🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-GA · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

United States – Georgia

US-GA schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 30 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
30Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No comprehensive omnibus statute or dedicated DPA exists; regulatory coverage is fragmented across federal sectoral law and a narrow state breach-notification statute.

Primary frameworkGeorgia data breach notification statute (O.C.G.A. § 10-1-910 et seq.); Federal Trade Commission Act, Section 5 (national baseline)
Traffic-light rationale — RedNo comprehensive omnibus statute or dedicated DPA exists; regulatory coverage is fragmented across federal sectoral law and a narrow state breach-notification statute.

Sub-modules (5)

Regulator And AuthorityRed

No dedicated Georgia DPA exists; the Georgia AG enforces consumer-protection and breach-notification law, while the FTC enforces Section 5 nationally.

Claims (1):

  • The Georgia Attorney General's Consumer Protection Division enforces general consumer-protection and breach-notification law but is not a dedicated data-protection authority.

Act And InstrumentsRed

Primary instruments are the Georgia breach-notification statute and FTC Act Section 5; no omnibus privacy act exists.

Claims (2):

  • Georgia has no comprehensive consumer-privacy statute; a comprehensive Georgia Consumer Privacy Act (SB 111) stumbled at the final legislative steps in the 2025 session and was not enacted.
  • The Federal Trade Commission Act, Section 5, provides a general national unfair/deceptive-practices baseline for privacy enforcement applicable to entities operating in Georgia, in the absence of a state omnibus law.

Material ScopeRed

No Georgia statute defines 'personal data' or processing scope comparable to GDPR; scope is confined to breach-notification 'personal information' definitions and sector-specific federal definitions.

Claims (1):

  • Georgia has no comprehensive consumer-privacy statute; a comprehensive Georgia Consumer Privacy Act (SB 111) stumbled at the final legislative steps in the 2025 session and was not enacted.

Territorial ScopeAmber

Georgia has no independent extraterritorial trigger; applicable federal sectoral statutes (COPPA, GLBA, HIPAA) apply based on federal jurisdictional tests regardless of where a controller is established.

Claims (1):

  • Georgia imposes no independent extraterritorial-scope test; coverage of out-of-state controllers processing Georgia residents' data is governed only by whichever federal sectoral statute (COPPA, GLBA, HIPAA) independently applies.

Regulator Registration And FilingRed

No state-level controller registration or filing obligation exists in Georgia absent a comprehensive privacy statute.

Claims (1):

  • No Georgia statute requires private-sector controllers to register with or file processing records with a state privacy regulator.
Category narrative72 words

US-GA (the U.S. state of Georgia) has no dedicated data-protection authority and no comprehensive consumer-privacy statute. The Georgia Attorney General enforces general consumer-protection law (Fair Business Practices Act) and the state's breach-notification statute; the FTC exercises general Section 5 unfair/deceptive-practices authority over commercial data practices nationally, including Georgia. A comprehensive Georgia Consumer Privacy Act (SB 111) failed to pass the 2025 legislative session, leaving no omnibus material/territorial-scope trigger comparable to GDPR/CCPA-style regimes.

Sources and claims (5)
  1. ConfirmedNAAGThe Georgia Attorney General's Consumer Protection Division enforces general consumer-protection and breach-notification law but is not a dedicated data-protection authority.observed
  2. ConfirmedIAPPGeorgia has no comprehensive consumer-privacy statute; a comprehensive Georgia Consumer Privacy Act (SB 111) stumbled at the final legislative steps in the 2025 session and was not enacted.observed
  3. ConfirmedFederal Trade CommissionThe Federal Trade Commission Act, Section 5, provides a general national unfair/deceptive-practices baseline for privacy enforcement applicable to entities operating in Georgia, in the absence of a state omnibus law.observed
  4. ProbableFederal Trade CommissionGeorgia imposes no independent extraterritorial-scope test; coverage of out-of-state controllers processing Georgia residents' data is governed only by whichever federal sectoral statute (COPPA, GLBA, HIPAA) independently applies.observed
  5. ConfirmedNAAGNo Georgia statute requires private-sector controllers to register with or file processing records with a state privacy regulator.observed

#

Absence of any state-level lawful-basis or special-category framework; only FTC Section 5 'unfairness/deception' backstop applies generally.

Primary frameworkFederal Trade Commission Act, Section 5 (general baseline only)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedAbsence of any state-level lawful-basis or special-category framework; only FTC Section 5 'unfairness/deception' backstop applies generally.

