Russian Data Localization Law: 242-FZ, Roskomnadzor Enforcement, and Internet Regulation

Russian data localization law, established by Federal Law No. 242-FZ of 21 July 2014, requires operators of personal data to store and process personal data of Russian citizens on servers physically located in the Russian Federation. The law, which entered into force on 1 September 2015, has significant implications for international companies operating in Russia, internet platforms, and cloud service providers. The Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor) is the primary enforcement authority.

The Data Localization Requirement

Article 2 of Federal Law No. 242-FZ amended Article 18 of the Federal Law on Personal Data (No. 152-FZ) to require that operators of personal data, when collecting personal data of citizens of the Russian Federation, ensure that the recording, systematisation, accumulation, storage, specification (updating, modification), and retrieval of personal data are carried out using databases located in the Russian Federation. The requirement applies to all operators — including foreign companies — that process personal data of Russian citizens. The law does not prohibit the cross-border transfer of personal data after recording in Russian databases; data may be transferred abroad for further processing provided that the cross-border transfer complies with the requirements of the Personal Data Law. The law also does not require the physical location of the operator in Russia — only the location of the databases used for the initial processing of personal data. The amendments of 2016 extended the requirement to operators processing personal data through the internet, including social networks, online platforms, and e-commerce services.

The Register of Personal Data Databases

Roskomnadzor maintains a register of personal data databases (reestr baz dannykh personalnykh dannykh) and has the authority to conduct inspections to verify compliance with the data localization requirement. Operators must notify Roskomnadzor of the location of databases used for processing personal data of Russian citizens. In the event of non-compliance, Roskomnadzor issues a warning setting a deadline for compliance. If the operator fails to comply within the specified period, Roskomnadzor may apply to court for an order restricting access to the operator’s information resources on the territory of the Russian Federation. The restriction may involve blocking the operator’s website or requiring the deletion of personal data processed in violation of the data localization requirement. The process has been applied to a range of platforms and services since enforcement began in 2015.

LinkedIn Blocking

The blocking of LinkedIn in Russia in 2016 was the first and most prominent enforcement action under the data localization law. In August 2016, Roskomnadzor requested that LinkedIn provide information on its compliance with the data localization requirement and confirm the location of its databases. Following LinkedIn’s failure to provide satisfactory confirmation, Roskomnadzor applied to the Tagansky District Court of Moscow for an order restricting access to the LinkedIn website in Russia. The court granted the order in November 2016, finding that LinkedIn had not provided evidence of compliance with the data localization requirement. The Moscow City Court upheld the decision on appeal. LinkedIn was blocked in Russia in November 2016 and remained blocked for several years, though the service had limited market presence in Russia. The LinkedIn blocking established the precedent that Roskomnadzor would enforce the data localization requirement against major international platforms and that the courts would support enforcement measures, including website blocking.

Roskomnadzor Enforcement Actions

Roskomnadzor has pursued enforcement actions under the data localization law against a range of companies. In addition to LinkedIn, Roskomnadzor issued warnings to Facebook (Meta), Twitter, Google, and other major internet platforms, requesting confirmation of compliance with data localization requirements. In 2018–2021, Roskomnadzor conducted inspections of the data processing practices of Russian companies (including Yandex, Mail.ru, Sberbank) and foreign companies (Apple, Huawei, Samsung, Uber, Airbnb, and others). The enforcement approach has combined formal inspections with negotiated compliance. Most major companies have taken steps to comply with the data localization requirement by establishing local data centres or entering into agreements with Russian data storage providers. Apple reported in 2018 that it would store personal data of Russian users on servers in Russia. Google has taken steps to localise data storage. The enforcement has been generally effective in ensuring formal compliance by major market participants, though the quality and completeness of compliance vary.

Yandex Data Processing and Compliance

Yandex, as the largest Russian technology company, has been at the centre of data localization compliance. Yandex processes vast amounts of personal data through its search engine, e-commerce platform, ride-hailing services, email, and cloud services. Yandex has invested in data centre infrastructure in Russia (including data centres in Vladimir, Sasovo, and Moscow) to comply with the data localization requirement. The company has also implemented data classification and access control systems to manage data localization obligations. Yandex’s compliance with data localization has been the subject of regulatory scrutiny, and the company has cooperated with Roskomnadzor inspections. The interaction between data localization and the broader regulatory environment — including the Sovereign Internet Law and the requirements for information dissemination organisers — has created a complex compliance landscape for Yandex and other Russian technology companies.

International Reaction and Extra-Territorial Effects

The Russian data localization law has attracted significant international attention and criticism. International businesses have raised concerns about the costs of compliance, the requirement to locate servers in Russia, and the implications for global data management strategies. The law has been criticised by human rights organisations for potentially facilitating government access to personal data and for creating barriers to the free flow of information. The law has also been subject to challenges under international trade and investment agreements, though no successful challenge has been brought. The data localization requirement has contributed to the development of the Russian data centre industry, with significant investment in data centre infrastructure by both Russian and international companies.

Cross-Border Data Transfers

The Personal Data Law permits cross-border transfer of personal data after initial recording in Russian databases, subject to certain conditions. The transfer of personal data to countries that are parties to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108) and to countries that are not on the Roskomnadzor list of countries that do not provide adequate protection of personal data is permitted without additional safeguards. Transfer to countries not providing adequate protection requires consent or one of the statutory exceptions (performance of a contract, protection of life and health, etc.). The 2022 sanctions and the withdrawal from the Council of Europe did not immediately affect the cross-border data transfer regime, though the evolving regulatory environment has created uncertainty.

Violations and Penalties

Violations of the data localization requirement may result in administrative penalties under Article 13.11 of the KoAP RF (Code of Administrative Offences). The penalties for failure to comply with the data localization requirement include fines: for officials, 20,000–40,000 rubles; for individual entrepreneurs, 20,000–40,000 rubles; for legal entities, 100,000–200,000 rubles. In 2019, the penalties were increased, with fines for legal entities reaching up to 6 million rubles for certain violations. In addition to administrative fines, Roskomnadzor may request the blocking of the operator’s information resource as described above. Criminal liability may also apply for certain violations of personal data legislation, though criminal prosecutions for data localization violations have been limited.

Significance

The Russian data localization law has established a regulatory model that has influenced data sovereignty legislation in other countries, including China, India, and others. The law reflects the Russian government’s concern for data sovereignty, national security, and the protection of citizens’ personal data from access by foreign governments. The law has been generally effective in requiring major data processors to establish local data storage infrastructure in Russia, though enforcement has been selective and compliance has varied. The data localization requirement interacts with other elements of Russian internet regulation — including the Sovereign Internet Law and the requirements for information dissemination organisers — to create a comprehensive framework for government oversight of data processing and internet communications. The future development of data localization regulation will be shaped by the evolution of the digital ruble, the development of artificial intelligence regulation, and the broader geopolitical context of Russian internet governance.