We provide your organization with every component of data protection support — from personal data protection audits to employee training.
A certified Data Protection Officer will perform the DPO functions for your organization.
We assess personal data processing activities, review documentation, examine infrastructure and information technology processes, develop specific recommendations, and support their implementation.
We prepare and update policies, protocols, guidelines, instructions, internal rules, document templates, and other materials tailored to your organization’s activities.
We provide ongoing awareness-raising and practical training for employees on personal data protection matters, including updates on legal and regulatory developments.
We support the identification, assessment, registration, and management of incidents, help minimize potential harm, and coordinate communication with data subjects and the supervisory authority.
We represent and support your organization in communications with the Personal Data Protection Service, including coordination and implementation of its instructions and requirements.
We assume financial responsibility for the services we provide. Your interests are protected not only through our professionalism, but also through a contractual guarantee of compensation for potential damage.
Data Protection Officer LLC helps private and public organizations process personal data lawfully and securely.
Our service covers the performance of the Data Protection Officer function, audits of data-processing activities and risk assessments, preparation of the necessary documentation, and support with implementing recommendations.
Our team of certified Data Protection Officers provides partner organizations with ongoing advice, compliance monitoring, and employee training. Our goal is to establish a well-functioning data protection system that complies with Georgian law and works effectively in practice.
Trusted by organizations from every sector.
Answers to the most common questions about personal data protection and Data Protection Officer (DPO) services.
Personal data is any information through which a person can be identified, directly or indirectly.
Examples include a person’s first and last name, personal identification number, telephone number, email address, address, photograph, video recording, information about a person’s health, banking information, place of employment, and information about online activity.
The appointment or designation of a Data Protection Officer is mandatory for:
It is also mandatory for any organization that:
Systematic and large-scale monitoring includes, among other activities:
When assessing other activities, consideration is given to how frequently and for how long the monitoring is carried out, how many people it covers, the volume and types of data processed, and the extent of its geographical coverage.
Ordinary video surveillance used solely to protect an office, workplace, or supporting infrastructure is not regarded as systematic and large-scale monitoring for this purpose. An exception applies to the use of “smart cameras” where the system automatically analyses individuals or their behaviour.
A Data Protection Officer helps an organization process personal data lawfully and securely. The Data Protection Officer’s main functions include:
A Data Protection Officer helps the organization identify problems at an early stage and prevent infringements.
No. The Data Protection Officer function may be performed by a company that provides the service under a contract.
The Data Protection Officer must have appropriate professional expertise, operate independently, and be free from conflicts of interest. The organization must involve the Data Protection Officer in a timely manner in important decisions concerning data processing and provide the resources needed to perform the role.
Within 10 working days of appointing or replacing the Data Protection Officer, the organization must notify the State Audit Office of Georgia of the officer’s identity and contact details. This information must also be published on the organization’s website or made available through another accessible means.
If an organization is legally required to appoint a Data Protection Officer and fails to meet that obligation, it will incur administrative liability.
The law does not prescribe a single uniform fine. Liability depends on the nature and seriousness of the infringement, the organization’s annual turnover, and the existence of aggravating or mitigating circumstances.
The law provides for both warnings and fines of varying amounts. A fine for an individual infringement may be as high as GEL 10,000.
If several infringements are identified in a single proceeding, the total amount of the fines may be:
In addition to a fine, the organization may be required to remedy the infringement, temporarily or permanently cease processing, or block, erase, destroy, or depersonalize the data, among other measures.
No. Consent is only one of the legal bases for processing personal data.
Personal data may also be processed to perform a contract, comply with a legal obligation, protect an important legitimate interest, or on another basis provided by law.
In each case, the purpose of processing and the legal basis corresponding to that purpose must be determined in advance. Merely obtaining consent cannot make unlawful or purpose-incompatible processing lawful.
An individual has the right to:
An organization should have an effective procedure for receiving, reviewing, and responding to such requests in a timely manner.
State supervision is carried out by the State Audit Office of Georgia, which is authorized to conduct scheduled and unscheduled inspections of organizations.
Data Protection Officer LLC provides organizations with a full range of personal data protection services, including:
Contact us and our team will answer any questions you may have about personal data.
Contact UsReach out anytime - we will gladly provide a consultation.