Russia's Article 10.1 on Personal Data Dissemination: Apparent and Real Contradictions in Federal Law 152-FZ
Part II of the series examines whether the text of Article 10.1 of Federal Law 152-FZ is workable after the concept was completely rewritten between the first and second readings without public discussion. The analysis focuses on three questions that any operator must answer: the meaning of the key terms 'access', 'dissemination' and 'provision'; the legal basis on which a person who obtained data from an open source may process them; and how restrictions set by the data subject reach that person and what happens when they are violated.
The author compares the terminology of 152-FZ with the general information law 149-FZ, both adopted on the same day in 2006. While 152-FZ defines both dissemination and provision through the undefined term 'disclosure', 149-FZ supplies a usable definition of 'access' as the possibility of obtaining information and using it. This definition is treated as a state rather than an action, which helps explain some provisions but creates new contradictions elsewhere.
Part 9 of Article 10.1 allows the data subject to prohibit an operator from transferring data to an unlimited circle of persons except by providing access, and to prohibit that circle from processing the data except by obtaining access. The first prohibition is coherent: the operator may keep data publicly available where consent permits but may not sell arrays, fulfil individual requests or otherwise transfer the data. The second prohibition, however, leads to an irresolvable collision because the word 'use' appears both in the definition of access and in the list of processing operations, making any consistent reading either ban reading the published data or permit almost all forms of processing.
The original draft by deputy Gorelkin had preserved the ground of public availability under Article 6 while conditioning it on the subject's conditions and prohibitions. This ground was removed during the second reading, and the special regime moved to Article 10.1 without a corresponding processing basis for subsequent operators. Judicial practice, including cases such as А40-5250/2017 and several 2022–2024 decisions, confirms that openness alone does not authorise processing; each subsequent operator must establish its own ground under Article 6.
Two readings of the special consent are possible. Under the 'portable consent' reading, the consent would authorise further processing by an unlimited circle within the recorded limits; under the narrower reading, it only authorises the primary operator's disclosure and every other person must find an independent ground. Courts appear to favour the narrower view, leaving the conditions and prohibitions without a legal foundation that would make them effective.
Parts 11 and 15 expressly exclude processing in state, public or other legally defined public interests and processing by state and municipal bodies from the operation of the article. These carve-outs were deliberately retained and expanded during the second reading. The resulting structure therefore preserves the subject's ability to set conditions while simultaneously removing the legal basis those conditions were intended to regulate.
Related articles
Russian Data Centers May Face Temporary State Management Under Decree 604 for Protection Shortfalls
Large Russian data centers could be placed under temporary government administration if they fail to meet security requirements outlined in presidential decree No. 604. The measure targets critical infrastructure operators that neglect physical and cyber protections, create operational risks, or respond slowly to incidents such as drone strikes. Rosimushchestvo would typically assume management duties by default. Market participants note that Tier III and higher facilities generally maintain strong cyber defenses, shifting the main compliance burden to physical safeguards for generators, cooling systems, and network nodes. Operators including RTK-DC and RUVDS have already begun reviewing and upgrading external equipment protection. Additional costs for redundant communications, DDoS mitigation, vulnerability management, and faster recovery are expected to be passed on to clients in government, finance, and telecom sectors. First Deputy Prime Minister Denis Manturov stated that decisions will remain targeted and will not trigger widespread nationalization.
iMazing 3.6.3 Restores Sideloading of Removed iOS Apps via macOS After Apple Authentication Changes
Developers of iMazing have released version 3.6.3 that restores the ability for users to download and install applications previously removed from the App Store onto iPhone devices. The update currently functions only through macOS, with Windows support still pending further development. The changes address authentication and download errors that appeared in macOS 26 and earlier versions following modifications by Apple to its CommerceKit system. Apple began returning HTTP 403 Forbidden responses to tools including iMazing, ipa_downloader, and 3uTools by deactivating legacy tokens and revoking certificates used for app authentication. The restrictions have particularly affected Russian users who relied on these tools to reinstall banking and other applications removed due to sanctions. Support for macOS 27 Golden Gate and Windows remains unavailable and requires additional engineering work.
FSTEC Order 60 Expands Attestation Rules to Municipal Systems, Defense Industry and Personal Data Operators
Russia's FSTEC Order No. 60, effective 1 September 2026, rewrites the list of entities subject to information system attestation under the updated Order No. 77. The changes reach far beyond state information systems to cover municipal information systems, industrial control systems at defense enterprises, protected premises for confidential talks, and any commercial personal data operators that voluntarily included attestation in their policies. New clauses introduce mandatory vulnerability analysis and penetration testing as explicit control methods, tighten reporting deadlines to five working days, and require FSTEC-licensed organizations with specific rights for testing. Parallel FSB Order No. 297 obliges every state institution, including schools and hospitals, to report incidents to NKTSKI within 24 hours via a personal cabinet established only after a formal interaction regulation is signed. Government Decree No. 1024 permits cloud services for state systems but keeps full compliance responsibility with the user organization. The combined rules take effect on 1 September 2026, with one provision delayed until March 2027.
From MTTD and MTTR to Real Value: How to Organize SOC Metrics Effectively
Anatoly Antipov, head of L1 analysts at a small in-house SOC, explains why traditional time-based metrics like MTTD and MTTR often lead to superficial incident handling and analyst burnout. Drawing on NIST SP 800-61 and the latest SANS SOC Survey, the article shows how speed-focused KPIs encourage analysts to game the system rather than improve security. The team replaced vague verdicts with a five-level matrix including TP.Ext, TP.Int, BP, FP, and FP.SOC to separate real incidents, benign activity, and internal detection debt. Weekly reports were restructured around three blocks covering overall volume, verdict distribution, and confirmed violations with actual effort metrics. Regular quality audits of closed alerts now check verdict accuracy, documentation completeness, and whether FP.SOC items trigger rule improvements. The approach helps small SOC teams focus on genuine risk reduction instead of dashboard optics.