{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/georgia",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/georgia.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/georgia",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/georgia/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/georgia/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "georgia",
    "frontmatter": {
      "title": "Georgia Consumer Privacy Law",
      "description": "Georgia has no comprehensive consumer-privacy statute. The operative framework is the Identity Theft article's breach-notification law plus the Georgia Fair Business Practices Act as the deception hook, with FTC Act, GLBA, HIPAA, and COPPA duties layered on top where they apply.",
      "state": "Georgia",
      "lastReviewed": "2026-06-12",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "O.C.G.A. §§ 10-1-910 to 10-1-912 (identity theft and data-breach notification) plus the Georgia Fair Business Practices Act, O.C.G.A. §§ 10-1-390 to 10-1-408 — Georgia has no comprehensive consumer-privacy statute",
        "appliesTo": "The breach-notification statute reaches information brokers and government data collectors that maintain computerized personal information about individuals, and gives vendors holding that data a 24-hour notice-up duty; the FBPA reaches unfair or deceptive practices in consumer transactions and consumer acts or practices in trade or commerce",
        "privacyPolicyRequired": "No Georgia statute generally requires a consumer privacy policy or fixes its contents; a policy that misstates actual practices is reachable as a deceptive practice under the FBPA and FTC Act § 5, with GLBA, HIPAA, COPPA, and other sectoral laws supplying notices where they apply",
        "privateRightOfAction": "Not expressly under the breach-notification article; the FBPA gives injured persons an individual action, but not a representative action, after a 30-day demand, with treble actual damages for intentional violations and attorney-fee shifting",
        "regulator": "Georgia Attorney General",
        "bottomLine": "Georgia has not enacted an omnibus consumer-privacy law, so there are no general state-law access, deletion, correction, opt-out, controller, processor, or privacy-notice duties. The current Georgia obligations are breach notification for information brokers and government data collectors, a fast 24-hour vendor notice-up rule, and truth-in-privacy-policy exposure through the Fair Business Practices Act and FTC Act § 5.",
        "lawCoverage": "baseline",
        "policyMandate": "none",
        "consumersCanSue": "narrow",
        "sensitiveDataConsent": "none",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "Georgia consumer privacy law",
        "Georgia data breach notification O.C.G.A. 10-1-912",
        "Georgia Fair Business Practices Act privacy",
        "Georgia no comprehensive privacy law",
        "Georgia privacy policy requirements",
        "Georgia vendor breach notification 24 hours",
        "Georgia Attorney General privacy enforcement",
        "Georgia data breach private right of action",
        "Georgia identity theft personal information",
        "Georgia consumer protection privacy policy"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "which-privacy-laws-apply",
        "label": "Which privacy laws apply to your business in Georgia?",
        "heading": "Which privacy laws apply to your business in Georgia?",
        "answerText": "Georgia has no comprehensive consumer-privacy law. The generally applicable state framework has two pieces: the Identity Theft article, which requires breach notice by an information broker or data collector that maintains computerized personal information, and the Georgia Fair Business Practices Act (FBPA), which declares unfair or deceptive practices in consumer transactions and consumer acts or practices in trade or commerce unlawful. Neither statute gives Georgia residents general rights to access, delete, correct, or opt out of sale or targeted advertising.",
        "sources": [
          {
            "id": "ga-breach-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-912",
            "citation": "O.C.G.A. § 10-1-912(a).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6348-FSJ1-DYB7-W1RP-00008-00",
            "proposition": "Georgia's breach-notification duty applies to an information broker or data collector that maintains computerized data including personal information of individuals.",
            "verbatimQuote": "Any information broker or data collector that maintains computerized data that includes personal information of individuals shall give notice of any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of this state whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-ga-breach-duty"
          },
          {
            "id": "ga-fbpa-unlawful",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-393",
            "citation": "O.C.G.A. § 10-1-393(a).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6FX8-GHW3-RTDX-K0FH-00008-00",
            "proposition": "The Georgia FBPA declares unfair or deceptive acts or practices in consumer transactions and consumer acts or practices in trade or commerce unlawful.",
            "verbatimQuote": "Unfair or deceptive acts or practices in the conduct of consumer transactions and consumer acts or practices in trade or commerce are declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-ga-fbpa-unlawful"
          },
          {
            "id": "ga-defs-covered",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-911",
            "citation": "O.C.G.A. § 10-1-911(2)-(3).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6C0M-58Y3-SK2M-M1R5-00008-00",
