HabrJuly 25, 2026🇷🇺Translated from Russian

How Russia's Article 10.1 on Personal Data Dissemination Emerged: Legislative History and Reform Flaws

The Russian personal data protection regime underwent significant change with the introduction of Article 10.1 in Federal Law No. 152-FZ. The reform, formally enacted through Federal Law No. 519-FZ, took effect on 1 March 2021 and required separate consent for processing personal data that a subject permits to be disseminated.

Author Anton Gorelk in, First Deputy Chairman of the State Duma Committee on Information Policy, Information Technology and Communications, sponsored the original bill 1057337-7 on 17 November 2020. The explanatory note claimed that once data appeared on websites, operators could freely accumulate, supplement and analyse it for purposes such as targeted advertising, without further control by the data subject.

This framing overlooked existing judicial practice. In case No. A40-5250/2017, courts upheld Roskomnadzor positions that data from open profiles on VKontakte, Odnoklassniki, Twitter and Avito did not automatically become publicly available personal data under Article 8. The Supreme Court refused to review the case. A further Tagansky District Court ruling on 3 March 2020 ordered an internet page that provided unrestricted access to personal data without consent to be included in the register of violators under Article 15.5 of the Law on Information.

The initial draft proposed a detailed consent mechanism: subjects would list specific categories of data, name the exact internet resources where data could appear, and set conditions or prohibitions. Two distinct prohibitions were envisaged—one preventing the operator from transferring data to an unlimited circle of persons (except providing access), and another preventing that circle from further processing (except receiving access). The draft also allowed subjects to demand cessation of processing at any time without proving a violation.

During the first reading on 9 December 2020, the responsible committee itself stated that the bill’s declared objectives were not achieved by its provisions. The Legal Department warned that the bill’s use of the term “access” conflicted with the definition already contained in 152-FZ, where processing includes transfer and transfer includes access. The committee nevertheless recommended passage, promising corrections before the second reading.

The final text preserved the broad definitions of processing, transfer and dissemination while adding new exceptions and a lengthy new category of data alongside the existing Article 8. The resulting framework mixes several legal models without adequate reconciliation, rendering consistent practical application extremely difficult for operators.

Related articles

SecuritylabPolicy & Regulation

Why Deep Packet Inspection Overestimates Its Reach in Encrypted Networks

Modern encryption has fundamentally limited the effectiveness of Deep Packet Inspection systems, leaving network monitors with only metadata and behavioral patterns rather than actual content. DPI tools can still classify traffic types and apply policies based on visible flow characteristics, but they cannot read messages, files, or credentials inside properly encrypted sessions without explicit TLS inspection. The article details how TLS 1.3, Encrypted Client Hello, and QUIC further reduce passive visibility while corporate inspection remains possible only when endpoint devices trust an organizational certificate. Russian regulatory requirements around TSPU systems are discussed separately from corporate DPI use, with emphasis on the need for technical confirmation rather than assumptions. The piece also clarifies distinctions between DPI, IDS, IPS, and DLP, and explains why machine learning cannot convert metadata into decrypted payloads. Overall, the analysis shows that DPI remains useful for traffic management and known-threat detection where visibility exists, but it cannot serve as a complete security foundation.

AntiMalwarePolicy & Regulation

EU Imposes 21st Sanctions Package Targeting 94 Russian Banks Including Ozon Bank, Yandex Bank and WB Bank

The European Union has adopted its 21st sanctions package against Russia, placing restrictions on 94 banks, the Moscow Exchange, and several payment organizations. The measures, effective from 23 July, directly affect Rosselkhozbank, Dom.rf, MTS Bank, Ak Bars, Uralsib, Zenit, Absolut Bank, WB Bank, Ozon Bank, Tochka, Yandex Bank, and Post Bank. Personal sanctions were also imposed on Bank of Russia Deputy Chairman Sergey Belov, Russian Railways head Oleg Belozerov, and other individuals. In addition to finance, the package covers energy, trade, and cryptocurrency sectors. Russian financial institutions have stated that operations continue normally, though the Golden Crown payment system has already suspended transfers to Georgia and several other countries. Moscow Exchange and affected banks including Ozon Bank and Tochka confirmed that trading, settlements, and client services remain unchanged.

AntiMalwarePolicy & Regulation

Sberbank to Terminate Currency and Multicurrency Visa Cards from September 2026 Despite Prior Extensions to 2030

Sberbank announced it will cease servicing currency and multicurrency Visa cards starting September 1, 2026, including those whose validity was previously extended until 2030. The bank notified customers via SMS and advised them to close affected cards in advance through the Sberbank Online app or at a branch to avoid access issues with their funds. This decision aligns with ongoing sanctions against Russia, import substitution policies, and the gradual removal of Visa and Mastercard from the Russian market. Central Bank officials, including Elvira Nabiullina and Alla Bakina, have confirmed that international payment systems must exit Russia, with the share of Visa and Mastercard already reduced to less than 17 percent. The National System of Payment Cards continues to incur costs supporting legacy cards while promoting domestic alternatives such as Mir. Customers are encouraged to transfer remaining balances to other accounts to maintain uninterrupted access to their money.

AntiMalwarePolicy & Regulation

.RU and .РФ Registries Stop Disclosing Legal Entity Domain Owners in WHOIS

The domain registries for .RU and .РФ have ceased displaying detailed information about administrators that are legal entities. Previously the WHOIS service revealed the full name of the organization along with its INN tax identification number, but the records now show only the generic term Organization. The change was first noticed on 22 July by Habr user @ifap, who observed that domains previously linked to government bodies such as the Federal Protective Service no longer reveal the actual administrator. Support staff at the Coordination Center attributed the disappearance of data to unspecified technical issues and described the outage as temporary, without providing any timeline or details on the root cause. Observers note that the reduced transparency turns routine owner identification into a lengthy investigation, especially for less prominent domains. One unconfirmed theory suggests the registry is being reconfigured to meet new authentication requirements for domain administrators. It remains unclear whether the previous level of disclosure will be restored or whether the current limited view will become permanent.