Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
cite Federal Law No. 572-FZ of 29 December 2022 "On the identification and/or authentication of individuals using biometric personal data"
stage In effect
since 2023-06-01
source Garant.ru legal database, official text of Federal Law No. 572-FZ, verified by direct crawler fetch (kremlin.ru, the originally cited signing record, was unreachable over https from this network)
Federal Law No. 572-FZ establishes the Unified Biometric System (Edinaya biometricheskaya sistema, EBS), a state information system for identifying and authenticating individuals from face and voice biometrics, and it is genuinely distinct from every other biometric regime in this wave. "Identification", matching an unknown person against the whole database, may be performed only through the state EBS.
"Authentication", verifying a claimed identity, may use the EBS or a private accredited system, but an accredited authentication system works only with derived mathematical vectors, never the original biometric template, and may not transmit those vectors to a third party.
Organizations that process biometric data for identification or authentication, banks, employers, security operators, call centers, must route identification through the state system; reporting documents that the law obliges banks and state agencies to deposit client face and voice biometrics into the EBS, and that the Central Bank has moved to bar branches from opening accounts or approving loans via mobile app without biometric authentication.
A broader duty for every prior private holder of biometric data to transfer its existing database into the EBS and destroy its own copy was not established in this research; only the narrower duty for banks and state agencies to deposit new biometrics is established.
Written consent is required under Article 11 of 152-FZ, cross-referenced by 572-FZ, and 572-FZ separately bars denying service to someone who declines biometric processing, except where a separate federal law affirmatively mandates identification. Accredited organizations may retain a biometric sample only up to 10 days, solely to process a complaint; the durable copy of record lives in the state EBS.
Voiceprint and faceprint are both squarely in scope, the statute's subject matter is literally identification and authentication using face and voice biometrics, and there is no carve-out for either. Whether individual consent is still required before an already-collected biometric record is transferred from a bank into the EBS, as distinct from consent to the original collection, was not resolved in this research.
What it asks of an app →
Breach notification
cite Federal Law No. 152-FZ, Art. 21, part 3.1, added by Federal Law No. 266-FZ (in force 1 September 2022)
stage In effect
since 2022-09-01
source Consultant.ru, codified text of Federal Law No. 152-FZ, Art. 21, part 3.1
Article 21, part 3.1, added by Federal Law No. 266-FZ, requires an operator that detects an unlawful or accidental transfer, provision, distribution, or access to personal data violating a subject's rights to notify Roskomnadzor within 24 hours of detection, covering the nature of the incident, suspected cause, likely harm, and remediation already taken, and to file a full report within 72 hours covering the internal investigation's results and the persons responsible.
What it asks of an app →
Comprehensive regime
cite Federal Law No. 152-FZ of 27 July 2006 "On Personal Data" (as amended)
stage In effect
since 2006-07-27
source Consultant.ru, codified text of Federal Law No. 152-FZ
Federal Law No. 152-FZ "On Personal Data" of 27 July 2006, as amended, most recently by Federal Law No. 23-FZ of 28 February 2025 and Federal Law No. 420-FZ, is Russia's comprehensive private- and public-sector data protection statute. Six lawful bases are recognized under Article 6: consent, contract performance, legal obligation, vital interests, legitimate interests, and a journalism, science, literature, or art exception.
An "operator" (controller) determines the purposes and content of processing, and a "processor" acts on the operator's instructions. As of 1 July 2025, Federal Law No. 23-FZ makes processors subject to the same localization duty as operators.
What it asks of an app →
Cross border transfer
cite Federal Law No. 152-FZ, Art. 12, Art. 18(5), as amended by Federal Law No. 23-FZ of 28 February 2025
stage In effect
since 2025-07-01
source Consultant.ru, codified text of Federal Law No. 152-FZ, Art. 12, 18(5)
Article 12 requires, before an international transfer, that the receiving country provide an adequate level of protection, which Roskomnadzor determines by list, Strasbourg Convention parties and a published Roskomnadzor adequacy list qualify automatically; transfers to a non-adequate jurisdiction need the subject's written consent naming the recipient country, an international treaty, a statutory security or constitutional necessity, contract performance, or vital-interest protection.
Separately, Article 18(5) requires operators to record, systematize, accumulate, store, update, and retrieve Russian citizens' personal data using databases physically located in Russia, a hard localization duty added in 2014 and in force since 1 September 2015. Localization does not itself prohibit a subsequent cross-border transfer or an offshore copy once the primary Russian database exists.
Federal Law No. 23-FZ of 28 February 2025 rewrote Article 18(5), extending the localization duty to processors as well as operators and closing a gap that let initial collection route through foreign infrastructure before a Russian copy was made, effective 1 July 2025.
What it asks of an app →
Data subject rights
cite Federal Law No. 152-FZ, Art. 14-17
stage In effect
since 2006-07-27
source Consultant.ru, codified text of Federal Law No. 152-FZ, Art. 14-17, corroborated by direct crawler fetch of Art. 17 via a second independent source, zakonrf.info
Articles 14 to 17 give a data subject in Russia the right to confirmation of processing and the categories, legal basis, and retention period involved; correction of inaccurate data; deletion where data was collected unlawfully, its purpose is fulfilled, or consent is withdrawn; withdrawal of consent at any time; and objection to a decision producing legal or similarly significant effects based solely on automated processing.
Article 17 gives the subject the right to complain to Roskomnadzor or to sue in court for damages and compensation of moral harm. Rights run against the operator.
What it asks of an app →
Enforcement supervision
cite Criminal Code of the Russian Federation, Art. 272.1, added by Federal Law No. 421-FZ, in force 11 December 2024
stage In effect
since 2024-12-11
source Consultant.ru, codified text of the Criminal Code of the Russian Federation, Art. 272.1, verified by direct crawler fetch (title metadata matches the cited article)
Federal Law No. 421-FZ added Article 272.1 to the Criminal Code, criminalizing illegal collection, storage, use, or transfer of personal data: up to 4 years' imprisonment for the base offense, up to 5 years where minors, special categories, or biometric data are involved, up to 8 years for an unauthorized cross-border transfer, and up to 10 years for an organized group or grave consequences, plus fines to 3 million rubles; a personal or family-use exemption applies.
What it asks of an app →
Sensitive categories
cite Federal Law No. 152-FZ, Art. 10-11
stage In effect
since 2006-07-27
source Legalacts.ru, direct crawler fetch of Federal Law No. 152-FZ, Art. 11 (confirmed against a second independent source, zakonrf.info, and the WebSearch summary of Art. 11 text), correcting an earlier draft's unsupported claim of an illustrative modality list
Article 10 of 152-FZ names special categories, race and ethnicity, political opinion, religious or philosophical belief, health, sex life, and criminal record data, requiring written consent or a statutory exception. Article 11 separately defines "biometric personal data" as information characterizing a person's physiological and biological features on the basis of which their identity can be established, used by the operator for that purpose.
Confirmed by direct crawler fetch of the article's own text: the definition is entirely general and technology-neutral. It carries no illustrative list of modalities at all, no mention of facial images, voice recordings, fingerprints, or DNA anywhere in the article; an earlier draft of this summary claimed such a list and that claim did not survive a primary-text check.
Written consent is required for biometric processing, and provision of biometric data cannot be made mandatory, except where Article 11(2)'s statutory exceptions apply. `excludes_recording_derived` is recorded false on that same general wording: the definition does not exclude an identifier derived from a photograph, video, or audio recording, it simply never names any modality, recording-derived or otherwise, so nothing in the text carves one out.
What it asks of an app →