What Is Federal Law No. 152-FZ "On Personal Data"?
The Russian Federation’s operative framework is Federal Law No. 152-FZ "On Personal Data," adopted in 2006. The current consolidated text reflects amendments through 24 June 2025, including changes concerning anonymized personal-data datasets, special-category and biometric data, cross-border transfers, minors’ data, protected-person processing, consent, and information exchange. FZ-420 substantially increased administrative penalties effective 30 May 2025, and an Article 10 amendment under FZ-200 has a future effective date of 1 March 2027. No 2026 federal law directly amending 152-FZ was located in the official publication search. The law has an unusually explicit public-source removal right: personal data in directories and address books must be removed at the subject’s request at any time. Article 10.1 also permits a subject to stop dissemination, provision, or access for data authorized for dissemination. However, no Russia-specific data-broker complaint portal or distinct public-record or broker-specific deletion procedure was located.
At a glance
- Full name
- Federal Law No. 152-FZ "On Personal Data"
- Short code
- 152-FZ
- Jurisdiction
- Russian Federation
- Enacted
- 2006
- Last major update
- Current consolidated text reflects amendments through 24 June 2025; FZ-420 substantially increased administrative penalties effective 30 May 2025, while an Article 10 amendment under FZ-200 is effective 1 March 2027. No 2026 federal law directly amending 152-FZ was located.
- Regulator
- Roskomnadzor
- Private right of action
- Yes
Scope, who 152-FZ covers
Protected data
Data subject rights
Right to give free, specific, informed, conscious, and unambiguous consent and withdraw consent
Right to request removal of personal data from public sources, including directories and address books, at any time
Right to information, inspection, correction, blocking, and destruction of incomplete, outdated, inaccurate, unlawfully obtained, or unnecessary data
Right to stop direct marketing or political agitation immediately on request after the required prior-consent framework
Protection against qualifying solely automated decisions with legal or similarly significant effects, subject to written consent or a federal-law basis with safeguards
Right to an explanation of automated processing, its consequences, the objection route, and applicable protections
Right to stop dissemination, provision, or access for data previously authorized for dissemination upon a compliant request
Right to complain directly to Roskomnadzor’s authorized body or go directly to court
Right to seek damages and compensation for moral harm
Notable features
The strongest distinctive feature located is Article 8’s general public-source removal right for directories and address books, together with Article 10.1’s dissemination-stop mechanism. The framework also combines data localization, prior cross-border-transfer notification, Roskomnadzor transfer controls, concrete operator deadlines, and a substantially increased penalty schedule effective 30 May 2025.
Enforcement & penalties
Regulator: Roskomnadzor
Penalties: Under Code of Administrative Offenses Article 13.11 as amended by FZ-420, localization violations may result in ₽800,000-1,000,000 for officials and ₽6,000,000-18,000,000 for legal entities. Breach-notification failures may result in ₽50,000-100,000 for individuals, ₽400,000-800,000 for officials, and ₽1,000,000-3,000,000 for legal entities. Unlawful transfers involving 1,000-10,000 subjects may result in ₽100,000-200,000 for individuals, ₽200,000-400,000 for officials, and ₽3,000,000-5,000,000 for legal entities, scaling up to ₽300,000-400,000 / ₽400,000-600,000 / ₽10,000,000-15,000,000 for 100,000 or more subjects. Unlawful special-category transfer may result in ₽300,000-400,000 for individuals, ₽1,000,000-1,300,000 for officials, and ₽10,000,000-15,000,000 for legal entities.
Private right of action: Article 17 permits a data subject to go directly to court, including for damages and compensation for moral harm, without first using the Roskomnadzor complaint route. Article 17 also permits complaints to the authorized body.
Relevance to data brokers
No Russia-specific data-broker complaint portal or distinct public-record/broker-specific deletion procedure was located. The available general mechanisms are Article 8 public-source removal, Article 10.1 dissemination-stop rights, and the general Roskomnadzor complaint route under Articles 17 and 23.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Can personal data be removed from Russian public sources?+
Yes. Article 8 provides that personal data in public sources such as directories and address books must be removed at the subject’s request or by court or authorized-government decision, at any time.
Does Russia have a dedicated data-broker complaint channel?+
Not located. General Article 8 and Article 10.1 rights together with complaints to Roskomnadzor or direct court action are the identified mechanisms, but no distinct broker-specific procedure.
How quickly must an operator respond to a data request?+
Several operator deadlines apply: generally 10 working days for access or information requests, 7 working days for correction after verification, up to 3 days to stop unlawful processing, and up to 10 days to destroy data that is unlawful and cannot be legalized.
Official sources & citations
Other international privacy regimes
152-FZ sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
