Jurisdictions
Georgia

Data protection and localisation requirements in Georgia under the Law on Entrepreneurs (2021): what changed in 2027

Following amendments that took effect in early 2027, Georgia's framework governing data protection and personal data localisation has moved from a principles-based arrangement into a more operationally prescriptive regime. For foreign companies with Georgian subsidiaries, branch offices, or significant business relationships in the country, the Law on Entrepreneurs (2021) now intersects directly with personal data obligations in ways that require deliberate compliance attention. What was previously a question of best practice has, in several respects, become a question of regulatory obligation — with consequences for registration, corporate governance, and cross-border data flows that foreign in-house counsel and their Georgian advisers must now address together.

H2: § I. What changed — the before and after

Before the 2027 amendments, Georgia's data protection regime operated primarily under the Law on Personal Data Protection, which established general principles of data processing, consent requirements, and the supervisory role of the Personal Data Protection Service. The Law on Entrepreneurs (2021), for its part, set out the foundational framework for company registration, governance, and the obligations of legal entities operating in Georgia. The two instruments operated largely in parallel rather than in combination: a company's regulatory registration obligations and its data handling practices were treated as distinct compliance tracks.

The 2027 amendments altered this relationship in material respects. First, they introduced explicit data governance disclosure requirements at the point of company registration and periodic reporting under the Law on Entrepreneurs framework. Foreign-incorporated entities registering a Georgian branch or subsidiary are now required to identify, at the registration stage, the categories of personal data processed, the data controller responsible within the Georgian entity, and — where data is transferred outside Georgia — the legal basis and receiving jurisdiction for those transfers. This information is incorporated into the public registry record.

Second, and of direct significance to foreign investors, the amendments introduced a localisation requirement for certain categories of personal data collected in connection with Georgian-resident customers or employees. Georgian-sourced personal data in defined sensitive categories must now be stored on servers located within Georgia or in jurisdictions that the Personal Data Protection Service has formally recognised as providing an adequate level of protection. The list of recognised jurisdictions is published and maintained by the Service; as of the date of this article, it reflects broadly the Georgian regulator's assessment of countries whose data protection standards are comparable to Georgia's own legislative framework.

Third, the amendments strengthened enforcement mechanisms. The Personal Data Protection Service acquired expanded investigatory powers, including the authority to request access to data processing records from entities registered under the Law on Entrepreneurs. Fines for non-compliance were restructured on a turnover-based scale, replacing the previous fixed-penalty model.

H2: § II. Who is affected — and does this apply to your Georgian entity?

The practical scope of the 2027 changes depends on the type and scale of the Georgian entity a foreign company operates. Three categories of foreign investor are most directly affected.

Foreign companies with Georgian subsidiaries registered under the Law on Entrepreneurs are the primary addressees of the new disclosure and localisation obligations. If the subsidiary processes personal data of Georgian residents — whether customers, employees, or counterparties — the localisation and disclosure rules apply from the date of registration for new entities, and from the first annual reporting cycle following the amendments' entry into force for entities already registered.

Foreign companies operating through Georgian branch offices face a comparable set of obligations. A branch registered in Georgia under the Law on Entrepreneurs is treated as a Georgian entity for the purposes of these provisions. The foreign parent's data governance documentation will need to be reviewed for compatibility with Georgian requirements, particularly where centralised data storage or processing is operated from the parent jurisdiction.

Foreign companies without a Georgian legal presence but conducting regulated commercial activities in Georgia — for example, through digital platforms serving Georgian-resident users — face a narrower but still operative set of obligations under the data protection framework, though these are enforced primarily through the Law on Personal Data Protection rather than the Law on Entrepreneurs. The practical distinction matters: enforcement routes and responsible authorities differ depending on which instrument applies.

For in-house counsel at multinational companies reviewing Georgian compliance status, the key threshold question is whether the Georgian entity holds a registration under the Law on Entrepreneurs. If it does, the 2027 amendments apply directly, and the compliance timeline is measured from the entity's registration date or the first reporting period following the amendments, whichever is earlier.

[CTA: If your company operates a registered entity in Georgia and you require an assessment of data localisation compliance under the Law on Entrepreneurs — make an enquiry: info@vetrovpartners.com | WhatsApp/Telegram: +7 (983) 510-38-76]

H2: § III. What foreign clients should do now

The practical response to the 2027 changes involves three areas of work that are best addressed in sequence rather than simultaneously.

The first is a data mapping exercise scoped specifically to the Georgian entity. This means identifying what personal data is collected from Georgian residents, in what categories, by which processing systems, and where that data is currently stored. For foreign companies whose Georgian subsidiaries rely on group-level IT infrastructure hosted outside Georgia, this exercise frequently reveals that data flows which were permissible before the amendments now require either a change in storage architecture or a formal legal basis under the recognised-jurisdictions list.

The second area is documentation and registry compliance. The Law on Entrepreneurs registration record must now reflect the data governance information required by the amended provisions. For entities already registered, this means filing an update with the National Agency of Public Registry. For entities being newly incorporated, the required information must be prepared before registration is completed. Gaps in this documentation are among the first items the Personal Data Protection Service examines in a compliance review.

