Russia Federal Law on Personal Data (152-FZ)
Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Breach Notification, Inspection and Liability
Operators must notify Roskomnadzor of incidents that led to unlawful or accidental transfer, including provision, dissemination or access to personal data, within 24 hours of identification, with a follow up notification on the results of the internal investigation within 72 hours.
- Breach response procedure aligned to 24 and 72 hour deadlines
- Internal breach register
- Initial and final notifications submitted to Roskomnadzor
- Investigation outcomes
- 24 hour deadline missed
- Investigation outcome not submitted
- No tracking of regulator responses
Operators must carry out internal control or audit of compliance of processing of personal data with the law and with their internal documents, with periodicity defined by their internal regulations.
- Internal audit program
- Audit reports
- Management action plans
- Evidence of remediation
- Audit not conducted or conducted only by IT
- No action plan tracking
- Audit scope misses processing on behalf
Roskomnadzor conducts scheduled and unscheduled inspections of operators. Operators must cooperate, provide requested documents and implement orders to remedy violations within the stated deadlines. Administrative liability applies under the Code of Administrative Offences.
- Inspection correspondence register
- Inspection response documentation
- Remediation evidence
- Records of complaints from data subjects forwarded by the regulator
- Late responses to inspections
- Remediation not evidenced
- Documents not maintained in expected format
Violations of personal data legislation may result in administrative penalties under the Code of Administrative Offences, including increased fines and turnover based fines for repeated breaches involving the leak of large volumes of personal data.
- Compliance risk register entry
- Legal advice on penalty exposure
- Records of board notifications
- Insurance coverage details where applicable
- No legal advice obtained on turnover based fines
- Board not informed of liability changes
- No risk register entry
Breach and Enforcement
Per 152-FZ Articles 23-24 + KoAP RF: breach + enforcement. Requirements include (a) implement Breach Notification to Roskomnadzor per 2022 amendments within 24 hours of becoming aware + (b) maintain incident response + (c) cooperate with RKN inspections + (d) maintain enforcement awareness including administrative penalties under KoAP + criminal penalties + (e) maintain breach log + tabletops.
- 152-FZ evidence for RUSPD-8
- data localization + RKN notification + 24-hr breach partial
Consent and Lawful Basis
Consent of the data subject to the processing of personal data must be specific, informed and conscious. In cases provided by law, consent must be in writing, including in electronic form signed with an electronic signature, and contain the elements specified in the law.
- Consent forms in Russian language
- Consent management system records
- Templates for written consent
- Records of consent withdrawal handling
- Consent text in English only
- Bundled consent across multiple unrelated purposes
- No documented withdrawal mechanism
Dissemination of personal data, including publication on the internet, requires a separate consent that is distinct from consent to general processing and that lists permitted categories of recipients and restrictions on further dissemination.
- Standalone dissemination consent forms
- Registry of publications relying on the consent
- Process to honour data subject restrictions
- Withdrawal and takedown procedure
- Dissemination treated as covered by general consent
- No registry of online publications relying on consent
- No mechanism for data subjects to add restrictions
Operators must provide data subjects with information about the processing of their personal data, including the operator's name, address and purposes of processing, the legal basis, categories of data subjects, sources of data and rights of data subjects.
- Privacy notice published in Russian
- Layered notice for data collection points
- Records of when and how notices are presented
- Updates log
- Notice not in Russian
- Notice not presented before data collection
- Updates not communicated
Cross-Border and Localization
Per 152-FZ Article 18.5 + Article 12: data localization + cross-border. Requirements include (a) implement Data Localization - personal data of Russian citizens collection + recording + storage + amendment + extraction + use of databases must occur in Russia + (b) implement Cross-Border Transfer per Article 12 + with consent + adequacy + (c) maintain RKN approval for transfers + (d) maintain inventory of cross-border flows + (e) maintain RKN notifications.
- 152-FZ evidence for RUSPD-6
- data localization + RKN notification + 24-hr breach partial
Data Subject Rights
Data subjects have the right to obtain information about the processing of their personal data, to demand clarification, blocking or destruction in case of inaccuracy or unlawful processing, and to withdraw consent. Operators must respond within statutory deadlines.
