Georgia
Georgia Data Privacy Laws: Breach Notification & Consumer Rights (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 7, 2026. · 20 primary sources cited on this page. How we verify our legal content

Georgia does not have a comprehensive consumer data privacy law. Senate Bill 111 would have created the Georgia Consumer Privacy Protection Act and given residents rights to access, correct, and delete their personal data, but a House committee stripped that text out in March 2026. Governor Kemp signed the substitute bill, an unrelated rural hospital tax credit measure, into law on May 11, 2026. The state's breach notification statute, O.C.G.A. Section 10-1-912, separately requires prompt notice after a breach, but it reaches a much narrower set of entities than most states' breach laws do.
Georgia's comprehensive privacy bill failed for a second consecutive year in the spring of 2026, though it advanced further than any prior attempt. The Senate passed Senate Bill 111, the Georgia Consumer Privacy Protection Act, in early 2026. A House committee then replaced the entire bill with an unrelated substitute amending the state's rural hospital tax credit statute, O.C.G.A. Section 31-8-9.1. That substitute, not the privacy bill, is what Governor Brian Kemp signed into law as Act 462 on May 11, 2026. Georgia remains without a comprehensive consumer data privacy statute.
Had it passed as introduced, SB 111 would have given Georgia residents rights over their personal data that do not currently exist at the state level: the right to access, correct, delete, and opt out of the sale of their information and its use for targeted advertising. It would also have placed obligations on businesses that meet specific revenue and data-processing thresholds. Consumer advocacy groups including EPIC and the ACLU of Georgia criticized the Senate-passed bill as one of the weakest privacy proposals in the country even before it was gutted, citing high applicability thresholds, a 60-day cure period before penalties could be imposed, and no private right of action.
Georgia residents continue to rely on the state's data breach notification law, sector-specific statutes, and federal protections for privacy coverage. Those laws remain in force and are the primary source of privacy protection for Georgians, since the state has no comprehensive consumer privacy statute.
This guide covers SB 111's legislative history in full, along with the breach notification statute, the Computer Systems Protection Act, student data protections, the AI chatbot disclosure law, the social media age verification law currently in federal court, and the federal overlay that applies to all Georgia residents.
SB 111: How Georgia's Consumer Privacy Protection Act Failed (2026)
Senate Bill 111 began as the Georgia Consumer Privacy Protection Act, which would have enacted Article 37 of Title 10 of the Official Code of Georgia Annotated (proposed Code Sections 10-1-960 through 10-1-974). The Senate passed this privacy version, following the Virginia Consumer Data Protection Act (VCDPA) model used by many other states. Consumer advocates at EPIC gave the Senate-passed bill a score of 6 out of 100, citing inadequate thresholds and weak enforcement mechanisms.
A House committee then replaced the entire bill with a substitute unrelated to privacy. The substitute amends O.C.G.A. Section 31-8-9.1, revising the definition of a rural hospital organization for purposes of Georgia's rural hospital tax credit program. That substitute, not the privacy bill, passed the House and Senate and is what Governor Kemp signed into law as Act 462 on May 11, 2026. The Governor's own press release announcing the signing describes SB 111 solely as expanding tax-credit eligibility for rural hospitals and freestanding emergency departments, with no mention of consumer privacy. This is the second consecutive year a Georgia comprehensive privacy bill has failed to reach the Governor's desk intact, after a similar effort (SB 473) stalled in 2024.

Applicability Thresholds
Had it become law, SB 111 would have applied to entities that conduct business in Georgia or produce products or services targeted to Georgia residents, AND that met one of the following thresholds:
- Control or process personal data of at least 175,000 Georgia residents per calendar year, OR
- Control or process personal data of at least 25,000 Georgia residents per calendar year AND derive more than 50% of gross annual revenue from the sale of personal data
The bill also would have required the entity to exceed $25 million in annual gross revenue. Those thresholds were substantially higher than in states like California and Maryland, one of the reasons consumer advocates criticized the Senate-passed bill as weak. None of this applies in Georgia today, since the privacy provisions never became law.
Exempt Sectors and Data Types
The Senate-passed version of SB 111 contained broad exemptions consistent with other Virginia-model laws. The following entities and data types would have been generally exempt had the bill become law:
- Government entities and their contractors
- Financial institutions and data subject to the Gramm-Leach-Bliley Act (GLBA)
- Covered entities and business associates subject to HIPAA
- Nonprofit organizations
- Institutions of higher education
- Data subject to the Fair Credit Reporting Act (FCRA)
- Employee and contractor data processed in a human resources context
Consumer Rights
Had SB 111 taken effect as passed by the Senate, Georgia residents would have had the following rights, exercised by submitting a verified request to a covered controller:
- Right to access: Confirm whether a controller processes your personal data and obtain a copy of it.
