GEORGIA
Since April 2022, last amended in December 2023
Pillar Online sales and transactions |
Indicator Framework for consumer protection applicable to online commerce
Law of Georgia No. 1455-VIIIMS-XMP on the Protection of Consumer Rights (საქართველოს კანონი 1455-VIIIმს-Xმპ მომხმარებლის უფლებების დაცვის შესახებ)
The Law on Consumer Rights provides a comprehensive framework for consumer protection that also applies to online transactions. Arts. 4(d), 10, and 12 include provisions for the protection of e-consumers.
Coverage Horizontal
GEORGIA
N/A
Pillar Online sales and transactions |
Indicator Ratification of the UN Convention on the Use of Electronic Communications in International Contracts
Lack of signature of the UN Convention on the Use of Electronic Communications in International Contracts
Georgia has not signed the United Nations (UN) Convention on the Use of Electronic Communications in International Contracts.
Coverage Horizontal
GEORGIA
N/A
Pillar Online sales and transactions |
Indicator UNCITRAL Model Law on Electronic Commerce
Lack of adoption of UNCITRAL Model Law on Electronic Commerce
Georgia has not adopted national legislation based on or influenced by the United Nations Commission on International Trade Law (UNCITRAL) Model Law on Electronic Commerce.
Coverage Horizontal
GEORGIA
N/A
Pillar Online sales and transactions |
Indicator UNCITRAL Model Law on Electronic Signatures
Lack of adoption of UNCITRAL Model Law on Electronic Signatures
Georgia has not adopted national legislation based on or influenced by the United Nations Commission on International Trade Law (UNCITRAL) Model Law on Electronic Signatures.
Coverage Horizontal
GEORGIA
Since December 2013, last amended in June 2019
Since June 2005, last amended in December 2025
Since June October 2014, last amended in November 2015
Since June 2005, last amended in December 2025
Since June October 2014, last amended in November 2015
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Export restrictions on ICT goods or online services
Law of Georgia No. 1683-Iს on the Control of Military and Dual-Use Goods (საქართველოს კანონი 1683-Iს სამხედრო და ორმაგი დანიშნულების პროდუქციის კონტროლის შესახებ)
Law of Georgia No. 1775 on Licences and Permits (საქართველოს კანონი 1775 ლიცენზიებისა და ნებართვების შესახებ)
Resolution of the Government of Georgia No. 394 on approval of lists of military and dual-purpose products (საქართველოს მთავრობის დადგენილება 394 სამხედრო და ორმაგი დანიშნულების პროდუქციის ნუსხების დამტკიცების შესახებ)
Law of Georgia No. 1775 on Licences and Permits (საქართველოს კანონი 1775 ლიცენზიებისა და ნებართვების შესახებ)
Resolution of the Government of Georgia No. 394 on approval of lists of military and dual-purpose products (საქართველოს მთავრობის დადგენილება 394 სამხედრო და ორმაგი დანიშნულების პროდუქციის ნუსხების დამტკიცების შესახებ)
According to Art. 5 of the Law of Georgia on the Control of Military and Dual-Use Goods, the export of "Dual-Purpose Products" included in the "control lists" outlined in Art. 2(p) is carried out on the basis of an export permit issued in accordance with the Law of Georgia on Licences and Permits, as specified in its Art. 24. Dual-purpose products, as defined in Art. 2(m), include computer software and technologies that serve both civil and military purposes.
The control list, detailed in the Government of Georgia's Resolution No. 394 on the Approval of Lists of Military and Dual-Purpose Products, includes semiconductor photocathodes, electro-optical converters, optical fibre, and optical fibre connectors, among other products. Additionally, Section 21 of Resolution No. 394 provides specific information about the types of software that fall under the licensing regime.
The control list, detailed in the Government of Georgia's Resolution No. 394 on the Approval of Lists of Military and Dual-Purpose Products, includes semiconductor photocathodes, electro-optical converters, optical fibre, and optical fibre connectors, among other products. Additionally, Section 21 of Resolution No. 394 provides specific information about the types of software that fall under the licensing regime.
Coverage Dual-use goods, including computer software, semiconductor photocathodes, optical fiber, optical fiber connectors, electro-optical converters
Sources
- https://web.archive.org/web/20230525130928/http://matsne.gov.ge/ka/document/view/2113659?publication=1
- https://web.archive.org/web/20241206151642/https://www.matsne.gov.ge/ka/document/view/26824?publication=111
- https://web.archive.org/web/20260507153309/https://matsne.gov.ge/en/document/view/2372203?publication=0
- Show more...
