Georgia Consumer Data Protection Act (GCDPA)
· About Georgia Consumer Data Protection Act (GCDPA)
Key Takeaways
- The Georgia Consumer Data Protection Act (GCDPA), as introduced in 2022, would have given Georgia consumers rights to access, correct, delete, and opt out of sale of their personal data, but it was not the law in force in Georgia as of 6 September 2026 because the 2026 privacy bill was replaced before enactment.[12][13]
- Georgia’s enacted consumer-privacy development in 2026 was not a comprehensive state privacy law comparable to Virginia or Colorado; the privacy bill was substituted with an unrelated rural hospital tax credit measure before final passage.[12]
- The original GCDPA text would have imposed controller obligations, required data protection assessments for certain processing, and created private-right-of-action exposure with statutory damages, which is why it drew unusually strong attention from compliance teams.[8][13]
- The draft GCDPA’s proposed penalties were severe: consumers could recover actual damages plus $2,500 per violation or $7,500 per intentional violation, while the Georgia Attorney General could also seek injunctive relief.[8][13]
- Because the GCDPA was not enacted, Georgia organizations should not build a Georgia-specific privacy program around it, but they should align to multi-state privacy, breach-notification, and unfair-practice laws that still apply.[12][14]
What It Is
The Georgia Consumer Data Protection Act was a proposed comprehensive consumer privacy statute intended to regulate controllers and processors handling Georgia residents’ personal data, but the state did not adopt that framework into law as of 6 September 2026.[12][13] The legislative materials show that a 2025–2026 privacy bill, Senate Bill 111, was introduced, but a later substitute replaced its text with an unrelated rural hospital tax credit measure, meaning the comprehensive privacy bill did not become Georgia law.[2][12]
The bill text on file for the earlier proposal treated July 1, 2026 as the effective date and made the data protection assessment rules apply only to processing activities created or generated on or after that date.[1][4] That same effective-date structure appears in the 2025–2026 substitute legislative documents, but those documents also show the privacy text was superseded by the substitute measure before enactment.[2][4][6]
The body that would have enforced the law, had it been enacted, was the Georgia Attorney General through civil enforcement and injunctive proceedings, alongside a consumer private right of action in the earlier draft text.[8][13] Because the statute was not enacted, those enforcement mechanisms do not operate as a current Georgia privacy regime.[12]
Who Must Comply
The proposed GCDPA was drafted to apply to entities acting as controllers or processors of personal data of Georgia residents, with controller-style duties and processor flow-down obligations reflected in the bill text.[9][13] The available legislative summaries and commentary indicate the statute was designed as a broad consumer privacy law rather than a narrow sectoral rule.[9][13]
The bill’s proposed scope was not limited to in-state companies; like other modern state privacy laws, it was aimed at businesses processing Georgia residents’ data, including organizations outside Georgia that target or serve Georgia consumers.[9][13] However, because the bill was not enacted, there is no operative Georgia comprehensive privacy-law threshold, extraterritorial test, or Georgia-specific exemption structure to apply today.[12]
For current compliance purposes, organizations should instead assess whether they are subject to other Georgia laws, including breach-notification, unfair-and-deceptive-practices, or sector-specific rules.[11][14] The absence of an enacted Georgia comprehensive privacy law means there are no GCDPA thresholds such as revenue, processing volume, or data-subject count currently in force under that title.[12]
Core Requirements
- Consumer rights handling — The draft GCDPA would have required a process to respond to consumer requests to access, correct, delete, and opt out of the sale of personal data, with defined response workflows and verification controls.[9][13]
- Notice and transparency — Controllers would have needed to disclose categories of personal data collected, the purposes for collection and use, and consumer-facing rights information in a clear privacy notice.[8][13]
- Data protection assessments — The bill text required data protection assessments for certain processing activities, and the effective-date language limited those assessment requirements to processing activities created or generated on or after 1 July 2026.[1][4]
- Controller and processor governance — The draft created obligations around processor contracts, accountability, and operational controls, including restrictions on processing outside the controller’s instructions.[2][6][9]
- Enforcement readiness — The enforcement structure would have exposed violators to state civil enforcement, injunctive relief, and private litigation risk with statutory damages, making documentation and defensible governance essential.[8][13]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Proposed effective date in bill text | 1 July 2026 | The draft GCDPA would have become effective on this date.[1][2][4] | | Assessment lookback date | 1 July 2026 | Data protection assessment requirements would have applied only to processing activities created or generated on or after this date.[1][4] | | Current legal status as of 6 September 2026 | N/A | The comprehensive Georgia privacy bill was not enacted; the privacy text was replaced before final passage.[12] |
