On September 1, 2015, amendments to the federal law came into force “On Personal Data” (Law 152 FZ).
According to the law, the data that the client enters on your website must be stored on the territory of the Russian Federation.
And that is not all. About who this law will affect and what to do, in our article.

On September 1, 2015, amendments to the law “On Personal Data” entered into force.
According to this law, all data that a client enters on your site and which is precisely personal data (passport, addresses, including e-mail, payment data, etc.) must be stored on the territory of the Russian Federation.

HERE IS THE EXTRACT FROM LAW 152 on the protection of personal data

“When collecting personal data, including through the Internet information and telecommunication network, the operator is obliged to ensure the recording, systematization, accumulation, storage, clarification (updating, change), extraction of personal data of citizens Russian Federation using databases located on the territory of the Russian Federation, except for the cases specified in paragraphs 2, 3, 4, 8 of part 1 of Article 6 of this Federal Law” (Part 5 of Article 18 of the Federal Law “On Personal Data”).”

The term "Operator" should be understood as all companies, in particular e-commerce, on whose websites customers provide personal information.

Well, that's not all. In February 2017, further amendments were made to the law on the protection of personal data. These amendments oblige all owners of sites and online stores (Operators) to notify users that when entering personal data on the site, they give their consent to their collection, processing and storage.

If you ignore these amendments to the law, then you risk getting a fine of up to 75,000 rubles for one violation. And if there are more of them, then the amount of the fine will increase (on violation of the legislation of the Russian Federation in the field of personal data - article 13.11 of the Code of Administrative Offenses of the Russian Federation)


We have already talked about significant fines. It can affect everyone. And do not think that this is not about you :) Look at the judicial practice and you will understand that this is not a joke. Here, for example, is the sensational case of the Tambov law firm (Decree No. 4A-288/2016 of October 4, 2016 in case No. 4A-288/2016), which was fined for violations in the field of PD storage. The amount of the fine is insignificant, but it must be borne in mind that since July 1, 2017, fines have increased significantly.

In addition to administrative liability, there may also be criminal liability. So if you cause moral harm to a user whose personal data, for example, fell into the wrong hands.
Well, for such violations, Roskomnadzor can block the site and add you to the so-called “black list”.
And then be prepared for additional checks by Roskomnadzor.


  1. The first thing to do is to notify users about the processing of personal data. If you haven't already, now is the time. Develop and post on the site a document on the processing of PD, and also obtain the consent of users for such processing (for example, by checking the checkbox with information under each registration form).
    In general, this can be done in different ways, depending on your goals and business features. For example, Ozon places a privacy policy on the site and, when registering a user, takes consent to the processing of PD. Or you can place information about the collection of PD as part of a public offer, as Lamoda does, and also collect consent to processing during registration. Or like Sberbank, which places such information in the contract.
  2. Prepare internal documents governing rules for the enforcement of this law. These include orders, instructions and appointments of persons responsible for storage personal information.
  3. It is very important to make sure that the data is stored in Russia (on Russian servers).
    This is required by the law on the protection of user information (part 5 of article 18 of the Federal Law “On Personal Data”).
    Therefore, check with your hosting provider for the address of the location of the servers that host your site and conclude an agreement with him, where this address will be indicated. You will need this address to fill out a notification to Roskomnadzor. If you have your own server, then be sure to save the documents on it. They may be required by Roskomnadzor during a possible audit. The same is true for a contract with a hosting provider.

    If your hosting provider hosts its servers in a Russian data center, then all is well.
    This is the easiest way to meet the requirements of the law by purchasing hosting from a domestic provider.

    There is another way, which is called cross-border data transfer. This is not prohibited by law. Storage of PD abroad is allowed, but with some reservations. So, in any case, a company, in addition to storing PD abroad, must have such a database on the territory of the Russian Federation. But at the same time, the database should be as complete and up-to-date as possible. The scheme here is this - the entire database with personal data is collected, systematized and stored on the territory of the Russian Federation, and then the data can be transferred abroad. It is important to understand here that the primary source is the base on the territory of the Russian Federation.

  4. After that, prepare and send a notification to Roskomnadzor.
    This can be done through the electronic form on the website:

    Notification is not required if:

      you process only employee data;

      enter into an agreement with a specific person and the data specified in the agreement are used only for the execution of this agreement, i.e. information is not published or transferred to third parties without the consent of the subject of personal data (this paragraph is ambiguous, as questions may arise due to the specifics of the business. It is important to correctly draw up an agreement, taking into account all the nuances that meet the requirements of the law. Therefore, we recommend consulting with lawyer, and if there is no definite answer, then it is better to file a notice.);

      if the collected data includes only the names of users;

      if the user himself made his personal data publicly available.

note that it is only about cases where notification is not required. The above data is still personal and it is necessary to notify the user about it.


There is no need to be afraid of this law. It regulates our rights with you, as individuals. Each of us at least once purchased goods via the Internet and left our personal data. Now you and I have grounds for defending our rights legally if our rights are violated.

For site owners, the most important thing is to arrange everything correctly. This way you protect yourself from fines, other liability and gain the trust of customers.
Small note: we advise you not to make a blueprint, for example, like competitors - each has its own specifics. It is better to spend time developing documentation specifically for your business than to pay fines later. And if you still have questions seek the help of your lawyer, as this article does not replace a specialist, which will help you do everything as you need and specifically for your goals and objectives.

After the entry into force of clause 4, part 2, article 19 of the Federal Law of July 27, 2006 No. 152-FZ "On Personal Data", each enterprise is obliged to bring its information systems and processes related to the processing of personal data in accordance with the requirements of the Legislation of the Russian Federation .

What does this mean for legal entities?

Organizations are obliged to ensure the protection of the rights and freedoms of a person and citizen in the processing of his personal data, including the protection of the rights to privacy, personal and family secrets. Thus, they become "organizations-operators of personal data". The Federal Service for Supervision in the Sphere of Communications will control the fulfillment of the requirements of the Legislation, information technologies and mass communications (Roskomnadzor), FSTEC and FSB of Russia.

the federal law applies to companies of any organizational form - this government bodies, federal and municipal institutions: banks, insurance companies, medical institutions, telecom operators, online stores, retail chains, manufacturing companies and other organizations that process personal data received from employees, customers and other individuals and legal entities.

The responsibilities of the operating organization include:

  • ensuring the legality of the processing of personal data;
  • building a personal data protection system in accordance with the requirements of the FSTEC and the FSB of Russia;
  • sending a notification to Roskomnadzor;
  • development of internal documentation;
  • carrying out attestation tests or conformity assessment;
  • systematic updating of the personal data protection system.

Often, this turns out to be a difficult and costly task, including due to the need to obtain a document confirming the effectiveness of the measures taken to protect personal data. That is why most companies prefer to optimize this process by looking for a reliable partner with a turnkey solution in an external virtual infrastructure.

