This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

152-FZ "On Personal Data"

Information Security

152-FZ is the federal law regulating the collection, processing, storage and protection of personal data of Russian citizens.

What is Federal Law No. 152-FZ "On Personal Data"

Federal Law No. 152-FZ "On Personal Data" is a key regulatory legal act of the Russian Federation, adopted on July 27, 2006. The law regulates the collection, processing, storage, transfer and protection of personal data (PD) of Russian citizens. Its requirements are mandatory for all organizations and individual entrepreneurs working with personal information: government bodies, banks, insurance and medical companies, internet services, HR departments and any other structures that in one way or another process data about people.

Personal data lifecycle under 152-FZ Visual diagram of personal data processing stages: collection, processing, storage, transfer, blocking and deletion. Requirements of 152-FZ for PD operators. Personal data lifecycle under 152-FZ From collection to destruction — requirements for each stage 1. Collection Obtaining data 2. Processing Systematization 3. Storage On servers in Russia 4. Transfer Cross-border 5. Blocking On request 6. Deletion Upon consent withdrawal Mandatory conditions for each stage Data subject consent In writing or personal account Specific processing purposes Roskomnadzor notification Before processing starts Entry in PD operators registry Localization Servers on Russian territory Art. 18 of 152-FZ Data protection Cryptographic Access control The operator must ensure PD protection at all processing stages
152-FZ "On Personal Data" — term diagram

In simple words, 152-FZ is a set of rules that protects your personal information from leaks and unscrupulous companies. The law obliges any organization (operator) to ask for your consent to collect data, keep it confidential and reliably protect it, and also delete it on first request. This applies to banks, online stores, medical institutions and any other structures that in one way or another gain access to your data.

Compliance with the law is controlled by Roskomnadzor, and serious fines and criminal liability are provided for violations. According to Roskomnadzor, in 2025 more than 5,000 violations of 152-FZ were detected, and the total amount of fines exceeded 2.5 billion rubles. This underscores the importance of compliance with the law for any organization working with citizens' data.

Main provisions of 152-FZ

The law establishes clear principles for personal data processing that all operators must comply with:

  • Legality and fairness: Data processing must be carried out on a legal basis and with good faith intentions. Processing data by deception or without legal grounds is not allowed.
  • Limitation by specific purposes: Data must be processed only for predetermined and lawful purposes. Use of data for purposes incompatible with those originally stated is not allowed.
  • Inadmissibility of combining databases: It is prohibited to combine databases containing personal data whose processing is carried out for incompatible purposes.
  • Ensuring accuracy and relevance: The operator is obliged to take measures to ensure the accuracy and relevance of data, as well as to delete or clarify incomplete or inaccurate data at the request of the subject.
  • Storage no longer than necessary: Data must be stored no longer than the purposes of processing require. After achieving the purposes or when the need is lost, the data is subject to destruction or depersonalization.

A key requirement of the law is obtaining the informed and conscious consent of the subject to the processing of their data. Additional requirements and enhanced protection are established for biometric and special categories of personal data (race, nationality, political views, health, intimate life). To effectively protect such data, organizations often implement DLP systems to prevent leaks and SIEM solutions for monitoring security events.

Obligations of personal data operators

Operators (organizations and individual entrepreneurs processing personal data) are obliged to fulfill a number of requirements fixed in 152-FZ and by-laws (in particular, FSTEC Order No. 21 and Government Resolution No. 1119):

  • Notify Roskomnadzor about the start of personal data processing (except for cases when this is not required — for example, if data is processed only for the execution of an employment contract).
  • Ensure the confidentiality of personal data and take technical and organizational protection measures.
  • Use certified CIPF tools when necessary (for example, when transferring data over open communication channels or when working with biometrics).
  • Appoint a person responsible for organizing the processing of personal data.
  • Conduct certification of information systems to confirm compliance with regulator requirements (FSTEC, FSB).
  • Maintain internal records and control over personal data processing.

Comprehensive measures are used to protect data: firewalls, DLP systems, SIEM solutions, access control systems and antivirus software. You can learn more about protection tools in our glossary.

Liability for violation of 152-FZ

Violation of the requirements of the law entails serious liability — from administrative fines to criminal prosecution:

  • Administrative liability (Code of Administrative Offenses of the Russian Federation): Fines for officials — from 10,000 to 100,000 rubles, for legal entities — from 100,000 to 500,000 rubles. For processing data without consent or for incompatible purposes, fines can reach 700,000 rubles.
  • Turnover fines: For repeated violations and large data leaks, turnover fines of up to 3% of the company's annual revenue are provided, but not less than 1 million rubles (according to the amendments that came into force from 2025).
  • Criminal liability (Article 137 of the Criminal Code of the Russian Federation): For illegal collection and dissemination of personal data (including using official position), imprisonment for up to 5 years is provided.
  • Website blocking and suspension of activity: Roskomnadzor has the right to block websites that violate 152-FZ, as well as to suspend the activities of organizations until violations are eliminated (up to 90 days).