- Right to correct: Correct inaccurate personal data maintained about you.
- Right to delete: Request deletion of personal data you provided or that the controller collected about you.
- Right to portability: Obtain a copy of your personal data in a portable, readily usable format.
- Right to opt out of targeted advertising: Opt out of the processing of your personal data for purposes of targeted advertising.
- Right to opt out of data sales: Opt out of the sale of your personal data.
- Right to opt out of profiling: Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects.
Under the never-enacted bill, controllers would have had to respond to verified consumer requests within 45 days, with a permitted 45-day extension when reasonably necessary. None of these rights or deadlines apply in Georgia today.
Sensitive Data
The Senate-passed SB 111 defined sensitive data broadly to include personal data that reveals racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sexual orientation, or citizenship or immigration status, genetic or biometric data processed for the purpose of uniquely identifying a natural person, precise geolocation data, and personal data of a known child.
Controllers would have had to obtain the consumer's consent before processing sensitive data under the bill as passed by the Senate. None of this is in force today, since the privacy provisions never became law.
Children's Data
The Senate-passed SB 111 would have let a known child's parent or legal guardian invoke any of the bill's consumer rights on the child's behalf, and would have required consent before processing a known child's sensitive data. None of these protections exist under current Georgia law.
Controller and Processor Obligations
Had SB 111 become law, controllers would have been required to:
- Provide consumers with a reasonably accessible privacy notice describing the categories of data collected, the purposes for processing, how consumers can exercise their rights, and the categories of data shared with third parties.
- Limit data collection to what is adequate, relevant, and reasonably necessary for the disclosed purposes.
- Establish reasonable administrative, technical, and physical security practices appropriate to the volume and nature of personal data processed.
- Conduct data protection assessments for high-risk processing activities including targeted advertising, sale of personal data, profiling with significant effects, processing sensitive data, and processing activities that present a heightened risk of harm.
- Execute data processing agreements with processors that establish the processor's instructions and obligations.
Processors would have been required to process data only on documented instructions from the controller and to assist controllers in meeting their security and consumer-rights obligations. None of these obligations exist under Georgia law today.
Enforcement and Penalties
The Senate-passed SB 111 would have given the Georgia Attorney General exclusive authority to enforce the law, with no private right of action for individual consumers. It would have required a 60-day cure period before the AG could bring an enforcement action, after which the AG could have sought:
- Civil penalties of up to $7,500 per violation
- Injunctive relief
None of this enforcement framework exists, because the privacy bill never became law.
What SB 111 Does Not Require
Even as passed by the Senate, before it was gutted, SB 111 would not have required:
- A Universal Opt-Out Mechanism (UOOM) or Global Privacy Control (GPC) recognition
- A dedicated privacy agency (the AG would have enforced it)
- Data minimization as an independent standalone requirement beyond what is reasonably necessary for disclosed purposes
This would have placed the Senate-passed bill toward the less protective end of the spectrum compared to California (CPRA), Oregon (OCPA), and Maryland (MODPA), had it become law. As actually enacted, Georgia has no comprehensive privacy statute at all.
Georgia's Data Breach Notification Law (O.C.G.A. Section 10-1-910 Through 10-1-912)
The Georgia Personal Identity Protection Act, originally enacted in 2005 and expanded in 2007, is the state's actual data-protection framework, since the Senate-passed SB 111 privacy provisions never became law. Its scope is unusually narrow, and that is the single most distinctive feature of Georgia's breach law. Section 10-1-912(a) places the notice duty on any information broker or data collector that maintains computerized personal information. Section 10-1-911(2) defines a data collector as any state or local agency or subdivision, including any department, bureau, authority, public university or college, academy, commission, or other government entity. Section 10-1-911(3) defines an information broker as a person or entity that, for monetary fees or dues, is in the business of collecting, assembling, evaluating, compiling, reporting, transmitting, transferring, or communicating information about individuals for the primary purpose of furnishing personal information to nonaffiliated third parties.
An ordinary Georgia retailer, restaurant, or employer holding customer or employee records is therefore not covered by Section 10-1-912(a) at all. Such a business is reached only by Section 10-1-912(b), and only when it maintains the data on behalf of an information broker or data collector, in which case its duty is to notify that broker or collector rather than the affected individuals.

What Qualifies as Protected Personal Information?
Under O.C.G.A. Section 10-1-911, personal information means an individual's first name or first initial and last name combined with any one or more of the following unencrypted or unredacted elements:
- Social Security number
- Driver's license number or state identification card number
- Account number, credit card number, or debit card number, if circumstances exist wherein such a number could be used without additional identifying information, access codes, or passwords
- Account passwords or personal identification numbers or other access codes
Section 10-1-911(6)(E) then widens the definition: any of those elements standing alone, unconnected to a first name or first initial and last name, still counts as personal information if what was compromised would be sufficient to perform or attempt to perform identity theft against the person. The definition excludes publicly available information lawfully made available to the general public from federal, state, or local government records.
