🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
RU v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing20 sources retrieved model claude-sonnet-5 · 2026-08-07

Russia

RU schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 44 claims · 29 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
44Claimsbaseline..claims[]
5Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Russia's data-protection framework under Federal Law No. 152-FZ has been amended by a cluster of 2025 measures -- Federal Law No. 420-FZ and Federal Law No. 421-FZ -- reported to raise fines for repeated data leaks to up to 3 percent of annual turnover and to introduce criminal liability of up to 10 years for illegal personal-data trafficking. Roskomnadzor is understood to remain the federal executive body responsible for supervision of personal-data processing compliance, alongside its existing media and internet-censorship functions. No primary rkn.gov.ru or pravo.gov.ru text for either 420-FZ or 421-FZ was retrieved this cycle, so these figures rest on secondary and vendor-summary sourcing rather than the statute itself, and are reported here with appropriately hedged confidence.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core regulator, statute and registration mechanics are clearly documented and stable; residual uncertainty concerns the final status of 2022 extraterritoriality-extension amendments.

Primary frameworkFederal Law No. 152-FZ 'On Personal Data' (27 July 2006, as amended)
Traffic-light rationale — GreenCore regulator, statute and registration mechanics are clearly documented and stable; residual uncertainty concerns the final status of 2022 extraterritoriality-extension amendments.

Sub-modules (5)

Regulator And AuthorityGreen

Roskomnadzor is designated the Competent Authority for protecting personal data subjects' rights under Article 23 of 152-FZ.

Claims (1):

  • Roskomnadzor is the Competent Authority for protecting the rights of personal data subjects in Russia pursuant to Article 23 of Federal Law No. 152-FZ.

Act And InstrumentsGreen

152-FZ (2006, as amended) is the core instrument, functioning as Russia's GDPR-analogue statute.

Claims (1):

  • Federal Law No. 152-FZ of 27 July 2006 'On Personal Data' is the core statute governing personal data processing in Russia and is treated as the functional analogue to the GDPR.

Material ScopeGreen

Scope covers automated processing and manual processing functionally equivalent to automated processing, by state, municipal and private operators.

Claims (1):

  • 152-FZ regulates personal data processing by state bodies, municipal bodies, legal entities and individuals using automated means (including telecommunications networks) or non-automated means where processing is functionally similar to automated processing.

Territorial ScopeAmber

Applies to Russian-based offices of non-Russian companies; a 2022 first-reading bill would have extended extraterritorial application, but final enactment status of that specific provision was not confirmed in this pass.

Claims (2):

  • The Law on Personal Data applies to legal entities processing personal data of Russian data subjects, including Russian-based offices of non-Russian companies that physically process such data in Russia.
  • A 2022 first-reading bill amending 152-FZ proposed extraterritorial application of the Law on Personal Data alongside mandatory notification of intended cross-border transfers; final enactment status of the extraterritoriality provision specifically was not confirmed.

Regulator Registration And FilingGreen

Pre-processing notification to Roskomnadzor is mandatory, recorded in a public Register of Operators, with 10-business-day update obligations; foreign hosting providers face separate registration duties since Feb 2024.

Claims (3):

  • CLM-RU-f6a7b8c9 (claim on file)
  • CLM-RU-a7b8c9d0 (claim on file)
  • CLM-RU-b8c9d0e1 (claim on file)
Category narrative81 words

Russia's data-protection regime is anchored in Federal Law No. 152-FZ 'On Personal Data' (27 July 2006, as amended), supervised by Roskomnadzor (the Federal Service for Supervision of Communications, Information Technology and Mass Media). The framework applies to state/municipal bodies, legal entities and private individuals processing personal data by automated or functionally-equivalent manual means, and extends to Russian-based offices of foreign companies. Operators must notify Roskomnadzor before processing and are recorded on a public Register of Operators, with periodic filing updates required.

Periodic update · new data 2026-09-28

Regulator & Framework

Roskomnadzor is the federal executive body understood to be responsible for supervision of personal-data processing compliance in Russia, a function it exercises alongside its separate media and internet-censorship remit. The core statute, Federal Law No. 152-FZ, has been amended repeatedly, most recently and materially by Federal Law No. 420-FZ and Federal Law No. 421-FZ, both reported in 2025, which are understood to raise fines for repeated data leaks to up to 3 percent of annual turnover and to introduce criminal liability of up to 10 years for illegal personal-data trafficking respectively. No rkn.gov.ru or pravo.gov.ru primary text for either amendment was retrieved this cycle; the figures above rest on secondary and vendor-compliance-database summaries, which caps confidence at Uncertain for the specific fine and liability figures even though the general direction of tightening is reasonably well corroborated across independent secondary sources.

Outlook

The key marker for this module is whether primary statutory text for 420-FZ and 421-FZ becomes available in a subsequent cycle, which would allow the reported figures to move from secondary-sourced to primary-confirmed status.

Sources and claims (5)
  1. ConfirmedRoskomnadzor — Roskomnadzor is the Competent Authority for protecting the rights of personal data subjects in Russia pursuant to Article 23 of Federal Law No. 152-FZ.observed
  2. ConfirmedOneTrust DataGuidance — Federal Law No. 152-FZ of 27 July 2006 'On Personal Data' is the core statute governing personal data processing in Russia and is treated as the functional analogue to the GDPR.observed
  3. ConfirmedOneTrust DataGuidance (hosting official-text translation) — 152-FZ regulates personal data processing by state bodies, municipal bodies, legal entities and individuals using automated means (including telecommunications networks) or non-automated means where processing is functionally similar to automated processing.observed
  4. ConfirmedOneTrust DataGuidance — The Law on Personal Data applies to legal entities processing personal data of Russian data subjects, including Russian-based offices of non-Russian companies that physically process such data in Russia.observed
  5. UncertainOneTrust DataGuidance — A 2022 first-reading bill amending 152-FZ proposed extraterritorial application of the Law on Personal Data alongside mandatory notification of intended cross-border transfers; final enactment status of the extraterritoriality provision specifically was not confirmed.observed

#

Lawful bases and biometric rules are reasonably well evidenced, but consent-threshold detail (freely given/informed/revocable) and a formal anonymisation safe-harbour are thinly sourced or absent.

Primary frameworkFederal Law No. 152-FZ 'On Personal Data'; Code of Administrative Offences (Federal Law No. 195-FZ) as amended by Federal Law No. 420-FZ (2024)
Supervisory authorityRoskomnadzor
Traffic-light rationale — AmberLawful bases and biometric rules are reasonably well evidenced, but consent-threshold detail (freely given/informed/revocable) and a formal anonymisation safe-harbour are thinly sourced or absent.