            "proposition": "Georgia defines a data collector as a state or local government agency or subdivision, and an information broker as a fee-based business furnishing personal information to nonaffiliated third parties.",
            "verbatimQuote": "“Information broker” means any person or entity who, for monetary fees or dues, engages in whole or in part in the business of collecting, assembling, evaluating, compiling, reporting, transmitting, transferring, or communicating information concerning individuals for the primary purpose of furnishing personal information to nonaffiliated third parties",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-ga-defs-covered"
          },
          {
            "id": "ga-vendor-24h",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-912",
            "citation": "O.C.G.A. § 10-1-912(b).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6348-FSJ1-DYB7-W1RP-00008-00",
            "proposition": "A vendor maintaining covered computerized data it does not own must notify the information broker or data collector within 24 hours after discovering a breach involving unauthorized acquisition or reasonably believed acquisition.",
            "verbatimQuote": "Any person or business that maintains computerized data on behalf of an information broker or data collector that includes personal information of individuals that the person or business does not own shall notify the information broker or data collector of any breach of the security of the system within 24 hours following discovery",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-ga-vendor-24h"
          },
          {
            "id": "ga-fbpa-purpose",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-391",
            "citation": "O.C.G.A. § 10-1-391(a)-(b).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6348-FSJ1-DYB7-W1B2-00008-00",
            "proposition": "The FBPA is intended to protect consumers and legitimate businesses from unfair or deceptive practices and is construed consistently with federal-court interpretations of FTC Act § 5.",
            "verbatimQuote": "The purpose of this part shall be to protect consumers and legitimate business enterprises from unfair or deceptive practices in the conduct of any trade or commerce in part or wholly in the state.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-ga-fbpa-purpose"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Georgia privacy policy contain?",
        "heading": "What must your Georgia privacy policy contain?",
        "answerText": "No Georgia statute generally requires a consumer privacy policy or fixes what it must say. The binding rule is consistency: the FBPA prohibits unfair or deceptive practices in consumer transactions, and the statute is construed consistently with FTC Act § 5. A policy that misstates actual data practices is therefore exposed as a deceptive-practices problem under Georgia and federal law, even though Georgia has no omnibus privacy-policy checklist.",
        "sources": [
          {
            "id": "q2-fbpa-unlawful",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-393",
            "citation": "O.C.G.A. § 10-1-393(a).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6FX8-GHW3-RTDX-K0FH-00008-00",
            "proposition": "The FBPA declares unfair or deceptive acts or practices in consumer transactions and consumer acts or practices in trade or commerce unlawful.",
            "verbatimQuote": "Unfair or deceptive acts or practices in the conduct of consumer transactions and consumer acts or practices in trade or commerce are declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q2-fbpa-unlawful"
          },
          {
            "id": "q2-fbpa-ftc",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-391",
            "citation": "O.C.G.A. § 10-1-391(b).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6348-FSJ1-DYB7-W1B2-00008-00",
            "proposition": "Georgia directs the FBPA to be interpreted consistently with federal-court interpretations of FTC Act § 5.",
            "verbatimQuote": "It is the intent of the General Assembly that this part be interpreted and construed consistently with interpretations given by the Federal Trade Commission in the federal courts pursuant to Section 5(a)(1) of the Federal Trade Commission Act (15 U.S.C. Section 45(a)(1)), as from time to time amended.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q2-fbpa-ftc"
          },
          {
            "id": "q2-glba-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA privacy notice",
            "citation": "15 U.S.C. § 6802(a).",
            "url": "https://www.law.cornell.edu/uscode/text/15/6802",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/6802#:~:text=a%20financial%20institution%20may%20not%2C,section%206803%20of%20this%20title.",
            "proposition": "A GLBA financial institution may not disclose nonpublic personal information to a nonaffiliated third party unless it has provided the consumer a compliant privacy notice.",
            "verbatimQuote": "a financial institution may not, directly or through any affiliate, disclose to a nonaffiliated third party any nonpublic personal information, unless such financial institution provides or has provided to the consumer a notice that complies with section 6803 of this title.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q2-glba-notice"
          },
          {
            "id": "q2-hipaa-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Notice of Privacy Practices",