Notification Requirements
When a breach occurs, the covered information broker or data collector must notify affected Georgia residents in the most expedient time possible and without unreasonable delay. Georgia does not impose a specific deadline measured in calendar days, distinguishing it from states that require notification within 30, 45, or 72 hours. The only permitted delay is when a law enforcement agency determines notification would compromise an active criminal investigation.
Section 10-1-911(4) permits written notice, telephone notice, or electronic notice consistent with the federal E-Sign Act. Substitute notice becomes available only where the cost of providing notice would exceed $50,000, the affected class exceeds 100,000, or the entity lacks sufficient contact information.
Substitute notice is not media notice alone. The statute says it shall consist of all of the following: email notice where the entity has email addresses for the individuals, conspicuous posting of the notice on the entity's website page if it maintains one, and notification to major state-wide media. An entity that runs a media notice by itself has not complied.
Large-Scale Breach Reporting
When a breach affects more than 10,000 Georgia residents at one time, the entity must also notify all three nationwide consumer reporting agencies. This notification must include the timing, distribution, and content of the notices sent to affected individuals.
Third-Party Data Processor Notice
Any person or business that maintains computerized personal information on behalf of an information broker or data collector must notify that broker or collector within 24 hours of discovering a breach. This is the subsection that reaches ordinary vendors and service providers, and the duty it creates runs to the client entity, not to the affected individuals.
Enforcement
Article 34 is silent on enforcement. O.C.G.A. Sections 10-1-910 through 10-1-912 contain no penalty, no enforcement mechanism, and no private right of action, and they do not cross-reference the Georgia Fair Business Practices Act. The contrast is instructive: Georgia's telephone-records breach statute, O.C.G.A. Section 46-5-214(d), expressly declares that a violation constitutes an unfair or deceptive practice in consumer transactions within the meaning of the Fair Business Practices Act, and the Article 34 breach sections carry no comparable clause. Consumers can still report a breach to the Georgia Attorney General's Consumer Protection Division, which handles consumer complaints generally.
In 2024, AG Chris Carr's Consumer Protection Division secured nearly $80 million total for Georgia taxpayers and consumers through enforcement across multiple consumer protection statutes.
Georgia Computer Systems Protection Act (O.C.G.A. Section 16-9-90 et seq.)
The Computer Systems Protection Act provides criminal penalties for unauthorized access to computer systems and personal data. It functions alongside the breach notification law, adding criminal liability for intrusions into computer systems and personal data.

Criminal Offenses
The Act establishes four major felony offenses under O.C.G.A. Section 16-9-93:
Computer Theft (Section 16-9-93(a)): Using a computer with intent to take or appropriate property of another, including data and programs.
Computer Trespass (Section 16-9-93(b)): Unauthorized access to a computer with intent to delete, alter, damage, or destroy data, or to introduce a contaminant.
Computer Invasion of Privacy (Section 16-9-93(c)): Using a computer with intent to examine employment, medical, salary, credit, or other financial or personal data relating to another person without authorization.
Computer Forgery (Section 16-9-93(d)): Using a computer to create, alter, or delete data in a manner that would constitute forgery under Georgia law.
Each of these felony offenses carries a maximum fine of $50,000 and up to 15 years in prison, or both. Computer Password Disclosure is a separate misdemeanor carrying a maximum fine of $5,000 and up to one year in jail.
Civil Remedies
Any person whose property or person is injured by a violation of the Computer Systems Protection Act may file a civil lawsuit. The statute of limitations for civil claims is four years from the date the violation is discovered or should have been discovered through reasonable diligence.
Protecting Georgia's Children on Social Media Act (SB 351, 2024)
The Protecting Georgia's Children on Social Media Act was signed into law in 2024. It requires social media platforms to verify the age of users and obtain parental consent before allowing children under 16 to create accounts.
Federal litigation immediately followed. The industry group NetChoice filed suit arguing the law violates the First Amendment. U.S. District Judge Amy Totenberg issued a preliminary injunction blocking the law on June 26, 2025, just days before its July 1, 2025 effective date. She found the law likely violated the First Amendment rights of children, adults, and platforms.
Georgia AG Chris Carr appealed to the U.S. Court of Appeals for the Eleventh Circuit. Oral arguments took place on March 10, 2026, in Jacksonville, Florida. A three-judge panel pressed NetChoice on standing and whether the lower court moved too quickly to issue a facial injunction. The panel signaled some receptiveness to Georgia's arguments but had not issued a ruling as of this writing. The law remains enjoined pending the appeal.
