According to an
ACC article dated August 29[1], the president signed Russia’s amended data protection law on July 22. The law will take full effect on September 1, 2016.
One important change is that Russian citizens’ data must be stored and processed within Russia. Violators will be entered in a registry maintained by Russia’s communications authority, Roskomnadzor, and ultimately subjected to web blocking.
According to a Hogan Lovells article[2], the procedure is as follows.
- First, a court determines whether the site is in violation.
- If a violation is found, Roskomnadzor notifies the business hosting the website of the violation.
- The hosting provider must contact the site provider within 1 days.
- The site provider must remedy the violation within 1 days from that point.
- If the violation is not remedied, the hosting provider must restrict access to the website.
This affects companies doing business with Russia and companies with operations in Russia. It appears this may include websites that allow Russian citizens to register. Until now, companies without a presence in Russia seem to have been outside Roskomnadzor’s jurisdiction, but if this legislation requires data to remain in Russia, those companies will automatically acquire some form of presence there.
For a website actually to comply, it would probably first need to contract with a Russian cloud provider or similar company, establish a replica site, detect users accessing the main site from Russia by their IP addresses or other means, redirect them to the Russian site, and process them there thereafter. The data would also have to be managed twice, which is burdensome. Furthermore, because the law refers to “Russian citizens,” presumably Russians abroad are also covered. That might require asking users their nationality, but in Japan nationality can be sensitive information, making this difficult. Would sites create a checkbox saying, “I am not a Russian citizen”…?
From Russia’s perspective, perhaps the aim is that if it enacts such legislation, websites wishing to avoid dual management will move to Russian clouds. But I wonder. It may simply lead businesses to bypass Russia. Alternatively, perhaps the original intention was to cover medical data, genomic data, and similar information, only for the scope somehow to become generalized.
According to experts, this law will have a major impact on foreign investment in Russia and will probably be amended before it takes effect. In any event, affected companies have reached the point where they should at least monitor developments while considering how to respond.
The amendment introduces no new fines, so existing fines apply. The amount is RUB 10,000[2], or slightly less than ¥30,000. That is not substantial. A penalty such as 5% of worldwide revenue, as in the EU, would be troublesome, so I sincerely hope no such change is made.
In any event, I will investigate further and report here again if I learn anything new.
[1] http://www.lexology.com/library/detail.aspx?g=a6877256-b7bc-4278-b984-d364ad150bf4
[2] http://www.hldataprotection.com/2014/07/articles/international-eu-privacy/russia-enacts-new-online-data-laws/
Related posts

Identity in Conflict: In Response to the Invasion of Ukraine
On June 21, I will hold a workshop titled “Identity in Conflict” at Identiverse 2022, near Denver, Colorado, USA. Identity in Conflict Tuesday, June 21, 11:30…

White House Bars BBC, New York Times, and Other News Organizations from Regular Press Briefing
The White House appears to have barred the New York Times and other news organizations from a regular press briefing. This is highly unusual and is…
