Data protection (privacy) laws in Russia

Data protection (privacy) laws in Russia are a rapidly developing branch in Russian legislation that have mostly been enacted in the 2005 and 2006.[1] The Russian Federal Law on Personal Data (No. 152-FZ), implemented on July 27, 2006, constitutes the backbone of Russian privacy laws and requires data operators to take "all the necessary organizational and technical measures required for protecting personal data against unlawful or accidental access".[2] Amendment was signed on December 20, 2020 and came into effect on March 1, 2021. The amendment requires "personal data made publicly available" needs to receive consent from the data subject.[3] Russia's Federal Service for Supervision of Communications, Information Technology and Mass Media is the government agency tasked with overseeing compliance.[4]

Applicable laws

  • Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, signed and ratified by the Russian Federation on December 19, 2005;[5]
  • the Law of the Russian Federation “On Personal Data” as of 27.07.2006 No. 152-FZ, regulating the processing of personal data by means of automation equipment. It is the operator who is required to comply with that Act;
  • the “Regulations on securing personal data being processed in personal data systems” enacted by the Russian Government Regulation as of 17.11.2007 No. 781. The Regulations contain mandatory security regulations to be complied with when processing and storing personal data;
  • the Federal law “On Advertisement” as of 13.03.2006 No. 38-FZ. This regulates marketing communications sent inter alia by electronic means including e-mail, SMS etc.;
  • the Russian Code on Administrative Infractions dated 30.12.2001 No.195-FZ. This regulates issues of responsibility for commission of administrative offences in connection with processing of personal data or distribution of marketing communications.

Definitions

  • personal data is any information related to identified or identifiable on the basis of such information individual (personal data subject), including last name, given name, patronymic, date, month, year and place of birth, address, family, social, property status, education, profession, income, other information;[6]
  • sensitive personal data means personal data relating to:
    • Race or ethnic origin
    • Political opinions
    • Religious beliefs
    • Health condition
    • Sexual life
  • processing is anything that can be done to or with personal data, including obtaining, organizing, accumulating, holding, adjusting (updating, modifying), using, disclosing (including transfer), impersonating, blocking or destroying such data;
  • operator is an entity which organizes and/or performs data processing, as well as determines the purposes and manner of data processing. In most cases both mother company and an entity which manages the relevant facility or service offered will be operators;
  • personal data system is a data system which includes personal data recorded in the data base as well as information technologies and technical equipment which make possible processing of such data.

Basic rules contained in the applicable legislative acts

Consent of the individual is required for processing of his personal data. This rule doesn't apply where such processing is necessary for performance of the contract, to which an individual is a party.

One shall bear in mind that a personal data subject is entitled at any time to revoke his previously granted consent, which obliges the operator to stop processing of such personal data and destroy it within three business days (unless other period of time was agreed on by the operator and an individual) after the date of such revocation, and notify the personal data subject of the fact that his personal data has been destroyed.

More specifically, processing of personal data for the purpose of direct marketing may be performed subject to prior consent of personal data subjects. Lack of such consent is presumed unless the operator proves the contrary. Processing of personal data for the purposes indicated above must be immediately ceased at the demand of personal data subject.

At the time of obtaining of personal data the operator is obliged, subject to request of an individual, to communicate to the latter information relating to the operator and the process of prospective processing.

If personal data is obtained not directly from a personal data subject, the operator prior to processing such information must provide the individual with the following information:

  • name and address of the operator or his representative;
  • purpose and legal grounds of personal data processing;
  • expected users of personal data; and
  • the rights of the individual in accordance with federal law “On Personal Data” dated 27.07.2006 No. 152-FZ.

Generally, it is prohibited to process in any way sensitive personal data of the individual, save for the cases where express written consent, containing all conditions provided for by the law, has been obtained from the individual prior to processing.

Generally, to transfer personal data outside the Russian Federation, the operator will have to make sure, prior to such transfer, that the rights of personal data subjects will enjoy adequate and sufficient protection in the country of destination.

