How to Complete the Roskomnadzor Personal Data Notification Form in 2026: Field-by-Field Analysis
The Roskomnadzor notification form is not a questionnaire about a company but an extract from documents that must already exist. Regulators expect operators to copy information already recorded in the personal data processing policy, the list of processed data categories, the appointment order for the responsible person, the act determining the protection level of information systems, and the list of applied security measures.
Before opening the form, operators must verify whether notification is required at all. Following the September 2022 amendments to 152-FZ, only three narrow exemptions remain: data in state information systems created for national security, processing performed exclusively without automation tools, and processing required by transport security legislation. Paper-based card indexes qualify for the second exemption, but Excel files, 1C, CRM systems, email, and cloud storage constitute automated processing.
Five documents supply the answers required by the form. The personal data processing policy provides processing purposes. The attached list of data categories supplies both categories of data and categories of data subjects. The appointment order gives the name and contact details of the responsible person. The protection level act and threat model, prepared under Government Decree No. 1119 of 1 November 2012, feed the largest text block. The list of applied security measures populates the two fields on protective measures and tools.
The form itself contains several practical features. A draft can be saved at any time and later retrieved via a permanent link. Entering an INN triggers an automatic check against the register; if a record already exists, the system blocks submission of a primary notification and offers links to the change-of-information form. An auto-population link can import data from a previously submitted notification using its identifier and email address.
Section I asks for the region of registration, taken from the Unified State Register of Legal Entities, and separately for the regions where processing actually occurs. The latter field refers to territories where staff with data access work or where equipment storing personal data is located, not merely the legal address or client locations.
Subsequent sections require operators to list each processing purpose together with five mandatory details: categories of data subjects, categories of data, legal grounds, actions performed, and data retention periods. Protection measures must be described with reference to the protection level act. Geographic scope, cross-border transfers, and final declarations complete the form.
After submission, the operator remains obliged to keep internal documents up to date and to notify Roskomnadzor of any changes. Failure to submit or submission of inaccurate information can result in administrative liability, although the absence of a record alone does not automatically trigger a fine without detection during an inspection.
Related articles
OBEP Raids on Russian IT Firms: How to Safeguard Source Code, Servers and Blockchain Assets During Searches
Russian IT companies, Web3 projects and fintech services now face frequent visits from OBEP operatives conducting pre-investigative checks or searches under criminal cases. The article details the legal distinction between operational-search measures and formal searches, emphasizing article 164.1 of the UPK RF that prohibits seizure of physical servers in economic crime investigations. It explains how companies can demand data mirroring instead of hardware removal and how to invoke article 51 of the RF Constitution when pressured for encryption keys. Commercial secret regimes are presented as a tool to raise criminal liability for leaks and to request closed court proceedings. Practical checklists cover document verification, staff instructions, password retention and immediate calls to specialized criminal counsel. The guidance aims to prevent business paralysis while preserving evidence integrity during raids.
RWB Deploys Enterprise-Wide Database Access Control with Trino and Open Policy Agent
RWB has replaced fragmented manual database access processes with a centralized architecture built on Trino as the single entry point and Open Policy Agent for policy enforcement. The system enforces least-privilege access, mandatory auditing, and automated revocation tied to HR records while eliminating anonymous and password-based logins. Access requests now complete in 3–10 minutes instead of an average of four days, with 92 percent handled automatically. Key components include Keycloak for OIDC authentication, Vault for secrets, Kafka for security event streaming to SOC, and Kubernetes orchestration. Responsibility is split across AI & Data Security, Core DevOps, Access Management, SOC, and Trust & Safety teams. More than 1,250 PostgreSQL clusters and 90 projects are now connected, with real-time dashboards tracking adoption and policy health.
Russia Moves to Allow Biometric Data Processing for Suspects and Convicts Without Consent
Russian law enforcement agencies may soon gain the legal right to process biometric data of suspects, accused individuals, and convicted persons without requiring their personal consent. A corresponding draft bill has already been submitted to the government and is scheduled for review at the next cabinet meeting, according to TASS. The measure covers fingerprints, facial images, voice recordings, and other physiological or behavioral characteristics used for identification. If approved, prior permission from the individual will no longer be needed when biometrics are used in criminal proceedings. The change applies not only to those already convicted but also to suspects and accused persons whose guilt has not yet been established by a court. For ordinary citizens, enrollment in the Unified Biometric System remains voluntary and is used for remote identity verification when accessing financial and government services.
FAS Clears Russian Operators on 'Unlimited' Internet Claims Despite Speed Throttling to 128 Kbit/s
The Federal Antimonopoly Service has declined to investigate complaints regarding promises of unlimited internet and unrestricted roaming access made by major Russian mobile operators. The Association of Professional Users of Social Networks and Messengers argued that operators including Vimpelcom, MegaFon, MTS, and T2 Mobile mislead customers by advertising unlimited plans while throttling speeds to 128-512 Kbit/s after data caps are reached. FAS determined that information on official company websites does not qualify as advertising under Russian law. Operators maintain that the term unlimited remains accurate because no total data volume limit exists, only speed reductions detailed in service descriptions. The complainants and legal experts contend that FAS reviewed only technical parameter pages and ignored banners, promotional news, search ads, SMS, and push notifications that may meet legal criteria for advertising. The decision leaves consumers facing slow connections unsuitable for video or file downloads after initial allowances are exhausted.