Most foreign companies meet Russian data law through a customer project. The obligation usually arrived earlier — with the first employment contract.
You employ anyone in Russia. Collecting a passport copy, a bank account or a medical certificate is enough — headcount does not matter.
A processing policy in Russian, valid consents, a record of what is held, and notification to Roskomnadzor.
Foreign companies tend to meet Russian data protection law through a customer-facing project. The obligation usually arrived earlier than that — with the first employment contract.
Employment records are personal data. Collecting a passport copy, a bank account, a medical certificate or an emergency contact makes an employer an operator, with the same core duties as a technology company processing millions of records. The duties do not scale with headcount in the way most foreign HR teams expect.
Four things are expected, and their absence is the most common finding in any inspection.
An internal policy on processing personal data — in Russian, reflecting what the company actually does with employee records
Consents where consent is the basis relied on, in a form that meets the statutory requirements rather than a translated group template
A record of what is processed, why, and for how long it is kept
Notification to Roskomnadzor of the intention to process — an omission that became separately punishable in 2025
The pattern here mirrors Russian employment law generally: the employer who behaved perfectly well but cannot evidence it is the one who gets the finding.
Some employee data attracts stricter treatment: health information, nationality, religious belief, criminal record. Biometric data — fingerprints for office access, facial recognition on a turnstile — is stricter again.
Foreign employers introduce these without noticing. A group-wide badge system rolled out to the Moscow office, an occupational health questionnaire from headquarters, a diversity survey run globally: each can bring special or biometric categories into processing that was otherwise routine. Penalties in these categories are higher than for ordinary personal data.
These are the three gaps we find most often:
This is where foreign groups run into genuine architectural difficulty. Russian law requires that personal data of Russian citizens be recorded, systematised and stored in databases located in Russia.
For an employer running a single global HR platform, that is not a policy question but an infrastructure one. The usual answers involve a Russian-resident database as the primary record with the group system fed from it, rather than the other way round — but the right structure depends on the platform, the vendor and what the group needs the data for.
It is worth resolving before a system rollout rather than after. Retrofitting localisation onto a live HR platform is materially harder than designing for it, and the intermediate state — where Russian records live only abroad — is the exposed one.
Most foreign employers hand employee data to at least one third party: a payroll provider, a benefits administrator, a recruitment platform. That transfer does not transfer the obligation.
The operator remains responsible for what happens to the data, which makes two things worth checking in any provider contract: that the provider is bound to the standards you are held to, and that they must tell you about an incident fast enough for you to meet your own 24-hour notification deadline. A provider who reports to you in three days has made your compliance impossible.
Employee data compliance rarely arrives alone. It surfaces during a labour inspection, in due diligence on a sale, when a departing employee complains, or when a group audit asks whether the Russian entity meets local standards.
That is an argument for treating it as part of the employment file rather than as an IT project: the documents that satisfy the data regulator are largely produced by the same exercise that produces compliant employment documentation.
Yes — the obligations attach to being an operator, not to the size of the operation. Small foreign teams are inspected, and a missing policy document or absent Roskomnadzor notification is exactly the kind of finding that does not depend on scale to be established.
Potentially. The localisation requirement expects the primary database of Russian citizens' personal data to be in Russia. A global platform is not automatically non-compliant, but the architecture has to be arranged so the Russian-resident database is the primary record. This is worth designing rather than discovering.
Partly — some processing is necessary to perform the contract and does not need separate consent. But not all of it: transfers to group companies abroad, photographs, biometric access systems and background checks usually need their own basis. Assuming the contract covers everything is a common and avoidable gap.
Retention has to have a defined basis and a defined period — keeping everything indefinitely is itself a compliance problem, while deleting records that must be retained for employment or tax purposes creates a different one. The two sets of rules have to be reconciled deliberately, which is easier with a retention schedule than case by case.
Employee data compliance almost never arrives on its own. It surfaces in a labour inspection, in diligence on a sale, or when a group audit asks whether the Russian entity meets local standards — which is why it belongs with the employment file rather than in an IT backlog.
Planning an HR system rollout? Localisation is far cheaper to design in than to retrofit once the platform is live.
Practical support for international business in Russia.