Russia Federal Law on Personal Data (152-FZ)
Russia's Federal Law No. 152-FZ on Personal Data (2006, as amended through 2023) regulates the processing of personal data in the Russian Federation. Roskomnadzor (Federal Service for Supervision of Communications) oversees compliance. Key requirements include data localisation (personal data of Russian citizens must be stored on servers in Russia), consent management, and breach notification. Significant amendments in 2022-2023 strengthened enforcement and increased penalties.
Russia Federal Law on Personal Data (152-FZ) is a compliance framework from Russia with 16 domains and 28 controls that map to 103 other frameworks. The largest domains are Breach Notification, Inspection and Liability (4 controls), Consent and Lawful Basis (3 controls), Localisation and Cross-Border Transfer (3 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (16)
Breach Notification, Inspection and Liability
Breach Notification, Inspection and Liability
| Code | Title |
|---|---|
| RU-152FZ-009 | Personal Data Breach Notification |
| RU-152FZ-015 | Internal Control and Audit |
| RU-152FZ-017 | Roskomnadzor Inspections and Enforcement |
| RU-152FZ-019 | Liability and Penalties |
Breach and Enforcement
| Code | Title |
|---|---|
| RUSPD-8 | Breach Notification, RKN Inspections, Sanctions |
Consent and Lawful Basis
Consent and Lawful Basis
| Code | Title |
|---|---|
| RU-152FZ-003 | Consent of the Data Subject |
| RU-152FZ-004 | Consent for Dissemination of Personal Data |
| RU-152FZ-018 | Privacy Notices and Transparency |
Cross-Border and Localization
| Code | Title |
|---|---|
| RUSPD-6 | Cross-Border Transfer and Data Localization (Article 18.5) |
Data Subject Rights
Data Subject Rights
| Code | Title |
|---|---|
| RU-152FZ-010 | Data Subject Rights and Requests |
Governance
| Code | Title |
|---|---|
| RUSPD-7 | Roskomnadzor Registration, Operator Notification, Governance |
High-Risk Processing
| Code | Title |
|---|---|
| RUSPD-4 | Special Categories, Biometric Data |
Individual Rights
| Code | Title |
|---|---|
| RUSPD-3 | Data Subject Rights (Access, Correction, Object, Block/Destroy) |
Lawful Basis and Consent
| Code | Title |
|---|---|
| RUSPD-2 | Lawful Basis, Consent, Notice |
Localisation and Cross-Border Transfer
Localisation and Cross-Border Transfer
| Code | Title |
|---|---|
| RU-152FZ-002 | Data Localisation of Russian Citizens Personal Data |
| RU-152FZ-005 | Cross Border Transfer Notification and Assessment |
| RU-152FZ-020 | Records of Provision of Personal Data to Third Parties |
Processors and Retention
Processors and Retention
| Code | Title |
|---|---|
| RU-152FZ-011 | Processing on Behalf of Another Operator |
| RU-152FZ-014 | Retention and Destruction of Personal Data |
Registration and Notification
Registration and Notification
| Code | Title |
|---|---|
| RU-152FZ-001 | Notification of Personal Data Processing to Roskomnadzor |
| RU-152FZ-007 | Designation of Person Responsible for Personal Data |
| RU-152FZ-008 | Internal Personal Data Documents |
Scope and Principles
| Code | Title |
|---|---|
| RUSPD-1 | Scope, Definitions, Principles under 152-FZ |
Security
| Code | Title |
|---|---|
| RUSPD-5 | Security of Processing, Confidentiality, FSB/FSTEC Requirements |
Security of Processing
Security of Processing
| Code | Title |
|---|---|
| RU-152FZ-006 | Technical and Organisational Protection Measures |
| RU-152FZ-016 | Levels of Protection for Information Systems |
Special and Biometric Categories
Special and Biometric Categories
| Code | Title |
|---|---|
| RU-152FZ-012 | Special Categories of Personal Data |
| RU-152FZ-013 | Biometric Personal Data |
Your Compliance Coverage
If you comply with Russia Federal Law on Personal Data (152-FZ), you already cover:
FTC GLBA Safeguards Rule (16 CFR Part 314)
11%
3 controls mapped
Compare →MARS-E
11%
3 controls mapped
Compare →FedRAMP Rev 5
11%
3 controls mapped
Compare →+ 100 more: Florida Digital Bill of Rights (FDBR) (11%), ITU-T X.805 - Security Architecture for End-to-End Communications (11%)
See all 103 mapped frameworks ↓Maps to 103 other frameworks
What is Russia Federal Law on Personal Data (152-FZ) and who does it apply to?
Russia Federal Law on Personal Data (152-FZ) is a compliance framework from Russia with 16 domains and 28 controls. Russia's Federal Law No. 152-FZ on Personal Data (2006, as amended through 2023) regulates the processing of personal data in the Russian Federation. Roskomnadzor (Federal Service for Supervision of Communications) oversees compliance. Key requirements include data localisation (personal data of Russian citizens must be stored on servers in Russia), consent management, and breach notification. Significant amendments in 2022-2023 strengthened enforcement and increased penalties. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Russia Federal Law on Personal Data (152-FZ) actually require?
Russia Federal Law on Personal Data (152-FZ) has 28 controls organised across 16 domains. The largest domains are Breach Notification, Inspection and Liability (4 controls), Consent and Lawful Basis (3 controls), Localisation and Cross-Border Transfer (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Russia Federal Law on Personal Data (152-FZ) do I already cover?
Russia Federal Law on Personal Data (152-FZ) maps to 103 other compliance frameworks. The top mapping partners are FTC GLBA Safeguards Rule (16 CFR Part 314) (11% coverage), MARS-E (11% coverage), FedRAMP Rev 5 (11% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Russia Federal Law on Personal Data (152-FZ)?
Start your Russia Federal Law on Personal Data (152-FZ) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Russia Federal Law on Personal Data (152-FZ) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required