Georgia AI Companion Chatbot Disclosure Law (SB 540, 2026)
Governor Kemp signed SB 540 into law in May 2026. The Act, which enacts O.C.G.A. Section 39-5-6, takes effect July 1, 2027. It reaches AI companion chatbots specifically rather than chatbots generally: systems that simulate a sustained human or human-like relationship with a user by retaining information from prior interactions or sessions, asking unprompted emotion-based questions that go beyond a direct response to a prompt, and sustaining an ongoing dialogue about matters personal to the user. Operators of a covered chatbot must clearly and conspicuously disclose that the user is interacting with an AI companion chatbot rather than a natural person.
The definition carries express exclusions. It does not cover systems used solely for a business's internal purposes, systems designed and marketed primarily for software development, research, technical assistance, or enterprise productivity, customer-service chatbots that do not sustain a relationship across multiple interactions or elicit emotional attachment, stand-alone voice-command devices and virtual assistants, narrowly tailored educational tools built for curriculum-aligned learning objectives rather than open-ended conversational companionship, video game nonplayer characters restricted to the subject matter of the game, or systems tied to a film, television program, other audiovisual work, or theme park attraction. An ordinary customer-service or task bot is therefore unlikely to be covered.
Key requirements include:
- Disclosure must appear at the beginning of each interaction or session and at least every three hours during continued interaction.
- Where the operator knows or reasonably should have known the user is a minor, or the chatbot is directed or marketed to minors, that disclosure repeats every hour instead.
- Where the user is a minor, the operator must take reasonable measures to prevent the chatbot from claiming to be sentient or a natural person and from refuting the disclosure.
- Every operator must maintain a protocol for detecting and responding to suicidal ideation, self-harm, and related crises, including referral to the 988 Suicide and Crisis Lifeline, and must publish a plain-language summary of that protocol.
- The Attorney General enforces the law and may seek a civil penalty of up to $10,000 per knowing violation, with discretion to allow a 30-day cure for a first-time violation that does not involve knowing misconduct, sexual exploitation of a minor, or self-harm related misconduct.
Student Data Privacy
Georgia enacted the Student Data Privacy, Accessibility, and Transparency Act (O.C.G.A. Section 20-2-661 through 20-2-667), effective July 1, 2016, to protect personal information of K-12 students. The law requires the Georgia Department of Education to designate a chief privacy officer, restricts collection of sensitive student data including political affiliations and religious beliefs, imposes data management requirements on education technology operators, and gives parents the right to inspect their children's education records.

These state protections supplement the federal Family Educational Rights and Privacy Act (FERPA), which has governed access to student education records since 1974.
Insurance Data Privacy
Georgia regulates the collection, use, and disclosure of personal information in insurance transactions through Georgia Administrative Code Section 120-2-87, issued by the Office of the Commissioner of Insurance. These regulations implement Title V of the federal Gramm-Leach-Bliley Act (GLBA) and cover insurance institutions, agents, and support organizations operating in Georgia.
Covered entities must provide privacy notices, allow opt-out of certain information sharing with nonaffiliated third parties, and implement safeguards to protect customer information.
Georgia has not adopted the NAIC Insurance Data Security Model Law (Model 668), which would impose more specific cybersecurity requirements on insurers.
Health Information Privacy
Georgia does not have a state health data privacy law that exceeds federal protections. The Health Insurance Portability and Accountability Act (HIPAA) governs protected health information held by covered entities and their business associates. Georgia relies primarily on HIPAA's Privacy Rule and Security Rule.
Georgia does have statutes governing medical records access: O.C.G.A. Section 31-33-2 requires physicians to provide patients with copies of medical records upon request, and Section 31-33-3 sets copying fees with annual CPI adjustments.
Workplace and Employee Data Privacy
Georgia does not have a comprehensive employee data privacy statute. Employer surveillance rights are broad: video monitoring is permitted in common areas, audio recording of business communications is lawful under Georgia's one-party consent standard (O.C.G.A. Section 16-11-62), and employee monitoring of computer use and communications on company systems is generally permitted. Had SB 111 become law, it would have exempted employee and contractor data processed in a human resources context from its consumer rights provisions.
Federal Laws That Protect Georgia Residents
Federal statutes remain the primary privacy framework for Georgia residents, since the state has no comprehensive privacy law of its own.

TAKE IT DOWN Act (Pub. L. 119-12, Signed May 19, 2025)
The TAKE IT DOWN Act is a federal law targeting nonconsensual intimate visual depictions (NCII), including AI-generated deepfakes. President Trump signed it into law on May 19, 2025. The criminal prohibition on publishing NCII took effect immediately upon signing.
