# Georgia

> Georgia (National Bank of Georgia · State Audit Office): The one place where privacy oversight went backwards. Region: Europe. Restricts anonymity: Anonymity-enhancing assets or unattributed transfers are barred outright, or barred for regulated firms.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Europe
- Subject: The one place where privacy oversight went backwards
- Authority: National Bank of Georgia · State Audit Office
- Stance on on-chain confidentiality: Restricts anonymity. Anonymity-enhancing assets or unattributed transfers are barred outright, or barred for regulated firms.
- Tags: DPA abolished, payments ban, registration regime, innovation office
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-georgia

## What it actually says

Across every jurisdiction surveyed for this section, institutional privacy oversight was either strengthening or holding steady. Georgia is the exception. Its independent data protection authority was liquidated in March 2026 and the function folded into the State Audit Office, which removes the separation that made the supervisor independent in the first place. On the financial side the picture is restrictive but conventional: providers have registered with the central bank since mid-2023, and using virtual assets for payment is barred by the organic law governing the central bank. Peer-to-peer trading with one's own funds stays outside the regime. We found no instrument addressing anonymity-enhancing assets either way.

## The instruments that matter

- **Data protection authority abolished 2 March 2026**: the independent Personal Data Protection Service was liquidated and its supervisory, inspection and complaint functions transferred to the State Audit Office
- **Virtual asset payments prohibited**: under Article 39¹(2) of the Organic Law on the National Bank, except in cases the central bank defines as necessary to provide virtual asset services
- **Provider registration since 1 July 2023**: under Governor's Decree N94/04 of 13 June 2023, imposing fit-and-proper, head office, systems and anti-money-laundering requirements on FATF lines
- **Peer-to-peer left alone**: trading with one's own funds does not trigger registration

## Sources

- [NBG virtual asset service providers](https://nbg.gov.ge/en/page/virtual-asset-service-providers-vasps)
- [Anti-money-laundering law on Matsne](https://matsne.gov.ge/en/document/view/4690334)

## Related entries

- [Switzerland](https://www.sodalabs.xyz/privacy-hub/regulation/jur-switzerland): Crypto-friendly and strict on anonymity at once
- [Thailand](https://www.sodalabs.xyz/privacy-hub/regulation/jur-thailand): Closed by whitelist, not by prohibition
- [Turkey](https://www.sodalabs.xyz/privacy-hub/regulation/jur-turkey): Caps, delays and a compelled purpose description
- [EU AMLR Article 79](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eu-amlr): Anti-money laundering · Regulation (EU) 2024/1624
- [EU Transfer of Funds Regulation](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eu-travel-rule): Travel rule · Regulation (EU) 2023/1113
- [Norway](https://www.sodalabs.xyz/privacy-hub/regulation/jur-norway): MiCA via the EEA, with a privacy-innovation sandbox