Until 1 September 2015 the position of Federal Service on Telecommunications the governmental body responsible for personal data protection was that adequate and sufficient protection exists only in those foreign states which signed and ratified Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data. Nevertheless, there are three major exceptions which permit transfer of personal data to the countries where lower or no standard of personal data protection applies, namely:

  • When transfer is necessary for performance of a contract to which an individual is a party
  • When a personal data subject gave his prior written consent, containing all conditions provided for by the law, to such transfer
  • When transfer is necessary for performance by the Russian Federation of its obligations under international agreement on readmission

On 1 September 2015 a new "Article 18 (5)" came into effect more strictly limiting the export of data. [7]

The Russian legislation imposes strict limitations on using of the electronic means of communication for direct marketing. Namely, express consent should be obtained from the individual before marketing communications are sent to him by email or SMS. Lack of such prior consent is presumed unless the sender proves the contrary. The law provides for immediate cessation of sending marketing communications at the individual’s short notice. It should be also noted that in Russia it is expressly prohibited to send emails or SMS messages using autodial.

To send marketing communications by post, operator must obtain specific permission from the Federal Service on Telecommunications. Unfortunately the procedure of obtaining of such permission hasn’t been established yet.

Where personal data is processed it should be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.

Personal data being processed shall enjoy confidential regime. It implies employment by the operator of sufficient technical and organisational means designed to prevent unauthorised access of any third parties to processed personal information. Procedures (including issuance of internal regulations or decrees) must be in place to regulate the process of access to such confidential information.

Personal data should be accurate and kept up to date where necessary. The operator is obliged to ensure accessibility of personal information for examination by personal data subjects at their request. In case such subjects find that this information is outdated or inadequate, the operator will be obliged to stop processing of such information until the required modifications are introduced.

Personal data should not be kept for longer than is necessary for the purposes for which they are processed, which requires its destruction after such purposes have been fulfilled or in case their fulfillment is not required any more.

Personal data must be processed in accordance with the rights of personal data subjects under applicable data protection legislation. An operator will be in breach of this principle if, amongst other things, he:

  • contravenes the rights of access provisions set out in the legislation;
  • fails to comply with a request to cease processing within the time limit specified by the law or agreed on by the parties.

Procedures must be in place to ensure that computer systems are configured appropriately to allow accurate recording of the giving of consents in all relevant cases, described herein. Procedures must also be in place to ensure that any notices or requests are responded to and dealt with promptly.

Appropriate technical and organization measures must be taken against unauthorized or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data. Operators should consider appropriate measures to ensure data integrity (for electronic processing), including the installation of virus protection software and firewalls, adopting encryption for data transfers, using privacy enhancing technologies and making regular backups that are securely stored. For manual processing, consideration should be given to appropriate security measures, such as storage of paper records in lockable, fire-proof cabinets.

The relevant provisions require effective protection of personal data. Mandatory regulations on protection of such data are currently being developed by Federal Security Service (hereinafter, the “FSS”) to be issued within two months. For the moment, according to information received from FSS specialist during telephone consultation, FSS has a preliminary draft of the said regulations which may be modified as the final version of said regulations is to be issued within two months. The draft in its current version provides for protection of all personal data being transferred outside Russia in form of encryption. It is worth mentioning, that for the time being, it is practically possible to use only Russian encryption software and equipment for that purpose.

Individual rights

The legislation gives certain rights to personal data subjects in respect of personal data held about them. These include:

  • a right of access to information relating to operator and to the processed personal data;
  • a right to demand cessation of processing, blocking or modifying of the personal data which have been illegally obtained, are inadequate or outdated; and
  • a right to demand immediate cessation of processing for the purposes of direct marketing.

Personal data categories

The legislation describes certain personal data categories:[8]

  • Public - personal data obtained only from publicly available personal data sources created in accordance with art. 8 of The Russian Federal Law on Personal Data (No. 152-FZ)
  • Biometric - information that characterizes the physiological and biological characteristics of a person on the basis of which it's possible to establish his personality and which are used by the personal data operator to identify the subject of the personal data.
  • Special - personal data relating to race, ethnic origin, political opinions, religious beliefs, health condition, sexual life of personal data subjects.
  • Other - personal data that doesn't belong to any of the above categories (public, biometric, special).

