13. Personal data protection

Data Protection Law

The Data Protection Law is the main law regulating personal data protection in Russia.
Some of its provisions are based on the 1981 Strasbourg Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data that Russia signed on 7 November 2001.
The Data Protection Law defines personal data and data processing, regulates the rights of data subjects and the obligations of data controllers, consent rules, data localisation and cross-border data transfer.

Extraterritorial principle

The Personal Data Law applies to foreign companies if they process personal data of Russian citizens on the basis of agreement with a data subject or consent of a data subject.

Supervisory authority

The Federal Service for Supervision of Communications, Information Technology and Mass Media (“Roskomnadzor”) is in charge of personal data protection in Russia.

Personal data

The Data Protection Law does not contain an exhaustive list of data that is deemed to be “personal data”. Personal data is any information referring directly or indirectly to an identified or identifiable individual (the “data subject”), which is a common approach worldwide. What constitutes personal data must be assessed on a case-by-case basis.
The Data Protection Law also sets forth special categories of personal data. Those include racial or ethnic origin, political opinions, religious or philosophical beliefs, personal health, sex life and criminal record. In addition, the processing of biometric data is regulated by the Data Protection Law and the Federal Law No. 572 dated 29 December 2022.
The Data Protection Law does not apply to personal data processing performed by individuals for their private needs.

Rights of data subjects

A data subject has the right to:
· Request details of processing of their personal data;
· Revoke the consent to data processing at any time;
· Object to data processing;
· Request, in certain cases, rectification, blocking or deletion of their personal data; and
· Be compensated for damages, including moral damages.

Legal basis for data processing

Personal data may be processed on the following legal basis¹:
· Consent;
· Statutory obligation;
· Agreement with a data subject;
· Processing in the course of judicial procedure;
· Legitimate interests; or
· Vital interests of a data subject.
Consent is one of the most reliable grounds for data processing. It must be specific, informed, conscious, substantive, unambiguous, and can be given in any form.

1 The list is not exhaustive, it only demonstrates the most common legal grounds.

Written consent

A written consent must be obtained when:
· Special categories of personal data or biometrics are processed;
· Decisions in relation to a data subject are taken automatically potentially affecting the rights and freedoms of a data subject; and
· Employees’ personal data is transferred to a third party, including companies of the same group.
Such consent must contain certain elements, including:
· The name, address and passport details of the data subject;
· The name and address of the personal data controller;
· The purpose of data processing and the list of data to be processed;
· The list of operations with personal data; and
· The term of processing.
The law also requires separate and specific consent to dissemination of personal data.

Cross-border transfer of personal data

Cross-border transfer of personal data is subject to mandatory prior notification.
In case the recipient is located in a country that is not on the list of countries providing “adequate” protection of personal data (maintained by Roskomnadzor), information on data protection legislation of such country must also be obtained.
The data controller must notify Roskomnadzor of its intention to transfer personal data across borders and provide detailed information on the planned transfer, including the type and content of the data to be transferred, the categories of data subjects, countries where such data will be transferred, etc.
Roskomnadzor has a right to prohibit or restrict the transfer of personal data.

Rules for biometrics processing

Processing specific biometric personal data outside the Unified Biometric System (UBS) is prohibited.
The UBS was created by Federal Law No. 572 dated 29 December 2022, which also regulates procedures for identification and authentication of individuals using biometric personal data.
The UBS currently includes the following types of biometric personal data:
· an image of a person;
· a record of a person’s voice.
Biometric data for identification and authentication purposes may only be stored in the UBS.
Identification based on biometric data can only be performed by the operator of the UBS – the Centre of Biometric Technologies.
Authentication using the data contained in the UBS can be carried out either by the Centre of Biometric Technologies or by organisations authorised by it.
Companies must not independently carry out identification or authentication based on biometrics.

Data controllers and data processors

The Data Protection Law defines the data controller as an entity (either a state agency, municipal authority or a legal entity) or individual who organises processing or processes personal data. It also determines the purposes and scope of processing, the content of personal data to be processed, and actions to be performed with the data.
Main obligations of data controllers
Data controllers must:
· Notify Roskomnadzor of their intention to process personal data;
· Ensure personal data security;
· Adopt a personal data processing policy which includes the list of data, the purposes of data processing, etc.;
· Appoint a data protection officer responsible for the organisation of data processing within the company;
· Periodically perform internal audits and assessments of the effectiveness of protection of personal data;
· Ensure compliance with the personal data localisation rules; and
· Comply with data breach notification requirements.

Protection

Personal data must be protected against unauthorised access, alteration, transfer, disclosure by transfer or deletion, as well as from damage and accidental destruction. To ensure the security of personal data, the data controller must, in particular:
· Use technical devices certified by the competent Russian authorities and keep a record of the devices on which personal data is stored;
· Detect unauthorised access to personal data and detect, prevent and eliminate the consequences of computer attacks on personal data information systems;
· Assess the level of damage which may be caused by unauthorised processing of personal data; and
· Establish rules of access to personal data.
The Law also requires the controller to interact with the State System of Detection, Prevention and Elimination of Consequences of Computer Attacks on Information Resources (GosSOPKA). The aim is to inform GosSOPKA about computer incidents that have led to unlawful transfer of personal data.

Localisation requirements

Localisation requirements apply to data controllers (including foreign data controllers if they process the personal data of Russian citizens) and to data processors.
Using databases located outside of Russia for collection of the Russian citizens’ personal data, including via the internet, recording, systemisation, accumulation, storage, clarification (updating, modification), and retrieval of Russian citizens’ personal data is prohibited. Limited exceptions to this requirement do not apply to businesses. Data controllers are usually required to disclose the location of the database containing Russian citizens’ personal data to Roskomnadzor.

Outsourcing

Data controllers may outsource processing of personal data on the basis of an agreement with a data processor. Such agreement must contain certain substantial terms and conditions set out by the Data Protection Law. Data controllers nevertheless remain responsible to data subjects for the fulfilment of their obligations. Data processor must ensure confidentiality and protection of personal data.

Data leak notification

If an operator discovers a data leak, it shall file two notifications to Roskomnadzor:
· Within 24 hours – a notice of the incident stating suspected causes and measures taken to mitigate the consequences of the incident;
· Within 72 hours – a report on the results of the internal investigation and persons responsible for the incident (if any).
Failure to file these notices is subject to an administrative fine from RUB 1m to 3m. The leak itself is subject to additional penalties depending on the number of data subjects affected.

Administrative liability

If a data controller has violated the requirements of the Data Protection Law, Roskomnadzor may:
· Require the data controller to rectify the violation(s);
· Issue a warning to the data controller; or
· Impose fines, which can be quite severe administrative fines.

Civil law claims

Data subjects may also file a court action against a data controller to seek compensation for damages caused by illegal processing of personal data.

Criminal law issues

In severe cases, unlawful data processing may also be deemed as crime of illegal collection and distribution of information on private life. The Russian Criminal Code provides that such violations are punishable with a fine, compulsory works or imprisonment.