Data protection in the Russian Federation: overview

A Q&A guide to data protection in the Russian Federation.

This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies.

To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool.

This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg.

Pavel Arievich, DLA Piper, Russia
Contents

Regulation

Legislation

1. What national laws regulate the collection and use of personal data?

General laws

Fundamental provisions of data protection law can be found in:

  • The Strasbourg Convention for the Protection of Individuals with Regard to Automatic Processing of Personal Data 1981 (Strasbourg Convention).

  • Articles 23 and 24 of the Russian Constitution, which establish the right to privacy for each individual.

There is also specific data protection legislation, including:

  • The Data Protection Act No. 152 FZ dated 27 July 2006 (DPA), and the various regulations implementing the DPA.

  • The Information, Information Technologies and Information Protection Act No. 149 FZ dated 27 July 2006, which establishes basic protection for information.

Sectoral laws

Part XIV of the Russian Labour Code contains provisions on the protection of employees' personal data. Other laws, which implement the provisions of DPA in relation to specific areas of state services or industries, may also contain data protection provisions.

Scope of legislation

2. To whom do the laws apply?

The laws apply to all natural and legal entities processing personal data in the Russian Federation. Russian laws do not distinguish between data "controllers" and "processors" and refer simply to processors.

Data processor is defined as "a state body, municipal body, legal or natural entity which alone or together with other persons organises and/or performs processing of personal data or defining the purposes of processing of personal data, types of personal data subject to processing and actions (operations) performed in relation to personal data".

 
3. What data is regulated?

All personal data is regulated, which includes any information that relates directly or indirectly to a specific or defined physical person and not a legal entity (data subject).

 
4. What acts are regulated?

All processing of personal data is regulated. This includes gathering, storing, blocking, deleting and transferring data.

 
5. What is the jurisdictional scope of the rules?

The rules apply to all actions taking place in the Russian Federation. If cross-border agreements involve the transfer of personal data from Russia abroad, personal data protection laws apply to both:

  • The Russian parties who undertake such transfer from Russia.

  • The cross-border agreements.

 
6. What are the main exemptions (if any)?

The processing of data by an individual for that individual's personal non-commercial needs is exempt from data protection law. There may be other exemptions subject to special laws (such as the state archive fund or national security).

Notification

7. Is notification or registration required before processing data?

A processor of personal data must notify the Federal Service for Supervision of Communications, Information Technologies and Mass Media (Roskomnadzor) before it begins to process personal data (see box, The regulatory authority). There are a few exemptions from this notification obligation (such as when an employer processes the personal data of its own employees without transferring the data to third parties).

The notification must contain:

  • The name of processor.

  • The type of data.

  • A description of the categories of data subjects.

  • The purposes of processing.

  • The timeframes of processing.

  • The description of IT systems of the processor.

 

Main data protection rules and principles

Main obligations and processing requirements

8. What are the main obligations imposed on data controllers to ensure data is processed properly?

Data processors must:

  • Obtain consent from data subjects before processing personal data.

  • Take appropriate technical and organisational measures against:

    • unauthorised or unlawful processing;

    • accidental loss, changing, blocking or destruction of, or damage to, personal data.

  • Notify Roskomnadzor of their activities involving personal data.

The regulations in this area are constantly being developed and changed. This creates a high degree of uncertainty and difficulty for the data processors in understanding and implementing the regulations.

 
9. Is the consent of data subjects required before processing personal data?

The consent of data subjects is required before processing personal data. Implied consent is not sufficient.

In a number of situations (such as cross-border transfers to unsecure jurisdictions or transfer of personal data), the law requires consent to be made in writing.

Electronic digital signatures are permissible when they comply with the 2002 law on Electronic Digital Signatures.

There is no prescribed form of consent.

 
10. If consent is not given, on what other grounds (if any) can processing be justified?

Processing without consent can be justified:

  • If it is necessary to perform a written contract with the data subject (that is, by implied consent).

  • On important public interest grounds.

  • By exemptions under special laws (such as laws governing statistics, archive activities, state services, and so on).

Special rules

11. Do special rules apply for certain types of personal data, such as sensitive data?

Sensitive personal data includes all information concerning a person's:

  • Health.

  • Private or intimate life.

  • Nationality.

  • Race.

  • Political, religious and philosophical views.

Sensitive data requires consent in written form before processing (subject to few exceptions, including for medical and state security purposes).

 

Rights of individuals

12. What information should be provided to data subjects at the point of collection of the personal data?

Consent must be informed, that is, the purpose and volume of data collected and processed must be disclosed to the individual at the point of data collection or beforehand.

 
13. What other specific rights are granted to data subjects?

Subjects are entitled to:

  • Require access to their personal data, and can request details of the data processing, including the:

    • types of data involved;

    • purposes of processing; and

    • name of the operator.