            "citation": "45 C.F.R. § 164.520(a)(1).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.520",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.520#:~:text=an%20individual%20has%20a%20right,respect%20to%20protected%20health%20information",
            "proposition": "A HIPAA covered entity must give individuals a notice describing uses and disclosures of protected health information, individual rights, and the entity's legal duties.",
            "verbatimQuote": "an individual has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q2-hipaa-notice"
          },
          {
            "id": "q2-coppa-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "COPPA",
            "citation": "15 U.S.C. § 6502(a)(1).",
            "url": "https://www.law.cornell.edu/uscode/text/15/6502",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/6502#:~:text=It%20is%20unlawful%20for%20an,regulations%20prescribed%20under%20subsection%20(b).",
            "proposition": "COPPA prohibits covered operators from collecting children's personal information in violation of the FTC's notice and parental-consent regulations.",
            "verbatimQuote": "It is unlawful for an operator of a website or online service directed to children, or any operator that has actual knowledge that it is collecting personal information from a child, to collect personal information from a child in a manner that violates the regulations prescribed under subsection (b).",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q2-coppa-notice"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with vendors say?",
        "heading": "What must your contracts with vendors say?",
        "answerText": "Georgia has no general data-processing-agreement statute. It does not prescribe controller-to-processor instructions, audit rights, deletion clauses, or subprocessor flow-downs for ordinary privacy vendors. The Georgia-specific vendor duty is narrow but fast: a person or business maintaining covered computerized personal information on behalf of an information broker or data collector must notify that owner within 24 hours after discovering a breach, if the personal information was or is reasonably believed to have been acquired by an unauthorized person.",
        "sources": [
          {
            "id": "q3-vendor-24h",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-912",
            "citation": "O.C.G.A. § 10-1-912(b).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6348-FSJ1-DYB7-W1RP-00008-00",
            "proposition": "A vendor maintaining covered computerized data it does not own must notify the information broker or data collector within 24 hours after discovering a breach involving unauthorized acquisition or reasonably believed acquisition.",
            "verbatimQuote": "Any person or business that maintains computerized data on behalf of an information broker or data collector that includes personal information of individuals that the person or business does not own shall notify the information broker or data collector of any breach of the security of the system within 24 hours following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q3-vendor-24h"
          },
          {
            "id": "q3-glba-safeguards",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule",
            "citation": "16 C.F.R. § 314.4(f).",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=Oversee%20service%20providers%2C%20by%3A%20(1),continued%20adequacy%20of%20their%20safeguards.",
            "proposition": "The GLBA Safeguards Rule requires a financial institution to oversee its service providers — selecting capable providers, requiring safeguards by contract, and periodically assessing them.",
            "verbatimQuote": "Oversee service providers, by: (1) Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; (2) Requiring your service providers by contract to implement and maintain such safeguards; and (3) Periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q3-glba-safeguards"
          },
          {
            "id": "q3-hipaa-baa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Business Associate Contracts",
            "citation": "45 C.F.R. § 164.504(e)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.504",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.504#:~:text=A%20contract%20between%20the%20covered,information%20by%20the%20business%20associate.",
            "proposition": "HIPAA requires a written business-associate contract that establishes the permitted and required uses and disclosures of protected health information by the business associate.",
            "verbatimQuote": "A contract between the covered entity and a business associate must: (i) Establish the permitted and required uses and disclosures of protected health information by the business associate.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q3-hipaa-baa"
          }
        ]
      },
      {
        "slug": "breach-notification",
        "label": "When must you notify people of a data breach in Georgia?",
        "heading": "When must you notify people of a data breach in Georgia?",
        "answerText": "For covered information brokers and data collectors, notice must go to each affected Georgia resident in the most expedient time possible and without unreasonable delay after discovery or notification of a breach, subject to law-enforcement delay and time needed to determine scope and restore reasonable system integrity. Georgia sets no fixed outer day-count for resident notice, but vendors maintaining covered data they do not own have a hard 24-hour notice-up clock to the information broker or data collector.",
        "sources": [
          {
            "id": "q4-resident-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-912",