According to statistics, in 2025 Roskomnadzor issued more than 7,000 rulings on administrative fines for violations of 152-FZ. The average fine for legal entities was 250,000 rubles, and for officials — 40,000 rubles.

How to ensure compliance with 152-FZ

To minimize risks and ensure compliance with legal requirements, organizations are recommended to take the following steps:

  1. Conduct a regular audit of all systems and personal data processing processes, identify all sources and data flows.
  2. Appoint a person responsible for organizing personal data processing and develop internal policies (Personal Data Processing Policy, Privacy Policy).
  3. Obtain the consent of subjects to process data in written or electronic form (using an electronic signature).
  4. Implement technical protection tools: DLP systems to prevent leaks, SIEM systems for monitoring, CIPF tools for encryption, and firewalls to protect against external threats.
  5. Conduct certification of information systems by authorized bodies (FSTEC, FSB) in accordance with the requirements.
  6. Train employees in the rules of working with personal data and liability for their violation.

Our certification and design of secure systems services will help you comply with regulator requirements and avoid sanctions. The full text of the law and current amendments are always available in the documents section.

Frequently asked questions

What relates to personal data under 152-FZ?

According to 152-FZ, personal data (PD) is any information that relates directly or indirectly to a specific individual. This includes identification data (full name, date of birth, place of birth), contact data (phone, address, email), passport data, TIN, SNILS, as well as digital traces (IP address, geolocation, cookies) and even photographs or voice if a person can be identified by them. A special category is formed by biometric data (fingerprints, face, voice), which requires enhanced protection and the mandatory use of CIPF tools during processing.

What is 152-FZ in simple words?

152-FZ is a law that protects your personal information. It obliges any organization (bank, online store, government body) to ask for your consent to collect data, store it confidentially and protect it from leaks, and also delete it on first request. Serious fines are provided for violating the law, up to turnover fines of 3% of annual revenue for companies.

What is the penalty for violating 152-FZ in 2025-2026?

Serious liability is provided for violating 152-FZ. This includes administrative fines (up to 700 thousand rubles for processing without consent), turnover fines for data leaks (up to 3% of annual revenue, but not less than 1 million rubles) and even criminal liability under Article 137 of the Criminal Code of the Russian Federation (imprisonment for up to 5 years). Website blocking and disqualification of officials are also possible. To avoid these risks, it is necessary to use certified protection tools such as CIPF and undergo regular security audits.

When is consent for personal data processing not required?

The consent of the subject is not required when data processing is necessary for the execution of a contract (for example, placing an order in a store), compliance with legal requirements (submitting reports to the tax authority), protecting the life and health of a person, as well as for the administration of justice. The full list of exceptions is specified in Article 6 of 152-FZ. In these cases too, the operator is obliged to ensure data confidentiality and use the necessary protection measures, including CIPF tools when transferring data.

What amendments to 152-FZ came into force in 2025?

Significant amendments to 152-FZ came into force on July 1, 2025: a ban was introduced on the use of foreign services (databases, cloud storage) for the primary collection and storage of data of Russians. Data collection through foreign web analytics is also considered a violation. Now businesses are obliged to use exclusively Russian infrastructure included in the Register of Domestic Software. Turnover fines for data leaks have also been increased — up to 3% of annual revenue.

Who is a personal data operator according to 152-FZ?

A personal data operator is any legal or natural person who organizes and carries out data processing, determining its purposes and composition. These can be government bodies, banks, online stores, employers, medical institutions and any other structures. The operator is charged with the obligation to ensure the security of systems, for which firewalls, SIEM systems and DLP systems are used. You can check whether you are an operator and learn about the procedure on the Roskomnadzor website.

How not to violate 152-FZ when working with personal data?

To comply with 152-FZ, it is necessary to complete several key steps: submit a notification to Roskomnadzor, obtain the consent of subjects for processing (in written or electronic form), publish a Privacy Policy on the website, and ensure data storage on the territory of the Russian Federation using Russian services from the Register of Domestic Software. It is also critically important to implement technical protection tools: DLP systems to prevent leaks, CIPF tools for encryption and SIEM systems for incident monitoring. Regular audit and design of secure systems will help avoid fines.

Was this information helpful?

Protect your network today

Leave a request — our information security specialists will help you select, configure and integrate 152-fz "on personal data" into your infrastructure. We will protect your data from threats.

Guaranteed result
Selection for your budget
Comprehensive approach
Certified experts

Or contact us:

+7 (499) 238-01-32 sales@fintech.ru

Open from 9:00 am to 6:00 pm