WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Europe

Russia Privacy & Data Protection Laws

Every regime below can apply to a business handling Russia residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

January 26, 2007; localization requirement in force since September 1, 2015
Federal Law No. 152-FZ on Personal Data
Russian Data Protection Law (152-FZ)
Verify details

Applies to processing by entities in Russia and, as applied by the regulator (Roskomnadzor), to foreign entities whose websites or services are directed at Russian territory (Russian-language interfaces, ruble pricing, .ru domains, Russia-targeted advertising). The defining obligation is data localization: personal data of Russian citizens must be recorded, systematized, accumulated, stored, amended, and retrieved using databases physically located in Russia — a primary-copy requirement, so cross-border transfer is permitted only after the Russian database is populated first. Cross-border transfers additionally require prior notification to Roskomnadzor, which can suspend them. Federal Law No. 420-FZ (signed November 30, 2024, penalties effective from 2025) introduced turnover-based administrative fines for data leaks and criminal liability for the illegal handling of personal data. Sanctions-related restrictions may independently affect whether a foreign business can lawfully operate here at all — a separate question from data-protection compliance.

Federal Law No. 152-FZ of July 27, 2006, as amended; data-localization duty added by Federal Law No. 242-FZ; penalties amended by Federal Law No. 420-FZ of Nov 30, 2024Read regulation →

Cross-Border Data Transfer · 1

March 1, 2023 (the notification and assessment regime added by Law No. 266-FZ)
Federal Law No. 152-FZ on Personal Data — cross-border transfer of personal data
152-FZ Art. 12
Verify details

Since March 1, 2023 Russia has required a FILING BEFORE THE FIRST TRANSFER, which is what distinguishes it from the adequacy-and-safeguards model used almost everywhere else here. The operator must notify Roskomnadzor of its intention to transfer personal data abroad — stating its name and address, the reference of its existing processing notification, its data protection officer, and the legal basis and purpose of the transfer and of the further processing — and must separately assess the protection available in the destination, obtaining information from the foreign recipient about how it will handle the data. States party to Council of Europe Convention 108, plus those on the list approved by Roskomnadzor Order No. 128 of August 5, 2022, are treated as providing adequate protection. Roskomnadzor can prohibit or restrict a transfer. Read this together with the separate and usually harder constraint noted in the comprehensive-law entry: Art. 18(5) requires that Russians' personal data be recorded and stored in databases located in Russia in the first place, so a lawful outbound transfer does not remove the localisation duty. Marked 'check': the primary text is Russian-language and the procedure was triangulated across independent legal-reference sources.

Federal Law No. 152-FZ, Art. 12, as amended by Federal Law No. 266-FZ of July 14, 2022; Roskomnadzor Order No. 128 of August 5, 2022 (list of foreign states providing adequate protection)Read regulation →

Data Security & Breach Notification · 1

September 1, 2022 (the notification duty added by Law No. 266-FZ)
Federal Law No. 152-FZ on Personal Data — incident notification to Roskomnadzor
152-FZ breach notification
Verify details

Russia runs a two-stage clock that is materially tighter than the GDPR's at the front end: an initial notification to Roskomnadzor within 24 hours of detecting an incident involving unlawful or accidental transfer of personal data, stating the suspected cause, the likely harm, and the measures taken; then, within 72 hours, the results of the operator's internal investigation, including information about the persons whose actions caused the incident. Note this sits on top of Russia's separate data-localisation requirement (Art. 18(5)), which is usually the harder constraint for a foreign business. Marked 'check': the deadlines are consistently reported across independent legal-reference sources but the primary text is Russian-language only and the enforcement practice around what counts as 'detection' was not verified against a primary source.

Federal Law No. 152-FZ, Art. 21, as amended by Federal Law No. 266-FZ of July 14, 2022Read regulation →

Other Europe jurisdictions