The platform takedown obligations took effect on May 19, 2026. Covered platforms must now maintain a process for consumers to report NCII and must remove reported content within 48 hours of receiving notice. The FTC enforces these obligations and may seek civil penalties of up to $53,088 per violation. The FTC launched TakeItDown.ftc.gov for consumers to report violations.
HIPAA
HIPAA protects individually identifiable health information held by covered entities (healthcare providers, health plans, clearinghouses) and their business associates. Georgia's healthcare sector is a major HIPAA-regulated industry.
Gramm-Leach-Bliley Act (GLBA)
GLBA requires financial institutions to explain information-sharing practices and safeguard customer data. Georgia's insurance regulator enforces GLBA compliance for insurers through GAC 120-2-87. Federal banking regulators cover banks and credit unions.
Children's Online Privacy Protection Act (COPPA)
COPPA requires operators of websites and online services directed at children under 13 to obtain verifiable parental consent before collecting personal information. The FTC enforces COPPA nationwide and has broad rulemaking authority.
Fair Credit Reporting Act (FCRA)
FCRA governs the collection, use, and disclosure of consumer credit information. Georgia residents have rights under FCRA to access their credit files and dispute inaccurate information. State law provides an additional two free credit reports per year from each major reporting agency, beyond the one federally guaranteed.
FTC Act Section 5
The FTC Act prohibits unfair or deceptive trade practices. The FTC uses Section 5 authority to enforce data security and privacy commitments against companies across all sectors, including against businesses that violate their own privacy policies or fail to maintain adequate data security.
American Privacy Rights Act (APRA)
Congress introduced the American Privacy Rights Act as a bipartisan federal comprehensive privacy bill in 2024. It did not pass the 118th Congress. As of mid-2026, no successor bill has been enacted into law. There is no federal comprehensive consumer privacy law in force.
Practical Compliance Steps for Businesses
Businesses operating in Georgia face a narrower compliance environment than a comprehensive privacy law would create, since Georgia has no comprehensive consumer privacy statute as of mid-2026.
Watch for a Revived Privacy Bill: Georgia's privacy bill has now failed in this specific form for a second consecutive session, after SB 473 stalled in 2024 and SB 111's privacy text was stripped in 2026. The Senate-passed thresholds and obligations described above show what a future Georgia law might require if lawmakers reintroduce similar text.
Check Whether the Breach Statute Reaches You at All: The Personal Identity Protection Act (O.C.G.A. Section 10-1-910 et seq.) puts the notice duty on information brokers and on government data collectors, not on Georgia businesses generally. If you hold personal information on behalf of one of those entities, your obligation under Section 10-1-912(b) is to notify that entity within 24 hours of discovering a breach. Businesses outside the statute still face contractual, sector-specific, and other states' breach obligations, so a written response plan remains worth maintaining.
Review Sector-Specific Obligations: Businesses in insurance, healthcare, and education continue to face obligations under Georgia's insurance data privacy regulations, HIPAA, and the state's student data privacy law.
Prepare AI Companion Chatbot Disclosures: If you operate an AI companion chatbot, plan for compliance with SB 540 by July 1, 2027. Customer-service, enterprise, and curriculum-aligned educational bots fall outside its definition.
TAKE IT DOWN Compliance: If you operate a covered platform, maintain a notice-and-removal process for nonconsensual intimate images.
How Georgia Residents Exercise Their Rights
Georgia residents do not have a state-law right to submit access, correction, deletion, or opt-out requests to businesses, since SB 111's consumer rights provisions were stripped from the bill before it became law. Residents can still exercise any rights a business voluntarily offers, or rights available under other states' privacy laws when a business is also subject to those laws.
For breach notification issues, file a complaint with the Georgia Attorney General's Consumer Protection Division at consumer.georgia.gov or call 404-651-8600.
For NCII or deepfake intimate images on platforms, report violations to the FTC at TakeItDown.ftc.gov as of May 19, 2026.
For credit-related privacy issues, contact the Consumer Financial Protection Bureau or file a dispute directly with the three major credit bureaus.
More Georgia Laws
Frequently Asked Questions
Does Georgia have a comprehensive consumer data privacy law?
No. Georgia does not have a comprehensive consumer data privacy law. The Senate passed Senate Bill 111, the Georgia Consumer Privacy Protection Act, in early 2026, but a House committee replaced the entire bill with an unrelated rural hospital tax credit measure before final passage. Governor Kemp signed that substitute, not the privacy bill, into law as Act 462 on May 11, 2026. Had the Senate-passed version become law, it would have given Georgia residents rights to access, correct, delete, and opt out of targeted advertising and data sales, applying to businesses with more than $25 million in revenue that process personal data of at least 175,000 Georgia residents, or at least 25,000 residents if more than 50% of revenue comes from data sales. None of that took effect.
