Georgia Privacy Law
Georgia’s recent privacy activity has been concentrated in minors’ online safety and online marketplaces rather than in general consumer data rights, and two of those statutes are currently blocked. A federal court enjoined the age-verification and parental-consent chapter of the Protecting Georgia’s Children on Social Media Act of 2024 on First Amendment grounds in June 2025, and enjoined the Georgia Inform Consumers Act a year earlier on federal preemption grounds. The Fair Business Practices Act of 1975 remains the general vehicle, and the Attorney General’s office has used the multistate route for data-breach recoveries, leading the Equifax settlement and taking a share of the 23andMe bankruptcy claims.
Sector-Specific Privacy Laws in Georgia
Protecting Georgia's Children on Social Media Act of 2024 (O.C.G.A. ch. 39-6, enacted by SB 351)
Code section 39-6-2 requires the provider of a social media platform to make commercially reasonable efforts to verify the age of account holders “with a level of certainty appropriate to the risks that arise from the social media platform’s information management practices”, or else to apply the chapter’s minor-specific conditions to every account holder; a person verified to be under sixteen must be treated as a minor. No minor may hold an account without the express consent of a parent or guardian, and the section lists six acceptable consent methods, including a signed returnable form, a toll-free number, a videoconference call, and collection of government-issued identification or payment-card information that must be deleted after the parent’s identity is confirmed. Code section 39-6-3 prohibits, for a minor account holder, any advertising based on the minor’s personal information other than age and location, and any collection or use of personal information from the minor’s posts, content, messages, text or usage activity beyond what is adequate, relevant and reasonably necessary for the disclosed purpose. Code section 39-6-4 gives the Attorney General exclusive enforcement authority through the Fair Business Practices Act, damages of up to $2,500 per violation, and a 90-day pre-suit notice with a cure opportunity. The Act separately requires local governing bodies to adopt a social media policy by April 1, 2026, and requires age verification by commercial entities distributing material harmful to minors while providing that age-verification information may not be retained.
Fair Business Practices Act of 1975 (O.C.G.A. § 10-1-390 et seq.)
Section 10-1-391 states the purpose as protecting consumers and legitimate business enterprises from unfair or deceptive practices, directs that the part be liberally construed, and instructs that it be interpreted consistently with Federal Trade Commission and federal-court interpretations of section 5(a)(1) of the FTC Act. Section 10-1-399 governs private suits and is unusually structured: a person injured by a consumer act or practice in violation of the part may sue “individually, but not in a representative capacity” for equitable injunctive relief and general damages, with exemplary damages only for intentional violations; a written demand for relief identifying the claimant and describing the practice and injury must be delivered at least thirty days before filing; a respondent who makes a written tender of settlement within thirty days that is rejected may limit recovery to the tendered relief if the court finds it reasonable; a court “shall award three times actual damages for an intentional violation”; and a successful plaintiff is awarded reasonable attorneys’ fees and expenses, except those incurred after rejecting a reasonable written settlement offer.
Georgia Inform Consumers Act (O.C.G.A. §§ 10-1-940 to 10-1-942)
Enacted in May 2022, GICA imposed disclosure requirements on high-volume third-party sellers operating on online marketplaces, defining such a seller by reference to transaction minimums for sales made through the marketplace and for which payment was processed by the marketplace or a third party. In December 2022 Congress enacted the federal INFORM Act, 15 U.S.C. § 45f, covering the same ground and carrying an express preemption clause barring any state law that conflicts with its requirements. In NetChoice, LLC v. Carr, No. 1:24-cv-02485-SDG (N.D. Ga.), the court granted NetChoice’s motion for a preliminary injunction against Act 564 — the 2024 amendment to GICA scheduled to take effect July 1, 2024 — on federal preemption grounds, without reaching the First Amendment and vagueness arguments also raised.
