Mandatory DPOs in Georgia: When Must You Appoint One?

Under the Law of Georgia on Personal Data Protection, appointing a Data Protection Officer is not optional for every business, but for some it is a firm legal obligation, and getting the analysis wrong carries real regulatory risk. The question is not whether you process personal data, but whether you meet the statutory trigger.

The Legal Test: Article 33

Article 33 obliges specific categories of controller and processor to designate a DPO:

  • public institutions
  • insurance organisations
  • commercial banks & microfinance organisations & credit bureaus
  • electronic communication companies
  • airlines & airports 
  • medical institutions.

The same obligation captures any controller or processor, regardless of sector, that processes the data of a significant number of data subjects or carries out systematic, large-scale monitoring of individuals’ behaviour.

This is a two-track test: sector membership, or processing scale and nature. A small clinic and a large fintech platform can both fall inside the rule, for different reasons, so the analysis must start with actual activities, not an industry label.

What Counts as Large-Scale

The Law does not leave “significant number of data subjects” to guesswork: it is tied to the national census, and processing concerning at least three percent of Georgia’s population is treated as significant. Below that threshold, the question turns on whether monitoring is systematic and large-scale in volume, reach or duration, a standard the State Audit Office, Georgia’s data protection authority since March 2026, applies case by case. A separate act of the Auditor General lists controllers exempted from the obligation.

Special Categories, Role and Independence

Processing special categories of data, health, biometric, genetic, ethnic origin, political or religious belief, criminal record, does not by itself trigger the obligation; what matters is the scale and systematic nature of that processing under Article 33. Where a DPO is appointed, the role is advisory and supervisory, not a transfer of legal liability: informing staff, reviewing internal policy and impact assessments, liaising with the State Audit Office and data subjects, and monitoring compliance. The Law requires genuine independence: adequate resources, no conflicting duties, and reporting to the highest level of governance. A DPO may be an employee or an outsourced specialist, and one officer may serve several group entities, provided the function is performed properly for each.

Sector Relevance

In practice, the rule reaches medical institutions and banks by category, and tech platforms, telecoms and large e-commerce operators once their monitoring or data volumes cross the statutory scale. A boutique consultancy handling ordinary client and payroll data typically sits outside the rule, though a voluntary DPO remains sound governance.

Quick Self-Check

  • Are you a listed entity: bank, insurer, telecom, airline, airport, medical institution or public body?
  • Do you process data concerning three percent or more of Georgia’s population?
  • Is your monitoring of individuals systematic and large-scale?
  • Have you documented the analysis, even where the answer is no?

How NOMOS GEORGIA Can Help

Getting the DPO analysis wrong, in either direction, creates unnecessary cost or real regulatory exposure. 

NOMOS GEORGIA advises Georgian and international businesses on personal data compliance, from the initial trigger assessment through to appointing and supporting a qualified officer.

Speak with our data protection team before your next compliance review.

Table Of Contents

Picture of Lika Tsintsabadze

Lika Tsintsabadze

Lika Tsintsabadze is a business lawyer, the Founder and Managing Partner of Nomos Georgia law firm. She advises local and international clients on corporate law, foreign investment, tax planning, regulatory compliance, and business structuring in Georgia.

Consultation Request

By clicking Submit Form, you agree to our Privacy Policy and Terms of Service.