GEORGIA
Reported in 2021, last reported in 2023
Pillar Technical standards applied to ICT goods and online services |
Indicator Self-certification for product safety
Supplier Declaration of Conformity allowed for foreign businesses
Self-certification is permitted for radio transmission, electromagnetic interference (EMI), and electromagnetic compatibility (EMC). Foreign companies are authorised to self-certify compliance with these standards through a Supplier Declaration of Conformity (SDoC). The registration of the equipment with the regulatory authority is not required, nor is testing by an accredited laboratory mandatory. When testing is conducted, the selection of the testing laboratory is at the discretion of the supplier or manufacturer.
Coverage Electronic products
GEORGIA
Since March 2006, last amended in June 2022
Pillar Domestic data policies |
Indicator Minimum period for data retention
Regulations on the Rules of Provision of Services and Protection of Consumer Rights in the Sphere of Electronic Communications - Resolution No. 3 of the Georgian National Communications Commission (რეგლამენტი ელექტრონული კომუნიკაციების სფეროში მომსახურების მიწოდების წესებისა და მომხმარებელთა უფლებების დაცვის - საქართველოს კომუნიკაციების ეროვნული კომისიის დადგენილება №3)
Art. 7 of Resolution No. 3 of the Georgian National Communications Commission "Regulations on the Rules of Provision of Services and Protection of Consumer Rights in the Sphere of Electronic Communications" addresses the information that the service provider retains about the user. The service provider must safeguard the following categories of user information for a period of four years: (a) the user's identification and contact details; (b) data related to the equipment or devices transferred to or used by the subscriber; (c) agreements or transactions related to service delivery; (d) payment information; (e) details of services received or provided, including a comprehensive record of incoming and outgoing telephone communications. Art. 3 defines a service provider as an operator of an electronic communications network or an authorised person who has access to the relevant elements or resources thereof and intends to, or is engaged in, provide electronic communication services through the elements or resources of the said network.
An article concerning the information service providers retain about consumers has been included in the Regulations since its initial version. However, it was originally listed as Art. 5, and there were some variations in the specific data categories and the duration of data retention.
An article concerning the information service providers retain about consumers has been included in the Regulations since its initial version. However, it was originally listed as Art. 5, and there were some variations in the specific data categories and the duration of data retention.
Coverage Telecommunications sector
Sources
- https://web.archive.org/web/20250116142813/https://matsne.gov.ge/ka/document/view/5489749?publication=0
- https://web.archive.org/web/20250116143111/https://matsne-gov-ge.translate.goog/ka/document/view/5489749?publication=0&_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=es&_x_tr_pto=wapp
- https://web.archive.org/web/20240226073000/https://matsne.gov.ge/ka/document/view/63556?publication=0
- Show more...
GEORGIA
Since June 2023, entry into force in June 2024, last amended in December 2025
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Law of Georgia on Personal Data Protection, No. 3144 (საქართველოს კანონი პერსონალურ მონაცემთა დაცვის შესახებ)
Art. 31 of Law No. 3144 requires data controllers to conduct data protection impact assessments (DPIAs) in cases where there is a high probability of a threat to the violation of fundamental human rights and freedoms during data processing, taking into account new technologies, categories, the volume of data, and the purposes and means of data processing. In addition, a DPIA is mandatory if the data controller : (i) makes decisions in a fully automated manner, including on the basis of profiling, which may have legal, financial, or other significant consequences for a data subject; (ii) processes data of a special category of a large number of data subjects; or (iii) carries out systematic and large-scale monitoring of data subjects' behaviour in places of public gathering. In the case of a substantial change in data processing, the controller is obliged to update the DPIA report and keep it for the entire period of data processing and for at least one year after termination of processing.
Coverage Horizontal
GEORGIA
Since June 2023, entry into force in June 2024, last amended in December 2025
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Law of Georgia on Personal Data Protection, No. 3144 (საქართველოს კანონი პერსონალურ მონაცემთა დაცვის შესახებ)
Pursuant to Art. 33(1) of Law No. 3144, certain entities are required to appoint or designate a personal data protection officer (DPO). These include public institutions, insurance organisations, commercial banks, microfinance organisations, credit bureaus, electronic communications companies, airlines, airports, and medical institutions, as well as controllers or processors that process the data of a significant number of data subjects or conduct systematic and large-scale monitoring of individuals’ behaviour. Other controllers and processors may appoint a DPO on a voluntary basis.