Sub-modules (4)

Lawful BasesGreen

Consent, contract performance and legal-obligation compliance are recognised lawful bases, mirroring GDPR Art 6.

Claims (1):

  • Under the Law on Personal Data, processing is lawful where the data subject has given consent, where processing is necessary for performance of a contract, or for compliance with a legal obligation, among other grounds paralleling GDPR Article 6.

Special CategoriesAmber

Biometric data is subject to escalating regulation: 2022 draft amendments addressed credit-institution biometric collection via the Unified Biometric System, and 2024's Federal Law No. 420-FZ introduced dedicated administrative fines for biometric-data disclosure.

Claims (1):

  • Federal Law No. 420-FZ (adopted 30 November 2024) amends the Code of Administrative Offences to introduce fines for unauthorized disclosure of personal data and biometric data, and for violations of consumer rights related to biometric identification and authentication.

Pseudonymisation And AnonymisationAmber

Roskomnadzor has consistently held that security measures such as hashing do not anonymise data; hashed/encrypted personal data remains 'personal data' for localisation purposes, meaning no GDPR-style anonymisation safe harbour currently operates in practice.

Claims (1):

  • Roskomnadzor maintains that applying security measures such as hashing does not change the nature of underlying data, and hashed data does not qualify as anonymised for purposes of the Law on Personal Data and its localisation requirements.
Category narrative78 words

Russian law recognises consent, contractual necessity and legal-obligation compliance as lawful bases, paralleling GDPR Article 6. Consent standards are reinforced by Federal Antimonopoly Service (FAS) guidance disallowing default/bundled consent in adhesion contracts. Special-category handling is most developed for biometric data, where a Unified Biometric System regime and (from late 2024) dedicated administrative fines for biometric-data disclosure now apply. Pseudonymisation/anonymisation lacks a GDPR-style safe harbour: Roskomnadzor treats hashed or encrypted data as still constituting personal data for localisation purposes.

Periodic update · new data 2026-09-28

Lawful Processing & Special Data

The 2022 amendments under Federal Law No. 266-FZ are reported to have eliminated bundled or pre-checked consent in Russian data-protection practice: each processing purpose now understood to require a separate, affirmative act by the data subject, rather than a single blanket consent covering multiple purposes. Distribution of personal data to an unlimited audience is reported to require separately and specifically obtained consent, distinct from consent to processing generally. This consent architecture is broadly comparable in structure to purpose-specific consent requirements found in GDPR-style regimes, though the Russian statute operates under its own enforcement and definitional framework. No primary statutory text was directly retrieved this cycle to confirm the precise wording of the affirmative-act standard; the claim rests on secondary legal-summary sourcing, and confidence is accordingly held at Uncertain.

Outlook

Whether Roskomnadzor issues implementing guidance further specifying what constitutes a valid separate affirmative act for consent purposes is the development to watch for this module.

Sources and claims (4)
  1. ConfirmedOneTrust DataGuidance — Under the Law on Personal Data, processing is lawful where the data subject has given consent, where processing is necessary for performance of a contract, or for compliance with a legal obligation, among other grounds paralleling GDPR Article 6.observed
  2. ProbableOneTrust DataGuidance — Mandatory inclusion of consent to receive direct marketing 'by default' within a public or adhesion service contract is not admissible under FAS Russia guidance, as it is inconsistent with the principle of free will underlying valid consent.observed
  3. ConfirmedOneTrust DataGuidance — Federal Law No. 420-FZ (adopted 30 November 2024) amends the Code of Administrative Offences to introduce fines for unauthorized disclosure of personal data and biometric data, and for violations of consumer rights related to biometric identification and authentication.observed
  4. ProbableIAPP — Roskomnadzor maintains that applying security measures such as hashing does not change the nature of underlying data, and hashed data does not qualify as anonymised for purposes of the Law on Personal Data and its localisation requirements.observed

#

Access, erasure and response-deadline mechanics are well evidenced (T1 primary-law text), but restriction/objection and portability rights are an evidenced gap.

Primary frameworkFederal Law No. 152-FZ 'On Personal Data', Articles 14, 20-21
Supervisory authorityRoskomnadzor
Traffic-light rationale — AmberAccess, erasure and response-deadline mechanics are well evidenced (T1 primary-law text), but restriction/objection and portability rights are an evidenced gap.

Sub-modules (5)

Access RightGreen

Operators must make personal data available for inspection by the subject free of charge.

Claims (1):

  • An operator must make personal data relating to a particular data subject available for inspection by that data subject or their representative free of charge.

Rectification And ErasureGreen

Unlawfully-obtained or no-longer-needed data must be destroyed within 7 working days; unlike the GDPR, no statutory exemptions apply to this erasure duty.

Claims (2):

  • Where a data subject demonstrates that personal data were unlawfully obtained or are no longer needed for the stated processing purpose, the operator must destroy that data within seven working days and notify the subject and, where feasible, downstream third-party recipients.
  • Unlike the GDPR, the Law on Personal Data does not provide statutory exemptions to the right to erasure.

Restriction And ObjectionRed

No explicit GDPR Art 18/21-style restriction or objection-to-profiling right was located in the sources reviewed.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , 1, 5, 2, -, F, Z, , r, i, g, h, t, , t, o, , r, e, s, t, r, i, c, t, , p, r, o, c, e, s, s, i, n, g, , r, i, g, h, t, , t, o, , o, b, j, e, c, t, , p, r, o, f, i, l, i, n, g, , o, p, t, -, o, u, t.

Data PortabilityRed

No GDPR Art 20-style data-portability right was located in 152-FZ or secondary commentary reviewed.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , 1, 5, 2, -, F, Z, , d, a, t, a, , p, o, r, t, a, b, i, l, i, t, y, , r, i, g, h, t.

Deadlines And Response WindowsGreen

30-day windows apply both to reasoned refusal responses to data subjects and to operator responses to Roskomnadzor information requests.

Claims (2):

  • An operator must give a reasoned written reply to a data subject's request within thirty days from the date of the application or request.
  • An operator must supply information requested by Roskomnadzor within thirty days from the date of receipt of that request.
Category narrative60 words

Data subjects have access, rectification and erasure rights with defined response windows (7 working days for destruction of unlawfully-obtained/unneeded data; 30 days for reasoned written responses and for regulator information requests). No GDPR-style exemptions apply to the erasure right. Explicit restriction-of-processing, objection-to-profiling, and data-portability rights analogous to GDPR Articles 18, 21 and 20 were not identified in the sources reviewed.

Periodic update · new data 2026-09-28

Data Subject Rights

Under the Federal Law No. 266-FZ amendment framework, data operators are reported to be required to cease processing within 10 working days of a valid withdrawal-of-consent or objection request from a data subject. This creates a defined statutory response window for rights requests, distinct from the separate 24-hour breach-notification duty that applies to security incidents rather than subject-rights requests. Evidence for the specific 10-working-day figure rests on secondary legal-summary sourcing rather than a directly retrieved primary statutory text this cycle, so confidence is held at Uncertain pending further corroboration.

