Russia's Article 10.1 on Personal Data Dissemination: Apparent and Real Contradictions in Federal Law 152-FZ
Part II of the series examines whether the text of Article 10.1 of Federal Law 152-FZ is workable after the concept was completely rewritten between the first and second readings without public discussion. The analysis focuses on three questions that any operator must answer: the meaning of the key terms 'access', 'dissemination' and 'provision'; the legal basis on which a person who obtained data from an open source may process them; and how restrictions set by the data subject reach that person and what happens when they are violated.
The author compares the terminology of 152-FZ with the general information law 149-FZ, both adopted on the same day in 2006. While 152-FZ defines both dissemination and provision through the undefined term 'disclosure', 149-FZ supplies a usable definition of 'access' as the possibility of obtaining information and using it. This definition is treated as a state rather than an action, which helps explain some provisions but creates new contradictions elsewhere.
Part 9 of Article 10.1 allows the data subject to prohibit an operator from transferring data to an unlimited circle of persons except by providing access, and to prohibit that circle from processing the data except by obtaining access. The first prohibition is coherent: the operator may keep data publicly available where consent permits but may not sell arrays, fulfil individual requests or otherwise transfer the data. The second prohibition, however, leads to an irresolvable collision because the word 'use' appears both in the definition of access and in the list of processing operations, making any consistent reading either ban reading the published data or permit almost all forms of processing.
The original draft by deputy Gorelkin had preserved the ground of public availability under Article 6 while conditioning it on the subject's conditions and prohibitions. This ground was removed during the second reading, and the special regime moved to Article 10.1 without a corresponding processing basis for subsequent operators. Judicial practice, including cases such as А40-5250/2017 and several 2022–2024 decisions, confirms that openness alone does not authorise processing; each subsequent operator must establish its own ground under Article 6.
Two readings of the special consent are possible. Under the 'portable consent' reading, the consent would authorise further processing by an unlimited circle within the recorded limits; under the narrower reading, it only authorises the primary operator's disclosure and every other person must find an independent ground. Courts appear to favour the narrower view, leaving the conditions and prohibitions without a legal foundation that would make them effective.
Parts 11 and 15 expressly exclude processing in state, public or other legally defined public interests and processing by state and municipal bodies from the operation of the article. These carve-outs were deliberately retained and expanded during the second reading. The resulting structure therefore preserves the subject's ability to set conditions while simultaneously removing the legal basis those conditions were intended to regulate.
Related articles
Ruthenium: Custom Chromium Build for Android Adds Russian Trusted Root CA Support
A developer has released Ruthenium, a modified Chromium browser for Android that embeds the Russian Trusted Root CA certificate issued by the Ministry of Digital Development. The build restricts trust to .ru and .рф domains only, avoiding changes to the system-wide Android certificate store. The project patches four Chromium source files to include the root with DNS constraints via CertWithConstraints, disables Google sign-in by default, and removes XR-related code for successful compilation. Ruthenium uses the official Chromium TLS verification logic without introducing a custom verifier. The APK is distributed with SHA-256 checksums, build metadata, and reproducible release tags tied to the exact Chromium revision and certificate digest. Users can install it alongside stock Chrome and use it selectively for Russian government and banking sites that rely on the state root.
US Federal Judge Orders Google to Simplify Installation of Third-Party App Stores on Android
A federal judge has directed Google to remove extra warnings and confirmation steps when users install competing app stores through Google Play on Android devices. The ruling stems from the ongoing antitrust litigation between Epic Games and Google, where a jury previously found that Google illegally maintained a monopoly over Android app distribution and in-app payments. Judge James Donato criticized the current multi-screen process as an intentional barrier designed to discourage ordinary users from choosing alternatives. Google must implement the changes within one week, making the installation of third-party stores as straightforward as any other Android application. The decision acknowledges that while Android has long permitted sideloading, the layered security prompts and hidden permission toggles effectively steered most users back to Google Play. Aptoide has already appeared in the US Google Play store as the first third-party marketplace to benefit from the eased process. Google argued the warnings protect users from malware, but the court rejected the notion that security should serve as a shield for market dominance.
Why Russia Needs Specialized Circumvention Tools Beyond Standard VPNs
The developers of Tunnel Kitten explain why another circumvention project is necessary despite the availability of numerous VPN services and solutions like AmneziaWG. A prolonged outage affected many long-term users, damaging trust and requiring ongoing fixes. Standard VPNs do not address the core issue: creating and maintaining tools to bypass internet blocks has been criminalized in Russia. This legal asymmetry makes public VPN services and self-hosted solutions risky or insufficient for users facing state-level censorship. Tunnel Kitten positions itself as a project focused on a different task that accounts for these legal realities. The team emphasizes that the problem is not merely technical but tied to the criminalization of circumvention efforts.
US Presidential Memo Authorizes Selected Private Companies to Join Federal Cyber Operations Against Foreign Criminal Groups
The United States government has established a formal program allowing vetted private-sector companies to participate in offensive cyber operations targeting foreign criminal organizations. Signed by President Donald Trump on August 12, 2026, the presidential memorandum places the initiative under the National Coordination Center with joint oversight from the Department of Justice and the Department of Homeland Security. Participating firms will operate exclusively under government contracts, direction, and supervision, with strict requirements including technical evaluations, financial guarantees of at least one million dollars, and pre-approval for every operation. The program focuses on disrupting ransomware, phishing, financial fraud, and other schemes affecting American citizens while imposing clear limits to prevent unintended harm to US persons or escalation to prohibited levels of force. In contrast to Brazil’s ongoing policy discussions, the US move formally recognizes that advanced offensive capabilities now reside primarily in the private sector and creates a regulated mechanism to access them. Operational rules must be published within 60 days, marking a significant shift in how governments integrate private expertise into state-directed cyber actions.