What must a company do if my personal data is breached in Georgia?
It depends on who holds the data, because Georgia's law is narrower than most. Under O.C.G.A. Section 10-1-912(a), the duty to notify you falls on information brokers and on government data collectors as O.C.G.A. Section 10-1-911 defines those terms, not on every business that holds your information. Where the duty applies, notice must be made in the most expedient time possible and without unreasonable delay, and it may be written, by telephone, or electronic. If the breach affects more than 10,000 Georgia residents, the entity must also notify all three nationwide consumer reporting agencies. A company that maintains the data on behalf of a broker or collector must notify that entity within 24 hours, and it is that entity that then notifies you.
Can I sue a company for a data breach in Georgia?
Georgia's breach notification statute does not provide a private right of action. Georgia has no comprehensive privacy statute that could support a private right of action either, since SB 111's privacy text never became law. However, you may have claims under the Computer Systems Protection Act (O.C.G.A. Section 16-9-93) if someone accessed your data without authorization, with a four-year statute of limitations. Common law claims for negligence or invasion of privacy may also be available depending on the circumstances.
Does Georgia have a Universal Opt-Out Mechanism like Colorado or California?
No. Georgia has no comprehensive privacy law, so there is no Universal Opt-Out Mechanism or Global Privacy Control recognition requirement, and no general Georgia-law right to opt out of targeted advertising or data sales. Some national businesses honor opt-out requests voluntarily under other states' laws through the mechanisms in their privacy notices, but Georgia statute does not require it.
What are the penalties for violating Georgia's privacy laws?
Georgia has no enacted comprehensive privacy statute, so there is no SB 111-style penalty in force. The breach notification sections, O.C.G.A. Sections 10-1-910 through 10-1-912, contain no penalty provision and no enforcement mechanism at all. The Computer Systems Protection Act imposes criminal penalties for unauthorized data access: up to 15 years in prison and a $50,000 fine for felony offenses. SB 540 will let the Attorney General seek up to $10,000 per knowing violation of the AI companion chatbot law once it takes effect on July 1, 2027. The Senate-passed version of SB 111 would have authorized civil penalties of up to $7,500 per violation after a 60-day cure period, but that provision was stripped before the bill became law.
Does the TAKE IT DOWN Act apply to Georgia residents?
Yes. The TAKE IT DOWN Act is a federal law signed on May 19, 2025, that applies nationwide. As of May 19, 2026, covered platforms must maintain a process to remove nonconsensual intimate images within 48 hours of receiving notice. This includes AI-generated deepfakes. Georgia residents can report platform non-compliance to the FTC at TakeItDown.ftc.gov.
What is the status of Georgia's social media age verification law?
The Protecting Georgia's Children on Social Media Act (SB 351, 2024) requires parental consent before children under 16 can open social media accounts. A federal district court blocked the law with a preliminary injunction on June 26, 2025, finding it likely violated the First Amendment. Georgia AG Chris Carr appealed to the Eleventh Circuit Court of Appeals. Oral arguments took place on March 10, 2026. The case remains pending, and the law is not in effect while the injunction stands.
How does Georgia protect student data privacy in schools?
Georgia enacted the Student Data Privacy, Accessibility, and Transparency Act (O.C.G.A. Section 20-2-661 through 20-2-667) in 2016. It requires the Department of Education to appoint a chief privacy officer, restricts collection of student political and religious data, protects juvenile delinquency and medical records, imposes requirements on education technology operators, and gives parents the right to inspect their children's records. These protections supplement the federal FERPA law.
Updates
Corrected the scope of Georgia's breach notification law, which reaches information brokers and government data collectors rather than businesses generally, restated the statutory definition of personal information and the full substitute-notice requirements, removed an unsupported claim that breach violations carry Fair Business Practices Act penalties, and narrowed the description of SB 540 to AI companion chatbots.
This page previously reported that Georgia enacted a comprehensive consumer privacy law (SB 111, the Georgia Consumer Privacy Protection Act) on May 11, 2026. That was incorrect: the Senate-passed privacy bill was replaced by a House committee with an unrelated rural hospital tax credit measure before final passage, and the bill Governor Kemp actually signed as Act 462 has no privacy content. Georgia has no comprehensive consumer data privacy law as of this correction; the article now describes the failed legislative history and the state's actual protections (breach notification law, Computer Systems Protection Act, and sector-specific and federal statutes).
