#
No comprehensive omnibus statute or dedicated DPA exists; regulatory coverage is fragmented across federal sectoral law and a narrow state breach-notification statute.
Sub-modules (5)
Regulator And AuthorityRed
No dedicated Georgia DPA exists; the Georgia AG enforces consumer-protection and breach-notification law, while the FTC enforces Section 5 nationally.
Claims (1):
- The Georgia Attorney General's Consumer Protection Division enforces general consumer-protection and breach-notification law but is not a dedicated data-protection authority.
Act And InstrumentsRed
Primary instruments are the Georgia breach-notification statute and FTC Act Section 5; no omnibus privacy act exists.
Claims (2):
- Georgia has no comprehensive consumer-privacy statute; a comprehensive Georgia Consumer Privacy Act (SB 111) stumbled at the final legislative steps in the 2025 session and was not enacted.
- The Federal Trade Commission Act, Section 5, provides a general national unfair/deceptive-practices baseline for privacy enforcement applicable to entities operating in Georgia, in the absence of a state omnibus law.
Material ScopeRed
No Georgia statute defines 'personal data' or processing scope comparable to GDPR; scope is confined to breach-notification 'personal information' definitions and sector-specific federal definitions.
Claims (1):
- Georgia has no comprehensive consumer-privacy statute; a comprehensive Georgia Consumer Privacy Act (SB 111) stumbled at the final legislative steps in the 2025 session and was not enacted.
Territorial ScopeAmber
Georgia has no independent extraterritorial trigger; applicable federal sectoral statutes (COPPA, GLBA, HIPAA) apply based on federal jurisdictional tests regardless of where a controller is established.
Claims (1):
- Georgia imposes no independent extraterritorial-scope test; coverage of out-of-state controllers processing Georgia residents' data is governed only by whichever federal sectoral statute (COPPA, GLBA, HIPAA) independently applies.
Regulator Registration And FilingRed
No state-level controller registration or filing obligation exists in Georgia absent a comprehensive privacy statute.
Claims (1):
- No Georgia statute requires private-sector controllers to register with or file processing records with a state privacy regulator.
Sources and claims (5)
- ConfirmedNAAG — The Georgia Attorney General's Consumer Protection Division enforces general consumer-protection and breach-notification law but is not a dedicated data-protection authority.observed
- ConfirmedIAPP — Georgia has no comprehensive consumer-privacy statute; a comprehensive Georgia Consumer Privacy Act (SB 111) stumbled at the final legislative steps in the 2025 session and was not enacted.observed
- ConfirmedFederal Trade Commission — The Federal Trade Commission Act, Section 5, provides a general national unfair/deceptive-practices baseline for privacy enforcement applicable to entities operating in Georgia, in the absence of a state omnibus law.observed
- ProbableFederal Trade Commission — Georgia imposes no independent extraterritorial-scope test; coverage of out-of-state controllers processing Georgia residents' data is governed only by whichever federal sectoral statute (COPPA, GLBA, HIPAA) independently applies.observed
- ConfirmedNAAG — No Georgia statute requires private-sector controllers to register with or file processing records with a state privacy regulator.observed