            "citation": "O.C.G.A. § 10-1-912(a).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6348-FSJ1-DYB7-W1RP-00008-00",
            "proposition": "A covered information broker or data collector must notify affected Georgia residents in the most expedient time possible and without unreasonable delay after discovery or notification of a breach involving unencrypted personal information.",
            "verbatimQuote": "The notice shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (c) of this Code section, or with any measures necessary to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q4-resident-notice"
          },
          {
            "id": "q4-vendor-24h",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-912",
            "citation": "O.C.G.A. § 10-1-912(b).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6348-FSJ1-DYB7-W1RP-00008-00",
            "proposition": "A vendor maintaining covered computerized data it does not own must notify the information broker or data collector within 24 hours after discovering a breach involving unauthorized acquisition or reasonably believed acquisition.",
            "verbatimQuote": "Any person or business that maintains computerized data on behalf of an information broker or data collector that includes personal information of individuals that the person or business does not own shall notify the information broker or data collector of any breach of the security of the system within 24 hours following discovery",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q4-vendor-24h"
          },
          {
            "id": "q4-breach-def",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-911",
            "citation": "O.C.G.A. § 10-1-911(1).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6C0M-58Y3-SK2M-M1R5-00008-00",
            "proposition": "Georgia defines breach of security as unauthorized acquisition of electronic data that compromises personal information, with a good-faith employee or agent exception if the information is not used or further disclosed without authorization.",
            "verbatimQuote": "“Breach of the security of the system” means unauthorized acquisition of an individual’s electronic data that compromises the security, confidentiality, or integrity of personal information of such individual maintained by an information broker or data collector.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q4-breach-def"
          },
          {
            "id": "q4-pi-def",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-911",
            "citation": "O.C.G.A. § 10-1-911(6)(A)-(D).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6C0M-58Y3-SK2M-M1R5-00008-00",
            "proposition": "Georgia personal information includes a name linked to unencrypted or unredacted Social Security number, driver's license or state ID number, account or payment-card number usable without more, account passwords, PINs, or access codes.",
            "verbatimQuote": "“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted or redacted",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q4-pi-def"
          },
          {
            "id": "q4-pi-standalone",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-911",
            "citation": "O.C.G.A. § 10-1-911(6)(E).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6C0M-58Y3-SK2M-M1R5-00008-00",
            "proposition": "Georgia also treats the listed identity-theft-enabling elements as personal information without a name if the compromised information would be sufficient to perform or attempt identity theft.",
            "verbatimQuote": "Any of the items contained in subparagraphs (A) through (D) of this paragraph when not in connection with the individual’s first name or first initial and last name, if the information compromised would be sufficient to perform or attempt to perform identity theft against the person whose information was compromised.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q4-pi-standalone"
          },
          {
            "id": "q4-notice-methods",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-911",
            "citation": "O.C.G.A. § 10-1-911(4).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6C0M-58Y3-SK2M-M1R5-00008-00",
            "proposition": "Georgia permits written, telephone, electronic, or substitute notice; substitute notice is available when cost exceeds $50,000, the affected class exceeds 100,000, or contact information is insufficient, and requires email where available, website posting where available, and major statewide media.",
            "verbatimQuote": "Substitute notice, if the information broker or data collector demonstrates that the cost of providing notice would exceed $50,000.00, that the affected class of individuals to be notified exceeds 100,000, or that the information broker or data collector does not have sufficient contact information to provide written or electronic notice to such individuals.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q4-notice-methods"
          },
          {
            "id": "q4-cra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-912",
            "citation": "O.C.G.A. § 10-1-912(d).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6348-FSJ1-DYB7-W1RP-00008-00",
            "proposition": "When notice is required for more than 10,000 Georgia residents at one time, the information broker or data collector must also notify nationwide consumer reporting agencies without unreasonable delay.",