Notification

Operators to whom Russian legislation applies are required to send notification to the territorial body of Russian Federal Service on Supervision over Mass Communications, Telecommunications and Preservation of the Cultural Heritage (hereinafter, the “Federal Service on Telecommunications”) for each region of Russia where he possesses personal information processing facilities. For Moscow it will be Moscow Department of the above mentioned federal service. Such notification is necessary for inclusion of the operator into specific Register and shall be made by the operators who have been processing personal information prior to enactment of the Federal law “On Personal Data” dated 27.07.2006 and continue to process it after its enactment prior to January 1, 2008. Those operators who haven’t been engaged in processing of personal information using their own or third party’s equipment located in Russia prior to enactment of the said law must send the notification before they actually start processing personal data. It is important that the said notification contain information provided for by the applicable legislation.

Jurisdiction

Scope of application of Russian Data Protection legislation: Russian laws apply when the operator uses his own or third-party data processing equipment located in Russia. As well as in cases where the data has been already transferred outside Russia, but there has been a violation of personal data subject’s rights prior to or during such transfer. If the data is transferred outside Russia duly, it will be subsequently regulated by the laws of country of destination and implications of Russian law will not apply thereto.

In most cases, the Federal Service on Telecommunications only has jurisdiction in relation to data held or processed in Russia. Nevertheless, the legal implications of the Russian legislation on data protection will apply in respect of the data already transferred outside Russia in case the rights of individuals, whose personal data has been collected and processed using equipment located in Russia, have been violated prior to or during such transfer (e.g., an operator transferred personal data to a country where personal data don’t enjoy adequate protection without prior written consent of a data subject). In that case the Federal Service on Telecommunications may file lawsuits against operators to protect the rights of the personal data subjects and impose respective fines for violation of the data protection legislation.

See also

References

  1. ^ Arievich, Pavel (1 June 2012). "Data protection in Russian Federation: Overview". Practical Law Company.
  2. ^ "English Translation of the Russian Federal Law on Personal Data Protection". International Association of Privacy Professionals.
  3. ^ "New regulations for processing publicly available personal data". International Law Office. 2021-01-29. Retrieved 2021-04-09.
  4. ^ Sotto, Lisa J. (August 2008). "Russia Launches a Data Protection Website" (PDF). Hunton & Williams.
  5. ^ See. the Federal law "On Ratification of the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data" as of 19.12.2005 N 160-FZ
  6. ^ Law of the Russian Federation “On Personal Data” as of 27.07.2006 No. 152-FZ, Article 3
  7. ^ Karpukhin, Alexander E.; Sivkova, Daria A. (November 2017). "How to comply with the Russian requirements on localisation of personal data". Financier Worldwide.
  8. ^ Bessonov, Evgeny (2017). "Personal data categories with IT infrastructure example in compliance with Federal Law No.152". Cloud4Y.

Read other articles:

Valvatida Solaster stimpsoni Klasifikasi ilmiah Domain: Eukaryota Kerajaan: Animalia Filum: Echinodermata Kelas: Asteroidea Superordo: Valvatacea Ordo: ValvatidaPerrier, 1884 Famili Lihat teks Valvatida merupakan salah satu ordo bintang laut. Ordo ini terdiri dari 695 spesies bintang laut yang tersebar dalam 172 genus dan dalam 17 famili.[1] Deskripsi Fisik Ordo ini mencakup spesies bintang laut kecil yang diameternya hanya beberapa milimeter seperti spesies dalam genus Asterina, dan ...

 

Енен-ле-БузонвільHeining-lès-Bouzonville   Країна  Франція Регіон Гранд-Ест  Департамент Мозель  Округ Форбак-Буле-Мозель Кантон Бузонвіль Код INSEE 57309 Поштові індекси 57320 Координати 49°18′36″ пн. ш. 6°35′22″ сх. д.H G O Висота 223 - 336 м.н.р.м. Площа 6,03 км² Населення 481 (01-2020&#...

 

2016年夏季奥林匹克运动会阿塞拜疆代表團阿塞拜疆国旗IOC編碼AZENOC阿塞拜疆共和國國家奧林匹克委員會網站www.olympic.az(阿塞拜疆文)(英文)2016年夏季奥林匹克运动会(里約熱內盧)2016年8月5日至8月21日運動員56參賽項目14个大项旗手开幕式:泰穆尔·马马多夫(拳击)[1][2]闭幕式:哈吉·阿利耶夫(摔跤)[3]獎牌榜排名第39 金牌 銀牌 銅牌 總計 1 7 10 18 历...