Sub-modules (4)

Lawful BasesRed

No Georgia statute enumerates lawful bases for processing; commercial processing is regulated only via the FTC's unfair/deceptive-practices standard.

Claims (1):

  • Georgia has no state-law enumerated lawful bases for processing personal data comparable to GDPR Article 6; commercial data processing is regulated only via FTC Act Section 5.

Special CategoriesRed

No Georgia general 'special category' regime; sensitive data protection is confined to sectoral statutes such as HIPAA for health data.

Absence provenance: not recorded. Searched: not recorded.

Pseudonymisation And AnonymisationRed

No Georgia statutory definition of pseudonymisation or anonymisation, and no associated safe harbour, was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative47 words

Georgia has no enumerated lawful-bases regime, no general consent-threshold statute, and no general special-category (sensitive data) regime analogous to GDPR Art 6/9. Coverage of consent and sensitive data is confined to sector-specific federal law (e.g., HIPAA authorization requirements, COPPA parental consent) rather than a Georgia general-purpose statute.

Sources and claims (2)
  1. ProbableFederal Trade CommissionGeorgia has no state-law enumerated lawful bases for processing personal data comparable to GDPR Article 6; commercial data processing is regulated only via FTC Act Section 5.observed
  2. ConfirmedFederal Trade CommissionNo general Georgia consent-threshold statute exists for commercial data processing; consent standards apply only within specific federal sectoral regimes (e.g., COPPA parental consent for under-13s).observed

#

No omnibus data-subject-rights framework; absence confirmed by legislative failure of SB 111 and lack of any successor bill.

Traffic-light rationale — RedNo omnibus data-subject-rights framework; absence confirmed by legislative failure of SB 111 and lack of any successor bill.

Sub-modules (5)

Access RightRed

No general Georgia right of access to personal data held by private-sector controllers exists absent an omnibus statute.

Claims (1):

  • Georgia confers no general private-sector consumer right of access to personal data absent an enacted comprehensive privacy statute.

Rectification And ErasureRed

No general Georgia right to rectify or erase ('right to be forgotten') personal data exists.

Claims (1):

  • Georgia confers no general consumer right to rectify or erase personal data held by private-sector controllers.

Restriction And ObjectionRed

No general Georgia right to restrict processing or object to profiling exists outside sector-specific opt-outs (e.g., GLBA financial-information opt-out).

Absence provenance: not recorded. Searched: not recorded.

Data PortabilityRed

No Georgia data-portability right exists for consumers.

Absence provenance: not recorded. Searched: not recorded.

Deadlines And Response WindowsRed

No Georgia statutory response-window applies to consumer data-rights requests generally; only sector-specific deadlines (outside GA general law) may apply within their own scope.

Absence provenance: not recorded. Searched: not recorded.

Category narrative55 words

Georgia confers no general consumer rights of access, rectification, erasure, restriction, objection, or portability over personal data held by private-sector controllers. Any such rights that exist for Georgia residents arise solely from federal sectoral statutes operating within their own scope (e.g., HIPAA access rights for patients of covered entities), not from a Georgia general-purpose statute.

Sources and claims (2)
  1. ConfirmedIAPPGeorgia confers no general private-sector consumer right of access to personal data absent an enacted comprehensive privacy statute.observed
  2. ConfirmedIAPPGeorgia confers no general consumer right to rectify or erase personal data held by private-sector controllers.observed

#

A breach-notification duty exists and is enforceable, but no DPIA/DPO/ROPA/retention framework exists at the state level.

Primary frameworkGeorgia data breach notification statute (O.C.G.A. § 10-1-910 et seq.)
Traffic-light rationale — AmberA breach-notification duty exists and is enforceable, but no DPIA/DPO/ROPA/retention framework exists at the state level.

Sub-modules (7)

Accountability And DpiaRed

No Georgia DPIA-trigger statute exists absent a comprehensive privacy law.

Absence provenance: not recorded. Searched: not recorded.

Dpo RequirementsRed

No Georgia DPO-appointment threshold exists.

Claims (1):

  • Georgia imposes no statutory requirement for private-sector controllers to appoint a data protection officer.

Ropa RequirementsRed

No Georgia records-of-processing requirement exists.

Absence provenance: not recorded. Searched: not recorded.

Joint Controller ArrangementsRed

No Georgia joint-controller allocation-of-liability regime exists.

