A surrogacy family file should be shared according to each person's rights and the purpose of the specific task, not simply because one client paid for the services. Identify the lawful requester, the organisation deciding how information is used and the minimum documents needed. Health and genetic information need particular care. International transfer, access, correction and incident reporting require separate analysis. Georgia's current data-protection supervisor is the State Audit Office, which succeeded the former service on 2 March 2026.
Legal support for this matter: Defamation & Privacy Disputes
Identify the people and information in the file
Start by separating the child's information from each adult's information. A folder may contain passport details, contracts, financial records, clinical material, genetic reports and messages about several individuals. The family does not acquire unrestricted rights over all those records by financing the arrangement. Ask whose data appear on each page and why the particular recipient needs them. A combined file can contain information that is relevant to one person's request but confidential in relation to another person.
Make an inventory by category and purpose rather than copying everything into a new shared folder. Record the holder, the intended recipient, the legal or administrative task and the proposed transmission method. Identify especially sensitive material before circulation. Georgia's law distinguishes ordinary personal information from special categories, including health and certain genetic or biometric information. The practical consequence is to assess the actual data and processing purpose instead of treating every attachment as harmless paperwork.
Official sources: Georgian Personal Data Protection Law
Find the responsible organisation behind each service
Ask which legal entity decides why and how the records will be used. The agency, clinic, translator, storage provider and lawyer may have different roles. A provider acting on another organisation's instructions is not necessarily the same as an organisation deciding its own purposes. Contract labels alone are insufficient if the actual handling differs. Establish a reliable contact for requests and incidents, and distinguish the corporate contact from an employee's personal chat account.
A useful answer explains what the organisation holds, why it holds it, who receives it and how long it is kept. Ask whether subcontractors can access the material and what happens when staff leave or services end. These questions can be raised before sending full records. The law's controller and processor framework supports this division of responsibility, but a family should obtain a case-specific assessment where multiple organisations jointly determine purposes. Naming one coordinator does not erase the responsibilities of other holders.
Official sources: Georgian Personal Data Protection Law
Assess the purpose and lawful basis of each use
Consent is one possible basis, but it is not the only basis for processing and it does not make every use lawful. The legal analysis depends on the purpose, the category of information and the relevant statutory conditions. A document needed for an official application raises different questions from the same document reused in advertising. Clinical processing and an agency's marketing activity should not be grouped under one broad permission that the family cannot meaningfully understand.
Ask for a clear explanation of the proposed activity: what information, whose information, which recipient and what result is sought. If the organisation relies on consent, the request should be understandable and specific. If it relies on a statutory duty or another basis, ask it to identify that basis. Do not sign a blank or unlimited authorisation simply because the file is urgent. Restrictions on disclosure must also be reconciled with lawful evidence preservation and mandatory records, rather than promising that every copy can disappear on demand.
Official sources: Georgian Personal Data Protection Law
Prepare a different disclosure set for each recipient
The consular authority, translator and courier do not ordinarily need the same set of information for the same reason. First identify the official requirement, then select the relevant pages. The Chinese Embassy's first-issuance checklist, for example, identifies parents' identity and residence or visa evidence at the child's birth, birth or relationship evidence and possible supplements. That does not mean every commercial intermediary should receive the complete consular package.
For initial legal intake, a short description of the problem and a redacted document sample may be sufficient. For a formal application, required details should not be concealed without agreement with the recipient. Keep a clean source file and create clearly labelled working copies with limited disclosure. Do not overwrite originals with redactions. Record what was sent, to whom and for which task. This approach supports minimisation while preserving the integrity of evidence that a competent authority actually needs to examine.
Official sources: Chinese Embassy: first passport and travel document
Use practical controls that match the sensitivity
Confirm the recipient through a known channel before sending a link or attachment, particularly after a sudden change of contact or account. Limit access to named people, use appropriate encryption and authentication, and avoid public links that anyone can forward. Send access credentials separately when suitable. A familiar messaging app does not itself prove that a group contains only authorised recipients or that downloaded files will be deleted after the work is finished.
Ask the provider how it controls staff access, records downloads, handles backups and removes access when a person leaves. Do not place DNA reports, full passports or children's medical records in a public website widget. A law firm's first-contact form can receive a minimal outline while a secure document channel is agreed. Security arrangements should be realistic enough that the family can actually use them. Complicated controls that force everyone to resort to uncontrolled personal accounts will not deliver the intended protection.
Official sources: Georgian Personal Data Protection Law
Treat sending the file abroad as a separate legal question
An overseas email recipient, a foreign cloud service or access by staff in another country can raise international-transfer questions. Map the destination and any onward recipients before selecting a route. Georgia's Article 37 sets transfer conditions in addition to general processing requirements. In particular, the agreement-based route under Article 37(2)(b) requires the State Audit Office's permission under Article 37(3). A confidentiality agreement by itself should not be described as sufficient for every transfer.