Outlook

Confirmation of the 10-working-day cessation window against a primary Roskomnadzor or pravo.gov.ru source remains the outstanding item for this module.

Sources and claims (5)
  1. ConfirmedRoskomnadzor — An operator must make personal data relating to a particular data subject available for inspection by that data subject or their representative free of charge.observed
  2. ConfirmedRoskomnadzor — Where a data subject demonstrates that personal data were unlawfully obtained or are no longer needed for the stated processing purpose, the operator must destroy that data within seven working days and notify the subject and, where feasible, downstream third-party recipients.observed
  3. ConfirmedOneTrust DataGuidance — Unlike the GDPR, the Law on Personal Data does not provide statutory exemptions to the right to erasure.observed
  4. ConfirmedRoskomnadzor — An operator must give a reasoned written reply to a data subject's request within thirty days from the date of the application or request.observed
  5. ConfirmedRoskomnadzor — An operator must supply information requested by Roskomnadzor within thirty days from the date of receipt of that request.observed

#

DPO-equivalent and breach-notification duties are well evidenced and increasingly strict, but ROPA, granular security-measure standards, and joint-controller concepts are gaps relative to GDPR-style regimes.

Primary frameworkFederal Law No. 152-FZ 'On Personal Data'; Code of Administrative Offences as amended by Federal Law No. 420-FZ (2024)
Supervisory authorityRoskomnadzor
Traffic-light rationale — AmberDPO-equivalent and breach-notification duties are well evidenced and increasingly strict, but ROPA, granular security-measure standards, and joint-controller concepts are gaps relative to GDPR-style regimes.

Sub-modules (7)

Accountability And DpiaRed

No DPIA-equivalent mechanism was identified in 152-FZ or secondary sources reviewed.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , 1, 5, 2, -, F, Z, , D, P, I, A, , p, r, i, v, a, c, y, , i, m, p, a, c, t, , a, s, s, e, s, s, m, e, n, t, , r, e, q, u, i, r, e, m, e, n, t.

Dpo RequirementsAmber

Operators must designate a person responsible for personal-data-processing compliance; this person (or the CEO where none is appointed) can incur personal administrative liability.

Claims (2):

  • Companies operating in Russia are required to designate a 'person responsible for the processing of personal data' who oversees compliance, informs employees of legal and internal requirements, and communicates with data subjects, a role functionally analogous to the GDPR's DPO.
  • Unlike the GDPR, the Law on Personal Data establishes that the person responsible for processing (DPO-equivalent) may incur personal administrative liability for non-compliance with the Law.

Ropa RequirementsAmber

The Law on Personal Data does not contain a GDPR Art 30-equivalent records-of-processing requirement; the notification-based Register of Operators is a partial analogue.

Claims (1):

  • The Law on Personal Data does not contain any record-of-processing-activities requirement equivalent to GDPR Article 30.

Joint Controller ArrangementsRed

152-FZ uses a single unitary 'operator' concept without a GDPR-style joint-controller regime; no joint-controller-specific provisions were located.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , 1, 5, 2, -, F, Z, , j, o, i, n, t, , c, o, n, t, r, o, l, l, e, r, , a, r, r, a, n, g, e, m, e, n, t, , p, r, o, v, i, s, i, o, n, s.

Security MeasuresAmber

General security-of-processing obligations exist under 152-FZ Article 19, but granular technical/organisational standards were not substantively retrieved in this pass.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , 1, 5, 2, -, F, Z, , A, r, t, i, c, l, e, , 1, 9, , t, e, c, h, n, i, c, a, l, , o, r, g, a, n, i, s, a, t, i, o, n, a, l, , s, e, c, u, r, i, t, y, , m, e, a, s, u, r, e, s, , d, e, t, a, i, l.

Breach NotificationGreen

Immediate breach/cyberattack reporting has been mandatory since September 2022, with 2024 amendments adding specific fines for notification failures.

Claims (2):

  • 2022 amendments to the Law on Personal Data, which entered into effect on 1 September 2022, require data operators to immediately report all cyberattacks and data breaches to relevant authorities.
  • Federal Law No. 420-FZ (30 November 2024) introduces administrative fines specifically for an operator's failure to notify Roskomnadzor of a personal data breach, effective 180 days after publication.

Retention And DisposalGreen

Data must be destroyed within 7 working days once unlawfully obtained or no longer needed, with notification duties to affected third parties.

Claims (1):

  • Operators must destroy personal data within seven working days where a data subject demonstrates the data were unlawfully obtained or are no longer required for the stated processing purpose, and must notify third parties to whom the data were transferred.
Category narrative86 words

Operators must designate a 'person responsible for the processing of personal data' (functionally analogous to a DPO), who may face personal administrative liability. Since September 2022, immediate reporting of cyberattacks and data breaches to authorities has been mandatory, reinforced by new 2024/2025 administrative fines for breach-notification failures and unauthorised disclosure. Russian law does not contain a GDPR Article 30-style ROPA obligation, though the Roskomnadzor operator-notification register performs a partial analogous function. Detailed technical/organisational security-measure requirements and joint-controller arrangements were not substantively evidenced in this research pass.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Data operators in Russia are reported to face a 24-hour breach-notification duty to Roskomnadzor, running from the point of detection of a personal-data-security incident, under the Federal Law No. 266-FZ amendment framework. A fuller follow-up notification addressing causes, harm and mitigation measures is understood to be required after the initial 24-hour notification. This is a materially shorter initial window than the 72-hour standard found in GDPR-style regimes, and represents one of the more distinctive compliance burdens facing controllers and processors operating in the Russian market. No primary statutory or Roskomnadzor-issued guidance text was directly retrieved this cycle confirming the exact mechanics of the follow-up notification; the claim rests on secondary legal-summary sourcing, and confidence is held at Uncertain.

Outlook

Whether Roskomnadzor publishes operational guidance detailing the follow-up notification's required content and format is the item to watch for this module.

