Law / Russia

Russia

18 of 22 named instruments researched to a stage, across five of the six areas of law we track: 16 in force and 2 enacted but not yet in force. As of 14 September 2026.

When they take effect9 of 18 carry a date, 9 do not. Earlier is before 2015.
Before 2015: 3 instruments (3 in force) earlier 2015: 0 instruments 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 1 instrument (1 in force) 2023: 1 instrument (1 in force) 2024: 1 instrument (1 in force) 2025: 1 instrument (1 in force) ’25 2026: 0 instruments 2027: 2 instruments (2 enacted but not yet in force) ’27 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 7
  3. Scraping law 5
  4. Cybersecurity law none researched
  5. Age gating law 2
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 enacted but not yet in force

Research summary (226 words)

Russia enacted its first dedicated AI statute, Federal Law No. 243-FZ 'On Supporting the Development of Artificial Intelligence Technologies in the Russian Federation', signed 26 July 2026 and in force in part from 1 September 2026.

The general framework (definitions, principles, government powers, and support measures for 'sovereign' and 'national' large foundation AI models, defined as at least 1 billion parameters and general multi-task capability) is already in force; the provisions that bind private parties directly, a labeling-capability duty for AI-generated audio and visual content and a set of safety and documentation duties on developers of sovereign or national models, do not take effect until 1 March 2027.

Outside this statute, Russia's Presidential Decree No. 490 of 10 October 2019 (National AI Strategy to 2030, as amended by Decree No. 124 of 2024) and Federal Law No. 258-FZ of 31 July 2020 (experimental legal regimes for digital innovation, the regulatory sandbox under which Federal Law No. 243-FZ Art. 13(4) permits special AI rules) are government-defined policy and framework instruments rather than found duties binding a private developer or deployer directly, and are not modeled as instruments here, as no primary-source text for either has been located.

No AI-specific criminal prohibition (such as a standalone deepfake or synthetic-CSAM ban) has been located beyond the general computer-misuse and personal-data provisions researched under the scraping and privacy topics respectively.

AI governance

Federal Law No. 243-FZ, Article 8, Duties of Sovereign and National Foundation Model Developers

Federal Law No. 243-FZ, Art. 8 (26 July 2026)Consultant.ru, codified text of Federal Law No. 243-FZ, Art. 8

In force in 159 days, effective 1 March 2027. Binds private bodies.

What this law does

Not yet binding: Article 8 of Federal Law No. 243-FZ, signed 26 July 2026, does not take effect until 1 March 2027.

Once in force, it will require the developer of a 'sovereign' or 'national' large foundation AI model to take organizational and technical measures to secure the model, to define rules for the model's operation including restrictions, conditions of use, updating, and decommissioning, and to maintain technical documentation describing the model's key parameters and limitations to the extent needed to assess the safety of its application.

A 'developer' for these purposes is an individual entrepreneur or a legal entity that designs, trains, or modifies the model.

Per Article 6 (also deferred to 1 March 2027 for these definitional parts), a 'sovereign' model must be developed, with its characteristics determined and changed at every lifecycle stage, by a Russian legal entity, with the whole development cycle including training fully technically reproducible by that developer, user-query processing and data storage kept in Russian-located, Russian-owned data centers, and confirmed compliance with Russian legislation and 'traditional Russian spiritual and moral values'.

A 'national' model shares the same developer-control, data-center, and compliance-confirmation requirements, but may incorporate components developed abroad, including other developers' foundation models, provided they are distributed under an open license.

What it requires

AI transparency

Federal Law No. 243-FZ, Article 9, AI-Generated Content Notice

Federal Law No. 243-FZ, Art. 9 (26 July 2026)Consultant.ru, codified text of Federal Law No. 243-FZ, Art. 9

In force in 159 days, effective 1 March 2027. Binds private bodies.

What this law does

Not yet binding: Article 9 of Federal Law No. 243-FZ, signed 26 July 2026, does not take effect until 1 March 2027.