Other statutory routes have their own conditions, including the informed written-consent route where applicable; do not assume that a general consent to agency services satisfies them. Verify current safeguards and the actual legal basis for the proposed destination instead of claiming that China is automatically approved. The receiving organisation may also have obligations under applicable Chinese law. This guide does not determine those obligations universally. Request a focused assessment of the actual transfer, storage, onward disclosure and child-representation facts.
Official sources: Georgian Personal Data Protection Law
Request information, correction or restriction precisely
A useful request identifies the person concerned, the requester's capacity, the organisation, the relevant information and the action sought. Ask whether data are held, their source and recipients, and how to obtain a copy through an appropriate process. If a name or factual entry is wrong, identify the error and supply the evidence needed to assess correction. An access request is not a demand for unrestricted copies of another person's records.
Erasure is not absolute. Lawful retention and the substantiation of claims or defences can affect the response. Where the family needs material preserved as evidence but wants wider use stopped, ask whether blocking or restricted processing is the appropriate measure. Keep the request, proof of delivery and response. A correction to a private database does not itself amend a Georgian civil-status record or a Chinese application; the relevant official procedure may still be required. Avoid promising a particular outcome before those distinctions are examined.
Official sources: Georgian Personal Data Protection Law
Act quickly after a suspected disclosure
If a provider sends a child's report to the wrong group, first contain further access where possible and preserve a limited record of what happened. Do not forward the exposed report widely as proof of the breach. Record discovery time, affected categories, known recipients and available access information. Ask the organisation to preserve logs, assess containment and identify a responsible contact. Where identity documents are involved, obtain issuer-specific advice about protective steps.
Under Article 29, controllers must assess the incident-notification requirement, including its statutory exception and the 72-hour period after identification; processors must inform controllers immediately. Article 30 separately addresses informing affected people. These are organisational duties, not an automatic rule that every parent must report every lost paper within 72 hours. The family's practical request should seek a clear account of exposure, mitigation and the notification assessment. Do not accept a deletion promise as proof that every downloaded copy has been recovered.
Official sources: Georgian Personal Data Protection Law
Use the current supervisory route
The regulator named in an old privacy policy may no longer be current. The December 2025 amendment provides for the former Personal Data Protection Service's liquidation and the State Audit Office's succession from 2 March 2026, including continuation of relevant pending matters. The current consolidated law identifies the State Audit Office's data-protection powers. Check its current official submission channel before sending a complaint containing sensitive information.
A focused complaint should explain the processing activity, the organisation involved, the requester's authority, the steps already taken and the practical outcome sought. Attach only evidence necessary to assess the alleged problem, using the official secure route. A regulatory complaint and a private claim for loss are different procedures, and neither automatically determines parentage or cancels a service contract. If immediate safeguarding is needed, seek advice on appropriate urgent measures rather than waiting for a general complaint to resolve every part of the dispute.
Official sources: Data protection supervisory transition
Hypothetical example: a report enters a large chat group
Suppose an agency employee posts a child's genetic report and a parent's passport into a group containing former contractors. The family had authorised delivery to a particular professional for a specific application. That permission should not be treated as permission for the wider group. The family can ask the agency to restrict access, preserve relevant logs, identify recipients and explain its legal assessment and protective measures. A screenshot used as evidence should be stored with restricted access.
At the same time, the family may need the original report for its pending application. Asking for indiscriminate deletion of every copy could harm that evidence trail. Separate preservation of the authoritative report from stopping unauthorised distribution. If the relationship is a mandate, Civil Code confidentiality provisions may also be relevant, subject to proper classification. This is a hypothetical illustration, not a reported client case. It does not establish that a fine, damages or any particular remedy will follow.
Official sources: Civil Code of Georgia
Agree retention and handover before the service ends
When changing providers, list the documents to transfer, identify the lawful recipient and agree a secure handover. Ask what copies must remain for legal obligations or claims and what unnecessary working copies will be deleted. Record the reason and period for any retention. Removing an employee's access, shutting an obsolete shared link and cancelling a marketing permission can be separate tasks. A blanket promise that all information will be deleted immediately may conflict with legitimate records or evidence needs.
Advokato can review authority, data requests, a proposed overseas transfer or an incident response on the actual documents. Start with the type of issue, organisations and countries involved, timing and the remedy sought. Do not send a child's DNA, passport or clinical file through a public contact form. Sources were checked on 3 October 2026. The objective is lawful, limited and traceable information handling while the separate questions of registration, parentage, nationality, travel documents, entry and household registration remain properly assessed.
Official sources: Georgian Personal Data Protection Law
Important noteThis material is general information, not personalised legal advice. Recheck current law, official practice, fees and deadlines against your facts before acting.