Cybercrime & digital privacy

Digital Forensics and Social-Media Evidence

Digital Forensics and Social-Media Evidence in Georgia: Criminal defence, corporate response and victim representation for hacking, account takeover, online fraud, digital extortion and unlawful use or disclosure of private communications in Georgia.

English legal guideTbilisi · Georgia-wide
Short answer

Digital Forensics and Social-Media Evidence in Georgia: Criminal defence, corporate response and victim representation for hacking, account takeover, online fraud, digital extortion and unlawful use or disclosure of private communications in Georgia.

Discuss this issue →
Practical overview

What this means in practice

Digital Forensics and Social-Media Evidence in Georgia: Criminal defence, corporate response and victim representation for hacking, account takeover, online fraud, digital extortion and unlawful use or disclosure of private communications in Georgia.

For Digital Forensics and Social-Media Evidence, the early priority is to preserve volatile digital evidence without altering it. The first evidence review should include device images, logs and authentication records and should be completed before assumptions harden into the case narrative.

Issues to assess early

01

Preserve volatile digital evidence without altering it

02

Separate device ownership from authorship and account control

03

Identify authorisation, access method, intent and alleged consequence

04

Coordinate criminal, privacy, employment, platform and recovery issues

Evidence that may matter

Evidence must be examined in context. Existence of a document, transfer, message or device artefact does not answer every question about authorship, knowledge, purpose, legality, completeness or reliability.

  • Device images, logs and authentication records
  • Messages, emails and platform data
  • IP, location, SIM and account-recovery records
  • Wallet, bank and payment evidence
  • Forensic acquisition and chain-of-custody material
Legal classification starting point

Potential Criminal Code provisions

The provisions below are a focused research map for digital forensics and social-media evidence, not a statement that any person has committed an offence. Each element, part, threshold and aggravating circumstance must be checked against the current Georgian text and the actual evidence.

Article 157

Disclosure of information on private life or personal data

Covers specified unlawful obtaining, storage, use or disclosure that satisfies the article's consequence and circumstance requirements; privacy concern alone does not settle criminal liability.

Read full Article 157 text on this page
Article 284

Unauthorised access to a computer system

Ownership of a device or account does not prove unauthorised access; permission, attribution, method and consequence should be tested.

Read full Article 284 text on this page
Article 286

Interference with computer data or systems

May be relevant where alteration, deletion, damage or obstruction is alleged; reliable forensic attribution is critical.

Read full Article 286 text on this page
Why the cited article can change

An investigation may start under one article and later be narrowed, expanded or reclassified. New evidence, expert conclusions, the legally assessed consequence, a defence application, prosecutorial review or a court ruling may support a different provision, part or aggravating circumstance. The Georgian consolidated text controls; an English translation may lag.

Criminal Code text on this page

Read the relevant provisions before the external source

The operative English text below is reproduced from the official consolidated Criminal Code of Georgia, publication 296, accessed 9 August 2026. Formatting has been normalised for on-screen reading; the current Georgian-language consolidated text controls if wording or timing differs.

Article 157Disclosure of information on private life or of personal data

1. Unlawful obtaining, storage, use, dissemination of or otherwise making available information on private life or personal data, which has resulted in considerable damage, –

shall be punished by a fine or corrective labour for up to two years, or by imprisonment for up to three years.

2. Unlawful use and/or dissemination of information on private life or of personal data through a piece of work disseminated in a certain way, through internet, including social network, mass media or other public appearance, which has resulted in considerable damage, –

shall be punished by a fine or corrective labour for up to two years, or by imprisonment for up to four years.

3. The act provided for in paragraph 1 or 2 of this article committed:

a) for mercenary purposes;

b) repeatedly, –

shall be punished by a fine or imprisonment for a term of up to five years.

4. The act under paragraphs 1, 2 or 3 of this article committed by a person, who, due to his/her official position, professional activities or other circumstances, was obliged to keep this information or data confidential, or who committed the above act using his/her official position, –

shall be punished by imprisonment for a term of four to seven years, with or without deprivation of the right to hold an office or to carry out activities for up to three years.

Note:

1. A person shall not incur criminal liability for a crime (obtaining, storage) under paragraph 1 of this article if he/she has submitted the obtained/stored information specified in paragraph 1 of this article to investigative authorities and communicated information on any other committed/anticipated criminal act in this manner.

2. For committing an act under this article, a legal person shall be punished by a fine, with deprivation of the right to carry out activities, or by liquidation and a fine.

Open Article 157 in the official consolidated Criminal Code
Article 284Unauthorised access to a computer system

1. Unauthorised access to a computer system, –

shall be punished by a fine or corrective labour for up to two years, or by imprisonment for the same term.

2. The same act:

a) committed by a group of persons with preliminary agreement;

b) committed using an official position;

c) committed repeatedly;

d) that has resulted in substantial damage, –

shall be punished by a fine or corrective labour for up to two years, or by imprisonment for a term of two to five years.

3. The act provided for by paragraphs 1 and/or 2 of this article, committed against a critical information system subject, –

shall be punished by imprisonment for a term of three to six years.

Note:

1. A computer system is any equipment/mechanism or a group of inter-connected equipment/mechanisms that automatically processes data (including personal computers, any equipment with a microprocessor, or a mobile phone) by means of software.

2. Computer data are any information displayed in any form that can be processed in the computer system, including software that ensures the operation of the computer system.

3. Unauthorised shall mean illegal, also those cases when the holder of the right has not, directly or indirectly, transferred the right to the person committing the act.