Sources and claims (6)
  1. ConfirmedIAPP — Companies operating in Russia are required to designate a 'person responsible for the processing of personal data' who oversees compliance, informs employees of legal and internal requirements, and communicates with data subjects, a role functionally analogous to the GDPR's DPO.observed
  2. ConfirmedOneTrust DataGuidance — Unlike the GDPR, the Law on Personal Data establishes that the person responsible for processing (DPO-equivalent) may incur personal administrative liability for non-compliance with the Law.observed
  3. ConfirmedOneTrust DataGuidance — The Law on Personal Data does not contain any record-of-processing-activities requirement equivalent to GDPR Article 30.observed
  4. ConfirmedOneTrust DataGuidance — 2022 amendments to the Law on Personal Data, which entered into effect on 1 September 2022, require data operators to immediately report all cyberattacks and data breaches to relevant authorities.observed
  5. ConfirmedOneTrust DataGuidance — Federal Law No. 420-FZ (30 November 2024) introduces administrative fines specifically for an operator's failure to notify Roskomnadzor of a personal data breach, effective 180 days after publication.observed
  6. ConfirmedRoskomnadzor — Operators must destroy personal data within seven working days where a data subject demonstrates the data were unlawfully obtained or are no longer required for the stated processing purpose, and must notify third parties to whom the data were transferred.observed

#

The localisation mandate is materially stricter than GDPR-style regimes, enforcement includes website-blocking, no SCC/BCR safe harbour exists, and the sanctions overlay adds acute cross-border compliance risk — collectively warranting a red rating per the CAUTION flags.

Primary frameworkFederal Law No. 152-FZ 'On Personal Data' (localisation provisions); Code of Administrative Offences Art. 13.11
Supervisory authorityRoskomnadzor
Traffic-light rationale — RedThe localisation mandate is materially stricter than GDPR-style regimes, enforcement includes website-blocking, no SCC/BCR safe harbour exists, and the sanctions overlay adds acute cross-border compliance risk — collectively warranting a red rating per the CAUTION flags.

Sub-modules (6)

Transfer MechanismsAmber

Cross-border transfer notification (including intended transfer and database location) must be declared to Roskomnadzor as part of operator registration.

Claims (1):

  • Operators intending cross-border transfer of personal data must indicate this intention, along with the physical location of their databases, in their notification to Roskomnadzor, which uses this information to audit localisation compliance.

Adequacy ReceivedRed

No adequacy determination has been identified as received by Russia from other regimes (e.g., no EU adequacy decision for Russia exists).

Absence provenance: unavailable. Searched: E, U, , a, d, e, q, u, a, c, y, , d, e, c, i, s, i, o, n, , R, u, s, s, i, a, , G, D, P, R, , A, r, t, i, c, l, e, , 4, 5.

Adequacy GrantedAmber

Roskomnadzor maintains its own assessed list of 'adequate' countries (including Japan, South Korea, Canada, Australia, New Zealand) against Convention 108 criteria; the US is notably excluded.

Claims (2):

  • Roskomnadzor assesses whether third countries' laws and data-security measures correspond to Council of Europe Convention 108 and its Protocol, and has recognised countries including Japan and South Korea as providing an adequate level of protection.
  • Roskomnadzor has approved a list of 23 'white-listed' countries deemed to have an adequate level of data protection, including Canada, New Zealand and Australia, while notably excluding the United States.

Sccs And BcrsRed

The Law on Personal Data contains no concept of appropriate safeguards for cross-border transfer analogous to SCCs, BCRs or approved codes of conduct.

Claims (1):

  • The Law on Personal Data does not contain any concept of appropriate safeguards applicable to cross-border transfers, such as Standard Contractual Clauses, Binding Corporate Rules, or an approved code of conduct.

Transfer Impact AssessmentRed

No formal TIA methodology equivalent to post-Schrems II EU practice was identified; transfer risk is instead managed informally by practitioners (e.g., via encryption architecture proposals).

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , t, r, a, n, s, f, e, r, , i, m, p, a, c, t, , a, s, s, e, s, s, m, e, n, t, , m, e, t, h, o, d, o, l, o, g, y, , c, r, o, s, s, -, b, o, r, d, e, r.

Data LocalisationRed

Mandatory localisation since September 2015 with escalating fines and website-blocking enforcement is the defining and materially stricter feature of the Russian regime.

Claims (3):

  • Since September 2015, Russian personal data law has required operators to record, systemise, accumulate, store, clarify and extract personal data of Russian citizens using databases physically located within the Russian Federation.
  • Non-compliance with the localisation requirement carries fines of RUB 1,000,000 to 6,000,000 on a company for a first offence and RUB 6,000,000 to 18,000,000 for repeat offences, with responsible managers separately liable for RUB 100,000-800,000.
  • Roskomnadzor guidance requires that the Russia-based database at all times contain data current with or exceeding any mirrored database held abroad, precluding write-first-abroad architectures.
Category narrative140 words

Russia operates one of the strictest data-localisation regimes among comprehensively-regulated jurisdictions: since September 2015, personal data of Russian citizens must first be recorded/stored on databases physically located in Russia, with Roskomnadzor requiring that the Russia-based database at all times hold data current with or ahead of any mirrored foreign database. Non-compliance carries escalating fines (RUB 1-6 million first offence; RUB 6-18 million repeat) plus separate liability for responsible managers, and Roskomnadzor retains power to block non-compliant websites (e.g., LinkedIn, blocked since 2016). No SCC/BCR-equivalent safeguard mechanism exists; transfers instead rely on a Roskomnadzor-assessed 'adequate' country list (including Japan, South Korea and a broader 23-country whitelist covering Canada, Australia and New Zealand, but excluding the US) informed by Council of Europe Convention 108. Any cross-border data-sharing analysis must additionally be read against applicable international sanctions regimes affecting Russia-linked counterparties and infrastructure.

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

Federal Law No. 242-FZ requires that personal data of Russian citizens be initially recorded, stored and processed in databases located within the Russian Federation -- a data-localisation requirement materially stricter than most GDPR-style adequacy-based transfer regimes. A 2025 amendment, Federal Law No. 23-FZ, is reported to have further tightened this localisation requirement, though the precise operational content of that tightening has not been independently confirmed against a primary source this cycle. Cross-border transfers outside the localisation requirement are otherwise understood to remain permitted to Strasbourg Convention states and to jurisdictions Roskomnadzor has separately approved, functioning as Russia's rough analogue to an adequacy mechanism, albeit one with a materially different legal basis and narrower footprint than the EU adequacy-decision framework.

Outlook

Whether Roskomnadzor's updated guidance operationalising the 2025 tightening amendment (23-FZ) is published remains an open gap; its absence this cycle limits confidence in exactly how the tightened localisation requirement will be applied in practice.