Once in force, it will require that a person applying a large foundation AI model (one with at least 1 billion parameters and general multi-task capability) to create audio or visual informational material be given the ABILITY to place a notice that AI technology was used; the format, content, and placement of that notice are left to agreement between the person applying the model and the person providing access to it, so displaying the notice is not itself mandatory.

Separately, the owner of a Russian-language website, information system, or program letting users distribute information through personal pages, where daily access exceeds 500,000 Russia-based internet users, must give its users the ABILITY to place that same AI-use notice on content they distribute that was created using a large foundation AI model.

What it requires

Privacy law7 instruments, 7 in force

Research summary (109 words)

Russia's comprehensive private- and public-sector personal data statute is Federal Law No. 152-FZ "On Personal Data" of 27 July 2006, as amended most recently by Federal Law No. 23-FZ of 28 February 2025, extending a hard data localization duty to processors, and Federal Law No. 420-FZ, which sharply raised administrative fines from 30 May 2025.

Biometric identification and authentication carry a separate, materially heavier regime under Federal Law No. 572-FZ, which mandates that identification against a database run only through a state-operated Unified Biometric System, distinguishing Russia from every other jurisdiction. This picture is statutory throughout; no lead enforcement case or court decision is identified for any instrument here.

Biometric privacy

Federal Law No. 572-FZ, Unified Biometric System for Identification and Authentication

Federal Law No. 572-FZ of 29 December 2022 "On the identification and/or authentication of individuals using biometric personal data"Garant.ru legal database, official text of Federal Law No. 572-FZ

In force since 1 June 2023. Binds public and private bodies.

What this law does

Federal Law No. 572-FZ establishes the Unified Biometric System (Edinaya biometricheskaya sistema, EBS), a state information system for identifying and authenticating individuals from face and voice biometrics, and it is genuinely distinct from every other biometric regime. "Identification", matching an unknown person against the whole database, may be performed only through the state EBS.

"Authentication", verifying a claimed identity, may use the EBS or a private accredited system, but an accredited authentication system works only with derived mathematical vectors, never the original biometric template, and may not transmit those vectors to a third party.

Organizations that process biometric data for identification or authentication, banks, employers, security operators, call centers, must route identification through the state system; reporting documents that the law obliges banks and state agencies to deposit client face and voice biometrics into the EBS, and that the Central Bank has moved to bar branches from opening accounts or approving loans via mobile app without biometric authentication.

A broader duty for every prior private holder of biometric data to transfer its existing database into the EBS and destroy its own copy is not established; only the narrower duty for banks and state agencies to deposit new biometrics is. Written consent is required under Article 11 of 152-FZ, cross-referenced by 572-FZ, and 572-FZ separately bars denying service to someone who declines biometric processing, except where a separate federal law affirmatively mandates identification.

Accredited organizations may retain a biometric sample only up to 10 days, solely to process a complaint; the durable copy of record lives in the state EBS. Voiceprint and faceprint are both squarely in scope, the statute's subject matter is literally identification and authentication using face and voice biometrics, and there is no carve-out for either.

Whether individual consent is still required before an already-collected biometric record is transferred from a bank into the EBS, as distinct from consent to the original collection, is unresolved.

What it requires

Breach notification

Federal Law No. 152-FZ, Article 21 Part 3.1, Breach Notification

Federal Law No. 152-FZ, Art. 21, part 3.1, added by Federal Law No. 266-FZ (in force 1 September 2022)Consultant.ru, codified text of Federal Law No. 152-FZ, Art. 21, part 3.1

In force since 1 September 2022. Binds public and private bodies.

What this law does

Article 21, part 3.1, added by Federal Law No. 266-FZ, requires an operator that detects an unlawful or accidental transfer, provision, distribution, or access to personal data violating a subject's rights to notify Roskomnadzor within 24 hours of detection, covering the nature of the incident, suspected cause, likely harm, and remediation already taken, and to file a full report within 72 hours covering the internal investigation's results and the persons responsible.

What it requires

Comprehensive regime

Federal Law No. 152-FZ "On Personal Data"

Federal Law No. 152-FZ of 27 July 2006 "On Personal Data" (as amended)Consultant.ru, codified text of Federal Law No. 152-FZ

In force since 27 July 2006. Binds public and private bodies.

