Federal Law No. 572-FZ, Unified Biometric System for Identification and Authentication
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 June 2023.
A biometric privacy rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Route biometric identification, matching an unknown person against a database, of a person in Russia only through the state Unified Biometric System; a private accredited system may only perform authentication, using derived mathematical vectors rather than the original template, and may not transmit those vectors to a third party.
- Obtain written consent before processing a person's biometric data in Russia, never condition service on that consent, and retain any biometric sample your organization holds only up to 10 days before deleting it, since the durable copy of record lives in the state system.
Who checks it
Audit expectation
continuous
Who audits it
Regulator
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Federal Law No. 572-FZ establishes the Unified Biometric System (Edinaya biometricheskaya sistema, EBS), a state information system for identifying and authenticating individuals from face and voice biometrics, and it is genuinely distinct from every other biometric regime. "Identification", matching an unknown person against the whole database, may be performed only through the state EBS.
"Authentication", verifying a claimed identity, may use the EBS or a private accredited system, but an accredited authentication system works only with derived mathematical vectors, never the original biometric template, and may not transmit those vectors to a third party.
Organizations that process biometric data for identification or authentication, banks, employers, security operators, call centers, must route identification through the state system; reporting documents that the law obliges banks and state agencies to deposit client face and voice biometrics into the EBS, and that the Central Bank has moved to bar branches from opening accounts or approving loans via mobile app without biometric authentication.
A broader duty for every prior private holder of biometric data to transfer its existing database into the EBS and destroy its own copy is not established; only the narrower duty for banks and state agencies to deposit new biometrics is. Written consent is required under Article 11 of 152-FZ, cross-referenced by 572-FZ, and 572-FZ separately bars denying service to someone who declines biometric processing, except where a separate federal law affirmatively mandates identification.
Accredited organizations may retain a biometric sample only up to 10 days, solely to process a complaint; the durable copy of record lives in the state EBS. Voiceprint and faceprint are both squarely in scope, the statute's subject matter is literally identification and authentication using face and voice biometrics, and there is no carve-out for either.
Whether individual consent is still required before an already-collected biometric record is transferred from a bank into the EBS, as distinct from consent to the original collection, is unresolved.
When LexLint raises it
processes_biometricsprocesses_voice
Read the law
Garant.ru legal database, official text of Federal Law No. 572-FZ
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.