Coverage Horizontal
GEORGIA
Since June 2005, as amended in August 2014, last amended in December 2025
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Law of Georgia No. 1514 on Electronic Communications (საქართველოს კანონი № 1514 ელექტრონული კომუნიკაციების შესახებ)
Art. 8 of the Law on Electronic Communications stipulates that the Operational and Technical Agency (OTA) shall have the capability to obtain real-time communications and their identification data transmitted through the infrastructure of an electronic communication company by using stationary or semi-stationary technical means.
For this purpose, the OTA is empowered to: a) place or install a lawful interception management system and/or any hardware and software required for its function, if necessary; b) require the electronic communication company to maintain the technical capacity, via stationary means, to provide the OTA with real-time communication content and its identification data, in accordance with the architecture and interface specified by the stationary technical capacity for obtaining real-time communication. The OTA functions under the authority of the State Security Service, an organisation subject to the direct oversight of the Prime Minister of Georgia.
An electronic communications company is defined as an authorised entity whose activities or services involve the provision of telephone networks, internet networks, or related services. Electronic communication identification data is defined as user identification data, data required for tracing and identifying the source of a communication; data necessary for identifying the recipient of a communication; data required for determining the date, time, and duration of a communication; data necessary for identifying the type of communication; data required for identifying the user's communication equipment or potential equipment; and data necessary for determining the location of mobile communication equipment.
For this purpose, the OTA is empowered to: a) place or install a lawful interception management system and/or any hardware and software required for its function, if necessary; b) require the electronic communication company to maintain the technical capacity, via stationary means, to provide the OTA with real-time communication content and its identification data, in accordance with the architecture and interface specified by the stationary technical capacity for obtaining real-time communication. The OTA functions under the authority of the State Security Service, an organisation subject to the direct oversight of the Prime Minister of Georgia.
An electronic communications company is defined as an authorised entity whose activities or services involve the provision of telephone networks, internet networks, or related services. Electronic communication identification data is defined as user identification data, data required for tracing and identifying the source of a communication; data necessary for identifying the recipient of a communication; data required for determining the date, time, and duration of a communication; data necessary for identifying the type of communication; data required for identifying the user's communication equipment or potential equipment; and data necessary for determining the location of mobile communication equipment.
Coverage Telecommunications sector
GEORGIA
Since June 2023, entry into force in January 2024
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for copyright infringement
Law of Georgia on Electronic Commerce 3110-XIms-Xmp (საქართველოს კანონი 3110-XIms-Xmp ელექტრონული კომერციის შესახებ)
Arts. 11–13 of Chapter V of the Law of Georgia on Electronic Commerce (No. 3110-XIms-Xmp) establish an intermediary liability framework covering the three core categories of intermediation services: mere conduit (transmission), caching, and hosting. Under Art. 11, transmission providers are exempt from liability for transmitted information where they do not initiate the transmission, select the recipient, or select or modify the content, and where any temporary storage is limited to what is technically necessary for transmission. Under Art. 12, caching providers are exempt where they do not modify the information, comply with conditions on access and updating, do not interfere with lawful usage-monitoring technologies, and remove or disable access to cached content expeditiously once they become aware that it has been removed at source or restricted by a court or competent authority. Under Art. 13, hosting providers are exempt where they lack actual knowledge of illegal activity or information, or, upon obtaining such knowledge, act expeditiously to remove or restrict access; this exemption does not apply where the recipient acts on the provider’s behalf or is under its control. Art. 2 clarifies that “actual knowledge” is linked to a court decision or a decision of a competent administrative or law-enforcement body.
Coverage Internet intermediaries
GEORGIA
Since June 2023, entry into force in January 2024
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for any activity other than copyright infringement
Law of Georgia on Electronic Commerce 3110-XIms-Xmp (საქართველოს კანონი 3110-XIms-Xmp ელექტრონული კომერციის შესახებ)
Arts. 11–13 of Chapter V of the Law of Georgia on Electronic Commerce (No. 3110-XIms-Xmp) establish an intermediary liability framework covering the three core categories of intermediation services: mere conduit (transmission), caching, and hosting. Under Art. 11, transmission providers are exempt from liability for transmitted information where they do not initiate the transmission, select the recipient, or select or modify the content, and where any temporary storage is limited to what is technically necessary for transmission. Under Art. 12, caching providers are exempt where they do not modify the information, comply with conditions on access and updating, do not interfere with lawful usage-monitoring technologies, and remove or disable access to cached content expeditiously once they become aware that it has been removed at source or restricted by a court or competent authority. Under Art. 13, hosting providers are exempt where they lack actual knowledge of illegal activity or information, or, upon obtaining such knowledge, act expeditiously to remove or restrict access; this exemption does not apply where the recipient acts on the provider’s behalf or is under its control. Art. 2 clarifies that “actual knowledge” is linked to a court decision or a decision of a competent administrative or law-enforcement body.