What this law does

Federal Law No. 152-FZ "On Personal Data" of 27 July 2006, as amended, most recently by Federal Law No. 23-FZ of 28 February 2025 and Federal Law No. 420-FZ, is Russia's comprehensive private- and public-sector data protection statute. Six lawful bases are recognized under Article 6: consent, contract performance, legal obligation, vital interests, legitimate interests, and a journalism, science, literature, or art exception.

An "operator" (controller) determines the purposes and content of processing, and a "processor" acts on the operator's instructions. As of 1 July 2025, Federal Law No. 23-FZ makes processors subject to the same localization duty as operators.

What it requires

Cross border transfer

Federal Law No. 152-FZ, Article 18(5), Data Localization and Cross-Border Transfer, as Amended by Federal Law No. 23-FZ

Federal Law No. 152-FZ, Art. 12, Art. 18(5), as amended by Federal Law No. 23-FZ of 28 February 2025Consultant.ru, codified text of Federal Law No. 152-FZ, Art. 12, 18(5)

In force since 1 July 2025. Binds public and private bodies.

What this law does

Article 12 requires, before an international transfer, that the receiving country provide an adequate level of protection, which Roskomnadzor determines by list, Strasbourg Convention parties and a published Roskomnadzor adequacy list qualify automatically; transfers to a non-adequate jurisdiction need the subject's written consent naming the recipient country, an international treaty, a statutory security or constitutional necessity, contract performance, or vital-interest protection.

Separately, Article 18(5) requires operators to record, systematize, accumulate, store, update, and retrieve Russian citizens' personal data using databases physically located in Russia, a hard localization duty added in 2014 and in force since 1 September 2015. Localization does not itself prohibit a subsequent cross-border transfer or an offshore copy once the primary Russian database exists.

Federal Law No. 23-FZ of 28 February 2025 rewrote Article 18(5), extending the localization duty to processors as well as operators and closing a gap that let initial collection route through foreign infrastructure before a Russian copy was made, effective 1 July 2025.

What it requires

Data subject rights

Federal Law No. 152-FZ, Articles 14-17, Data Subject Rights

Federal Law No. 152-FZ, Art. 14-17Consultant.ru

In force since 27 July 2006. Binds public and private bodies.

What this law does

Articles 14 to 17 give a data subject in Russia the right to confirmation of processing and the categories, legal basis, and retention period involved; correction of inaccurate data; deletion where data was collected unlawfully, its purpose is fulfilled, or consent is withdrawn; withdrawal of consent at any time; and objection to a decision producing legal or similarly significant effects based solely on automated processing.

Article 17 gives the subject the right to complain to Roskomnadzor or to sue in court for damages and compensation of moral harm. Rights run against the operator.

What it requires

Enforcement supervision

Criminal Code Article 272.1, Illegal Collection, Storage, Use, or Transfer of Personal Data

Criminal Code of the Russian Federation, Art. 272.1, added by Federal Law No. 421-FZ, in force 11 December 2024Consultant.ru

In force since 11 December 2024. Binds public and private bodies.

What this law does

Federal Law No. 421-FZ added Article 272.1 to the Criminal Code, criminalizing illegal collection, storage, use, or transfer of personal data: up to 4 years' imprisonment for the base offense, up to 5 years where minors, special categories, or biometric data are involved, up to 8 years for an unauthorized cross-border transfer, and up to 10 years for an organized group or grave consequences, plus fines to 3 million rubles; a personal or family-use exemption applies.

What it requires

Sensitive categories

Federal Law No. 152-FZ, Articles 10-11, Special Categories and the Biometric Data Definition

Federal Law No. 152-FZ, Art. 10-11Legalacts.ru

In force since 27 July 2006. Binds public and private bodies.

What this law does

Article 10 of 152-FZ names special categories, race and ethnicity, political opinion, religious or philosophical belief, health, sex life, and criminal record data, requiring written consent or a statutory exception. Article 11 separately defines "biometric personal data" as information characterizing a person's physiological and biological features on the basis of which their identity can be established, used by the operator for that purpose.