Data Breach Notification in Georgia
The Attorney General’s Consumer Protection Division describes O.C.G.A. § 10-1-912 as requiring businesses that collect, transmit or maintain unencrypted digital records of an individual’s personal information — the Division’s examples are a driver’s license and a credit card — to notify that individual when the business knows or reasonably believes that its system has been breached. The Division states the notice must be provided “in the most expedient time possible and without unreasonable delay”, subject to an exception where a law enforcement agency determines that notification will compromise a criminal investigation, and notes that the notice a consumer receives may come from a third-party company maintaining the data rather than from the business that collected it. The office’s consumer-facing material on the statute does not describe a threshold at which the Attorney General itself must be notified. Georgia’s own privacy legislation has, for the last several sessions, been directed at minors’ online safety and online marketplaces rather than at the breach statute, which has not been the subject of the General Assembly’s recent privacy activity.
Residents must be notified in the most expedient time possible and without unreasonable delay, unless a law enforcement agency determines notification will compromise a criminal investigation. The Attorney General's Consumer Protection Division describes no general duty to report breaches to the office. Complaints are taken by the Georgia Attorney General, which enforces the statute.
How Georgia Enforces Its Privacy Laws
The Fair Business Practices Act supplies the remedies. Code section 39-6-4(a) gives the Attorney General exclusive authority to enforce the social media chapter and the authority to act under Part 2 of Article 15 of Chapter 1 of Title 10, the Fair Business Practices Act of 1975 — so the newer statute borrows the older one’s machinery rather than building its own. The chapter allows the Attorney General to seek damages of up to $2,500 for each violation, but conditions any action on a 90-day pre-suit notice identifying each alleged violation and explaining its basis, and bars the action if the person cures within those 90 days and so informs the Attorney General.
Private suits: individual only, trebled for intent. Section 10-1-399(a) permits a person injured by a violation to sue “individually, but not in a representative capacity”, for injunctive relief and general damages, with exemplary damages reserved for intentional violations. Subsection (b) requires a written demand for relief at least thirty days before filing and lets a respondent cap exposure by making a written settlement tender the court finds reasonable. Subsection (c) directs that a court “shall award three times actual damages for an intentional violation”, and subsection (d) awards attorneys’ fees and expenses to a plaintiff who prevails, but denies fees incurred after the rejection of a reasonable written settlement offer.
Recent Enforcement in Georgia
23andMe — multistate settlement of bankruptcy claims, $452,232 to Georgia. The Attorney General announced on July 14, 2026 that Georgia had joined 42 states and the District of Columbia in settling with the bankruptcy trustee for 23andMe over the 2023 breach of genetic data, which the office puts at 6.9 million customers worldwide including 171,125 Georgians. Georgia’s share of the $18 million in allowed claims payable out of the estate is $452,232, against $150 million in allowed claims overall, with a separate $46.75 million class settlement for consumers who filed claims by February 17, 2026. The office reports that the multistate investigation found 23andMe had no safeguards against credential-stuffing attacks and no multifactor authentication, no rate limiting or intrusion prevention, no logging, monitoring or breach-detection tooling, did not investigate unusual login patterns, left known vulnerabilities unresolved and conducted inadequate design review and testing. The sale to TTAM Research Institute, now the 23andMe Research Institute, carries enhanced data security requirements, risk analysis, an advisory board, a commitment to be bound by comprehensive privacy laws without exception, and continued consumer deletion rights.
Google location tracking — $391.5 million multistate settlement, more than $12.4 million to Georgia. The Attorney General’s office announced on November 14, 2022 that Georgia had joined 39 other states in settling with Google over its location-tracking practices, and that Georgia’s share of the $391.5 million total was more than $12.4 million. The office states the investigation concerned conduct going back to at least 2014, and that Google confused users about the Location History setting, about the separate existence of Web & App Activity, and about their ability to limit tracking through account and device settings. The settlement requires Google to show additional information when users toggle location settings on or off, to make key location-tracking information unavoidable rather than buried, to publish detailed disclosures about the types of location data it collects and how they are used, to limit its use and storage of certain location information, and to make account controls easier to use.