Absence provenance: not recorded. Searched: not recorded.

Security MeasuresAmber

General security-of-processing obligations apply only to sector-covered entities (e.g., GLBA-covered financial institutions under the FTC Safeguards Rule); no Georgia general-purpose security statute exists.

Claims (1):

  • The FTC's Safeguards Rule under GLBA requires covered financial institutions to notify the FTC of security breaches affecting 500 or more consumers, effective nationally including Georgia since May 13, 2024.

Breach NotificationGreen

Georgia's breach-notification statute requires notice to affected residents without unreasonable delay and imposes a comparatively high 10,000-individual threshold for notifying nationwide consumer reporting agencies.

Claims (2):

  • Georgia's breach-notification statute requires notification to affected residents in the most expedient time possible and without unreasonable delay following discovery of unauthorized acquisition of personal information.
  • Georgia sets a 10,000-affected-individual threshold for notifying nationwide consumer reporting agencies following a breach, a higher bar than the 1,000-individual threshold used by most other states.

Retention And DisposalRed

No general Georgia retention-limit or disposal-duty statute exists outside sector-specific requirements.

Absence provenance: not recorded. Searched: not recorded.

Category narrative85 words

Georgia's principal controller duty is breach notification under its data-breach statute, which requires notice to affected residents in the most expedient time possible and without unreasonable delay, and to nationwide consumer reporting agencies once notification thresholds are met — Georgia's threshold for CRA notification is set at 10,000+ affected individuals, higher than most states' 1,000-individual trigger. Georgia imposes no general DPIA, DPO, or ROPA obligations. Sector-specific federal security obligations (e.g., the FTC Safeguards Rule for financial institutions under GLBA) supplement this baseline for covered entities.

Sources and claims (4)
  1. ConfirmedIAPPGeorgia imposes no statutory requirement for private-sector controllers to appoint a data protection officer.observed
  2. ConfirmedFederal Trade CommissionThe FTC's Safeguards Rule under GLBA requires covered financial institutions to notify the FTC of security breaches affecting 500 or more consumers, effective nationally including Georgia since May 13, 2024.observed
  3. ConfirmedNAAGGeorgia's breach-notification statute requires notification to affected residents in the most expedient time possible and without unreasonable delay following discovery of unauthorized acquisition of personal information.observed
  4. ConfirmedIAPPGeorgia sets a 10,000-affected-individual threshold for notifying nationwide consumer reporting agencies following a breach, a higher bar than the 1,000-individual threshold used by most other states.observed

#

No state-level transfer-mechanism regime exists; all relevant adequacy/transfer-mechanism competence sits with the US federal government, not Georgia.

Traffic-light rationale — RedNo state-level transfer-mechanism regime exists; all relevant adequacy/transfer-mechanism competence sits with the US federal government, not Georgia.

Sub-modules (6)

Transfer MechanismsRed

No Georgia-specific transfer-mechanism regime exists; outbound transfer of Georgia residents' data is unregulated at the state level.

Claims (1):

  • Georgia imposes no state-level restrictions or required transfer mechanisms governing the outbound transfer of personal data from Georgia.

Adequacy ReceivedRed

Adequacy is a federal, not state, competence; Georgia cannot independently receive an adequacy decision.

Claims (1):

  • Adequacy determinations affecting US data flows (e.g., the EU-US Data Privacy Framework) are negotiated at the US federal level; individual states including Georgia have no independent adequacy-granting or adequacy-receiving competence.

Adequacy GrantedRed

Georgia has no independent authority to grant adequacy to other regimes; this sits with US federal instruments.

Claims (1):

  • Adequacy determinations affecting US data flows (e.g., the EU-US Data Privacy Framework) are negotiated at the US federal level; individual states including Georgia have no independent adequacy-granting or adequacy-receiving competence.

Sccs And BcrsRed

No Georgia-specific SCC/BCR uptake requirement exists; use of SCCs/BCRs by Georgia-based recipients of EU personal data is governed by GDPR Chapter V, not Georgia law.

Absence provenance: not recorded. Searched: not recorded.

Transfer Impact AssessmentRed

No Georgia TIA requirement exists.

Absence provenance: not recorded. Searched: not recorded.

Data LocalisationRed

Georgia imposes no data-localisation mandate.

