Skip to the content
Global Data RulesData governance rules, country by country

Russia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Russia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

A copy must stayWork: Very highEnforcement: Active

If you collect personal data from people in Russia, the database you collect it into must sit inside Russia. You may then send a copy abroad, but only after you tell the regulator first and only to a country on its approved list. The United States is not on that list. Breaking the storage rule costs up to 6 million roubles, about $75,000, and leaking data can now put a person in prison.

Data governance in Russia

The eight things that decide how you handle data about people in Russia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it reaches you even with no office in Russia. The law applies whenever you use the personal data of Russian citizens under a contract with them. It also applies under any other agreement with them, or with their consent. There is no size or revenue threshold. Almost every organisation must also file a notice with the regulator before it starts. And you must file a second, separate notice before any data leaves the country.

What you have to do here:
Register or notify · Appoint a representative

Where the data is allowed to live

A copy can leave, but the original must stay. When you collect personal data about Russian citizens, the database you record, store, update or retrieve it from has to be physically in Russia. Since 1 July 2025 the law says this as a flat ban on using databases outside Russia for those steps. After that, sending a copy abroad is a separate question with its own paperwork. Several industries are stricter still and allow no copy out at all.

What you have to do here:
Keep the data in the country

What to do: Plan for a database inside Russia: this data is not allowed to leave.

Sending data out of the country

Russia runs a list of approved countries. A transfer is banned unless the destination is on that list. Before any data leaves, you must send the regulator a separate written notice. It names the countries, the data and the recipients. You must also collect written assurances from the recipient first, about how it will protect the data. If the destination is on the approved list, you may start as soon as the notice is sent. If it is not, you must wait, and you will most likely be refused. The United States is not on the list.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Government sign-off needed

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

Roskomnadzor, the federal communications and media supervisor, is the data protection regulator. It is a long-established federal service and fully staffed. It is still issuing binding orders. Its most recent inspection check-list order was published on the state legal portal in December 2025. It is not the only enforcer. The security service runs the national cyber-attack reporting system. The technical regulator FSTEC sets security requirements for government and critical systems. The Bank of Russia supervises banks and payment firms.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There is a minimum and a maximum, and they collide. Personal data must be destroyed within 30 days of the purpose being achieved. The same applies within 30 days of consent being withdrawn. If you used the data unlawfully, you have 10 working days. Against that, staff records must be kept for 50 years. Telecoms and messaging records must be kept for three years, and message content for up to six months. Where a law sets a minimum, the minimum wins and you keep the data.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are at least three clocks and they run at once. You have 24 hours to tell the data regulator that personal data has leaked, and 72 hours to give it the results of your internal investigation. Separately, if the leak came from a computer attack you must report it to the security service's national attack-detection system. Banks and payment firms report to the Bank of Russia as well. Missing the 24-hour notice is itself a fine of up to 3 million roubles, about $37,000.

What you have to do here:
Report breaches to the regulator · Report cyber incidents · Secure the data

What to do: Your breach process has to reach Russia's regulator inside the deadline above.

What catches people out

Five things catch people out. First, leaking data is now a crime. Doing it across a border carries up to eight years in prison. Second, repeat leaks are fined as a share of annual revenue, between 1 and 3 percent. The minimum is 20 million roubles, about $250,000. Third, staff files must be kept 50 years, which flatly conflicts with the 30-day deletion duty. Fourth, biometric data can only be handled by a Russian-controlled company using databases in Russia. Fifth, refusing to serve a customer because they will not give biometrics is itself a fine.

What you have to do here:
Keep data for a minimum period
What it costs if you get it wrong:
Criminal liability · Percentage of global turnover

What's changing next

One dated change is already fixed. From 1 September 2027, Moscow's public bodies move onto a single city technology platform. That will pull a large volume of citizen data into one place. Much more important are the powers the government already holds and can use with no consultation. The approved-country list can be cut by a single regulator order. Any transfer can be banned outright on security or economic grounds. And the rules for foreign use of Russian mapping technology have been written into the law but never issued.

What to do: Diarise 1 September 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries6 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Payments

Payments data must stay in the country

Official name: Федеральный закон от 27.06.2011 № 161-ФЗ «О национальной платежной системе», статьи 12 и 16 · Federal Law No. 161-FZ, article 12(8)-(9) and article 16(11)-(12), inserted by Federal Law No. 112-FZ of 5 May 2014 · Act of parliament

In forceNo — it stays put

Information about any money transfer made inside Russia may not be sent abroad. No one abroad may be given access to it. There are only two exceptions: transfers that really do cross the border, and handling customer complaints about payments made without their consent.

In force since 5 May 2014

Enforced by Central Bank of the Russian Federation (Bank of Russia)

How this country controls where data goes: Not allowed

Personal data must stay in the country

Official name: Федеральный закон от 29.12.2022 № 572-ФЗ об идентификации и аутентификации с использованием биометрических персональных данных · Federal Law No. 572-FZ of 29 December 2022, articles 14 and 17 · Act of parliament

In forceNo — it stays put

Biometric data must sit in databases inside Russia and nowhere else. A company cannot be accredited to identify people by biometrics if it is foreign, or more than 49 percent foreign-owned. So a foreign group cannot run this itself.

In force since 1 June 2023

Enforced by Ministry of Digital Development, Communications and Mass Media

How this country controls where data goes: Not allowed

Telecoms

Telecoms data must stay in the country

Official name: Федеральный закон от 07.07.2003 № 126-ФЗ «О связи», статья 64; Федеральный закон от 27.07.2006 № 149-ФЗ, статья 10.1 · Communications Law article 64(1); Information Law article 10.1(3), the latter amended by Federal Law No. 41-FZ of 1 April 2025 · Act of parliament

In forceNo — it stays put

Telecoms operators must keep three years of call and connection records and up to six months of message content, all inside Russia. Internet messaging and communication services carry the same duty, and their metadata period was raised from one year to three years on 1 April 2025.

In force since 20 July 2016Enforced from 1 July 2018

Enforced by Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor)

How this country controls where data goes: Not allowed

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

Personal data needs a copy kept in the country

Official name: Федеральный закон от 27.07.2006 № 152-ФЗ «О персональных данных», статья 18 часть 5 · Federal Law No. 152-FZ of 27 July 2006, article 18(5), as replaced by Federal Law No. 23-FZ of 28 February 2025 · Act of parliament

In forceA copy must stay

When you collect personal data about Russian citizens, the database you record and keep it in must be inside Russia. Since 1 July 2025 the law is written as an outright ban on using foreign databases for those steps, with only four narrow exceptions.

In force since 1 September 2015Enforced from 1 July 2025

Enforced by Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor)

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed

Rules for sending data abroad

Official name: Федеральный закон от 27.07.2006 № 152-ФЗ «О персональных данных», статья 12 · Federal Law No. 152-FZ, article 12, as amended by Federal Law No. 266-FZ of 14 July 2022 and Federal Law No. 265-FZ of 26 July 2026 · Act of parliament

In forceYes, with paperwork

Nothing may go abroad until you have filed a separate notice with the regulator. You must also collect written protection assurances from the recipient first. Transfers to countries on the regulator's approved list may start at once. Transfers to any other country must wait, and can be refused.

In force since 1 March 2023

Enforced by Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor)

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, To save someone’s life

Data rules

Official name: Федеральный закон № 152-ФЗ, статья 21 часть 3.1 и статья 19 часть 12 · Federal Law No. 152-FZ, articles 21(3.1) and 19(12), as inserted by Federal Law No. 266-FZ of 14 July 2022 · Act of parliament

In forceA copy must stay

Two clocks run from the moment a leak is identified: 24 hours to tell the data regulator, 72 hours to hand over your investigation findings. A computer attack that caused the leak must also be reported to the security service's national system.

In force since 1 September 2022

Enforced by Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor)

Who you would hear from

  • Федеральная служба по надзору в сфере связи, информационных технологий и массовых коммуникаций (Роскомнадзор)

    Personal data, cross-border transfer approvals, the register of operators, internet content and the landing law

    A long-established federal service, not a new body. It was still issuing binding rules during the period we reviewed. Its inspection check-list order No. 166 of 28 July 2025 was published on the state legal portal on 22 December 2025. We could not reach its own website from outside Russia on 18 August 2026. So its 2026 case volumes and fine totals are unverified.

  • ФСБ России, Национальный координационный центр по компьютерным инцидентам (НКЦКИ)

    The state system for detecting, preventing and eliminating computer attacks; incident reporting for critical infrastructure; monitoring access to organisations' information resources

    Accredits incident response centres and receives mandatory incident reports under Presidential Decree 250 and the Critical Information Infrastructure Law.

  • Федеральная служба по техническому и экспортному контролю (ФСТЭК России)

    Technical protection requirements for state information systems, critical infrastructure and personal data information systems; certification of security products

    Issued Order No. 117 on 11 April 2025 replacing its 2013 requirements for state information systems, in force 1 March 2026.

  • Центральный банк Российской Федерации (Банк России)

    Banks, payment systems, insurers and securities firms; information protection requirements for financial institutions; approval of foreign software purchases for banking critical infrastructure

    Keeps a public register of its binding rules. That includes Regulation No. 683-P on information protection for credit institutions.

  • Министерство цифрового развития, связи и массовых коммуникаций Российской Федерации

    The unified biometric system, the register of Russian software, and policy for the sector

  • Федеральная служба государственной регистрации, кадастра и картографии (Росреестр)

    Geodesy, cartography and the federal spatial data fund

    Named in the geodesy law as the authority for spatial data; we could not reach its site from outside Russia on 18 August 2026.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Roskomnadzor's 2026 enforcement volumes — how many fines, of what size, and how many transfer notifications it has refused

    We could not check Roskomnadzor's enforcement output. Its own site (rkn.gov.ru) returns a server error to requests from outside Russia, so we could not read its reports or news. Our rating of 'active' rests on the legal machinery we could verify. That is turnover fines in force since 30 May 2025, criminal liability since December 2024, and monitoring powers that need no contact with you. The real position may well be more aggressive.

  • Whether Roskomnadzor has amended or pruned the approved-country list since Law 265-FZ took effect on 26 July 2026

    We could not rule out a very recent change to the approved-country list. The state legal portal shows Order No. 128 of 5 August 2022 in its original edition, with no amendments as at 18 August 2026. But an order registered in the last three weeks might not show yet. This is the single most volatile item in this record. Check the current list before you send anything.

  • Whether a copy of Russian citizens' personal data may still lawfully be held abroad after the 1 July 2025 rewrite of article 18(5)

    We could not confirm how the rewritten wording works. The old wording was a positive duty to use a Russian database. The new wording bans using a foreign one for collection, recording, storage, updating and retrieval. Read literally, the two may not mean the same thing. The regulator's guidance on this sits on its own site, which we could not reach.

  • The exact commencement date of Criminal Code article 272.1

    We could not confirm the exact start date of the criminal offence. Law 421-FZ of 30 November 2024 contains no start-date clause, so the default ten-day rule gives 11 December 2024. We found no official statement confirming that date.

  • Incident reporting deadlines to the Bank of Russia for banks and payment firms, in hours

    We could not read the Bank of Russia's incident reporting rules in full. We could find them by title but not open them. Financial firms should assume a third clock exists alongside the 24-hour and 72-hour ones. Confirm the details with the Bank of Russia.

  • Whether health, insurance and securities regulators impose residency rules of their own

    We found no separate rule about where the data must sit for those three industries, checked 18 August 2026. But not finding one is not proof there is none. Bank of Russia rules in particular are not carried on the state legal portal. Check before you rely on this.

  • United States dollar equivalents for rouble penalties

    Dollar figures here are converted at roughly 80 roubles to the dollar. The rouble moves a lot. Treat the dollar figures as indicative only.

  • Whether the Government has issued the order under article 23(6) of the geodesy law governing foreign use of mapping technology in Russia

    We found the power in the statute but no order actually issuing the rules. So we record it as a power the government holds, not as a live rule. It could be used at any time.

  • The exact commencement date of the payment-information localisation provisions in the National Payment System Law

    We could not confirm the historical start date. Federal Law No. 112-FZ of 5 May 2014 inserted these articles. That law staged its parts across several dates in 2014 and 2015, and we did not open its start-date article. The articles are certainly in force today. Only the historical start date is uncertain.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.