How Russia's Article 10.1 on Personal Data Dissemination Emerged: Legislative History and Reform Flaws
The Russian personal data protection regime underwent significant change with the introduction of Article 10.1 in Federal Law No. 152-FZ. The reform, formally enacted through Federal Law No. 519-FZ, took effect on 1 March 2021 and required separate consent for processing personal data that a subject permits to be disseminated.
Author Anton Gorelk in, First Deputy Chairman of the State Duma Committee on Information Policy, Information Technology and Communications, sponsored the original bill 1057337-7 on 17 November 2020. The explanatory note claimed that once data appeared on websites, operators could freely accumulate, supplement and analyse it for purposes such as targeted advertising, without further control by the data subject.
This framing overlooked existing judicial practice. In case No. A40-5250/2017, courts upheld Roskomnadzor positions that data from open profiles on VKontakte, Odnoklassniki, Twitter and Avito did not automatically become publicly available personal data under Article 8. The Supreme Court refused to review the case. A further Tagansky District Court ruling on 3 March 2020 ordered an internet page that provided unrestricted access to personal data without consent to be included in the register of violators under Article 15.5 of the Law on Information.
The initial draft proposed a detailed consent mechanism: subjects would list specific categories of data, name the exact internet resources where data could appear, and set conditions or prohibitions. Two distinct prohibitions were envisaged—one preventing the operator from transferring data to an unlimited circle of persons (except providing access), and another preventing that circle from further processing (except receiving access). The draft also allowed subjects to demand cessation of processing at any time without proving a violation.
During the first reading on 9 December 2020, the responsible committee itself stated that the bill’s declared objectives were not achieved by its provisions. The Legal Department warned that the bill’s use of the term “access” conflicted with the definition already contained in 152-FZ, where processing includes transfer and transfer includes access. The committee nevertheless recommended passage, promising corrections before the second reading.
The final text preserved the broad definitions of processing, transfer and dissemination while adding new exceptions and a lengthy new category of data alongside the existing Article 8. The resulting framework mixes several legal models without adequate reconciliation, rendering consistent practical application extremely difficult for operators.
Related articles
Rosfinmonitoring Denies Mass Bank Account Blocks Over Partial Data Matches with Sanctions Lists
Rosfinmonitoring has issued clarifications rejecting reports of potential widespread freezes of bank accounts due to partial matches between client data and records of individuals subject to asset freezes. The agency stressed that the draft law is not intended to penalize people who merely share surnames or have similar name transliterations with sanctioned persons. Criteria for determining partial matches have not yet been defined and will be established by a separate order only after the federal law is adopted and real cases are analyzed. The measure provides only for temporary suspension of a transaction rather than automatic refusal or indefinite account blocking. Earlier reports from Izvestia had warned that loosely defined partial-match rules could generate numerous false positives affecting ordinary clients.
Understanding GOST Cryptography Standards: A Practical Guide for Russian Developers
The article provides a beginner-friendly breakdown of Russian GOST cryptographic standards, separating the core functions of hashing, digital signatures, and encryption. It covers the evolution of GOST algorithms across three generations from the 1990s to the current 2012+ standards including Stribog, Kuznechik, and Magma. Detailed explanations address how PKCS#11 interfaces with hardware tokens, how X.509 certificates function as digital passports, and how formats like CAdES, XAdES, and PAdES package signatures for verification. Comparisons with Western equivalents such as SHA-256, RSA, and AES help developers map familiar concepts to GOST implementations. The guide emphasizes practical integration with tools like CryptoPro for tasks involving detached signatures and certificate requests in PKCS#10 and PKCS#12 containers.
Why Vulnerability Management Specialists Must Master Compliance: Closing All CVEs but Leaving admin:admin
The article explains how compliance has evolved from a paperwork exercise into a mandatory, heavily penalized process in Russian cybersecurity. New regulations such as FSTEC Order 117, turnover fines for personal data leaks, and Presidential Decree 250 impose strict timelines and personal liability for vulnerability management failures. It outlines three approaches to compliance, from doing nothing to building custom standards based on CIS Benchmarks and local requirements. The text stresses moving from reactive scanning to golden images that embed compliance controls before deployment. It highlights tools like MaxPatrol HCC, RedCheck, and ScanOVAL for automated checks and warns that technical patches alone are useless without proper configuration controls such as strong passwords.
China Public Security Ministry Warns IoT Operators: Default Passwords on Devices Like Bus Stop Displays Violate Cybersecurity Law Even Without Major Incidents
A bus electronic display router in Wuhu, Anhui, was compromised in April 2026 because the device retained factory-default credentials and exposed multiple management ports. The Ministry of Public Security highlighted the case in its Hu Wang 2026 report, stressing that failing to change default passwords and leaving ports open constitutes a violation of the Cybersecurity Law regardless of whether serious harm occurred. The RCtea botnet actively targeted similar routers and cameras across China, infecting 9,827 devices in just six days in January 2026 through Telnet brute-force attacks. Experts from the Chinese Academy of Social Sciences clarified that penalties do not require actual damage and that operators must implement technical measures, retain logs for at least six months, and maintain internal security procedures. Additional cases in Qinghai and Nanchong demonstrated repeated enforcement actions against entities that ignored weak-password remediation orders. The report calls on operators, regulators, and manufacturers to enforce password changes at installation, close unnecessary ports, and apply network segmentation to prevent low-hanging IoT devices from becoming botnet recruits.