The proposed penalties in the draft were substantial. The earlier bill text provided for injunctive relief and civil penalties, and the legislative commentary on that text states consumers could recover actual damages plus up to $2,500 per violation or $7,500 per intentional violation.[8][13] Because the GCDPA was not enacted, those penalties are not currently operative under Georgia comprehensive privacy law, but they remain relevant as a risk benchmark for bill analysis and internal policy planning.[12][13]
How to Comply
- Confirm your legal perimeter — Determine whether Georgia residents’ data is handled under other applicable laws, especially sectoral privacy, breach-notification, and consumer-protection statutes, since there is no enacted Georgia comprehensive privacy law.[12][14]
- Build a rights-intake workflow — Use a single process for access, deletion, correction, portability, and opt-out requests so your program can adapt quickly if Georgia or another state law changes.[9][13]
- Map data and purposes — Maintain a current data inventory, processing purpose register, retention schedule, and vendor map; this is the operational foundation for any future GCDPA-style obligations and aligns well with ISO 27001 asset and control management.[2][6]
- Run privacy impact and risk assessments — For targeted advertising, sensitive data, and other high-risk uses, perform documented assessments; this maps directly to the risk-management discipline in NIST CSF 2.0 and the privacy-governance expectations in ISO 42001 when AI systems are involved.[1][4]
- Harden contracts and vendor controls — Update processor and service-provider terms to address confidentiality, subprocessing, security, deletion, and audit rights, which is the common control point across modern state privacy laws.[2][6][9]
- Align security controls to recognized standards — Use ISO 27001 for security management, NIST CSF 2.0 for governance and resilience, and ISO 42001 where automated decision-making or AI-enabled profiling may touch personal data.[2][6]
- Train and test response teams — Exercise request-handling, complaint escalation, and incident response with legal and customer-support teams so deadlines can be met if Georgia adopts a future privacy statute or if other state laws impose similar duties.[12][14]
Related Regulations
- Georgia Personal Identity Protection Act — This is Georgia’s existing breach-notification framework, and it overlaps with privacy programs on incident response even though it does not create the same consumer rights as a comprehensive privacy law.[11][14]
- California Consumer Privacy Act / CPRA — California’s law is the closest operational analogue for consumer rights, vendor controls, and notice obligations, so many organizations standardize to that model across states.
- Virginia Consumer Data Protection Act — Virginia’s statute is a common benchmark for controller/processor structures and rights-response governance, but unlike the non-enacted GCDPA, it is currently in force.
- Colorado Privacy Act — Colorado is especially relevant for opt-out and assessment practices, and its governance expectations are useful when designing a multi-state privacy program.
- FTC Act Section 5 — Even without a Georgia comprehensive privacy statute, unfair or deceptive privacy practices can still trigger federal consumer-protection exposure.
FAQ
Does the Georgia Consumer Data Protection Act apply to companies outside Georgia?
No current Georgia comprehensive privacy law of that title applies, because the GCDPA was not enacted.[12] If Georgia ever adopted a similar law, it would almost certainly have reached out-of-state businesses processing Georgia residents’ data, as reflected in the draft structure.[9][13]
Is there a Georgia consumer privacy law in force in 2026?
No comprehensive Georgia consumer privacy law is in force as of 6 September 2026.[12] The 2025–2026 privacy proposal was replaced in the legislative process, so compliance teams should not treat the draft GCDPA as operative law.[12]
What consumer rights would the GCDPA have created?
The draft would have given consumers rights to access, correct, delete, and opt out of the sale of their personal data.[9][13] The bill materials also reflect notice and assessment obligations designed to support those rights.[1][2]
What were the penalties under the draft GCDPA?
The draft enforcement model exposed companies to injunctive relief and civil penalties, and commentary on the bill states consumers could recover actual damages plus $2,500 per violation or $7,500 per intentional violation.[8][13] Because the law was not enacted, these penalties are not currently enforceable as Georgia privacy-law penalties.[12]
Should Georgia companies do anything now?
Yes. Companies handling Georgia residents’ data should maintain a multi-state privacy program, because breach-notification, consumer-protection, and sector-specific obligations still apply.[11][14] A privacy program aligned to ISO 27001, NIST CSF 2.0, and, where relevant, ISO 42001 will be easier to adapt if Georgia later enacts a comprehensive privacy law.[2][6]
Sources
- Georgia General Assembly, 2023–2024 legislation document 224856
- Georgia General Assembly, 2025–2026 Senate Bill 111 legislative document 231441
- Georgia General Assembly, 2025–2026 legislative document 235009
- Georgia General Assembly, 2025–2026 floor amendment document 248631
- Georgia General Assembly, 2021–2022 Senate Bill 394 legislative text
- WilmerHale, State Comprehensive Privacy Law Update – February 21, 2025
- Alston & Bird, Georgia Introduces Privacy Bill Stricter than CCPA – The Top 10 Issues
- Recording Law, Georgia Data Privacy Laws: Breach Notification & Consumer Privacy
Put it into practice
- Generate the policy: Privacy policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)