Sources and claims (7)
  1. ConfirmedIAPP — Operators intending cross-border transfer of personal data must indicate this intention, along with the physical location of their databases, in their notification to Roskomnadzor, which uses this information to audit localisation compliance.observed
  2. ConfirmedOneTrust DataGuidance — Roskomnadzor assesses whether third countries' laws and data-security measures correspond to Council of Europe Convention 108 and its Protocol, and has recognised countries including Japan and South Korea as providing an adequate level of protection.observed
  3. ConfirmedIAPP — Roskomnadzor has approved a list of 23 'white-listed' countries deemed to have an adequate level of data protection, including Canada, New Zealand and Australia, while notably excluding the United States.observed
  4. ConfirmedOneTrust DataGuidance — The Law on Personal Data does not contain any concept of appropriate safeguards applicable to cross-border transfers, such as Standard Contractual Clauses, Binding Corporate Rules, or an approved code of conduct.observed
  5. ConfirmedIAPP — Since September 2015, Russian personal data law has required operators to record, systemise, accumulate, store, clarify and extract personal data of Russian citizens using databases physically located within the Russian Federation.observed
  6. ConfirmedIAPP — Non-compliance with the localisation requirement carries fines of RUB 1,000,000 to 6,000,000 on a company for a first offence and RUB 6,000,000 to 18,000,000 for repeat offences, with responsible managers separately liable for RUB 100,000-800,000.observed
  7. ProbableIAPP — Roskomnadzor guidance requires that the Russia-based database at all times contain data current with or exceeding any mirrored database held abroad, precluding write-first-abroad architectures.observed

#

Telecoms and employment overlays are reasonably evidenced; financial-sector biometric rules remain at draft stage; health, education, insurance and credit-scoring overlays are unevidenced gaps.

Primary frameworkFederal Law No. 152-FZ 'On Personal Data'; Federal Law 'On Communications'; Yarovaya-package amendments
Supervisory authorityRoskomnadzor
Traffic-light rationale — AmberTelecoms and employment overlays are reasonably evidenced; financial-sector biometric rules remain at draft stage; health, education, insurance and credit-scoring overlays are unevidenced gaps.

Sub-modules (7)

Financial Sector OverlayAmber

2022 draft amendments addressed credit-institution collection of biometric personal data and remote biometric identification via the Unified Biometric System; final enactment status not confirmed.

Claims (1):

  • Draft 2022 amendments address the collection of biometric personal data and remote biometric identification by credit institutions via Russia's Unified Biometric System.

Health Sector OverlayRed

No health-sector-specific personal data overlay was identified in this research pass.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , h, e, a, l, t, h, , s, e, c, t, o, r, , p, e, r, s, o, n, a, l, , d, a, t, a, , l, a, w, , m, e, d, i, c, a, l, , r, e, c, o, r, d, s, , o, v, e, r, l, a, y.

Telecoms And EprivacyAmber

Communications providers face traffic-retention/disclosure duties under the Yarovaya package, and mobile advertising requires prior subscriber consent under the Law on Communications.

Claims (2):

  • Under Russia's 'Yarovaya package', telecommunications and internet-communications providers must store transmitted traffic content for a defined period and disclose it to Russian law-enforcement agencies upon request.
  • Under the Law on Communications, advertising messages sent via mobile networks require the prior consent of the subscriber, and mobile operators must maintain technical means to verify such consent and cease distribution from a given sender upon subscriber request.

Employment DataAmber

Notification to Roskomnadzor is not required for employee-data processing strictly for labour-law compliance, though this exemption is interpreted narrowly and excludes third-party transfers.

Claims (1):

  • Notification to Roskomnadzor of personal data processing is not required for employee-data processing undertaken solely for compliance with Russian labour law, though this exception is interpreted narrowly and does not extend to data transferred to third parties such as accounting firms.

Credit And ScoringRed

No dedicated credit-scoring personal-data overlay was identified beyond general biometric/financial-sector provisions.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , c, r, e, d, i, t, , s, c, o, r, i, n, g, , p, e, r, s, o, n, a, l, , d, a, t, a, , r, e, g, u, l, a, t, i, o, n.

EducationRed

No education-sector-specific personal data overlay was identified.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , e, d, u, c, a, t, i, o, n, , s, e, c, t, o, r, , p, e, r, s, o, n, a, l, , d, a, t, a, , s, t, u, d, e, n, t, , r, e, c, o, r, d, s, , l, a, w.

InsuranceRed

No insurance-sector-specific personal data overlay was identified.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , i, n, s, u, r, a, n, c, e, , s, e, c, t, o, r, , p, e, r, s, o, n, a, l, , d, a, t, a, , o, v, e, r, l, a, y.

Category narrative68 words

Sectoral overlays are unevenly documented. Financial-sector biometric-collection rules for credit institutions were in draft/amendment stage as of 2022. Telecoms carry a distinctive dual overlay: mobile-advertising consent rules under the Law on Communications, and mandatory traffic-retention/disclosure duties to law enforcement under the 'Yarovaya package'. Employment data processing benefits from a narrowly-construed notification exemption. Health, education, insurance and credit-scoring sector-specific personal-data overlays were not substantively evidenced in this research pass.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. UncertainOneTrust DataGuidance — Draft 2022 amendments address the collection of biometric personal data and remote biometric identification by credit institutions via Russia's Unified Biometric System.observed
  2. ConfirmedIAPP — Under Russia's 'Yarovaya package', telecommunications and internet-communications providers must store transmitted traffic content for a defined period and disclose it to Russian law-enforcement agencies upon request.observed
  3. ConfirmedOneTrust DataGuidance — Under the Law on Communications, advertising messages sent via mobile networks require the prior consent of the subscriber, and mobile operators must maintain technical means to verify such consent and cease distribution from a given sender upon subscriber request.observed
  4. ConfirmedIAPP — Notification to Roskomnadzor of personal data processing is not required for employee-data processing undertaken solely for compliance with Russian labour law, though this exception is interpreted narrowly and does not extend to data transferred to third parties such as accounting firms.observed

#

Direct marketing enforcement is reasonably well evidenced under a distinct sectoral regulator (FAS Russia); cookie-consent, dark-pattern, opt-out-signal and clean-room concepts are unevidenced gaps.

Primary frameworkFederal Law No. 38-FZ 'On Advertising' (13 March 2006); Federal Law 'On Communications' Art. 44.1
Supervisory authorityRoskomnadzor
Traffic-light rationale — AmberDirect marketing enforcement is reasonably well evidenced under a distinct sectoral regulator (FAS Russia); cookie-consent, dark-pattern, opt-out-signal and clean-room concepts are unevidenced gaps.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent regime analogous to EU ePrivacy was identified for Russia.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , c, o, o, k, i, e, , c, o, n, s, e, n, t, , l, a, w, , t, r, a, c, k, e, r, , r, e, g, u, l, a, t, i, o, n.

Dark PatternsRed

No dark-pattern-specific prohibition was identified in Russian consumer or data-protection law.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , d, a, r, k, , p, a, t, t, e, r, n, s, , c, o, n, s, u, m, e, r, , p, r, o, t, e, c, t, i, o, n, , o, n, l, i, n, e, , i, n, t, e, r, f, a, c, e, , l, a, w.

