152-FZ

Federal Law No. 152-FZ on Personal Data

Key Facts

Effective Date
January 27, 2007
Enacted
July 27, 2006
Enforcing Authority
Roskomnadzor (Federal Service for Supervision of Communications, Information Technology and Mass Media)
Consent Model
Opt-in
Applies To
Any organization processing personal data of Russian citizens, regardless of where the organization is based

Overview

Russia's Federal Law 152-FZ governs personal data protection, with Roskomnadzor interpreting cookies as personal data when they contain identifying information. The law's strict data localization requirements — mandating that Russian citizens' data be stored on Russian servers — create unique compliance challenges for international websites.

What This Means for Your Website

  • Prior opt-in consent is required for cookies containing personal data of Russian visitors
  • A consent banner must be displayed on the first visit
  • If cookies contain identifying data, data localization requirements may apply (storage on Russian servers)
  • Breach notification must reach Roskomnadzor within 24 hours (stricter than GDPR's 72 hours)
  • Electronic consent must follow specific format requirements

Key Requirements

Roskomnadzor enforces 152-FZ with significant penalties: up to RUB 6 million for processing without consent, RUB 1-6 million for first data localization offenses, and RUB 6-18 million for repeat localization violations. The 24-hour breach notification requirement and data localization obligations create operational demands beyond typical consent management. Data localization requirements were tightened in July 2025.

How ConsentStack Handles This

ConsentStack presents Russian visitors with a consent banner on first visit and blocks identifying cookies until consent is given. Consent records are maintained with the format requirements needed for Russian compliance.

Penalties

Processing without consent: up to RUB 6 million. Data localization: RUB 1-6M (first), RUB 6-18M (repeat). Breach notification failure: up to RUB 3 million.

Maximum Fine
RUB 18,000,000 per violation

Key Requirements

  • Prior opt-in consent for non-essential cookies when containing personal data
  • Data localization: Russian citizens data must be stored on Russian servers
  • 24-hour breach notification to Roskomnadzor
  • Consent banners required on first visit
  • Written or electronic consent with specific format requirements

Notable Provisions

  • Data localization tightened July 2025 — servers in Russia may be required
  • 24-hour breach notification (stricter than GDPR 72-hour)
  • Roskomnadzor interprets cookies as personal data
  • Significant penalties for data localization non-compliance (up to RUB 18M repeat)

Other Europe Regulations

GDPREuropean Union + EEA
The GDPR sets the global standard for data protection, requiring explicit opt-in consent before processing personal data of EU/EEA residents. For websites, non-essential cookies must be blocked until visitors actively consent. Pre-ticked boxes and implied consent are invalid.
PECRUnited Kingdom
PECR is the UK's cookie-specific law, requiring consent before storing or accessing cookies. The DUAA 2025 significantly increased penalties from GBP 500,000 to GBP 17.5 million and introduced analytics exceptions on an opt-out basis. Only strictly necessary cookies are exempt.
ePrivacy DirectiveEuropean Union + EEA
Article 5(3) of the ePrivacy Directive is the primary EU legal basis requiring cookie consent. It mandates prior informed consent before storing or accessing any information on a user's device, with narrow exceptions only for transmission necessity and explicitly requested services.
FDPAFrance
France has the most actively enforced cookie regime in Europe. CNIL issued 259 corrective decisions in 2025, with cookie-specific fines totaling EUR 486.8 million including EUR 325M against Google. A Refuse all button or Continue without accepting must appear on the first layer.
UK GDPRUnited Kingdom
The UK GDPR is the retained EU GDPR post-Brexit, with consent standards identical to the EU version. The UK adequacy decision was renewed December 2025, valid until December 2031. Combined with PECR, it forms the legal framework for cookie consent in the UK.
TDDDGGermany
Germany implements the ePrivacy Directive through Section 25 of TDDDG (renamed from TTDSG in May 2024). A Consent Management Ordinance (EinwV) became effective April 2025, establishing a voluntary framework for recognized consent management services. Cookie banners must not obscure website content.

Frequently Asked Questions

Does Russia require cookie consent?

Yes, for cookies containing personal data. Roskomnadzor interprets cookies with identifying information as personal data subject to consent requirements under 152-FZ.

What is Russia's data localization requirement?

Personal data of Russian citizens must be stored on servers located within Russia. This may apply to identifying cookies. Penalties reach RUB 18 million for repeat violations.

How fast must data breaches be reported in Russia?

Within 24 hours to Roskomnadzor — significantly faster than the GDPR's 72-hour requirement.

Stay compliant with 152-FZ

ConsentStack helps you implement Opt-in consent for Russia automatically.