            "verbatimQuote": "In the event that an information broker or data collector discovers circumstances requiring notification pursuant to this Code section of more than 10,000 residents of this state at one time, the information broker or data collector shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nation-wide basis",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q4-cra"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business in Georgia over privacy?",
        "heading": "Can a consumer sue your business in Georgia over privacy?",
        "answerText": "The breach-notification article captured here does not create an express private right of action. The private-suit path is the FBPA: a person injured by consumer acts or practices in violation of the FBPA may bring an individual action, but not a representative action, for equitable injunctive relief and general and exemplary damages. Before filing, the claimant generally must send a written demand at least 30 days in advance identifying the unfair or deceptive practice and the injury suffered.",
        "sources": [
          {
            "id": "q5-fbpa-private-action",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-399",
            "citation": "O.C.G.A. § 10-1-399(a).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6FX3-0RK3-RWYN-91FC-00008-00",
            "proposition": "The FBPA authorizes an injured person to bring an individual, but not representative, action for equitable injunctive relief and general and exemplary damages.",
            "verbatimQuote": "any person who suffers injury or damages as a result of a violation of Chapter 5B of this title, as a result of consumer acts or practices in violation of this part, as a result of office supply transactions in violation of this part or whose business or property has been injured or damaged as a result of such violations may bring an action individually, but not in a representative capacity",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q5-fbpa-private-action"
          },
          {
            "id": "q5-demand",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-399",
            "citation": "O.C.G.A. § 10-1-399(b).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6FX3-0RK3-RWYN-91FC-00008-00",
            "proposition": "A claimant generally must deliver a written demand for relief at least 30 days before filing an FBPA action.",
            "verbatimQuote": "At least 30 days prior to the filing of any such action, a written demand for relief, identifying the claimant and reasonably describing the unfair or deceptive act or practice relied upon and the injury suffered, shall be delivered to any prospective respondent.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q5-demand"
          },
          {
            "id": "q5-treble",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-399",
            "citation": "O.C.G.A. § 10-1-399(c).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6FX3-0RK3-RWYN-91FC-00008-00",
            "proposition": "Subject to the demand-and-tender subsection, a court must award three times actual damages for an intentional FBPA violation.",
            "verbatimQuote": "Subject to subsection (b) of this Code section, a court shall award three times actual damages for an intentional violation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q5-treble"
          },
          {
            "id": "q5-fees",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-399",
            "citation": "O.C.G.A. § 10-1-399(d).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6FX3-0RK3-RWYN-91FC-00008-00",
            "proposition": "If the court finds an FBPA violation, the injured person receives reasonable attorney's fees and litigation expenses, subject to the statute's settlement and bad-faith limitations.",
            "verbatimQuote": "If the court finds in any action that there has been a violation of this part, the person injured by such violation shall, in addition to other relief provided for in this Code section and irrespective of the amount in controversy, be awarded reasonable attorneys’ fees and expenses of litigation incurred in connection with said action",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q5-fees"
          },
          {
            "id": "q5-ag-service",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-399",
            "citation": "O.C.G.A. § 10-1-399(g).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6FX3-0RK3-RWYN-91FC-00008-00",
            "proposition": "The Attorney General must be served with the initial complaint and amended complaints in an FBPA action within 20 days after filing and is entitled to be heard.",
            "verbatimQuote": "In any action brought under this Code section the Attorney General shall be served by certified or registered mail or statutory overnight delivery with a copy of the initial complaint and any amended complaint within 20 days of the filing of such complaint.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q5-ag-service"
          },
          {
            "id": "q5-fbpa-unlawful",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "O.C.G.A. § 10-1-393",
            "citation": "O.C.G.A. § 10-1-393(a).",
            "url": "https://advance.lexis.com/document/?pdmfid=1000516&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6FX8-GHW3-RTDX-K0FH-00008-00",
            "proposition": "The FBPA's underlying prohibition is limited to unfair or deceptive practices in consumer transactions and consumer acts or practices in trade or commerce.",
            "verbatimQuote": "Unfair or deceptive acts or practices in the conduct of consumer transactions and consumer acts or practices in trade or commerce are declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/georgia#src-q5-fbpa-unlawful"
          }
        ]
      }
    ]
  }
}