Opt Out SignalsRed

No recognition of browser-based opt-out signals (e.g., Global Privacy Control) was identified.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , G, l, o, b, a, l, , P, r, i, v, a, c, y, , C, o, n, t, r, o, l, , o, p, t, -, o, u, t, , s, i, g, n, a, l, , r, e, c, o, g, n, i, t, i, o, n.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room-specific rules were identified.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , d, a, t, a, , c, l, e, a, n, , r, o, o, m, , d, a, t, a, , c, o, l, l, a, b, o, r, a, t, i, o, n, , r, o, o, m, , r, e, g, u, l, a, t, i, o, n.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context-advertising concept was identified in Russian law.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , c, r, o, s, s, -, c, o, n, t, e, x, t, , b, e, h, a, v, i, o, u, r, a, l, , a, d, v, e, r, t, i, s, i, n, g, , s, a, l, e, , s, h, a, r, e, , c, o, n, c, e, p, t.

Direct MarketingAmber

FAS Russia enforces consent-based direct-marketing rules under the Law on Advertising and the Law on Communications, with a 2025 amendment adding platform-level restrictions tied to 'undesirable' foreign resources.

Claims (3):

  • FAS Russia enforces Article 18 of the Law on Advertising against unsolicited direct-marketing communications sent without the recipient's prior consent, though it lacks independent capability to establish violations of unsolicited messaging without a complainant-supplied evidentiary record.
  • In September 2021, Moscow FAS found a subsidiary of Estée Lauder in violation of Article 18 of the Advertising Law for distributing marketing messages without consent and failing to act on an opt-out request, ordering cessation and exposing the company to a fine of up to RUB 500,000.
  • A 2025 amendment to Russia's Law on Advertising prohibits advertising on platforms designated as 'undesirable' foreign resources or liquidated associations, effective 1 September 2025.
Category narrative82 words

Direct marketing is the best-evidenced adtech sub-area: Article 18 of the Law on Advertising, enforced by the Federal Antimonopoly Service (FAS Russia, a distinct authority from Roskomnadzor), requires prior consent for unsolicited communications, though FAS enforcement capacity depends heavily on subscriber complaints. A 2025 amendment further restricts advertising on platforms designated as 'undesirable' foreign resources. Cookie/tracker-specific consent rules, dark-pattern prohibitions, opt-out signal recognition (e.g., GPC), and clean-room/data-collaboration rules analogous to EU ePrivacy or US state frameworks were not identified in Russian law.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidance — FAS Russia enforces Article 18 of the Law on Advertising against unsolicited direct-marketing communications sent without the recipient's prior consent, though it lacks independent capability to establish violations of unsolicited messaging without a complainant-supplied evidentiary record.observed
  2. ConfirmedOneTrust DataGuidance — In September 2021, Moscow FAS found a subsidiary of Estée Lauder in violation of Article 18 of the Advertising Law for distributing marketing messages without consent and failing to act on an opt-out request, ordering cessation and exposing the company to a fine of up to RUB 500,000.observed
  3. ProbableOneTrust DataGuidance — A 2025 amendment to Russia's Law on Advertising prohibits advertising on platforms designated as 'undesirable' foreign resources or liquidated associations, effective 1 September 2025.observed

#

The combination of an expansive, weakly-constrained state-surveillance/data-retention regime and the absence of any profiling, ADM-transparency, AI-risk-assessment or genetic-data framework warrants a red rating.

Primary frameworkFederal Law No. 152-FZ 'On Personal Data'; Code of Administrative Offences as amended by Federal Law No. 420-FZ (2024); Yarovaya-package communications-retention amendments
Supervisory authorityRoskomnadzor
Traffic-light rationale — RedThe combination of an expansive, weakly-constrained state-surveillance/data-retention regime and the absence of any profiling, ADM-transparency, AI-risk-assessment or genetic-data framework warrants a red rating.

Sub-modules (6)

Profiling RestrictionsRed

No GDPR Article 22-style profiling restriction was identified in Russian law.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , 1, 5, 2, -, F, Z, , p, r, o, f, i, l, i, n, g, , r, e, s, t, r, i, c, t, i, o, n, , a, u, t, o, m, a, t, e, d, , d, e, c, i, s, i, o, n, -, m, a, k, i, n, g.

Automated Decision Making TransparencyRed

No ADM-transparency or explanation-right provision analogous to GDPR Article 22 was identified.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , a, u, t, o, m, a, t, e, d, , d, e, c, i, s, i, o, n, , m, a, k, i, n, g, , t, r, a, n, s, p, a, r, e, n, c, y, , e, x, p, l, a, n, a, t, i, o, n, , r, i, g, h, t, , l, a, w.

Ai Risk AssessmentsRed

No AI-specific risk-assessment statute or state-level AI-transparency law analogous to the EU AI Act was identified for Russia.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , A, I, , A, c, t, , r, i, s, k, , a, s, s, e, s, s, m, e, n, t, , l, a, w, , a, r, t, i, f, i, c, i, a, l, , i, n, t, e, l, l, i, g, e, n, c, e, , r, e, g, u, l, a, t, i, o, n, , 2, 0, 2, 5, , 2, 0, 2, 6.

Biometric RegimeAmber

2024 amendments impose fines for unauthorised biometric-data disclosure; a Unified Biometric System framework (partly still in draft as of the credit-institution provisions) governs biometric collection and remote identification.

Claims (2):

  • Federal Law No. 420-FZ (2024) creates specific administrative fines for unauthorized disclosure of biometric data and for violations of consumer rights connected to biometric identification and authentication.
  • Draft amendments concerning the Unified Biometric System enable authorised access to state, municipal and other information systems via a unified identification and authentication system that processes, collects and stores biometric personal data of State Services users.

Genetic DataRed

No genetic-data-specific regime was identified in the sources reviewed.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , g, e, n, e, t, i, c, , d, a, t, a, , p, e, r, s, o, n, a, l, , d, a, t, a, , l, a, w, , r, e, g, u, l, a, t, i, o, n.

State Surveillance CarveoutsRed

The Yarovaya package imposes expansive traffic-retention and law-enforcement-disclosure duties on communications providers; external legal commentary assesses Russian investigations law as falling short of EU 'essential guarantees' standards.