The article's own text is entirely general and technology-neutral. It carries no illustrative list of modalities at all, and no mention of facial images, voice recordings, fingerprints, or DNA anywhere in the article. Written consent is required for biometric processing, and provision of biometric data cannot be made mandatory, except where Article 11(2)'s statutory exceptions apply.

On that same general wording, an identifier derived from a photograph, video, or audio recording is not excluded: the definition simply never names any modality, recording-derived or otherwise, so nothing in the text carves one out.

What it requires

Scraping law5 instruments, 5 in force

Research summary (194 words)

Russia has no scraping-specific statute; open-web collection is governed by the general computer-misuse provisions of the Criminal Code (Arts. 272 to 274.1, unauthorized access, malicious software, and critical-infrastructure interference), the Civil Code's sui generis database maker's right (Part IV, Arts. 1334 to 1336), and the personal-data statute researched separately under the privacy topic.

Article 273's malware offense reaches software built to neutralize a site's technical security tools, which covers a scraping tool built to defeat access controls, though the article names no such use case itself.

Civil Code Art. 1274's free-use exception, the provision that would otherwise carry a text-and-data-mining carve-out, covers only quotation, illustration, and specifically enumerated informational and educational uses; it names no exception for automated bulk reproduction or machine analysis of protected works, so mass scraping for training or indexing purposes falls outside it and back onto the ordinary reproduction right.

Federal Law No. 149-FZ 'On Information, Information Technologies and Information Protection' authorizes Roskomnadzor to order blocking of sites distributing unlawful content (Art. 15.1 and related provisions), a content-blocking regime rather than a scraping-specific one. No reported case construing any of these provisions against a scraping fact pattern has been located.

Computer misuse

Criminal Code Article 272, Unauthorized Access to Computer Information

Criminal Code of the Russian Federation, Art. 272 (No. 63-FZ, 1996)Consultant.ru, codified text of the Criminal Code of the Russian Federation, Art. 272

In force. Binds public and private bodies.

What this law does

Article 272 criminalizes unauthorized access to legally protected computer information where the act causes destruction, blocking, modification, or copying of that information, with four escalating penalty tiers keyed to significant damage or mercenary motive, commission by a group or through an official position, and grave consequences.

The article, as currently in force, dates its main structure to Federal Law No. 420-FZ of 7 December 2011 and was most recently amended by Federal Law No. 421-FZ of 30 November 2024, which excepted conduct already covered by the newer Article 272.1 on unlawful handling of personal data.

What it requires

Criminal Code Article 273, Creation, Use and Distribution of Malicious Computer Programs

Criminal Code of the Russian Federation, Art. 273 (No. 63-FZ, 1996)Consultant.ru, codified text of the Criminal Code of the Russian Federation, Art. 273

In force. Binds public and private bodies.

What this law does

Article 273 criminalizes creating, using, or distributing computer programs or other computer information known to be intended for unauthorized destruction, blocking, modification, copying of computer information, or for neutralizing computer information security tools, with three escalating tiers for organized or for-profit commission and for grave consequences.

The article separately reaches software known to be intended for neutralizing computer-information security tools, without naming any particular downstream use for that software.

What it requires

Criminal Code Article 274, Violation of Rules for Operating Computer-Information Storage, Processing or Transmission Systems

Criminal Code of the Russian Federation, Art. 274 (No. 63-FZ, 1996)Consultant.ru, codified text of the Criminal Code of the Russian Federation, Art. 274

In force. Binds public and private bodies.

What this law does

Article 274 criminalizes violating the rules for operating protected computer-information storage, processing, or transmission facilities, telecommunications networks and terminal equipment, or the rules for accessing telecommunications networks, where the violation causes destruction, blocking, modification, or copying of information and significant damage, with a second tier for grave consequences.

What it requires

Criminal Code Article 274.1, Unlawful Impact on Critical Information Infrastructure

Criminal Code of the Russian Federation, Art. 274.1 (added 2017)Consultant.ru, codified text of the Criminal Code of the Russian Federation, Art. 274.1

In force. Binds public and private bodies.