Claims (1):

  • Georgia has not enacted a data-localisation mandate requiring in-state storage of personal data.
Category narrative39 words

Georgia has no independent authority over cross-border data transfers; adequacy determinations, SCCs, and BCR frameworks operate exclusively at the US federal level (e.g., the EU-US Data Privacy Framework) and are outside Georgia's state competence. Georgia imposes no data-localisation mandate.

Sources and claims (3)
  1. ProbableIAPPGeorgia imposes no state-level restrictions or required transfer mechanisms governing the outbound transfer of personal data from Georgia.observed
  2. ProbableFederal Trade CommissionAdequacy determinations affecting US data flows (e.g., the EU-US Data Privacy Framework) are negotiated at the US federal level; individual states including Georgia have no independent adequacy-granting or adequacy-receiving competence.observed
  3. ProbableIAPPGeorgia has not enacted a data-localisation mandate requiring in-state storage of personal data.observed

#

Financial and children's-data sectoral overlays are well-evidenced federally; other sub-modules (insurance, health, telecoms, employment, credit, education) lack Georgia-specific confirmation in this pass.

Primary frameworkGramm-Leach-Bliley Act / FTC Safeguards Rule (financial); COPPA (children)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberFinancial and children's-data sectoral overlays are well-evidenced federally; other sub-modules (insurance, health, telecoms, employment, credit, education) lack Georgia-specific confirmation in this pass.

Sub-modules (7)

Financial Sector OverlayGreen

GLBA and the FTC Safeguards Rule govern financial institutions' handling of nonpublic personal information nationally, including in Georgia.

Claims (1):

  • The Gramm-Leach-Bliley Act and its implementing FTC Safeguards Rule govern financial institutions' security and confidentiality obligations for nonpublic personal information nationally, including for institutions operating in Georgia.

Health Sector OverlayAmber

HIPAA is the operative federal health-data framework per the seed disambiguation; this research pass did not independently re-verify HIPAA provisions via search.

Absence provenance: not recorded. Searched: not recorded.

Telecoms And EprivacyRed

No Georgia-specific telecoms/ePrivacy statute distinct from federal TCPA/CAN-SPAM baselines was verified in this research pass.

Absence provenance: not recorded. Searched: not recorded.

Employment DataRed

No Georgia employment-data-specific privacy statute was verified in this research pass.

Absence provenance: not recorded. Searched: not recorded.

Credit And ScoringRed

No Georgia-specific credit-scoring statute distinct from federal FCRA baseline was verified in this research pass.

Absence provenance: not recorded. Searched: not recorded.

EducationRed

No Georgia-specific education-data statute distinct from federal FERPA baseline was verified in this research pass.

Absence provenance: not recorded. Searched: not recorded.

InsuranceAmber

Whether Georgia has adopted the NAIC Insurance Data Security Model Law as binding state regulation could not be confirmed in this research pass.

Claims (1):

  • Adoption of the NAIC Insurance Data Security Model Law by the Georgia legislature/Insurance Commissioner could not be confirmed in this research pass; NAIC model laws are not self-executing and require independent state adoption.
Category narrative77 words

Georgia relies entirely on federal sectoral overlays for privacy-adjacent obligations: GLBA (and its FTC Safeguards Rule) for financial institutions, COPPA for children's online data, and HIPAA for health information (health-sector confirmation not independently re-verified in this research pass). Whether Georgia has adopted the NAIC Insurance Data Security Model Law as binding state insurance regulation could not be confirmed in this research pass. Telecoms/ePrivacy, employment, credit-scoring, and education sub-modules had no Georgia-specific findings distinct from generic federal baselines.

Sources and claims (2)
  1. ConfirmedFederal Trade CommissionThe Gramm-Leach-Bliley Act and its implementing FTC Safeguards Rule govern financial institutions' security and confidentiality obligations for nonpublic personal information nationally, including for institutions operating in Georgia.observed
  2. UncertainIAPPAdoption of the NAIC Insurance Data Security Model Law by the Georgia legislature/Insurance Commissioner could not be confirmed in this research pass; NAIC model laws are not self-executing and require independent state adoption.observed

#

No dedicated commercial-privacy/adtech statute exists; coverage is incidental via general consumer-protection law.

Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedNo dedicated commercial-privacy/adtech statute exists; coverage is incidental via general consumer-protection law.

Sub-modules (6)

Cookies And TrackersRed

No Georgia cookie/tracker-consent statute exists.

Claims (1):

  • Georgia has no state-level cookie-consent or tracking-technology statute; online tracking is regulated only via applicable federal/sectoral rules.