4. For the purposes of this Chapter, ‘substantial damage’ shall be considered damage exceeding GEL 2 000, except in cases provided for by Article 2861 of this Code.

5. A crime provided for by this Chapter shall be deemed as having been committed repeatedly if it has been preceded by any of the crimes provided for by this Chapter.

6. A critical information system subject shall be a critical information system subject as provided for by the Law of Georgia on Information Security.

7. For the act provided for by this article, a legal person shall be punished by a fine, with deprivation of the right to carry out activities, or by liquidation and a fine.

Open Article 284 in the official consolidated Criminal Code
Article 286Interference with computer data and/or computer systems

1. Unauthorised damage, deletion, modification or concealment of computer data, –

shall be punished by a fine or corrective labour for up to two years and/or by imprisonment for the same term.

2. The act provided for by paragraph 1 of this article, and unauthorised insertion or transfer of computer data that has resulted in considerable and intentional disruption of the operation of a computer system, –

shall be punished by a fine or corrective labour for up to two years and/or by imprisonment for up to three years.

3. The act provided for by paragraph 1 or 2 of this article:

a) committed by a group of persons with preliminary agreement;

b) committed using an official position;

c) committed repeatedly;

d) that has resulted in substantial damage, –

shall be punished by a fine or corrective labour for up to two years, or by imprisonment for a term of three to five years.

4. The act provided for by paragraphs 1 and/or 2 of this article, committed against a critical information system subject, –

shall be punished by imprisonment for a term of four to seven years.

Note: For committing an act provided for by this article, a legal person shall be punished by a fine, with deprivation of the right to carry out activities, or by liquidation and a fine.

Open Article 286 in the official consolidated Criminal Code
Case-specific decision point

In a Digital Forensics and Social-Media Evidence matter, a device extraction or platform export may look decisive even though access, authorship, timestamps, completeness and chain of custody remain disputed.

The immediate decision is how to protect the record and prepare for incident containment without prejudicing the client’s procedural position. This is a fictional example for orientation, not a report of a client matter or an assumption of guilt.

How the process may develop

01Incident containment
02Legal preservation
03Attribution analysis
04Forensic review
05Authority or platform response
06Defence, complaint and recovery

Not every matter reaches every stage, and several steps can overlap. Arrest, search, seizure, charging, restraint measures and court review each have their own legal basis. Current deadlines should be verified against the consolidated Criminal Procedure Code and the specific decision served in the case.

How defence counsel can assist

Criminal defence counsel can clarify status and rights, attend permitted investigative actions, review prosecution evidence, obtain lawful defence evidence, prepare motions and submissions, represent the client at restraint and trial hearings, negotiate only where instructed and appropriate, and coordinate appeals or international work.

Presumption and burden

An investigation or charge is not a conviction. Only a court may find a person guilty, and defence rights must remain practical and effective throughout the proceedings.

Frequently asked questions

Does Article 157 — Disclosure of information on private life or personal data — automatically apply to Digital Forensics and Social-Media Evidence?+

For Digital Forensics and Social-Media Evidence, Article 157, Article 284, Article 286 may provide a starting point, but a page title is not a legal qualification. Investigators and prosecutors must match proved facts to every element, part and aggravating circumstance. The qualification may be narrowed, expanded or changed after expert results, new evidence, a defence motion, prosecutorial review or a court decision. Covers specified unlawful obtaining, storage, use or disclosure that satisfies the article's consequence and circumstance requirements; privacy concern alone does not settle criminal liability.

Which factual boundary is decisive in a Digital Forensics and Social-Media Evidence case?+

In a Digital Forensics and Social-Media Evidence case, the evidence must distinguish device or account ownership from actual access, authorisation, authorship and criminal purpose. That boundary is tested through the person's individual conduct, knowledge or intent, the legally classified consequence and every circumstance relied upon to move the allegation into a different article or aggravated part.

What evidence can prove—or undermine—the allegation of Digital Forensics and Social-Media Evidence?+

The focused record for Digital Forensics and Social-Media Evidence is not the same as for every offence. Priority material includes forensic images, access logs, session history, provider records, messages, network data and recovery events. The defence should test provenance, completeness, authorship, lawful collection, chain of custody and whether each item proves the disputed element rather than merely repeating the accusation.

Can the article or charge for Digital Forensics and Social-Media Evidence change after the investigation starts?+

Yes. For Digital Forensics and Social-Media Evidence, Article 157, Article 284, Article 286 may be a starting map, but expert results, quantity or value, injury classification, individual role, attempt or participation, a defence application, prosecutorial review or a court decision may support a different article, part or legal outcome.

What should be preserved immediately in a Digital Forensics and Social-Media Evidence matter?+

In a Digital Forensics and Social-Media Evidence matter, preserve the original chronology, procedural records and the topic-specific material before routine loss or alteration. Early advice is important because logs expire and well-meant resets can destroy attribution evidence; preservation must be lawful and must not involve hiding, changing or coordinating evidence.

Sources & legislation

Primary sources for this guide

Legislation can change and official English translations may lag the Georgian text. Check the current consolidated version and obtain advice before relying on a deadline, offence classification or remedy.

Criminal Procedure Code of GeorgiaCriminal Code of GeorgiaConstitution of Georgia
Need advice on this issue?

Discuss the facts, documents and next decision.

Use the urgent route for detention, searches, questioning or time-critical international matters. Standard and corporate enquiries can be scheduled separately.

Urgent assistance