Russian 152-FZ personal data law for foreign companies: data localisation, Roskomnadzor registration, cross-border transfer rules and penalties.
The legal framework: 152-FZ and who it applies to
Data localisation: storing Russian personal data in Russia
Roskomnadzor registration and notification
Cross-border data transfers: the new rules
Practical compliance steps for foreign companies
Federal Law No. 152-FZ "On Personal Data" (2006, significantly amended in 2022–2023) is Russia's primary personal data protection law. It applies to any organisation that processes personal data of Russian citizens — regardless of whether the organisation is based in Russia or abroad.
Foreign companies with a Russian subsidiary automatically fall under 152-FZ through their subsidiary's operations. But foreign companies without a Russian presence — including those operating under agency arrangements, selling goods or services to Russian consumers online, or employing Russian remote workers — may also fall under 152-FZ if they process personal data of Russian citizens.
Since September 2022, the law has been significantly strengthened: higher fines, mandatory notification of Roskomnadzor for data breaches, and stricter enforcement of the data localisation requirement.
Article 18.1 of 152-FZ requires that the initial collection and recording of personal data of Russian citizens be performed on servers located in Russia. This is the "data localisation" requirement — one of the most contentious aspects of Russian personal data law.
Employee HR records (salaries, addresses, passport data) must be stored on Russian servers first
Customer databases for Russian customers must be initialised on Russian servers
A copy of the data can subsequently be transferred abroad for processing — but the primary copy must remain in Russia
Companies that use international HR, CRM or ERP systems (SAP, Oracle, Workday, Salesforce) must ensure that Russian employee and customer data is either stored in Russian data centres or that the system vendor has a Russian data residency option enabled.
Violations of the localisation requirement can result in the Russian regulator (Roskomnadzor) blocking access to a company's Russian website — as happened with LinkedIn in 2016 (still blocked) and several other platforms.
Most organisations that process personal data in Russia must register as a "personal data operator" with Roskomnadzor. Registration is done through the Roskomnadzor information system.
Categories of personal data processed (employees, customers, contractors)
Purposes of processing
Legal basis for processing
Location of servers (Russian and foreign)
Cross-border transfer destinations (if any)
Data retention periods
Since September 2022, companies must also notify Roskomnadzor within 24 hours of discovering a personal data breach, and provide a detailed report within 72 hours.
Failure to register is an administrative offence with fines up to RUB 100,000. Repeated violations carry higher penalties.
Amendments to 152-FZ effective from September 2023 significantly changed the cross-border transfer regime. Transferring personal data of Russian citizens to foreign recipients (including parent companies abroad) is now subject to:
Prior notification to Roskomnadzor — before the first transfer to each foreign recipient, the Russian entity must notify Roskomnadzor with details of the recipient, the data categories, and the legal basis
Roskomnadzor's response period — the regulator has 10 business days to prohibit the transfer or request additional information. Transfer can proceed if no prohibition is received
Permitted destinations — transfers to countries that have ratified Council of Europe Convention 108 are generally permitted. Russia maintains a separate "white list" of countries providing adequate data protection
Standard data transfer agreement — transfers to countries not on the white list require a data transfer agreement that meets Roskomnadzor's requirements
Practical support for international business in Russia.