Georgia's Data Breach Notification Law, Explained for Businesses
Georgia's data breach notification law, O.C.G.A. 10-1-910 to 10-1-912, requires information brokers and data collectors to tell Georgia residents when their computerized personal information is acquired by an unauthorized person. It sets a 24-hour rule for vendors and a 10,000-resident trigger for extra notices. It does not require security testing. This guide explains what the law does and does not ask of your business.
Who the law covers
The statute names two groups. "Information brokers" are businesses that collect and sell personal information. "Data collectors" is the broader term. It includes state and local agencies, and in practice it covers any organization that keeps computerized personal information about Georgia residents.
A third group is pulled in indirectly. Any company that maintains that data on behalf of a broker or collector, such as a hosting provider, a payroll processor or a SaaS vendor, has its own duty under the law. That duty is covered in the timing section below.
If you run a Georgia business with customer or employee records in a database, assume you are a data collector. If you process that data for someone else, assume you are a third-party custodian.
What counts as a breach
The law applies to computerized personal information about Georgia residents. It defines "personal information" by listing specific data elements. The list sits in 10-1-911. Check an incident against that list with counsel before you decide whether it is reportable. An attacker who copies a newsletter list has not necessarily triggered the statute. An attacker who copies a customer table with identity numbers almost certainly has.
Three phrases the statute never uses: "reasonable security", "assessment" and "penetration test". Georgia's law tells you what to do after a breach. It says nothing about how to prevent one. That gap is the reason the question "does Georgia require penetration testing" has a short answer: no, not under state law.
Timing: the 24-hour vendor rule and the 10,000-resident trigger
Notice to affected residents must go out "in the most expedient time possible and without unreasonable delay". The statute sets no fixed number of days for that notice.
Two rules are more specific.
The 24-hour vendor rule. If you maintain data on behalf of another business and you discover a breach, you must notify the data owner "within 24 hours". The owner then handles the resident notices. For a SaaS vendor or managed service provider with Georgia clients, this is the clause that bites. 24 hours is not long when you are still working out what happened.
The 10,000-resident trigger. If a breach requires notice to "more than 10,000 Georgia residents", you must also notify the nationwide consumer reporting agencies.
One thing the statute does not require is a notice to the Georgia Attorney General. Several states require regulator notice for every breach. Georgia's breach statute does not. Federal and sector rules may still require one, so do not treat this as the end of your reporting duties.
Penalties and enforcement under the Fair Business Practices Act
Sections 10-1-910 to 10-1-912 contain no penalty clause of their own. Enforcement runs through the Georgia Fair Business Practices Act, which treats a failure to notify as an unfair or deceptive practice.
You will see dollar figures quoted online for Georgia breach penalties. The breach statute itself states none. Treat any number you read, including on this page, as something to verify with counsel against the current FBPA text.
In practice the cost of a Georgia breach rarely comes from the state. It comes from customer notification, credit monitoring, contract claims from clients whose data you held, and the cyber insurer asking what controls you had in place.
What Georgia does not have
Two claims about Georgia circulate online, and both are wrong as of 2 October 2026.
Georgia has no comprehensive consumer privacy act. There is no Georgia equivalent of California's or Virginia's privacy law. A bill numbered SB 111 and titled the Georgia Consumer Privacy Protection Act was signed on 11 May 2026. Before passage, the House had replaced its privacy text with a rural hospital tax credit measure. The title survived. The privacy law did not. Any page telling you a Georgia privacy act "took effect on 1 July 2026" with consumer-count thresholds is describing a law that does not exist.
Georgia has no insurance data security act. 28 of 56 US jurisdictions had adopted the NAIC Insurance Data Security Model Law as of August 2025. Georgia is not one of them. Georgia-licensed insurers and agencies follow federal rules such as GLBA, not a state cybersecurity statute. South Carolina, by contrast, adopted the model first. We cover it in our South Carolina Insurance Data Security Act guide.
