely manner in important decisions concerning data processing and provide the resources needed to perform the role.

Within 10 working days of appointing or replacing the Data Protection Officer, the organization must notify the State Audit Office of Georgia of the officer’s identity and contact details. This information must also be published on the organization’s website or made available through another accessible means.

Can a company be sanctioned for failing to designate a Data Protection Officer?

If an organization is legally required to appoint a Data Protection Officer and fails to meet that obligation, it will incur administrative liability.

What are the penalties for breaching personal data protection law?

The law does not prescribe a single uniform fine. Liability depends on the nature and seriousness of the infringement, the organization’s annual turnover, and the existence of aggravating or mitigating circumstances.

The law provides for both warnings and fines of varying amounts. A fine for an individual infringement may be as high as GEL 10,000.

If several infringements are identified in a single proceeding, the total amount of the fines may be:

  • Up to GEL 10,000 for an individual, public institution, non-profit organization, or business with an annual turnover of up to GEL 500,000
  • Up to GEL 20,000 for a commercial organization with an annual turnover exceeding GEL 500,000

In addition to a fine, the organization may be required to remedy the infringement, temporarily or permanently cease processing, or block, erase, destroy, or depersonalize the data, among other measures.

Is consent always required to process personal data?

No. Consent is only one of the legal bases for processing personal data.

Personal data may also be processed to perform a contract, comply with a legal obligation, protect an important legitimate interest, or on another basis provided by law.

In each case, the purpose of processing and the legal basis corresponding to that purpose must be determined in advance. Merely obtaining consent cannot make unlawful or purpose-incompatible processing lawful.

What rights do individuals have in relation to their personal data?

An individual has the right to:

  • Find out whether their personal data is being processed
  • Receive information about the purpose and legal basis of the processing
  • Access their personal data and obtain a copy
  • Request the correction or updating of inaccurate data
  • Request the blocking of data in cases provided by law
  • Request that processing cease or that data be erased or destroyed
  • Withdraw consent previously given
  • Challenge the unlawful processing of their data

An organization should have an effective procedure for receiving, reviewing, and responding to such requests in a timely manner.

Which state authority supervises compliance with the Law of Georgia on Personal Data Protection?

State supervision is carried out by the State Audit Office of Georgia, which is authorized to conduct scheduled and unscheduled inspections of organizations.

How does Data Protection Officer LLC support organizations?

Data Protection Officer LLC provides organizations with a full range of personal data protection services, including:

  • Assessing whether the organization is required to appoint a Data Protection Officer
  • Providing Data Protection Officer services
  • Conducting compliance audits and risk assessments
  • Mapping and documenting data-processing activities
  • Preparing policies, rules, consent forms, agreements, and other documents
  • Training employees
  • Providing ongoing legal advice
  • Assisting with the management of security incidents
  • Reviewing individuals’ requests and complaints
  • Communicating with the State Audit Office of Georgia and representing the organization

Couldn't find the answer to your question?

Contact us and our team will answer any questions you may have about personal data.

Contact Us
Contact

Contact Us

Reach out anytime - we will gladly provide a consultation.

Successful companies trust us with their data protection

Contact us