Coverage Internet intermediaries
GEORGIA
Since March 2006, last amended in June 2022
Pillar Intermediary liability |
Indicator User identity requirement
Resolution No. 3 of Georgian National Communications Commission on the Approval of the Regulations in respect to the Provision of Services and Protection of Consumer Rights in the Sphere of Electronic Communications (საქართველოს კომუნიკაციების ეროვნული კომისიის დადგენილება No. 3 ელექტრონული კომუნიკაციების სფეროში მომსახურების მიწოდებისა და მომხმარებელთა უფლებების შესახებ რეგლამენტის დამტკიცების თაობაზე)
According to Art. 5.1 of Resolution No. 3 of Georgian National Communications Commission on the Approval of the Regulations in respect to the Provision of Services and Protection of Consumer Rights in the Sphere of Electronic Communications, electronic-communication service providers must record and keep information concerning consumers, including the name and surname of the consumer. It is also reported that mobile network operators must collect and store a user's personal information and proof of identity for SIM card registration.
Coverage Telecommunication services
GEORGIA
Since March 2006, as amended in November 2007, last amended in June 2022
Pillar Intermediary liability |
Indicator Monitoring requirement
Resolution No. 3 of Georgian National Communications Commission on the Approval of the Regulations in respect to the Provision of Services and Protection of Consumer Rights in the Sphere of Electronic Communications (საქართველოს კომუნიკაციების ეროვნული კომისიის დადგენილება No. 3 ელექტრონული კომუნიკაციების სფეროში მომსახურების მიწოდებისა და მომხმარებელთა უფლებების შესახებ რეგლამენტის დამტკიცების თაობაზე)
Pursuant to Art. 10.2(c) of Resolution No. 3 of the Georgian National Communications Commission approving the Regulations on the Provision of Services and Consumer Rights Protection in the Electronic Communications Sector, the owner of an internet site must examine any link made available on the site to ensure that the linked site or page does not contain offensive or otherwise inadmissible content. Where such content is identified, the site owner must take appropriate measures to eliminate it.
It is reported that individuals or entities who own a website are required to regularly monitor their web content to prevent the publication of inadmissible material. However, this monitoring is often inconsistent and is usually carried out only at the request of the Georgian National Communications Commission.
It is reported that individuals or entities who own a website are required to regularly monitor their web content to prevent the publication of inadmissible material. However, this monitoring is often inconsistent and is usually carried out only at the request of the Georgian National Communications Commission.
Coverage Internet sites
GEORGIA
Since March 2006, as amended in November 2007, last amended in June 2022
Pillar Intermediary liability |
Indicator Monitoring requirement
Resolution No. 3 of Georgian National Communications Commission on the Approval of the Regulations in respect to the Provision of Services and Protection of Consumer Rights in the Sphere of Electronic Communications (საქართველოს კომუნიკაციების ეროვნული კომისიის დადგენილება No. 3 ელექტრონული კომუნიკაციების სფეროში მომსახურების მიწოდებისა და მომხმარებელთა უფლებების შესახებ რეგლამენტის დამტკიცების თაობაზე)
According to Art. 10.3 of Resolution No. 3 of the Georgian National Communications Commission on the Approval of the Regulations in Respect to the Provision of Services and Protection of Consumer Rights in the Sphere of Electronic Communications, Internet domain issuers must periodically review the content of the websites registered under their domain to prevent the hosting of inappropriate material. Upon discovering such content, the domain issuer must promptly (a) warn the domain owner and set a deadline for the removal of the inappropriate material and (b) block the Internet site if the warning is ignored.
It is reported that individuals or entities who manage an Internet domain are required to regularly monitor web content to prevent the publication of inadmissible material. However, this monitoring is often inconsistent and is usually carried out only at the request of the Georgian National Communications Commission.
It is reported that individuals or entities who manage an Internet domain are required to regularly monitor web content to prevent the publication of inadmissible material. However, this monitoring is often inconsistent and is usually carried out only at the request of the Georgian National Communications Commission.
Coverage Internet domain issuers