هذه المقالة يتيمة إذ تصل إليها مقالات أخرى قليلة جدًا. فضلًا، ساعد بإضافة وصلة إليها في مقالات متعلقة بها. (يوليو 2020) متحف أديتاورمان   إحداثيات 0°57′19″S 100°21′21″E / 0.95525°S 100.35583333333°E / -0.95525; 100.35583333333  معلومات عامة الدولة إندونيسيا[1]  سنة التأسيس 1974  تار

 

Hachette Librería Hachette, alrededor de 1880.Tipo grupo de comunicacionesIndustria ediciónpaper and publishing industryedición de librosForma legal public limited company with a board of directors (n.o.s.)Fundación 1826Fundador Louis HachetteSede central XV Distrito de París (Francia), París (Francia) y Vanves (Francia)Productos softwarelibrorevistaEmpresa matriz Lagardère Publishing y Grupo LagardèreMiembro de World Wide Web ConsortiumFiliales Hachette BooksHodder & StoughtonLib...

 

  لمعانٍ أخرى، طالع روس كينغ (توضيح). روس كينغ معلومات شخصية الميلاد 19 فبراير 1919  بورتاج لابريري  الوفاة 6 يونيو 1972 (53 سنة)   بورتاج لابريري  مواطنة كندا  الحياة العملية المهنة لاعب هوكي الجليد  الرياضة هوكي الجليد  تعديل مصدري - تعديل   روس كينغ هو لاعب...

Metropolitan borough council ward in Liverpool, England 53°21′32″N 2°55′01″W / 53.359°N 2.917°W / 53.359; -2.917 Human settlement in EnglandGrassendale and CressingtonGrassendale (1980–2004)Cressington (2004-2023)Grassendale and Cressington ward within LiverpoolPopulation5,832 (2021 census)Registered Electors4,635 (2023 election)Metropolitan boroughCity of LiverpoolMetropolitan countyMerseysideRegionNorth WestCountryEnglandSovereign st...

 

1969 studio album by Alan SilvaSkillfulnessStudio album by Alan SilvaReleased1969RecordedNovember 1968StudioNew York CityGenreFree jazzLabelESP-DiskESP 1091Alan Silva chronology Skillfulness(1969) Luna Surface(1969) Reissue cover Skillfulness (also released as Skillfullness) is an album by multi-instrumentalist Alan Silva. It was recorded in November 1968 in New York City, and was released in 1969 by ESP-Disk. On the album, Silva is joined by flutist Becky Friend, pianist Dave Burrell...

 

German composer (1821–1894) Postage stamp showing Louis Lewandowski Louis Lewandowski (April 3, 1821 – February 4, 1894) was a Polish-Jewish and German-Jewish composer of synagogal music. Louis Lewandowski He contributed greatly to the liturgy of the Synagogue Service. His most famous works were composed during his tenure as musical director at the Neue Synagoge in Berlin and his melodies form a substantial part of synagogue services around the world today. Life Lewandowski was born in Wr...

Riverine lake in North IslandLake KimihiaLake Kimihia from Waikato Expressway in 2021Lake KimihiaLocationNorth IslandCoordinates37°31′30″S 175°11′30″E / 37.52500°S 175.19167°E / -37.52500; 175.19167Typeriverine lakeCatchment area1,485 ha (3,670 acres)Basin countriesNew ZealandMax. length1.1 km (0.68 mi)Max. width0.4 km (0.25 mi)Surface area0.55 km2 (140 acres)Average depth3.3 m (11 ft) Lake Kimihia is located app...

 

1994 shooting massacre in Hebron Cave of the Patriarchs massacrePart of Israeli settler violenceThe compound in 2009Hebronclass=notpageimage| Location of Hebron within the West BankShow map of the West BankHebronclass=notpageimage| Location of Hebron within the de jure State of PalestineShow map of State of PalestineLocationHebron, West BankCoordinates31°32′00″N 35°05′42″E / 31.53333°N 35.09500°E / 31.53333; 35.09500DateFebruary 25, 1994; 29 ye...