Independently fact-checked against the cited primary sources
Governing law re-checked for recent changes
Correction (2026-08-14): This entry previously stated that Georgia enacted SB 111 as a comprehensive consumer privacy law. That was incorrect. The Senate-passed privacy text was stripped by a House committee substitute in March 2026, and the bill Governor Kemp signed as Act 462 on May 11, 2026, is an unrelated rural hospital tax credit measure. Georgia has no comprehensive consumer data privacy statute. Original entry (2026-05-20): Updated SB 351 social media law status (injunction in place, Eleventh Circuit argued March 10, 2026). Added SB 540 AI chatbot disclosure law (signed May 2026, effective July 1, 2027). Updated TAKE IT DOWN Act section to reflect platform takedown obligations now in force as of May 19, 2026. Updated APRA status (not enacted). Revised KeyTakeaways, FAQ, and SourcesList.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Official Code of Georgia Annotated
§ 10-1-912Notification required upon breach of security regarding personal information.In forcecited in 3 of our articles
(a) Any information broker or data collector that maintains computerized data that includes personal information of individuals shall give notice of any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of this state…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legis.ga.gov
Cited in 3 court opinions in our collectionLatest citing opinion in our collection: 2019
Opinions citing this section in our collection:
- McCONNELL Et Al. v. DEPARTMENT OF LABOR (Court of Appeals of Georgia 2016, 337 Ga. App. 457)“…is of the timing, distribution, and content of the notices. OCGA §10-1-912. See OCGA § 10-1-911 (1) (definition of…”
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 362 F. Supp. 3d 1295)“…The Court agrees that the absence of any such language in O.C.G.A. § 10-1-912 counsels strongly against inferring a p…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Georgia Biometric Privacy Laws: Collection, Consent & Penalties (2026), Georgia Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 10-1-911Definitions.In forcecited in 3 of our articles
As used in this article, the term: (1) "Breach of the security of the system" means unauthorized acquisition of an individual's electronic data that compromises the security, confidentiality, or integrity of personal information of such individual maintained by an information broker or data collect
Official text (excerpt) · last checked 2026-08-04 · Read the full text in our law library · Verify at legis.ga.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2018
Opinions citing this section in our collection:
- McCONNELL Et Al. v. DEPARTMENT OF LABOR (Court of Appeals of Georgia 2016, 337 Ga. App. 457)“…stribution, and content of the notices. OCGA §10-1-912. See OCGA § 10-1-911 (1) (definition of a “breach of the sec…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 16-11-62Eavesdropping, surveillance, or intercepting communication which invades privacy of another; divulging private message.In forcecited in 25 of our articles
It shall be unlawful for: (1) Any person in a clandestine manner intentionally to overhear, transmit, or record or attempt to overhear, transmit, or record the private conversation of another which shall originate in any private place; (2) Any person, through the use of any device, without the
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at legis.ga.gov
Cited in 94 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Kelley v. State (1998) held OCGA 16-11-62(2) reached a guardian who photographed a nude 16-year-old in the family bathroom, with no exception for family members. Burgeson v. State (1996) held a conversation recorded in a patrol car was not covered, because no reasonable expectation of privacy existed there.
Opinions citing this section in our collection:
- Burgeson v. State (Supreme Court of Georgia 1996, 267 Ga. 102)✓Police secretly recorded two arrestees talking in the back of a patrol car. The court held a police car is much like a jail cell, with no reasonable expectation of privacy, so intercepting that conversation did not offend OCGA 16-11-62 and the tape was admissible.
- Kelley v. State (Court of Appeals of Georgia 1998, 233 Ga. App. 244)✓A guardian photographed her 16-year-old niece nude and passed out in the family bathtub. The court held OCGA 16-11-62(2) reaches any person with no family exception, that the film need not be developed, and that a jury could find the bathroom a private place.
