Cross-Border Data Transfer
Federal Law No. 152-FZ on Personal Data — cross-border transfer of personal data
Russia · March 1, 2023 (the notification and assessment regime added by Law No. 266-FZ)
Verify detailsSince March 1, 2023 Russia has required a FILING BEFORE THE FIRST TRANSFER, which is what distinguishes it from the adequacy-and-safeguards model used almost everywhere else here. The operator must notify Roskomnadzor of its intention to transfer personal data abroad — stating its name and address, the reference of its existing processing notification, its data protection officer, and the legal basis and purpose of the transfer and of the further processing — and must separately assess the protection available in the destination, obtaining information from the foreign recipient about how it will handle the data. States party to Council of Europe Convention 108, plus those on the list approved by Roskomnadzor Order No. 128 of August 5, 2022, are treated as providing adequate protection. Roskomnadzor can prohibit or restrict a transfer. Read this together with the separate and usually harder constraint noted in the comprehensive-law entry: Art. 18(5) requires that Russians' personal data be recorded and stored in databases located in Russia in the first place, so a lawful outbound transfer does not remove the localisation duty. Marked 'check': the primary text is Russian-language and the procedure was triangulated across independent legal-reference sources.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.