Russia's Article 10.1 on Personal Data Dissemination: Apparent and Real Contradictions in Federal Law 152-FZ
Part II of the series examines whether the text of Article 10.1 of Federal Law 152-FZ is workable after the concept was completely rewritten between the first and second readings without public discussion. The analysis focuses on three questions that any operator must answer: the meaning of the key terms 'access', 'dissemination' and 'provision'; the legal basis on which a person who obtained data from an open source may process them; and how restrictions set by the data subject reach that person and what happens when they are violated.
The author compares the terminology of 152-FZ with the general information law 149-FZ, both adopted on the same day in 2006. While 152-FZ defines both dissemination and provision through the undefined term 'disclosure', 149-FZ supplies a usable definition of 'access' as the possibility of obtaining information and using it. This definition is treated as a state rather than an action, which helps explain some provisions but creates new contradictions elsewhere.
Part 9 of Article 10.1 allows the data subject to prohibit an operator from transferring data to an unlimited circle of persons except by providing access, and to prohibit that circle from processing the data except by obtaining access. The first prohibition is coherent: the operator may keep data publicly available where consent permits but may not sell arrays, fulfil individual requests or otherwise transfer the data. The second prohibition, however, leads to an irresolvable collision because the word 'use' appears both in the definition of access and in the list of processing operations, making any consistent reading either ban reading the published data or permit almost all forms of processing.
The original draft by deputy Gorelkin had preserved the ground of public availability under Article 6 while conditioning it on the subject's conditions and prohibitions. This ground was removed during the second reading, and the special regime moved to Article 10.1 without a corresponding processing basis for subsequent operators. Judicial practice, including cases such as А40-5250/2017 and several 2022–2024 decisions, confirms that openness alone does not authorise processing; each subsequent operator must establish its own ground under Article 6.
Two readings of the special consent are possible. Under the 'portable consent' reading, the consent would authorise further processing by an unlimited circle within the recorded limits; under the narrower reading, it only authorises the primary operator's disclosure and every other person must find an independent ground. Courts appear to favour the narrower view, leaving the conditions and prohibitions without a legal foundation that would make them effective.
Parts 11 and 15 expressly exclude processing in state, public or other legally defined public interests and processing by state and municipal bodies from the operation of the article. These carve-outs were deliberately retained and expanded during the second reading. The resulting structure therefore preserves the subject's ability to set conditions while simultaneously removing the legal basis those conditions were intended to regulate.
Related articles
Rosfinmonitoring Denies Mass Bank Account Blocks Over Partial Data Matches with Sanctions Lists
Rosfinmonitoring has issued clarifications rejecting reports of potential widespread freezes of bank accounts due to partial matches between client data and records of individuals subject to asset freezes. The agency stressed that the draft law is not intended to penalize people who merely share surnames or have similar name transliterations with sanctioned persons. Criteria for determining partial matches have not yet been defined and will be established by a separate order only after the federal law is adopted and real cases are analyzed. The measure provides only for temporary suspension of a transaction rather than automatic refusal or indefinite account blocking. Earlier reports from Izvestia had warned that loosely defined partial-match rules could generate numerous false positives affecting ordinary clients.
Understanding GOST Cryptography Standards: A Practical Guide for Russian Developers
The article provides a beginner-friendly breakdown of Russian GOST cryptographic standards, separating the core functions of hashing, digital signatures, and encryption. It covers the evolution of GOST algorithms across three generations from the 1990s to the current 2012+ standards including Stribog, Kuznechik, and Magma. Detailed explanations address how PKCS#11 interfaces with hardware tokens, how X.509 certificates function as digital passports, and how formats like CAdES, XAdES, and PAdES package signatures for verification. Comparisons with Western equivalents such as SHA-256, RSA, and AES help developers map familiar concepts to GOST implementations. The guide emphasizes practical integration with tools like CryptoPro for tasks involving detached signatures and certificate requests in PKCS#10 and PKCS#12 containers.
Why Vulnerability Management Specialists Must Master Compliance: Closing All CVEs but Leaving admin:admin
The article explains how compliance has evolved from a paperwork exercise into a mandatory, heavily penalized process in Russian cybersecurity. New regulations such as FSTEC Order 117, turnover fines for personal data leaks, and Presidential Decree 250 impose strict timelines and personal liability for vulnerability management failures. It outlines three approaches to compliance, from doing nothing to building custom standards based on CIS Benchmarks and local requirements. The text stresses moving from reactive scanning to golden images that embed compliance controls before deployment. It highlights tools like MaxPatrol HCC, RedCheck, and ScanOVAL for automated checks and warns that technical patches alone are useless without proper configuration controls such as strong passwords.
China Public Security Ministry Warns IoT Operators: Default Passwords on Devices Like Bus Stop Displays Violate Cybersecurity Law Even Without Major Incidents
A bus electronic display router in Wuhu, Anhui, was compromised in April 2026 because the device retained factory-default credentials and exposed multiple management ports. The Ministry of Public Security highlighted the case in its Hu Wang 2026 report, stressing that failing to change default passwords and leaving ports open constitutes a violation of the Cybersecurity Law regardless of whether serious harm occurred. The RCtea botnet actively targeted similar routers and cameras across China, infecting 9,827 devices in just six days in January 2026 through Telnet brute-force attacks. Experts from the Chinese Academy of Social Sciences clarified that penalties do not require actual damage and that operators must implement technical measures, retain logs for at least six months, and maintain internal security procedures. Additional cases in Qinghai and Nanchong demonstrated repeated enforcement actions against entities that ignored weak-password remediation orders. The report calls on operators, regulators, and manufacturers to enforce password changes at installation, close unnecessary ports, and apply network segmentation to prevent low-hanging IoT devices from becoming botnet recruits.