Dark PatternsAmber

No dedicated Georgia dark-patterns prohibition exists; general deceptive-practices law may reach some conduct incidentally.

Claims (1):

  • Georgia has no dedicated privacy-focused dark-patterns prohibition; general deceptive-practices provisions under the Georgia Fair Business Practices Act and FTC Act Section 5 may incidentally reach some dark-pattern conduct.

Opt Out SignalsRed

No Georgia statute mandates recognition of universal opt-out signals such as Global Privacy Control.

Absence provenance: not recorded. Searched: not recorded.

Clean Rooms And DcrRed

No Georgia clean-room/data-collaboration-room regime exists.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' definitions exist under Georgia law.

Absence provenance: not recorded. Searched: not recorded.

Direct MarketingAmber

Direct marketing to Georgia residents is governed by federal telemarketing/anti-spam statutes rather than a Georgia-specific consent regime.

Claims (1):

  • Direct-marketing communications to Georgia residents are subject to federal telemarketing and anti-spam regimes (TCPA, CAN-SPAM, FTC Telemarketing Sales Rule/National Do-Not-Call Registry) rather than a Georgia-specific consent statute.
Category narrative67 words

Georgia has no cookie/tracker-consent statute, no dark-patterns prohibition specific to privacy, no universal opt-out-signal recognition, and no clean-room or cross-context-advertising ('sale'/'share') regime akin to CPRA. Direct marketing to Georgia residents is governed by federal telemarketing/anti-spam law (TCPA, CAN-SPAM, FTC Telemarketing Sales Rule/National Do-Not-Call Registry) rather than Georgia-specific consent rules; general deceptive-practices prohibitions (Georgia Fair Business Practices Act, FTC Act Section 5) may reach some dark-pattern conduct incidentally.

Sources and claims (3)
  1. ProbableIAPPGeorgia has no state-level cookie-consent or tracking-technology statute; online tracking is regulated only via applicable federal/sectoral rules.observed
  2. UncertainFederal Trade CommissionGeorgia has no dedicated privacy-focused dark-patterns prohibition; general deceptive-practices provisions under the Georgia Fair Business Practices Act and FTC Act Section 5 may incidentally reach some dark-pattern conduct.observed
  3. ProbableFederal Trade CommissionDirect-marketing communications to Georgia residents are subject to federal telemarketing and anti-spam regimes (TCPA, CAN-SPAM, FTC Telemarketing Sales Rule/National Do-Not-Call Registry) rather than a Georgia-specific consent statute.observed

#

No Georgia-specific algorithmic, biometric, or AI-governance statute was identified.

Traffic-light rationale — RedNo Georgia-specific algorithmic, biometric, or AI-governance statute was identified.

Sub-modules (6)

Profiling RestrictionsRed

No Georgia profiling-restriction statute exists.

Claims (1):

  • Georgia has not enacted a statute granting consumers a right to opt out of profiling or automated decision-making.

Automated Decision Making TransparencyRed

No Georgia ADM-transparency or explanation-right statute exists.

Absence provenance: not recorded. Searched: not recorded.

Ai Risk AssessmentsRed

Georgia has not enacted AI-specific risk-assessment legislation as of the current research date.

Claims (1):

  • Georgia has not enacted comprehensive AI-specific risk-assessment or algorithmic-transparency legislation as of the current research date.

Biometric RegimeRed

Georgia has no biometric-privacy statute comparable to Illinois BIPA; no private right of action or statutory damages for biometric misuse exists under Georgia law.

Claims (1):

  • Georgia has not enacted a biometric-privacy statute analogous to Illinois' Biometric Information Privacy Act; no statutory private right of action for biometric-data misuse exists under Georgia law.

Genetic DataAmber

No independent Georgia genetic-data statute was identified; any protection derives from federal HIPAA/GINA frameworks, not independently re-verified this pass.

Absence provenance: not recorded. Searched: not recorded.

State Surveillance CarveoutsRed

No Georgia-specific state-surveillance carve-out distinct from generic federal national-security exemptions was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative55 words

Georgia has not enacted a biometric-privacy statute analogous to Illinois' BIPA, no AI-specific risk-assessment or algorithmic-transparency legislation, and no profiling/ADM opt-out right. Genetic-data protection, to the extent it exists for Georgia residents, derives from federal law (HIPAA for covered entities; GINA) rather than Georgia statute; this was not independently re-verified via search in this pass.

