---
title: Information Security Breach in Georgia - SCA Security
description: Georgia Information Security Breach Law Statute Codes Breach notification laws in Georgia are covered under the Georgia Personal Identity Protection act, Ga. Code § 10-1-910 et seq. This includes S.B. 230, and 236. S.B. 230 was signed into law on May 5, 2005, and became effective May 5, 2005. S.B. 236 was signed into law
image: https://blog.scasecurity.com/hubfs/Imported_Blog_Media/Georgia.jpg
---

[727-571-1141 Talk to an Expert](tel:727-571-1141) [info@scasecurity.com Email Us](mailto:info@scasecurity.com) <https://www.facebook.com/Security-Compliance-Associates-170070577097300/?ref=br_rs> <https://twitter.com/scasecurity> <https://www.linkedin.com/company/security-compliance-associates/>

[![sca-logo-r](https://blog.scasecurity.com/hs-fs/hubfs/sca-logo-r.png?length=190&name=sca-logo-r.png)](https://scasecurity.com/)

☰

- [Home](https://scasecurity.com/)
- [Security](https://scasecurity.com/security/) 
    - [Email Phishing & Employee Training](https://scasecurity.com/anti-phishing-training-with-phished-io/)
    - [Vulnerability Assessments](https://scasecurity.com/security/vulnerability-assessments/)
    - [Penetration Testing](https://scasecurity.com/security/penetration-testing/)
    - [Applications](https://scasecurity.com/security/applications/)
    - [Controls](https://scasecurity.com/security/controls/)
    - [Centurion ESO](https://scasecurity.com/executive-security-officer/)
    - [Consulting](https://scasecurity.com/security/consulting/)
- [Risk & Compliance](https://scasecurity.com/compliance/) 
    - [CMMC](https://scasecurity.com/cybersecurity-maturity-model-certification/)
    - [HITRUST](https://scasecurity.com/hitrust/)
    - [Federal](https://scasecurity.com/compliance/federal/)
    - [State](https://scasecurity.com/compliance/state/)
    - [Industry](https://scasecurity.com/compliance/industry/)
    - [Cybersecurity Risk Assessment](https://scasecurity.com/security/risk-assessment/)
    - [NIST Cybersecurity Framework Assessment](https://scasecurity.com/compliance/nist-framework/)
    - [AI Risk Management Services](https://scasecurity.com/ai-risk-management-services/)
- [Governance](https://scasecurity.com/compliance/governance/)
- [Industries](https://scasecurity.com/industries/) 
    - [Financial Services](https://scasecurity.com/industries/financial-services/)
    - [Healthcare](https://scasecurity.com/industries/healthcare/)
    - [Government/Public Sector](https://scasecurity.com/industries/government-public-sector/)
    - [Title/Real Estate](https://scasecurity.com/industries/title-real-estate/)
    - [Technology](https://scasecurity.com/industries/technology/)
    - [Manufacturing](https://scasecurity.com/industries/manufacturing/)
    - [Professional Services](https://scasecurity.com/industries/professional-services/)
    - [Automotive](https://scasecurity.com/automotive/)
    - [Higher Education](https://scasecurity.com/higher-education/)
- News & Resources 
    - [Blog](https://blog.scasecurity.com)
    - [Events](https://scasecurity.com/event/)
    - [Case Studies](https://scasecurity.com/case-studies/)
    - [Recorded Webinars](https://scasecurity.com/recorded-webinars/)
    - [SCA Breach Notification Guide](https://scasecurity.com/breach-notification-guide/)
    - [HIPAA Security Audit Checklist](https://info.scasecurity.com/hipaa-audit-checklist)
    - [Cybersecurity Checklist for Insurance Providers](https://info.scasecurity.com/cybersecurity-checklist-for-insurance-providers)
- Company 
    - [About Us](https://scasecurity.com/about-us/)
    - [Leadership](https://scasecurity.com/leadership/)
    - [Affiliates](https://scasecurity.com/affiliates/)
    - [Career Opportunities](https://scasecurity.com/career-opportunities/)
    - [Testimonials](https://scasecurity.com/testimonials/)
- [Contact Us](https://scasecurity.com/contact-us/)

#### Menu

 Home

 Security ›

 Email Phishing & Employee Training

 Vulnerability Assessments

 Penetration Testing

 Applications

 Controls

 Centurion ESO

 Consulting

 Risk & Compliance ›

 CMMC

 HITRUST

 Federal

 State

 Industry

 Cybersecurity Risk Assessment

 NIST Cybersecurity Framework Assessment

 AI Risk Management Services

 Governance

 Industries ›

 Financial Services

 Healthcare

 Government/Public Sector

 Title/Real Estate

 Technology

 Manufacturing

 Professional Services

 Automotive

 Higher Education

 News & Resources ›

 Blog

 Events

 Case Studies

 Recorded Webinars

 SCA Breach Notification Guide

 HIPAA Security Audit Checklist

 Cybersecurity Checklist for Insurance Providers

 Company ›

 About Us

 Leadership

 Affiliates

 Career Opportunities

 Testimonials

 Contact Us

[727-571-1141 Talk to an Expert](tel:727-571-1141)