What this law does

Article 274.1, added by Federal Law No. 194-FZ of 26 July 2017, criminalizes creating or using malicious software aimed at Russia's critical information infrastructure, unlawful access to protected information held in it, and violating the operating or access rules for systems classified as critical information infrastructure, across five escalating tiers running from forced labor up to five years to imprisonment of five to ten years for grave consequences.

A 2026 amendment added a cooperation-based exemption from liability for a person who actively assists the investigation.

What it requires

Database right

Civil Code Part IV, Database Maker's Exclusive Right

Civil Code of the Russian Federation, Part IV, Arts. 1334-1336Consultant.ru, codified text of the Civil Code of the Russian Federation, Part IV, Arts. 1334-1336

In force. Binds public and private bodies.

What this law does

Article 1334 grants the maker of a database that required substantial financial, material, organizational, or other outlay to create an exclusive sui generis right to extract materials from the database and reuse them in any form, and bars anyone from extracting materials and reusing them without the rightholder's permission except as the Code provides; a database is presumed to have required substantial outlay if it contains at least 10,000 independent information elements.

Article 1335 sets the term at 15 years from completion (or publication) of the database, renewed on every update. Article 1336 extends the right to a Russian citizen or legal entity, a foreign rightholder whose home state reciprocally protects a Russian maker's database, or as an international treaty otherwise provides.

"Extraction" is defined as transferring the whole content of a database, or a substantial part of its constituent materials, onto another information medium by any technical means and in any form, which reaches automated bulk copying of a database's contents.

What it requires

Age gating law2 instruments, 2 in force

Research summary (205 words)

Russia's general age-gating regime is Federal Law No. 436-FZ 'On Protecting Children from Information Harmful to Their Health and Development' (29 December 2010, as amended), which classifies all information products into five age tiers (under 6, 6+, 12+, 16+, and prohibited for children) and requires producers and distributors to self-classify and label accordingly; most internet content is exempted from the physical labeling duty, but a website may voluntarily carry a machine-readable age mark, and an 'audiovisual service' (a defined term reaching video-on-demand and similar platforms) must classify itself and must prevent minors from accessing content in the prohibited-for-children category.

Live entertainment events restricted to adults require the organizer to check a government-issued identity document where a visitor's age is in doubt.

Separately, Federal Law No. 149-FZ Art. 10.6 imposes a content-monitoring duty, rather than an access-restriction duty, on the owner of any social network with more than 500,000 Russia-based daily users, requiring it to monitor for and act on child sexual abuse material, drug-related content, suicide-related content, and material recruiting minors into unlawful or dangerous acts.

Neither statute conditions general website access to adults-only material on age verification at the point of access; no dedicated adult-content age-verification statute or app-store age-verification statute has been located.

Age-appropriate design code

Federal Law No. 436-FZ, Information-Product Classification and Minor-Access Regime

Federal Law No. 436-FZ, Arts. 6, 11, 12, 14Consultant.ru, codified text of Federal Law No. 436-FZ, Arts. 6, 11, 12, 14

In force. Binds public and private bodies.

What this law does

Article 6 requires the producer or distributor of an information product to self-classify it, before it enters circulation in Russia, into one of five age categories: for children under 6, for children 6 and older, for children 12 and older, for children 16 and older, or prohibited for children. Article 12 sets the corresponding age marks (0+, 6+, 12+, 16+, 18+) and their minimum display size.

Article 11 requires the age mark on most information products before circulation, but exempts information distributed over telecommunications networks including the Internet other than registered network media and audiovisual services, and requires an event organizer to check an identity document establishing age where there is doubt that an attendee at an adults-only event has reached majority.

Article 14 lets an unregistered website voluntarily carry a machine-readable age mark under its own self-classification, but requires an audiovisual service to classify itself and to ensure minors cannot access content in the prohibited-for-children category.

Note and primary source

Social media and minors

Federal Law No. 149-FZ, Article 10.6, Social Network Minor-Protection Monitoring Duty

Federal Law No. 149-FZ, Art. 10.6 (added 2020)Consultant.ru, codified text of Federal Law No. 149-FZ, Art. 10.6

In force. Binds private bodies.

