HabrJuly 25, 2026🇷🇺Translated from Russian

Russia's Article 10.1 on Personal Data Dissemination: Apparent and Real Contradictions in Federal Law 152-FZ

Part II of the series examines whether the text of Article 10.1 of Federal Law 152-FZ is workable after the concept was completely rewritten between the first and second readings without public discussion. The analysis focuses on three questions that any operator must answer: the meaning of the key terms 'access', 'dissemination' and 'provision'; the legal basis on which a person who obtained data from an open source may process them; and how restrictions set by the data subject reach that person and what happens when they are violated.

The author compares the terminology of 152-FZ with the general information law 149-FZ, both adopted on the same day in 2006. While 152-FZ defines both dissemination and provision through the undefined term 'disclosure', 149-FZ supplies a usable definition of 'access' as the possibility of obtaining information and using it. This definition is treated as a state rather than an action, which helps explain some provisions but creates new contradictions elsewhere.

Part 9 of Article 10.1 allows the data subject to prohibit an operator from transferring data to an unlimited circle of persons except by providing access, and to prohibit that circle from processing the data except by obtaining access. The first prohibition is coherent: the operator may keep data publicly available where consent permits but may not sell arrays, fulfil individual requests or otherwise transfer the data. The second prohibition, however, leads to an irresolvable collision because the word 'use' appears both in the definition of access and in the list of processing operations, making any consistent reading either ban reading the published data or permit almost all forms of processing.

The original draft by deputy Gorelkin had preserved the ground of public availability under Article 6 while conditioning it on the subject's conditions and prohibitions. This ground was removed during the second reading, and the special regime moved to Article 10.1 without a corresponding processing basis for subsequent operators. Judicial practice, including cases such as А40-5250/2017 and several 2022–2024 decisions, confirms that openness alone does not authorise processing; each subsequent operator must establish its own ground under Article 6.

Two readings of the special consent are possible. Under the 'portable consent' reading, the consent would authorise further processing by an unlimited circle within the recorded limits; under the narrower reading, it only authorises the primary operator's disclosure and every other person must find an independent ground. Courts appear to favour the narrower view, leaving the conditions and prohibitions without a legal foundation that would make them effective.

Parts 11 and 15 expressly exclude processing in state, public or other legally defined public interests and processing by state and municipal bodies from the operation of the article. These carve-outs were deliberately retained and expanded during the second reading. The resulting structure therefore preserves the subject's ability to set conditions while simultaneously removing the legal basis those conditions were intended to regulate.

Related articles

SecuritylabPolicy & Regulation

Why Deep Packet Inspection Overestimates Its Reach in Encrypted Networks

Modern encryption has fundamentally limited the effectiveness of Deep Packet Inspection systems, leaving network monitors with only metadata and behavioral patterns rather than actual content. DPI tools can still classify traffic types and apply policies based on visible flow characteristics, but they cannot read messages, files, or credentials inside properly encrypted sessions without explicit TLS inspection. The article details how TLS 1.3, Encrypted Client Hello, and QUIC further reduce passive visibility while corporate inspection remains possible only when endpoint devices trust an organizational certificate. Russian regulatory requirements around TSPU systems are discussed separately from corporate DPI use, with emphasis on the need for technical confirmation rather than assumptions. The piece also clarifies distinctions between DPI, IDS, IPS, and DLP, and explains why machine learning cannot convert metadata into decrypted payloads. Overall, the analysis shows that DPI remains useful for traffic management and known-threat detection where visibility exists, but it cannot serve as a complete security foundation.

HabrPolicy & Regulation

How Russia's Article 10.1 on Personal Data Dissemination Emerged: Legislative History and Reform Flaws

The article examines the origins of Article 10.1 in Federal Law 152-FZ, introduced via bill 1057337-7 by deputy Anton Gorelk in in November 2020. It traces how the reform aimed to separate publication, access, extraction, and reuse of personal data but retained outdated definitions from the original law and added exceptions that created contradictions. The piece details pre-reform court rulings, including Supreme Court decisions confirming that open internet profiles do not automatically qualify as publicly available data under Article 8. It highlights the committee's own admission that the bill failed to meet its stated goals and the Legal Department's warning about inconsistent terminology around 'access' and 'transfer'. The resulting 519-FZ law is described as an imprecise attempt to solve real control problems with unsuitable conceptual tools, leaving operators unable to apply the rules consistently.

AntiMalwarePolicy & Regulation

EU Imposes 21st Sanctions Package Targeting 94 Russian Banks Including Ozon Bank, Yandex Bank and WB Bank

The European Union has adopted its 21st sanctions package against Russia, placing restrictions on 94 banks, the Moscow Exchange, and several payment organizations. The measures, effective from 23 July, directly affect Rosselkhozbank, Dom.rf, MTS Bank, Ak Bars, Uralsib, Zenit, Absolut Bank, WB Bank, Ozon Bank, Tochka, Yandex Bank, and Post Bank. Personal sanctions were also imposed on Bank of Russia Deputy Chairman Sergey Belov, Russian Railways head Oleg Belozerov, and other individuals. In addition to finance, the package covers energy, trade, and cryptocurrency sectors. Russian financial institutions have stated that operations continue normally, though the Golden Crown payment system has already suspended transfers to Georgia and several other countries. Moscow Exchange and affected banks including Ozon Bank and Tochka confirmed that trading, settlements, and client services remain unchanged.

AntiMalwarePolicy & Regulation

Sberbank to Terminate Currency and Multicurrency Visa Cards from September 2026 Despite Prior Extensions to 2030

Sberbank announced it will cease servicing currency and multicurrency Visa cards starting September 1, 2026, including those whose validity was previously extended until 2030. The bank notified customers via SMS and advised them to close affected cards in advance through the Sberbank Online app or at a branch to avoid access issues with their funds. This decision aligns with ongoing sanctions against Russia, import substitution policies, and the gradual removal of Visa and Mastercard from the Russian market. Central Bank officials, including Elvira Nabiullina and Alla Bakina, have confirmed that international payment systems must exit Russia, with the share of Visa and Mastercard already reduced to less than 17 percent. The National System of Payment Cards continues to incur costs supporting legacy cards while promoting domestic alternatives such as Mir. Customers are encouraged to transfer remaining balances to other accounts to maintain uninterrupted access to their money.