[info@scasecurity.com Email Us](mailto:info@scasecurity.com)

<https://www.facebook.com/Security-Compliance-Associates-170070577097300/?ref=br_rs>

<https://twitter.com/scasecurity>

<https://www.linkedin.com/company/security-compliance-associates/>

 December 18, 2019

# Information Security Breach in Georgia

 By: SCA Editor

![](https://blog.scasecurity.com/hubfs/Imported_Blog_Media/Georgia.jpg)

## Georgia Information Security Breach Law

### Statute Codes

Breach notification laws in Georgia are covered under the Georgia Personal Identity Protection act, Ga. Code § 10-1-910 et seq. This includes S.B. 230, and 236. S.B. 230 was signed into law on May 5, 2005, and became effective May 5, 2005. S.B. 236 was signed into law on May 24, 2007, and became effective May 24, 2007.

### Legal Requirements

The “entity” covered under the Georgia breach notification law is rather extensive. It includes individuals who in whole or in part assemble, collect, compile, evaluate,  
 transmit, transfer, report, or communicate PI of individuals for either monetary fees or dues. Entities who do this for non-affiliated third parties, or for any legal agency be it state, local, or federal, are included. This covers bureaus, public educational institutions, and legal institutions. The statute doesn’t affect government agencies maintaining records primarily as a means of keeping traffic safety. The same is true of law enforcement, or licensing for public access court records to property information either real or personal. The legal definition of “entity” in Georgia applies to non-local parties who manage PI of state residents.

A [security](https://scasecurity.com/security/) breach is when PI is accessed without authorization. Good faith data utility isn’t a breach, unless the data is misused, or made subject to any subsequent disclosure of an unauthorized kind.

### Time Frames for Breach Reporting

An entity is obligated to provide breach notification in Georgia after a breach is discovered, and to whoever’s information was accessed by unauthorized parties. Consumer reporting agencies must be notified should 10,000 or more residents in Georgia be compromised at once. This must additionally be done without unreasonable delay. Should an entity keep computerized data for a third party, they must be notified within 24 hours of breach discovery–provided PI was, or is reasonably expected to have been, acquired by an unauthorized person(s).

Notification must be made as quick as possible and without delay. Determining the scope of a breach, and re-establishing a data system’s operational integrity, are determined to be reasonable delays. Means by which affected parties can be notified include either written notice or electronic notice conforming to the E-SIGN Act (15 U.S.C. § 7001). Substitute notification methods become available should more than $50,000 be required to notify affected individuals, should more than 100,000 parties be affected, or if there isn’t available contact information.

### Associated Penalties

Private lawsuits are not allowed for PI compromise in Georgia. If PI was encrypted, associated notification laws do not apply.

### Exceptions/Exemptions

Breach notification exceptions for Georgia include delays for law enforcement should such an agency determine that notifying affected parties would impede an investigation. As soon as law enforcement allows notification, it must be made. Additionally, if an entity keeps notification procedures in consistence with timing and notification requirements of existing Georgia statutes, this is permissible–provided notification of affected parties according to such procedures is followed.

### Contact Security Compliance Associates Today to Learn More about Information Security Breach Law in Georgia

Security [Compliance](https://scasecurity.com/compliance/) Associates (SCA) has years of experience helping organizations across the United States to prevent and manage potential data breaches. Contact us today at 727-571-1141 to schedule a no-cost consultation. You can also download our free [Data Breach Response Guide](https://scasecurity.com/data-breach-response-guide/) to learn more about breach notification law in your state.

#### Subscribe

Email\*

Notification Frequency

[Data Breach](https://blog.scasecurity.com/tag/data-breach)

[September 26, 2024 6 Functions of the NIST Cybersecurity Framework](https://blog.scasecurity.com/nist-security-framework) [September 14, 2023 7 Lessons Learned from the Dish TV Ransomware Attack](https://blog.scasecurity.com/7-lessons-learned-from-the-dish-tv-ransomware-attack) [August 27, 2023 Cybersecurity Consulting: Five Considerations for AI and Privacy Issues](https://blog.scasecurity.com/cybersecurity-consulting-five-considerations-for-ai-and-privacy-issues)

### Comments

© 2026 - All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SCA Editor",
    "url" : "https://blog.scasecurity.com/author/sca-editor"
  },
  "dateModified" : "2025-04-10T15:30:43.980Z",
  "datePublished" : "2019-12-18T05:00:00.000Z",
  "headline" : "Information Security Breach in Georgia - SCA Security",
  "image" : [ "https://blog.scasecurity.com/hubfs/Imported_Blog_Media/Georgia.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.scasecurity.com/information-security-breach-in-georgia",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.scasecurity.com/hubfs/sca-logo-r.png"
    },
    "name" : "Security Compliance Associates"
  }
}
```