Skip to content

Evidence request lists

Russia Federal Law on Personal Data (152-FZ)

Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Breach Notification, Inspection and Liability

RU-152FZ-009
Personal Data Breach Notification

Operators must notify Roskomnadzor of incidents that led to unlawful or accidental transfer, including provision, dissemination or access to personal data, within 24 hours of identification, with a follow up notification on the results of the internal investigation within 72 hours.

Artefacts an auditor will ask for
  • Breach response procedure aligned to 24 and 72 hour deadlines
  • Internal breach register
  • Initial and final notifications submitted to Roskomnadzor
  • Investigation outcomes
Where this commonly fails
  • 24 hour deadline missed
  • Investigation outcome not submitted
  • No tracking of regulator responses
RU-152FZ-015
Internal Control and Audit

Operators must carry out internal control or audit of compliance of processing of personal data with the law and with their internal documents, with periodicity defined by their internal regulations.

Artefacts an auditor will ask for
  • Internal audit program
  • Audit reports
  • Management action plans
  • Evidence of remediation
Where this commonly fails
  • Audit not conducted or conducted only by IT
  • No action plan tracking
  • Audit scope misses processing on behalf
RU-152FZ-017
Roskomnadzor Inspections and Enforcement

Roskomnadzor conducts scheduled and unscheduled inspections of operators. Operators must cooperate, provide requested documents and implement orders to remedy violations within the stated deadlines. Administrative liability applies under the Code of Administrative Offences.

Artefacts an auditor will ask for
  • Inspection correspondence register
  • Inspection response documentation
  • Remediation evidence
  • Records of complaints from data subjects forwarded by the regulator
Where this commonly fails
  • Late responses to inspections
  • Remediation not evidenced
  • Documents not maintained in expected format
RU-152FZ-019
Liability and Penalties

Violations of personal data legislation may result in administrative penalties under the Code of Administrative Offences, including increased fines and turnover based fines for repeated breaches involving the leak of large volumes of personal data.

Artefacts an auditor will ask for
  • Compliance risk register entry
  • Legal advice on penalty exposure
  • Records of board notifications
  • Insurance coverage details where applicable
Where this commonly fails
  • No legal advice obtained on turnover based fines
  • Board not informed of liability changes
  • No risk register entry

Breach and Enforcement

RUSPD-8
Breach Notification, RKN Inspections, Sanctions

Per 152-FZ Articles 23-24 + KoAP RF: breach + enforcement. Requirements include (a) implement Breach Notification to Roskomnadzor per 2022 amendments within 24 hours of becoming aware + (b) maintain incident response + (c) cooperate with RKN inspections + (d) maintain enforcement awareness including administrative penalties under KoAP + criminal penalties + (e) maintain breach log + tabletops.

Artefacts an auditor will ask for
  • 152-FZ evidence for RUSPD-8
Where this commonly fails
  • data localization + RKN notification + 24-hr breach partial

Consent and Lawful Basis

RU-152FZ-003
Consent of the Data Subject

Consent of the data subject to the processing of personal data must be specific, informed and conscious. In cases provided by law, consent must be in writing, including in electronic form signed with an electronic signature, and contain the elements specified in the law.

Artefacts an auditor will ask for
  • Consent forms in Russian language
  • Consent management system records
  • Templates for written consent
  • Records of consent withdrawal handling
Where this commonly fails
  • Consent text in English only
  • Bundled consent across multiple unrelated purposes
  • No documented withdrawal mechanism
RU-152FZ-004
Consent for Dissemination of Personal Data

Dissemination of personal data, including publication on the internet, requires a separate consent that is distinct from consent to general processing and that lists permitted categories of recipients and restrictions on further dissemination.

Artefacts an auditor will ask for
  • Standalone dissemination consent forms
  • Registry of publications relying on the consent
  • Process to honour data subject restrictions
  • Withdrawal and takedown procedure
Where this commonly fails
  • Dissemination treated as covered by general consent
  • No registry of online publications relying on consent
  • No mechanism for data subjects to add restrictions
RU-152FZ-018
Privacy Notices and Transparency

Operators must provide data subjects with information about the processing of their personal data, including the operator's name, address and purposes of processing, the legal basis, categories of data subjects, sources of data and rights of data subjects.