Claims (2):

  • Under the 'Yarovaya package', communications providers must store transmitted traffic and disclose it to law-enforcement agencies upon request, a data-retention and access regime materially more expansive than typical GDPR-style national-security carve-outs.
  • External legal commentary assesses that Russian investigations law does not fully meet the level of guarantees required under the EU's 'European Essential Guarantees' framework, a factor relevant to GDPR transfer-risk assessments involving Russia.
Category narrative79 words

Biometric-data governance is the most developed sub-area, with 2024 fines targeting unauthorised biometric-data disclosure and a Unified Biometric System framework for state and (in draft form) credit-institution biometric collection. State-surveillance access is comparatively expansive: the 'Yarovaya package' mandates telecoms/internet traffic retention and law-enforcement disclosure, and Russian investigations law has been assessed by external commentary as not meeting the EU's 'European Essential Guarantees' standard. No Article-22-style profiling or automated-decision-making transparency regime, AI-specific risk-assessment statute, or dedicated genetic-data regime was identified.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedOneTrust DataGuidance — Federal Law No. 420-FZ (2024) creates specific administrative fines for unauthorized disclosure of biometric data and for violations of consumer rights connected to biometric identification and authentication.observed
  2. UncertainOneTrust DataGuidance — Draft amendments concerning the Unified Biometric System enable authorised access to state, municipal and other information systems via a unified identification and authentication system that processes, collects and stores biometric personal data of State Services users.observed
  3. ConfirmedIAPP — Under the 'Yarovaya package', communications providers must store transmitted traffic and disclose it to law-enforcement agencies upon request, a data-retention and access regime materially more expansive than typical GDPR-style national-security carve-outs.observed
  4. ProbableIAPP — External legal commentary assesses that Russian investigations law does not fully meet the level of guarantees required under the EU's 'European Essential Guarantees' framework, a factor relevant to GDPR transfer-risk assessments involving Russia.observed

#

No comprehensive children/vulnerable-groups provisions within the personal-data framework were located; this is an explicit, fully-scoped evidentiary gap rather than a silent omission.

Supervisory authorityRoskomnadzor
Traffic-light rationale — Not assessedNo comprehensive children/vulnerable-groups provisions within the personal-data framework were located; this is an explicit, fully-scoped evidentiary gap rather than a silent omission.

Sub-modules (5)

Age VerificationRed

No age-verification requirement specific to personal-data processing was identified.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , 1, 5, 2, -, F, Z, , a, g, e, , v, e, r, i, f, i, c, a, t, i, o, n, , m, i, n, o, r, s, , o, n, l, i, n, e.

Minor Profiling BansRed

No minor-specific profiling ban was identified.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , m, i, n, o, r, s, , p, r, o, f, i, l, i, n, g, , b, a, n, , p, e, r, s, o, n, a, l, , d, a, t, a.

Education SettingsRed

No education-setting-specific personal-data rule for minors was identified.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , e, d, u, c, a, t, i, o, n, , s, e, t, t, i, n, g, s, , s, t, u, d, e, n, t, , d, a, t, a, , m, i, n, o, r, s, , l, a, w.

Dependent AdultsRed

No dependent-adult-specific personal-data protection was identified.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, s, , e, l, d, e, r, l, y, , i, n, c, a, p, a, c, i, t, a, t, e, d, , p, e, r, s, o, n, a, l, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n.

Category narrative48 words

No GDPR Article 8-style age-of-consent threshold, parental-consent mechanism, minor-profiling ban, education-setting-specific rule, or dependent-adult protection specific to personal-data processing was identified for Russia in this research pass. General civil-law capacity rules (age of majority) may bear on contractual consent capacity, but no personal-data-specific minor/vulnerable-group framework was substantively evidenced.

#

Regulator powers, penalty ceilings and website-blocking sanctions are well evidenced; regulator funding/capacity, standalone private-right-of-action mechanisms, and confirmed within-180-day developments are gaps.

Primary frameworkCode of Administrative Offences (Federal Law No. 195-FZ), Article 13.11, as amended; Federal Law No. 152-FZ Article 23
Supervisory authorityRoskomnadzor
Traffic-light rationale — AmberRegulator powers, penalty ceilings and website-blocking sanctions are well evidenced; regulator funding/capacity, standalone private-right-of-action mechanisms, and confirmed within-180-day developments are gaps.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Roskomnadzor can order rectification/blocking/destruction of data, suspend unlawful processing, refer cases to court, and block non-compliant websites; the maximum single fine is RUB 18 million.

Claims (3):

  • The maximum single administrative fine for violation of the Law on Personal Data under the Code of Administrative Offences is RUB 18 million (approximately €260,000), substantially lower than the GDPR's maximum penalty of up to €20 million or 4% of global annual turnover.
  • Roskomnadzor may request operators to rectify, block or remove incorrect or illegally obtained personal data, and may take measures to suspend or terminate unlawful personal data processing.
  • Roskomnadzor retains the power to block access to a non-compliant company's website, a distinctive enforcement sanction exemplified by the blocking of LinkedIn in Russia since 2016 over data-localisation non-compliance.

Enforcement Activity IndexAmber

Documented enforcement includes the LinkedIn website block (since 2016) and ongoing compliance demands to Twitter/Facebook on localisation; granular last-12-months enforcement statistics were not retrieved.

Absence provenance: unavailable. Searched: R, o, s, k, o, m, n, a, d, z, o, r, , e, n, f, o, r, c, e, m, e, n, t, , a, c, t, i, o, n, s, , f, i, n, e, s, , 2, 0, 2, 5, , 2, 0, 2, 6, , p, e, r, s, o, n, a, l, , d, a, t, a.

Claims (1):

  • Roskomnadzor has demanded compliance answers from Twitter and Facebook regarding data-localisation, described as an ongoing enforcement matter in recent reporting.

Regulator Funding And CapacityRed

No Roskomnadzor personal-data-department funding or headcount data was located; FAS Russia separately noted limited independent investigative capacity for direct-marketing complaints, a proxy data point for sectoral (not DP-regulator) capacity.

Absence provenance: unavailable. Searched: R, o, s, k, o, m, n, a, d, z, o, r, , p, e, r, s, o, n, a, l, , d, a, t, a, , d, e, p, a, r, t, m, e, n, t, , b, u, d, g, e, t, , h, e, a, d, c, o, u, n, t, , f, u, n, d, i, n, g, , c, a, p, a, c, i, t, y.

Collective Redress And Class ActionsAmber

Roskomnadzor may file lawsuits seeking protection of personal data subjects' rights, including protection of the rights of the general public.

Claims (1):

  • Roskomnadzor is empowered to file lawsuits in Russian courts seeking protection of personal data subjects' rights, including protection of the rights of the general public.

Private Right Of ActionRed

No standalone statutory private-right-of-action mechanism independent of Roskomnadzor-mediated enforcement was substantively confirmed.

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , p, r, i, v, a, t, e, , r, i, g, h, t, , o, f, , a, c, t, i, o, n, , p, e, r, s, o, n, a, l, , d, a, t, a, , d, i, r, e, c, t, , c, o, u, r, t, , a, c, c, e, s, s.