- Dobbins v. State (Supreme Court of Georgia 1992, 262 Ga. 161)“…th the consent of one of the parties to the conversation. OCGA § 16-11-62 (1) provides that: It shall be unlawf…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Georgia Ring Doorbell Laws: What You Need to Know in 2026, Georgia Surveillance Camera Laws (2026 Guide), Georgia Windshield Mounting Laws (2026 Guide)
United States Code Title 15
§ 6801Protection of nonpublic personal informationIn forcecited in 4 of our articles
It is the policy of the Congress that each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and to protect the security and confidentiality of those customers’ nonpublic personal information. In furtherance of the policy in subsection (a), each agency or authority described in section 6805(a) of this title, other than the Bureau of Consumer Financial Protection, shall establish appropriate standards for the financial institutions subject to their jurisdiction relating to administrative, technical, and physical safeguards— to insure the security and confidentiality of customer records and information; to protect against any anticipated threats or hazards to the security or integrity of such records; and to protect against unauthorized access to or use of such records or information which could result in substantial harm or inconvenience to any customer.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 250 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Individual Reference Services Group, Inc. v. Federal Trade Commission (District Court, District of Columbia 2001, 145 F. Supp. 2d 6)“…o. 106-102, 113 Stat. 1338 (1999) (codified as amended at 15 U.S.C.A. § 6801 'et seq. (2000)) (the “GL…”
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 371 F. Supp. 3d 1150)“…p. , 799 F.3d 236 , 247 (3d Cir. 2015). See 15 U.S.C. § 6801 (b). See 16 C.F.R. § 314.4…”
- Leland Stevens v. Interactive Financial Advisors (Court of Appeals for the Seventh Circuit 2016, 830 F.3d 735)“…clients to a non- affiliated third party like Stevens. See 15 U.S.C. § 6801; 17 C.F.R. § 248.10. This prevented Ste…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Oklahoma Data Privacy Laws: OKCDPA, Breach Notification & Consumer Rights (2026), Michigan Data Breach Notification Laws: Reporting Rules & Timelines (2026), New Hampshire Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Georgia Code § 10-1-912 - Notification required upon breach of security regarding personal information(law.justia.com)
- Georgia Code § 10-1-911 - Definitions(law.justia.com)
- Georgia Attorney General - Data Breaches: How to Protect Your Information(consumer.georgia.gov).gov
- Getting notified following a data breach - Georgia Consumer Protection Division(consumered.georgia.gov).gov
- Georgia Computer Systems Protection Act - O.C.G.A. Title 16, Chapter 9, Article 6, Part 1(law.justia.com)
- Georgia Administrative Code - GAC 120-2-87: Regulations Governing Collection, Use, and Disclosure of Information in Insurance Transactions(rules.sos.ga.gov).gov
- NAIC Insurance Data Security Model Law - State Adoption Status(content.naic.org)
- Student Data Privacy, Accessibility, and Transparency Act - Georgia Department of Education(georgiainsights.gadoe.org).gov
- FERPA - Georgia Department of Education(georgiainsights.gadoe.org).gov
- Georgia Code § 16-11-62 - Eavesdropping, Surveillance, or Intercepting Communication(law.justia.com)
- SB 111 - Georgia Consumer Privacy Protection Act, As Passed Senate (never enacted; House substitute removed all privacy provisions before final passage)(legis.ga.gov).gov
- SB 473 - Georgia Consumer Privacy Protection Act (2024)(legis.ga.gov).gov
- Protecting Georgia's Children on Social Media Act - SB 351(legis.ga.gov).gov
- Georgia Attorney General - Carr Continues Fight to Keep Kids Safe Online (March 2026)(law.georgia.gov).gov
- HIPAA Privacy Notices - Georgia Department of Community Health(dch.georgia.gov).gov
- Cybersecurity in Georgia - Georgia Attorney General Consumer Protection(consumer.georgia.gov).gov
- Georgia Privacy/Security Policy(georgia.gov).gov
- Georgia DHS Data Breach Response Policy(pamms.dhs.ga.gov).gov
- Georgia General Assembly - SB 111 Bill History (Act 462 is an unrelated rural hospital tax credit substitute, not the privacy bill)(legis.ga.gov).gov
- Georgia Governor - Signed Legislation SB 111 / Act 462 (2026) - rural hospital tax credit eligibility, not a privacy law(gov.georgia.gov).gov
- Office of the Georgia Attorney General - Chris Carr(law.georgia.gov).gov
- Georgia AG Press Release: Carr Secures Nearly $80 Million for Georgia Taxpayers and Consumers in 2024(law.georgia.gov).gov
- Gramm-Leach-Bliley Act, 15 U.S.C. Section 6801 (Safeguarding Customer Information) - Cornell LII(law.cornell.edu)
- FTC - TAKE IT DOWN Act (Pub. L. 119-12)(ftc.gov).gov
- FTC Blog: Take It Down Act Enforcement Starts Now (May 2026)(ftc.gov).gov
- FTC Consumer Advice: What Will the FTC Enforcement of the TAKE IT DOWN Act Mean for You?(consumer.ftc.gov).gov
- EPIC - Georgia Privacy Bill (SB 111) Earns Failing Grade(epic.org)
- ACLU of Georgia - Report: Georgia Consumer Privacy Bill Gets a Failing Grade(acluga.org)
- Chambers and Partners - Data Protection and Privacy 2026: USA Georgia Trends and Developments(practiceguides.chambers.com)
- Business Software Alliance - BSA Letter on Georgia SB 111(bsa.org)
- Georgia SB 236 (2007), as passed - Georgia Personal Identity Protection Act, enacting the current text of O.C.G.A. Sections 10-1-911 and 10-1-912(legis.ga.gov)
- Georgia SB 540 (2026), signed act text enacting O.C.G.A. Section 39-5-6 (AI companion chatbot disclosures)(gov.georgia.gov)