Fonts, CDNs, and Hosting: The Cross-Border Data Transfers No One Notices
A developer running a service that processes third-party contracts paid close attention to Russia's 152-FZ personal data law. All documents, forms, and logins were routed to a Russian server, which he verified multiple times. When he examined the website itself rather than the backend service, he found three foreign companies receiving data on every visit.
The site used Vercel, a U.S. hosting provider, so every page load exposed the visitor's IP address, browser details, and visited pages. Google Fonts were loaded on all 33 pages, causing browsers to connect directly to Google servers. Two PDF and Word libraries on the contract verification page were served from cdnjs, operated by Cloudflare. Although contracts themselves stayed in Russia, technical visitor data left the country.
Why this counts as cross-border transfer
Article 12 of 152-FZ defines trans-border transfer as any transmission of personal data to a foreign entity. Regulators treat IP addresses combined with cookies, browser fingerprints, and visit history as personal data. A 2022 German court ruling (Landgericht München I, 3 O 17493/20) already awarded compensation to a visitor whose IP was sent to Google Fonts without consent; Russian authorities apply similar logic.
Since March 2023, operators must file a separate notification with Roskomnadzor before any cross-border transfer. Transfers to the United States or EU require a ten-working-day waiting period during which the regulator may block or restrict the transfer. Failure to notify falls under Article 13.11 and carries fines of 150,000–300,000 rubles for legal entities. If forms collect names, phones, or emails on foreign platforms, additional localization violations under part 8 can result in fines of 1–6 million rubles.
Common hidden vectors
- Hosting and CDN: Vercel, Netlify, GitHub Pages, Firebase, and Cloudflare in proxy mode decrypt traffic and see full request data.
- Fonts: Google Fonts and Adobe Fonts loaded via a single link tag on every page.
- Libraries: cdnjs, jsDelivr, unpkg, and Google Hosted Libraries for jQuery, Bootstrap, or PDF readers.
- Analytics and pixels: Google Analytics, Microsoft Clarity, and Hotjar that record clicks and session replays.
- CAPTCHA: reCAPTCHA sends behavioral data to Google on every load.
- Embedded content: YouTube videos, Google Maps, and foreign chat widgets that load even when unused.
- Forms and email: Google Forms, Typeform, Mailchimp, and SendGrid that store submissions abroad.
The developer identified external domains with one console command that extracted all resource hosts from the performance timeline. He then downloaded Inter and Fira Code fonts (256 KB total), hosted pdf.js and mammoth.js locally (2 MB), moved the site to a Russian server, and rewrote the privacy policy to reflect the changes. Only technical Telegram alerts without personal data remain on a foreign platform.
Operators who still need foreign services are advised to submit both processing and cross-border notifications, minimize data sent abroad, and document the arrangement transparently in their privacy policy.
Related articles
How to Complete the Roskomnadzor Personal Data Notification Form in 2026: Field-by-Field Analysis
The article provides a detailed walkthrough of the current Roskomnadzor notification form for operators processing personal data under Russian law. It explains that the form is an extract from existing internal documents rather than a questionnaire, requiring operators to reference their data processing policy, inventory results, appointment orders, and protection level acts. Key prerequisites include confirming that notification is mandatory after the 2022 amendments removed most exemptions, preparing five core documents, and understanding that the form pulls data directly from those records. The guide covers every section, from operator identification and processing regions to data categories, protection measures, geography, and post-submission obligations. It also addresses common mistakes, the option to save drafts, auto-population features, and liability for non-compliance or inaccurate information. The piece concludes with a checklist mapping each form field to its source document.
OBEP Raids on Russian IT Firms: How to Safeguard Source Code, Servers and Blockchain Assets During Searches
Russian IT companies, Web3 projects and fintech services now face frequent visits from OBEP operatives conducting pre-investigative checks or searches under criminal cases. The article details the legal distinction between operational-search measures and formal searches, emphasizing article 164.1 of the UPK RF that prohibits seizure of physical servers in economic crime investigations. It explains how companies can demand data mirroring instead of hardware removal and how to invoke article 51 of the RF Constitution when pressured for encryption keys. Commercial secret regimes are presented as a tool to raise criminal liability for leaks and to request closed court proceedings. Practical checklists cover document verification, staff instructions, password retention and immediate calls to specialized criminal counsel. The guidance aims to prevent business paralysis while preserving evidence integrity during raids.
RWB Deploys Enterprise-Wide Database Access Control with Trino and Open Policy Agent
RWB has replaced fragmented manual database access processes with a centralized architecture built on Trino as the single entry point and Open Policy Agent for policy enforcement. The system enforces least-privilege access, mandatory auditing, and automated revocation tied to HR records while eliminating anonymous and password-based logins. Access requests now complete in 3–10 minutes instead of an average of four days, with 92 percent handled automatically. Key components include Keycloak for OIDC authentication, Vault for secrets, Kafka for security event streaming to SOC, and Kubernetes orchestration. Responsibility is split across AI & Data Security, Core DevOps, Access Management, SOC, and Trust & Safety teams. More than 1,250 PostgreSQL clusters and 90 projects are now connected, with real-time dashboards tracking adoption and policy health.
Russia Moves to Allow Biometric Data Processing for Suspects and Convicts Without Consent
Russian law enforcement agencies may soon gain the legal right to process biometric data of suspects, accused individuals, and convicted persons without requiring their personal consent. A corresponding draft bill has already been submitted to the government and is scheduled for review at the next cabinet meeting, according to TASS. The measure covers fingerprints, facial images, voice recordings, and other physiological or behavioral characteristics used for identification. If approved, prior permission from the individual will no longer be needed when biometrics are used in criminal proceedings. The change applies not only to those already convicted but also to suspects and accused persons whose guilt has not yet been established by a court. For ordinary citizens, enrollment in the Unified Biometric System remains voluntary and is used for remote identity verification when accessing financial and government services.