- Rights request register
- Standard response templates in Russian
- Identity verification procedure
- Records of consent withdrawal
- No central request register
- Responses in English to Russian language requests
- No documented identity verification
Governance
Per 152-FZ Articles 22 + 18: operator registration + notification. Requirements include (a) submit Operator Notification to Roskomnadzor before processing + (b) maintain Operator obligations + responsible person designation + (c) maintain register of processing + (d) implement training + awareness + (e) cooperate with RKN + (f) maintain documented governance.
- 152-FZ evidence for RUSPD-7
- data localization + RKN notification + 24-hr breach partial
High-Risk Processing
Per 152-FZ Articles 10 + 11: special categories + biometric. Requirements include (a) Special Categories of Data (Article 10) prohibited processing without specific consent or legal basis including race + ethnicity + political + religious + philosophical + health + sex life + (b) Biometric Personal Data (Article 11) including authentication + criminal procedure + with written consent + (c) implement safeguards + DPIA-equivalent assessment + (d) maintain documentation.
- 152-FZ evidence for RUSPD-4
- data localization + RKN notification + 24-hr breach partial
Individual Rights
Per 152-FZ Articles 14-17: data subject rights. Requirements include (a) Right of Access (Article 14) + (b) Right to Correction + (c) Right to Block and Destroy (Article 16) + (d) Right to Object (Article 17) + (e) Direct Marketing restrictions + automated decisions safeguards + (f) maintain mechanism for receiving + responding.
- 152-FZ evidence for RUSPD-3
- data localization + RKN notification + 24-hr breach partial
Lawful Basis and Consent
Per 152-FZ Articles 6 + 9 + 18: lawful basis + consent + notice. Requirements include (a) establish lawful basis per Article 6 + (b) obtain Specific Consent Requirements per Article 9 including written or electronic + specific to purposes + revocable + (c) provide notice to data subjects + (d) maintain records of consent + notices + (e) align with RKN guidance on consent.
- 152-FZ evidence for RUSPD-2
- data localization + RKN notification + 24-hr breach partial
Localisation and Cross-Border Transfer
When collecting personal data, including via the internet, operators must ensure the recording, systematisation, accumulation, storage, refinement (update, modification) and retrieval of personal data of Russian citizens using databases located on the territory of the Russian Federation.
- Database inventory identifying primary databases for Russian citizen data located in Russia
- Network diagrams showing data flows
- Hosting contracts confirming Russian territory
- Roskomnadzor questionnaire responses
- Primary database located outside Russia with replica inside
- Cloud arrangements without documented Russian hosting
- No segregation of Russian citizen records
Before starting cross border transfers of personal data, operators must notify Roskomnadzor and obtain confirmation. For transfers to countries that do not provide adequate protection, additional assessments and safeguards are required, and Roskomnadzor may prohibit or restrict the transfer.
- Cross border transfer notification submitted to Roskomnadzor
- Confirmation receipt or response
- Assessment of recipient country protection
- Safeguard documentation for non adequate countries
- Transfers commenced before notification
- No assessment of recipient country
- Safeguards not documented
Operators must keep records of the provision of personal data to third parties, including state authorities, with details of the recipient, legal basis, scope of data and date of provision.
- Provision register
- Standard request handling procedure
- Approval workflow for non standard disclosures
- Periodic review reports
- No central register
- Disclosures made without recording legal basis
- Approval workflow inconsistent
Processors and Retention
Where the operator entrusts personal data processing to another person, this must be done on the basis of an agreement that contains the list of operations, processing purposes, confidentiality and protection obligations, and the requirement to act on the operator's instructions.
- Data processing agreements with all processors
- Inventory of processors
- Audit rights documentation
- Sub processor approval records
- Contracts lack mandatory clauses
- No inventory of processors
- Sub processors used without approval
Personal data must not be stored longer than is necessary for the purposes of processing, unless retention is required by law or contract. Once the purpose is achieved or consent withdrawn, the operator must destroy the personal data within statutory deadlines and confirm destruction.
