Veltos.Tech

Business and process

Russian personal data law (152-FZ)

Also known as: personal data law Russia, data localisation Russia, personal data compliance

Definition

152-FZ is the Russian personal data law: it requires that data on Russian citizens be collected in databases located in Russia, that the regulator be notified of processing, that consent be obtained separately, and that any breach be reported within 24 hours.

Personal data means any information relating to an identified or identifiable individual. In practice that covers almost everything an ordinary website collects: a name and phone number in a request form, an email in a newsletter signup, a delivery address, order history, the content of a support enquiry, and under some readings the combination of identifiers that makes a person recognisable. A company collecting that is a personal data operator with all the resulting obligations, regardless of its size or whether it ever thought about it.

The key requirement for technical decisions is localisation. Collection, recording, organisation and storage of personal data on Russian citizens must use databases located in the Russian Federation. That directly constrains the stack and the infrastructure: foreign managed services are out for the primary database, so are several external analytics and marketing tools, and cross-border transfer, where it is needed at all, requires a separate notification to the regulator. Bringing a system into compliance after launch usually means data migration and a rewrite of the access layer, meaning months of work with no new user-facing functionality.

The organisational side is equally mandatory and cheaper than it looks. The operator files a processing notification with Roskomnadzor, publishes a processing policy, collects consent as a separate action rather than a tick box buried in general terms, appoints a responsible person, maintains an inventory of the data processed and defines retention periods. Incident response is a distinct obligation: a breach must be reported to the regulator within 24 hours of discovery, with the results of the internal investigation submitted within 72 hours.

The stakes have risen considerably. Since 30 May 2025 a revised liability regime for personal data violations has been in force: fixed fines are measured in millions of roubles, and a repeat breach carries a turnover-based fine of 1 to 3% of annual revenue with a floor of 20 million RUB. Criminal liability for unlawful handling of personal data exists separately. The practical conclusion for any project is that storage, access, logging and transfer questions get settled in the first week of development, not when a regulator’s request arrives.

Related terms

Related services

Read more

Need this done, not just defined?

We do this work, not only write about it. Describe the task and we will scope it and send a staged estimate.