{
 "jurisdiction_id": "US-GA",
 "jurisdiction": "United States – Georgia",
 "url": "https://dataprotection.gi/jurisdictions/united-states-georgia/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 30,
  "sub_modules": 57,
  "source_register": 13
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "red",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-georgia/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "No comprehensive omnibus statute or dedicated DPA exists; regulatory coverage is fragmented across federal sectoral law and a narrow state breach-notification statute.",
   "claims": [
    {
     "statement": "The Georgia Attorney General's Consumer Protection Division enforces general consumer-protection and breach-notification law but is not a dedicated data-protection authority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Georgia has no comprehensive consumer-privacy statute; a comprehensive Georgia Consumer Privacy Act (SB 111) stumbled at the final legislative steps in the 2025 session and was not enacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retrospective-2025-in-state-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Federal Trade Commission Act, Section 5, provides a general national unfair/deceptive-practices baseline for privacy enforcement applicable to entities operating in Georgia, in the absence of a state omnibus law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Georgia imposes no independent extraterritorial-scope test; coverage of out-of-state controllers processing Georgia residents' data is governed only by whichever federal sectoral statute (COPPA, GLBA, HIPAA) independently applies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No Georgia statute requires private-sector controllers to register with or file processing records with a state privacy regulator.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-georgia/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Absence of any state-level lawful-basis or special-category framework; only FTC Section 5 'unfairness/deception' backstop applies generally.",
   "claims": [
    {
     "statement": "Georgia has no state-law enumerated lawful bases for processing personal data comparable to GDPR Article 6; commercial data processing is regulated only via FTC Act Section 5.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No general Georgia consent-threshold statute exists for commercial data processing; consent standards apply only within specific federal sectoral regimes (e.g., COPPA parental consent for under-13s).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/kids-privacy-coppa",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-georgia/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "No omnibus data-subject-rights framework; absence confirmed by legislative failure of SB 111 and lack of any successor bill.",
   "claims": [
    {
     "statement": "Georgia confers no general private-sector consumer right of access to personal data absent an enacted comprehensive privacy statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retrospective-2025-in-state-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Georgia confers no general consumer right to rectify or erase personal data held by private-sector controllers.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retrospective-2025-in-state-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-georgia/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "A breach-notification duty exists and is enforceable, but no DPIA/DPO/ROPA/retention framework exists at the state level.",
   "claims": [
    {
     "statement": "Georgia imposes no statutory requirement for private-sector controllers to appoint a data protection officer.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retrospective-2025-in-state-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The FTC's Safeguards Rule under GLBA requires covered financial institutions to notify the FTC of security breaches affecting 500 or more consumers, effective nationally including Georgia since May 13, 2024.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/blog/2024/05/safeguards-rule-notification-requirement-now-effect",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Georgia's breach-notification statute requires notification to affected residents in the most expedient time possible and without unreasonable delay following discovery of unauthorized acquisition of personal information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Georgia sets a 10,000-affected-individual threshold for notifying nationwide consumer reporting agencies following a breach, a higher bar than the 1,000-individual threshold used by most other states.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/examining-the-presidents-proposed-national-data-breach-notification-standard-against-existing-legislation",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-georgia/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No state-level transfer-mechanism regime exists; all relevant adequacy/transfer-mechanism competence sits with the US federal government, not Georgia.",
   "claims": [
    {
     "statement": "Georgia imposes no state-level restrictions or required transfer mechanisms governing the outbound transfer of personal data from Georgia.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retrospective-2025-in-state-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Adequacy determinations affecting US data flows (e.g., the EU-US Data Privacy Framework) are negotiated at the US federal level; individual states including Georgia have no independent adequacy-granting or adequacy-receiving competence.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Georgia has not enacted a data-localisation mandate requiring in-state storage of personal data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retrospective-2025-in-state-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-georgia/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial and children's-data sectoral overlays are well-evidenced federally; other sub-modules (insurance, health, telecoms, employment, credit, education) lack Georgia-specific confirmation in this pass.",
   "claims": [
    {
     "statement": "The Gramm-Leach-Bliley Act and its implementing FTC Safeguards Rule govern financial institutions' security and confidentiality obligations for nonpublic personal information nationally, including for institutions operating in Georgia.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/blog/2024/05/safeguards-rule-notification-requirement-now-effect",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Adoption of the NAIC Insurance Data Security Model Law by the Georgia legislature/Insurance Commissioner could not be confirmed in this research pass; NAIC model laws are not self-executing and require independent state adoption.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/naic-releases-insurance-data-security-model-law/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-georgia/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No dedicated commercial-privacy/adtech statute exists; coverage is incidental via general consumer-protection law.",
   "claims": [
    {
     "statement": "Georgia has no state-level cookie-consent or tracking-technology statute; online tracking is regulated only via applicable federal/sectoral rules.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retrospective-2025-in-state-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Georgia has no dedicated privacy-focused dark-patterns prohibition; general deceptive-practices provisions under the Georgia Fair Business Practices Act and FTC Act Section 5 may incidentally reach some dark-pattern conduct.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Direct-marketing communications to Georgia residents are subject to federal telemarketing and anti-spam regimes (TCPA, CAN-SPAM, FTC Telemarketing Sales Rule/National Do-Not-Call Registry) rather than a Georgia-specific consent statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-georgia/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "No Georgia-specific algorithmic, biometric, or AI-governance statute was identified.",
   "claims": [
    {
     "statement": "Georgia has not enacted a statute granting consumers a right to opt out of profiling or automated decision-making.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retrospective-2025-in-state-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Georgia has not enacted comprehensive AI-specific risk-assessment or algorithmic-transparency legislation as of the current research date.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retrospective-2025-in-state-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Georgia has not enacted a biometric-privacy statute analogous to Illinois' Biometric Information Privacy Act; no statutory private right of action for biometric-data misuse exists under Georgia law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retrospective-2025-in-state-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-georgia/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "COPPA provides solid federal coverage (green-level certainty), but Georgia's own children's online-safety statute is in active, unresolved litigation (NetChoice v. Carr), and its current effective status is Uncertain.",
   "claims": [
    {
     "statement": "Georgia enacted a children's online-safety/social-media statute (reported introduced 2024) that is the subject of ongoing First Amendment litigation captioned NetChoice v. Carr; this research pass could not confirm the statute's current injunction status or final operative provisions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "FTC / Amelia Vance",
     "source_url": "https://www.ftc.gov/system/files/ftc_gov/pdf/Amelia-Vance-Age-Verification.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "COPPA requires operators of online services directed to children under 13 to obtain verifiable parental consent before collecting personal information, applicable nationally including Georgia, and is a current FTC enforcement priority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/kids-privacy-coppa",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-georgia/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement capacity exists via the AG's general consumer-protection authority and FTC national authority, but no dedicated privacy-specific enforcement regime, fine schedule, or confirmed private right of action exists for Georgia.",
   "claims": [
    {
     "statement": "The FTC retains general Section 5 civil-penalty and injunctive enforcement authority over unfair/deceptive data practices nationally, including for entities operating in Georgia.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Georgia's Attorney General played a leading role in the historic multistate Equifax data-breach settlement, illustrating the state's participation in coordinated privacy/security enforcement.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/georgia-attorney-general-chris-carr-on-breaches-federal-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Some US state breach-notification statutes allow a private right of action for noncompliance, but whether Georgia's statute does so specifically was not confirmed in this research pass.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/state-data-breach-notification-chart",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Georgia's comprehensive consumer-privacy bill, SB 111, stumbled at the final legislative steps during the 2025 session and was not enacted, leaving Georgia without an omnibus privacy statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retrospective-2025-in-state-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}