DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Europe · In force · Opt-in

🇷🇺 Russia Data Privacy Laws

Russia pairs consent formalism with hard data localization. Databases of Russian citizens' personal data must sit in Russia (LinkedIn has been blocked since 2016 for refusing), and a 2025 overhaul added turnover-based fines for leaks, criminal exposure, a ban on using foreign databases for citizens' data from July 2025, and standalone consent documents from September 2025. A July 2026 law narrowed what counts as an adequate destination for transfers. Western platforms operate here under heavy restriction or not at all.

Updated September 28, 2026 · digitalprivacyregs.com
Status
In force
Consent model
Opt-in
Primary law
Federal Law No. 152-FZ on Personal Data
Year
2006
Authority
Roskomnadzor
Marketing consent
Written or clearly demonstrable consent is the default basis, and since 1 September 2025 it must be obtained as a separate document; separate consent for dissemination; strict formalities.
Transfers
Prior notification to Roskomnadzor for cross-border transfers; since 26 July 2026 only countries on Roskomnadzor's list count as adequate, and Convention 108 membership no longer qualifies on its own. Since 1 July 2025, Russian citizens' data may not be processed in databases located abroad.
Penalties
From May 30, 2025, leak-related fines reach turnover-based levels up to 3%, plus large fixed fines and criminal liability for illegal data trafficking.

The framework

Russia's framework rests on Federal Law No. 152-FZ on Personal Data, adopted in 2006, with Roskomnadzor as the supervisory authority.

That puts Russia in the global opt-in majority, where permission comes before processing and marketing waits for consent.

Key instruments

Federal Law 242-FZ (localization amendment)

2015 · In force

Requires initial recording, systematization, storage and updating of Russian citizens' personal data using databases located in Russia.

2025 liability amendments

2025 · In force from 30 May 2025

Introduced turnover-based administrative fines for personal data leaks (up to 3% of annual revenue within set floors and caps), higher fixed fines, and criminal liability for trading in stolen personal data.

Federal Law 265-FZ

2026 · In force from 26 Jul 2026

Ends the automatic adequacy status of Convention 108 parties for cross-border transfers; only countries on Roskomnadzor's list now qualify, which leaves the regulator free to narrow the list.

Marketing and advertising

Written or clearly demonstrable consent is the default basis, and since 1 September 2025 it must be obtained as a separate document; separate consent for dissemination; strict formalities. That single sentence decides most channel plans here.

Cross-border transfers

Prior notification to Roskomnadzor for cross-border transfers; since 26 July 2026 only countries on Roskomnadzor's list count as adequate, and Convention 108 membership no longer qualifies on its own. Since 1 July 2025, Russian citizens' data may not be processed in databases located abroad.

Enforcement and penalties

From May 30, 2025, leak-related fines reach turnover-based levels up to 3%, plus large fixed fines and criminal liability for illegal data trafficking.

Primary sources

Cite this page: "Russia Data Privacy Laws." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/russia.html. Accessed [date].