The third area concerns cross-border data transfer arrangements. Foreign companies that transfer Georgian-sourced personal data to their parent or group entities — for HR, payroll, customer management, or CRM purposes — need to verify that the receiving jurisdiction appears on the recognised-jurisdictions list or that an alternative legal basis is available and documented. Where the receiving jurisdiction is not on the list, a data transfer agreement or equivalent instrument aligned with Georgian regulatory standards may be required.

For foreign law firms advising clients with Georgian interests from outside the jurisdiction, the 2027 amendments represent a material compliance development that warrants updating client advice on Georgian entity governance. The intersection of corporate registration obligations with personal data requirements is a pattern increasingly visible across the region — similar developments are underway in Kazakhstan (/jurisdictions/kazakhstan/regulatory-licensing/) and Armenia (/jurisdictions/armenia/regulatory-licensing/) — and early-stage compliance planning is substantially less disruptive than retrospective remediation.

"The 2027 amendments mark a significant step in Georgia's regulatory convergence toward European-standard data governance — an evolution that foreign investors with Georgian entities need to reflect in their compliance programmes now, not at the next audit cycle." — Nino Beridze, Contributing Regional Analyst — Georgia, Vetrov & Partners

The firm advises on Georgian regulatory matters in collaboration with locally admitted Georgian counsel. Initial scoping discussions for cross-border matters involving both Russian and Georgian legal dimensions can be initiated directly with the Vetrov & Partners team.

[CTA: To discuss how the Law on Entrepreneurs amendments affect your Georgian entity's data compliance position — make an enquiry: info@vetrovpartners.com | WhatsApp/Telegram: +7 (983) 510-38-76]

H2: Related reading

  • Company formation in Georgia: a guide for foreign investors (/jurisdictions/georgia/company-formation/) [publisher note: assign cluster article slug on import]
  • Regulatory licensing requirements in Georgia for foreign-owned companies (/jurisdictions/georgia/regulatory-licensing/) [publisher note: assign cluster article slug on import]
  • Georgia jurisdiction overview (/jurisdictions/georgia/)

H2: Frequently asked questions

Q: What specifically changed under the Law on Entrepreneurs (2021) in Georgia in 2027?

A: The 2027 amendments introduced three substantive changes. First, foreign companies registering a Georgian entity must now disclose their data processing categories, the responsible data controller within the Georgian entity, and the legal basis for any cross-border data transfers — all as part of the Law on Entrepreneurs registration record. Second, certain categories of personal data collected from Georgian residents must now be stored in Georgia or in a jurisdiction recognised by the Personal Data Protection Service as providing adequate protection. Third, the Service received expanded investigatory powers and a restructured, turnover-based penalty regime replacing the previous fixed-penalty framework.

Q: Which foreign companies are directly affected by the Georgian data localisation rules?

A: The primary addressees are foreign companies that have registered a subsidiary or branch in Georgia under the Law on Entrepreneurs and that process personal data of Georgian residents — including employees, customers, or commercial counterparties. Existing registered entities are subject to compliance requirements from the first reporting cycle following the amendments' entry into force. Foreign companies operating in Georgia through digital platforms without a registered Georgian legal presence are regulated primarily through the Law on Personal Data Protection rather than the Law on Entrepreneurs, meaning a different enforcement channel applies.

Q: What should foreign companies do first to address the 2027 Georgian data requirements?

A: The most practical starting point is a scoped data mapping exercise for the Georgian entity specifically: identifying what personal data is collected from Georgian residents, where it is stored, and whether current cross-border transfer arrangements are consistent with the amended requirements. This exercise determines whether storage architecture changes are needed, whether registry documentation must be updated, and whether cross-border transfer agreements need to be put in place. Firms advising clients on Georgian matters from outside the jurisdiction should treat this as a standing item in their Georgian entity compliance review.

H2: About Vetrov & Partners

Vetrov & Partners is a Russian boutique law firm established in 2009, recognised by Pravo-300 — Russia's principal legal directory — for eight consecutive years, and listed as a trusted adviser by the German Consulate General in Novosibirsk.

The firm's Regulatory & Licensing practice advises foreign companies on compliance requirements across post-Soviet jurisdictions, including cross-border matters with a Georgian dimension. Georgian-law matters are handled in collaboration with locally admitted Georgian counsel. For matters governed by foreign law or requiring local admission in another jurisdiction, we collaborate with trusted counsel in the relevant jurisdiction. With over 1,000 matters handled since inception, the team provides direct partner-level involvement on every engagement.

Enquiries: info@vetrovpartners.com | WhatsApp / Telegram: +7 (983) 510-38-76 | t.me/vitvetcom

This publication is provided for informational purposes only and does not constitute legal advice under Russian or any other applicable law. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. Vetrov & Partners is a Russian-qualified law firm. For matters governed by foreign law or requiring local admission in another jurisdiction, we collaborate with trusted counsel in the relevant jurisdiction. For advice regarding your particular situation, please contact info@vetrovpartners.com.

— Nino Beridze Contributing Regional Analyst — Georgia, Vetrov & Partners vetrovpartners.com/contributions/