- Retention schedule
- Destruction acts (certificates)
- Process for handling consent withdrawal
- Audit logs of destruction
- Retention schedule absent
- No destruction certificates
- Backups not addressed
Registration and Notification
Operators that process personal data must submit a notification of intent to process personal data to Roskomnadzor before commencing processing, except where a statutory exemption applies. The notification must include identification details, processing purposes, categories of data and data subjects, applied protective measures and intended cross border transfers.
- Notification submitted to Roskomnadzor
- Confirmation of inclusion in the operators register
- Update notifications when processing changes
- Internal process for triggering updates
- Notification not updated when new processing activities begin
- Cross border transfers omitted from notification
- No designated owner for notification updates
Operators that are legal entities must designate a person responsible for organising the processing of personal data, with the powers to organise compliance, conduct internal control and respond to data subjects and the regulator.
- Order designating the responsible person
- Job description with required powers
- Reporting line documentation
- Annual workplan and reports
- Designation not formalised by order
- Person lacks authority to access systems
- No annual reporting cycle
Operators must adopt and publish a document defining the policy on processing personal data, as well as internal documents establishing procedures for protection of personal data, and ensure unrestricted access to the published policy.
- Personal data processing policy published on the operator website
- Internal procedure for personal data protection
- Approval orders for the policy
- Version history
- Policy not in Russian language
- Policy not accessible from the website footer
- No version history maintained
Scope and Principles
Per Russia Federal Law on Personal Data (152-FZ): scope + principles. Requirements include (a) determine scope per Article 1 + (b) apply key definitions per Article 3 + (c) apply processing principles per Article 5 (legality + purpose limitation + adequacy + accuracy + retention limitation + (d) document applicability + (e) align with Roskomnadzor (RKN) + Federal Service for Supervision in the Sphere of Communications guidance.
- 152-FZ evidence for RUSPD-1
- data localization + RKN notification + 24-hr breach partial
Security
Per 152-FZ Articles 18.1-19 + FSTEC/FSB Orders: security. Requirements include (a) implement Security of Processing per FSTEC + FSB orders depending on data category + threat level + (b) implement certified cryptography for sensitive data + (c) implement access control + audit logging + (d) maintain documentation of security measures + (e) cooperate with FSTEC + FSB inspections + (f) maintain Roskomnadzor registration.
- 152-FZ evidence for RUSPD-5
- data localization + RKN notification + 24-hr breach partial
Security of Processing
Operators must take legal, organisational and technical measures to protect personal data from unlawful or accidental access, destruction, alteration, blocking, copying, distribution and from other unlawful actions, including the use of information security tools that have passed conformity assessment in accordance with Russian law where required.
- Information security policy
- Threat model for personal data information systems
- List of applied protection means with certification
- Internal control records on personal data security
- Threat model absent or out of date
- Foreign information security tools used without certification
- No internal control program
Personal data information systems are classified into four levels of protection based on the categories of personal data processed, the number of data subjects and the type of threats. Each level requires specific security measures defined by government regulations.
- Information system classification document
- Security measures matrix per level
- Conformity assessment records
- Periodic review of classification
- Classification not documented
- Security measures not aligned to level
- No reclassification after material change
Special and Biometric Categories
Processing of special categories of personal data, including data on race, nationality, political views, religious or philosophical beliefs, state of health and private life, is prohibited except in cases listed by law, including where the data subject has given consent in writing.
- Inventory of special category data
- Written consents
- Lawful basis assessment
- Access restrictions
- Special category data processed without written consent
- No inventory available
- Access not restricted
Biometric personal data, defined as data characterising physiological and biological features that allow identification of the data subject, may only be processed with the written consent of the data subject, except in cases listed by law. Operators that process biometric data are subject to additional security requirements.
- Written consent for biometric processing
- Biometric system security documentation
- Records of integration with the Unified Biometric System where applicable
- Roskomnadzor and Ministry of Digital Development notifications
- Implicit consent treated as sufficient
- Biometric systems lacking certified protection means
- No integration where required by law
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Russia Federal Law on Personal Data (152-FZ) framework page.