Sources and claims (3)
  1. ProbableIAPPGeorgia has not enacted a statute granting consumers a right to opt out of profiling or automated decision-making.observed
  2. ProbableIAPPGeorgia has not enacted comprehensive AI-specific risk-assessment or algorithmic-transparency legislation as of the current research date.observed
  3. ProbableIAPPGeorgia has not enacted a biometric-privacy statute analogous to Illinois' Biometric Information Privacy Act; no statutory private right of action for biometric-data misuse exists under Georgia law.observed

#

COPPA provides solid federal coverage (green-level certainty), but Georgia's own children's online-safety statute is in active, unresolved litigation (NetChoice v. Carr), and its current effective status is Uncertain.

Primary frameworkChildren's Online Privacy Protection Act (COPPA) — federal, operative in Georgia
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberCOPPA provides solid federal coverage (green-level certainty), but Georgia's own children's online-safety statute is in active, unresolved litigation (NetChoice v. Carr), and its current effective status is Uncertain.

Sub-modules (5)

Age VerificationAmber

Georgia's own age-verification/social-media statute is subject to unresolved litigation (NetChoice v. Carr); federal age-verification precedent (Free Speech Coalition v. Paxton) affects how such laws may be enforced.

Claims (1):

  • Georgia enacted a children's online-safety/social-media statute (reported introduced 2024) that is the subject of ongoing First Amendment litigation captioned NetChoice v. Carr; this research pass could not confirm the statute's current injunction status or final operative provisions.

Minor Profiling BansRed

No general Georgia minor-profiling ban exists beyond COPPA's under-13 protections and the contested social-media statute.

Absence provenance: not recorded. Searched: not recorded.

Education SettingsRed

No Georgia education-settings-specific children's-data statute distinct from federal FERPA baseline was verified.

Absence provenance: not recorded. Searched: not recorded.

Dependent AdultsRed

No Georgia dependent-adults-specific data-protection statute was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative93 words

COPPA is the operative federal framework requiring verifiable parental consent for collecting personal information from children under 13 online, enforced by the FTC nationally including in Georgia. Georgia introduced children's online-safety/social-media legislation (reported for the 2024 session) that has become subject to First Amendment litigation captioned NetChoice v. Carr (Georgia AG Chris Carr as defendant); this research pass could not confirm the law's current injunction status, enacted text, or effective date. No general Georgia parental-consent or minor-profiling-ban statute exists beyond COPPA and the contested social-media law. No Georgia dependent-adults-specific data-protection statute was identified.

Sources and claims (2)
  1. UncertainFTC / Amelia VanceGeorgia enacted a children's online-safety/social-media statute (reported introduced 2024) that is the subject of ongoing First Amendment litigation captioned NetChoice v. Carr; this research pass could not confirm the statute's current injunction status or final operative provisions.observed
  2. ConfirmedFederal Trade CommissionCOPPA requires operators of online services directed to children under 13 to obtain verifiable parental consent before collecting personal information, applicable nationally including Georgia, and is a current FTC enforcement priority.observed

#

Enforcement capacity exists via the AG's general consumer-protection authority and FTC national authority, but no dedicated privacy-specific enforcement regime, fine schedule, or confirmed private right of action exists for Georgia.

Primary frameworkGeorgia Fair Business Practices Act; Georgia breach-notification statute; FTC Act Section 5
Traffic-light rationale — AmberEnforcement capacity exists via the AG's general consumer-protection authority and FTC national authority, but no dedicated privacy-specific enforcement regime, fine schedule, or confirmed private right of action exists for Georgia.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Georgia AG enforces via the Fair Business Practices Act and breach-notification statute; the FTC enforces via Section 5 civil-penalty and injunctive remedies nationally.

Claims (1):

  • The FTC retains general Section 5 civil-penalty and injunctive enforcement authority over unfair/deceptive data practices nationally, including for entities operating in Georgia.

Enforcement Activity IndexAmber

The Georgia AG participated in the multistate Equifax data-breach settlement, a leading example of Georgia-linked privacy/security enforcement activity.

Claims (1):

  • Georgia's Attorney General played a leading role in the historic multistate Equifax data-breach settlement, illustrating the state's participation in coordinated privacy/security enforcement.

Regulator Funding And CapacityRed

No dedicated privacy-specific funding or headcount data for the Georgia AG's office was identified in this research pass.

Absence provenance: not recorded. Searched: not recorded.