Artefacts an auditor will ask for
  • Privacy notice published in Russian
  • Layered notice for data collection points
  • Records of when and how notices are presented
  • Updates log
Where this commonly fails
  • Notice not in Russian
  • Notice not presented before data collection
  • Updates not communicated

Cross-Border and Localization

RUSPD-6
Cross-Border Transfer and Data Localization (Article 18.5)

Per 152-FZ Article 18.5 + Article 12: data localization + cross-border. Requirements include (a) implement Data Localization - personal data of Russian citizens collection + recording + storage + amendment + extraction + use of databases must occur in Russia + (b) implement Cross-Border Transfer per Article 12 + with consent + adequacy + (c) maintain RKN approval for transfers + (d) maintain inventory of cross-border flows + (e) maintain RKN notifications.

Artefacts an auditor will ask for
  • 152-FZ evidence for RUSPD-6
Where this commonly fails
  • data localization + RKN notification + 24-hr breach partial

Data Subject Rights

RU-152FZ-010
Data Subject Rights and Requests

Data subjects have the right to obtain information about the processing of their personal data, to demand clarification, blocking or destruction in case of inaccuracy or unlawful processing, and to withdraw consent. Operators must respond within statutory deadlines.

Artefacts an auditor will ask for
  • Rights request register
  • Standard response templates in Russian
  • Identity verification procedure
  • Records of consent withdrawal
Where this commonly fails
  • No central request register
  • Responses in English to Russian language requests
  • No documented identity verification

Governance

RUSPD-7
Roskomnadzor Registration, Operator Notification, Governance

Per 152-FZ Articles 22 + 18: operator registration + notification. Requirements include (a) submit Operator Notification to Roskomnadzor before processing + (b) maintain Operator obligations + responsible person designation + (c) maintain register of processing + (d) implement training + awareness + (e) cooperate with RKN + (f) maintain documented governance.

Artefacts an auditor will ask for
  • 152-FZ evidence for RUSPD-7
Where this commonly fails
  • data localization + RKN notification + 24-hr breach partial

High-Risk Processing

RUSPD-4
Special Categories, Biometric Data

Per 152-FZ Articles 10 + 11: special categories + biometric. Requirements include (a) Special Categories of Data (Article 10) prohibited processing without specific consent or legal basis including race + ethnicity + political + religious + philosophical + health + sex life + (b) Biometric Personal Data (Article 11) including authentication + criminal procedure + with written consent + (c) implement safeguards + DPIA-equivalent assessment + (d) maintain documentation.

Artefacts an auditor will ask for
  • 152-FZ evidence for RUSPD-4
Where this commonly fails
  • data localization + RKN notification + 24-hr breach partial

Individual Rights

RUSPD-3
Data Subject Rights (Access, Correction, Object, Block/Destroy)

Per 152-FZ Articles 14-17: data subject rights. Requirements include (a) Right of Access (Article 14) + (b) Right to Correction + (c) Right to Block and Destroy (Article 16) + (d) Right to Object (Article 17) + (e) Direct Marketing restrictions + automated decisions safeguards + (f) maintain mechanism for receiving + responding.

Artefacts an auditor will ask for
  • 152-FZ evidence for RUSPD-3
Where this commonly fails
  • data localization + RKN notification + 24-hr breach partial

Lawful Basis and Consent

RUSPD-2
Lawful Basis, Consent, Notice

Per 152-FZ Articles 6 + 9 + 18: lawful basis + consent + notice. Requirements include (a) establish lawful basis per Article 6 + (b) obtain Specific Consent Requirements per Article 9 including written or electronic + specific to purposes + revocable + (c) provide notice to data subjects + (d) maintain records of consent + notices + (e) align with RKN guidance on consent.

Artefacts an auditor will ask for
  • 152-FZ evidence for RUSPD-2
Where this commonly fails
  • data localization + RKN notification + 24-hr breach partial

Localisation and Cross-Border Transfer

RU-152FZ-002
Data Localisation of Russian Citizens Personal Data

When collecting personal data, including via the internet, operators must ensure the recording, systematisation, accumulation, storage, refinement (update, modification) and retrieval of personal data of Russian citizens using databases located on the territory of the Russian Federation.

Artefacts an auditor will ask for
  • Database inventory identifying primary databases for Russian citizen data located in Russia
  • Network diagrams showing data flows
  • Hosting contracts confirming Russian territory
  • Roskomnadzor questionnaire responses
Where this commonly fails
  • Primary database located outside Russia with replica inside
  • Cloud arrangements without documented Russian hosting
  • No segregation of Russian citizen records
RU-152FZ-005
Cross Border Transfer Notification and Assessment

Before starting cross border transfers of personal data, operators must notify Roskomnadzor and obtain confirmation. For transfers to countries that do not provide adequate protection, additional assessments and safeguards are required, and Roskomnadzor may prohibit or restrict the transfer.

Artefacts an auditor will ask for
  • Cross border transfer notification submitted to Roskomnadzor
  • Confirmation receipt or response
  • Assessment of recipient country protection
  • Safeguard documentation for non adequate countries
Where this commonly fails
  • Transfers commenced before notification
  • No assessment of recipient country
  • Safeguards not documented
RU-152FZ-020
Records of Provision of Personal Data to Third Parties

Operators must keep records of the provision of personal data to third parties, including state authorities, with details of the recipient, legal basis, scope of data and date of provision.

Artefacts an auditor will ask for
  • Provision register
  • Standard request handling procedure
  • Approval workflow for non standard disclosures
  • Periodic review reports
Where this commonly fails
  • No central register
  • Disclosures made without recording legal basis
  • Approval workflow inconsistent

Processors and Retention

RU-152FZ-011
Processing on Behalf of Another Operator

Where the operator entrusts personal data processing to another person, this must be done on the basis of an agreement that contains the list of operations, processing purposes, confidentiality and protection obligations, and the requirement to act on the operator's instructions.

Artefacts an auditor will ask for
  • Data processing agreements with all processors
  • Inventory of processors
  • Audit rights documentation
  • Sub processor approval records
Where this commonly fails
  • Contracts lack mandatory clauses
  • No inventory of processors
  • Sub processors used without approval
RU-152FZ-014
Retention and Destruction of Personal Data

Personal data must not be stored longer than is necessary for the purposes of processing, unless retention is required by law or contract. Once the purpose is achieved or consent withdrawn, the operator must destroy the personal data within statutory deadlines and confirm destruction.

Artefacts an auditor will ask for
  • Retention schedule
  • Destruction acts (certificates)
  • Process for handling consent withdrawal
  • Audit logs of destruction
Where this commonly fails
  • Retention schedule absent
  • No destruction certificates
  • Backups not addressed

Registration and Notification

RU-152FZ-001
Notification of Personal Data Processing to Roskomnadzor

Operators that process personal data must submit a notification of intent to process personal data to Roskomnadzor before commencing processing, except where a statutory exemption applies. The notification must include identification details, processing purposes, categories of data and data subjects, applied protective measures and intended cross border transfers.

Artefacts an auditor will ask for
  • Notification submitted to Roskomnadzor
  • Confirmation of inclusion in the operators register
  • Update notifications when processing changes
  • Internal process for triggering updates
Where this commonly fails
  • Notification not updated when new processing activities begin
  • Cross border transfers omitted from notification
  • No designated owner for notification updates
RU-152FZ-007
Designation of Person Responsible for Personal Data

Operators that are legal entities must designate a person responsible for organising the processing of personal data, with the powers to organise compliance, conduct internal control and respond to data subjects and the regulator.

Artefacts an auditor will ask for
  • Order designating the responsible person
  • Job description with required powers
  • Reporting line documentation
  • Annual workplan and reports
Where this commonly fails
  • Designation not formalised by order
  • Person lacks authority to access systems
  • No annual reporting cycle
RU-152FZ-008
Internal Personal Data Documents

Operators must adopt and publish a document defining the policy on processing personal data, as well as internal documents establishing procedures for protection of personal data, and ensure unrestricted access to the published policy.

Artefacts an auditor will ask for
  • Personal data processing policy published on the operator website
  • Internal procedure for personal data protection
  • Approval orders for the policy
  • Version history
Where this commonly fails
  • Policy not in Russian language
  • Policy not accessible from the website footer
  • No version history maintained

Scope and Principles

RUSPD-1
Scope, Definitions, Principles under 152-FZ

Per Russia Federal Law on Personal Data (152-FZ): scope + principles. Requirements include (a) determine scope per Article 1 + (b) apply key definitions per Article 3 + (c) apply processing principles per Article 5 (legality + purpose limitation + adequacy + accuracy + retention limitation + (d) document applicability + (e) align with Roskomnadzor (RKN) + Federal Service for Supervision in the Sphere of Communications guidance.

Artefacts an auditor will ask for
  • 152-FZ evidence for RUSPD-1
Where this commonly fails
  • data localization + RKN notification + 24-hr breach partial

Security

RUSPD-5
Security of Processing, Confidentiality, FSB/FSTEC Requirements

Per 152-FZ Articles 18.1-19 + FSTEC/FSB Orders: security. Requirements include (a) implement Security of Processing per FSTEC + FSB orders depending on data category + threat level + (b) implement certified cryptography for sensitive data + (c) implement access control + audit logging + (d) maintain documentation of security measures + (e) cooperate with FSTEC + FSB inspections + (f) maintain Roskomnadzor registration.

Artefacts an auditor will ask for
  • 152-FZ evidence for RUSPD-5
Where this commonly fails
  • data localization + RKN notification + 24-hr breach partial

Security of Processing

RU-152FZ-006
Technical and Organisational Protection Measures

Operators must take legal, organisational and technical measures to protect personal data from unlawful or accidental access, destruction, alteration, blocking, copying, distribution and from other unlawful actions, including the use of information security tools that have passed conformity assessment in accordance with Russian law where required.

Artefacts an auditor will ask for
  • Information security policy
  • Threat model for personal data information systems
  • List of applied protection means with certification
  • Internal control records on personal data security
Where this commonly fails
  • Threat model absent or out of date
  • Foreign information security tools used without certification
  • No internal control program
RU-152FZ-016
Levels of Protection for Information Systems

Personal data information systems are classified into four levels of protection based on the categories of personal data processed, the number of data subjects and the type of threats. Each level requires specific security measures defined by government regulations.

Artefacts an auditor will ask for
  • Information system classification document
  • Security measures matrix per level
  • Conformity assessment records
  • Periodic review of classification
Where this commonly fails
  • Classification not documented
  • Security measures not aligned to level
  • No reclassification after material change

Special and Biometric Categories

RU-152FZ-012
Special Categories of Personal Data

Processing of special categories of personal data, including data on race, nationality, political views, religious or philosophical beliefs, state of health and private life, is prohibited except in cases listed by law, including where the data subject has given consent in writing.

Artefacts an auditor will ask for
  • Inventory of special category data
  • Written consents
  • Lawful basis assessment
  • Access restrictions
Where this commonly fails
  • Special category data processed without written consent
  • No inventory available
  • Access not restricted
RU-152FZ-013
Biometric Personal Data

Biometric personal data, defined as data characterising physiological and biological features that allow identification of the data subject, may only be processed with the written consent of the data subject, except in cases listed by law. Operators that process biometric data are subject to additional security requirements.

Artefacts an auditor will ask for
  • Written consent for biometric processing
  • Biometric system security documentation
  • Records of integration with the Unified Biometric System where applicable
  • Roskomnadzor and Ministry of Digital Development notifications
Where this commonly fails
  • Implicit consent treated as sufficient
  • Biometric systems lacking certified protection means
  • No integration where required by law
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Russia Federal Law on Personal Data (152-FZ) framework page.