Russia flag

Russia

Russia Data Privacy Laws: Federal Law 152-FZ, Penalties & 2025 Changes

By Recording Law Editorial TeamReviewed May 20, 202621 min read
Russia Data Privacy Laws: Federal Law 152-FZ, Penalties & 2025 Changes

Frequently Asked Questions

Does Russia's Federal Law 152-FZ apply to foreign companies?

Yes. The law applies to any entity that processes personal data of Russian citizens, regardless of where the entity is incorporated or hosted. Roskomnadzor uses several practical tests to determine whether a foreign entity targets Russian users: use of .ru or .su domains, Russian-language content or advertising, and acceptance of Russian currency. Non-compliant foreign operators risk having their websites blocked in Russia.

What are the data localization requirements and how have they changed in 2025?

Since September 2015, all operators must store personal data of Russian citizens in databases physically located in Russia. As of July 1, 2025, this obligation extends to processors acting on behalf of operators, and the initial collection of personal data through foreign-hosted infrastructure is expressly prohibited. Operators may still transfer copies of data abroad after complying with the cross-border transfer notification regime, but the primary database must remain on Russian territory.

What are the maximum penalties for data protection violations in Russia?

Administrative penalties for repeat large-scale breaches can reach 1 to 3 percent of annual revenue, capped at 500 million rubles (approximately USD 5.5 million), effective May 30, 2025. Biometric data breaches carry fixed fines of 15 to 20 million rubles per incident. On the criminal side, organized illegal data trafficking or offenses causing grave consequences carry imprisonment up to 10 years and fines up to 3 million rubles under Article 272.1 of the Criminal Code.

How quickly must a data breach be reported in Russia?

Operators must notify Roskomnadzor within 24 hours of discovering a breach. A full supplementary report must follow within 72 hours. Failure to meet the 24-hour deadline can result in additional fines of 1 to 3 million rubles for legal entities, on top of any penalties for the breach itself.

What is SORM and how does it affect privacy in Russia?

SORM is the FSB's mandatory interception infrastructure. All Russian telecoms and internet providers must install FSB-accessible hardware at their own expense. The FSB can access traffic in real time. Under the Yarovaya Law, operators must also retain communications content for 6 months and metadata for 3 years. SORM operates outside the consent framework of 152-FZ: state access does not require the data subject's consent and court oversight is extremely limited in practice.

Is consent always required to process personal data in Russia?

No. Consent is the most commonly used legal basis but 152-FZ recognizes five others: contract performance, legal obligation, vital interests, legitimate interests, and journalistic or scientific purposes. However, written consent is specifically required for processing special categories of data, biometric data, cross-border transfers to countries without adequacy status, and automated decision-making with legal effects.

What criminal offenses did Law 421-FZ create?

Federal Law No. 421-FZ (effective December 11, 2024) introduced Article 272.1 into the Russian Criminal Code, covering illegal collection, storage, use, transfer, and cross-border transfer of personal data. The base offense carries up to 4 years imprisonment. Aggravated cases involving minors or biometric data carry up to 5 years; cross-border unauthorized transfers carry up to 8 years; and organized criminal activity or grave consequences carry up to 10 years imprisonment with fines up to 3 million rubles.

Updates

Major expansion: added Federal Law 420-FZ penalty details (effective May 30 2025), 421-FZ criminal liability tiers, July 2025 localization tightening under Law 23-FZ, SORM/Yarovaya surveillance overlay, fine reduction conditions, and expanded compliance guidance.

Original publication covering 152-FZ framework, data localization, Roskomnadzor, breach notification, and cross-border transfers.

Sources and References

  1. Federal Law No. 152-FZ On Personal Data -- Roskomnadzor Official Registry(rkn.gov.ru).gov
  2. Russian Ministry of Digital Development, Communications and Mass Media(digital.gov.ru).gov
  3. Federal Law No. 242-FZ on Data Localization Requirements -- Duane Morris Analysis(duanemorris.com)
  4. Federal Law No. 23-FZ (February 2025) -- Tightened Localization Requirements Effective July 1 2025 -- Lidings(lidings.com)
  5. New Requirements for Localization of Personal Data in Russia: July 2025 Changes -- Konsu Group(konsugroup.com)
  6. Federal Law No. 420-FZ and 421-FZ: Criminal Liability and Fines Up to 500 Million Rubles -- Acsour(acsour.com)
  7. Increased Liability for Personal Data Violations -- Birch Legal Analysis of Laws 420-FZ and 421-FZ(birchlegal.ru)
  8. Federation Council Approved Laws Toughening Liability for Personal Data Violations -- Lidings(lidings.com)
  9. Cross-Border Transfer Notification Regime -- Konsu Group Step-by-Step Guide(konsugroup.com)
  10. Russia Adopts New Rules on Cross-Border Data Transfers -- Gorodissky and Partners(gorodissky.com)
  11. Data Protection Authority Registration and DPO Requirements -- Gorodissky and Partners(gorodissky.com)
  12. Russia: Basics of Biometric Data Processing and Protection -- Morgan Lewis(morganlewis.com)
  13. Russia: Freedom on the Net 2025 Country Report -- Freedom House(freedomhouse.org)
  14. Yarovaya Law and New Telecoms Data Storage Requirements -- Gorodissky and Partners(gorodissky.com)
  15. Russia: Harmonising Data Protection Laws with the EU -- Gorodissky and Partners(gorodissky.com)
Share: