Data Protection Atlas

Russia

Tier 3 Comprehensive law Europe

Principal framework: Federal Law 152-FZ on Personal Data (2006). Regulator: Roskomnadzor. Law 152-FZ plus strict localisation, cross-border notification and a hardened 2024–25 penalty regime; enforcement is centralised in Roskomnadzor.

At a glance

Principal law
Federal Law 152-FZ on Personal Data
Regulator
Roskomnadzor
Breach notification
24-hour initial notice to Roskomnadzor, 72-hour follow-up report
Maximum penalty
2025 amendments added turnover-based fines up to 3% (capped RUB 500m) for repeat leaks
DPO required
A person responsible for processing must be designated
Digital consent age
No specific digital-consent age
Extraterritorial reach
Localisation — Russians’ data must first be stored on servers in Russia

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
RU

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

No instrument profiled yet.

Sources

No source recorded yet. This record cannot rise above Tier 3 until it has one — see depth tiers.

Never independently verified — seeded from the prototype.