Law on Personal Data Protection art. 19 — a GDPR-shaped automated-decision right whose exceptions cover only profiling, whose safeguards must be asked for, and whose fine tops out at GEL 20 000
Binds Controllers and processors. Art. 2(1) applies the Law to processing wholly or partly by automated means within the territory of Georgia, to non-automated processing of data forming part of or destined for a filing system, and — the extraterritorial hook — to processing by a controller not established in Georgia using technical means available in Georgia, except where those means serve solely to transit data. That is a means-based test rather than the GDPR's targeting test, so it can reach a foreign operator with equipment in Georgia and no Georgian customers. Such a controller must appoint a special representative in Georgia before processing begins (art. 36). Art. 19 sits in Chapter III (arts. 13-25), the rights chapter, so it binds anyone who is a controller for the decision in question. Art. 2(2)-(4) carve out purely personal or household processing and put semi-automated and non-automated processing of state-secret data for crime prevention, investigation and prosecution outside the Law; automated and semi-automated processing by those same institutions stays inside it. No sectoral limit and no size threshold applies to art. 19 — the SME relief in this Law runs to the data protection officer duty (art. 33) and to the size of the fine, never to the automated-decision right.. Art. 19 of the Law of Georgia on Personal Data Protection (No. 3144-XIმც-Xმპ of 14 June 2023) is titled «ავტომატიზებული ინდივიდუალური გადაწყვეტილების მიღება და მასთან დაკავშირებული უფლებები» — automated individual decision-making and related rights. Art. 19(1) gives the data subject the right not to be subject to a decision taken solely by automated means, including on the basis of profiling, which produces for them a legal effect or an effect of other substantial significance. Three features separate it from GDPR art. 22, and all three are in the Georgian text, not artefacts of translation. First, the exception clause is narrower than the prohibition it qualifies. Art. 19(1) reads «გარდა იმ შემთხვევისა, როდესაც პროფაილინგის საფუძველზე გადაწყვეტილების მიღება» — except where the taking of the decision *on the basis of profiling* is (a) based on the data subject's explicitly expressed consent; (b) necessary for concluding or performing a contract between the data subject and the controller; or (c) provided for by law or by a subordinate normative act issued within delegated statutory powers. The prohibition in the opening limb covers any solely automated decision; the escape hatches are drafted only for profiling-based ones. On the face of the text a solely automated decision that does not rest on profiling — a hard-coded threshold rule, for instance — has no exception route at all. Second, the safeguards are reactive. Art. 19(2) opens «მონაცემთა სუბიექტის შესაბამისი მოთხოვნისა» — upon the data subject's respective request — the controller must take appropriate measures to protect the subject's rights, freedoms and legitimate interests, including by involving human resource in the decision-making process, and by giving the subject the possibility to express a view and to contest the decision. GDPR art. 22(3) makes the same three safeguards a standing duty the controller owes without being asked; Georgia makes the subject go first, and gives no deadline for the controller's answer. Third, the human-review carve-out is inverted in the official English translation and must be read from the Georgian. The Georgian parenthesis is «(გარდა ამ მუხლის პირველი პუნქტის „გ“ ქვეპუნქტით გათვალისწინებული შემთხვევისა)» — human involvement is required *except* in the case under paragraph 1(c), the law-or-subordinate-act limb. matsne's English renders this as «including by involving human resources in the decision-making as provided for by paragraph 1(c)», which says the opposite: that human involvement attaches to the statutory limb. The Georgian reading is the GDPR-aligned one — human review for the consent and contract routes, none for decisions the legislature itself mandated — and the Georgian text governs. Art. 19(3) permits special-category data in such decisions only in the cases at art. 6(1)(a), (f) and (j), and only where appropriate safeguards for the subject's rights, freedoms and legitimate interests exist. The transparency limb is request-triggered, not proactive. Art. 13(1)(g) entitles the data subject, on request and free of charge, to «the decision made as a result of automated processing, including profiling, and the logic involved in making such a decision, as well as its impact on the processing and the expected results of the processing», answered within 10 working days and extensible by 10 more. But arts. 24 and 25 — the proactive notice lists for data collected from the subject and from third parties, the slots occupied by GDPR arts. 13(2)(f) and 14(2)(g) — were read item by item and contain no automated-decision or logic item at all. A Georgian controller therefore never has to volunteer that a decision was machine-made; the subject has to know to ask. The DPIA duty is independent and unconditional. Art. 31(2)(a) makes a data protection impact assessment mandatory whenever a controller «makes decisions, in a fully automated manner, including on the basis of profiling, having legal, financial or other significant consequences for a data subject» — no high-risk screening test first, and note that it adds *financial* consequences to the trigger, which GDPR art. 35(3)(a) does not name. Art. 31 and its penalty at art. 80 commenced on 1 June 2024, three months after art. 19 itself.
In force since 1 March 2024. Art. 90(2) of the Law names articles 7-30 among those commencing on that date, which carries art. 19 and its penalty route at art. 72; the Law itself was promulgated on the website of the Legislative Herald on 3 July 2023 but art. 90(1) commenced only the final provisions then. The DPIA trigger at art. 31(2)(a) and its penalty at art. 80 followed on 1 June 2024 under art. 90(3). Art. 89 declared the previous Law on Personal Data Protection of 28 December 2011 invalid from the same 1 March 2024 date, and art. 88(1) keeps the 2011 Law alive only for administrative liability for offences committed before it. Art. 19 has not been amended: the consolidated text as at 10 June 2026 carries no amendment footnote on art. 19, while thirteen other articles carry one for Law of Georgia No 1289 of 17 December 2025. That amendment did not touch the rule but did move the regulator — see the max_penalty field.
Stated maximum penalty — GEL 20 000 in total, which is roughly USD 7 400 — the lowest ceiling of any GDPR-family automated-decision rule in the atlas. Breach of art. 19 is an administrative offence under art. 72, «violation of the rights of a data subject provided for by Chapter III (except for Article 22)». The tariff is fixed, not a range: art. 72(1) gives a warning or GEL 1 000 for a natural person, public institution, non-commercial legal entity, or an undertaking whose annual turnover does not exceed GEL 500 000, and GEL 1 500 for a legal person, branch of a foreign enterprise or individual entrepreneur above that turnover line. Art. 72(2) raises it to GEL 2 000 / 3 000 where two or more Chapter III rights are violated; art. 72(3) and (4) raise the same two tiers to GEL 1 500 / 3 000 and GEL 3 000 / 5 000 respectively where an aggravating circumstance is present. Failing the art. 31 impact assessment is a separate offence under art. 80 at GEL 2 000 / 3 000, or GEL 3 000 / 5 000 aggravated. Art. 64(2) then caps the aggregate: where offences are found in a single inspection or dealt with in one set of proceedings, total fines may not exceed GEL 10 000 for the lower tier and GEL 20 000 for the upper. Art. 64(3) bars double-counting the same act across articles. Enforcement passed from the Personal Data Protection Service to the State Audit Office of Georgia and the Auditor General under Law of Georgia No 1289 of 17 December 2025 (website, 23 December 2025), which rewrote Chapter VI as «Principles of Activities of the State Audit Office in the Field of Data Protection»; the data subject's route under art. 22 now runs to the State Audit Office, a court, or a superior administrative body. Art. 52 non-monetary measures may be imposed alongside a fine.