How Russia's Article 10.1 on Personal Data Dissemination Emerged: Legislative History and Reform Flaws
The Russian personal data protection regime underwent significant change with the introduction of Article 10.1 in Federal Law No. 152-FZ. The reform, formally enacted through Federal Law No. 519-FZ, took effect on 1 March 2021 and required separate consent for processing personal data that a subject permits to be disseminated.
Author Anton Gorelk in, First Deputy Chairman of the State Duma Committee on Information Policy, Information Technology and Communications, sponsored the original bill 1057337-7 on 17 November 2020. The explanatory note claimed that once data appeared on websites, operators could freely accumulate, supplement and analyse it for purposes such as targeted advertising, without further control by the data subject.
This framing overlooked existing judicial practice. In case No. A40-5250/2017, courts upheld Roskomnadzor positions that data from open profiles on VKontakte, Odnoklassniki, Twitter and Avito did not automatically become publicly available personal data under Article 8. The Supreme Court refused to review the case. A further Tagansky District Court ruling on 3 March 2020 ordered an internet page that provided unrestricted access to personal data without consent to be included in the register of violators under Article 15.5 of the Law on Information.
The initial draft proposed a detailed consent mechanism: subjects would list specific categories of data, name the exact internet resources where data could appear, and set conditions or prohibitions. Two distinct prohibitions were envisaged—one preventing the operator from transferring data to an unlimited circle of persons (except providing access), and another preventing that circle from further processing (except receiving access). The draft also allowed subjects to demand cessation of processing at any time without proving a violation.
During the first reading on 9 December 2020, the responsible committee itself stated that the bill’s declared objectives were not achieved by its provisions. The Legal Department warned that the bill’s use of the term “access” conflicted with the definition already contained in 152-FZ, where processing includes transfer and transfer includes access. The committee nevertheless recommended passage, promising corrections before the second reading.
The final text preserved the broad definitions of processing, transfer and dissemination while adding new exceptions and a lengthy new category of data alongside the existing Article 8. The resulting framework mixes several legal models without adequate reconciliation, rendering consistent practical application extremely difficult for operators.
Related articles
Why Russia Needs Specialized Circumvention Tools Beyond Standard VPNs
The developers of Tunnel Kitten explain why another circumvention project is necessary despite the availability of numerous VPN services and solutions like AmneziaWG. A prolonged outage affected many long-term users, damaging trust and requiring ongoing fixes. Standard VPNs do not address the core issue: creating and maintaining tools to bypass internet blocks has been criminalized in Russia. This legal asymmetry makes public VPN services and self-hosted solutions risky or insufficient for users facing state-level censorship. Tunnel Kitten positions itself as a project focused on a different task that accounts for these legal realities. The team emphasizes that the problem is not merely technical but tied to the criminalization of circumvention efforts.
US Presidential Memo Authorizes Selected Private Companies to Join Federal Cyber Operations Against Foreign Criminal Groups
The United States government has established a formal program allowing vetted private-sector companies to participate in offensive cyber operations targeting foreign criminal organizations. Signed by President Donald Trump on August 12, 2026, the presidential memorandum places the initiative under the National Coordination Center with joint oversight from the Department of Justice and the Department of Homeland Security. Participating firms will operate exclusively under government contracts, direction, and supervision, with strict requirements including technical evaluations, financial guarantees of at least one million dollars, and pre-approval for every operation. The program focuses on disrupting ransomware, phishing, financial fraud, and other schemes affecting American citizens while imposing clear limits to prevent unintended harm to US persons or escalation to prohibited levels of force. In contrast to Brazil’s ongoing policy discussions, the US move formally recognizes that advanced offensive capabilities now reside primarily in the private sector and creates a regulated mechanism to access them. Operational rules must be published within 60 days, marking a significant shift in how governments integrate private expertise into state-directed cyber actions.
Russia to Require Independent Lab Testing of Sovereign AI Models for Legal and Traditional Values Compliance
The Russian Ministry of Digital Development is discussing a certification scheme under which developers can submit large generative AI models to accredited independent laboratories. These labs will verify compliance with Russian legislation and traditional spiritual-moral values defined in presidential decree No. 809. Only models seeking official national or sovereign status, which unlocks state support, data access and priority procurement, will undergo the process. Developers must first conduct self-testing according to a risk-oriented methodology and supply architecture details, filtering mechanisms and other documentation. Accredited laboratories will then run benchmarks, attempt prompt-injection attacks and produce evaluation reports, while the final decision remains with MinTsifry. Separate security assessments for government systems will be performed by the FSB and FSTEC Russia. Experts have called for transparent, reproducible tests and periodic re-certification after model updates.
Why Separate Corporate and Personal Email Accounts: Risks of Mixing Work and Private Communications
Mixing corporate and personal email accounts creates serious security, compliance, and operational risks for both employees and organizations. When employees forward contracts or client data to personal mailboxes to bypass size limits or convenience, copies proliferate beyond company control in phones, backups, and cloud services. After termination, the employer loses any ability to revoke access or audit the data, while personal accounts often lack multi-factor authentication and strong password practices. Russian legislation including Federal Law No. 152-FZ on personal data, the Labor Code, and Federal Law No. 98-FZ on trade secrets requires proper protection of sensitive information. Using work email for shopping, banking, or password recovery exposes the corporate domain to phishing and leaks, while the reverse creates dependency on private accounts for business continuity. The recommended practice is strict separation with unique passwords, MFA on both accounts, and approved corporate channels for file transfer.