 

Local government area in Tasmania, AustraliaDerwent Valley CouncilTasmaniaMap showing the Derwent Valley local government area.Coordinates42°48′46″S 146°25′22″E / 42.8129°S 146.4227°E / -42.8129; 146.4227Population10,290 (2018)[1] • Density2.5049/km2 (6.488/sq mi)Established2 April 1994[2]Area4,108 km2 (1,586.1 sq mi)[1]MayorMichelle DracoulisCouncil seatNew NorfolkRegionUpper Derwent River regionState...

Анімалькулізм (від лат. Animalculum — звірок, мікроскопічна тварина) — один із напрямків преформізму, зародився в XVII-XVIII століттях, прихильники якого (А. Левенгук, Н. Гартсекер, Йохан Ліберкюн та ін.) вважали, що в сперматозоїдах міститься невидима доросла тварина, а її розв...

 

2008 collection of stories by H. P. Lovecraft This article has multiple issues. Please help improve it or discuss these issues on the talk page. (Learn how and when to remove these template messages) This article does not cite any sources. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: Necronomicon: The Best Weird Tales of H. P. Lovecraft: Commemorative Edition – news · newspapers&...

 

Kenyan journalist and writer This article has multiple issues. Please help improve it or discuss these issues on the talk page. (Learn how and when to remove these template messages) This article is an orphan, as no other articles link to it. Please introduce links to this page from related articles; try the Find link tool for suggestions. (December 2015) This biography of a living person needs additional citations for verification. Please help by adding reliable sources. Contentious material...

Delta PawanKecamatanDelta PawanPeta lokasi Kecamatan Delta PawanTampilkan peta KalimantanDelta PawanDelta Pawan (Indonesia)Tampilkan peta IndonesiaKoordinat: 1°50′40″S 109°58′43″E / 1.844569°S 109.978555°E / -1.844569; 109.978555Koordinat: 1°50′40″S 109°58′43″E / 1.844569°S 109.978555°E / -1.844569; 109.978555Negara IndonesiaProvinsiKalimantan BaratKabupatenKetapangPemerintahan • CamatPitriyadi, S.Hut., M...

 

Australian actor (born 1938) Ian SmithSmith in 2001Born (1938-06-19) 19 June 1938 (age 85)Melbourne, Victoria, AustraliaOther namesIain SmithOccupationsActortelevision producerscreenwriterYears active1958–presentKnown forNeighbours as Harold BishopNotable workPrisoner (known internationally as Prisoner: Cell Block H - Executive Producer Screenwriter - ActorSpouseGail Smith Ian Smith (born 19 June 1938)[1] is an Australian actor, television producer and screenwrit...

 

This article relies excessively on references to primary sources. Please improve this article by adding secondary or tertiary sources. Find sources: Anglican Diocese of Belize – news · newspapers · books · scholar · JSTOR (October 2014) (Learn how and when to remove this template message) St John's Cathedral, Belize City Arms of the Diocese of Belize The Anglican Diocese of Belize was established in 1883.[1] The current bishop is Philip Wright....

American anthropologist This article has multiple issues. Please help improve it or discuss these issues on the talk page. (Learn how and when to remove these template messages) This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: George S. Metcalf – news · newspapers · books · scholar · JSTOR (November 2023) (Le...

 

Artikel ini sebatang kara, artinya tidak ada artikel lain yang memiliki pranala balik ke halaman ini.Bantulah menambah pranala ke artikel ini dari artikel yang berhubungan atau coba peralatan pencari pranala.Tag ini diberikan pada Maret 2016. SMA Negeri 1 BuruInformasiJurusan atau peminatanIPA dan IPSRentang kelasX IPA, X IPS, XI IPA, XI IPS, XII IPA, XII IPSKurikulumKurikulum 2013AlamatLokasiJl. Jiku Besar 01, Namlea, MalukuMoto SMA Negeri (SMAN) 1 Buru, merupakan salah satu Sekolah Menengah...

 

Strategi Solo vs Squad di Free Fire: Cara Menang Mudah!