HB 156: incident reporting for agencies and utilities
House Bill 156, signed on 25 March 2021, adds a reporting duty for Georgia state agencies and utilities. They must report cyberattacks, data breaches or malware to the Georgia Emergency Management and Homeland Security Agency "within two hours of notifying federal emergency management agencies" when the incident could "create a life-safety event, substantially impact the security of data and information systems, or affect critical systems, equipment, or service delivery". GEMA/HS runs a reporting portal for this.
HB 156 contains no testing requirement either. If you sell software or services to a Georgia utility or agency, expect that two-hour clock to show up in your contract as an incident notification clause. Your own detection and response time becomes their compliance problem.
Where a penetration test fits
Georgia law does not order you to test. Three things still make a test the right move.
Prevention. Every clause above starts after an attacker is already inside. A penetration test is the step before that. An OSCP-certified tester tries to break in the way a real attacker would and hands you the list of what to fix.
A defensible posture. When regulators, insurers or plaintiffs ask what you did to protect data, a dated report from an independent tester is the answer they expect. Georgia has history here. In 2018 the legislature passed SB 315, a computer crime bill that would have made good-faith security research a crime. Governor Deal vetoed it on 8 May 2018 after the security industry warned it would hurt the state's ability to defend itself. Authorized testing is legal, expected and encouraged in Georgia.
Evidence. Counsel, cyber insurers and enterprise customers all ask for the same document.
Budget Security runs penetration tests for US companies at $985 per tester-day (€849 per day for EU clients). You scope online, testing starts within 7 days of booking, the report is delivered within 48 hours after the test ends, and you pay after the report is delivered. For Atlanta and Georgia companies, start on our Atlanta penetration testing page.
PCI DSS 11.4 for Transaction Alley
More than 70 percent of US payment transactions pass through Georgia's "Transaction Alley", and six of the ten largest US payment processors are headquartered in the state. For those companies, and for any merchant that stores card data, PCI DSS Requirement 11.4 is the rule that names penetration testing: internal and external tests at least once every 12 months and after any significant change. That is a contractual obligation to the card brands, not a Georgia statute, but it is the testing mandate most Atlanta companies actually face. Scope and evidence details are on our PCI DSS pentesting page.
HIPAA evaluations for Georgia health systems
Georgia's hospital systems are large. Piedmont runs 20 hospitals, Wellstar 13, Emory 11 and Northside 6. Every covered entity and business associate in that supply chain, including health-tech startups selling into it, falls under the HIPAA Security Rule. 45 CFR 164.308(a)(8) requires "a periodic technical and nontechnical evaluation"; the rule never says "penetration test", but a pentest report is the evidence regulators look for. See our HIPAA penetration testing page.
GLBA Safeguards Rule for Georgia lenders and fintechs
Non-bank lenders, mortgage brokers, fintechs and payment firms under FTC jurisdiction follow the GLBA Safeguards Rule. 16 CFR 314.4(d)(2) calls for annual penetration testing and vulnerability assessments at least every six months unless you run effective continuous monitoring. Banks follow the equivalent interagency guidelines. For Georgia's state-chartered banks, the testing expectation comes from these federal rules, not from state banking regulation. See our GLBA penetration testing page.
CMMC for Augusta and Fort Eisenhower suppliers
Augusta hosts Fort Eisenhower, home to US Army Cyber Command and the NSA Georgia Cryptologic Center, plus the Georgia Cyber Center. Defense suppliers in that ecosystem face CMMC 2.0, in force under 32 CFR Part 170 since 16 December 2024 and written into DoD contracts since 10 November 2025. Level 2 does not mandate a penetration test. Level 3 requires one each year. See our CMMC penetration testing page.
FAQ
Questions we get
Does Georgia require penetration testing?
What is O.C.G.A. 10-1-912?
Do I have to notify the Georgia Attorney General after a breach?
How fast must a vendor notify its client under Georgia law?
Does Georgia have a consumer privacy law like California's?
Does Georgia have an insurance data security law?
What does Georgia HB 156 require?
Which rules do require a penetration test for a Georgia company?
See the price for your scope before you book.
$985 per tester-day for US clients (€849 per day for EU clients). Start within 7 days of booking. Report within 48 hours after testing ends. Pay after delivery.