  • Demand the processor to discontinue processing their personal data (except where processing cannot be terminated or will result in other violations of Russian law).

 
14. Do data subjects have a right to request the deletion of their data?

Subjects can request the deletion of their data if that data is:

  • Wrong.

  • Unlawfully obtained.

  • Not necessary for the declared purpose of processing.

 

Security requirements

15. What security requirements are imposed in relation to personal data?

Data processors must take appropriate technical and organisational measures, although the regulations in this area are constantly being developed and changed (see Question 8).

 
16. Is there a requirement to notify personal data security breaches to data subjects or the national regulator?

There is no formal requirement to notify personal data security breaches to data subjects or Roskomnadzor. Notification is neither practised nor advisable.

 

Processing by third parties

17. What additional requirements (if any) apply where a third party processes the data on behalf of the data controller?

The data subject must give prior written consent to the transfer of data to third parties. Third parties are subject to the same requirements and obligations as data processers (see Questions 8 and 15).

 

Electronic communications

18. Under what conditions can data controllers store cookies or equivalent devices on the data subject's terminal equipment?

There is currently no specific regulation governing cookies, so no conditions are imposed on data controllers in practice.

 
19. What requirements are imposed on the sending of unsolicited electronic commercial communications (spam)?

Unsolicited electronic commercial communications are unlawful. Spam can only be lawfully sent after obtaining an individual's consent and must be stopped on his request.

 

International transfer of data

Transfer of data outside the jurisdiction

20. What rules regulate the transfer of data outside your jurisdiction?

The transfer of data outside Russia is subject to the same general limitations as for the processing of personal data (see Questions 3 to 19). Data can be transferred to Strasbourg Convention states or other states that ensure adequate protection of personal data without following additional requirements (unless this would be contrary to public order, state security, and so on). Data can only be transferred to other states ("unsecure" jurisdictions) on limited grounds, including the written consent of data subjects. There are currently no established guidelines concerning which states are unsecure.

Data transfer agreements

21. Are data transfer agreements contemplated or in use? Have any standard forms or precedents been approved by national authorities?

Data transfer agreements are in use, but they are not currently regulated. Roskomnadzor has not yet approved any standard forms.

 
22. Is a data transfer agreement sufficient to legitimise transfer, or must additional requirements (such as the need to obtain consent) be satisfied?

The consent of the data subject is required to transfer data to "unsecure" jurisdictions (see Question 20).

 
23. Does the relevant national regulator need to approve the data transfer agreement?

Roskomnadzor does not need to approve the data transfer agreement.

 

Enforcement and sanctions

24. What are the enforcement powers of the national regulator?

Roskomnadzor can:

  • Undertake inspections of personal data processes conducted by processors.

  • Impose orders to cure violations and issue administrative fines on violating parties (currently up to RUB10,000 (as at 1 June 2012, US$1 was about RUB33.1)).

  • In the most serious cases, apply to the relevant enforcement authorities to initiate criminal proceedings or suspend the violating company's business activity.

 
25. What are the sanctions and remedies for non-compliance with data protection laws?

See Question 24. Criminal sanctions are rarely applied in practice, but apply to the most serious violations (such as intentional dissemination of personal data), which are punishable by imprisonment for up to two years.

 

The regulatory authority

Federal Service for Supervision of Communications, Information Technologies and Mass Media (Roskomnadzor)

W www.rsoc.ru

Main areas of responsibility. Supervision of data processing, inspections, issuing regulations and guidelines, and accepting notifications on data processors.



Contributor details

Pavel Arievich

DLA Piper, Russia

T +7 495 221 4472
F +7 495 221 4401
E pavel.arievich@dlapiper.com
W www.dlapiper.com

Qualified. Russia, 2000; New York, US, 2001

Areas of practice. Intellectual property; trade marks; franchise law; data protection.

Recent transactions

  • Advising an international software company on data protection legal requirements and preparing necessary forms.
  • Advising a multinational IT company on data protection requirements.
  • Performing a data protection review for a major worldwide hotel operator.

{ "siteName" : "PLC", "objType" : "PLC_Doc_C", "objID" : "1247358482272", "objName" : "Data protection in the Russian Federation overview", "userID" : "2", "objUrl" : "http://crossborder.practicallaw.com/cs/Satellite/2-502-2227?source=relatedcontent", "pageType" : "", "contentAccessed" : "true", "analyticsPermCookie" : "2-65e08793:13f5a638676:1043", "analyticsSessionCookie" : "2-65e08793:13f5a638676:1044", "statisticSensorPath" : "http://analytics.practicallaw.com/sensor/statistic" }