ARTICLE
5 December 2019

Russia Significantly Increases Fines For Violations Of Data Localization Requirement

O
Orrick
Contributor
Orrick logo
Orrick is a global law firm focused on serving the technology & innovation, energy & infrastructure and finance sectors. Founded over 150 years ago, Orrick has offices in 25+ markets worldwide. Financial Times selected Orrick as the Most Innovative Law Firm in North America for three years in a row.
Under Russian Data Protection Law, when collecting personal data, data operators (controllers) must ensure that recording
Russian Federation Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

Under Russian Data Protection Law, when collecting personal data, data operators (controllers) must ensure that recording, systematization, accumulation, storage, updating and extraction of personal data relating to Russian citizens are performed utilizing databases located in Russia (data localization requirement).

The new law, adopted by the Russian parliament and signed into law on December 2, 2019, introduces substantial fines for violations of that requirement.

Currently, the most stringent liability for violating the localization requirement is the right of the Russian data protection authority (Roskomnadzor) to block access to internet websites belonging to the entities violating the localization requirement. The most widely known instance of this sanction's application was the blocking of LinkedIn on the territory of Russia, imposed back in 2016. The blockage still applies – all Russian Internet service providers currently have to deny access to LinkedIn in Russia.

There are currently no substantial fines specifically punishing violations of the localization requirement. The new law introduces significant fines specifically for failure to localize the personal data:

  • for the first violation: fines on private citizens up to RUR 50,000 (approx. USD 780); on officials up to RUR 200,000 (approx. USD 3,100); and on legal entities up to RUR 6 mln. (approx. USD 93,750); and
  • for repeated violations: fines on private citizens up to RUR 100,000 (approx. USD 1,600); on officials up to RUR 800,000 (approx. USD 12,500); and on legal entities up to RUR 18 mln. (approx. USD 281,000).

All companies collecting personal data on Russian citizens would be well advised to review their compliance practices.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

ARTICLE
5 December 2019

Russia Significantly Increases Fines For Violations Of Data Localization Requirement

Russian Federation Privacy
Contributor
Orrick logo
Orrick is a global law firm focused on serving the technology & innovation, energy & infrastructure and finance sectors. Founded over 150 years ago, Orrick has offices in 25+ markets worldwide. Financial Times selected Orrick as the Most Innovative Law Firm in North America for three years in a row.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More