Recent Developments 180DAmber

No new legislative, case-law, guidance or adequacy development strictly within the 180 days preceding the 2026-08-07 dispatch date was located; the most recent substantive change remains Federal Law No. 420-FZ (Nov 2024, effective ~May 2025).

Absence provenance: unavailable. Searched: R, u, s, s, i, a, , p, e, r, s, o, n, a, l, , d, a, t, a, , l, a, w, , a, m, e, n, d, m, e, n, t, , F, e, b, r, u, a, r, y, -, A, u, g, u, s, t, , 2, 0, 2, 6, , R, o, s, k, o, m, n, a, d, z, o, r.

Claims (1):

  • Federal Law No. 420-FZ, published 30 November 2024, amends the Code of Administrative Offences to introduce new fines for unauthorized disclosure of personal and biometric data and for failure to notify Roskomnadzor of breaches, entering into force 180 days after publication.
Category narrative120 words

Roskomnadzor holds broad investigative and remedial powers (rectify/block/destroy orders, processing-suspension orders, court referral, and website-blocking), with the maximum single administrative fine under the Code of Administrative Offences set at RUB 18 million (~€260,000) — materially lower than GDPR's maximum. Roskomnadzor may also litigate on behalf of data subjects, including collectively. The most recent substantive legislative development identified is Federal Law No. 420-FZ (30 November 2024, effective ~29 May 2025), which post-dates the strict 180-day recency window from the 2026-08-07 dispatch date but remains the most recent operative enforcement-relevant change found; no new legislative or enforcement development strictly within the last 180 days was located. Regulator funding/headcount data and an explicit private-right-of-action mechanism (independent of Roskomnadzor-mediated litigation) were not substantively evidenced.

Periodic update · new data 2026-09-28

Enforcement & Redress

Roskomnadzor holds the power to order suspension of data-processing activities and to order website blocking against non-compliant operators. Administrative fines for data-localisation violations are reported to range from ₽1-6 million for a first offence to ₽6-18 million for a repeat offence. Separately, penalties for repeated data leaks are reported to have been raised to up to 3 percent of annual turnover under a 2025 amendment (Federal Law No. 420-FZ), and Federal Law No. 421-FZ is reported to have introduced criminal liability of up to 10 years' imprisonment for illegal personal-data trafficking. Together these represent a marked escalation in the enforcement posture available to Roskomnadzor, moving from fixed administrative-fine bands toward turnover-based penalties and criminal exposure. All of the specific figures above are drawn from secondary vendor and compliance-database sourcing; no rkn.gov.ru primary text for either 420-FZ or 421-FZ was retrieved this cycle, so confidence on the precise figures is held at Uncertain even though the general direction of escalation is corroborated across multiple independent secondary sources.

Outlook

Retrieval of primary statutory text for 420-FZ and 421-FZ remains the key outstanding item for this module; until then, the figures reported here should be treated as indicative rather than confirmed.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidance — The maximum single administrative fine for violation of the Law on Personal Data under the Code of Administrative Offences is RUB 18 million (approximately €260,000), substantially lower than the GDPR's maximum penalty of up to €20 million or 4% of global annual turnover.observed
  2. ConfirmedRoskomnadzor — Roskomnadzor may request operators to rectify, block or remove incorrect or illegally obtained personal data, and may take measures to suspend or terminate unlawful personal data processing.observed
  3. ConfirmedIAPP — Roskomnadzor retains the power to block access to a non-compliant company's website, a distinctive enforcement sanction exemplified by the blocking of LinkedIn in Russia since 2016 over data-localisation non-compliance.observed
  4. ProbableIAPP — Roskomnadzor has demanded compliance answers from Twitter and Facebook regarding data-localisation, described as an ongoing enforcement matter in recent reporting.observed
  5. ConfirmedRoskomnadzor — Roskomnadzor is empowered to file lawsuits in Russian courts seeking protection of personal data subjects' rights, including protection of the rights of the general public.observed
  6. ConfirmedOneTrust DataGuidance — Federal Law No. 420-FZ, published 30 November 2024, amends the Code of Administrative Offences to introduce new fines for unauthorized disclosure of personal and biometric data and for failure to notify Roskomnadzor of breaches, entering into force 180 days after publication.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct18.52
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Russia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s) (44 category placement(s)), 29 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy granted
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

T1 primary-source coverage (rkn.gov.ru / pd.rkn.gov.ru / eng.rkn.gov.ru statutory text and official regulator statements) was obtained for regulator_and_framework, core data_subject_rights (access/erasure/deadlines), and enforcement powers within enforcement_and_redress. Controller_processor_duties (DPO, breach notification, retention) and cross_border_and_adequacy (localisation, adequacy list, SCC/BCR absence) rely primarily on T2 (DataGuidance) and T3 (IAPP) secondary analysis of the same underlying 152-FZ text and its 2020-2024 amendments, cross-checked across multiple independent secondary sources for consistency. Sectoral_watch and adtech_and_commercial_privacy achieved partial T1/T2 coverage only for telecoms, employment and direct-marketing sub-modules (via Law on Communications/Law on Advertising primary provisions cited in T2 analysis); health, education, insurance, credit-scoring, cookies/trackers, dark patterns, opt-out signals and clean-room sub-modules returned no results and are recorded as explicit gaps. Algorithmic_biometric_and_surveillance_governance achieved T2/T3 coverage for biometric-data fines and state-surveillance traffic-retention duties, but profiling, ADM-transparency, AI-risk-assessment and genetic-data sub-modules are explicit gaps. Children_and_vulnerable_groups returned no substantive results across all five sub-modules and is recorded as a fully-scoped gap module per GAP DISCIPLINE.

Unresolved questions (6):

  • Did the 2022 first-reading Duma bill's extraterritoriality-extension and mandatory pre-transfer-notification provisions ultimately pass into force, and if so on what effective date?
  • Was the 2022 draft amendment on credit-institution biometric collection via the Unified Biometric System finalised and brought into force, and under what statute number?
  • Does any Russian instrument establish a GDPR Article 8-style minor age-of-consent threshold or parental-consent mechanism for personal-data processing specifically (as opposed to general civil-law contractual capacity)?
  • What is Roskomnadzor's current personal-data-department headcount/budget, and has enforcement activity in the 2025-2026 period (fines, site-blocking orders) been compiled into a comparable index to the 2021-2022 precedents identified?
  • Is there a standalone private right of action for Russian data subjects independent of Roskomnadzor-mediated litigation, and if so under which civil-procedure provision?
  • What is the current in-force status and precise citation of the Yarovaya-package traffic-retention statute (exact federal law number/date) as it applies to data-protection-relevant surveillance carve-outs?

Escalate to primary-source review: yes