Collective Redress And Class ActionsRed

No Georgia privacy-specific collective-redress mechanism beyond generally available Georgia class-action procedure was identified.

Absence provenance: not recorded. Searched: not recorded.

Private Right Of ActionAmber

Whether Georgia's breach-notification statute confers a private right of action could not be confirmed specifically for Georgia in this research pass; the majority of US state breach statutes do not confer one.

Claims (1):

  • Some US state breach-notification statutes allow a private right of action for noncompliance, but whether Georgia's statute does so specifically was not confirmed in this research pass.

Recent Developments 180DAmber

The most significant recent development is the failure of Georgia's comprehensive privacy bill (SB 111) to pass during the 2025 session, confirmed as of the retrospective published in the review period.

Claims (1):

  • Georgia's comprehensive consumer-privacy bill, SB 111, stumbled at the final legislative steps during the 2025 session and was not enacted, leaving Georgia without an omnibus privacy statute.
Category narrative121 words

The Georgia AG's Consumer Protection Division enforces the state's general consumer-protection statute (Fair Business Practices Act) and the breach-notification law, and has participated in major multistate data-breach actions (e.g., the multistate Equifax breach settlement). The FTC retains general Section 5 enforcement authority nationally. No dedicated Georgia privacy regulator with independent fine-setting or investigative powers (comparable to California's CPPA) exists. Georgia's breach-notification statute does not clearly create a private right of action; this was not independently confirmed for Georgia specifically in this pass. The most significant recent development (within 180 days) is the failure of the comprehensive Georgia Consumer Privacy Act (SB 111) to pass during the 2025 legislative session, leaving Georgia without an omnibus statute as of the current research date.

Sources and claims (4)
  1. ConfirmedFederal Trade CommissionThe FTC retains general Section 5 civil-penalty and injunctive enforcement authority over unfair/deceptive data practices nationally, including for entities operating in Georgia.observed
  2. ConfirmedIAPPGeorgia's Attorney General played a leading role in the historic multistate Equifax data-breach settlement, illustrating the state's participation in coordinated privacy/security enforcement.observed
  3. UncertainIAPPSome US state breach-notification statutes allow a private right of action for noncompliance, but whether Georgia's statute does so specifically was not confirmed in this research pass.observed
  4. ConfirmedIAPPGeorgia's comprehensive consumer-privacy bill, SB 111, stumbled at the final legislative steps during the 2025 session and was not enacted, leaving Georgia without an omnibus privacy statute.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Georgia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 30 claim(s), 13 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (34 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. Strong T1/T2 sourcing was obtained for: regulator_and_framework (Georgia breach statute, FTC Section 5), controller_processor_duties.breach_notification (Georgia's 10,000-individual CRA-notification threshold, FTC Safeguards Rule), sectoral_watch.financial_sector_overlay (GLBA/Safeguards Rule), children_and_vulnerable_groups.parental_consent (COPPA), and enforcement_and_redress (Equifax multistate settlement, SB 111 legislative failure). Weaker T3/T4 or absent-field coverage applies to: lawful_processing_and_special_data.special_categories/pseudonymisation, data_subject_rights (all sub-modules, given no omnibus law), cross_border_and_adequacy (all sub-modules — federal, not state, competence), sectoral_watch.health/telecoms/employment/credit/education/insurance (HIPAA/FERPA/FCRA specifics not independently re-verified this pass; NAIC model-law adoption by Georgia unconfirmed), adtech_and_commercial_privacy (all sub-modules), algorithmic_biometric_and_surveillance_governance (all sub-modules), and children_and_vulnerable_groups.age_verification (NetChoice v. Carr litigation confirmed to exist but current injunction/effective status unconfirmed).

Unresolved questions (5):

  • Does Georgia's breach-notification statute (O.C.G.A. § 10-1-910 et seq.) confer a private right of action, or is enforcement exclusively via the state AG?
  • What is the current litigation/injunction status and enacted text of Georgia's children's online-safety/social-media statute underlying NetChoice v. Carr?
  • Has Georgia adopted the NAIC Insurance Data Security Model Law in whole or in part via state insurance regulation?
  • Are there Georgia-specific HIPAA, FERPA, FCRA, GINA, or TCPA/CAN-SPAM enforcement actions or state-law overlays that supplement the federal baseline?
  • Will a successor comprehensive privacy bill be introduced in Georgia's 2026 legislative session following SB 111's failure in 2025?

Escalate to primary-source review: yes