What this law does

Article 10.6, added by Federal Law No. 530-FZ of 30 December 2020, applies to the owner of a Russian-language (or Russian minority-language) website, information system, or program that lets users distribute information through personal pages, where daily access exceeds 500,000 Russia-based internet users (a 'social network owner').

It requires that owner to monitor the social network for, among other things, child sexual abuse material and advertisements recruiting minors as performers in pornographic events, drug-related content, suicide-related content, and material inducing minors into unlawful acts that endanger their life or health, and to publish an annual report on complaint handling and monitoring results.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (140 words)

Russia has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, and no dedicated text-and-data-mining exception for news content; instead it regulates news aggregation through a bespoke registration and content-accountability regime for large news aggregators (Federal Law No. 149-FZ, Art. 10.4) layered on top of the Civil Code's general free-use exception for quotation and informational reproduction of periodical material (Part IV, Art. 1274).

An aggregator that verbatim-reproduces material already published on an official state-body website or by a registered mass medium is shielded from liability for that content under Art. 10.4(2), which functions as Russia's closest analogue to a linking or reproduction safe harbor for aggregators, though it is a content-liability shield rather than a copyright defense.

No hot-news misappropriation doctrine, no reported case construing Art. 10.4 or Art. 1274 against an aggregator, and no compelled-bargaining code have been located.

Snippet reproduction

Civil Code Part IV Article 1274, Free Use of a Work for Informational, Scientific, Educational or Cultural Purposes

Civil Code of the Russian Federation, Part IV, Art. 1274Consultant.ru, codified text of the Civil Code of the Russian Federation, Part IV, Art. 1274

In force. Binds public and private bodies.

What this law does

Article 1274 permits, without the rightholder's consent and without payment but with mandatory attribution of the author and the source, quotation of lawfully published works in the original or in translation for scientific, polemical, critical, informational, or educational purposes, or to reveal the author's creative intent, to the extent justified by the purpose of the quotation, including reproducing excerpts of newspaper and magazine articles in the form of press reviews.

It separately permits reproducing in a periodical print publication, and communicating to the public, lawfully published articles on current economic, political, social, or religious topics broadcast or communicated to the public, unless the author or rightholder has specifically prohibited such use, and permits reproduction and communication, within the bounds justified by an informational purpose, of works seen or heard in the course of covering current events, in reviews of current events.

The article names no exception at all for automated text-and-data-mining or bulk machine reproduction of protected works; its enumerated free uses are limited to quotation, illustration for educational material, periodical press reproduction of specified subject-matter, parody, and accessibility formats for the visually impaired, so mass scraping of copyrighted content for indexing, aggregation beyond quotation-length excerpts, or model training draws on none of them and falls back to the ordinary reproduction right.

Note and primary source

Federal Law No. 149-FZ, Article 10.4, News Aggregator Duties

Federal Law No. 149-FZ, Art. 10.4 (added 2016)Consultant.ru, codified text of Federal Law No. 149-FZ, Art. 10.4

In force. Binds private bodies.

What this law does

Article 10.4, added by Federal Law No. 208-FZ of 23 June 2016, applies to the owner of a Russian-language (or a Russian minority-language) website, information system, or program used to process and distribute news information, where daily access exceeds one million internet users in Russia (a 'news aggregator owner'), and requires it to verify the accuracy of socially significant information before distribution, avoid concealing or falsifying such information, avoid defamatory or discriminatory distribution, publish contact information, retain distributed news information and its source for six months, and register with Roskomnadzor once its audience crosses the threshold.

A news aggregator owner is not liable for distributing news information that verbatim reproduces material already posted on an official government-body website or already distributed by an identifiable, accountable registered mass medium. Ownership of a news aggregator is restricted to a Russian citizen without other citizenship or a Russian legal entity that is not more than 50 percent controlled, directly or indirectly, by a foreign state, organization, or citizen. A registered online mass medium (a 'network publication') is excluded from the news-aggregator definition entirely.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.