Equifax — Georgia led the 50-state settlement, $7,181,455.28 to Georgia. The Attorney General’s office announced on July 22, 2019 that Georgia had led the multistate investigation of the 2017 Equifax breach, alongside Illinois, the District of Columbia, Maryland, California, Florida, Pennsylvania, Ohio, Connecticut, New Jersey and New York. The office reports a Consumer Restitution Fund of up to $425 million with $300 million dedicated to consumer redress, a separate $175 million payment to the states of which Georgia received $7,181,455.28, and a breach reaching more than 147 million consumers — 56 percent of American adults. Equifax committed to reorganising its data security team, minimising collection of sensitive data, regular security monitoring, improved access controls, network segmentation and new patch-management policies, together with easier credit freezing and thawing, a simplified dispute process, dedicated staff for identity-theft victims, and extended credit-monitoring services for a total of ten years.
Pending Privacy Legislation
Senate Bill 111 as introduced in 2025 by Senator Albers and others would have amended Title 10 to enact the “Georgia Consumer Privacy Protection Act”: a comprehensive statute applying to a person controlling or processing the personal information of at least 25,000 consumers who also derives revenue from that data, creating consumer rights exercisable by request to a controller, imposing notice, disclosure and security duties, requiring data protection assessments producible to the Attorney General on a civil investigative demand, giving the Attorney General exclusive enforcement authority with a 60-day cure period and civil penalties of up to $7,500 per violation, barring disclosure of consumers’ personal data to local governments absent a subpoena or court order, preempting local regulation, and taking effect July 1, 2026. That text did not become law. The version of Senate Bill 111 the General Assembly passed and the Governor signed in 2026 carries the same bill number and sponsors but a different subject entirely — it amends Code Section 31-8-9.1 on the tax credit for contributions to rural hospital organizations.
Federal Privacy Laws That Apply in Georgia
Federal privacy law applies in Georgia by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
Outside those federal sectors, Georgia obligations run through the state’s breach-notification statute and the Georgia Attorney General’s general consumer-protection authority rather than through a privacy statute of its own.
Industry Rules That Reach Georgia Businesses
With no comprehensive state statute, most privacy obligations on a Georgia business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach Georgia businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Georgia itself has none, and any business holding personal information about Georgia residents is subject to the state’s breach-notification statute described above.
Georgia Privacy Law FAQ
Is Georgia’s social media age-verification law in effect?
What would Georgia’s social media law require of platforms?
When must a Georgia business notify consumers of a data breach?
Can a Georgia consumer bring a class action under the Fair Business Practices Act?
Are treble damages available in Georgia consumer-protection cases?
What happened to Georgia’s online marketplace disclosure law?
Has Georgia enacted a comprehensive consumer privacy law?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Senate Bill 351 (2024) — Protecting Georgia's Children on Social Media Act, signed text legislation
- Senate Bill 111 (2025) — Georgia Consumer Privacy Protection Act, as introduced legislation
- Senate Bill 111 (2026) — as passed and signed legislation
- O.C.G.A. § 10-1-390 et seq. — Fair Business Practices Act of 1975 (published by the Attorney General's Consumer Protection Division) statute
- NetChoice v. Carr, No. 1:25-cv-2422-AT (N.D. Ga. June 26, 2025) — opinion and order decision
- NetChoice, LLC v. Carr, No. 1:24-cv-02485-SDG (N.D. Ga. June 30, 2024) — opinion and order decision
- Georgia Attorney General — Multistate settlement with 23andMe over the genetic data breach (July 14, 2026) agency
- Georgia Attorney General — Consumer Ed: getting notified following a data breach (O.C.G.A. 10-1-912) agency
- Georgia Attorney General — Georgia joins the $391.5 million multistate settlement with Google over location tracking (November 14, 2022) agency
- Georgia Attorney General — Georgia leads states in reaching the Equifax settlement (July 22, 2019) agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.