Most foreign companies meet 152-FZ through a customer project. The obligation usually arrived earlier — with an employment contract, a passport copy and a bank account. Until 2025 that was a documentary irritation. Since penalties moved to a turnover basis, it is a board-level number.
Notify Roskomnadzor of the intention to process. Since 2025 the omission is separately punishable — and trivially easy to establish.
An internal processing policy in Russian, consents where consent is the basis, and records of what is held and for how long.
Personal data of Russian citizens recorded and stored in databases located in Russia — an architecture question, not a policy one.
24 hours to notify a breach, 72 to report the investigation. The clock starts at discovery.
Amendments in force from 30 May 2025 moved leaks onto a graded scale, with turnover-based penalties for larger companies on repeat incidents. Separately, failing to notify the regulator of an intention to process became its own violation, and special categories — health, religion, nationality, criminal record — and biometric data attract higher penalties than ordinary data.
The practical consequence for a foreign group is that Russian data compliance moved from a local administrative matter to something a parent company's risk function asks about. Usefully, the documentation that satisfies a Russian inspection is largely what a group audit wants to see anyway.
Penalty ranges have moved repeatedly — figures should be confirmed against the current text rather than a summary
None of these is a story of a company behaving badly. They are what happens when a business grows into obligations nobody was watching for — which is also why they are inexpensive to close before anyone asks.
Years of processing employee data without ever telling Roskomnadzor. Since 2025, punishable on its own.
The first thing asked for in any interaction with the regulator, and frequently absent.
A global HR or CRM platform with no Russian-resident primary database.
A translated group form that does not meet the statutory requirements here.
Nobody authorised to file within 24 hours, and no tested way of doing it in Russian.
Vendors who hold your data but are not required to tell you fast enough to meet your own deadline.
What you process, what you have filed and where the exposure sits — with a plain read on what each gap risks.
Roskomnadzor registration, the Russian-language document set, consent forms, and advice on localisation architecture.
Keeping the register entry current as processing changes, refreshing consents, reviewing processor contracts — on a fixed monthly fee.
The 24-hour and 72-hour filings drafted and submitted, and the correspondence that follows handled for you.
If you process personal data of individuals in Russia, the law treats you as an operator whatever your place of incorporation. Whether a penalty can practically be enforced against a company with no local presence is a separate question from whether the obligation exists — and a group with a Russian subsidiary, branch or employees has very direct exposure through those.
No, and this is the most common misconception we meet. Employment records are personal data and an employer is an operator: passport copies, bank details, medical certificates and emergency contacts all count. Foreign companies that assume the regime is about consumer-facing businesses are among those most often caught out, precisely because they never considered themselves in scope.
Not automatically, but it needs looking at. The requirement is that personal data of Russian citizens is recorded, systematised and stored in databases located in Russia. A global platform can be arranged compliantly — typically with a Russian-resident database as the primary record feeding the group system — but the architecture has to be designed for it. Retrofitting is materially harder than building it in.
Since 2025 failing to notify the regulator of an intention to process personal data is a violation in its own right, with a substantial fixed penalty, and it is trivially easy to establish — either you are on the register or you are not. It is much better addressed voluntarily than found. The sequencing matters: the register entry describes what you process, so it is worth being clear about your actual data flows before filing.
Within 24 hours of discovering it, with a follow-up report on your internal investigation within 72 hours. The clock runs from discovery, not from the incident, which in practice often means a Friday evening discovery is due before Monday. Court practice shows prompt notification supporting warnings rather than fines — late notification is a separate violation stacked on top of the original one.
Both, in sequence. Getting registered, documented and localised is a defined piece of work. Staying compliant is not: processing changes as the business does, the register entry has to keep pace, consents need refreshing, and an incident can arrive on any Friday. Most clients do the first as a project and keep the second on a retainer.
That question has a yes-or-no answer and it takes minutes to establish. So do most of the others. Tell us what you process and we will tell you what is missing.
ex-Big Four team · Moscow · since 2018 · © TaxWell & Partners
Practical support for international business in Russia.